light bulb

Did You Know?



Reply
Posts: 8,452
Topics: 577
Kudos: 7,039
Registered: ‎02-03-2012

Microsoft Security Advisory Notification Issued: June 19, 2014

[ Edited ]

********************************************************************

Title: Microsoft Security Advisory Notification Issued: June 19,2014

 

********************************************************************

 

Security Advisories Updated or Released Today ===================

 

* Microsoft Security Advisory (2960358)

- Title: Update for Disabling RC4 in .NET TLS

- https://technet.microsoft.com/library/security/2960358

- Revision Note: V1.1 (June 19, 2014): Added link to Microsoft Knowledge Base Article 2978675 under Known Issues in the Executive Summary.

 

Daniel

coollogo_com-133794099.gif


asapvip.png  SigSVIP.png EPA.png


Webroot® SecureAnywhere™ Internet Security Complete Beta v8.0.7.33 on my main system Windows 7 Ultimate 64bit & on Win XP 32bit, Win Vista 32bit, Win 7 32bit, Win 8.1 Pro 32bit & 64bit, Win 10 Preview 32bit & 64bit Build 9926 all on VM's also on my HTC One M8 Android Lollipop 5.0.1 Phone v3.6.0.6652.


MVP.gif.png Microsoft® MVP Consumer Security


Twitter.png Untitled-1.png Community-Badges-BetaTester.png

Frequent Voice
Posts: 59
Registered: ‎06-08-2014

Re: Microsoft Security Advisory Notification Issued: June 19, 2014


TripleHelix wrote:

********************************************************************

Title: Microsoft Security Advisory Notification Issued: June 19,2014

 

********************************************************************

 

Security Advisories Updated or Released Today ===================

 

* Microsoft Security Advisory (2960358)

- Title: Update for Disabling RC4 in .NET TLS

- https://technet.microsoft.com/library/security/2960358

- Revision Note: V1.1 (June 19, 2014): Added link to Microsoft Knowledge Base Article 2978675 under Known Issues in the Executive Summary.

 

Daniel


Being completely tech challenged, what does this mean for security?  What is this supposed to do for our systems?

Posts: 8,452
Topics: 577
Kudos: 7,039
Registered: ‎02-03-2012

Re: Microsoft Security Advisory Notification Issued: June 19, 2014

[ Edited ]

Well these are release by Microsoft but we WSA users have no problem as we are protected see what it says here in the article:

 

Executive Summary

Microsoft is announcing the availability of an update for Microsoft .NET Framework that disables RC4 in Transport Layer Security (TLS) through the modification of the system registry. Use of RC4 in TLS could allow an attacker to perform man-in-the-middle attacks and recover plaintext from encrypted sessions.

 

And WSA's Identity Shield does protect us from man-in-the-middle attacks see the picture below!

 

Hope that helps,

 

Daniel :smileywink:

 

2014-05-07_14-37-48.png

 

coollogo_com-133794099.gif


asapvip.png  SigSVIP.png EPA.png


Webroot® SecureAnywhere™ Internet Security Complete Beta v8.0.7.33 on my main system Windows 7 Ultimate 64bit & on Win XP 32bit, Win Vista 32bit, Win 7 32bit, Win 8.1 Pro 32bit & 64bit, Win 10 Preview 32bit & 64bit Build 9926 all on VM's also on my HTC One M8 Android Lollipop 5.0.1 Phone v3.6.0.6652.


MVP.gif.png Microsoft® MVP Consumer Security


Twitter.png Untitled-1.png Community-Badges-BetaTester.png

Community Guide
Posts: 227
Registered: ‎06-04-2014

Re: Microsoft Security Advisory Notification Issued: June 19, 2014

From what I understood the update disables RC4-encryption for TLS as it's not secure anymore.

You would only be affected if you had a .net application which used RC4.

 

http://blogs.technet.com/b/srd/archive/2013/11/12/security-advisory-2868725-recommendation-to-disabl...

Community Guide



-Webroot Endpoint Protection user-
Posts: 8,452
Topics: 577
Kudos: 7,039
Registered: ‎02-03-2012

Re: Microsoft Security Advisory Notification Issued: June 19, 2014

Correct and thanks for the link!

 

Cheers,

 

Daniel :smileywink:

coollogo_com-133794099.gif


asapvip.png  SigSVIP.png EPA.png


Webroot® SecureAnywhere™ Internet Security Complete Beta v8.0.7.33 on my main system Windows 7 Ultimate 64bit & on Win XP 32bit, Win Vista 32bit, Win 7 32bit, Win 8.1 Pro 32bit & 64bit, Win 10 Preview 32bit & 64bit Build 9926 all on VM's also on my HTC One M8 Android Lollipop 5.0.1 Phone v3.6.0.6652.


MVP.gif.png Microsoft® MVP Consumer Security


Twitter.png Untitled-1.png Community-Badges-BetaTester.png

Community Guide
Posts: 227
Registered: ‎06-04-2014

Re: Microsoft Security Advisory Notification Issued: June 19, 2014

Also thanks for mentioning that WSA blocks MITM attacks :smileywink:

Community Guide



-Webroot Endpoint Protection user-