Part II · Chapter 20

The Keys to Everything

One key can unlock everything — and it almost never falls to broken encryption. It falls the moment the password is typed, or one layer below, where account-recovery flows and forgotten permissions quietly hand over the rest.

A password manager exists to solve one problem: remembering many strong, unique passwords so a person never has to reuse a weak one. It is, properly built and properly used, a genuinely strong defense. The question is what happens when the one thing standing between an intact vault and a fully exposed one — a single master password — has to be typed into a device someone else already has access to.

There is a real architectural distinction here, and it determines whether that defense actually holds. A dedicated password manager — 1Password, Bitwarden, and similar products — encrypts its vault behind a separate master password the operating system session itself never has. Someone using an already-unlocked laptop still cannot see the vault without that second secret. A browser’s own built-in password storage offers no such gate. On a Windows machine, the protection on Chrome’s saved passwords is only as strong as the Windows login itself. Chrome will prompt for the account’s own credential before it displays a saved password — but in a shared household that is the credential a controlling partner most often already has, and it does nothing to stop software running under the logged-in account.1 Free, publicly distributed utilities exist that will scan every browser installed on a machine and export all locally saved passwords to a file, requiring no hacking skill beyond downloading and running one.2 And in a shared household, “physical or remote access to an unlocked computer” is not a hypothetical attacker capability. It is the ordinary daily condition of living with someone.

Even a well-designed password manager has a second point of failure its encryption cannot defend against: the moment the master password itself gets typed. Commercial stalkerware — mSpy, FlexiSPY, sold openly as parental or employee monitoring tools but documented predominantly in intimate-partner surveillance — markets keylogging as a named feature, capturing passwords as they’re entered into any field, master password included.3 This defeats the vault’s protection entirely, regardless of how strong the password is, because the mechanism breaks no encryption. It only needs to be running when the one password unlocking everything else gets typed. A parallel and, if anything, more disturbing tactic is reported in the domestic-abuse technology literature: some abusers are described unlocking a partner’s phone with the partner’s own fingerprint or face while they sleep. A separate, quantified finding on coerced access sits alongside it: a 2024 peer-reviewed study in the British Journal of Social Work, surveying frontline domestic-abuse practitioners, found that ninety-eight percent had worked with clients who experienced some form of technology-based coercive control, and documented the specific tactic of partners forcing or coercing disclosure of device passwords through manipulation or threat — and becoming more abusive when a victim subsequently tried to change those security settings.4 If a device unlocks via a sleeping partner’s fingerprint and a password manager app on that device is still authenticated from an earlier session, the vault’s protection was never actually tested. Access was obtained one layer below it entirely.

A different failure mode sits at the vendor level: the 2022 LastPass breach, in which the company initially told users no vaults had been accessed, then disclosed two months later that twenty-five to thirty million encrypted vault backups had, in fact, been stolen. Offline cracking of weak master passwords was later confirmed, and by the end of 2025 investigators had traced more than four hundred thirty-eight million dollars in cryptocurrency theft to this single breach, including a theft from a Ripple co-founder worth about a hundred twelve million dollars when it was taken in January 2024, later valued at roughly a hundred fifty million as the stolen cryptocurrency’s price rose.5 It establishes that concentrating credentials in one place creates real concentration risk — but it is a criminal, financial case with no interpersonal-coercive-control dimension of its own. The mechanisms that do connect directly to coercive control are the quieter ones: a keylogger running silently, or a fingerprint pressed to a sleeping face.


Everything a mobile stalkerware keylogger can do, a browser extension can do as well, with meaningfully less friction. The permission “read and change all your data on all websites” is an entirely ordinary, disclosed browser permission — even Google’s own Translate extension requests it, because translating a page requires reading its content. In a malicious extension, the identical permission enables recording every password typed, stealing session cookies to take over an account without ever defeating a password at all, reading or screenshotting any page including banking activity, and logging every URL visited — a complete browsing- history exfiltration. Security researchers have documented more than 3.2 million users exposed to exactly this behavior through tracked malicious extension campaigns,6 and the comparison to mobile stalkerware is not flattering to the browser: installing mSpy or FlexiSPY on a phone requires an Accessibility Service permission grant, a distinct and sometimes noticeable step. Installing a browser extension is comparatively frictionless, and the same “read all data” permission a legitimate translator or ad-blocker needs is indistinguishable, at the moment of granting it, from what a surveillance tool needs.

The scale this can reach was demonstrated by DataSpii, documented by the security researcher Sam Jadali in 2019. At least eight browser extensions — tab managers, screenshot tools, and similar ordinary-seeming utilities — harvested the URL, title, and often the embedded hyperlinks of every page their users visited, and sold the aggregated browsing histories through a paid data service marketed, without apparent irony, as “God mode for the Internet.” The confirmed reach extended to as many as four million users, including staff at more than fifty Fortune 500 companies, and for ordinary users exposed tax returns, private photos and videos, and medical information7 — a direct, documented instance of exactly the “watch and search history reveals the most sensitive facts of someone’s life” claim this book’s profiling chapter makes in the abstract, here shown actually happening at multi-million-user scale through extensions nobody suspected.

Trust in an already-installed extension does not stay put once granted. It can be undone in at least two distinct ways. The Great Suspender, a hugely popular and long-trusted tab- management extension, was quietly sold to an unknown third party in 2021, which promptly shipped an update adding remote code execution and ad fraud; Google forcibly disabled it for every existing user once this was discovered.8 No technical breach was required — only a change of ownership nobody using the extension was informed of. A more alarming mechanism struck the security company Cyberhaven at the end of 2024: a phishing email disguised as a Chrome Web Store policy notice tricked an employee into authorizing a malicious app, giving attackers publishing access to Cyberhaven’s own real, previously trustworthy extension. Attackers pushed a malicious update that exfiltrated cookies and authenticated sessions, and it auto-propagated to roughly four hundred thousand users within the incident window with no install action required from anyone at all — the browser’s own auto-update mechanism did the work. The same campaign compromised more than thirty other extensions, affecting over 2.6 million users combined.9


Cloud accounts carry their own version of this same lesson, and its strongest documented anchor involves not a hack but a feature working precisely as designed. Location-sharing and “Find My” services have accumulated the clearest evidentiary record in this chapter, with real convictions attached. Cornell Tech’s Clinic to End Tech Abuse reports that among the fifteen to thirty victims it assists every month, find-my-device apps used as a remote monitoring tool are the single most common issue raised. A National Network to End Domestic Violence survey found that half of victim-service providers report offenders using phone apps to stalk survivors, and forty-one percent specifically report GPS tracking.10 Callum Henderson, in the UK, was convicted in 2019 of harassing a woman he had met on a dating app by following her movements through Find My iPhone.11 Brooks Laughlin, a Washington state police officer, was convicted of felony stalking and harassment for tracking a former partner through a phone GPS app and video surveillance.12 A juvenile trafficking victim told investigators her trafficker used Find My iPhone to monitor multiple women being trafficked along a specific stretch of road.13 And in one especially severe documented case, spanning a decade of abuse, a man who had taken control of a victim’s Facebook and Apple accounts used Find My iPhone to locate her at a restaurant, took her to a hotel, and sexually assaulted her, filming the attack.14 Apple’s own product response reads as independent confirmation that the company regards this as a real and serious problem: iOS 16 shipped, in 2022, a feature called Safety Check built specifically to let someone quickly review and cut off everyone they’ve shared location, photos, or account access with, explicitly designed for people leaving an abusive relationship.15

A related but distinct pattern involves a shared Apple ID or family- sharing arrangement set up, often years earlier, purely for convenience — shared purchases, a shared photo library. Family-law practitioners consistently report that this shared credential grants unrestricted access to most information on both people’s devices, and that access persists after separation unless someone actively unwinds it — surfacing, in practice, as an ex-partner reading messages about the divorce itself, the children’s schedules, or privileged communications with a divorce attorney.16 It is the identical ownership-model problem examined earlier, one layer up.

The same category of account can fail in two further, distinct ways worth naming precisely. Mat Honan, a Wired senior writer, documented in 2012 how an attacker exploited a gap between Amazon’s and Apple’s account-recovery processes. The attacker convinced Amazon to add a fake credit card over the phone, then used that fake card as “verification” to add a new email address to the account — an email address that Apple then accepted as sufficient to grant iCloud recovery access, no password or technical hack required at any point. Within about an hour, eight years of his Gmail history had been deleted and his iPhone, iPad, and laptop were remotely wiped through the very same Find My feature this chapter has already documented protecting stalking victims — here weaponized instead against the account’s own owner.17 And in 2014, Apple confirmed that a wave of leaked celebrity photographs, including images of Jennifer Lawrence and more than a hundred others, resulted from a targeted phishing campaign rather than any platform breach: Ryan Collins, sentenced to eighteen months in federal prison, had sent emails impersonating Apple and Google to harvest login credentials from more than a hundred victims and download their full iCloud photo backups.18 It remains the clearest documented case of cloud-stored personal photographs becoming extortion and reputational-destruction material at scale, with a federal conviction attached.

A final, quieter layer sits beneath all of this, and it comes with an honest caveat. Third-party apps granted scoped API access to a cloud account — through what’s called OAuth — operate on a permission layer technically separate from the account password entirely. Google’s own support documentation confirms that automatic token revocation on a password change is scoped only to mail-related tokens; apps installed through the Workspace Marketplace or built with Apps Script explicitly keep their access even after the password changes.19 A forgotten backup tool, automation script, or photo-sync utility, set up once years earlier, can retain its full granted access indefinitely, unless someone specifically finds and revokes it in the account’s connected-apps settings — a genuinely different species of the ownership problem this chapter has traced throughout, because this permission was never tied to the password in the first place. Google’s own 2018 review of third-party developer access, launched in the wake of the broader Cambridge Analytica reckoning, tightened exactly this gap for Google Drive, moving from blanket account access to a per-file consent model — the company does not overhaul its developer policy company-wide unless it has concluded the prior model was a real, exploitable risk.20 And Dropbox’s disclosed 2016 breach shows the identical lesson can strike a provider’s own internal systems: an employee’s password, reused from an unrelated breach at a different company, was used to access an internal document containing user email addresses, and the resulting dataset — covering more than sixty million accounts — surfaced for sale on a dark- web forum four years after the original incident.21 The honest limit: the technical mechanism here is as solidly documented as any in this book, but no named case of a partner or ex-partner specifically exploiting a forgotten connected app for post-separation surveillance was found in this research. The architecture is proven. The specific interpersonal instance, as of this book’s research, is not.

Pulled back to the whole chapter, though, a copied key never copies cleanly. Account-recovery emails and phone numbers change on a dated log; new-device logins are timestamped; every third-party app still holding access sits listed in a connected-apps panel a person can actually open; location shares can be enumerated and revoked. Apple built Safety Check into iOS 16 for exactly this audit.

Notes

  1. A dedicated password manager (1Password, Bitwarden) encrypts its vault behind a separate master password the OS/browser session never has; browser-native password storage (e.g., Chrome on Windows) gates the on-screen reveal only behind the OS account credential (Windows Hello / the account password) — no separate secret — so it offers no protection against anyone who knows that credential or who runs extraction tooling under the logged-in account. https://www.howtogeek.com/please-stop-using-your-browsers-built-in-password-manager/↑

  2. Free, publicly distributed Windows utilities exist that scan every installed browser on a machine and export all locally saved passwords in plaintext to a file, requiring no technical skill; the specific product name and download link are omitted here deliberately. The defensive takeaway is to use a dedicated password manager secured by a separate master password rather than the browser’s built-in store.↑

  3. Commercial stalkerware mSpy and FlexiSPY, sold as “parental monitoring” or “employee tracking,” include keyloggers that capture passwords as typed into login fields; their documented use predominantly in intimate-partner surveillance is established in Citizen Lab’s The Predator in Your Pocket: A Multidisciplinary Assessment of the Stalkerware Application Industry (2019), cited more fully in Chapter 6.↑

  4. Brookfield, K., Fyson, R., & Goulden, M., “Technology-Facilitated Domestic Abuse: An under-Recognised Safeguarding Issue?” British Journal of Social Work 54:1 (2024): 419–436 — a literature review arguing that technology-facilitated domestic abuse is under-recognised in social work, noting that 72% of service users at one specialist service had been subjected to tech-enabled abuse and reporting a 97% rise in complex cases involving it, and documenting partners forcing or coercing disclosure of device passwords, becoming more abusive when victims tried to change security settings afterward. https://academic.oup.com/bjsw/article/54/1/419/7272719↑

  5. The 2022 LastPass breach: the company initially stated (Sept. 15, 2022) no vaults were accessed, then disclosed (Nov. 30, 2022) that 25–30 million encrypted vault backups had been stolen. Offline cracking of weak master passwords was confirmed by Krebs on Security in Sept. 2023; by December 2025, TRM Labs had traced roughly $35M in laundered proceeds to this breach (describing that as likely only a fraction of the total), and a US Department of Justice forfeiture complaint (March 2025) tied the single largest theft — about 283 million XRP (~$150M on January 30, 2024) belonging to Ripple co-founder Chris Larsen — to the same breach, after his private keys were found stored in LastPass. https://thehackernews.com/2025/12/lastpass-2022-breach-led-to-years-long.html · https://www.forbes.com/sites/thomasbrewster/2025/03/07/lastpass-hackers-stole-150-million-in-crypto-from-single-person-now-worth-715-million/↑

  6. The “read and change all your data on all websites” browser extension permission — an ordinary, disclosed permission even Google’s own Translate extension requests — can, in a malicious extension, enable password capture, session-cookie theft, page reading/screenshotting, and full browsing-history logging. Security researchers have documented large-scale malicious-extension campaigns exploiting exactly this permission. https://www.island.io/browser-extension-security/browser-extension-security-defending-against-permissions-awareness-gaps↑

  7. DataSpii, documented by security researcher Sam Jadali (2019): at least eight browser extensions harvested URLs, titles, and hyperlinks of visited pages and sold aggregated browsing histories through a service called Nacho Analytics, marketed as “God mode for the Internet.” Confirmed reach extended to as many as 4 million users, including staff at 50+ Fortune 500 companies, exposing tax returns, private photos/videos, and medical information for ordinary users. Sam Jadali, “DataSpii: The catastrophic data leak via browser extensions” (securitywithsam.com, 2019), reported by Ars Technica (July 2019).↑

  8. The Great Suspender, a popular tab-management extension, was sold to an unknown third party in June 2020, which shipped an update adding remote code execution and ad fraud; Google forcibly disabled it for all users once discovered. https://thehackernews.com/2021/02/warning-hugely-popular-great-suspender.html↑

  9. A phishing email disguised as a Chrome Web Store policy notice tricked a Cyberhaven employee (December 2024) into authorizing a malicious app, giving attackers publishing access to Cyberhaven’s own extension; a malicious update exfiltrating cookies and sessions auto-propagated to Cyberhaven’s users, part of a broader campaign that compromised dozens of other browser extensions affecting millions of users combined. https://www.securityweek.com/several-chrome-extensions-compromised-in-supply-chain-attack/↑

  10. Cornell Tech’s Clinic to End Tech Abuse reports find-my-device apps as the single most common issue among the 15–30 victims it assists monthly; a National Network to End Domestic Violence survey found 50% of victim-service providers report offenders using phone apps to stalk survivors, and 41% specifically report GPS tracking. Per Forbes’ 2023 reporting aggregating this data. https://www.forbes.com/sites/thomasbrewster/2023/10/03/apple-find-my-iphone-abused-by-stalkers-and-traffickers/↑

  11. Callum Henderson (UK), convicted in 2019 of harassing a woman he met on a dating app by following her movements through Find My iPhone. Per Thomas Brewster, “Apple Find My iPhone Abused By Stalkers And Traffickers,” Forbes, October 3, 2023 (same source as [^10]). https://www.forbes.com/sites/thomasbrewster/2023/10/03/apple-find-my-iphone-abused-by-stalkers-and-traffickers/↑

  12. Brooks Owen Laughlin, a Bellingham, Washington police corporal from Everson, was arrested in March 2018 and convicted by jury of felony stalking, felony harassment, and multiple counts of assault in a sustained abuse campaign against a woman known to him; per charging documents he isolated and tracked her whereabouts through a phone GPS app and monitored her with video surveillance (not, on the available public record, Find My iPhone specifically). Conviction affirmed in part, State v. Laughlin, Wash. Ct. App. Div. I (2020). https://www.kiro7.com/news/north-sound-news/bellingham-officer-charged-with-repeatedly-abusing-woman-1/728170727/; https://www.heraldnet.com/northwest/bellingham-cop-arrested-for-second-time-in-two-months/↑

  13. A juvenile trafficking victim told investigators her trafficker used Find My iPhone to monitor multiple women being trafficked along a specific stretch of road. Per Thomas Brewster, “Apple Find My iPhone Abused By Stalkers And Traffickers,” Forbes, October 3, 2023 (same source as [^10]).↑

  14. A man who took control of a victim’s Facebook and Apple accounts over a decade of abuse used Find My iPhone to locate her at a restaurant, took her to a hotel, and sexually assaulted her, filming the attack. Per Thomas Brewster, “Apple Find My iPhone Abused By Stalkers And Traffickers,” Forbes, October 3, 2023 (same source as [^10]) — reported there under the pseudonyms “Johanne” (victim) and “John” (perpetrator), the perpetrator arrested in Virginia in April 2023.↑

  15. Apple’s iOS 16 (2022) shipped “Safety Check,” a feature letting someone quickly review and cut off everyone they’ve shared location, photos, or account access with, built explicitly for people leaving an abusive relationship. https://techcrunch.com/2022/06/06/apple-safety-check/↑

  16. Family-law practitioners report that a shared Apple ID or family-sharing arrangement grants unrestricted access to most information on both people’s devices, persisting after separation unless actively unwound — surfacing as an ex-partner reading divorce-related messages, children’s schedules, or privileged attorney communications. https://www.gislason.com/why-am-i-receiving-my-ex-spouses-text-messages-divorce-and-shared-apple-ids/↑

  17. Mat Honan, a Wired senior writer, documented in 2012 how an attacker exploited a gap between Amazon’s and Apple’s account-recovery processes — adding a fake credit card to his Amazon account, then using it as “verification” to add a new email address that Apple accepted for iCloud recovery access — leading to deletion of eight years of his Gmail and remote wipe of his iPhone, iPad, and laptop via Find My. Mat Honan, “How Apple and Amazon Security Flaws Led to My Epic Hacking,” Wired, August 6, 2012. https://www.wired.com/2012/08/apple-amazon-mat-honan-hacking/↑

  18. The 2014 celebrity photo leak (“Celebgate”): Apple confirmed a targeted phishing campaign, not a platform breach, was responsible. Ryan Collins was sentenced to 18 months in federal prison for sending emails impersonating Apple and Google to harvest login credentials from 100+ victims, including Jennifer Lawrence, and downloading their full iCloud photo backups. https://www.justice.gov/usao-cdca/pr/pennsylvania-man-sentenced-today-18-months-federal-prison-hacking-apple-and-google-e↑

  19. Google’s own support documentation confirms automatic OAuth token revocation on a password change is scoped only to mail-related tokens; apps installed through the Workspace Marketplace or built with Apps Script explicitly keep their access after a password change. https://support.google.com/a/answer/6328616?hl=en↑

  20. Google’s Project Strobe (announced October 2018), a company-wide review of third-party developer access launched in the wake of the Facebook/Cambridge Analytica scandal, tightened Google Drive from blanket account access to a per-file consent model. https://workspace.google.com/blog/product-announcements/enhancing-security-controls-for-google-drive-third-party-apps↑

  21. Dropbox’s breach (occurred 2012, fully disclosed 2016): an employee’s password, reused from an unrelated breach, was used to access an internal document containing user email addresses; the resulting dataset, covering 60+ million accounts, surfaced for sale on a dark-web forum in 2016. https://techcrunch.com/2016/08/30/dropbox-employees-password-reuse-led-to-theft-of-60m-user-credentials/↑

From The Machinery of Compliance by Willow Whitman · edition 1.0.2, · free under CC BY-NC-ND 4.0 · corrections

The whole book

Forty-nine chapters, free in every sense

Read it in the browser, or take the EPUB or PDF and keep it. No sign-up, no tracking, nothing to pay.

Read online Download EPUB or PDF