TTPwire Vol. 1 · MITRE ATT&CK·Tagged

← All stories

Slashdot

Microsoft Edge Stores Passwords In Plaintext In RAM

BeauHD · 5 hours ago · Read original ↗

ATT&CK techniques detected

1 predictions
T1003.001LSASS Memory
84%
"microsoft edge stores passwords in plaintext in ram microsoft edge stores passwords in plaintext in ram ( pcmag. com ) 6 microsoft downplayed the risk noting access would require control over a user ' s pc like a malware infection : " access to browser data as described in the re…"

Summary

Longtime Slashdot reader UnknowingFool writes: Security researcher Tom Joran Sonstebyseter Ronning has found that Microsoft Edge stores passwords in plaintext in RAM. After creating a password and storing it using Edge's password manager, Ronning found that he could dump the RAM and recover his password which was stored in plaintext. Part of the issue is Edge loads all passwords to all sites upon a single verification check, even if the user was not visiting a specific site. This is very different from Chrome, which only loads passwords for specific websites when challenged for the site's password. Also, Chrome will delete the password from memory once the password has been filled. Edge does not delete the passwords from memory once they are used. Microsoft downplayed the risk noting access would require control over a user's PC like a malware infection: "Access to browser data as described in the reported scenario would require the device to already be compromised," Microsoft said. Ronning countered that it was possible to dump passwords for multiple users using administrative privileges for one user to view the passwords for other logged-on users. "Design choices in this area involve balancing performance, usability, and security, and we continue to review it against evolving threats," Microsoft said. "Browsers access password data in memory to help users sign in quickly and securely -- this is an expected feature of the application. We recommend users install the latest security updates and antivirus software to help protect against security threats."

Read more of this story at Slashdot.