Proton Pass password manager follows the bad practice of keeping unencrypted usernames and passwords in the computer’s memory.
To make matters worse, this sensitive data is not wiped from the memory when the vault is locked post-login, making it susceptible to exfiltration by info-stealer malware or attackers with physical access to the target machine
Seems they promised this would be fixed BUT several updates later still no fix
https://restoreprivacy.com/proton-pass-retains-passwords-in-cleartext-form-in-memory
@ecksmc
Good morning Eric. Thank you for these super informative posts!!
@Esther morning 😊
@ecksmc 😲
i'm still 🤣 at the fact they fixed it then reintroduced it
wtf 🤣