this post was submitted on 06 May 2026
744 points (98.7% liked)

Technology

84478 readers
3583 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


founded 2 years ago
MODERATORS
top 50 comments
sorted by: hot top controversial new old
[–] JackbyDev@programming.dev 20 points 2 days ago (7 children)

This is sort of like saying "I leave my valuables in plain sight by my door because it has a lock on it and door locks are trustworthy." I'm not super into cyber security and stuff but it seems like one of the most common problems is programs managing to get access to memory they shouldn't have access to. It seems to happen all the time! Just like many locks for you door are trash.

[–] quack@lemmy.zip 5 points 2 days ago

Defense in depth is a concept they teach you in cybersecurity 101. But that's expensive and time consuming, so you end up with shit like this.

[–] partofthevoice@lemmy.zip 2 points 2 days ago* (last edited 2 days ago)

It’s ridiculous. It presupposes that cybersecurity doesn’t value or employ defense in depth. Completely untrue.

Look at the attack vector researchers were trying to solve when they created OAuth2.0 w/ PKCE.

load more comments (5 replies)
[–] pwxd@lemmy.zip 18 points 2 days ago (1 children)

"Yeah totally secure! Just trust me!.." basically

This is LITERALLY isn't secure; they should atleast make it encrypted. This is just the same as using your notes app as password manager! But it's microsoft, and they're willingly giving your bitlocker encryption key to the FBIs for your drives. So I'm not surprised..

[–] Rooster326@programming.dev 6 points 2 days ago* (last edited 2 days ago)

I feel it may be worse than using your notes app.

A malicious attack doesn't know which notes app, nor the filename.

This has every browser opening the exact same passwords.txt in root.

[–] GreenBeanMachine@lemmy.world 58 points 3 days ago (1 children)

That's the added trust and security they always boast about

[–] Alberat@lemmy.world 12 points 3 days ago

trust is multiplicative, not additive

[–] baronvonj@piefed.social 168 points 3 days ago (2 children)

Microsoft SSH agent persistently stores your unencrypted private keys in the registry. They're still there unlocked and usable after you reboot.

https://github.com/PowerShell/Win32-OpenSSH/issues/1487

[–] mbp@slrpnk.net 30 points 3 days ago (1 children)

God, the final comment in that thread makes my blood boil.

[–] rbos@lemmy.ca 3 points 2 days ago

That is infuriating. Leaving those keys available to the user means that worms can later use you to compromise additional machines. It turns a local problem into a much bigger one. There's a recursive script out there that automatically scans your ssh files and attempts to access all hosts in your history..name escapes me at the moment.

load more comments (1 replies)
[–] FosterMolasses@leminal.space 41 points 3 days ago

Everytime I read a Microsoft headline these days

[–] quantumvoid0@programming.dev 103 points 3 days ago (3 children)

does this company intentionally want users to stop using it? cuz day by day either theres a new windows bug or just shittier softwares

[–] Senseless@feddit.org 17 points 3 days ago (1 children)

Not to worry, the next update will fix it. (And make 12 others things worse. Also it will make your printer stop working. Again.)

load more comments (1 replies)
load more comments (2 replies)
[–] Passerby6497@lemmy.world 35 points 3 days ago

Safety and security are foundational to Microsoft Edge. Access to browser data as described in the reported scenario would require the device to already be compromised. Design choices in this area involve balancing performance, usability, and security, and we continue to review it against evolving threats.

"We value user safety and usability, but if you're already compromised you can go fuck yourself"

[–] SeductiveTortoise@piefed.social 26 points 3 days ago
[–] GainGround@kopitalk.net 48 points 3 days ago (1 children)

Our lives are in the hands of morons. What the fuck.

load more comments (1 replies)
[–] fira@lemmy.today 8 points 2 days ago (1 children)
[–] teyrnon@sh.itjust.works 4 points 2 days ago (3 children)

Edge is on my computer, and I can't delete it, at least not with my limited IT experience. It's buried deep in the operating system, and it opens up seemingly randomly, I use firefox.

Looking online about getting rid of it, others described it as cancer.

[–] Benaaasaaas@group.lt 7 points 2 days ago

It's not that hard, all you need is usb drive and choosing a distro (the hard step)

[–] jaykrown@lemmy.world 3 points 2 days ago (1 children)

The solution is to use Linux Mint.

[–] teyrnon@sh.itjust.works 2 points 2 days ago (1 children)

I'm afraid as I am on my backup computer, and I worry that if I try to change over I will not do it correctly as has been the case every single time I've tried to download a program to accept zip files, or torrents I don't know what my deal is.

I really do want to switch over, I am working on fixing my better computer. More than anything I want a graphene OS phone.

[–] jaykrown@lemmy.world 3 points 2 days ago

Good that you want to switch, take your time, don't be afraid. There are many resources online for how to switch without accidentally deleting or losing access to things. I have been using Linux Mint for over a year now switching from Windows 10 and I haven't run into any limitations or issues. It's been a great learning experience and has overall lead to me being more technologically savvy. If you have any questions there are many places to discuss, feel free to ask.

[–] mirshafie@europe.pub 3 points 2 days ago (3 children)

Not sure how it works in Win11 but historically it has not been possible to remove Internet Explorer or Edge from Windows.

[–] teyrnon@sh.itjust.works 2 points 2 days ago

That is an anti-competitive practice and illegal in truth. Against the laws of the United states, the ones that aren't enforced anymore.

load more comments (2 replies)
[–] afporritt1001@lemmy.today 3 points 2 days ago* (last edited 2 days ago)

Fuck Microslop Fuck windows 11

[–] Reygle@lemmy.world 49 points 3 days ago (2 children)

HOLY @#%^ WHAT IN THE @#%^ DO THEY MEAN "NOT TO WORRY"?????????????????

[–] XLE@piefed.social 31 points 3 days ago (1 children)

Well, hold on now, maybe Microsoft has a reasonable explanation for how they actually do secure their passwords...

This is an expected feature of the application.

... Never mind.

[–] JohnAnthony@lemmy.dbzer0.com 12 points 3 days ago (1 children)

Design choices in this area involve balancing performance, usability, and security

Nothing to do with usability since decrypting your passwords one by one is perfectly fine. So they are saying this is about performance ? Holy fuck...

load more comments (1 replies)
load more comments (1 replies)
[–] boogiebored@lemmy.world 7 points 2 days ago

phew it’s an expected feature, thank goodness!!!

if they patch this, they should be dragged through the town square after that comment

[–] 58008@lemmy.world 27 points 3 days ago (12 children)

2026 is gonna be the year I finally move to Linux. I have huge concerns about many aspects of switching, but they're being overtaken by concerns about staying with Windows. I don't even mind if my overall user experience is a bit worse on Linux (I am trying to have reasonable expectations that it won't be the walk in the park Linux advocates on Lemmy like to claim), I just have much more faith in its security, privacy, customisability and - most importantly - the motivations and intentions of its developers.

[–] Bytemeister@lemmy.world 3 points 2 days ago

I switched my mom to Linux because teaching her how to use Linux as her daily driver was easier than trying to unfuck windows on her computer.

Back up your data and then go nuts.

[–] BozeKnoflook@lemmy.world 16 points 3 days ago

Best of luck! If you've got questions or problems feel free to DM me (or reply here) and I'll try to help as best I can. I've been using linux since the mid 90s, so I have a decent idea of how it all works :)

load more comments (10 replies)
[–] BaraCoded@literature.cafe 10 points 3 days ago

How will the NSA spy on you if Microsoft doesn't hand them your passwords?

[–] azvasKvklenko@sh.itjust.works 19 points 3 days ago (1 children)

I don’t worry, I just don’t use Edge or Windows or any MS software really (except for Teams at work)

load more comments (1 replies)
[–] weaponG@lemmy.world 13 points 3 days ago (2 children)

Nothing in this timeline surprises me any more.

load more comments (2 replies)
[–] Quazatron@lemmy.world 18 points 3 days ago (1 children)

Microsoft - So secure we ROT13 encode everything... TWICE!

load more comments (1 replies)
[–] Blackdoomax@sh.itjust.works 7 points 3 days ago

Trust me bro

[–] goatinspace@feddit.org 22 points 3 days ago
[–] zerofk@lemmy.zip 16 points 3 days ago (3 children)

Access to browser data as described in the reported scenario would require the device to already be compromised.

Yes you can open our safe with just a good yank but if a thief can do that they’re already in your house.

load more comments (3 replies)
[–] iglou@programming.dev 15 points 3 days ago* (last edited 3 days ago) (2 children)

Eh. To be honest it indeed does not matter much. Scanning your RAM for passwords is much harder than simply reading them off the browsers files. Sure, it is encrypted and the key is not necessarily on your computer, but remember that if the software can decrypt your passwords without you inputting a password or similar, then anything with access to your device can as well.

Don't use your browser's password manager.

load more comments (2 replies)
[–] darkmogool@feddit.org 14 points 3 days ago

Why did I read "Microsoft Edge lords"?

load more comments
view more: next ›