Live data from Hacker News

Microsoft plans to kill off NTLM authentication in Windows 11

bleepingcomputer.com

11–20 of 86 posts

Re: Microsoft plans to kill off NTLM authentication in Windows 11

#11

Is this going to break things like SAMBA?

I'm wondering more about Workgroup networking. I can understand dumping it for domain controllers, but what authentication is used on domain-less networks?

It's in the article: (and the whole reason for finally killing off NTLM)

> However, Microsoft is now working on two new Kerberos features: IAKerb (Initial and Pass Through Authentication Using Kerberos) and Local KDC (Local Key Distribution Center).

> "The local KDC for Kerberos is built on top of the local machine's Security Account Manager so remote authentication of local user accounts can be done using Kerberos," Microsoft's Matthew Palko explained.

> "This leverages IAKerb to allow Windows to pass Kerberos messages between remote local machines without having to add support for other enterprise services like DNS, netlogon, or DCLocator. IAKerb also does not require us to open new ports on the remote machine to accept Kerberos messages."

Re: Microsoft plans to kill off NTLM authentication in Windows 11

#12
post #8

I felt a great disturbance in the force as if thousands of pen-testers and grey hats cried out in agony as their go to means of breaking enterprise networks was lost.

Don't worry, that printer from 2003 the CEO has an emotional connection to probably requires the entire network to keep NTLM enabled.

The moment Microsoft rolls out a "turn NTLM back on" checkbox, the internet will be flooded with "how to fix printer not working on Windows 11" articles that will linger at least as long as the stupid "just disable SELinux if you run into any kind of error" articles are sticking around.

Re: Microsoft plans to kill off NTLM authentication in Windows 11

#13

Is this going to break things like SAMBA?

I'm wondering about Sonos v1 systems. They require some ancient login protocol from the server (NTLM v1?) that breaks every year or two. Sonos will never update their system to modernize it. The dumbest thing is it's just read only access for effectively a public account.

Re: Microsoft plans to kill off NTLM authentication in Windows 11

#15

Is the future of windows only online?

Welcome to the new Windows virtual experience, where you can connect all of your Windows devices in a joined ecosystem, and here's the best part you no longer have to worry about paying the full price of a computer, instead you'll be able to pay a small monthly subscription to get a premium Windows Connected Computing Experience(TM). You'll be able to do all the things you normally do* at a fraction of the price of buying a full machine, and best of all if there are any issues the Microsoft Experience Team will ship you a new device absolutely free of charge.** Welcome to the Windows future where you get the experience you deserve.

* Noted not all activities are applicable to all people some activities may violate our terms of service and result in a closing of your account without these activites include but are not limited to, the production of tools or services that would result in loss of revenue for the Microsoft corporation, developing free or open source (FOSS) software without an authorized Microsoft FOSS developer license, publishing misinformation, false or libelous claims about the Microsoft corporation or products, and other activities as determined by Microsoft.

** Free in this case is exclusive of necessary fees, surcharges, and shipping and handeling related expenses.

Welcome to the Windows future where you get the experience you deserve.

P.S. Please don't create the torment nexus

Re: Microsoft plans to kill off NTLM authentication in Windows 11

#16

Is this going to break things like SAMBA?

No. NTLM is an ancient protocol that dates back to Windows NT 3.1 in 1993. That's thirty years ago. Microsoft has been actively telling customers to "please stop using this" for over 10 years. Enough time has passed. NTLM is the Telnet of file sharing. There was a time and place for it and that time has passed.

Microsoft has said the same about SMB2 but people still turn that back on because of old NASes and printers.

Most guides for Samba still seem to be written with NTLM in mind. Any Linux/*BSD based consumer NAS may break, as well as many hobbyist NAS setups.

Microsoft is right to get rid of these old, vulnerable protocols, but there may still be an impact.

Re: Microsoft plans to kill off NTLM authentication in Windows 11

#17

What is the replacement for single sign-on? NTLM was kind of useful because some web browsers supported pass-through NTLM authentication, making website login process a breathe.

Normal Kerberos. For SSO NTLM was a fallback with no SSO power only.

Re: Microsoft plans to kill off NTLM authentication in Windows 11

#18

What is the replacement for single sign-on? NTLM was kind of useful because some web browsers supported pass-through NTLM authentication, making website login process a breathe.

Browsers support Integrated Windows Authentication, which is more than NTLM but often erroneously labeled as such for historical reasons.

Re: Microsoft plans to kill off NTLM authentication in Windows 11

#20

Is the future of windows only online?

Windows 365 (enterprise) is actually really nice. I started using it to manage an org transition @ work, but I am thinking I might also set up a personal instance at this point.

The dream is to throw away 100% of my desktops and run with just a MacBook and a decent external monitor. I don't have the patience to manage hardcore/gamer hardware anymore.

Post reply on HN