TECH ROUNDUP

Microsoft is set to deprecate the insecure RC4 encryption algorithm.

Microsoft Sắp Khai Tử Thuật Toán Mã Hóa Rc4 Kém Bảo Mật

In a significant move to bolster cybersecurity for the Windows ecosystem, Microsoft has officially confirmed plans to completely phase out default support for the RC4 encryption algorithm. This stream cipher was first introduced by the software giant in Windows 2000 as the default authentication algorithm for Active Directory services. However, after decades of existence accompanied by countless warnings regarding security vulnerabilities, Redmond has finally decided to “retire” this aging technology in the coming months, ending a long era of this risky security standard.

The Vulnerable History of the RC4 Encryption Algorithm

Recently, Microsoft officially confirmed that they are taking the final steps to discontinue the use of RC4, the encryption method used by the Kerberos authentication protocol over the past three decades. To better understand the origins of this technology, we must go back to 1987, when mathematician Ron Rivest developed Rivest Cipher 4 (RC4). Although it was once a popular standard, the algorithm was actually deemed vulnerable to attacks as early as 1994, when this secret algorithm was leaked to the public.

Mr. Matthew Palko, a Microsoft Principal Program Manager, spoke candidly about this issue. He acknowledged that while RC4 once provided significant benefits in terms of system compatibility, it has long become the “Achilles’ heel” of security systems due to its vulnerability to a dangerous attack method known as “Kerberoasting.” The combination of the Kerberos protocol and RC4 encryption has existed as a core component of Active Directory since the service’s early days, creating a vast attack surface for hackers to exploit.

Microsoft Is About To Phase Out The Insecure Rc4 Encryption Algorithm

According to the announced roadmap, developers in Redmond expect to disable RC4 support by default by mid-2026. The Kerberos Key Distribution Center (KDC) on systems from Windows Server 2008 onwards will switch to using the AES-SHA1 standard by default. This is a modern security standard that is significantly more secure than its predecessor, the aging RC4. While domain administrators can still configure KDC accounts with RC4 authentication if desired, they must fully understand and accept the serious security risks that come with that decision.

Technical Challenges in Removing Legacy Technology

Immediately following Mr. Palko’s announcement, Mr. Steve Syfuhs, another Microsoft expert, shared on Bluesky that removing RC4 from the Windows Kerberos stack is a long-awaited process. In fact, developers have been quietly working on this project for over a decade. However, removing an encryption algorithm that has been deeply embedded in every operating system released over the past 25 years is an incredibly complex task fraught with technical challenges.

Throughout this time, Microsoft programmers have had to keep RC4 “alive” by surgically addressing its most critical security issues. They maintained this support until the decision to prioritize the AES standard for Kerberos communications was made. This strategic shift has significantly reduced the use of RC4 in systems while ensuring minimal impact on the compatibility of organizations running Active Directory systems.

Transition Support Tools and Expert Warnings

With the “phase-out” plan finalized, Microsoft is currently providing the necessary tools to help administrators identify and remediate issues related to remaining RC4-based connections. New PowerShell scripts have been released, allowing for the identification of ongoing RC4 authentication instances within Windows environments. Mr. Palko specifically advises organizations to quickly migrate these systems to AES-SHA1 or upgrade to newer versions of Windows. It is important to note that Windows Server 2003 is the final operating system that lacks full and standard support for AES128-SHA96 and AES256-SHA96.

This move by Microsoft is regarded as a positive step, finally addressing the inherent insecurity of RC4. It could also be seen as a response to recent harsh criticism from Democratic Senator Ron Wyden, who called the maintenance of old security standards “gross cybersecurity negligence.” However, a concerning reality remains: this algorithm is still widely supported across the industry. This means that insecure communications and vulnerable networks may persist for many years before being completely eliminated.

Share: 𝕏 P in
Question and answer (0 comments)

Table of contents
  1. Top