• pedroapero
    arrow-up
    1
    arrow-down
    0
    ·
    3 months ago
    link
    fedilink

    All your session cookies are stored in plaintext.

    • x1gma
      arrow-up
      1
      arrow-down
      0
      ·
      3 months ago
      link
      fedilink

      Chrome cookies are encrypted, for exactly the reasons stated. If malware gains access to your system and compromises it in a way that DPAPI calls can be replicated in the way Chrome does it, then your sessions will also be compromised. But this is way harder to do, and at least prevents trivial data exfiltration.