Btw does anyone at the FIA want to explain to me how crashing into someone and directly causing their retirement gives you a 10 second penalty, but when someone crashes behind you, you get a 20s penalty?
❗️🚨 Microsoft Edge keeps every saved password in process memory as cleartext from the moment it launches. Microsoft's responsed when reported: "by design."
All of them. Including credentials for sites you won't open this session.
Researcher @L1v1ng0ffTh3L4N tested every major Chromium browser. Edge is the only one that behaves this way.
Chrome decrypts credentials on demand, and App-Bound Encryption locks the keys to an authenticated Chrome process so other processes can't reuse them.
In Chrome, plaintext surfaces only during autofill or when a password is viewed, making memory scraping far less useful.
What makes this extra weird is that Edge still demands re-authentication before revealing those passwords in its Password Manager UI, while the same browser process already holds every one of them in plaintext.
In shared environments, this turns into a credential harvest. On a terminal server, an attacker with admin rights can read the memory of every logged-on user process. In the published PoC video, a compromised admin account lifts stored credentials from two other logged-on (and even disconnected) users with Edge running.
Microsoft's official response when notified: "by design."
The finding was disclosed April 29 at BigBiteOfTech by PaloAltoNtwks Norway, alongside a small educational tool that lets anyone verify the cleartext storage for themselves.
We've been tricked, again. Many of the thousands of bugs and vulnerabilities Mythos found are in older software are impossible to exploit. And the severe zero-day reports rely on just 198 manual reviews https://t.co/WhDRhTtCX2
Super interesting take from one of the greatest hackers
He says Mythos is not as good as they claim, because zero-day vulnerabilities are not that hard to find for skilled hackers
I'm far from the hacking world but sounds reasonable
Any thought?
As someone who has audited dozens of safety-critical systems, built static analysis tools, and used most formal verification and security tools, here are some red flags that should be a caution in taking these claims at face value:
1. There are no comparison benchmarks with 1/
Es triste ver a la gente huir de sus emociones cuando la vida le pone a alguien enfrente con quien experimentan una conexión especial. Me da nostalgia la gente que por seguir su plan de vida estructurado no comprende que a veces tambien suceden cosas al azar, y que el universo nos hace cruzar con personas interesantes que valen la pena conocer.
Ser escapistas es no vivir, cuando la vida es arriesgar.
Ojo que nadie pasa dos veces. Y cuidado con seguir buscando por todos lados al amor que tuviste y perdiste.
When someone keeps trying to talk to you, messaging again and again, finding the tiniest excuses just to stay connected, it doesn’t mean they’re crazy it means you matter to them more than their pride, more than their ego, even more than their self-respect. They aren’t desperate, they’re just terrified of losing the one person who feels like home to them, because not everyone loves with that kind of depth the kind of love where ego and attitude don’t stand in the way.
“there’s a special kind of sadness that hits when a new year is coming and you realize you’re walking into it without the person who was once your whole world. all those years, all that love and now they won’t be standing beside you in this next chapter. it’s like the calendar is moving forward, but your heart is still holding on to the days when they were here.”