ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Microsoft promises to fix Passport flaw by end of day

Will Knight ZDNet.co.uk

Published: 22 Oct 1999 16:38 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Microsoft has promised that the flaw giving unauthorised users access to Hotmail Passport accounts after they have been left without the authorised user logging off, will be fixed by the end of the day.

The problem, discovered by security enthusiast Pete Krawczyk, means that Hotmail does not automatically log someone out of a Passport account once they have left the site -- in a cyber café for example -- if the browser's cookie settings are correctly configured.

Passport lets users access e-commerce sites from a Hotmail account and retains credit card numbers that could, potentially be used illegally.

Because Hotmail is particularly popular in cyber cafés , this represents a serious problem for Microsoft, which is still recovering from the embarrassment of the last Hotmail breach.

Stuart Anderson, marketing manager for Microsoft Passport, told ZDNet: "I have been assured that this will be fixed by the end of the day. That's the beauty of having a server-side program." Anderson was keen to spin the breach into a positive outcome, "When you drill down, considering all the things you have to do, it is a much smaller proportion of people who could be effected. I must also stress that it does not effect the Wallet section of Passport."

Take me to Hackers

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Did you find this article useful?
32 out of 75 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:







Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Should a security professional have a...

My own experience and talking to colleagues has prompted me to wonder whether the day has arrived that security professionals will need a legal background. The information security... More

1 comment

Transys comment speculation

I've been pondering why it's so difficult to get any official comment out of any of the organisations involved when it comes to what is happening with Transys. Transys is the consortium... More

Post a comment

Wallet Phones Are Coming:Visa Should J...

Wallet Phones Are Coming:Visa Should Jump On Board Author: Eric Everson, Founder MyMobiSafe.com I have touched on the subject of wallet phones (a mobile handset capable of eliminating... More

Post a comment