Security scientist Daniel Wade discovers worrying Microsoft RDP feature
This makes it possible to use old credentials when logging in
Microsoft has confirmed that it has no plans to change this
Security researcher Daniel Wade has discovered a protocol within Microsoft’s Remote Desktop Protocol (RDP), which allows users to log on to machines using recalled passwords.
Wade’s report warns “This is not just a mistake. It’s a breach of trust” that reminds Microsoft that people are changing their passwords that trust that this will “cut off unauthorized access”, making this feature completely modintuitive. Wade warned “millions of users – at home in small businesses or hybrid work – is unconsciously in danger.