News: 1636056047

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Expired cert breaks Windows 11 snipping tool, emoji panel, S Mode features, other stuff

(2021/11/04)


It has proved an unfortunate Halloween for Microsoft, with the ghost of an expired certificate haunting Windows 11 users. The upshot is: various built-in programs may stop working properly or cannot be opened at all.

Redmond yesterday said "some users" are affected, so you may or may not notice the blunder. This all applies to at least Windows 11 version 21H2.

The cryptographic cert at the heart of this affair ran out at the end of October leading to failures this month, according to Microsoft: "Starting on November 1, 2021, some users might be unable to open or use certain built-in Windows apps or parts of some built-in apps. This is caused by an issue with a Microsoft digital certificate, which expired October 31, 2021."

[1]

The hardest hit is the snipping tool, used to capture and annotate screenshots, which is now just broken. Microsoft can't fix it just yet, and so advises folks to experience the joys of turn-of-the-century computing with the following suggested workaround.

[2]

[3]

"Use the Print Screen key on your keyboard and paste the screenshot into your document. You can also paste it into Paint to select and copy the section you want," [4]it advised .

For those using the supposedly more secure-and-streamlined Windows 11 S Mode, the accounts and landing pages in the Settings app may be inaccessible. The Start menu is also knackered in S Mode. Again, Microsoft has no fix for this, or even a workaround, right now.

[5]

"We are working on a near term resolution for the Snipping tool and the S mode issues and will provide an update when available," the IT giant said.

[6]Microsoft emits more Win 11 fixes for AMD speed issues and death by PowerShell bug

[7]A Windows 11 tsunami? No, more of a ripple as Microsoft's latest OS hits 5% PC market

[8]Microsoft report says many employees are stuck on oldy-mouldy computers and should probably be upgraded

[9]These couldn't wait for Patch Tuesday: Adobe issues bonus fixes for 92 security holes in 14 products

The following components are also busted: the Touch Keyboard, Voice Typing and Emoji Panel; the Input Method Editor user interface; and, incredibly, the Getting started and Tips app. Yup, Microsoft broke emoji input. How will it ever regain the trust of the youth now?

These three items can be restored to working order by installing [10]KB5006746 , which you can try applying by checking the Settings > Update & Security > Windows Update > Optional updates available panel.

The patch, which was released on October 21, is described as a preview, meaning you'd normally have to install it manually if needed. That said, Microsoft said it "will automatically update affected devices with KB5006746." To us, that sounds as though you can apply it by yourself now, or wait for Redmond to roll it out to you. Microsoft hasn't given a timescale for fixing the snipping tool or S mode issues as yet.

We guess there are two takeaways from this: try not to let your certs expire, and try not to rush into installing a new operating system as soon as it's released. Give it a few months at least to settle down. ®

Get our [11]Tech Resources



[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/oses&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YYlXzJ4Po4aSZOlChvMZHwAAAMI&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/oses&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YYlXzJ4Po4aSZOlChvMZHwAAAMI&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/oses&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YYlXzJ4Po4aSZOlChvMZHwAAAMI&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[4] https://docs.microsoft.com/en-us/windows/release-health/status-windows-11-21h2#2739msgdesc

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/oses&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YYlXzJ4Po4aSZOlChvMZHwAAAMI&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[6] https://www.theregister.com/2021/10/22/windows_11_fixes_windows_10_/

[7] https://www.theregister.com/2021/10/28/windows_11/

[8] https://www.theregister.com/2021/11/04/microsoft_device_decisions/

[9] https://www.theregister.com/2021/10/26/adobe_october_extra_patches/

[10] https://support.microsoft.com/en-us/topic/october-21-2021-kb5006746-os-build-22000-282-preview-03190705-0960-4ba4-9ee8-af40bef057d3

[11] https://whitepapers.theregister.com/



Certified useless

Hans 1

This basically means these apps have a killswitch, the whole design is buggered. Why would you need a valid certificate somewhere on the internet to be able to open apps ?

Re: Certified useless

Snake

I guess we can now say this applies with any computerised construct, be it app or data, that has been secured by certificates: kill the cert, your data is GONE!

Re: Certified useless

Anonymous Coward

Remember when Firefox did it a few years ago, and it disabled all add-ons?

https://www.theregister.com/2019/05/06/mozilla_firefox_add_on_expiry/

@Snake - Re: Certified useless

Anonymous Coward

Not necessarily. It all depends on what the program decides to do when certificates fail, they could simply display a warning and allow you to continue after some extra clicks for confirmation. Firefox for example does that most of the time.

Re: Certified useless

JimboSmith

I don't think people using PC over IP via a thin client will be able to use the Print Screen workaround MSFT have suggested. Unless things have changed in W11 from 10. Pressing Print Screen never worked and you had to use the snipping tool. Well done MSFT.

If you want more people to upgrade I don't think having loads of your accessories failing is a good idea.

Re: Certified useless

Blackjack

Even Vista wasn't this terrible.

Re: Even Vista wasn't this terrible

Anonymous Coward

You have forgotten

Re: Certified useless

Antonius_Prime

It could be worse, it could be WinME...

(Even typing that was painful. Imma need me one o'dem tings in the icon...

Or a few...)

Re: Certified useless

ChrisC

I must be one of the few people on the entire planet who had a decent experience with WinME - in comparison to the flakey mess that was Win98 running on the same hardware, ME was (relatively, insofar as any of that era of consumer-focused Windows versions ever could be) pretty stable during its time in residence at Chez Chris, especially when it came to handling those newfangled USB whatchamacallits.

Put it this way, of all the versions of Windows I've used and paid for out of my own pocket one way or another, ME wouldn't be at the top of the "seriously MS, I pay you good money and THIS is what I get in return" list...

Re: Certified useless

drankinatty

There were a few of us. After configured properly, there was little actual difference between WinME and Win98 2nd Edition. I never had any issue with it either. It came on a couple of Dell boxes bought for secretarial computers. Load Firefox (still 2.X at that time before the rabbit-pellet version number cycle started), Office 2K, connect to the SAMBA shares for the Linux servers, and Me was quite usable.

Re: Certified useless

trindflo

It probably means more than applications. All of Windows 10 drivers are required to be signed with Microsoft's certificate. I've been asking if that means that Windows 10 has a kill switch, and now I think I have my answer.

Re: Certified useless

Zippy´s Sausage Factory

Worse, this provides a nice easy attack path for malware. I don't care how secure they say their certificate store is - nothing is infallible. Doing this to a thousand Windows PCs at once on a network is going to be a great denial of service tool, and I wouldn't be surprised if a lot of "security" agencies just added a new item to their "to research" lists...

Re: Certified useless

J. Cook

This leads me to ask: how hard is it to fake a CRL or return a "this certificate has been revoked" OCSP response? Because I can see that as a nice way to wreck havoc.

Re: Certified useless

Cederic

So that malware doesn't overwrite and pretend to be those apps?

Re: Certified useless

Ken Hagan

No. That doesn't explain it. You can, and probably should, sign your code to stop Trojans but as long as you also timestamp that sig it remains valid after the certificate has expired. There are no excuses for not timestamping the sig on released software.

Re: Certified useless

Anonymous Coward

The certificate process can be considered malware, as it can take away functionality that would have been available had it not been for the certificate.

mark l 2

These sort of bug are exactly the reason why I wouldn't upgrade to Windows 11 for at least 6 months after release. As imagine your critical piece of hardware with a touch screen device running Windows 11 is rendered useless by this expired cert because you cannot use the on screen keyboard or voice typing until MS get a fix sorted.

the spectacularly refined chap

Would that be any safer though? The one thing you can be sure of with an expiring cert is that it's going to expire. That could be now, it could be too or three years down the line. This isn't a teething problem in a new OS but a structural weakness of Microsoft's own making. It's pure coincidence that it happened now and not in 18 months time when the wait for the service pack types have already jumped.

For myself it's part of the reason I've ditched MS wherever possible on a personal basis at least - the last hold out is a rather pricey EDA package I don't mind keeping a VM for. I've never liked this direction of users (and owners) losing operational sovereignty of their own machines, whether that is breaking changes via updates shuffled down your throat or plain carelessness as here.

MatthewSt

If it's not a teething problem in a new OS then why do other versions of Windows (which ship with the same tools) not have the same problem?

Doctor Syntax

Different certs with different expiry dates. It's a certificate management problem. If the certs are due to expire you need to ship updates in good time. It could happen to any product that takes its eye off the ball. Being a new OS is no excuse.

John Brown (no body)

"losing operational sovereignty of their own machines"

I voted MSEXIT, I'm a proud FreeBSD using MSEXITeer :-)

Always looked like Beastie to me --------->

Part of the OS

Anonymous Coward

Why would individual parts of the OS need certificates anyway?

Re: Part of the OS

Howard Sway

So that it can report everything you do back to Redmond over a secure encrypted connection.

I mean, why the hell else would the start menu and screenshot tool even need a security certificate to work?

Also, this sounds like a sneaky way of forcing you to upgrade your OS in future.

Re: Part of the OS

FIA

Probably because they're cryptographically signed.

Their integrity can no-longer be guaranteed as the certificate has expired so no screenshots for you. (I mean sure, the OS could ignore this, but then that kind of renders any protection it offers moot too).

It's a broader issue with this kind of security. You need some expiration mechanism otherwise mis-issued or compromised certs will never expire, however you also don't want your apps to stop working randomly.

If you figure out a good solution, you'll probably end up quite wealthy. :D

Re: Part of the OS

jake

"If you figure out a good solution, you'll probably end up quite wealthy."

Nah. I figured out the solution before MS-DOS 2.0 came out. It's quite simple, really.

User education.

Sadly, the users want no truck with it.

Re: Part of the OS

Filippo

"Sadly, the users want no truck with it."

So, not the solution then. Any proposal in the form of "this would work, if only [...]" is not a solution until the [...] bit is sorted.

Re: Part of the OS

ChrisC

Tying your system security to something outside of your (and by "your" I mean not just the end user sat in front of a new somewhat useless PC, but every part of whatever IT support structure sits above them) control isn't the answer either, as this latest Redmond fubar so amply demonstrates.

There probably isn't a simple answer, but personally I'd prefer a solutuon which is at least wholly controlled by me or the people I work with, even if that means having to take a bit more personal responsibility. Because if something outside of our control prevents me from doing what I need to do with the PC, then I'm not going to be thinking a pleasant "phew, good job on keeping my system safe", but a rather more sarcastic "great job on keeping us safe from malwa...oh, wait, you are the fucking malware", and wondering if there's some sneaky workaround to restore correct system operation...

Re: Part of the OS

jake

"So, not the solution then."

Actually, yes. It is. After several decades of studying how users manage to bollocks up damn near everything out of sheer, unadulterated ignorance, I truly believe that user education is THE solution. No others will work.

"Any proposal in the form of "this would work, if only [...]" is not a solution until the [...] bit is sorted."

All I did was point out the solution. I in no way suggested a method to implement it.

Re: Part of the OS

trindflo

The certificates are for testing the signatures inside executables. Drivers have different signatures than apps, and apps that aren't published on the same day probably expire at different times.

This is to prevent hackers from replacing key parts of the operating system (AKA a root kit). If the OS won't start without properly signed drivers a root kit would break the system rather than lurk under the surface as a Trojan Horse (and potentially steal your money) - that is, the root kit would not work.

It also seems to give Microsoft a convenient kill switch for Windows 10.

Re: Part of the OS

Anonymous Coward

"the root kit would not work."

Not sure if you have noticed, that doesn't seem to stop them and ransomeware.

Chocolate fireguard comes to mind.

Re: Part of the OS

Doctor Syntax

"The certificates are for testing the signatures inside executables."

OTOH the executable is the same as it was last week. The problem isn't the executable. It's not even certification. It's the expiry date of the certificate. The solution is to either ensure the expiry date is far enough ahead of expected lifetime when the executable's published or have a sufficiently robust system for enabling update to be installed well in advance and also take into account those systems that are not and will not be connected to the internet.

Re: Part of the OS

Loyal Commenter

It makes sense to verify the certificate on installation, to ensure the software is from who it says it is from (and not, for instance, malware delivered by a phishing attack). It makes sense for those certificates to expire, and to be revokable, for security reasons.

Verifying the same signature on every load seems like overkill, though. What's wrong with creating a cryptographic hash of the software, along with some unique OS key, when it is installed, and checking that. Something that doesn't expire.

OK, that doesn't solve the issue with being able to make the software revokable, but I'd question whether that is actually a feature anyone other than Microsoft would want to implement. Once I've installed something, I'd like it to remain installed.

Re: Part of the OS

drankinatty

Moreover and specifically, "Why on God's Green Earth" would "snipping" tool need to phone-home? It's not like it will have a big risk of being pirated. The new "Snip & Sketch" is patently worthless compared to the original "Snipping Tool" (circa Win7). In fact, there should be an option to disable telemetry completely. The larger question being what information about screen shots should ever be transmitted?

I wonder what happens to the apps if you have no network cable? Does Win11 roll over and die on a stand-alone machine? That's is one of the primary reason I always install with a normal windows login and never a Microsoft account.

Early adopters

Duffaboy

You are doing the testing for Microsoft, that's why I wait till the O/S is embedded in before I will install it. Windows 10 is just fine for me.

karlkarl

So when does the new certificate expire?

2022? 2023? 2024?

DRM bullsh*t. You are basically buying an unspecified time limited demo.

Anonymous Coward

It is worrying isn't it.

karlkarl

Indeed.

But what is even more worrying is that this time next year 99% of desktop users will be running the defective piece of crap and my software will have to support it.

It is embarrassing frankly. Us plebs are a ridiculous bunch.

jake

"It is worrying isn't it."

Not if you don't buy into it.

I'm absolutely astonished that the Corporate World keeps falling for it, year after year, decade after decade. You'd think they'd have learned by now.

I wonder how many tens of billions of dollars have been lost in man-hours alone due to Microsoft incompetence. And the Corporate Lawyers allow this crap in the building? Still? Mind boggling.

Tim99

OK, your power in an organization is proportional to your budget and the number of staff you control. Many senior IT types like Windows, it needs a lot of hand-holding staff, gets expensively updated, and breaks on a regular basis; and is "what everybody uses".

Plausible support for this idea is that IBM who, arguably, invented the PC (Wintel) ditched manufacture of PCs to Lenovo. IBM (Perhaps, as part of their cost-cutting slow amble to the bottom?) stated that they use a lot of Apple kit. They claim support costs are lower than for Windows. Here is my post from last year:-

----------------------------------------------

...At the end of 2019 they (IBM) had ~290,000 Apple devices of which ~200,000 use macOS. At the same time they had 383,800 employees, obviously some employees will use more than one device. I have a relative who is a very senior IBM techie who told me that in his (large) part of IBM far more techies use Linux than Windows - He was also of the opinion that a number of IBMers elected to go to Apple rather than move from Windows 7 to 10.

According to IBM, Mac users cost less to support with about 1/3 of the support personnel and are generally happier and more productive.

https://www.zdnet.com/article/ibm-cio-mac-users-perform-better-more-engaged-than-windows-users/

https://www.jamf.com/resources/press-releases/ibm-announces-research-showing-mac-enables-greater-productivity-and-employee-satisfaction-at-ibm/

https://www.macrotrends.net/stocks/charts/IBM/ibm/number-of-employees

---------------------------------------------

The last link is probably incorrect (or very worrying?!), as it states that IBM ditched 92% of their workforce in 2020 - Other links suggest ~345,000 current staff - So unless COVID was worse that we believe...

Trigun

An interesting way of making your OS redudant and, more importantly, unusable when *you* have decided it's eol. Microsoft are heading into the red on my peeved scale if they are going to be applying certificates to things which don't need it.

Anonymous Coward

If that was the case, then why wouldn't they 1) set the support timeframe for Windows 11, and then 2) create a signing certificate that expired after the end-of-support of Windows 11, and then 3) sign all Windows 11 applications with this certificate?

John Brown (no body)

"Microsoft are heading into the red on my peeved scale"

Only just heading into red now? For me. the pointer is wrapped around the stop needle at the end of the red and it got there years ago!

Good job MS hasn't heard of Let's Encrypt

TJ1

Don't phone home for 3 months? Sorry, your applications will not start!

(not sure how much of a joke this actually is!)

Re: Good job MS hasn't heard of Let's Encrypt

Anonymous Coward

I'm not sure why you think the systems on which LetsEncrypt certficates are installed need to be the systems contacting letencrypt.org.

Re: Good job MS hasn't heard of Let's Encrypt

TJ1

It was a joke, but seeing as you missed that part, I never mentioned contacting letencrypt.org (shouldn't that be letSencrypt.org) but "phoning home" as almost all Microsoft software seems to do - to Microsoft.

If the signing certificate expired every 3 months and the system hadn't phoned home to Microsoft to fetch updates in that time things would get 'interesting'.

Scary that this appears to pre-suppose all Windows systems must be online regularly, and have to re-fetch signed applications even if the code hasn't changed (unless the signatures are detached and it can just fetch the new signature).

That could equate to a lot of bandwidth!

Re: Good job MS hasn't heard of Let's Encrypt

John Brown (no body)

"If the signing certificate expired every 3 months and the system hadn't phoned home to Microsoft to fetch updates in that time things would get 'interesting'."

Doesn't Windows already get a bit arsey if it's not connected to the internet for some defined length of time any way? I though it started doing that years ago.

cornetman

> These three items can be restored to working order by installing KB5006746, which you can try applying by checking the Settings > Update & Security > Windows Update > Optional updates available panel.

Just waiting for Windows 11 Update to be broken by an expired certificate to really mess you up.

Honestly, that doesn't seem all that far-fetched considering it is downloading packages from the Internet.

"Some users are affected"

Anonymous Coward

Ahem, that's the comment we put in our release notes when all users are affected but we don't want to make it obvious we fucked up.

Anon, obvs.

Re: "Some users are affected"

yetanotheraoc

Yes, that's the code:

Some users -.> all users who match a popular configuration

Limited number of users -.> all users who match a less usual configuration

crackle, hum, radio silence -.> we are still researching how many users...

What a shame

redpawn

my computer is not supported by Widows 11.

"...you might as well skip the Xmas celebration completely, and instead
sit in front of your linux computer playing with the
all-new-and-improved linux kernel version."
(By Linus Torvalds)