Password Box behaviour in Edge

Fixed, not yet flighted Issue #7339969

Details

Author
lucien t.
Created
Apr 26, 2016
Privacy
This issue is public.
Reports
Reported by 1 person

Sign in to watch or report this issue.

Steps to reproduce

Environment:

Any login/password web page

Background

I often use CTRL-Shift-Arrow to select words, the copy command obviously doesn’t work but in Edge, it Does show me something, when selecting something.

Action

This is what I do:

  • Put my cursor on the end of the **** in the password box
  • Use ctrl-shift-arrow-left to select

results

Normal case:

Password: test123
Result: entire box selected

special character in password

Password: test123!
Result: last letter selected

Apply action once more, entire word selected.

verify suspected behaviour

Password: aa!!aa!!aa!!
Result: last two letters selected
Expanding the selection piece by piece, I need to use ctrl-shift-arrow six times to select the entireword.

vulnerability

While this does not show much it does give me information about the password:

It shows me how often a switch between Alphanumeric and “special” characters happens in a password.

By itself not a huge piece of information, but a piece of the puzzle
Especially if your password is “Mycatsname!” or something of the form.

Anyways; it might be something to look at

Attachments

0 attachments

    Comments and activity

    • Microsoft Edge Team

      Changed Assigned To to “Rick J.”

      Changed Assigned To to “Amit J.”

    • This bug has been fixed. The change should be available in the upcoming Windows Insider build.

    • Microsoft Edge Team

      Changed Status to “Fixed, not yet flighted”

    • This bug has been fixed. The change should be available in the upcoming Windows Insider build.  Marking as a duplicate of the internal deliverable.

      Thank you for your feedback. Looking forward to more going forward.

      All the best,
      The MS Edge Team

    You need to sign in to your Microsoft account to add a comment.

    Sign in