Skip to content
  • Categories
  • Recent
  • Tags
  • All Topics
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Caint logo. It's just text.
  1. Home
  2. Uncategorized
  3. A prominent US Senator has called on the Federal Trade Commission to investigate Microsoft for “gross cybersecurity negligence,” citing the company’s continued use of the obsolete and vulnerable RC4 encryption cipher that Windows uses by default.

A prominent US Senator has called on the Federal Trade Commission to investigate Microsoft for “gross cybersecurity negligence,” citing the company’s continued use of the obsolete and vulnerable RC4 encryption cipher that Windows uses by default.

Scheduled Pinned Locked Moved Uncategorized
5 Posts 3 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • Dan GoodinD This user is from outside of this forum
    Dan GoodinD This user is from outside of this forum
    Dan Goodin
    wrote last edited by
    #1

    A prominent US Senator has called on the Federal Trade Commission to investigate Microsoft for “gross cybersecurity negligence,” citing the company’s continued use of the obsolete and vulnerable RC4 encryption cipher that Windows uses by default. Senator Ron Wyden went on to liken Microsoft to an "arsonist selling firefighting services to their victims.”

    https://arstechnica.com/security/2025/09/senator-blasts-microsoft-for-making-default-windows-vulnerable-to-kerberoasting/

    Karl AuerbachK 1 Reply Last reply
    1
    0
    • Dan GoodinD Dan Goodin

      A prominent US Senator has called on the Federal Trade Commission to investigate Microsoft for “gross cybersecurity negligence,” citing the company’s continued use of the obsolete and vulnerable RC4 encryption cipher that Windows uses by default. Senator Ron Wyden went on to liken Microsoft to an "arsonist selling firefighting services to their victims.”

      https://arstechnica.com/security/2025/09/senator-blasts-microsoft-for-making-default-windows-vulnerable-to-kerberoasting/

      Karl AuerbachK This user is from outside of this forum
      Karl AuerbachK This user is from outside of this forum
      Karl Auerbach
      wrote last edited by
      #2

      @dangoodin This is a losing argument. Microsoft and other companies have to be concerned with many issues, such as not breaking existing systems. The business judgement rule, assuming that decisions are made beyond mere concern for "shareholder value", provides a fairly decent standard to measure whether negligence or reckless behavior has occurred.

      One could extend Wyden's argument to other places - like automobiles. It is well known that helmets, fire suits, and especially five point seat harnesses enhance driver safety. So do we hold VW and GM and Ford liable for not putting those into cars?

      We've already condemned a large number of people to lifetime pain by our near ban on opioid pain relief (on the grounds of attempting to deny abuse by some others.)

      We have a balance in all things - and my sense is that in this case "gross negligence" is an inappropriate accusation.

      (I would say that clear notice of the issue on the product would be appropriate.)

      Steve BellovinS 1 Reply Last reply
      0
      • Karl AuerbachK Karl Auerbach

        @dangoodin This is a losing argument. Microsoft and other companies have to be concerned with many issues, such as not breaking existing systems. The business judgement rule, assuming that decisions are made beyond mere concern for "shareholder value", provides a fairly decent standard to measure whether negligence or reckless behavior has occurred.

        One could extend Wyden's argument to other places - like automobiles. It is well known that helmets, fire suits, and especially five point seat harnesses enhance driver safety. So do we hold VW and GM and Ford liable for not putting those into cars?

        We've already condemned a large number of people to lifetime pain by our near ban on opioid pain relief (on the grounds of attempting to deny abuse by some others.)

        We have a balance in all things - and my sense is that in this case "gross negligence" is an inappropriate accusation.

        (I would say that clear notice of the issue on the product would be appropriate.)

        Steve BellovinS This user is from outside of this forum
        Steve BellovinS This user is from outside of this forum
        Steve Bellovin
        wrote last edited by
        #3

        @karlauerbach @dangoodin Sorry, no; as I notes, the problem was known long before Active Directory, so there wasn’t a backwards compatibility issue.

        Dan GoodinD 1 Reply Last reply
        0
        • Steve BellovinS Steve Bellovin

          @karlauerbach @dangoodin Sorry, no; as I notes, the problem was known long before Active Directory, so there wasn’t a backwards compatibility issue.

          Dan GoodinD This user is from outside of this forum
          Dan GoodinD This user is from outside of this forum
          Dan Goodin
          wrote last edited by
          #4

          @SteveBellovin @karlauerbach

          Geez, talk about painting yourself into a corner.

          Karl AuerbachK 1 Reply Last reply
          0
          • Dan GoodinD Dan Goodin

            @SteveBellovin @karlauerbach

            Geez, talk about painting yourself into a corner.

            Karl AuerbachK This user is from outside of this forum
            Karl AuerbachK This user is from outside of this forum
            Karl Auerbach
            wrote last edited by
            #5

            @dangoodin @SteveBellovin I've spent many an hour in the corner, often deservedly.

            I think the greater issue here is not the use of an algorithm that is know to be vulnerable but rather that we have too often used the "crunchy on the outside, soft on the inside" model of security rather than building layers of protection and adherence to the principle of "least privilege".

            Microsoft may well be culpable for not keeping up with the often staggering rate of change of security risks, methods, and algorithms.

            But what is the standard that we use to measure that culpability? Are we to go to a strict product-liability standard? (i.e. they made it, they are liable, no excuses - essentially an insurance system.)

            I bring up self driving vehicles as an example of the fuzziness of the standards. We want to encourage innovation but we also want to block crazed deployment such as Tesla's "full self driving" representations. The real question is who bears the risk and costs of the damage?

            1 Reply Last reply
            1
            0
            • R AodeRelay shared this topic
              R ActivityRelay shared this topic
            Reply
            • Reply as topic
            Log in to reply
            • Oldest to Newest
            • Newest to Oldest
            • Most Votes


            • Login

            • Don't have an account? Register

            • Login or register to search.
            • First post
              Last post
            0
            • Categories
            • Recent
            • Tags
            • All Topics
            • Popular
            • World
            • Users
            • Groups