Lemmy at mair.io
  • Communities
  • Create Post
  • Create Community
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
ItWasntMe@discuss.online to Technology@lemmy.worldEnglish · 11 days ago

Microsoft Edge loads your passwords into memory in plaintext, but Microsoft says not to worry

www.windowscentral.com

external-link
message-square
110
fedilink
  • cross-posted to:
  • technology@lemmy.zip
1
external-link

Microsoft Edge loads your passwords into memory in plaintext, but Microsoft says not to worry

www.windowscentral.com

ItWasntMe@discuss.online to Technology@lemmy.worldEnglish · 11 days ago
message-square
110
fedilink
  • cross-posted to:
  • technology@lemmy.zip
A security researcher has discovered that Microsoft Edge will load all your stored passwords into memory in plaintext at startup, making it easy for malware to scrape those passwords.
alert-triangle
You must log in or register to comment.
  • zerofk@lemmy.zip
    link
    fedilink
    English
    arrow-up
    0
    ·
    11 days ago

    Access to browser data as described in the reported scenario would require the device to already be compromised.

    Yes you can open our safe with just a good yank but if a thief can do that they’re already in your house.

    • MonkderVierte@lemmy.zip
      link
      fedilink
      English
      arrow-up
      0
      ·
      11 days ago

      If the thief is already in your house, he can also eat your meal and steal your furniture.

  • quantumvoid0@programming.dev
    link
    fedilink
    English
    arrow-up
    0
    ·
    11 days ago

    does this company intentionally want users to stop using it? cuz day by day either theres a new windows bug or just shittier softwares

    • Senseless@feddit.org
      link
      fedilink
      English
      arrow-up
      0
      ·
      11 days ago

      Not to worry, the next update will fix it. (And make 12 others things worse. Also it will make your printer stop working. Again.)

    • CileTheSane@lemmy.ca
      link
      fedilink
      English
      arrow-up
      0
      ·
      11 days ago

      The AI tells them this is fine, and we are not to question the AI.

    • smeenz@lemmy.nz
      link
      fedilink
      English
      arrow-up
      0
      ·
      11 days ago

      I think it’s more than they just don’t care. Microsoft cornered the business world decades ago because they’ve got wot C-levels crave…or something. End users have no say in it.

  • Reygle@lemmy.world
    link
    fedilink
    English
    arrow-up
    0
    ·
    11 days ago

    HOLY @#%^ WHAT IN THE @#%^ DO THEY MEAN “NOT TO WORRY”???

    • DreadPirateSnuggles@lemmy.ca
      link
      fedilink
      English
      arrow-up
      0
      ·
      11 days ago

      They mean that it won’t affect them.

    • XLE@piefed.social
      link
      fedilink
      English
      arrow-up
      0
      ·
      11 days ago

      Well, hold on now, maybe Microsoft has a reasonable explanation for how they actually do secure their passwords…

      This is an expected feature of the application.

      … Never mind.

      • JohnAnthony@lemmy.dbzer0.com
        link
        fedilink
        English
        arrow-up
        0
        ·
        11 days ago

        Design choices in this area involve balancing performance, usability, and security

        Nothing to do with usability since decrypting your passwords one by one is perfectly fine. So they are saying this is about performance ? Holy fuck…

        • Albbi@piefed.ca
          link
          fedilink
          English
          arrow-up
          0
          ·
          11 days ago

          They’re just doing what Copilot told them to!

  • goatinspace@feddit.org
    link
    fedilink
    English
    arrow-up
    0
    ·
    11 days ago

  • baronvonj@piefed.social
    link
    fedilink
    English
    arrow-up
    0
    ·
    11 days ago

    Microsoft SSH agent persistently stores your unencrypted private keys in the registry. They’re still there unlocked and usable after you reboot.

    https://github.com/PowerShell/Win32-OpenSSH/issues/1487

    • mbp@slrpnk.net
      link
      fedilink
      English
      arrow-up
      0
      ·
      11 days ago

      God, the final comment in that thread makes my blood boil.

      • rbos@lemmy.ca
        link
        fedilink
        English
        arrow-up
        0
        ·
        10 days ago

        That is infuriating. Leaving those keys available to the user means that worms can later use you to compromise additional machines. It turns a local problem into a much bigger one. There’s a recursive script out there that automatically scans your ssh files and attempts to access all hosts in your history…name escapes me at the moment.

    • unemployedclaquer@sopuli.xyz
      link
      fedilink
      English
      arrow-up
      0
      ·
      11 days ago

      Right there in the name, it says Secure She’ll Hades

  • HotsauceHurricane@lemmy.world
    link
    fedilink
    English
    arrow-up
    0
    ·
    11 days ago

    Wow, that’s bad.

  • MadMadBunny@lemmy.ca
    link
    fedilink
    English
    arrow-up
    0
    ·
    11 days ago

    Yeah, that’s what she said…

  • SCmSTR@lemmy.blahaj.zone
    link
    fedilink
    English
    arrow-up
    0
    ·
    11 days ago

    And this is why you don’t give microslop anything

  • GainGround@kopitalk.net
    link
    fedilink
    English
    arrow-up
    0
    ·
    11 days ago

    Our lives are in the hands of morons. What the fuck.

    • 1hitsong@lemmy.ml
      link
      fedilink
      English
      arrow-up
      0
      ·
      11 days ago

      Our lives are in the hands of product managers driving programming decisions.

      Oh, sorry. I just realized I repeated what you said.

    • Teppa@lemmy.world
      link
      fedilink
      English
      arrow-up
      0
      ·
      11 days ago

      Theres an AI for that.

  • KyuubiNoKitsune@lemmy.blahaj.zone
    link
    fedilink
    English
    arrow-up
    0
    ·
    11 days ago

    What is even the point of the DPAPI?

    • Uairhahs@lemmy.world
      link
      fedilink
      English
      arrow-up
      0
      ·
      11 days ago

      DPAPI no black, he’s Dominican.

      • FosterMolasses@leminal.space
        link
        fedilink
        English
        arrow-up
        0
        ·
        11 days ago

        If you consider Haitians black, so are Dominicans.

        Source: am Dominican.

  • unemployedclaquer@sopuli.xyz
    link
    fedilink
    English
    arrow-up
    0
    ·
    11 days ago

    Moms insists on pen an paper! Omg!

  • Quazatron@lemmy.world
    link
    fedilink
    English
    arrow-up
    0
    ·
    11 days ago

    Microsoft - So secure we ROT13 encode everything… TWICE!

    • LeFrog@discuss.tchncs.de
      link
      fedilink
      English
      arrow-up
      0
      ·
      11 days ago

      Ah yes, the good old ROT26 encryption. Some say its unbreakable

  • starik@lemmy.zip
    link
    fedilink
    English
    arrow-up
    0
    ·
    11 days ago

    If you don’t have anything to hide, what’s the worry?

    • quantumvoid0@programming.dev
      link
      fedilink
      English
      arrow-up
      0
      ·
      edit-2
      11 days ago

      arguing that you don’t care about the right to privacy because you have nothing to hide is no different than saying you don’t care about free speech because you have nothing to say. –edward snowden

      also in this case the thing ur hiding is ur freaking passwords

      • starik@lemmy.zip
        link
        fedilink
        English
        arrow-up
        0
        ·
        11 days ago

        It’s the height of narcissism to believe that everyone wants to get your passwords.

        • quantumvoid0@programming.dev
          link
          fedilink
          English
          arrow-up
          0
          ·
          11 days ago

  • SaharaMaleikuhm@feddit.org
    link
    fedilink
    English
    arrow-up
    0
    ·
    11 days ago

    I am not worried, cause I’m not dumb enough to use Edge or Windows for that matter.

  • AbsolutelyNotAVelociraptor@piefed.social
    link
    fedilink
    English
    arrow-up
    0
    ·
    11 days ago

    They say not to worry because they know nobody uses that dumpster fire of a browser so there’s no actual risk of your passwords being leaked since you’re not using it anyways.

    • unemployedclaquer@sopuli.xyz
      link
      fedilink
      English
      arrow-up
      0
      ·
      11 days ago

      Hey. Hey. I got some PS scripts

    • nodiratime@lemmy.world
      link
      fedilink
      English
      arrow-up
      0
      ·
      11 days ago

      Corporate has entered the chat.

    • dragonlover@lemmy.zip
      link
      fedilink
      English
      arrow-up
      0
      ·
      11 days ago

      Unless you’re like me and the websites you use for work require it and don’t work in literally any other browser (I have tried everything)

Technology@lemmy.world

technology@lemmy.world

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: !technology@lemmy.world

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


  • @L4s@lemmy.world
  • @autotldr@lemmings.world
  • @PipedLinkBot@feddit.rocks
  • @wikibot@lemmy.world
Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 643 users / day
  • 2.58K users / week
  • 5.04K users / month
  • 12.5K users / 6 months
  • 0 local subscribers
  • 84.7K subscribers
  • 3.94K Posts
  • 111K Comments
  • Modlog
  • mods:
  • L3s@lemmy.world
  • enu@lemmy.world
  • Technopagan@lemmy.world
  • L4sBot@lemmy.world
  • L3s@hackingne.ws
  • UI: unknown version
  • BE: 0.19.18
  • Modlog
  • Instances
  • Docs
  • Code
  • join-lemmy.org