
@z@sunny.garden
Chrome security team metaprogrammer
"#Passkeys are useless to me because I use a fancy password manager and always look at the URL".
Yes but the other users of the site don't so you also have to pay the shitty 2fa tax like everyone else.
Also I promise you you can get phished.
I published a step by step guide on using Windows event logs to hunt for malware trying to steal sensitive data from browsers e.g. cookies, passwords etc. https://security.googleblog.com/2024/04/detecting-browser-data-theft-using.html #DFIR Hope it's useful!
Google Online Security Blog
Detecting browser data theft using Windows Event LogsPosted by Will Harris, Chrome Security Team Chromium's sandboxed process model defends well from malicious web content, but...