Password Management
Ongoing coverage on Password Management.
Latest coverage
Evening Safety Dance
Microsoft is implementing a fix for how its Edge browser stores user passwords. This update aims to improve the security and management of saved credentials within the browser.
Microsoft reiterates that it's totally fine with Edge storing passwords in cleartext, despite security…
Microsoft has confirmed that Microsoft Edge stores saved passwords in cleartext within the browser's memory, a design choice intended to balance performance and usability. While Microsoft states this requires the device to already be compromised, security researchers highlight that this vulnerability could allow attackers with admin rights to easily access sensitive credentials, especially in shared environments. The company recommends users maintain up-to-date security software.
Microsoft Edge saves passwords in cleartext 'by design' and researchers argue 'this turns into a credential harvest' on shared PCs
Cybersecurity researcher Tom Jøran Sønstebyseter Rønning discovered that Microsoft Edge saves passwords in memory in cleartext, a behavior Microsoft has stated is "by design." This method differs from other Chromium-based browsers like Chrome, which only decrypt credentials when needed. Critics argue this practice creates a significant security risk, especially on shared PCs, potentially leading to credential harvesting.