Edge stores passwords in plaintext memory at startup; a tool has been released to test against the flaw.

all 10 comments

sorted by: hot top controversial new old
[–] 16 points 4 months ago (1 child)

Use a real password manager people

  • source
  • hideshow 1 child comment
  • [–] 11 points 4 months ago (3 children)

    This requires reading application memory

  • source
  • hideshow 3 child comments
  • [–] 17 points 4 months ago* (2 children)

    Seems like a pretty basic security precaution to avoid loading decrypted secrets into memory before they're needed. Someone who can access application memory can already own you but there isn't really a good reason why they should be able to access secrets that you never accessed while they were in.

    I wouldn't say it's an alarming flaw, just seems weirdly and unnecessarily unsafe

  • source
  • parent
  • hideshow 2 child comments
  • [–] 2 points 4 months ago (1 child)

    At some point they will need to be decrypted anyway

    I think this was done for performance and simplicity

  • source
  • parent
  • hideshow 1 child comment
  • [–] 5 points 4 months ago*

    TIL: If you cat /proc/sys/kernel/yama/ptrace_scope on your linux distro:

    • 0: All processes with same UID can read each other's memory
    • 1: Restricted (Only parents can read children)
    • 2: Admin only (Requires sudo).

    Most distros have this set to 1 by default.

    More details: man 2 ptrace, search using /: scope

  • source
  • [+] 2 points 4 months ago* (last edited 3 months ago)
    [+] -13 points 4 months ago (1 child)