Ex-NSA hacker drops macOS High Sierra zero-day hours before launch
zdnet.com
zdnet.com
It's been possible to dump passwords from the current user's Login Keychain via "security dump-keychain -d login.keychain" or "sudo keychaindump" for a long time:
https://tinyapps.org/blog/mac/201211030700_recover_keychain_...
You should publish.
It sure would be nice if gaining a foothold on my computer didn't instantly mean gaining complete control over al my credentials.
If you disagree with his argument perhaps you could give an actual counter argument?