Earlier quoted context omitted.
Absolutely wrong. Are we writing the same code here? Page guards are for all userspace access. (In fact, I think kernel space might also trigger them, but can be circumvented. PS: I'm being polite :) Kernel space 100% triggers them, but can be cleverly circumvented by fucking with logs.)
Could you not use VirtualProtectEx to strip PAGE_GUARD? Even so, none if these methods offer protection, at best you can get some detection, but that doesn't matter when they got your passwords already.
Microsoft Edge stores all passwords in memory in clear text, even when unused
201–210 of 243 posts
Re: Microsoft Edge stores all passwords in memory in clear text, even when unused
#202Re: Microsoft Edge stores all passwords in memory in clear text, even when unused
#203For reference, this is how Google says Chrome stores passwords encrypted in memory and uses an elevated service to prevent other processes from impersonating Chrome and gaining access to the plain text passwords: https://security.googleblog.com/2024/07/improving-security-o...
That appears to be storage at rest (on disk), rather than in memory.
Re: Microsoft Edge stores all passwords in memory in clear text, even when unused
#204Earlier quoted context omitted.
I travel a lot. By train, plane, and car. I also use passkeys when possible. I have multiple Yubikeys, stored in different locations. I also have a password manager, where I typically keep track of which logins aren’t yet backed up across physical tokens. It takes a bit of effort, but it’s not impossible. Yes, it means that in the event of catastrophic failure I might not be able to log in to some services until I ge…
>Yes, it means that in the event of catastrophic failure I might not be able to log in to some services until I get to one of the backups. I haven’t been able to imagine a scenario where that would be truly problematic. No need to imagine! Remove all passkeys from your phone and laptop, then go somewhere overseas without any of those Yubikeys. Have fun enjoy a "not truly problematic" scenario of getting your Yibikeys…
I don't have any passkeys on my phone or laptop. They're all on the Yubikeys.
I don't really see a difference with (some) password managers, though. If you use one of the keepasses, and you lose access to the file, you're in the same situation right?
And yeah, you're right, there is a risk of inconvenience. I'm not debating that. I just choose to organise my life in such a way that it is just an inconvenience.
Re: Microsoft Edge stores all passwords in memory in clear text, even when unused
#205Earlier quoted context omitted.
That doesn't help if my machine (with only a few USB ports) gets stolen/lost with the token in it. It doesn't help if some of my devices only have USB-C and some only have USB-A. It's absolutely more annoying than letting my password manager fill things in or typing in a 6 digit code from my authenticator app.
Get a better password manager? Most store passkeys.
Re: Microsoft Edge stores all passwords in memory in clear text, even when unused
#206Earlier quoted context omitted.
I recall chrome used to let you reveal passwords with a simple button press in the UI. I think their conclusion at the time was if an attacker had local access there was no point in pretending they were hidden.
I still found it insane to display passwords that easily. Sometimes I give brief access to my PC to friends, family, acquaintances, or even colleagues, and they shouldn't be able to see my passwords with a simple button. It's like leaving your bike out unlocked, because someone with the right tools can break the locks anyway.
Not to strain the analogy, but it's more like not locking your bike when it's in your locked apartment (the apartment being your computer). The thought being that if someone puts the time and effort into breaking into your apartment, a bike lock isn't going to do anything to stop them.
Re: Microsoft Edge stores all passwords in memory in clear text, even when unused
#207Earlier quoted context omitted.
This makes me miss running Qubes a few years ago, and keeping BitWarden in a separate VM from everything else. I've never felt as secure as when I had that setup.
Why did you stop?
My personal computer is too gaming-focused to be a good candidate for Qubes.
Re: Microsoft Edge stores all passwords in memory in clear text, even when unused
#208Earlier quoted context omitted.
Look, Ihate Microsoft too but Edge is just Chrome with a different skin, so they'd have to have gone out of their way (and spent money paying engineers) to make Edge less secure than Chrome/ium.
The whole point of them using chromium shows how little they care. The old edge wasn't used much no but that wasn't due to its engine. Most people don't even know what a browser engine is. They just didn't want to bother making a browser. But they want to benefit from the marketing advantages of having a browser so now they just lift along with chrome.
I think they do care, but they care about relevance, not browser monoculture. Doesn't matter how good Trident was, no one was ever going to use it. Even Firefox is barely hanging on, and the only reason Safari is still somewhat relevant is because it's the only choice on iOS.
And my relevance I mean their bread and butter, enterprise, not consumers. Edge is what lets MS give enterprise IT departments maximum control without the grumbling of "we'd rather have Chrome" from the end users.
Re: Microsoft Edge stores all passwords in memory in clear text, even when unused
#209Earlier quoted context omitted.
The subject here is literally websites trying to push passkeys on users. That is who is asking us to. About every week now Amazon tries to trick me into creating a passkey. It doesn't even ask, it just goes ahead and triggers my browser passkey creation mechanism without my consent. PayPal recently tried to force me to create one too and I had to kill and restart the app because that was the only way to skip it. I'll…
We have now gone from having to “redo everything” to being asked to switch to a passkey by a grand total of one website. I’ll be honest I’ve heard a lot of griping about passkeys but I have gone out of my way to switch over to them and have had precisely zero issues over the dozens of sites that I’ve bothered to make the switch on. Login flow is simpler and doesn’t rely on a browser extension guessing at login fields…
Me giving an example of one major website (actually, I gave two) is all that is needed to disprove your claim. I could provide plenty more examples of major websites asking me to, but I don't need to. I could provide plenty of examples of people telling people to "redo everything" with passkeys, but your own comment is literally advocating the same thing...
Please don't mischaracterize the conversation that is plainly visible for all to see. Just accept that you tried to suggest that nobody is asking users to switch to passkeys, and you were wrong. It seems like your error is that you just haven't been seeing it personally, since you switched on your own before the nagging started, and so you weren't aware of it. Well, now you are.