Technologist Mag
  • Home
  • Tech News
  • AI
  • Apps
  • Gadgets
  • Gaming
  • Guides
  • Laptops
  • Mobiles
  • Wearables
  • More
    • Web Stories
    • Trending
    • Press Release

Subscribe to Updates

Get the latest tech news and updates directly to your inbox.

What's On
FBI Agent’s Sworn Testimony Contradicts Claims ICE’s Jonathan Ross Made Under Oath

FBI Agent’s Sworn Testimony Contradicts Claims ICE’s Jonathan Ross Made Under Oath

12 January 2026
This ,600 discount makes a 98-inch QLED TV much easier to justify

This $1,600 discount makes a 98-inch QLED TV much easier to justify

12 January 2026
Peter Molyneux’s Final Game, Masters Of Albion, Gets April Release Date

Peter Molyneux’s Final Game, Masters Of Albion, Gets April Release Date

12 January 2026
GoFundMe Ignores Own Rules by Hosting a Legal-Defense Fund for the ICE Agent Who Killed Renee Good

GoFundMe Ignores Own Rules by Hosting a Legal-Defense Fund for the ICE Agent Who Killed Renee Good

12 January 2026
Snag a Feature-Packed Gaming Headset for Under 0

Snag a Feature-Packed Gaming Headset for Under $100

12 January 2026
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram
Technologist Mag
SUBSCRIBE
  • Home
  • Tech News
  • AI
  • Apps
  • Gadgets
  • Gaming
  • Guides
  • Laptops
  • Mobiles
  • Wearables
  • More
    • Web Stories
    • Trending
    • Press Release
Technologist Mag
Home » Microsoft Will Finally Kill an Encryption Cipher That Enabled a Decade of Windows Hacks
Tech News

Microsoft Will Finally Kill an Encryption Cipher That Enabled a Decade of Windows Hacks

By technologistmag.com17 December 20253 Mins Read
Microsoft Will Finally Kill an Encryption Cipher That Enabled a Decade of Windows Hacks
Share
Facebook Twitter Reddit Telegram Pinterest Email
Microsoft Will Finally Kill an Encryption Cipher That Enabled a Decade of Windows Hacks

Microsoft is killing off an obsolete and vulnerable encryption cipher that Windows has supported by default for 26 years. This follows more than a decade of devastating hacks that exploited it and recent blistering criticism from a prominent US senator.

When the software maker rolled out Active Directory in 2000, it made RC4 a sole means of securing the Windows component, which administrators use to configure and provision fellow administrator and user accounts inside large organizations. RC4, short for Rivist Cipher 4, is a nod to mathematician and cryptographer Ron Rivest of RSA Security, who developed the stream cipher in 1987. Within days of the trade-secret-protected algorithm being leaked in 1994, a researcher demonstrated a cryptographic attack that significantly weakened the security it had been believed to provide. Despite the known susceptibility, RC4 remained a staple in encryption protocols, including SSL and its successor TLS, until about a decade ago.

Out With the Old

One of the most visible holdouts in supporting RC4 has been Microsoft. Eventually, Microsoft upgraded Active Directory to support the much more secure AES encryption standard. But by default, Windows servers have continued to respond to RC4-based authentication requests and return an RC4-based response. The RC4 fallback has been a favorite weakness hackers have exploited to compromise enterprise networks. Use of RC4 played a key role in last year’s breach of health giant Ascension. The breach caused life-threatening disruptions at 140 hospitals and put the medical records of 5.6 million patients into the hands of the attackers. US senator Ron Wyden, an Oregon Democrat, in September called on the Federal Trade Commission to investigate Microsoft for “gross cybersecurity negligence,” citing the continued default support for RC4.

“By mid-2026, we will be updating domain controller defaults for the Kerberos Key Distribution Center (KDC) on Windows Server 2008 and later to only allow AES-SHA1 encryption,” Matthew Palko, a Microsoft principal program manager, wrote. “RC4 will be disabled by default and only used if a domain administrator explicitly configures an account or the KDC to use it.”

AES-SHA1, an algorithm widely believed to be secure, has been available in all supported Windows versions since the rollout of Windows Server 2008. Since then, Windows clients by default authenticated using the much more secure standard, and servers responded using the same. But, Windows servers, also by default, respond to RC4-based authentication requests and returned an RC4-based response, leaving networks open to Kerberoasting.

Following next year’s change, RC4 authentication will no longer function unless administrators perform the extra work to allow it. In the meantime, Palko said, it’s crucial that admins identify any systems inside their networks that rely on the cipher. Despite the known vulnerabilities, RC4 remains the sole means of some third-party legacy systems for authenticating to Windows networks. These systems can often go overlooked in networks even though they are required for crucial functions.

Share. Facebook Twitter Pinterest LinkedIn Telegram Reddit Email
Previous ArticleApple’s next iPad mini could take a big leap in performance and visual experience
Next Article Dispatch Is Seemingly Heading To Switch, According To Australian Nintendo Eshop Listing

Related Articles

FBI Agent’s Sworn Testimony Contradicts Claims ICE’s Jonathan Ross Made Under Oath

FBI Agent’s Sworn Testimony Contradicts Claims ICE’s Jonathan Ross Made Under Oath

12 January 2026
This ,600 discount makes a 98-inch QLED TV much easier to justify

This $1,600 discount makes a 98-inch QLED TV much easier to justify

12 January 2026
GoFundMe Ignores Own Rules by Hosting a Legal-Defense Fund for the ICE Agent Who Killed Renee Good

GoFundMe Ignores Own Rules by Hosting a Legal-Defense Fund for the ICE Agent Who Killed Renee Good

12 January 2026
Snag a Feature-Packed Gaming Headset for Under 0

Snag a Feature-Packed Gaming Headset for Under $100

12 January 2026
You can now pre-order Anker’s Solix E10 smart hybrid home backup system

You can now pre-order Anker’s Solix E10 smart hybrid home backup system

12 January 2026
Right-Wing Influencers Have Flooded Minneapolis

Right-Wing Influencers Have Flooded Minneapolis

12 January 2026
Stay In Touch
  • Facebook
  • Twitter
  • Pinterest
  • Instagram
  • YouTube
  • Vimeo

Subscribe to Updates

Get the latest tech news and updates directly to your inbox.

Don't Miss
This ,600 discount makes a 98-inch QLED TV much easier to justify

This $1,600 discount makes a 98-inch QLED TV much easier to justify

By technologistmag.com12 January 2026

A 98-inch TV is one of those purchases that instantly turns “watching something” into an…

Peter Molyneux’s Final Game, Masters Of Albion, Gets April Release Date

Peter Molyneux’s Final Game, Masters Of Albion, Gets April Release Date

12 January 2026
GoFundMe Ignores Own Rules by Hosting a Legal-Defense Fund for the ICE Agent Who Killed Renee Good

GoFundMe Ignores Own Rules by Hosting a Legal-Defense Fund for the ICE Agent Who Killed Renee Good

12 January 2026
Snag a Feature-Packed Gaming Headset for Under 0

Snag a Feature-Packed Gaming Headset for Under $100

12 January 2026
You can now pre-order Anker’s Solix E10 smart hybrid home backup system

You can now pre-order Anker’s Solix E10 smart hybrid home backup system

12 January 2026
Technologist Mag
Facebook X (Twitter) Instagram Pinterest
  • Privacy
  • Terms
  • Advertise
  • Contact
© 2026 Technologist Mag. All Rights Reserved.

Type above and press Enter to search. Press Esc to cancel.