Last updated on September 8th, 2018
TrustWave SpiderLabs uncovered a key called “UserPasswordHint” during wider research into how the Redmond operating system stores password hashes. Subsequent studies showed it was easy to extract and decode password hints from the registry on both Windows 7 and Windows 8 machines. The value stored is obscured with the addition of zeros but not encrypted.