https://www.google.ru/search?client=opera&q=intitle:%22index...
Firefox would appear to be vulnerable to that approach. Not sure about Opera's wand.dat, probably vulnerable as well.
"Good question! You're right - in these cases it is assumed malware is already present on the system and running in the context of the user. But there can simply be better protection.
Consider Firefox's use of a Master Password. Even if an attacker is on the otherside of the airtight hatchway, he/she will not get the credentials unless they can find out the password used.
Thanks for the great comment!"
But yes, to answer your question (and to validate the other poster on this thread) - If malware infects your system, you will likely have a bad time.
There are scenarios where master passwords are extremely useful and that's passive file disclosure such as a network home directory, a compromise of another account while you're not logged in, or – particularly relevant these days – a breached cloud sync service. I would make the case for that reason rather than as a malware resistance measure.
The long term fix requires architectural changes: none of the attacks described work directly on Mac OS X because the Keychain decoding happens in the securityd process which runs as root so the malware would trigger a confirmation prompt for each password it tried to pilfer. Unfortunately, this is also less than perfect as most users check the “Always allow” box granting permission to their browser for unprompted access…
Short of making you log in to your browser/password manager with a master password every time, how can you possibly store and retrieve passwords without letting other programs running with exact same permissions as you retrieve them?
Of course, that's assuming all the software is well-behaved. You could have local malware that pops up a fake master password dialog, trick a user into filling it out, pulling the keychain out of the user's Library, then decrypting the whole keychain file manually.
Once there's malware running as the user himself, all bets are off. This is why iOS is probably the most secure OS out there - there's no chance for malware to get on the device.
Personally, I just disable all password storage on all browsers and use 1Password.
This is the airtight hatchway we're talking about. The post's premise, and the solutions for Chrome and IE, imply bad guys are already on the other side. All hope is lost. Best you can do is try and make it so that anyone just stumbling around rather than purposefully looking for the passwords doesn't find them, and the value of that is questionable on false sense of security arguments.
It's non-news to anyone who understands how Windows is built.