Live data from Hacker News

Microsoft Edge stores all passwords in memory in clear text, even when unused

twitter.com

101–110 of 243 posts

Re: Microsoft Edge stores all passwords in memory in clear text, even when unused

#101
post #70

Earlier quoted context omitted.

>your hardware dies Or your backpack gets stolen. Oops. I swear, people who idolize passkey security must never travel anywhere. PS: "just have more devices with passkeys", they invariably say. Yeah right because people are made of money, everyone has the forethought, and a 2nd laptop in the US is a great asset when you're in Poland and can't login anywhere.

I've been avoiding passkeys but more and more websites are trying to push them, and one website I use now requires them. I've already got a password manager! I don't need to change everything again!

Your password manager almost certainly already has baked-in passkey support.

Re: Microsoft Edge stores all passwords in memory in clear text, even when unused

#102

Earlier quoted context omitted.

One more reason to use hardware-bound passkeys and not passwords.

True. But then your hardware dies, and you're locked out of every account you own. It is objectively good security, but has a ton of usability headaches yet to be really solved. I've seen orgs move to passkeys only, then offer reset-questions (e.g. city of first job, etc); because the Customer Service volume/workflow wasn't figured out.

>It is objectively good security, but has a ton of usability headaches yet to be really solved.

Thank you, then this is still true today?

Disappointing the rollout was botched (recall cross platform and password manager difficulties). Haven’t done research since but even with some new UIs and flows promoting passkeys in the past couple months, haven’t regained my trust either.

Re: Microsoft Edge stores all passwords in memory in clear text, even when unused

#103

Correct me if I am wrong but chrome is-at least was- keeping passwords as raw text in Windows too. I got friend's forgotten password from Chrome on 2021 version

Yeah it's been years but I remember seeing arguments with Google devs saying if someone had access to your local file system, you're already SOL.

Re: Microsoft Edge stores all passwords in memory in clear text, even when unused

#104

Earlier quoted context omitted.

> This comment feels like it's written by AI. Why exactly? I'm genuinely asking, because I feel like I get this a lot , and it is pretty frustrating.

I'm not the other commenter (and I believe you that it's not AI), but I'd guess it's mostly the first line: a short affirmation followed by "The problem is ...." feels like the sort of formula the LLMs love to use. (Not trying to imply that there's anything inherently wrong with it, of course.) While we're at it, I'm under the impression that the recent LLMs have also co-opted "genuinely", which I'll never forgive th…

Thanks for the explanation. Yeah, I use "genuinely" and "honestly" far too much; and often in odd places. It is a bad habit.

As to that comment's tone, my entire comment history is visible going back years. I'd invite people to peruse it.

Re: Microsoft Edge stores all passwords in memory in clear text, even when unused

#105
post #22

Earlier quoted context omitted.

Security isn't black and white. If i leave a post-it note of my logins on my monitor, that's definitely less safe than in a unlocked drawer, and so on.

If I leave a post-it note of passwords on my monitor inside a vault to which only I have access, it’s not a big deal. That’s the point of the “airtight hatch” metaphor.

I think we've moved away from the secure perimeter thinking and towards defense in depth - if that list of passwords helps you get somewhere other than the vault, removing the post-it improves security. Vaults get infiltrated all the time - and often in partial ways like being able to see into the vault but not reach in.

Re: Microsoft Edge stores all passwords in memory in clear text, even when unused

#106
post #70

Earlier quoted context omitted.

True. But then your hardware dies, and you're locked out of every account you own. It is objectively good security, but has a ton of usability headaches yet to be really solved. I've seen orgs move to passkeys only, then offer reset-questions (e.g. city of first job, etc); because the Customer Service volume/workflow wasn't figured out.

>your hardware dies Or your backpack gets stolen. Oops. I swear, people who idolize passkey security must never travel anywhere. PS: "just have more devices with passkeys", they invariably say. Yeah right because people are made of money, everyone has the forethought, and a 2nd laptop in the US is a great asset when you're in Poland and can't login anywhere.

>"just have more devices with passkeys"

Confirms that strategy then

For people who only use passwords having an extra device can help too. Google does not necessarily permit a login with a backup code, so to me it seems ideal to grab a spare phone, log into important accounts, and store it with a trusted party/friend.

It could be very difficult to login to an account like Gmail from overseas in the event of PC+phone[+hardware key] theft. Maybe no big deal if you can port your number to a new phone right away. Or maybe the trusted friend can help (unless Google still finds the login suspicious after all, no idea there)

Re: Microsoft Edge stores all passwords in memory in clear text, even when unused

#108

Earlier quoted context omitted.

I've been avoiding passkeys but more and more websites are trying to push them, and one website I use now requires them. I've already got a password manager! I don't need to change everything again!

Your password manager almost certainly already has baked-in passkey support.

It does, but what's your point? Why should I redo everything?

Re: Microsoft Edge stores all passwords in memory in clear text, even when unused

#109
post #59

Earlier quoted context omitted.

This is accurate as far as page protection goes. The problem is the largest threat model. If Process A and Process B are running in the same user context on a desktop OS, PAGE_NOACCESS is not a strong boundary by itself. Process B may be able to obtain PROCESS_VM_OPERATION/PROCESS_VM_READ, change the page protection with VirtualProtectEx, inject code that calls VirtualProtect inside Process A, load a DLL, attach as a…

This comment feels like it's written by AI. Anyway, PAGE_GUARD helps you get around VirtualProtectEx, which is a very common way of detecting userspace cheats.

Guard pages are one-shot exceptions used for growing the stack.

Re: Microsoft Edge stores all passwords in memory in clear text, even when unused

#110
post #4

This feels like a case of "It rather involved being on the other side of this airtight hatchway"[1]. If you can read arbitrary process memory, you're probably also in a position to just dump out the passwords by pretending to be the user in question. > If an attacker gains administrative access on a terminal server, they can access the memory of all logged‑on user processes. If an attacker has administrative access,…

Agreed. I keep seeing "high priority" "vulns" that require so much system access to actually exploit that they become pointless. If an untrusted process can read your memory or run as an administrator you have already lost.

It honestly feels like more and more "security" people and businesses have less interest in actually securing systems and more in marketing themselves and their business hence the tendency to make every niche attack into a five alarm fire.

Post reply on HN