4 ms·
I don't know if you're wrong but how do those password programs work? If they emulate a keyboard by sending keystokes to the appropriate input field they are m
by bockris 14y ago
I don't know if you're wrong but how do those password programs work? If they emulate a keyboard by sending keystokes to the appropriate input field they are most likely logged by programs like these. (not HW keyloggers tho).
If the password programs use the clipboard, then it is just another source for the keylogger to capture and trivial to add.
(edit: a screenshot lower in the article of the 'Perfect Keylogger' options screen shows a clipboard option.)
- jiggy2011 14y agoNot to mention the fact that once the attacker has enough access to your machine to get a keylogger installed they have pretty much pwned at least your user account so getting cookies/settings or whatever out of your browsers data folders shouldn't be too much of an issue.
- qeorge 14y agoIts been a while (AOL ;), but IIRC the Windows API lets you SET_TEXT directly by window handle. Assuming that's how 1Password works, it should be safe. I think that's a fair assumption because using the clipboard or SendKeys to an input box is all kinds of trouble in practice, and the API is easy.
- bockris 14y agoBut isn't that in itself another vector to 'hook' and redirect (just like the keystokes and clipboard)? I'm going to agree with jiggy2011. Once you are compromised at that level then it's pretty much game over.
- deleted 14y ago[deleted]
- qeorge 14y agoDefinitely. I meant that it probably didn't use the clipboard or keyboard emulation, and so it would be safe from those particular attacks. Didn't mean to imply it would be safe from everything. To nitrogen's point, there's definitely a corresponding GETTEXT message. There's even hooks[1]. But that's about all I know. Haven't written a desktop app in > 10 years. [1] http://msdn.microsoft.com/en-us/library/ms644990%28v=vs.85%29.aspx http://msdn.microsoft.com/en-us/library/ms644990%28v=vs.85%2...
- nitrogen 14y agoIf you can SET_TEXT, you can probably also get text. I've heard stories of win32 "password stealers" that constantly loop through all the window handles on the system looking for password fields, and if one is found, they log the contents of all nearby text fields (to get the username) and the password field to a file.
- martingordon 14y agoI was mostly thinking about the browser extensions, which probably use the extension API to directly set the values on the fields. FWIW, the 1Password website (http://help.agile.ws/1Password3/security.html http://help.agile.ws/1Password3/security.html) mentions copy and paste in the context of other password managers that require you to copy/paste: > Not only is this manual work inconvenient, but as soon as “copy and paste” are mentioned, you become vulnerable to keyloggers and phishing attacks.