Could a website that has a keylogger in it potentially pick up these keystrokes when I put my password into an extension?
Could a website that has a keylogger in it potentially pick up these keystrokes when I put my password into an extension?
I think this article is a bit sensationalist. These sites already have access to all of your data (stored in their databases!). There's nothing additional they are gaining from this aside from how you input that data. That is much less sensitive information and I can't think of another usage aside from improving their site's UX.
Say for example a website asks me for something (e.g. an address, phone number, bank account number), I type it in (thus registering my keystroke presses to the keylogger) and then realise oops I didn't mean to type that, I meant to type something else
Does the website then submit the logged keystrokes for offline analysis?
All responsible implementations of this won't actually log PII. It's pretty trivial to withhold certain inputs. All of the services mentioned in the article have easy ways to flag an input field as private / do not log. I'd wager a lot of money that these sites are interested in gathering UX data and not scraping for accidental form input.
I suppose there's a certain level of trust involved, but I don't think that's any different than when you make an online purchase. /shrug
The assumption for most people is going to be that they have the data that you explicitly sent them. Implicitly gathering and sending data is equivalent to snooping on people without consent. It's all about expectations.
Yes of course. All it takes is misclicking and having the focus on a wrong window, and you're toast.
Hacking a popular extension is one of the easiest routes to fully compromising millions of users (and every account they own). People are generally unaware of this danger, but it's much worse than ads or tracking.