Windows

Microsoft Says It's Not Planning To Use AI To Rewrite Windows From C To Rust 41

Microsoft has denied any plans to rewrite Windows 11 using AI and Rust after a LinkedIn post from one of its top-level engineers sparked a wave of online backlash by claiming the company's goal was to "eliminate every line of C and C++ from Microsoft by 2030."

Galen Hunt, a principal software engineer responsible for several large-scale research projects at Microsoft, made the claim in what was originally a hiring post for his team. His original wording described a "North Star" of "1 engineer, 1 month, 1 million lines of code" and outlined a strategy to "combine AI and Algorithms to rewrite Microsoft's largest codebases." The repeated use of "our" in the post led many to interpret it as an official company direction rather than a personal research ambition.

Frank X. Shaw, Microsoft's head of communications, told Windows Latest that the company has no such plans. Hunt subsequently edited his LinkedIn post to clarify that "Windows is NOT being rewritten in Rust with AI" and that his team's work is a research project focused on building technology to enable language-to-language migration. He characterized the reaction as "speculative reading between the lines."
Businesses

Amazon Faces 'Leader's Dilemma' - Fight AI Shopping Bots or Join Them (cnbc.com) 11

Amazon finds itself caught between two competing impulses as AI shopping agents from OpenAI, Google, Perplexity and Microsoft mushroom across the e-commerce space -- block them to protect its dominant position, or partner with them to avoid being left behind. The company has largely played defense so far. Amazon recently updated its website code to block external AI agents from crawling it, and as of this week had blocked 47 bots including those from all major AI companies. In November, Amazon sued Perplexity over an agent in the startup's Comet browser that can make purchases on users' behalf, alleging the company concealed its agents to continue scraping Amazon's site. But Amazon's stance appears to be shifting, CNBC reports.

CEO Andy Jassy said on an October earnings call that Amazon expects to partner with third-party agents and has engaged in conversations with some providers. The company is now hiring a corporate development leader to forge strategic partnerships in "agentic commerce." Amazon is also investing in its own tools. The company launched shopping chatbot Rufus last February and has been testing an agent called Buy For Me that can purchase products from other sites within Amazon's app.
Programming

What Might Adding Emojis and Pictures To Text Programming Languages Look Like? 83

theodp writes: We all mix pictures, emojis, and text freely in our communications. So why not in our code? That's the premise of "Fun With Python and Emoji: What Might Adding Pictures to Text Programming Languages Look Like?" (two-image Bluesky explainer; full slides), which takes a look at what mixing emoji with Python and SQL might look like. A GitHub repo includes a Google Colab-ready Python notebook proof of concept that does rudimentary emoji-to-text translation via an IPython input transformer.

So, in the Golden Age of AI -- some 60+ years after Kenneth Iverson introduced the chock-full-of-symbols APL -- are valid technical reasons still keeping symbols and pictures out of code, or is their absence more of a programming dogma thing?
Software

Ireland's Diarmuid Early Wins World Microsoft Excel Title (bbc.com) 14

Irish competitor Diarmuid Early, dubbed the "Lebron James of Excel spreadsheets," has won the 2025 Microsoft Excel World Championship in Las Vegas, dethroning three-time champion Andrew Ngai. The BBC reports: The esport showpiece in December attracted competitors worldwide as 256 spreadsheet heads battled it out across knockout rounds to join the final 24 in Vegas. [...] A three-time champion in the financial Excel tournaments, this win was Diarmuid's first in the overall competition. He held the triple-world champion Andrew Ngai to second place, and won the $5,000 prize and title belt. [...]

Excel esports transforms a common office tool into a dynamic sport. More than 20 years old, the competitive scene has evolved from being finance based to now involving more general problem solving. Although it might help, Diarmuid said "it doesn't require accounting or finance knowledge." He described an example where Excel is used in solving a maze, scoring poker hands, or even sorting Kings and Queens into the battles in which they fought.

Generally there is a 30 minute challenge, with each challenge broken up into levels. The questions increase gradually in difficulty, with each correct answer gaining a player points. Whoever gets the most points wins, and in a tie, it is whoever got there first. "It's just, can you think on your feet and do things quickly in Excel?" he said. "If you solve the earlier levels in a neat way, that'll let you hit the ground running faster on the later ones."

Software

'Fragmented' Microsoft Tools Undercut Efficiency at Amazon and Whole Foods, Internal Deloitte Review Finds (businessinsider.com) 27

An anonymous reader shares a report: It's been more than eight years since Amazon bought Whole Foods, but the two companies still haven't aligned their setup for the Microsoft software their employees use. That disconnect was flagged in an 8-week Deloitte review of Whole Foods' use of Microsoft 365 apps earlier this year, according to an internal document obtained by Business Insider. Deloitte found that Whole Foods relies on "fragmented" Microsoft toolsets, has loose security and data-retention practices, and employs a complex user-management setup -- all of which contribute to inefficiencies and lower productivity when working with Amazon employees.

The consulting firm recommended a 24-month integration plan that would first move Whole Foods' corporate employees onto Amazon's backend system, followed by its frontline workers. The phased approach would ensure a "smooth transition for users and minimal disruption to business processes," while generating cost savings, the document said. The review, completed in May, highlights Amazon's ongoing challenges in integrating Whole Foods. Since acquiring the chain in 2017, the company has struggled to scale the business and integrate operations, resulting in frequent reorganizations and shifting strategic priorities.

EU

Europe's Public Institutions Are Quietly Ditching US Cloud Providers (theregister.com) 90

European public institutions are quietly migrating away from American cloud providers and office software, driven less by policy ambitions in Brussels than by the mundane legal reality that GDPR-mandated risk assessments keep flagging the US CLOUD Act as an unacceptable threat to citizen data.

Austria's Federal Ministry for Economy, Energy and Tourism moved 1,200 employees to the open-source platform Nextcloud in four months. Germany's Schleswig-Holstein has already transitioned 24,000 of its 30,000 civil servants to LibreOffice, Nextcloud and Thunderbird. The International Criminal Court in The Hague announced in November 2025 that it would replace Microsoft office software after chief prosecutor Karim Khan was temporarily locked out of his Outlook account.

Competition economist Cristina Caffarra estimates that 90% of Europe's digital infrastructure is now controlled by non-European companies. Forrester predicts no European enterprise will fully abandon US hyperscalers in 2026, but these targeted migrations for sensitive government applications are already underway.
Programming

Microsoft To Replace All C/C++ Code With Rust By 2030 (thurrott.com) 272

Microsoft plans to eliminate all C and C++ code across its major codebases by 2030, replacing it with Rust using AI-assisted, large-scale refactoring. "My goal is to eliminate every line of C and C++ from Microsoft by 2030," Microsoft Distinguished Engineer Galen Hunt writes in a post on LinkedIn. "Our strategy is to combine AI and Algorithms to rewrite Microsoft's largest codebases. Our North Star is '1 engineer, 1 month, 1 million lines of code.' To accomplish this previously unimaginable task, we've built a powerful code processing infrastructure. Our algorithmic infrastructure creates a scalable graph over source code at scale. Our AI processing infrastructure then enables us to apply AI agents, guided by algorithms, to make code modifications at scale. The core of this infrastructure is already operating at scale on problems such as code understanding."

Hunt says he's looking to hire a Principal Software Engineer to help with this effort. "The purpose of this Principal Software Engineer role is to help us evolve and augment our infrastructure to enable translating Microsoft's largest C and C++ systems to Rust," writes Hunt. "A critical requirement for this role is experience building production quality systems-level code in Rust -- preferably at least 3 years of experience writing systems-level code in Rust. Compiler, database, or OS implementation experience is highly desired. While compiler implementation experience is not required to apply, the willingness to acquire that experience in our team is required."
Businesses

State of Play: Who Holds the Power in the Video Games Industry in 2025? (theguardian.com) 25

The video games industry in 2025 finds itself caught between the familiar forces of consolidation and job losses that have plagued creative industries, and a newer development: governments and the ultra-wealthy have begun treating games as tools of political influence. Saudi Arabia's Public Investment Fund closed a $55 billion deal for EA this year and acquired Niantic, the makers of Pokemon Go, in March.

Microsoft's 2023 acquisition of Activision already signaled the direction of travel. The workforce has borne the costs of this consolidation. More than 5,000 jobs have been lost in the industry this year, and several studios have shuttered, including Monolith Productions. The instability has pushed unions into greater prominence: United Videogame Workers formed in the US and Canada in March as part of the Communications Workers of America, and the firing of 30 staff from Rockstar Games in the UK brought the IWGB Game Workers Union into the spotlight.

Meanwhile, the Trump administration has posted AI-generated images of the president as Halo's Master Chief and used Pokemon and Halo memes to recruit for ICE.
XBox (Games)

Is Xbox Betting on Cross-Platform Gaming? (cnbc.com) 26

A "slew of layoffs, price hikes and studio closures" for Microsoft's Xbox "have led many to declare — not for the first time — that the Xbox is dead," reports CNBC.

Or is it just changing its business model? The company's overall gaming revenue decreased 2% year-over-year, with a 29% dip in Xbox hardware sales, according to Microsoft's first-quarter earnings for fiscal 2026. The broader console industry has been in a major slump, with hardware spending down 27% year-over-year in November, which is typically a busy shopping month, according to a recent report from research firm Circana. It was the worst November in two decades, IGN reported, citing Circana data. Combined Switch and Switch 2 unit sales were down more than 10% during the month and PS5 sales were down more than 40%, IGN said. But the Xbox Series hardware took the biggest beating, with a dramatic 70% drop in sales...Microsoft's Xbox Series S and Series X, at 1.7 million units, couldn't outsell the original Nintendo Switch, which launched in 2017 and has sold 3.4 million units so far this year, data from game sales tracking site VGChartz estimated...

Microsoft CEO Satya Nadella said in a recent interview with the TBPN podcast that the company's gaming business model will look to be "everywhere in every platform," from consoles to TV to mobile. His comments also hinted that the next Xbox may function more like a PC. "It's kind of funny people think about the console and PC as two different things," Nadella said. "We built a console because we wanted to build a better PC, which could then perform for gaming. So I kind of want to revisit some of that conventional wisdom...." A source familiar with Xbox strategy told CNBC that the company is looking at creating an open system that enables players to jump between console, PC and cloud gaming — and any form of entertainment beyond gaming. [Wedbush analyst Michael Pachter told CNBC] that while Microsoft is not completely abandoning hardware, the company is splitting its audience into existing buyers interested in specialized consoles and everyone else.

Xbox Game Pass subscription service, which gives subscribers access to games from a variety of publishers, is a clear example of this strategy... The growth in cloud gaming has been blistering. Xbox reported a record 34 million Game Pass subscribers in 2024 and a total Game Pass revenue of almost $5 billion over the last fiscal year. Xbox said in a November blog post that the number of cloud gaming hours from Game Pass subscribers was up 45% compared to the same time last year. The Microsoft subsidiary also said console players are "spending 45% more time cloud streaming on console and 24% more on other devices..."

Despite gaming's scaling limitations, Microsoft seems committed to doing what it has done with the rest of its products — moving it to the cloud... [Xbox President Sarah] Bond recently said in an interview with Mashable that the idea of exclusive games is "antiquated" as the company has leaned into cross-platform gaming... Xbox is betting that cloud and cross-platform gaming are the future. For a decade, claims have been made about the death of the Xbox, and what comes next could fully spell the end, or bring a metamorphosis.

Education

Inaugural 'Hour of AI' Event Includes Minecraft, Microsoft, Google and 13.1 Million K-12 Schoolkids (csforall.org) 13

Long-time Slashdot reader theodp writes: Last September, tech-backed nonprofit Code.org pledged to engage 25 million K-12 schoolchildren in an "Hour of AI" this school year. Preliminary numbers released this week by the Code.org Advocacy Coalition showed that [halfway through the five-day event Computer Science Education Week] 13.1 million users had participated in the inaugural Hour of AI, attaining 52.4% of its goal of 25 million participants.

In a pivot from coding to AI literacy, the Hour of AI replaced Code.org's hugely-popular Hour of Code this December as the flagship event of Computer Science Education Week (December 8-14). According to Code.org's 2024-25 Impact Report, "in 2024–25 alone, students logged over 100 million Hours of Code, including more than 43 million in the four months leading up to and including CS Education Week."

Minecraft participated with their own Hour of AI lessons. ("Program an AI Agent to craft tools and build shelter before dusk falls in this iconic challenge!") And Google contributed AI Quests, "a gamified, in-class learning experience" allowing students to "step into the shoes of Google researchers using AI to solve real-world challenges." Other participating organizations included the Scratch Foundation, Lego Education, Adobe, and Roblox.

And Microsoft contributed two — including one with their block-based programming environment Microsoft MakeCode Arcade, with students urged to "code and train your own super-smart bug using AI algorithms and challenge other AI bugs in an epic Tower battle for ultimate Bug Arena glory!"

See all the educational festivities here...
United States

Trump Admin to Hire 1,000 for New 'Tech Force' to Build AI Infrastructure (cnbc.com) 56

An anonymous reader shared this report from CNBC: The Trump administration on Monday unveiled a new initiative dubbed the "U.S. Tech Force," comprising about 1,000 engineers and other specialists who will work on artificial intelligence infrastructure and other technology projects throughout the federal government.

Participants will commit to a two-year employment program working with teams that report directly to agency leaders in "collaboration with leading technology companies," according to an official government website. ["...and work closely with senior managers from companies partnering with the Tech Force."] Those "private sector partners" include Amazon Web Services, Apple, Google Public Sector, Dell Technologies, Microsoft, Nvidia, OpenAI, Oracle, Palantir, Salesforce and numerous others [including AMD, IBM, Coinbase, Robinhood, Uber, xAI, and Zoom], the website says.

The Tech Force shows the Trump administration increasing its focus on developing America's AI infrastructure as it competes with China for dominance in the rapidly growing industry... The engineering corps will be working on "high-impact technology initiatives including AI implementation, application development, data modernization, and digital service delivery across federal agencies," the site says.

"Answer the call," says the new web site at TechForce.gov.

"Upon completing the program, engineers can seek employment with the partnering private-sector companies for potential full-time roles — demonstrating the value of combining civil service with technical expertise." [And those private sector companies can also nominate employees to participate.] "Annual salaries are expected to be in the approximate range of $150,000 to $200,000."
IT

Is America's Tech Industry Already Facing a Recession? (msn.com) 66

America's unemployment rate for tech jobs rose to 4% in November, and "has been steadily rising since May," reports the Washington Post (citing data from the IT training/certifications company CompTIA). Between October and November, the number of technology workers across different industries fell 134,000, while the number of people working in the tech industry declined by more than 6,800. Tech job postings were also down by more than 31,800, the report found, citing data from the Bureau of Labor Statistics and California-based market intelligence firm Lightcast. "The data is pretty definitive that the tech industry is struggling," said Mark Zandi, Moody's chief economist. "There's a jobs recession in the industry, and it feels like that's going to continue given the slide in postings...."

The unemployment rate in the tech industry still sits below the national rate, which in November hit 4.6 percent, the highest since 2021. However, that gap has been narrowing, with tech unemployment rising faster in recent months than is the case nationally.... Employers are largely in "wait and see" mode when it comes to hiring given the current uncertainties surrounding the economy and impact of AI, so they're likely to delay backfilling, Herbert said, citing CompTIA's surveys of chief information officers. But Justin Wolfers, professor of public policy and economics at the University of Michigan, said uncertainty is likely to continue in the foreseeable future. "I'm feeling substantially more pessimistic," Wolfers said, recalling that Federal Reserve Chair Jerome H. Powell recently suggested that federal job numbers may be overstated. "That's pretty grim."

Technology companies have announced more than 141,000 job cuts so far this year, representing a 17 percent increase from the same period last year, according to outplacement firm Challenger, Gray & Christmas. At the same time Big Tech companies like Google, Microsoft, Meta and Amazon have announced plans to invest up to $375 billion in AI infrastructure this year.

"AI is quickly becoming a requirement, with 41 percent of all active job postings representing AI roles or requiring AI skills, according to CompTIA's analysis," the article points out.

Economist Zandi tells the Post that "If you have AI skills, there seems to be jobs. But if you don't, I think it's going to feel like you've been hit by a dump truck."
Cloud

Airbus Moving Critical Systems Away From AWS, Google, and Microsoft Citing Data Sovereignty Concerns (theregister.com) 63

Airbus is preparing to tender a major contract to move mission-critical systems like ERP, manufacturing, and aircraft design data onto a digitally sovereign European cloud, citing national security concerns and fears around U.S. extraterritorial laws like the CLOUD Act. "I need a sovereign cloud because part of the information is extremely sensitive from a national and European perspective," Catherine Jestin, Airbus's executive vice president of digital, told The Register. "We want to ensure this information remains under European control." The Register reports: The driver is access to new software. Vendors like SAP are developing innovations exclusively in the cloud, pushing customers toward platforms like S/4HANA. The request for proposals launches in early January, with a decision expected before summer. The contract -- understood to be worth more than 50 million euros -- will be long term (up to ten years), with price predictability over the period. [...] Jestin is waiting for European regulators to clarify whether Airbus would truly be "immune to extraterritorial laws" -- and whether services could be interrupted.

The concern isn't theoretical. Chief Prosecutor of the International Criminal Court (ICC) Karim Khan reportedly lost access to his Microsoft email after Trump sanctioned him for criticizing Israeli PM Benjamin Netanyahu, though Microsoft denies suspending ICC services. Beyond US complications, Jestin questions whether European cloud providers have sufficient scale. "If you asked me today if we'll find a solution, I'd say 80/20."

Microsoft

Microsoft Made Another Copilot Ad Where Nothing Actually Works (theverge.com) 38

Microsoft's latest holiday ad for its Copilot AI assistant features a 30-second montage of users seamlessly syncing smart home lights to music, scaling recipes for large gatherings, and parsing HOA guidelines -- none of which the software can actually perform reliably when put to the test. The Verge methodically tested each prompt shown in the ad and found that Copilot repeatedly hallucinated interface elements that didn't exist, claimed to highlight on-screen buttons when it hadn't, and abandoned calculations midway through.

The smart home interface shown in the ad belongs to "Relecloud," a fictional company Microsoft uses in internal case studies. A Microsoft spokesperson confirmed that both the HOA document and the inflatable reindeer photo were fabricated for the advertisement. The ad closes with Santa Claus asking Copilot why toy production is behind schedule.

Further reading: Talking To Windows' Copilot AI Makes a Computer Feel Incompetent.
AI

Microsoft AI Chief: Staying in the Frontier AI Race Will Cost Hundreds of Billions (businessinsider.com) 34

Microsoft AI CEO Mustafa Suleyman estimates that staying competitive in frontier AI development will require "hundreds of billions of dollars" over the next five to ten years, a sum that doesn't even account for the high salaries companies are paying individual researchers and technical staff. Speaking on a podcast, Suleyman compared Microsoft to a "modern construction company" where hundreds of thousands of workers are building gigawatts of CPUs and AI accelerators. There's "a structural advantage by being inside a big company," he said.

When asked whether startups could compete with Big Tech, Suleyman said "it's hard to say," adding that "the ambiguity is what's driving the frothiness of the valuations." Meta CEO Mark Zuckerberg said in September he'd rather risk "misspending a couple of hundred billion" than fall behind in superintelligence.
Microsoft

LG Will Let TV Owners Delete Microsoft Copilot After Customer Outcry (theverge.com) 39

LG said it will let owners of its TVs delete Microsoft's Copilot shortcut after several reports highlighted the unremovable icon. In a statement to The Verge, LG says the company "respects consumer choice and will take steps to allow users to delete the shortcut icon if they wish." From the report: Last week, a user on the r/mildlyinfuriating subreddit posted an image of the Microsoft Copilot icon in their lineup of apps on an LG TV, with no option to delete it. "My LG TV's new software update installed Microsoft Copilot, which cannot be deleted," the post says. The post garnered more than 36,000 upvotes as people grow more frustrated with AI popping up just about everywhere.

Both LG and Samsung announced plans to add Microsoft's Copilot AI assistant to their TVs in January, but it appears to be popping up on LG TVs following a recent update to webOS. [LG spokesperson Chris De Maria] clarifies that the icon is a "shortcut" to the Microsoft Copilot web app that opens in the TV's web browser, rather than "an application-based service embedded in the TV." He also adds that "features such as microphone input are activated only with the customer's explicit consent." There's no word on when LG will roll out the ability to delete the Copilot icon.

IT

Browser Extensions With 8 Million Users Collect Extended AI Conversations (arstechnica.com) 12

An anonymous reader shares a report: Browser extensions with more than 8 million installs are harvesting complete and extended conversations from users' AI conversations and selling them for marketing purposes, according to data collected from the Google and Microsoft pages hosting them.

Security firm Koi discovered the eight extensions, which as of late Tuesday night remained available in both Google's and Microsoft's extension stores. Seven of them carry "Featured" badges, which are endorsements meant to signal that the companies have determined the extensions meet their quality standards. The free extensions provide functions such as VPN routing to safeguard online privacy and ad blocking for ad-free browsing. All provide assurances that user data remains anonymous and isnâ(TM)t shared for purposes other than their described use.

AI

OpenAI in Talks With Amazon About Investment That Could Exceed $10 Billion (cnbc.com) 39

OpenAI is in discussions with Amazon about a potential investment and an agreement to use its AI chips, CNBC confirmed on Tuesday. From the report: The details are fluid and still subject to change but the investment could exceed $10 billion, according to a person familiar with the matter who asked not to be named because the talks are confidential. The discussions come after OpenAI completed a restructuring in October and formally outlined the details of its partnership with Microsoft, giving it more freedom to raise capital and partner with companies across the broader AI ecosystem.

Microsoft has invested more than $13 billion in OpenAI and backed the company since 2019, but it no longer has a right of first refusal to be OpenAI's compute provider, according to an October release. OpenAI can now also develop some products with third parties. Amazon has invested at least $8 billion into OpenAI rival Anthropic, but the e-commerce giant could be looking to expand its exposure to the booming generative AI market. Microsoft has taken a similar step and announced last month that it will invest up to $5 billion into Anthropic, while Nvidia will invest up to $10 billion in the startup.

Power

Senators Count the Shady Ways Data Centers Pass Energy Costs On To Americans (arstechnica.com) 53

U.S. senators are probing whether Big Tech data centers are driving up local electricity bills by socializing grid upgrade costs onto residents. Some of the tactics they're using include NDAs, shell companies, and lobbying. Ars Technica reports: In letters (PDF) to seven AI firms, Senators Elizabeth Warren (D-Mass.), Chris Van Hollen (D-Md.), and Richard Blumenthal (D-Conn.) cited a study estimating that "electricity prices have increased by as much as 267 percent in the past five years" in "areas located near significant data center activity." Prices increase, senators noted, when utility companies build out extra infrastructure to meet data centers' energy demands -- which can amount to one customer suddenly consuming as much power as an entire city. They also increase when demand for local power outweighs supply. In some cases, residents are blindsided by higher bills, not even realizing a data center project was approved, because tech companies seem intent on dodging backlash and frequently do not allow terms of deals to be publicly disclosed.

AI firms "ask public officials to sign non-disclosure agreements (NDAs) preventing them from sharing information with their constituents, operate through what appear to be shell companies to mask the real owner of the data center, and require that landowners sign NDAs as part of the land sale while telling them only that a 'Fortune 100 company' is planning an 'industrial development' seemingly in an attempt to hide the very existence of the data center," senators wrote. States like Virginia with the highest concentration of data centers could see average electricity prices increase by another 25 percent by 2030, senators noted. But price increases aren't limited to the states allegedly striking shady deals with tech companies and greenlighting data center projects, they said. "Interconnected and interstate power grids can lead to a data center built in one state raising costs for residents of a neighboring state," senators reported.

Under fire for supposedly only pretending to care about keeping neighbors' costs low were Amazon, Google, Meta, Microsoft, Equinix, Digital Realty, and CoreWeave. Senators accused firms of paying "lip service," claiming that they would do everything in their power to avoid increasing residential electricity costs, while actively lobbying to pass billions in costs on to their neighbors. [...] Particularly problematic, senators emphasized, were reports that tech firms were getting discounts on energy costs as utility companies competed for their business, while prices went up for their neighbors.

Microsoft

Microsoft Will Finally Kill Obsolete Cipher That Has Wreaked Decades of Havoc (arstechnica.com) 63

An anonymous reader quotes a report from Ars Technica: Microsoft is killing off an obsolete and vulnerable encryption cipher that Windows has supported by default for 26 years following more than a decade of devastating hacks that exploited it and recently faced blistering criticism from a prominent US senator. When the software maker rolled out Active Directory in 2000, it made RC4 a sole means of securing the Windows component, which administrators use to configure and provision fellow administrator and user accounts inside large organizations. RC4, short for Rivist Cipher 4, is a nod to mathematician and cryptographer Ron Rivest of RSA Security, who developed the stream cipher in 1987. Within days of the trade-secret-protected algorithm being leaked in 1994, a researcher demonstrated a cryptographic attack that significantly weakened the security it had been believed to provide. Despite the known susceptibility, RC4 remained a staple in encryption protocols, including SSL and its successor TLS, until about a decade ago. [...]

Last week, Microsoft said it was finally deprecating RC4 and cited its susceptibility to Kerberoasting, the form of attack, known since 2014, that was the root cause of the initial intrusion into Ascension's network. "By mid-2026, we will be updating domain controller defaults for the Kerberos Key Distribution Center (KDC) on Windows Server 2008 and later to only allow AES-SHA1 encryption," Matthew Palko, a Microsoft principal program manager, wrote. "RC4 will be disabled by default and only used if a domain administrator explicitly configures an account or the KDC to use it." [...] Following next year's change, RC4 authentication will no longer function unless administrators perform the extra work to allow it. In the meantime, Palko said, it's crucial that admins identify any systems inside their networks that rely on the cipher. Despite the known vulnerabilities, RC4 remains the sole means of some third-party legacy systems for authenticating to Windows networks. These systems can often go overlooked in networks even though they are required for crucial functions.

To streamline the identification of such systems, Microsoft is making several tools available. One is an update to KDC logs that will track both requests and responses that systems make using RC4 when performing requests through Kerberos. Kerberos is an industry-wide authentication protocol for verifying the identities of users and services over a non-secure network. It's the sole means for mutual authentication to Active Directory, which hackers attacking Windows networks widely consider a Holy Grail because of the control they gain once it has been compromised. Microsoft is also introducing new PowerShell scripts to sift through security event logs to more easily pinpoint problematic RC4 usage. Microsoft said it has steadily worked over the past decade to deprecate RC4, but that the task wasn't easy.
"The problem though is that it's hard to kill off a cryptographic algorithm that is present in every OS that's shipped for the last 25 years and was the default algorithm for so long, Steve Syfuhs, who runs Microsoft's Windows Authentication team, wrote on Bluesky. "See," he continued, "the problem is not that the algorithm exists. The problem is how the algorithm is chosen, and the rules governing that spanned 20 years of code changes."

Slashdot Top Deals