Newsletter Archives
-
Steve Syfuhs: What happens behind the scenes when you type your password into the Windows logon screen
A fascinating story from a guy who knows where the bodies are buried.
This basically works like an oracle. Cred Guard returns an opaque blob to LSA. Later LSA asks Cred Guard to decrypt something so LSA hands it the opaque blob and the thing to decrypt. Cred Guard decrypts the opaque blob, then using the key in that blob, decrypts the thing.
It ain’t pretty.