Webtrends Tracking Code
 
UK Home >  OUT-LAW News >  News Archive >  2003 >  May 2003 >  Do not use Microsoft's Passport, says Gartner

Do not use Microsoft's Passport, says Gartner

OUT-LAW News, 20/05/2003

A recent security flaw in Microsoft’s Passport service – which provides on-line identity authentication for 200 million users – has led analyst firm Gartner to warn its clients not to use the system even though Microsoft has since fixed the problem.

The Passport service allows a user to sign into any participating site by using only the user’s e-mail address and a single password. But on 8th May, Microsoft admitted that a serious security flaw had been discovered in the system.

The flaw could allow a novice hacker to hijack another's account, thereby accessing credit card details and more, by using a function that resets forgotten passwords.

To hack the system, all that was needed was to enter a URL into a web browser that contained the e-mail address of the account to be changed and the e-mail address to which the hacker wants the new password sent.

Only when the holder tried to log in using the old password or, more likely, when the credit card bills began to flood in, would the account holder discover what had happened.

Microsoft has confirmed that the flaw was quickly rectified and that, so far as it is aware, no accounts were tampered with.

However, while acknowledging the repair, Gartner warned:

“A serious security flaw shows that Microsoft Passport identities could be easily compromised. Financial institutions and other enterprises should replace or augment Passport until at least November 2003.”

The hard-hitting report speculates that more vulnerabilities are likely to surface in the software. Consequently, Gartner says business users should abandon it until Microsoft can prove that proper security is in place.

Gartner also recommends that businesses contact customers who use Passport, advising these customers to follow Microsoft’s instructions with regard to the breach.

 

 

OUT-LAW Recommends

Data Protection training
We offer training courses on Data Protection and Freedom of Information laws

Winner at 2008 Webby Awards

OUT-LAW star: link to the home page
Disclaimer: This was printed from OUT-LAW.COM, a service of international law firm Pinsent Masons. We hope you find this content useful. However, please note that nothing in this document constitutes specific legal advice. You should consult a suitably qualified lawyer on any specific legal problem or matter. Any questions, please email info@out-law.com.