background gif

Attacks · Credentials & humans

Keylogging

Captured input does not become lasting request authority. Bearings and ceremony fragments are one-shot — already spent by the time an observer could reuse them.

~6 min readRelated: Phishing

Opening

What the attacker wants

The keylogger wants recorded keystrokes, paste buffers, or ceremony input to work again later as a password-like credential. The conversion is capture-to-login: film the human, replay the string, own the session on another host. Keylogging is privacy-invasive even when it fails to mint lasting authority — deny conversion, do not romanticize malware.

How it works today

Passwords and reusable OTPs make keylogging pay because the typed string is the secret. Ambient estates put lasting value into every keypress. Malware, shoulder surfing, and shared terminals all convert surface input into lasting callers. Cognitive ceremonies move lasting value out of the keystream and into one-shot bearings.

Why it fails against one-shot proofs

Nothing typed has lasting value as a channel authorizer under one-shot bearings. Ceremony input burns with the request. An observer notebook of surface input does not yield a second authorization — the nonce is already spent. Keylogging still violates privacy; it fails as an ambient-credential mint. If a notebook of keystrokes cannot authorize a second call, the ambient password model has been replaced.

Read the dual plates as ambient success versus mechanism denial for keylogging: the surface plate shows why classical estates pay; the denial plate shows which ENI6MA check family stops the conversion without dumping an NDA attack-to-stage matrix. Claims below stay model-scoped.

Keylog captures the password

How to read: observer notebook left; replay-string ambient win right. Takeaway: typed input is a reusable secret.

Ambient keylog success is the password string that logs in again elsewhere.

Keylog captures spent work

How to read: password-reuse myths fail; bearings → burn → already spent. Takeaway: surface only; authority spent.

Spent bearings leave the notebook with surface only — already burned.

Scoped claims

Immune to keylogging.ValidatedNothing typed has lasting value; bearings are one-shot and already burned by the time an observer could reuse them.Holds under the reference architecture

Where it shows up

Watch it fail

Go deeper

Formal note

Keylogging immunity claims concern lasting channel authority, not the absence of endpoint malware.