Tech

Microsoft RDP apparently lets you log in with expired passwords – and it apparently doesn’t have plans to fix the issue

Share
Share


  • Security researcher Daniel Wade discovers worrying Microsoft RDP feature
  • This allows old credentials to be used when logging in
  • Microsoft has confirmed it has no plans to change this

Security researcher Daniel Wade has discovered a protocol within Microsoft’s Remote Desktop Protocol (RDP), which allows users to log into machines using revoked passwords.

Wade’s report warns “this isn’t just a bug. It’s a trust breakdown,” reminding Microsoft that people change their passwords trusting that this will “cut off unauthorized access”, making this feature entirely counter-intuitive. Wade cautioned “millions of users—at home, in small businesses, or hybrid work setups—are unknowingly at risk.

Share

Leave a comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Related Articles
Samsung Galaxy Z Flip 7 rumored specs: predictions for every key spec
Tech

Samsung Galaxy Z Flip 7 rumored specs: predictions for every key spec

The Samsung Galaxy Z Flip 7 might not be a comprehensive upgrade...

Agatha Christie’s AI ghost is here to teach you how to kill…at writing mystery stories
Tech

Agatha Christie’s AI ghost is here to teach you how to kill…at writing mystery stories

BBC Maestro has launched a writing course taught posthumously by an AI...

Online shopping is now a bot fest — real users just lost the internet to AI-powered fake shoppers
Tech

Online shopping is now a bot fest — real users just lost the internet to AI-powered fake shoppers

Report warns sophisticated bots mimic human behavior so well outdated defenses don’t...

Is the UK’s energy storage growing fast enough?
Tech

Is the UK’s energy storage growing fast enough?

Credit: Pixabay/CC0 Public Domain Britain’s booming green energy generation has a costly...