惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

B
Blog RSS Feed
B
Blog
N
Netflix TechBlog - Medium
量子位
月光博客
月光博客
博客园_首页
博客园 - Franky
酷 壳 – CoolShell
酷 壳 – CoolShell
Last Week in AI
Last Week in AI
T
The Blog of Author Tim Ferriss
Hugging Face - Blog
Hugging Face - Blog
雷峰网
雷峰网
M
MIT News - Artificial intelligence
J
Java Code Geeks
大猫的无限游戏
大猫的无限游戏
D
DataBreaches.Net
腾讯CDC
Engineering at Meta
Engineering at Meta
云风的 BLOG
云风的 BLOG
L
LangChain Blog
GbyAI
GbyAI
IT之家
IT之家
Y
Y Combinator Blog
人人都是产品经理
人人都是产品经理

Forbes - Innovation

Why Do Humans Have Fingerprints? Hint: It’s Not What You Think Booking.com Confirms Data Breach, Reservation PIN Codes Changed Why Major News Sites Are Blocking The Internet Archive’s Wayback Machine iPhone Fold Release Date: New Report Details Frustrating Apple News Comet Tracker: How To See Pan-STARRS And Three Planets On Wednesday NYT Mini Crossword Today: Tuesday, April 14 Hints And Answers Today’s NYT Strands Hints, Spangram, Answers: Tuesday, April 14 (It’s A Little Unclear) Today’s Wordle #1760 Hints And Answer For Tuesday, April 14 Most Of The Microplastics In Urban Air Come From Tires Today’s Wordle #1759 Hints And Answer For Monday, April 13 NYT Mini Crossword Today: Monday, April 13 Hints And Answers NYT Pips Today: Hints, Answers And Walkthrough For Monday, April 13 The YC Chief Who Codes 10,000 Lines A Day Has A Simple Secret Samsung Expands One UI 8.5 Beta To More Galaxy Owners Why You Should Stop Using Your iPhone If It’s On This List Chamath Says Firms That Treat AI As A Strategy Hand Rivals Their Edge 3 Unexpected Habits Of Secure Couples, By A Psychologist The First Lamp That Folds Your Clothes Samsung’s Disappointing Price Update For Galaxy Phone Buyers 3 Subtle Signs Someone Is Falling In Love With You, By A Psychologist Do Mantis Shrimp See More Colors Than Humans? A Biologist Explains NYT Connections Answers Explained For Monday, April 13 (#1,037) NYT Connections Hints Today: Monday, April 13 Clues And Answers (#1,037) LEGO Luigi & Mach 8 (72050) Review: 2026’s Best Set Yet? Marc Andreessen Says AI Productivity Will Trigger A Hiring Boom 3D Printing Is The Ultimate Hack To Reduce Household Spending Apple iPhone Fold: Striking Design Revealed In Leaked Photos Apple Smart Glasses: New Leak Reveals A Major Design Twist To Beat Meta Tested: The AI Coming To The Rivian R2 Quordle Hints Today: Monday, April 13 Clues And Answers
Microsoft Confirms Surprising Edge Password Security U-Turn
Davey Winder · 2026-05-19 · via Forbes - Innovation
Microsoft Edge logo on smartphone.

Microsoft pulls u-turn on Edge password security issue.

SOPA Images/LightRocket via Getty Images

Microsoft has now confirmed that a “defense-in-depth change will come to every supported version of Edge” after initially refusing to address a password vulnerability identified for users of the web browser password manager. When I first reported that a researcher had publicly disclosed the security vulnerability, whereby all saved passwords were loaded into memory, in plaintext, at startup, Microsoft said that this happened “by design” and the behavior fell “within the expected threat model.” That was 10 days ago. Now, Microsoft has said that it will “no longer load passwords into memory on startup,” and starting with version 148 and “every supported version of Edge” will get the update, the rollout of which is now being prioritized.

ForbesMy Password Has Been Stolen—What Happens Next?

The Microsoft Edge Saved Passwords Vulnerability Explained

A security researcher went public at the start of May after Microsoft told him that the password security vulnerability he had found in the Edge browser was by design, and therefore would not be moving forward with his vulnerability report or making any changes to rectify. “Microsoft Edge loads all your saved passwords into memory in cleartext,” Tom Jøran Sønstebyseter Rønning said, “even when you’re not using them.” I mean, if leaving decrypted plaintext passwords in Edge process memory after startup, regardless of whether they are used during that session, isn’t a security vulnerability, then, frankly, I’m not sure what is. Sure, an attacker would need to already have admin privileges to exploit it, but it remains a vulnerability regardless, in my never humble opinion. Regardless of whether it has an official Common Vulnerabilities and Exposures designation or not. Especially as none of the other Chromium-based web browsers tested displayed the same memory-saving issue according to Rønning.

ForbesMicrosoft Windows 11 Exploited 3 Times In 24 Hours By Zero-Day HackersBy Davey Winder

Why Microsoft Is Making An Edge Password Security U-Turn

Gareth Evans, the Microsoft Edge security lead, has now posted a detailed explanation of the changes that are being made to how passwords are saved in Edge memory, and why those changes are being made.

As part of Microsoft’s Secure Future Initiative, Evans said, the security team continuously reviews how Edge handles sensitive data in order to reduce the risk of any exposure. While maintaining that, as the risk begins after an attacker has access, the so-called vulnerability remains within the expected threat model, Evans admitted that there is still room to improve the browser security. “We will no longer load passwords into memory on startup,” Evans said, but in an effort to minimize data exposure through defense-in-depth improvements, the update provides “a practical step in that direction.”

Which sounds like a U-turn to me, and likely to you as well.

ForbesMicrosoft Windows 11 Exploited 3 Times In 24 Hours By Zero-Day HackersBy Davey Winder

The good news is that users of the Microsoft Edge password manager need to do nothing but wait for the version 148 update to reach them. Meanwhile, Evans confirmed that Microsoft is “reviewing how we handle researcher reports, with a focus on speed, clarity, and applying defense-in-depth thinking earlier.” I‘d like to think that is a success for both common security sense and media reporting pressure. And given the number of Microsoft security vulnerabilities that have been dropped recently, that has to be a good thing.