Proton Pass Retains Passwords in Cleartext Form in Memory

[correlate]

Level 18
Thread author
Verified
Top Poster
Well-known
Forum Veteran
May 4, 2019
792
9,574
1,670
New York
The Proton Pass password manager follows the bad practice of keeping unencrypted usernames and passwords in the computer’s memory.
To make matters worse, this sensitive data is not wiped from the memory when the vault is locked post-login, making it susceptible to exfiltration by info-stealer malware or attackers with physical access to the target machine.
 
Hard to believe the good folks over at CERN and Proton AG would allow one of their applications to do something as such, but is a reminder of why i do not trust many password manager applications now days.
 
what's the current version and has Proton fixed this memory security faux pas (pardon my French)
 
  • Thanks
Reactions: simmerskool