Hacker Timesnew | past | comments | ask | show | jobs | submitlogin

I remember about decades ago that keyloggers would be very scary and powerful because your only defense was your password, and you couldn't know someone was logging in at the same time as you if you were not aware of it.

Nowadays, with 2FA and all the big companies doing extra security check up when they see something wrong with the login patterns ... I don't see the use of keyloggers anymore.



Even if 2FA prevents you from logging in, you still get A LOT of information from a keylogger.

You know the content of all the emails this user writes. You know the websites they visit. Based on the 2FA auth key they use, you may find out what kind of system it is.

A great start for social engineering. The target user writes an email to someone and the day afterwards you can fake call them and pretend to be the recipient of the email (you have all the information). If you're lucky they wrote an email to management and now you can pass orders in this call.


I can assure you keyloggers still work very well at most major companies.

Maybe in a couple more decades they will have begun to use basic defenses already available.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: