←back to thread

1192 points gniting | 1 comments | | HN request time: 0.222s | source
Show context
cheschire ◴[] No.43519772[source]
Can windows apps (not installed from the MS store) enumerate through the window titles of all open windows? How hard would it be for an app to monitor all of your web traffic based on the title alone?

Legit question. ChatGPT isn't super helpful here since it agrees with everything when I'm really looking for someone to say why this isn't really feasible in the real world.

replies(8): >>43519783 #>>43519798 #>>43519847 #>>43519871 #>>43520382 #>>43520475 #>>43521311 #>>43521404 #
gruez ◴[] No.43519783[source]
Most windows apps aren't sandboxed, so them being able to grab window titles is the least of your worries. Any program can steal your login sessions and passwords if they wanted to.

https://xkcd.com/1200/

replies(1): >>43519795 #
facile3232 ◴[] No.43519795[source]
Are you essentially discussing like a keylogger? I can't imagine windows intentionally keeps the plaintext password anywhere longer than it needs to be.
replies(5): >>43519816 #>>43520114 #>>43520858 #>>43522437 #>>43523306 #
gruez ◴[] No.43519816[source]
Obviously there's no way for a malicious program to grab your login credentials that you've entered into an incognito tab that have been closed. There might not be sandboxing, but viruses can't timetravel yet. However that's not going to be much of a defense when many users use password managers, and are terrible at detecting malware (so it's only a matter of time before their passwords are keylogged).
replies(1): >>43520008 #
1. misnome ◴[] No.43520008[source]
> viruses can't timetravel yet

_Windows Recall to the rescue!_