<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Holy shit, Microsoft.]]></title><description><![CDATA[<p>Holy shit, Microsoft. Whoever made this decision should be fired. Into the Sun. </p><p></p><div class="card col-md-9 col-lg-6 position-relative link-preview p-0">



<a href="https://lemmy.world/post/46435614" title="Microsoft Edge loads all your saved passwords into memory in cleartext — even when you’re not using them; Microsoft will not fix, says the behavior is ">
<img src="https://lemmy.world/pictrs/image/0fd47927-ca3a-4d2c-b2e4-a25353786671.png" class="card-img-top not-responsive" style="max-height:15rem" alt="Link Preview Image" />
</a>











































<div class="card-body">
<h5 class="card-title">
<a href="https://lemmy.world/post/46435614">
Microsoft Edge loads all your saved passwords into memory in cleartext — even when you’re not using them; Microsoft will not fix, says the behavior is "by design" - Lemmy.World
</a>
</h5>
<p class="card-text line-clamp-3">Hacker News [https://news.ycombinator.com/item?id=48012735]. &gt; When you save
passwords in Edge, the browser decrypts every credential at startup and keeps
them resident in process memory. This happens even if you never visit a site
that uses those credentials. &gt; &gt; At the same time, Edge requires you to
re‑authenticate before showing those same passwords in the Password Manager UI —
yet the browser process already has them all in plaintext. &gt; &gt; Edge is the only
Chromium‑based browser I’ve tested that behaves this way. By contrast, Chrome
uses a design that makes it far harder for attackers to extract saved passwords
by simply reading process memory. &gt; &gt; It decrypts credentials only when needed,
instead of keeping all passwords in memory at all times. App‑Bound Encryption
(ABE) adds another layer by binding decryption to an authenticated Chrome
process, preventing other processes from reusing Chrome’s encryption keys. &gt; &gt;
Because of these controls, plaintext passwords appear only briefly during
autofill or when the user views them, making broad memory scraping far less
effective. The risk of keeping the passwords in cleartext in memory becomes
evident in shared environments. &gt; &gt; If an attacker gains administrative access
on a terminal server, they can access the memory of all logged‑on user
processes. In the video the attacker has compromised a user account with
administrative rights and is able to view stored credentials for two other
logged on &gt; &gt; (or even disconnected) users with Edge running. I reported this to
Microsoft, and the official response was that the behavior is “by design”. They
have been informed that I would be sharing this as a responsible disclosure so
users and organizations can make informed decisions &gt; &gt; about how they manage
credentials. Last wednesday (April 29th) I disclosed this on BigBiteOfTech by
Norway Simple, educational proof of concept
[https://github.com/L1v1ng0ffTh3L4N/Proof-of-Concepts/tree/main/EdgeSavedPasswordsDumper],
to show that the passwords are stored in cleartext in memory. Source
[https://farside.link/nitter/L1v1ng0ffTh3L4N/status/2051308329880719730].</p>
</div>
<a href="https://lemmy.world/post/46435614" class="card-footer text-body-secondary small d-flex gap-2 align-items-center lh-2">



<img src="https://lemmy.world/pictrs/image/0fd47927-ca3a-4d2c-b2e4-a25353786671.png" alt="favicon" class="not-responsive overflow-hiddden" style="max-width:21px;max-height:21px" />





<p class="d-inline-block text-truncate mb-0"> <span class="text-secondary">(lemmy.world)</span></p>
</a>
</div><p></p><p><a href="https://exquisite.social/tags/infosec" rel="tag">#<span>infosec</span></a> <a href="https://exquisite.social/tags/facepalm" rel="tag">#<span>facepalm</span></a> <a href="https://exquisite.social/tags/clowncar" rel="tag">#<span>clowncar</span></a></p>]]></description><link>https://board.circlewithadot.net/topic/eeff2e11-6cf0-4e97-9d97-aeb2b4651c5f/holy-shit-microsoft.</link><generator>RSS for Node</generator><lastBuildDate>Fri, 15 May 2026 06:55:21 GMT</lastBuildDate><atom:link href="https://board.circlewithadot.net/topic/eeff2e11-6cf0-4e97-9d97-aeb2b4651c5f.rss" rel="self" type="application/rss+xml"/><pubDate>Mon, 04 May 2026 22:42:01 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Holy shit, Microsoft. on Tue, 05 May 2026 02:21:56 GMT]]></title><description><![CDATA[<p><span><a href="/user/kaidenshi%40exquisite.social">@<span>kaidenshi</span></a></span> ahahahaahahahaahaha</p>]]></description><link>https://board.circlewithadot.net/post/https://mastodon.social/users/Gh0stlyM0use/statuses/116519581537409789</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mastodon.social/users/Gh0stlyM0use/statuses/116519581537409789</guid><dc:creator><![CDATA[gh0stlym0use@mastodon.social]]></dc:creator><pubDate>Tue, 05 May 2026 02:21:56 GMT</pubDate></item><item><title><![CDATA[Reply to Holy shit, Microsoft. on Tue, 05 May 2026 02:15:43 GMT]]></title><description><![CDATA[<p><span><a href="https://kolektiva.social/@jargoggles">@<span>jargoggles</span></a></span> <span><a href="/user/kaidenshi%40exquisite.social">@<span>kaidenshi</span></a></span> </p><p>Ah yes, Intelligent Design <img src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/1f923.png?v=28325c671da" class="not-responsive emoji emoji-android emoji--rolling_on_the_floor_laughing" style="height:23px;width:auto;vertical-align:middle" title="🤣" alt="🤣" /></p>]]></description><link>https://board.circlewithadot.net/post/https://masto.hackers.town/users/float13/statuses/116519557107862673</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://masto.hackers.town/users/float13/statuses/116519557107862673</guid><dc:creator><![CDATA[float13@masto.hackers.town]]></dc:creator><pubDate>Tue, 05 May 2026 02:15:43 GMT</pubDate></item><item><title><![CDATA[Reply to Holy shit, Microsoft. on Tue, 05 May 2026 01:49:30 GMT]]></title><description><![CDATA[<p><span><a href="/user/kaidenshi%40exquisite.social">@<span>kaidenshi</span></a></span> Wait. People actualy use Edge?</p>]]></description><link>https://board.circlewithadot.net/post/https://mstdn.social/users/Microplastics101/statuses/116519454023148674</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mstdn.social/users/Microplastics101/statuses/116519454023148674</guid><dc:creator><![CDATA[microplastics101@mstdn.social]]></dc:creator><pubDate>Tue, 05 May 2026 01:49:30 GMT</pubDate></item><item><title><![CDATA[Reply to Holy shit, Microsoft. on Tue, 05 May 2026 01:35:57 GMT]]></title><description><![CDATA[<p><span><a href="/user/kaidenshi%40exquisite.social">@<span>kaidenshi</span></a></span> </p><p>This is why I close every Edge process at least two or three times per day!</p>]]></description><link>https://board.circlewithadot.net/post/https://beige.party/users/mycotropic/statuses/116519400762837175</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://beige.party/users/mycotropic/statuses/116519400762837175</guid><dc:creator><![CDATA[mycotropic@beige.party]]></dc:creator><pubDate>Tue, 05 May 2026 01:35:57 GMT</pubDate></item><item><title><![CDATA[Reply to Holy shit, Microsoft. on Mon, 04 May 2026 23:12:50 GMT]]></title><description><![CDATA[<p><span><a href="/user/cienmilojos%40infosec.exchange">@<span>cienmilojos</span></a></span> yep. "You will be pwned by script kiddies and skilled adversaries alike, by design, and you will like it" ~ Microchud</p>]]></description><link>https://board.circlewithadot.net/post/https://exquisite.social/users/kaidenshi/statuses/116518837946019394</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://exquisite.social/users/kaidenshi/statuses/116518837946019394</guid><dc:creator><![CDATA[kaidenshi@exquisite.social]]></dc:creator><pubDate>Mon, 04 May 2026 23:12:50 GMT</pubDate></item><item><title><![CDATA[Reply to Holy shit, Microsoft. on Mon, 04 May 2026 23:10:04 GMT]]></title><description><![CDATA[<p><span><a href="/user/kaidenshi%40exquisite.social">@<span>kaidenshi</span></a></span> “by design”</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/cienmilojos/statuses/116518827098852525</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/cienmilojos/statuses/116518827098852525</guid><dc:creator><![CDATA[cienmilojos@infosec.exchange]]></dc:creator><pubDate>Mon, 04 May 2026 23:10:04 GMT</pubDate></item></channel></rss>