4 ms·
The plaintext passwords may well be sitting somewhere in memory even on Linux (e.g. see [1]) but I do agree that the organised caching of such passwords in Wind
by quasque 13y ago
The plaintext passwords may well be sitting somewhere in memory even on Linux (e.g. see [1]) but I do agree that the organised caching of such passwords in Windows is a weakness.
I'm quite surprised that LSASS.EXE is not protected in the same manner as AUDIODG.EXE [2]. Just goes to show how DRM protection is considered more important than system security.
[1] http://philosecurity.org/pubs/davidoff-clearmem-linux.pdf http://philosecurity.org/pubs/davidoff-clearmem-linux.pdf
[2] http://msdn.microsoft.com/en-us/library/windows/hardware/gg463417.aspx http://msdn.microsoft.com/en-us/library/windows/hardware/gg4...