Please use a dedicated password manager, instead of a browser-based one. KeePass is likely the best going forward.
EDIT: Yes, he claimed that for online password managers, not keepass. I thought the argument was about password managers in general.
11–20 of 243 posts
Please use a dedicated password manager, instead of a browser-based one. KeePass is likely the best going forward.
EDIT: Yes, he claimed that for online password managers, not keepass. I thought the argument was about password managers in general.
This feels like a case of "It rather involved being on the other side of this airtight hatchway"[1]. If you can read arbitrary process memory, you're probably also in a position to just dump out the passwords by pretending to be the user in question. > If an attacker gains administrative access on a terminal server, they can access the memory of all logged‑on user processes. If an attacker has administrative access,…
Does this tool access an Edge instance running on the same machine? Couldn't you then just simply export all saved passwords anyway? https://support.microsoft.com/en-us/topic/export-passwords-i...
Please use a dedicated password manager, instead of a browser-based one. KeePass is likely the best going forward.
@taviso had claimed the exact opposite: https://lock.cmpxchg8b.com/passmgrs.html EDIT: Yes, he claimed that for online password managers, not keepass. I thought the argument was about password managers in general.
> Good examples of simple and safe password managers are keepass and keepassx
Please use a dedicated password manager, instead of a browser-based one. KeePass is likely the best going forward.
The fix isn't Edge Vs. Chrome. Vs KeePass Vs. Bitwarden, it is "How do I have my passwords exist in a different execution context than [evil process able to read all memory]?"
Android and iOS have an "answer" to this problem. Desktop OSs having all processes running side by side in the user's execution context, do not. It is only as secure as the least secure process running.
Please use a dedicated password manager, instead of a browser-based one. KeePass is likely the best going forward.
Out of curiosity, why KeePass versus Bitwarden? I've been using Bitwarden for years, but if there's a specific reason I should be using KeePass instead, I'm open to changing.
Please use a dedicated password manager, instead of a browser-based one. KeePass is likely the best going forward.
@taviso had claimed the exact opposite: https://lock.cmpxchg8b.com/passmgrs.html EDIT: Yes, he claimed that for online password managers, not keepass. I thought the argument was about password managers in general.