Posted by: kurtsh | June 27, 2024

INFO: NTLM Deprecation in Windows coming H2 CY2024

Deprecating NT LAN Manager (NTLM) has been a huge ask from our security community as it will strengthen user authentication, and so we are announcing that deprecation of NTLM is planned in the 2nd half of 2024 in Windows.

Why?

  • No server authentication (read: can’t verify malicious authentication servers)
  • Legacy MD4 encryption used for hashing password (read: weak & guessable)
  • Password submitted not salted (read: offline crackable)
  • Only supports password-based authentication (read: no certs, biometrics, MFA, FIDO, etc.)
  • Bugs (read: vulnerabilities)

Read more at:


Categories