Forum Discussion
Autofill in Microsoft Edge
If possible, Elliot Kirk, could you or someone on the team compose a post explaining the security measures that protect the password data? I did considerable research into LastPass before storing my data there, and I'm loathe to change unless I have similar information. How is the sensitive data stored? Is it encrypted at rest? What sort of salting info or other details can be shared about that encryption? Is it only available after a clean authentication to Windows? Is it available for use after Windows login, or only after secondary authentication in Edge? Is it available for viewing/editing after Windows login, or only after secondary authentication in Edge? What does the Microsoft Cyber Security Team think about the capability?
- laalithyaJun 18, 2019Microsoft
David Gibson thanks for the detailed questions and clearly calling out your concerns. Given we are talking about sensitive information here, we believe that security around how this data is stored and accessed is very important. In short, you can view the saved password for a website only upon additional authentication. We will follow up with a detailed post that will address all aspects of security and encryption regarding how your sensitive data is handled in Edge.