Android malware steals user credentials using optical character recognition

octalfudge@lemmy.world to Technology@lemmy.world – 138 points –
Android malware steals user credentials using optical character recognition
arstechnica.com
8

You are viewing a single comment

Most integrated password managers should thwart this assuming the user doesn't reveal their passwords, though. The only thing in plaintext that would be visible would be the username. Of course, this assumes that OCR is their only vector.

If the password is being manually typed by the user, you could still theoretically use OCR against the keyboard inputs updating as the user taps each key, since most keyboards will highlight the selected key in some way.

@Chozo That's exactly why we should pick our mobile keyboards wisely lmao. Also regarding that, there are alot of open-source keyboards on F-Droid.