People reuse passwords, so its likely that WeChat passwords allow access to other systems (like Facebook, Twitter, Alibaba, Amazon,...)
This attack angle of just collecting passwords for government has not yet occured to me before.
People reuse passwords, so its likely that WeChat passwords allow access to other systems (like Facebook, Twitter, Alibaba, Amazon,...)
This attack angle of just collecting passwords for government has not yet occured to me before.
And then people getting surprised from where do those ginormous plaintext password leaks come from.
All kinds of popular online forum engines were being hacked for password captures since times immemorial. PHPBB still uses server side hashing for example.
Now, for people concerned, take a look who was the party who sank crypto forms at W3C.
Direct access via the companies themselves is probably much more valuable today.
In the case of China in particular we know that part of the "Great Firewall" have IP addresses associated with Chinese residential ISPs, whether those are "hijacked" or the relevant agency just asks nicely we do not know. So it may be that "Chinese central government intelligence agency" and "My neighbour's WiFi" are similar IP addresses if you live there.
But yes multi-factor authentication can reduce the impact of credential stuffing attacks.