Hacker Newsnew | past | comments | ask | show | jobs | submitlogin
Pass the Hash on Windows 8.1 (samsclass.info)
5 points by lelf on Feb 23, 2014 | hide | past | favorite | 3 comments


The thread on /r/netsec offers some clarification: http://www.reddit.com/r/netsec/comments/1ypdo1/sorry_microso...

Ostensibly, the vulnerability is necessary to maintain functionality. Something to do with the particular Kerberos implementation and backwards compatibility. They've made it more difficult to get to the point where you can attack, however.


Whilst this interesting, I feel the need to channel Raymond Chen (of http://blogs.msdn.com/b/oldnewthing/)and say "if you disable security features, you have disabled security features, don't be surprised when it is now less secure".

In this case there still is an issue that should really be addressed, but that will be why it probably isn't ranked high on the to-address list


https://twitter.com/markrussinovich/status/43768318205430579...

Here is a Tweet from Mark Russinovich to this topic! I asked him bout that!




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: