Sitemap
Press enter or click to view image in full size

Member-only story

Microsoft’s Silly Root Certificates

4 min readNov 3, 2024

--

I trust Apple for their usage of cryptography and in implementing it on their operating systems and devices. Overall, Apple has a long track record in using secure enclaves on their devices and has generally advanced digital trust with the latest cryptographic methods. Personally, I do not rate Microsoft highly at all for its digital trust and in the implementation of cryptography. To me, Microsoft is often years behind the rest of the industry when it comes to the usage of state-of-the-art cryptography methods.

So, I might be wrong, but I think Microsoft is adding root CA (Certificate Authority) digital certificates on the fly from the Cloud. This is not good practice and could cause a great deal of problems and become an attack vector. This is especially a problem for air-gapped systems. Other applications, such as for Python, will not trigger a download of trusted root certificates, so it could break some Python programmes. Amongst other strange things, Microsoft also seems to add expired root CA certificates to their new installations of Windows, too.

Just so that you understand the importance of digital certificates, let’s investigate where they are used.

--

--

Prof Bill Buchanan OBE FRSE
Prof Bill Buchanan OBE FRSE

Written by Prof Bill Buchanan OBE FRSE

Professor of Cryptography. Serial innovator. Believer in fairness, justice & freedom. Based in Edinburgh. Old World Breaker. New World Creator. Building trust.