Microsoft Edge loads your passwords into memory in plaintext, but Microsoft says not to worry
2026-05-06 01:32 UTC
Replies (40)
-
@SaharaMaleikuhm@feddit.org 2026-05-06 05:37
I am not worried, cause I’m not dumb enough to use Edge or Windows for that matter.
-
@quantumvoid0@programming.dev 2026-05-06 01:36
does this company intentionally want users to stop using it? cuz day by day either theres a new windows bug or just shittier softwares
-
@58008@lemmy.world 2026-05-06 07:51
2026 is gonna be the year I finally move to Linux. I have huge concerns about many aspects of switching, but they’re being overtaken by concerns about staying with Windows. I don’t even mind if my overall user experience is a bit worse on Linux (I am trying to have reasonable expectations that it won’t be the walk in the park Linux advocates on Lemmy like to claim), I just have much more faith in its security, privacy, customisability and - most importantly - the motivations and intentions of its developers.
-
@MonkderVierte@lemmy.zip 2026-05-06 10:05
Btw, don’t ever copy&paste from your password manager, if that’s a problem. The problem is, how it is implemented in Edge and how MS handles the issue.
-
@zerofk@lemmy.zip 2026-05-06 06:46
Access to browser data as described in the reported scenario would require the device to already be compromised. Yes you can open our safe with just a good yank but if a thief can do that they’re already in your house.
-
@gokayburucdev@lemmy.world 2026-05-06 10:22
I will take your data but don’t worry be happy 😁 🇯🇲 I will not use it. Because we are smoking ganja and smiling to each other in our office. We are so happy; Thanks to AI. Peace ☮️✌️😁🕶️ Microslop Edge Team
-
@azvasKvklenko@sh.itjust.works 2026-05-06 10:38
I don’t worry, I just don’t use Edge or Windows or any MS software really (except for Teams at work)
-
@fira@lemmy.today 2026-05-07 03:51
You guys are using edge?
-
@pwxd@lemmy.zip 2026-05-07 03:59
“Yeah totally secure! Just trust me!..” basically This is LITERALLY isn’t secure; they should atleast make it encrypted. This is just the same as using your notes app as password manager! But it’s microsoft, and they’re willingly giving your bitlocker encryption key to the FBIs for your drives. So I’m not surprised…
-
@JackbyDev@programming.dev 2026-05-07 11:27
This is sort of like saying “I leave my valuables in plain sight by my door because it has a lock on it and door locks are trustworthy.” I’m not super into cyber security and stuff but it seems like one of the most common problems is programs managing to get access to memory they shouldn’t have access to. It seems to happen all the time! Just like many locks for you door are trash.
-
@Microtonal_Banana@lemmy.zip 2026-05-06 20:03
I haven’t used a Microsoft browser or operating syatem in almost 25 years.
-
@baronvonj@piefed.social 2026-05-06 02:56
Microsoft SSH agent persistently stores your unencrypted private keys in the registry. They're still there unlocked and usable after you reboot. https://github.com/PowerShell/Win32-OpenSSH/issues/1487
-
@GainGround@kopitalk.net 2026-05-06 04:25
Our lives are in the hands of morons. What the fuck.
-
@Reygle@lemmy.world 2026-05-06 02:16
HOLY @#%^ WHAT IN THE @#%^ DO THEY MEAN "NOT TO WORRY"?????????????????
-
@FosterMolasses@leminal.space 2026-05-06 15:14
Everytime I read a Microsoft headline these days 
-
@Passerby6497@lemmy.world 2026-05-06 12:33
> Safety and security are foundational to Microsoft Edge. Access to browser data as described in the reported scenario would require the device to already be compromised. Design choices in this area involve balancing performance, usability, and security, and we continue to review it against evolving threats. "We value user safety and usability, but if you're already compromised you can go fuck yourself"
-
@SeductiveTortoise@piefed.social 2026-05-06 15:02

-
@goatinspace@feddit.org 2026-05-06 02:33

-
@Quazatron@lemmy.world 2026-05-06 06:39
Microsoft - So secure we ROT13 encode everything... TWICE!
-
@darkmogool@feddit.org 2026-05-06 07:09
Why did I read "Microsoft Edge lords"?
-
@SCmSTR@lemmy.blahaj.zone 2026-05-06 04:04
And this is why you don't give microslop anything
-
@iglou@programming.dev 2026-05-06 07:39
Eh. To be honest it indeed does not matter much. Scanning your RAM for passwords is much harder than simply reading them off the browsers files. Sure, it is encrypted and the key is not necessarily on your computer, but remember that if the software can decrypt your passwords without you inputting a password or similar, then anything with access to your device can as well. Don't use your browser's password manager.
-
@weaponG@lemmy.world 2026-05-06 12:50
Nothing in this timeline surprises me any more.
-
@AbsolutelyNotAVelociraptor@piefed.social 2026-05-06 05:54
They say not to worry because they know nobody uses that dumpster fire of a browser so there's no actual risk of your passwords being leaked since you're not using it anyways.
-
@BaraCoded@literature.cafe 2026-05-06 20:24
How will the NSA spy on you if Microsoft doesn't hand them your passwords?
-
@boogiebored@lemmy.world 2026-05-07 03:37
phew it’s an expected feature, thank goodness!!! if they patch this, they should be dragged through the town square after that comment
-
@rmrf@lemmy.ml 2026-05-07 15:40
This is why gamers should reject kernel anti cheats. A single dev at a single company that requires one could read them as easily as any other file. I'm not exaggerating, unless I'm misinformed
-
@uenticx@lemmy.world 2026-05-06 19:20
M365 chat also fetches a copy of whatever secured file links you send to each other. Goes without saying, but never use Microsoft products if you value security.
-
@HotsauceHurricane@lemmy.world 2026-05-06 03:49
Wow, that's bad.
-
@Blackdoomax@sh.itjust.works 2026-05-06 20:38
Trust me bro
-
@KyuubiNoKitsune@lemmy.blahaj.zone 2026-05-06 04:47
What is even the point of the DPAPI?
-
@afporritt1001@lemmy.today 2026-05-07 15:10
Fuck Microslop Fuck windows 11
-
@unemployedclaquer@sopuli.xyz 2026-05-06 06:32
Moms insists on pen an paper! Omg!
-
@nutsack@lemmy.dbzer0.com 2026-05-06 16:53
don't worry bb
-
@MrKoyun@lemmy.world 2026-05-06 19:03
How can a company manage to be so bafflingly incompetent and why are there people out there still standing for it.
-
@sturmblast@lemmy.world 2026-05-06 19:17
.... They are so bad
-
@starik@lemmy.zip 2026-05-06 07:09
If you don’t have anything to hide, what’s the worry?
-
@experimentmapass@social.trom.tf 2026-05-06 01:46
@Itwasntme223@discuss.online Retarded trade-based retard, retarding about retarded trade-based retarded society, about how it is retarding...
-
@Alberat@lemmy.world 2026-05-06 16:59
trust is multiplicative, not additive
-
@mirshafie@europe.pub 2026-05-07 13:34
True, and I've met many of both groups. Vegans are usually pretty chill.