ZDNet: Why Edge stores your passwords in plaintext, according to Microsoft. “A security researcher found that Edge stores your plaintext passwords in memory when you use the browser to manage them. In a social media post, researcher Tom Jøran Sønstebyseter Rønning explained how the process works and posted a video showing it in action.”

https://rbfirehose.com/2026/05/07/zdnet-why-edge-stores-your-passwords-in-plaintext-according-to-microsoft/
ZDNet: Why Edge stores your passwords in plaintext, according to Microsoft

ZDNet: Why Edge stores your passwords in plaintext, according to Microsoft. “A security researcher found that Edge stores your plaintext passwords in memory when you use the browser to manage…

ResearchBuzz: Firehose

This dumb password rule is from Dutch Tax Authorities (Belastingdienst).

At least 8 and at most 25 characters, of which at least 3 of the characters were not used in the previous password.
No more than 3 of the same characters.
At least 1 upper case and 4 lower case characters.
No more than 3 special characters.

It's not like hashing passwords is a thing or something.

https://dumbpasswordrules.com/sites/dutch-tax-authorities-belastingdienst/

#password #passwords #infosec #cybersecurity #dumbpasswordrules

Dutch Tax Authorities (Belastingdienst) - Dumb Password Rules

At least 8 and at most 25 characters, of which at least 3 of the characters were not used in the previous password. No more than 3 of the same characters. At least 1 upper case and 4 lower case characters. No more than 3 special characters. It's not like hashing passwords is a thing or something.

Comparitech: Where do leaked passwords end up? A statistical analysis of the dark web’s credential pipeline https://www.comparitech.com/news/where-do-leaked-passwords-end-up-dark-webs-credential-pipeline/

More:

Betanews: What really happens to leaked credentials? https://betanews.com/article/what-really-happens-to-leaked-credentials/ @betanews @iandbarker #infosec #passwords #cybercrime

A security researcher demonstrated that Microsoft Edge stores saved passwords in plaintext memory after launch, making them accessible to malware or attackers with elevated system access.

Read more: https://hackread.com/edge-browser-stores-saved-plaintext-passwords/

#MicrosoftEdge #Cybersecurity #Passwords #Privacy

Researcher Shows Edge Browser Stores Saved Passwords in Plaintext

Cybersecurity expert Tom Rønning finds Microsoft Edge loads all saved passwords into computer memory as cleartext, making them easy for hackers to steal.

Hackread - Cybersecurity News, Data Breaches, AI and More
Happy Password Day! Do you have a favorite password? Share it with hashtag #passwords. 🤪

RE: https://bsky.app/profile/did:plc:siul2ctdwvvrzfnfhyunmgvh/post/3mlbbxyk3ko23

In honor of #WorldPasswordDay, I looked at the Internet exposure of 5 different password manager products with web-accessible vaults.

Vaultwarden was the most popular by far (62% of instances observed), followed by Passbolt and Bitwarden.

I did a deeper dive on Vaultwarden and Bitwarden and was surprised to see how relatively current these instances were:

+ 64% of Bitwarden instances appear to be running a version ~6 months old or newer
+ 65% of Vaultwarden instances appear to be ~5 months old or newer

Read more:

https://censys.com/blog/password-manager-infrastructure/

#passwords #vaultwarden #bitwarden #passbolt

Password Manager Infrastructure in the Wild: Surveying Prevalence, Internet Footprint, and Exposure - Censys

Censys ARC examined the Internet footprint of five different password managers and found over 31,000 instances online. Here's what we learned.

Censys

Microsoft Edge Stores Passwords in Process Memory, Posing Enterprise Risk

An attacker with administrative privileges can gain access to Microsoft Edge user passwords even when they're not in use, because the browser stores them in cleartext in process memory as part of a design decision by Microsoft.

#microsoft #edge #password #passwords #security #cybersecurity #hackers #hacking

https://www.darkreading.com/cyber-risk/microsoft-edge-passwords-enterprise-risk

Microsoft Edge Stores Passwords in Process Memory, Posing Risk

Proof-of-concept exploit (PoC) shows how someone with admin privileges can exploit the bug to steal passwords, and use them for further malicious activity.

Dark Reading
Microsoft Edge security alert: All saved passwords unencrypted | Proton

Microsoft Edge keeps all saved passwords in plaintext memory instead of encrypting them. Here’s what you risk and what you should do instead.

Proton

A famous hacker who was on the FBI most wanted list used his cat’s name as his password, followed by ‘123.’

Happy World Password Day!

https://topicaltens.blogspot.com/2026/05/6-may-passwords.html

#WorldPasswordDay #Passwords

6 May: Passwords

The first Thursday in May is World Password Day. Here are ten facts about passwords. The first passwords were spoken words, used, oft...

Topical Tens

This dumb password rule is from College Board.

Password must be 9-30 characters with at least one upper case letter, one lower case letter, one number and one special character (no spaces) and be different than your username.

https://dumbpasswordrules.com/sites/college-board/

#password #passwords #infosec #cybersecurity #dumbpasswordrules

College Board - Dumb Password Rules

Password must be 9-30 characters with at least one upper case letter, one lower case letter, one number and one special character (no spaces) and be different than your username.