Microsoft just made a rather embarrassing basic security error

internet
(Image credit: Shutterstock)

Microsoft has failed to renew the certificate for one of its rather important web pages, causing the site to break and to redirect people elsewhere. 

Spotted by The Register, the certificate for the Windows Insider software testing program expired on Thursday, June 9, in the afternoon hours. 

Those who tried to visit the site during that time were met with the usual “Your connection is not private” message, and users of Chrome, Firefox, or Safari, were advised by their browsers not to proceed.

Share your thoughts on Cybersecurity and get a free copy of the Hacker's Manual 2022end of this survey

Share your thoughts on Cybersecurity and get a free copy of the Hacker's Manual 2022. Help us find how businesses are preparing for the post-Covid world and the implications of these activities on their cybersecurity plans. Enter your email at the end of this survey to get the bookazine, worth $10.99/£10.99.

Those who did, were redirected to the main Windows page with 302 and 307 redirect responses, the publication claims, hinting the company was already aware of the issue, at the time. 

Expired certificates

Since then, the certificate has been renewed and the site back up and running again. 

Every now and then, certificates expire and don’t get renewed on time, breaking a few things in the process. In October 2021, one of the biggest non-profit Certificate Authorities (CA) services experienced high levels of renewals from websites and apps, resulting in some big name sites experiencing significant outages.

Due to its cross-signed DST Root CA X3 expiring, Let’s Encrypt's issue, which is run by the Internet Security Research Group, left websites and apps such as Shopify and Slack experiencing outages. At the time, Let’s Encrypt took to Twitter to advise the affected customers to consult the community forum, offering no promise of resolving the issue quickly.

A month later, an expired certificate affected Windows 11 21H2 and prevented Windows users from opening certain apps.

Back in 2020, an expired authentication certificate made Microsoft Teams inaccessible for a while. 

While expired certifications are a nuisance, they can be even worse if they affect root certificates and bork services, the publication explains. Such was the case with Sectigo’s AddTrust legacy root certificate which, when it expired two years ago, affected thousands of customers. 

TOPICS

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
A hand laying out a password
Microsoft fixes concerning issue with its Entra ID authentication tool
A laptop with the Windows 11 desktop on screen, glowing, while on a work desk
Are you unable to get security updates for Windows 11 24H2? Here’s the likely reason why, and the fix to get your PC safe and secure again
The best free firewall
Microsoft fixes Power Pages security flaw, tells users to be on their guard
A Windows 11 laptop sitting on a desk in front of a window
Microsoft warns its January Windows updates may fail if this Citrix software is installed
A close-up of an interent search bar with 'http://ww' visible
Let’s Encrypt halts expiration alerts - but it's for a good reason
Young woman using laptop, looking annoyed
Microsoft embarrasses itself with Windows 10 pop-up that hogs the desktop urging an upgrade to Windows 11 – then promptly crashes
Latest in Security
Data Breach
Thousands of healthcare records exposed online, including private patient information
China
Juniper patches security flaws which could have let hackers take over your router
Representational image depecting cybersecurity protection
GitLab has patched a host of worrying security issues
Ai tech, businessman show virtual graphic Global Internet connect Chatgpt Chat with AI, Artificial Intelligence.
AI agents can be hijacked to write and send phishing attacks
China
Volt Typhoon threat group had access to American utility networks for the best part of a year
Abstract image of cyber security in action.
MassJacker malware targets those looking for pirated software
Latest in News
A super close up image of the Google Gemini app in the Play Store
It's official: Google Assistant will be retired for phones this year, with Gemini taking over
Quordle on a smartphone held in a hand
Quordle hints and answers for Sunday, March 16 (game #1147)
NYT Strands homescreen on a mobile phone screen, on a light blue background
NYT Strands hints and answers for Sunday, March 16 (game #378)
NYT Connections homescreen on a phone, on a purple background
NYT Connections hints and answers for Sunday, March 16 (game #644)
Three iPhone 16 handsets on show
Apple could launch an iPhone 17 Ultra this year – but we've heard these rumors before
Super Mario Odyssey
ChatGPT is the ultimate gaming tool - here's 4 ways you can use AI to help with your next playthrough