Open Menu
AllLocalCommunitiesAbout
lotide
AllLocalCommunitiesAbout
Login

Windows RDP lets you log in using revoked passwords. Microsoft is OK with that.

⁨63⁩ ⁨likes⁩

Submitted ⁨⁨1⁩ ⁨week⁩ ago⁩ by ⁨neme@lemm.ee⁩ to ⁨windows@sopuli.xyz⁩

https://arstechnica.com/security/2025/04/windows-rdp-lets-you-log-in-using-revoked-passwords-microsoft-is-ok-with-that/

source

Comments

Sort:hotnewtop
  • 18USCode2381@infosec.pub ⁨1⁩ ⁨week⁩ ago

    Ransomware Delivery Protocol at it again.

    source
    • Onomatopoeia@lemmy.cafe ⁨1⁩ ⁨week⁩ ago

      Sounds like this is nothing more than the native credential token caching NT always had. So even if you lost domain connectivity for months, anyone who had previously logged into that machine could still log in (of course, because it hasn’t connected to the domain directory for credential updates).

      Not sure why it’s seen as an RDP specific thing, I don’t see anything in the article clarifying this only affects RDP. It should affect the entire machine/any local logins (not local credentials, any logins that happened on the machine, so the credential token was cached).

      Some clarification around how credentials are updated from Azure/MS would be helpful, and clarify if this is any more than the original NT token caching.

      source
      • wizardbeard@lemmy.dbzer0.com ⁨1⁩ ⁨week⁩ ago

        Thank you. It’s annoying that there isn’t a separate set of settings for RDP connections specifically, but as far as I can tell this is the standard caching feature controlled/mitigated by the same means as it always has been.

        source
  • Zachariah@lemmy.world ⁨1⁩ ⁨week⁩ ago

    Microsoft said the behavior is a “a design decision to ensure that at least one user account always has the ability to log in no matter how long a system has been offline.” As such, Microsoft said the behavior doesn’t meet the definition of a security vulnerability, and company engineers have no plans to change it.

    source
  • phoenixz@lemmy.ca ⁨1⁩ ⁨week⁩ ago

    Install Linux already, just get it over with

    source