Microsoft Edge stores all passwords in memory in clear text, even when unused
1–10 of 243 posts
Re: Microsoft Edge stores all passwords in memory in clear text, even when unused
#2Re: Microsoft Edge stores all passwords in memory in clear text, even when unused
#3Re: Microsoft Edge stores all passwords in memory in clear text, even when unused
#4> If an attacker gains administrative access on a terminal server, they can access the memory of all logged‑on user processes.
If an attacker has administrative access, they can also attach a debugger to every chrome process and force it to decrypt all the passwords. The only difference this really makes is in coldboot attacks, but even then it's still not clear whether it makes the attacker's job slightly easier, or allows an attack that's otherwise not possible.
[1] https://devblogs.microsoft.com/oldnewthing/20060508-22/?p=31...
Re: Microsoft Edge stores all passwords in memory in clear text, even when unused
#5https://support.microsoft.com/en-us/topic/export-passwords-i...
Re: Microsoft Edge stores all passwords in memory in clear text, even when unused
#6To be fair, 'loads into memory' and 'stores' are not the same thing.
Re: Microsoft Edge stores all passwords in memory in clear text, even when unused
#7Re: Microsoft Edge stores all passwords in memory in clear text, even when unused
#8To be fair, 'loads into memory' and 'stores' are not the same thing.
The headline here says "stores in memory", which sounds pretty much identical to me. Can you elaborate on what you consider the difference between "loading" and "storing" into memory?
Re: Microsoft Edge stores all passwords in memory in clear text, even when unused
#9Re: Microsoft Edge stores all passwords in memory in clear text, even when unused
#10Please use a dedicated password manager, instead of a browser-based one. KeePass is likely the best going forward.