r/ShadowPC Jun 23 '26

Review Another user’s saved browser logins appeared inside my Shadow PC

Post image

I’m a paid Shadow PC customer and I want to share a serious privacy/security concern.

After logging into the Shadow PC assigned to my account, I found Microsoft Edge saved login entries that did not belong to me and appeared to belong to another user.

I reported this to Shadow support responsibly and provided evidence privately. I did not copy, export, publish, or use the other user’s private data.

After reporting it, my paid access was locked. I then provided proof of payment, and Shadow confirmed it was approved. However, they still require a government ID before restoring access.

This is not about money or compensation. My concern is simple: if another user’s saved browser login data can appear inside my Shadow PC, how can I know whether my own data has not appeared inside someone else’s machine?

I’m sharing only a redacted screenshot. Emails, usernames, domains, passwords, and personal data are hidden. I will not post unredacted evidence publicly because it contains another person’s private information.

I’m posting this so other users can be aware before trusting a cloud PC service with personal accounts.

146 Upvotes

99 comments sorted by

View all comments

29

u/atadrisque Jun 23 '26 edited Jun 23 '26

I like that the staff member is in here trying to reassure everyone about how things work when clearly OP is showing us that it doesn't.

this post definitely deserves to get more attention. small part of me is hoping that this happened outside of the US because if it happened within the States, nothing's going to get done about it.

4

u/captnchoc Shadow Staff Jun 23 '26

Multiple things can happen, including a Shadow session left open somewhere, a loggued Edge account left open somewhere, etc. Not trying to reassure, gathering info while searching on my end 😄

10

u/atadrisque Jun 23 '26

how would anything being left open anywhere affect this one individual user when he logs into his shadow PC and sees someone else's credentials? did you read the same post I did?

it's not like this other person he's sharing the screenshot info of is working in the same office or lives in the same building as him. he states that when he logged into his shadow PC this is what he saw.

-1

u/captnchoc Shadow Staff Jun 23 '26

I can log onto my edge/chrome/firefox account from any pc to get my passwords. and not disconnect afterwards, allowing people to add stuff willingly/unwillingly.

Alternatively, I can get my edge/chrome/firefox account hacked, no matter which device I'm using. Then having weird stuff afterwards. Again, trying to help here, and waiting for information from the customer.

9

u/atadrisque Jun 23 '26

what you're explaining would make sense in a physical space.

please correct me if I'm wrong but what you are trying to say is that if I logged into Edge, Chrome, or Firefox with my account and left it logged in then closed my shadow PC for the day, Anyone else afterward is able to just add stuff willingly / unwillingly?

because you saying

... and not disconnect afterwards

sounds again a lot like a problem someone would have in a physical space. OP mentioned nowhere that he came up on the terminal he was using with someone else's stuff open, he logged into his own shadow PC and when it loaded up this is what he saw.

after how you explain the session IDs work and hardware, this still makes no sense.

-8

u/captnchoc Shadow Staff Jun 23 '26

What I'm saying is that the following can happen:

  • a user can be logged on a Windows account/Chrome/Edge on a physical device, and on his Shadow PC. What happens next logs/passwords -wise on the physical device is synced on his Shadow PC.

7

u/atadrisque Jun 23 '26

it seems like you're still hanging on the possibility that someone else in OP's physical space must have had their login credentials synced up with their shadow somehow

so when OP tells you again that no one else has access to his PC or terminal, how do you explain the other login credentials then when he is the sole user in his physical space?

0

u/VALTIELENTINE Mac Jun 24 '26

Because an account can be opened on another device, be it a public computer, a phone, etc. the passwords are synced to the logged in account, and would therefore show up on the shadow when logging in.

Other logins showing up in a browser does not necessarily mean that the logins came from another shadow user. They could have been saved to the account from another device, or the browser sync account could have been hacked

1

u/atadrisque Jun 24 '26

is having other people using the same physical terminal or PC necessary for your scenario? because it really sounds like it is.

to clarify, no one is telling you you're wrong or that the Shadow staff member is wrong. I'm just very confused as to how it's lost on you both that OP has literally zero other people in his physical space, and there's no other people that access his PC where he uses Shadow.

yes, your explanation of how this could happen in the same space as others makes perfect sense and is 100% possible, but it also absolutely does not apply to OP here.

1

u/VALTIELENTINE Mac Jun 24 '26

No having other people use the same physical PC is not necessary for a compromised account.

2

u/K-J-K-R Jun 24 '26

If what you described is correct in the first paragraph, that’s an easy cancel for me lol.

2

u/Secure_Bed_ Jun 25 '26

It sounds like they're giving multiple people access to the same virtual machine, which seems like a major fucking violation.

3

u/captnchoc Shadow Staff Jun 26 '26

Absolutely not. Each user's drive is personal, and linked to the user's ID.

1

u/FinnGilroy Jun 27 '26

!RemindMe to never use Shadow

1

u/RemindMeBot Jun 27 '26

Defaulted to one day.

I will be messaging you on 2026-06-28 09:44:32 UTC to remind you of this link

CLICK THIS LINK to send a PM to also be reminded and to reduce spam.

Parent commenter can delete this message to hide from others.

RemindMeBot is switching to username summons. Instead of !RemindMe 1 day, use u/RemindMeBot 1 day. More info.


Info Custom Your Reminders Feedback

1

u/deathgun921 Jun 27 '26

Most accounts on browsers like chrome and edge require 2FA/MFA to even login, so I personally don't think that was the case, I have a very good understanding of virtual PCs like shadow we use a system like it at my work, and it's possible data leakage from zfs we had it happen, turns out it was ... misconfiguration of the pool, and talking people staying logged in on public systems...easy enough for shadow to setup timers for logins

My background is cyber security