View Single Post
Old 19-10-12, 01:07   #1
Ladybbird
 
Ladybbird's Avatar
 
Join Date: Feb 2011
Posts: 50,566
Thanks: 28,767
Thanked 14,428 Times in 10,234 Posts
Ladybbird has a reputation beyond reputeLadybbird has a reputation beyond reputeLadybbird has a reputation beyond reputeLadybbird has a reputation beyond reputeLadybbird has a reputation beyond reputeLadybbird has a reputation beyond reputeLadybbird has a reputation beyond reputeLadybbird has a reputation beyond reputeLadybbird has a reputation beyond reputeLadybbird has a reputation beyond reputeLadybbird has a reputation beyond repute

Awards Showcase
Best Admin Best Admin Gold Medal Gold Medal 
Total Awards: 8

Default Windows 8 Has Critical Security Flaw

First Critical Windows 8 Security Flaw: Logon Passwords Stored in Plain Text

Softpedia

Decrypting a Windows 8 password is easy, says Passcape

Microsoft says that Windows 8 is the most secure operating system ever, but the first critical security flaw has already been discovered.

Passcape Software developers have discovered that Windows 8 stores user accounts passwords in plain text whenever the user switches to a picture password or a PIN.

As you may know in case you’re a Windows 8 early adopter, the new operating system comes with two new authentication options, allowing users to log in via a picture password or a secure PIN.

“The matter is that these two authentication methods are based on a regular user account. In other words, the user must first have created an account with a regular password and then optionally switch to PIN or picture password authentication. Notably that the original plain-text (!) password to the account also remains in the system,” Passcape wrote in a blog post.

Passwords could, of course, be decrypted and Passcape says that some software solutions especially created in this regard have already been developed.

“Once the user has switched to a new authentication method, his text password is encrypted using the AES algorithm and saved to protected Vault storage in the folder %SYSTEM_DIR%/config/systemprofile/AppData/Local/Microsoft/Vault/4BF4C442-9B8A-41A0-B380-DD4A704DDB28,” the software company explained.

“The text password is not bound to the PIN or picture password; therefore, any user of the PC with the Administrator privileges can easily recover it (the encryption key is protected with system DPAPI).”

Microsoft hasn’t yet commented on the matter, but we’ve contacted the Redmondians for an official statement, so we’ll keep you updated.

__________________
6000 PLUS Cases-He's LOST ALL Heard So Far: TRUMPs Onslaught of Lawyers are 'Hitting a Wall' -Judges & Cases Lining Up Against TRUMP

France To Ask For Statue of Liberty Back -No Longer Fits 'Freedom' Under TRUMP
.. AND Starmers REVOLTING Betrayal of Britain Will NEVER Be Forgiven




TRUMPs' REVENGE -Clear & Present Danger -People Who Worship at The Altar of Trump Will KNEEL, NOT STAND Up to Him

PLEASE Click DONATE & Thanks to ALL Members of ...

1..
Ladybbird is online now   Reply With Quote
The Following User Says Thank You to Ladybbird For This Useful Post:
online24 (19-10-12)