Comment on Windows RDP lets you log in using revoked passwords. Microsoft is OK with that. - Ars Technica
taladar@sh.itjust.works 3 days agoYeah, but “some cases” is extremely vague. If it is indeed cached indefinitely under all circumstances I would expect changed passwords to never work at all.
SL3wvmnas@discuss.tchncs.de 3 days ago
In typical MS fashion this might be very hard to debug with the hundreds of interacting components./s
In all seriousness they reviewed their internal docs not even the code (likely because it’s extremely complex) and said fixing this would brake existing functionality. I think “some cases” is doing heavy lifting for “we know many cases, but won’t tell the bad guys out there”.