❗️🚨 Microsoft Edge keeps every saved password in process memory as cleartext from the moment it launches. Microsoft's responsed when reported: "by design."
All of them. Including credentials for sites you won't open this session.
Researcher @L1v1ng0ffTh3L4N tested every major Chromium browser. Edge is the only one that behaves this way.
Chrome decrypts credentials on demand, and App-Bound Encryption locks the keys to an authenticated Chrome process so other processes can't reuse them.
In Chrome, plaintext surfaces only during autofill or when a password is viewed, making memory scraping far less useful.
What makes this extra weird is that Edge still demands re-authentication before revealing those passwords in its Password Manager UI, while the same browser process already holds every one of them in plaintext.
In shared environments, this turns into a credential harvest. On a terminal server, an attacker with admin rights can read the memory of every logged-on user process. In the published PoC video, a compromised admin account lifts stored credentials from two other logged-on (and even disconnected) users with Edge running.
Microsoft's official response when notified: "by design."
The finding was disclosed April 29 at BigBiteOfTech by PaloAltoNtwks Norway, alongside a small educational tool that lets anyone verify the cleartext storage for themselves.
Worth a repost.
“A former city planner, Condon has become a prominent voice in Vancouver’s own housing debate. He told the gathered crowd he has seen firsthand how increasing density doesn’t solve the problem of housing unaffordability. Despite a massive development boom in recent decades that has made Vancouver one of the densest cities in North America, housing prices there are among the highest on the continent.
“Unfortunately, it will take 30 years for you to realize that you were wrong,” he said.”
https://t.co/0nhb2h2Qeq
they're going to be liquefied and used to pay for long-term care for their owners. There's a very real housing x disability tension that nobody in power seems interested in addressing
The governor’s team supplied senators with talking points and rebuttals to criticism from public health organizations, disability rights activists and anti-poverty advocates...
5/x
The Republican governor’s proposal was intended to cull Medicaid, the safety net healthcare program that provides insurance to impoverished families and disabled Floridians...
2/x
“I just didn’t want to accept my career was ending so soon because of COVID, because of a virus so out of my control… eventually I got to a point where… 15 months in, I’m still housebound, still mostly bedbound, unable to do most basic things” #LongCovid https://t.co/pF0sqTrwe1
@neck_cheese@newstart_2024 We have all watched the propaganda grow & change over time. The Anything But Covid narratives will get worse. They’re going to throw everything at the wall.
@newstart_2024 Three generations of humans used screens with no dementia-like changes reported. It’s weird how screens only began doing this after Covid began. I wonder what that’s about?
Cool business concept, I guess. First push everyone to get a progressive (often deadly) persistent infection. Then find a “cure”.
LC treatments are incredibly urgent, but it’s wild how the same folks who undermined clean air, masks & vaccines are now salivating at “innovation”.
Polymarket’s CMO almost leaked insider info to Clavicular before noticing he was wearing a mic
"You have to understand bro...Oh hold on"
"You almost got me caught."
assisted suicide is one of those things where i very strongly agree in theory but in practice seeing people be told “well no we won’t cover this treatment for your disease but you CAN kill yourself” is absolutely fucking heinous
Why do people psychologize Long COVID? Why have people psychologized ME/CFS for decades?
I have been thinking about this for a long time, and I think I finally figured it out.
It's not that doctors are stupid or cruel. It's that the alternative to "you're crazy" is "our entire society is organized in a way that sacrifices people like you, and we know it, and we've decided the cost of fixing it is too high."
Psychologization isn't a diagnostic error. It's a defense mechanism. Not for the patient, but for society.
If a common virus can destroy a healthy person's life, then every school, every office, every restaurant, every airplane is a potential site of life-altering harm.
That's an intolerable reality for a society built on the assumption that showing up is safe. So the person who got destroyed becomes the anomaly. The anxious one. The one with pre-existing vulnerabilities. The one whose personality predisposed them. Anything to keep the virus from being the cause, because if the virus is the cause, then every subsequent infection is a policy choice.
NEW: Louisiana has the nation's highest share of residents living in poverty & the nation's highest incarceration rate
Now the state wants to subject unhoused people to fines, jail time, or unpaid labor if they are found sleeping outdoors.
FULL STORY: https://t.co/tpX5fjm8oT
What if we destroyed video stores to give you movies the way they were really meant to be seen: interrupted every 20 minutes by ads for online gambling apps
Epstein file documents show Kash Patel and Dan Bongino carefully coordinated "clear and specific guidance" to redact files containing the name of Trump, other former US presidents and a former Secretary of State.