CIO News Hubb
Advertisement
  • Home
  • News
  • Operations CIO
  • Visionary CIO
  • IT Management
  • Information Security
  • Contact
No Result
View All Result
  • Home
  • News
  • Operations CIO
  • Visionary CIO
  • IT Management
  • Information Security
  • Contact
No Result
View All Result
CIO News Hubb
No Result
View All Result
Home Information Security

Microsoft to Phase Out NTLM in Favor of Kerberos for Stronger Authentication

admin by admin
October 15, 2023
in Information Security


Oct 14, 2023NewsroomAuthentication / Endpoint Security

Microsoft has announced that it plans to eliminate NT LAN Manager (NTLM) in Windows 11 in the future, as it pivots to alternative methods for authentication and bolster security.

“The focus is on strengthening the Kerberos authentication protocol, which has been the default since 2000, and reducing reliance on NT LAN Manager (NTLM),” the tech giant said. “New features for Windows 11 include Initial and Pass Through Authentication Using Kerberos (IAKerb) and a local Key Distribution Center (KDC) for Kerberos.”

Cybersecurity

IAKerb enables clients to authenticate with Kerberos across a diverse range of network topologies. The second feature, a local Key Distribution Center (KDC) for Kerberos, extends Kerberos support to local accounts.

First introduced in the 1990s, NTLM is a suite of security protocols intended to provide authentication, integrity, and confidentiality to users. It is a single sign-on (SSO) tool that relies on a challenge-response protocol that proves to a server or domain controller that a user knows the password associated with an account.

It has since been supplanted by another authentication protocol called Kerberos since the release of Windows 2000, although NTLM continues to be used as a fallback mechanism.

“The main difference between NTLM and Kerberos is in how the two protocols manage authentication. NTLM relies on a three-way handshake between the client and server to authenticate a user,” CrowdStrike notes. “Kerberos uses a two-part process that leverages a ticket granting service or key distribution center.”

Cybersecurity

Another crucial distinction is that while NTLM relies on password hashing, Kerberos leverages encryption.

Besides NTLM’s inherent security weaknesses, the technology has been rendered vulnerable to relay attacks, potentially allowing bad actors to intercept authentication attempts and gain unauthorized access to network resources.

Microsoft said it’s also working on addressing hard-coded NTLM instances in its components in preparation for the shift to ultimately disable NTLM in Windows 11, adding it’s making improvements that encourage the use of Kerberos instead of NTLM.

“All these changes will be enabled by default and will not require configuration for most scenarios,” Matthew Palko, Microsoft’s senior product management lead in Enterprise and Security, said. “NTLM will continue to be available as a fallback to maintain existing compatibility.”

Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.





Source link

Tags: computer securitycyber attackscyber newscyber security newscyber security news todaycyber security updatescyber updatesdata breachhacker newshacking newshow to hackinformation securitynetwork securityransomware malwaresoftware vulnerabilitythe hacker news
Previous Post

PCI DSS v4.0 on AWS Compliance Guide now available

Next Post

Binance’s Smart Chain Exploited in New ‘EtherHiding’ Malware Campaign

Related Posts

Information Security

New PoolParty Process Injection Techniques Outsmart Top EDR Solutions

by admin
December 11, 2023
Information Security

New Spectre-based Vulnerability Impacts Intel, AMD, and Arm CPUs

by admin
December 10, 2023
Information Security

Researchers Unveal GuLoader Malware’s Latest Anti-Analysis Techniques

by admin
December 9, 2023
Information Security

2023 ISO and CSA STAR certificates now available with ISO 27001 transition from 2013 to 2022 version

by admin
December 9, 2023
Information Security

Founder of Bitzlato Cryptocurrency Exchange Pleads Guilty in Money-Laundering Scheme

by admin
December 8, 2023
Next Post

Binance's Smart Chain Exploited in New 'EtherHiding' Malware Campaign

Recommended

New PoolParty Process Injection Techniques Outsmart Top EDR Solutions

December 11, 2023

Information Paradox ~ Future of CIO

December 10, 2023

New Spectre-based Vulnerability Impacts Intel, AMD, and Arm CPUs

December 10, 2023

Innovateviastronggovernance

December 9, 2023

Technology Innovation of the Year for Summit’s Service Automation Solution

December 9, 2023

Researchers Unveal GuLoader Malware’s Latest Anti-Analysis Techniques

December 9, 2023

© CIO News Hubb All rights reserved.

Use of these names, logos, and brands does not imply endorsement unless specified. By using this site, you agree to the Privacy Policy and Terms & Conditions.

Navigate Site

  • Home
  • News
  • Operations CIO
  • Visionary CIO
  • IT Management
  • Information Security
  • Contact

Newsletter Sign Up

No Result
View All Result
  • Home
  • News
  • Operations CIO
  • Visionary CIO
  • IT Management
  • Information Security
  • Contact

© 2022 CIO News Hubb All rights reserved.