Microsoft Edge stores all your saved passwords unencrypted in memory
Serving tech enthusiasts for over 25 years.
TechSpot means tech analysis and advice you can trust.
Why it matters: Microsoft advertises its password manager as having robust encryption on par with well-regarded third-party options. However, security researchers have discovered that the browser effectively decrypts all passwords while it is running, potentially putting them within reach of hackers with local access to a device. Edge has maintained this behavior for years, and Microsoft does not plan to change it.
Security researcher Tom Jøran Sønstebyseter Rønning recently shared evidence that Microsoft's web browser-based password manager stores all of its saved passwords in memory without encryption while running. He released and demonstrated a simple proof of concept that displays the passwords and their associated accounts.
Microsoft's documentation claimsthat Edge uses on-disk AES encryption, similar to independent password managers such as Bitwarden, with encryption keys stored in a protected location on the...
Copyright of this story solely belongs to techspot.com. To see the full text click HERE