Microsoft Still Uses RC4
Senator Ron Wyden has asked the Federal Trade Commission to investigate Microsoft over its continued use of the RC4 encryption algorithm. The letter talks about a hacker technique called Kerberoasting, that exploits the Kerberos authentication system.
Subscribe to comments on this entry
Wayne • September 16, 2025 9:47 AM
I was reading about this last week and was quite surprised. Kind of amusing that the world is underpinned by MS, and it turns out it’s a deck of cards. I think a lot of us if asked in the ’90s about something like this, we might have said ‘Yeah, probably.’
Microsoft’s fix timetable really needs to be faster, now that this little disaster is known widely. I wonder what, if any, mitigations can be taken to defend against it.