{"id":4490,"date":"2017-07-24T16:53:14","date_gmt":"2017-07-24T20:53:14","guid":{"rendered":"https:\/\/www.thesslstore.com\/blog\/?p=4490"},"modified":"2023-04-10T16:12:20","modified_gmt":"2023-04-10T20:12:20","slug":"crypto-changes-windows-10-fall-creators-update","status":"publish","type":"post","link":"https:\/\/www.thesslstore.com\/blog\/crypto-changes-windows-10-fall-creators-update\/","title":{"rendered":"Crypto Changes in Windows 10 Fall Creators Update"},"content":{"rendered":"<h2>RC4 Disabled and CAPI Features Discouraged<\/h2>\n<p>Later this year Microsoft will release the \u201cFall Creators Update\u201d for Windows 10. This is similar to the \u201cService Packs\u201d traditionally released as major lifecycle updates for Windows, though Microsoft has eschewed that term recently in favor of more consumer friendly names.<\/p>\n<p>Usually, when we think of software updates we think of new features &#8211; but there are also features being removed or \u201cdeprecated\u201d (or, officially put on notice) in order to keep the OS modern.<\/p>\n<p>The full list of removals\/deprecations <a href=\"https:\/\/support.microsoft.com\/en-us\/help\/4034825\/features-that-are-removed-or-deprecated-in-windows-10-fall-creators-up\" rel=\"nofollow\">are listed on this Microsoft support page<\/a>, but we have highlighted a few that are relevant to your SSL\/TLS configuration or cryptography work.<\/p>\n<p>The following features are \u201cdeprecated\u201d in the Fall Creators Update, which means they are \u201cnot in active development and might be removed in future releases.\u201d<\/p>\n<h2>TLS RC4 Ciphers Disabled By Default<\/h2>\n<p>RC4 &#8211; an encryption cipher which has been broken for quite a while &#8211; will be disabled by default. Presumably this means the cipher will still be available for \u2018compatibility.\u2019<\/p>\n<p>All <a href=\"https:\/\/support.microsoft.com\/en-us\/help\/3151631\/rc4-cipher-is-no-longer-supported-in-internet-explorer-11-or-microsoft\" rel=\"nofollow\">modern<\/a> browsers <a href=\"https:\/\/venturebeat.com\/2015\/09\/01\/google-microsoft-and-mozilla-will-drop-rc4-support-in-chrome-edge-ie-and-firefox-next-year\/\" rel=\"nofollow\">have disabled<\/a> RC4, so it has been unusable on updated machines for some time. Even <a href=\"https:\/\/blog.cloudflare.com\/end-of-the-road-for-rc4\/\" rel=\"nofollow\">Cloudflare disabled it network-wide more than 2 years ago<\/a> and at that time only 1 millionth of one percent of requests to their network was using it.<\/p>\n<span style=\"--tl-form-height-m:150.25px;--tl-form-height-t:121.4583px;--tl-form-height-d:121.4583px;\" class=\"tl-placeholder-f-type-shortcode_12753 tl-preload-form\"><span><\/span><\/span>\n<h2>CAPI RSA\/AES Provider Deprecated<\/h2>\n<p>The title for this one reads \u201cRSA\/AES Encryption for IIS\u201d and the description says \u201cwe recommend that users use CNG encryption provider.\u201d<\/p>\n<p>This is rather poorly worded and its meaning may not be immediately obvious to those that are not familiar with Windows\u2019 APIs. There is more than one API that can be used to implement crypto functions and in this update some features are being deprecated in an older API.<\/p>\n<p><a href=\"https:\/\/msdn.microsoft.com\/en-us\/library\/ms867086.aspx\" rel=\"nofollow\">CAPI, or Crypto API<\/a>, is the aging API <a href=\"https:\/\/twitter.com\/vcsjones\/status\/889477986868756480\" rel=\"nofollow\">where AES\/RSA functionality is being <\/a>discouraged.<\/p>\n<p><a href=\"https:\/\/msdn.microsoft.com\/en-us\/library\/windows\/desktop\/aa376210(v=vs.85).aspx\" rel=\"nofollow\">CNG (Cryptography API: Next Generation)<\/a> is CAPI\u2019s successor, first introduced in Vista, and recommended if you want to work with RSA or AES.<\/p>\n<h2>Other Changes<\/h2>\n<p>There are some changes to Windows\u2019 Trusted Platform Module (TPM) management features. TPM is a hardware chip that manages certain cryptographic operations. Windows\u2019 TPM Owner Password Management will be removed, while TPM.msc will be replaced in a future version, and TPM Remote Management will be removed in a future version.<\/p>\n<p>Syskey.exe is the only feature mentioned here which is being entirely removed in the update. It is a legacy application intended to be used as an additional security measure to protect user password information. However it is now severely outdated &#8211; using the aforementioned RC4 cipher &#8211; and does not provide suffcient security. However <a href=\"https:\/\/support.microsoft.com\/en-us\/help\/4025993\/syskey-exe-utility-is-no-longer-supported-in-windows-10-rs3-and-window\" rel=\"nofollow\">it has become a tool used by ransomware and other \u201ctechnical support\u201d scammers<\/a> and is a liability to keep around. Bitlocker is the recommended modern replacement.<\/p>\n<hr \/>\n<p><em>Thanks to <\/em><a href=\"https:\/\/twitter.com\/vcsjones\/\" rel=\"nofollow\"><em>Kevin Jones<\/em><\/a><em> who shared his encyclopedic familiarity with Windows\u2019 cryptography capabilities.<\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<p>RC4 Disabled and CAPI Features Discouraged Later this year Microsoft will release the \u201cFall Creators Update\u201d for Windows 10. This is similar to the \u201cService Packs\u201d traditionally released as major&#8230;<\/p>\n","protected":false},"author":2,"featured_media":4494,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":"","tve_updated_post":"","tve_custom_css":"","tve_user_custom_css":"","tve_globals":{},"tcb2_ready":0,"tcb_editor_enabled":0,"tve_landing_page":"","_tve_header":"","_tve_footer":""},"categories":[17],"tags":[182,253],"class_list":["post-4490","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-industry-lowdown","tag-encryption","tag-microsoft","post-with-tags"],"views":9885,"jetpack_featured_media_url":"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2017\/07\/iStock-495108702.jpg","_links":{"self":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts\/4490","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/comments?post=4490"}],"version-history":[{"count":0,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts\/4490\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/media\/4494"}],"wp:attachment":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/media?parent=4490"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/categories?post=4490"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/tags?post=4490"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}