Microsoft Is Finally Killing RC4
好的,我现在需要帮用户总结一篇文章的内容,控制在100字以内,并且不需要特定的开头。首先,我得仔细阅读文章内容,抓住主要信息。 文章讲的是微软在Windows中使用了26年的RC4加密算法终于要升级了。RC4一直是微软支持的最后一个实例,尽管之前已经升级到AES,但默认情况下Windows服务器仍然支持RC4,这导致了很多安全问题,比如去年Ascension医疗集团的数据泄露事件,影响非常严重。 用户的需求是总结内容,所以我要提取关键点:微软升级RC4加密算法,RC4被黑客利用导致安全问题,特别是Ascension事件,以及微软终于弃用RC4的原因是易受Kerberoasting攻击。 接下来,我需要把这些信息浓缩成一句话或两句话,确保不超过100字。同时要注意用词简洁明了。 可能的结构是:微软在Windows中使用了26年的RC4加密算法终于升级。RC4曾被黑客利用导致安全漏洞,例如去年的Ascension事件。微软现在弃用RC4以提升安全性。 检查一下字数是否符合要求,并且确保没有遗漏关键点。最后确认语言流畅自然。 </think> 微软在Windows中使用了26年的RC4加密算法终于升级。该算法曾被黑客利用导致企业网络漏洞,例如去年Ascension医疗集团的数据泄露事件。微软最终弃用RC4以提升安全性。 2025-12-22 17:5:9 Author: www.schneier.com(查看原文) 阅读量:0 收藏

After twenty-six years, Microsoft is finally upgrading the last remaining instance of the encryption algorithm RC4 in Windows.

of the most visible holdouts in supporting RC4 has been Microsoft. Eventually, Microsoft upgraded Active Directory to support the much more secure AES encryption standard. But by default, Windows servers have continued to respond to RC4-based authentication requests and return an RC4-based response. The RC4 fallback has been a favorite weakness hackers have exploited to compromise enterprise networks. Use of RC4 played a key role in last year’s breach of health giant Ascension. The breach caused life-threatening disruptions at 140 hospitals and put the medical records of 5.6 million patients into the hands of the attackers. US Senator Ron Wyden (D-Ore.) in September called on the Federal Trade Commission to investigate Microsoft for “gross cybersecurity negligence,” citing the continued default support for RC4.

Last week, Microsoft said it was finally deprecating RC4 and cited its susceptibility to Kerberoasting, the form of attack, known since 2014, that was the root cause of the initial intrusion into Ascension’s network.

Fun fact: RC4 was a trade secret until I published the algorithm in the second edition of Applied Cryptography in 1995.

Tags: , , , , ,

Posted on December 22, 2025 at 12:05 PM1 Comments

Sidebar photo of Bruce Schneier by Joe MacInnis.


文章来源: https://www.schneier.com/blog/archives/2025/12/microsoft-is-finally-killing-rc4.html
如有侵权请联系:admin#unsafe.sh