By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
The Tech DiffThe Tech DiffThe Tech Diff
  • Home
  • Shop
  • Computers
  • Phones
  • Technology
  • Wearables
Reading: “Senator Criticizes Microsoft for Default Windows Kerberoasting Vulnerability”
Share
Font ResizerAa
The Tech DiffThe Tech Diff
Font ResizerAa
  • Computers
  • Phones
  • Technology
  • Wearables
Search
  • Home
  • Shop
  • Computers
  • Phones
  • Technology
  • Wearables
Follow US
  • Shop
  • About
  • Contact
  • Terms & Conditions
  • Privacy Policy
© Copyright 2022. All Rights Reserved By The Tech Diff.
The Tech Diff > Blog > Technology > “Senator Criticizes Microsoft for Default Windows Kerberoasting Vulnerability”
Technology

“Senator Criticizes Microsoft for Default Windows Kerberoasting Vulnerability”

Admin
Last updated: September 11, 2025 2:08 am
Admin
Share
“Senator Criticizes Microsoft for Default Windows Kerberoasting Vulnerability”
SHARE

Contents
Concerns Over Security PracticesThe Vulnerability of RC4Exploiting Misconfiguration

A prominent US senator has called on the Federal Trade Commission (FTC) to investigate Microsoft for what he described as “gross cybersecurity negligence.” This urgent request comes in light of the company’s continued use of the outdated RC4 encryption cipher as the default setting on Windows.

-87% Top Wireless Earbuds: ENC Noise Canceling & Bass Boosted!
Headphones

Top Wireless Earbuds: ENC Noise Canceling & Bass Boosted!

$199.99 Original price was: $199.99.$25.99Current price is: $25.99.
Buy Now
-36% Soundcore Q20i: Wireless ANC Headphones with Big Bass & 40H Playtime!
Headphones

Soundcore Q20i: Wireless ANC Headphones with Big Bass & 40H Playtime!

$69.99 Original price was: $69.99.$44.99Current price is: $44.99.
Buy Now
-92% 80Hrs Wireless Earbuds: Rose Gold Bluetooth for Active Lifestyles!
Headphones

80Hrs Wireless Earbuds: Rose Gold Bluetooth for Active Lifestyles!

$299.99 Original price was: $299.99.$22.99Current price is: $22.99.
Buy Now
-15% Experience Studio Sound: OneOdio A71 Hi-Res Headphones!
Headphones

Experience Studio Sound: OneOdio A71 Hi-Res Headphones!

$34.99 Original price was: $34.99.$29.74Current price is: $29.74.
Buy Now

In a detailed letter to FTC Chairman Andrew Ferguson, Senator Ron Wyden (D–Ore.) referred to an investigation conducted by his office which looked into the 2024 ransomware breach of healthcare giant Ascension. This catastrophic breach compromised the medical records of approximately 5.6 million patients and was attributed directly to the use of the vulnerable RC4 encryption cipher.

Concerns Over Security Practices

This isn’t the first time Wyden has expressed concern regarding Microsoft’s security measures. In fact, he has once again labeled their actions as “negligence.” According to Wyden, “because of dangerous software engineering decisions by Microsoft, which the company has largely hidden from its corporate and government customers, a single individual at a hospital or other organization clicking on the wrong link can quickly result in an organization-wide ransomware infection.”

The Vulnerability of RC4

RC4, or Rivest Cipher 4, was created by cryptographer Ron Rivest in 1987. Initially, it was a proprietary cipher until it became publicly documented in 1994. Soon after, significant vulnerabilities were discovered, rendering RC4 susceptible to cryptographic attacks. Despite this, the algorithm remained in widespread use within popular encryption protocols such as SSL and TLS until around a decade ago.

Despite the advancements in encryption technology, Microsoft continues to rely on RC4 as the default encryption method for Active Directory, a crucial Windows component that manages user accounts within large organizations. Many entities do not activate stronger encryption options available in Windows, causing Active Directory authentication to revert to the insecure Kerberos method that employs RC4.

Exploiting Misconfiguration

Cryptography expert Matt Green from Johns Hopkins University has pointed out that the persistent support for Kerberos alongside RC4, compounded by common misconfigurations, exposes networks to a type of attack known as kerberoasting. This attack technique employs offline password-cracking strategies against Kerberos-protected accounts that are not using stronger encryption methods. Kerberoasting has been a known vulnerability since 2014, yet it continues to threaten organizations relying on outdated security protocols.

As the cybersecurity landscape evolves, it becomes imperative for tech giants like Microsoft to prioritize robust security measures that protect sensitive information. The consequences of negligence in this domain can be dire, affecting millions and undermining public trust in technology companies.

For further information, you can read more about this issue here.

Image Credit: arstechnica.com

You Might Also Like

“Kids Choosing Landlines Over Smartphones: The Surprising New Trend”

“Visa Crackdowns Force Indian Students to Reroute Study Abroad Plans”

“SMS Phishing Scams Often Originating From Devices Like This”

Ubisoft Unveils Vantage Studios for Major Franchise Development

“TikTok Control: Concerns Over US and China Influence Rise”

Share This Article
Facebook Twitter Copy Link Print
Previous Article Shokz OpenFit 2: Ideal for Runners, Unfit for General Consumers Shokz OpenFit 2: Ideal for Runners, Unfit for General Consumers
Next Article iPhone 17 Pro: Why Its Chunky Camera Bar Matters iPhone 17 Pro: Why Its Chunky Camera Bar Matters
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Product categories

  • Computer & Accessories
  • Headphones
  • Laptops
  • Phones
  • Wearables

Trending Products

  • Unleash Sound: Philips Audio SHP9500 HiFi Over-Ear Headphones! Unleash Sound: Philips Audio SHP9500 HiFi Over-Ear Headphones! $99.99 Original price was: $99.99.$79.98Current price is: $79.98.
  • Smart Watches for Men: 1.46″ Fitness Tracker with GPS & More! Smart Watches for Men: 1.46" Fitness Tracker with GPS & More! $49.99
  • Ultimate Gaming Bundle: Hornet RX-250 – Key & Headset Set! Ultimate Gaming Bundle: Hornet RX-250 - Key & Headset Set! $49.91 Original price was: $49.91.$39.99Current price is: $39.99.
  • Unleash Soundcore P30i: Ultimate Noise Cancelling Earbuds! Unleash Soundcore P30i: Ultimate Noise Cancelling Earbuds! $49.99 Original price was: $49.99.$29.99Current price is: $29.99.
  • Panasonic Lets Note CF-FV4SDHMBM: Power Meets Portability! Panasonic Lets Note CF-FV4SDHMBM: Power Meets Portability! $1,861.25

You Might also Like

“Automating Science: Former OpenAI and DeepMind Researchers Secure 0M Seed Funding”
Technology

“Automating Science: Former OpenAI and DeepMind Researchers Secure $300M Seed Funding”

Admin Admin 4 Min Read
AI Model Maintains Focus for 30 Hours on Complex Multistep Tasks
Technology

AI Model Maintains Focus for 30 Hours on Complex Multistep Tasks

Admin Admin 4 Min Read
“55 Must-Grab Deals Ahead of Amazon’s Fall Prime Day”
Technology

“55 Must-Grab Deals Ahead of Amazon’s Fall Prime Day”

Admin Admin 3 Min Read

About Us

At The Tech Diff, we believe technology is more than just innovation—it’s a lifestyle that shapes the way we work, connect, and explore the world. Our mission is to keep readers informed, inspired, and ahead of the curve with fresh updates, expert insights, and meaningful stories from across the digital landscape.

Useful Link

  • Shop
  • About
  • Contact
  • Terms & Conditions
  • Privacy Policy

Categories

  • Computers
  • Phones
  • Technology
  • Wearables

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

We don’t spam! Read our privacy policy for more info.

Check your inbox or spam folder to confirm your subscription.

The Tech DiffThe Tech Diff
Follow US
© Copyright 2022. All Rights Reserved By The Tech Diff.
Welcome Back!

Sign in to your account

Lost your password?