Why Edge stores your passwords in plaintext, according to Microsoft


Microsoft Edge

Lance Whitney/ZDNET

Follow ZDNET: Add us as a preferred source on Google.


ZDNET’s key takeaways

  • Microsoft Edge stores your passwords in plaintext in RAM.
  • This behavior occurs if you use Edge as your password manager.
  • Microsoft says that this behavior is a feature, not a bug.

Do you use Microsoft Edge to save and manage your website passwords? If so, a new finding raises questions about the safety and security of your stored passwords.

A security researcher found that Edge stores your plaintext passwords in memory when you use the browser to manage them. In a social media post, researcher Tom Jøran Sønstebyseter Rønning explained how the process works and posted a video showing it in action.

Also: Trojan abuses Microsoft Phone Link app to steal your passwords

“When you save passwords in Edge, the browser decrypts every credential at startup and keeps them resident in process memory,” Rønning said. “This happens even if you never visit a site that uses those credentials. At the same time, Edge requires you to re‑authenticate before showing those same passwords in the Password Manager UI — yet the browser process already has them all in plaintext.”

Microsoft calls behavior an expected feature 

On GitHub, Rønning posted the code he created to detect this behavior. Dubbed EdgeSavedPasswordsDumper, the code demonstrates that any credentials stored by someone using the Microsoft Password Manager in Edge are saved in plaintext in the Edge process memory.

In a statement shared with ZDNET, Microsoft acknowledged this behavior but said that it’s an expected feature and would pose a risk only if your device was already compromised.

“Access to browser data as described in the reported scenario would require the device to already be compromised,” a Microsoft spokesperson said in the statement. “Design choices in this area involve balancing performance, usability, and security, and we continue to review it against evolving threats. Browsers access password data in memory to help users sign in quickly and securely — this is an expected feature of the application. We recommend users install the latest security updates and antivirus software to help protect against security threats.”

Also: It’s possible to switch password managers without losing a single login – and I’m proof

Microsoft’s claim that your device would already need to be compromised appears to ring true, at least based on Rønning’s testing. As shown in a video, the process is predicated on an attacker having already compromised a user account with administrative rights, which would then give them access to the memory of all logged‑on user processes, with the plaintext passwords viewable.

Rønning said that Edge is the only Chromium‑based browser he’s tested that acts this way. In contrast, Google Chrome decrypts credentials only when needed rather than keeping all passwords in memory at all times. Chrome’s design makes it far more difficult for an attacker to extract saved passwords by simply reading the device’s memory, Rønning added. So far, this weakness appears to be specific to the Microsoft Password Manager used in Edge.

“Despite Edge being Chromium-based, none of the other Chromium-based browsers I have tested are using Microsoft Password Manager to store passwords and autofill data,” said Rønning. “And I doubt that’s based on Chromium?”

Also: These 5 critical Windows Defender settings are off by default – turn them on ASAP

If Google can better secure its browser from exposing plaintext passwords in memory, then shouldn’t Microsoft be able to do the same? In response to Rønning’s post, another person said that the credentials could be stored in memory in an encrypted format. They would be decrypted only when required to sign in to a website and then immediately wiped thereafter.

“From a defensive perspective, storing passwords in clear-text memory violates the principles of least privilege, zero trust, and secure application design,” Morey Haber, chief security advisor at security provider BeyondTrust, told ZDNET. “It is simply just a bad idea. If a password can be read in memory by a human or malicious process, it is no longer a protected secret. It is already compromised in principle through clear-text storage in an already insecure medium.”

Pitfalls of using your browser’s built-in password manager  

Unless Microsoft decides to change the way its password manager works, what can you do if you use Edge as your default browser to manage your passwords?

My advice would be to switch to a dedicated third-party password manager. Yes, using your browser’s built-in password manager seems quick and convenient. But there are some pitfalls beyond this latest one.

If someone gains access to your PC or mobile device via your password, PIN, or passcode, they could launch your browser and use the same method to view your passwords. I’ve tried this on a Windows PC using just my PIN and was able to access plaintext passwords in Edge. A good third-party password manager requires stronger authentication to view your passwords.

Also: The best password managers: Expert tested

A built-in password manager works just with that specific browser. You can use Edge as your default, but you might sometimes turn to Chrome or Firefox. In that case, your stored passwords wouldn’t be available. I use Firefox, Chrome, and Edge both personally and professionally, so my passwords need to be accessible across all three.

Hopefully, Microsoft will see this as a security flaw and adopt the same method used in Chrome and other browsers to decrypt passwords only when needed. Until then, I’d advise against using Edge as your password manager.





Source link

Leave a Reply

Subscribe to Our Newsletter

Get our latest articles delivered straight to your inbox. No spam, we promise.

Recent Reviews


With the start of April, Netflix is welcoming entertaining movies that will be available to stream for the foreseeable future. One of the new movies I’m ready to watch is Thrash, a new shark movie where the Jaws-like creatures wreak havoc on a coastal town during a hurricane. It might only be spring, but I’ll watch this type of survival thriller any time of the year.

Speaking of thrillers, there are several prominent movies featured on the genre page. My top pick for thrillers this week is a gritty punk-rock film, now streaming on Netflix in the U.S. The other two thrillers we want to spotlight are a twisty crime tale from the 1990s and an allegorical dystopian mystery set in prison.

3

The Platform

Maybe don’t watch on a full stomach

Read what I wrote under the title again. The Platform is not for viewers with queasy stomachs. I have a strong stomach, and yet there are several moments when certain prisoners chow down where I wanted to look away. Between that and the violence, watching before dinner might be the move.

In a dystopian future, there is a prison called the Vertical Self-Management Center. Two prisoners are stationed on each floor, and there is a giant hole in the center. Every day, a platform filled with food lowers to the floor. Prisoners can have as much food as they want when the platform is on their level. However, they can no longer eat when the platform lowers to the next floor. The higher you are in the building, the more food you’ll have at your disposal. The lower floors are left to eat the scraps.

The Platform has much to say about social inequality and greed. I did not expect the Spanish thriller to be as gory as it was. This movie reflects how society treats the rich and the poor, so I should have expected a few uprisings. Overall, it’s a surprisingly effective thriller.​​​​​​​

2

Wild Things

A steamy thriller from the 1990s

The following phrase is meant as a compliment: Wild Things is sexy trash. It is unapologetically lustful. It’s like playing Mad Libs with an erotic thriller. Plus, its attractive cast—Matt Dillon, Neve Campbell, Denise Richards, Daphne Rubin-Vega, and Kevin Bacon—adds to the appeal.

In Miami, high school counselor Sam Lombardo (Dillon) is accused of raping popular student Kelly Van Ryan (Richards) and outcast Suzie Toller (Campbell). Sam then hires sleazy lawyer Kenneth Bowden (Murray) to defend him at trial. As the case progresses, Detective Duquette (Bacon) remains suspicious of the girls’ motives and questions whether Sam is innocent.

I’m being intentionally vague in my synopsis because of the significant twists this movie takes. Even if you guess one of the twists, more will follow. It approaches parody with how ridiculous it is, but I’m a sucker for this movie. It’s a soap opera with scandal, murder, and sexual longing. Wild Things is a scripted version of your favorite reality TV show.​​​​​​​

1

Caught Stealing

Austin Butler races around New York City

Austin Butler has the “it factor.” Ever since Elvis, Hollywood has been pushing Butler as one of its future stars. The 34-year-old has the looks and skills of an A-list talent. He has good taste, as evidenced by the directors he works with, a list that includes Quentin Tarantino, Jeff Nichols, Denis Villeneuve, Ari Aster, and Darren Aronofsky.

Butler headlined Aronofsky’s 2025 crime thriller Caught Stealing. In the late 1990s, Hank (Butler) is a bartender living in New York City. Hank had aspirations of playing in the MLB, but a car accident derailed his opportunity. One day, Hank’s neighbor Russ (Matt Smith) asks him to look after his cat. That small task somehow leads to Hank going on the run from Russian mobsters.

Butler is the perfect actor for this star-making performance that would have taken him to new heights had it come out in the 1990s. Caught Stealing was considered a box office flop—$32 million on an estimated budget of $40 million. I don’t necessarily blame Butler for the poor box office. I think the August 29 release date played a role in its poor performance. Butler’s inclusion in a project might not lead to significant financial gains. However, I appreciate that he made a grimy mid-budget crime thriller that has seemingly disappeared from today’s movie landscape. If Butler’s down to make more crime capers with breakneck action and frenetic pacing, sign me up.


More movies and shows to stream on Netflix

Netflix users in the United States, you got it made. There are thousands of movies and TV shows to stream with the push of a button. For some family-friendly content with Dwayne Johnson and Jack Black, Jumanji: Welcome to the Jungle is now on Netflix. If you want something more adult-focused, give some serials like Black Mirror a chance.

Subscription with ads

Yes, $8/month

Simultaneous streams

Two or four




Source link