What is a keylogger?
A keylogger records keystrokes and captures passwords at the moment you type them. A 32-character random password is captured as easily as a weak one. This is why keeping the device clean matters alongside choosing a strong password.
- Topic
- Attacks
- Reading time
- 1 min
- Reviewed
On this page
Why strength is irrelevant here
A keylogger does not guess. It reads. This is the same reason phishing beats strong passwords: both attacks capture the secret rather than compute it. The relevant defences are keeping the device clean, using autofill instead of typing, and adding a second factor so a captured password is not sufficient.
What limits the damage
Two-factor authentication limits some of the damage because a recorded password alone may not complete a login. Autofill reduces exposure because the password is never typed. If you suspect a device is compromised, change passwords from a different device. Otherwise the keylogger may capture the replacements too.
Sources
These primary references support the terminology and current security guidance used in this definition.
