Skip to content(if available)orjump to list(if available)

Lessons in disabling RC4 in Active Directory (2021)

philodeon

When you turn off the bad cryptography, the product becomes unusable.

The purpose of a system is what it does.

ethanwillis

That quote would mean that the system being unusable without RC4 is exactly the point.

It doesn't mean that a system is what its makers intended for it to do.

gleenn

Kinda wild hearing about anything even using MD4. I remember doing an MD5 attack in a security class like 20 years ago. Obviously that kinda what this whole article is about but literally the first time ever hearing "MD4".

tptacek

Notably, those attacks aren't problematic in the setting MD4 is used in here (but the "outer" construction iterating it is deeply problematic).

lousken

just like windows 11 gui, security on windows is like putting lipstick on a pig