HomeSecurityMicrosoft: its plans to strengthen security in Windows 10

Microsoft: its plans to strengthen security in Windows 10

Windows 10 will apparently use two-factor authentication standards for every device. The company considers the measure necessary to effectively defend against phishing attacks and data breaches in general through a weak password. The company announced new features aimed at securing corporate systems from malware attacks and data leaks.safe deposit Windows 10 Windows 10 Windows 10 Windows 10

Most people are calling the early release of Windows 10 Technical Preview the “event of the year” for the return of the Start menu, virtual desktops, and other visible features that make for a better and more intuitive user experience. However, the company says that the new operating system will bring much more significant changes, especially in the crucial area of ​​security.

If you really dig into the new Windows, you'll see a new service called Next Generation Credentials , which is installed, but doesn't work in preview builds.
NGC Windows

Today, Microsoft revealed more details about its plans to “move people away from single sign-on options like passwords.” The feature, which is not currently enabled in Windows 10 Technical Preview builds, will allow owners of systems running the new operating system (PC, tablet, or phone) to designate that device as trusted for authentication purposes. Combined with a PIN or some other biometric credential, such as a fingerprint, the user will be able to sign in to any supported mobile service.

The PIN, Microsoft says, can be any combination of alphanumeric characters – it won’t be limited to a short numeric code. If that PIN is stolen in a data breach or phishing attack, the thief won’t be able to access any services because the hardware part (the machine with the biometric device, such as a touchscreen) of the two-factor authentication requirement isn’t present. Similarly, a stolen device without the necessary PIN will be useless.

The authentication system wasn't built entirely by Microsoft. It's based on standards from the FIDO Alliance, which is backed by IT giants (Google, Microsoft, Lenovo, and others), banks and payment companies (BofA, PayPal, Visa, and MasterCard), and established security firms like RSA and IdentityX.

On the device itself, the required public and private keys can be issued directly by an enterprise, using the existing PKI infrastructure, while consumer devices will be able to have them from Windows 10 which will also be able to generate them.

According to Microsoft, Windows 10 users will be able to add any or all of their devices to their trusted computer with these new credentials. Alternatively, they can choose to add a single device, which will then serve as a virtual smart card. A mobile phone, for example, could offer two-factor authentication over Bluetooth or Wi-Fi to add local devices or access remote resources.

User access tokens will be stored in a virtual secure location running on Hyper-V technology, eliminating the effectiveness of common attacks such as Pass The Hash.

In today's announcements, Microsoft also mentioned two new Windows 10 features that will enhance security in its customers' businesses.

The first is a set of information-protection capabilities that will make it possible to protect corporate data, even on employee-owned devices. Windows 10, the company says, will allow network administrators to define policies that will automatically encrypt sensitive information, including corporate applications, data, email, and the content of intranet sites.

Because this encryption will be built into common Windows control panels, such as the Open and Save dialogs, it will be available to all Windows applications that use these controls. To enhance security, administrators will be able to create lists of applications that are allowed to access encrypted data, as well as those that will not have access to network management, and they can choose not to grant access to cloud services like Dropbox, for example.

Finally, a security measure that is built for high-profile companies with high security needs, such as banks, or the defense sector and government organizations. With Windows 10 Enterprise and specially configured OEM hardware, administrators will be able to completely lock down all devices, so that they cannot execute untrusted code.

With this setting, the only apps you will be allowed to run are those that have entered into an agreement with Microsoft that issued and signed the security certificate. These apps include any app from the Windows Store, as well as desktop apps that have been approved by Microsoft. Businesses with internal lines and corporate applications will be able to have their own security key generator, which will allow these apps to run on their network, but they will not operate outside the network.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS