Tech

Microsoft RDP apparently lets you log in with expired passwords – and it apparently doesn’t have plans to fix the issue

Share
Share


  • Security researcher Daniel Wade discovers worrying Microsoft RDP feature
  • This allows old credentials to be used when logging in
  • Microsoft has confirmed it has no plans to change this

Security researcher Daniel Wade has discovered a protocol within Microsoft’s Remote Desktop Protocol (RDP), which allows users to log into machines using revoked passwords.

Wade’s report warns “this isn’t just a bug. It’s a trust breakdown,” reminding Microsoft that people change their passwords trusting that this will “cut off unauthorized access”, making this feature entirely counter-intuitive. Wade cautioned “millions of users—at home, in small businesses, or hybrid work setups—are unknowingly at risk.

Share

Leave a comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Related Articles
Old smartphones become working data servers in sustainable tech project from Estonia
Tech

Old smartphones become working data servers in sustainable tech project from Estonia

Old smartphones could be reused to support data collection and analysis University...

Researchers develop ultra-low noise, high sensitivity photodetector
Tech

Researchers develop ultra-low noise, high sensitivity photodetector

OPDs using 2PACz and 3PAFCN electronic blocking layers were tested under simulated...

AI-driven personalized pricing may not help consumers
Tech

AI-driven personalized pricing may not help consumers

Credit: Mikhail Nilov from Pexels The autonomous nature and adaptability of artificial...