There are some programs that take a "snapshot" of the process memory. Then we can diff it before and after typing the username (since I think - not sure though - that the auth file is downloaded and "executed" just before the user types his password).
I think I'll take a look at that in the next days.
I think I'll take a look at that in the next days.