Microsoft Edge -- don't save passwords

860 Views | 9 Replies | Last: 2 days ago by Lathspell
eric76
How long do you want to ignore this user?
AG
It is being reported that Microsoft Edge keeps passwords unencrypted and that is by design.

From https://proton.me/business/blog/microsoft-edge-passwords-exposed

Quote:

If you save passwords in Microsoft Edge, there's a security risk you should know about. According to a new disclosure, whenever you open Edge, the browser immediately loads all saved passwords into memory in readable form not just the password for the website you're logging into. That means credentials for every account saved in Edge could be exposed if malware, a compromised admin account, or another attacker gains access to your device or user session[/.b].

...

Security researcher Tom Jran Snstebyseter Rnning says Microsoft Edge loads all saved passwords into the browser's memory in plaintext as soon as it launches, instead of only decrypting a specific password when it's needed. This includes all passwords saved in the Edge password manager, even those for websites you don't visit or autofill during the current browsing session.

...

If an attacker gains sufficient access to the device or user session, they may be able to inspect the browser's memory. If only one password is decrypted when needed, the attacker has a smaller window and less data to capture. But if every saved password is already sitting in memory unprotected by encryption, memory scraping becomes far more valuable.



Just say no to Edge?
Mega Lops
How long do you want to ignore this user?
AG
Who the hell uses Edge?
Rex Racer
How long do you want to ignore this user?
AG
Don't save passwords in any browser. Use a good password locker like Proton Pass.
htownag08
How long do you want to ignore this user?
AG
I was just thinking the other day of finally setting up on a password protection site. I'll have to check out this proton one.
eric76
How long do you want to ignore this user?
AG
Rex Racer said:

Don't save passwords in any browser. Use a good password locker like Proton Pass.


Proton has by far the best e-mail service in my opinion. I have been using it since 2016.

If anyone wants to try Proton, they can get two weeks free on their chosen plan using the following referral link and if they subscribe, we both get $20 in credits.

https://pr.tn/ref/AZ0CPNEP
heddleston
How long do you want to ignore this user?
AG
Proton Pass & BitWarden both are great, if youre looking for something a little more free but still extremely stout, look at KeePass and just keeping your kee file in your cloud storage of choice.
Average Joe
How long do you want to ignore this user?
AG
Much ado...

Most password managers save your passwords in plaintext in RAM as long as they are unlocked, including BitWarden. The problem with Edge is the long lifecycle on the key.

If someone wanted to exploit this then they would have to be an admin user on the system already and be able to access your RAM. If they are doing that then you're already screwed.
WestHoustonAg79
How long do you want to ignore this user?
Tom Jran Snstebyseter Rnning

What name right there!
YouBet
How long do you want to ignore this user?
AG
Mega Lops said:

Who the hell uses Edge?

I do. It's the best of the big-name browsers and it's not close.

I don't use their password manager.
Lathspell
How long do you want to ignore this user?
AG
I use MFA for anything worth a damn.

Also, eww... edge...

I love living ad free in Brave!
Refresh
Page 1 of 1
 
×
subscribe Verify your student status
See Subscription Benefits
Trial only available to users who have never subscribed or participated in a previous trial.