light bulb

Did You Know?



Reply
Highlighted
Posts: 12,771
Topics: 868
Kudos: 15,369
Ideas: 7
Registered: ‎02-03-2012

Microsoft Security Advisory Notification Issued: June 19, 2014

[ Edited ]

********************************************************************

Title: Microsoft Security Advisory Notification Issued: June 19,2014

 

********************************************************************

 

Security Advisories Updated or Released Today ===================

 

* Microsoft Security Advisory (2960358)

- Title: Update for Disabling RC4 in .NET TLS

- https://technet.microsoft.com/library/security/2960358

- Revision Note: V1.1 (June 19, 2014): Added link to Microsoft Knowledge Base Article 2978675 under Known Issues in the Executive Summary.

 

Daniel


 


Webroot® SecureAnywhere™ Internet Security Complete Beta Tester v9.0.14.59 on my main system Alienware 17R2 with Windows 10 Professional x64 Version 1607 (Build 14393.479) & Motorola Moto Z Android 6.0.1 Marshmallow with WSA Mobile Complete v3.7.1.7660 which is full Cloud now as well! I also test new Windows Insider 32bit & 64bit builds on Virtual Machines.


 Microsoft® Windows Insider MVP - Windows Security


        chfinj.png

Community Guide
Posts: 150
Registered: ‎06-08-2014

Re: Microsoft Security Advisory Notification Issued: June 19, 2014


TripleHelix wrote:

********************************************************************

Title: Microsoft Security Advisory Notification Issued: June 19,2014

 

********************************************************************

 

Security Advisories Updated or Released Today ===================

 

* Microsoft Security Advisory (2960358)

- Title: Update for Disabling RC4 in .NET TLS

- https://technet.microsoft.com/library/security/2960358

- Revision Note: V1.1 (June 19, 2014): Added link to Microsoft Knowledge Base Article 2978675 under Known Issues in the Executive Summary.

 

Daniel


Being completely tech challenged, what does this mean for security?  What is this supposed to do for our systems?

Community Guide

Posts: 12,771
Topics: 868
Kudos: 15,369
Ideas: 7
Registered: ‎02-03-2012

Re: Microsoft Security Advisory Notification Issued: June 19, 2014

[ Edited ]

Well these are release by Microsoft but we WSA users have no problem as we are protected see what it says here in the article:

 

Executive Summary

Microsoft is announcing the availability of an update for Microsoft .NET Framework that disables RC4 in Transport Layer Security (TLS) through the modification of the system registry. Use of RC4 in TLS could allow an attacker to perform man-in-the-middle attacks and recover plaintext from encrypted sessions.

 

And WSA's Identity Shield does protect us from man-in-the-middle attacks see the picture below!

 

Hope that helps,

 

Daniel Smiley Wink

 

 


 


Webroot® SecureAnywhere™ Internet Security Complete Beta Tester v9.0.14.59 on my main system Alienware 17R2 with Windows 10 Professional x64 Version 1607 (Build 14393.479) & Motorola Moto Z Android 6.0.1 Marshmallow with WSA Mobile Complete v3.7.1.7660 which is full Cloud now as well! I also test new Windows Insider 32bit & 64bit builds on Virtual Machines.


 Microsoft® Windows Insider MVP - Windows Security


        chfinj.png

Community Guide
Posts: 230
Registered: ‎06-04-2014

Re: Microsoft Security Advisory Notification Issued: June 19, 2014

From what I understood the update disables RC4-encryption for TLS as it's not secure anymore.

You would only be affected if you had a .net application which used RC4.

 

http://blogs.technet.com/b/srd/archive/2013/11/12/security-advisory-2868725-recommendation-to-disabl...

Community Guide



-Webroot Endpoint Protection user-
Posts: 12,771
Topics: 868
Kudos: 15,369
Ideas: 7
Registered: ‎02-03-2012

Re: Microsoft Security Advisory Notification Issued: June 19, 2014

Correct and thanks for the link!

 

Cheers,

 

Daniel Smiley Wink


 


Webroot® SecureAnywhere™ Internet Security Complete Beta Tester v9.0.14.59 on my main system Alienware 17R2 with Windows 10 Professional x64 Version 1607 (Build 14393.479) & Motorola Moto Z Android 6.0.1 Marshmallow with WSA Mobile Complete v3.7.1.7660 which is full Cloud now as well! I also test new Windows Insider 32bit & 64bit builds on Virtual Machines.


 Microsoft® Windows Insider MVP - Windows Security


        chfinj.png

Community Guide
Posts: 230
Registered: ‎06-04-2014

Re: Microsoft Security Advisory Notification Issued: June 19, 2014

Also thanks for mentioning that WSA blocks MITM attacks Smiley Wink

Community Guide



-Webroot Endpoint Protection user-