Skip to content

Windows 8 stores logon passwords in plain-text

passcape.com
3 pointscschramm3 comments
On HN

Comments

The phrase "stored in plain text" does not mean anything near the same thing as "encrypted with AES in the Windows Vault using the Data Protection API". This story is complete hogwash.

I'm thinking the same thing. These aren't website passwords, they need to be recoverable by an administrator. I'm sure this is by design.

Why do you think they should be recoverable by anyone? You can verify your details against a hash, or reset them anyway.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.