Advertisement
Promo

Industry watch Toolkit

Passport security takes another holiday

Munir Kotadia ZDNet.co.uk

Published: 02 Jul 2003 14:09 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Microsoft has had to admit that for the second time in six weeks, a major security flaw has been discovered in Passport -- the single sign-on repository designed to keep all its users' personal details and credit card numbers in a safe place.

The more recent glitch, fixed by Microsoft on Monday, could have allowed attackers to gain access to user accounts that were opened more than four years ago, according to several industry reports. The flaw, publicised on a security mailing list, made it possible for an attacker who knew an account name and the account holder's general geographic location to discover the account's password. Microsoft was not aware of accounts having been compromised, reports said.

The flaw is similar to one reported in May by Pakistan MBA student Muhammad Faisal Rauf Danka, who discovered that the Passport password recovery mechanism -- which is used by users who have forgotten their passwords -- could allow an attacker to gain full access to any users' account. According to Danka, he had tried to warn Microsoft about the problem for months, but the software giant did not respond to his emails.

Microsoft has long claimed that Passport is central to its future plans, but an alarming number of security vulnerabilities have been discovered.

Last August, Microsoft promised the Federal Trade Commission that it would improve the security of Passport and refrain from making false statements about privacy and protection. The FTC could hit Microsoft with a fine of $11,000 per violation, which would amounts to trillions of dollars if the millions of Passport users are taken into account.


For all security-related news, including updates on the latest viruses, hacking exploits and patches, check out ZDNet UK's Security News Section.

Let the editors know what you think in the Mailroom.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
37 out of 87 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:










Discussions

NoThomas NoThomas

We can agree to disagree

Monday 16 November 2009, 3:55 PM

16 comments
CarlBrummy CarlBrummy

Enough already

Monday 16 November 2009, 9:36 AM

53 comments
Video icon

Video

Featured Talkback

In association with Network Liberation Movement
When all is said, if Microsoft produce the best product people will buy it and thats a good thing. If people have to buy their product because no one else can produce an alternative, only because interoperability protocols are kept secret, then thats a bad thing.

By: pround

Read full story:
EU court crushes Microsoft's antitrust appeal


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters