Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Any malware or LLM with user-level filesystem access can attack the outdated KDF [1] and/or wait for Firefox to be running with an unlocked credential store and read the decrypted passwords from Firefox's process memory.

[1] https://bugzilla.mozilla.org/show_bug.cgi?id=973759



Isn't it game over anyway once you have an adversary on your system capable of reading process memory?




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: