3 ms·
It would be, but if they had a keylogger installed then the endpoint is completely owned, in which case they could just exfiltrate the password database from me
by thinkharderdev 4y ago
It would be, but if they had a keylogger installed then the endpoint is completely owned, in which case they could just exfiltrate the password database from memory. Or they can just pilfer authentication/session tokens directly once you logged in. More generally, making things more cumbersome (in the sense of requiring more steps) doesn't really provide any meaningful security since it can generally be automated anyway.