Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Is that different? "Eventually get all of your passwords" sounds just as bad to me, especially since only some passwords are worth anything and my email password can be used to reset all other passwords.


You can't reset my online banking login password by email.

You can't reset my online banking operation password by email.

You can't reset my crypto wallet passwords by email.

If you can read all of these from memory without me ever having interacted with the password, you can take all my money and then what do I do?


The malware just waits until you use one of these passwords? The threat model of "I have these crazy essential passwords that I literally never use" is worthless. It costs the malware author nothing to wait.


Malware is like any other threat to any system. The longer it persists, the more likely it is to be detected and purged.

Malware that exists purely transiently in my system is a lot more likely to be successful and remain undetected, than malware that persists.


What bank does not use 2FA?! Only having your password should not expose your banking.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: