Microsoft Edge stores all your saved passwords unencrypted in memory

https://www.techspot.com/images2/news/ts3_thumbs/2023/08/2023-08-07-ts3_thumbs-f6e.jpg

Serving tech enthusiasts for over 25 years.
TechSpot means tech analysis and advice you can trust.

Why it matters: Microsoft advertises its password manager as having robust encryption on par with well-regarded third-party options. However, security researchers have discovered that the browser effectively decrypts all passwords while it is running, potentially putting them within reach of hackers with local access to a device. Edge has maintained this behavior for years, and Microsoft does not plan to change it.

Security researcher Tom Jøran Sønstebyseter Rønning recently shared evidence that Microsoft's web browser-based password manager stores all of its saved passwords in memory without encryption while running. He released and demonstrated a simple proof of concept that displays the passwords and their associated accounts.

Microsoft's documentation claimsthat Edge uses on-disk AES encryption, similar to independent password managers such as Bitwarden, with encryption keys stored in a protected location on the...

Copyright of this story solely belongs to techspot.com. To see the full text click HERE