Live data from Hacker News

Microsoft plans to kill off NTLM authentication in Windows 11

bleepingcomputer.com

51–60 of 86 posts

Re: Microsoft plans to kill off NTLM authentication in Windows 11

#51

Earlier quoted context omitted.

I guess that's why they're killing of third party printer drivers as well: https://news.ycombinator.com/item?id=37473628

They're not killing off printer drivers entirely, but they are moving them to userspace. A good idea that should've been implemented a long time ago, in my opinion, though I suspect printer driver manufacturers would've thrown a hissy fit if they actually did so back in the day.

They tried in Windows 8 and printer driver manufacturers did throw a hissy fit. It was one of the big propaganda sources for "UWP is terrible" discourse because UWP gave the best printer experience for userspace printer drivers and that was Windows 8's carrot incentive to try to get the driver writers to upgrade. Rather than accept the carrot most of the driver writers jumped straight into "UWP is bad and no one wants it and please, please users should ignore the nice parts like the new print driver stack" bandwagon.

Re: Microsoft plans to kill off NTLM authentication in Windows 11

#52
post #32

So for the uninitiated, what was the issue with NTLM that makes everyone happy they're switching to kerberos?

I'm a Security Architect dealing with the pain of an old environment with a default NTLM configuration so i'll chime in: - NTLM doesn't sign packets. If you can intercept an NTLM auth request you can forward that authentication attempt to another resource and impersonate the user without needing to know or crack their password. You simply MitM the challenge-response between the client and the server. This is called N…

This is not accurate.

NTLM provides signing and sealing using a session key. It is the responsibility of the protocol using NTLM for auth to use that key to sign or seal. The problem is that this feature is frequently turned off.

So it's actually not accurate to say "NTLM is vulnerable to relay attacks". If someone turns off signing in SMB to improve performance, that is not a problem with NTLM, that is a problem with the operator turning off signing. If a door has a lock but it's left unlocked, is that a problem with the security of the door?

NTLM also calculates a MIC over all of the NTLMSSP tokens which provides integrity protection independent of the protocol using NTLM. That MIC includes the target SPN so even if signing is turned off, it cannot be hacked.

Regarding hashes, there are two types of NTLM hashes. There are the password equivalent hashes which are only accessible through hacking system memory of a compromised machine that has access to them. It suffices to say, this is not the path of least resistance for an attacker. This is also known as "pass the hash".

Then you have what are called NetNTLMv2 hashes within the NTLMSSP tokens exchanged during authentication. These are muxed from the password and challenge using MD4 and MD5 but also RC4 if key exchange is used (session key mentioned above). This is not trivial to break. It could easily take a room full of GPUs months and maybe never depending on the generator and complexity of the password.

The problem with NTLM is not so much with the NTLM protocol itself but with the various implementations that either don't implement the necessary security features or they simply get turned off. Last I checked Windows Server domain members do not require clients to negotiate signing by default. If an acceptor required an SPN and a MIC, that would stop a relay attack even if signing wasn't used (because they would not be able to forge the MIC without the password and the MIC factors in the SPN).

Another issue is that the security community needs to find issues to justify their existence. NTLM being oldest and relatively weak crytographically naturally draws a lot of critisizm. But the facts are obscured and hyperbolized regularly. People largely regurgitate what they hear without really knowing what they're talking about. They need to to make it at least sound like they know what they're talking about. The only way anyone REALLY knows how this stuff works is to studying the documentation ([MS-NLMP].pdf), looking at captures and step through computations in code.

Re: Microsoft plans to kill off NTLM authentication in Windows 11

#53

Is this going to break things like SAMBA?

No. NTLM is an ancient protocol that dates back to Windows NT 3.1 in 1993. That's thirty years ago. Microsoft has been actively telling customers to "please stop using this" for over 10 years. Enough time has passed. NTLM is the Telnet of file sharing. There was a time and place for it and that time has passed.

I looked up my Debian file server and apparently it's using NTLM between it and my Windows desktop to share files.

I have no idea how to set up Kerberos. It looks like I need a Kerberos domain or something? It seems a lot more complicated.

Re: Microsoft plans to kill off NTLM authentication in Windows 11

#54

Earlier quoted context omitted.

They're not killing off printer drivers entirely, but they are moving them to userspace. A good idea that should've been implemented a long time ago, in my opinion, though I suspect printer driver manufacturers would've thrown a hissy fit if they actually did so back in the day.

They tried in Windows 8 and printer driver manufacturers did throw a hissy fit. It was one of the big propaganda sources for "UWP is terrible" discourse because UWP gave the best printer experience for userspace printer drivers and that was Windows 8's carrot incentive to try to get the driver writers to upgrade. Rather than accept the carrot most of the driver writers jumped straight into "UWP is bad and no one want…

Windows 8's implementation of UWP was shit for most use cases, though. Desktop users and full screen touch interfaces just don't mix.

Re: Microsoft plans to kill off NTLM authentication in Windows 11

#55
post #50
post #5

Earlier quoted context omitted.

Samba has supported Kerberos for a while. I'm sure there's some IoT shit that will break with NTLM disabled, but I believe maintained servers shouldn't be impacted.

Doesn't Samba only support Kerberos as part of a full Active Directory deployment? Switching to Kerberos authentication is not just a matter of flipping a switch, it drastically raises the minimum required infrastructure.

That's definitely the most common way to deploy Samba with Kerberos, but I don't think it's strictly necessary: https://blog.dan.drown.org/kerberos-for-windows-without-ad/

Re: Microsoft plans to kill off NTLM authentication in Windows 11

#56

Earlier quoted context omitted.

I'm wondering more about Workgroup networking. I can understand dumping it for domain controllers, but what authentication is used on domain-less networks?

It's in the article: (and the whole reason for finally killing off NTLM) > However, Microsoft is now working on two new Kerberos features: IAKerb (Initial and Pass Through Authentication Using Kerberos) and Local KDC (Local Key Distribution Center). > "The local KDC for Kerberos is built on top of the local machine's Security Account Manager so remote authentication of local user accounts can be done using Kerberos,"…

Thanks, I skimmed. I wonder if there are other ad-hoc Kerberos systems like this.

Re: Microsoft plans to kill off NTLM authentication in Windows 11

#57

Is this going to break things like SAMBA?

No. NTLM is an ancient protocol that dates back to Windows NT 3.1 in 1993. That's thirty years ago. Microsoft has been actively telling customers to "please stop using this" for over 10 years. Enough time has passed. NTLM is the Telnet of file sharing. There was a time and place for it and that time has passed.

I get the sentiment, but I think a batter example is needed. Telnet is still very useful for troubleshooting purposes.

Re: Microsoft plans to kill off NTLM authentication in Windows 11

#58
post #30

Earlier quoted context omitted.

To be fair, finding a good printer is hard. Mid-range enterprise printers manufactured before 2006 are in great demand, because of the progress of enshittification by the industry.

Or you can buy a Brother and spend your time on anything else. Let markets do their thing!

Which exact model do you have and when did you buy it? I would advise against trusting an entire company.

Re: Microsoft plans to kill off NTLM authentication in Windows 11

#60
post #50

Earlier quoted context omitted.

Doesn't Samba only support Kerberos as part of a full Active Directory deployment? Switching to Kerberos authentication is not just a matter of flipping a switch, it drastically raises the minimum required infrastructure.

That's definitely the most common way to deploy Samba with Kerberos, but I don't think it's strictly necessary: https://blog.dan.drown.org/kerberos-for-windows-without-ad/

From what I've been able to dig up, the situation has been getting worse over time so workarounds that worked circa Samba 4.8 or 4.9 are not effective on current distros.
Post reply on HN