A security researcher has discovered that Microsoft Edge will load all your stored passwords into memory in plaintext at startup, making it easy for malware to scrape those passwords.
Eh. To be honest it indeed does not matter much. Scanning your RAM for passwords is much harder than simply reading them off the browsers files. Sure, it is encrypted and the key is not necessarily on your computer, but remember that if the software can decrypt your passwords without you inputting a password or similar, then anything with access to your device can as well.
For real. Like why isn’t that a plugin? I feel like security best practices have advised against using the baked-in password manager in the browser for near a decade now, so any browser claiming an interest in security could score a big win by literally just removing that functionality.
Its a disservice that they even exist st all at this point.
Eh. To be honest it indeed does not matter much. Scanning your RAM for passwords is much harder than simply reading them off the browsers files. Sure, it is encrypted and the key is not necessarily on your computer, but remember that if the software can decrypt your passwords without you inputting a password or similar, then anything with access to your device can as well.
Don’t use your browser’s password manager.
For real. Like why isn’t that a plugin? I feel like security best practices have advised against using the baked-in password manager in the browser for near a decade now, so any browser claiming an interest in security could score a big win by literally just removing that functionality.
Its a disservice that they even exist st all at this point.
Or simply… Make it encrypted with a password. That simple.