Yes, it requires an attacker in a powerful position with local access. However, it does not require special privileges or techniques that may trigger endpoint security (such as keyloggers or memory dumping). The only requirements are reading a JSON file and making a single Windows API call to retrieve the key.
jabart|2 years ago
kadoban|2 years ago
malfist|2 years ago
Sohcahtoa82|2 years ago
Sufficiently paranoid endpoint security could trip when the keyboard is unplugged and then plugged back in.
RedTeamPT|2 years ago
sumedh|2 years ago
It just shut me down "I can't assist with that request."
eddythompson80|2 years ago
hypeatei|2 years ago