Microsoft says Edge saving passwords in plaintext is ‘by design’ but it still seems like a bad idea

Microsoft says Edge saving passwords in plaintext is ‘by design’ but it still seems like a bad idea


Earlier this week, we reported that a researcher found Microsoft Edge saves passwords in cleartext in the memory of your machine. This means you can seemingly bypass even the likes of 2FA if you have access to someone’s rig. At the time, Microsoft said this was ‘by design’, and it has affirmed the same statement in a correspondence with me.

I’ve been told, “Safety and security are foundational to Microsoft Edge. Access to browser data as described in the reported scenario would require the device to already be compromised.”





News Source link