Huh? If you have this level of local privileges you can just read session cookies from the browsers store? I guess stealing all the keys is notable, but you can manipulate any password manager with this level of access right?
What's the threat model here, that synced passkeys should be secure in even in situations involving compromised clients? How?
But I largely agree, if they're able to do this on your system you're already hacked and they can do a ton of very bad things.
ted_dunning•31m ago
ikidd•28m ago
ted_dunning•15m ago