Microsoft Edge goes homomorphic: Nobody will see your credentials... but you'll need to sign in to use it
- Reference: 1611328032
- News link: https://www.theregister.co.uk/2021/01/22/edge_password_monitor/
- Source link:
The release follows the recent first anniversary of [3]Chromium-based Edge emerging from preview. The Password Monitor feature was rolled out in an update tilted towards "transparency and control."
[4]
The Password Monitor technology had already been [5]made available to Insiders during 2020 and notifies users in the event their saved passwords are found in a third-party breach.
While such technology has been a mainstay of other browsers and password managers, Microsoft's [6]twist is to ensure that neither Microsoft itself, nor anyone else, can learn a user's passwords. This is achieved through the use of homomorphic encryption – performing actions on encrypted data without decrypting it first.
[7]
It's a neat feature that means, since the data remains encrypted, neither Microsoft nor miscreants-in-the-middle can read a user's credentials.
As well as password monitoring, a more traditional Password Generator has turned up in the release alongside improved controls for which websites have access to the user's location, microphone, and camera. Other browsers, such as Google's Chrome, make these settings available too.
It has also been made easier to enable tracking prevention in Strict mode while InPrivate because "No one wants a personalized ad based on browsing history ruining all the fun," said Microsoft, using the example of a surprise gift's recipient perhaps seeing an ad over the user's shoulder. Secure DNS (using HTTPS to connect to DNS service provider) is also in the release.
While the focus on privacy and security is laudable, some might be disappointed to learn that in order to use Password Monitor (which is only available on Windows 7/8/10 at present), a user must be signed into Edge with a work, school, or personal Microsoft account.
[8]
The password generator similarly requires sign-in, and password sync must be turned on. On the plus side, it will work on macOS. ®
Get our [9]Tech Resources
[1] https://blogs.windows.com/msedgedev/2021/01/21/edge-88-privacy/
[2] https://docs.microsoft.com/en-us/deployedge/microsoft-edge-release-schedule
[3] https://www.theregister.com/2020/01/15/microsofts_edge_chromium/
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YAsEpdsq5d3E0FRKyHuUQQAAAM4&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[5] https://techcommunity.microsoft.com/t5/articles/password-monitor-is-now-available-in-microsoft-edge-preview/m-p/1499656
[6] https://www.microsoft.com/en-us/research/blog/password-monitor-safeguarding-passwords-in-microsoft-edge/
[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YAsEpdsq5d3E0FRKyHuUQQAAAM4&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YAsEpdsq5d3E0FRKyHuUQQAAAM4&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[9] https://whitepapers.theregister.com/
On the plus side, it will work on macOS.
I am sure those two Edge on MacOS users will appreciate the feature. :)
Huh?
What am I missing? I have been writing software for decades that only stores a hash of the passwords given it, and when the user inputs a password to gain access, the hash of the candidate password is compared to the hash of the real password. This has been standard practice everywhere I have worked since the dawn of time. This is considered new & innovative?
Re: Huh?
Wahey! I'm an innovative software developer who's way ahead of the infosec curve
A+B --> C
[1]Alice and Bob in Cipherspace
[1] https://www.americanscientist.org/article/alice-and-bob-in-cipherspace
Haven't we seen this before?
Password manager manages your passwords then they get the password to your password manager and you get ruined.
So no thank you, I know how this story ends.
"Microsoft's twist"
Erm, unless I'm missing something, hasn't Firefox [1]been doing something like this with email addresses for two and a half years ? And [2]haveibeenpwned has certainly been doing it with passwords for quite a while . In any case, it's a bit of a stretch to call it a "twist" like they've had some magic new idea.
[1] https://www.theregister.com/2018/06/27/firefox_monitoring_haveibeenpwned/
[2] https://www.troyhunt.com/ive-just-launched-pwned-passwords-version-2/#cloudflareprivacyandkanonymity
Just choose a decent password and you will be OK without these "features" ... my default password is "badpassword" it's never been hacked, if it's ever hacked all I would have to do is drop the "p" and continue... I'm posting anonymously to protect my username and keep the password safe..
badassword
And if that got hacked you could swap to the UK spelling:- “badarseword”.
All your web viewing habits
are belong to M$.