Comment by charcircuit
2 hours ago
>Data Protection API do meaningfully reduce what you can extract from a windows system
It's not meaningfully reduced. The stealer just has to call CryptUnprotectData before uploading it. It's not even like it will show a suspicious prompt to the user, without having to do anything extra the stealer can silently decrypt it.
I agree with the rest of the post though.
No comments yet
Contribute on Hacker News ↗