ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Online business Toolkit

Microsoft: We're patching MSN hole

Published: 11 Feb 2002 13:31 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Microsoft is putting the final touches on a patch to limit an MSN Messenger feature that allowed any Web site to grab a visitor's IM nickname and buddy list.

While representatives for the Microsoft Network have said no customers have fallen prey to the potential privacy problem, the group plans to release early next week an updated version of MSN Messenger that fixes the problem.

"In order to implement the fix, customers will have to upgrade to the next version of MSN messenger," a representative for the software behemoth said on Friday.

The issue occurs because Microsoft designed MSN Messenger to allow JavaScript contained in Web pages to access a customer's buddy list and, for certain Microsoft sites, the e-mail addresses of the person.

Software engineer Richard Burton highlighted the privacy implications of the feature in a post to SecurityFocus' BugTraq mailing list recently.

"It appears to have been intended as a feature so they could put in nice customizations on their Web sites," said the UK-based programmer on Friday. "I only raised it as a potential, so I don't think people need to panic."

The ill-conceived feature comes at a poor time for the software giant. Last month, Chairman Bill Gates wrote a companywide memo spurring employees to make security and privacy their top priorities.

"So now, when we face a choice between adding features and resolving security issues, we need to choose security," Gates wrote. Calling the initiative "Trustworthy Computing," the founder of Microsoft kicked off extensive code reviews to catch potential problems in the company's flagship software.

Coming two weeks after the memo, the current slipup spotlights the sheer amount of work that Microsoft needs to accomplish to make its software trustworthy.

A little more than a week ago, gamers had problems connecting to the Microsoft Network owing to a glitch with the company's Passport log-in service. In August, Microsoft patched a hole in Hotmail that could allow a person's e-mail to be read by others.

But the current problem is considered more of a privacy hiccup than a major problem, the Microsoft representative said.

After Microsoft releases the fixed version, MSN Messenger users will receive notification when they start up the application that the new software is ready for download.

"The level of risk is considered low," the Microsoft representative said.

Burton agreed. "I wouldn't say it is as serious as people have taken it," he said. "I don't think it is being actively exploited."


For all security-related news, including updates on the latest viruses, hacking exploits and patches, check out ZDNet UK's Viruses and Hacking News Section.

Have your say instantly, and see what others have said. Go to the Security forum.

Let the editors know what you think in the Mailroom.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
47 out of 103 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:








Related Jobs

1st/2nd Line Technical Support/Helpdesk Agent/Analyst/Engineer HR.net, SQL, IIS, RDBMS, .NET Salary up to 21,000 - Worle, Weston-Super-Mare Nr Bristol

HR.net you will be working with SQL, JavaScript and VBScript and require a high level of adaptability as well as a keen eye for detail as well as the ...

JAVA SOFTWARE DEVELOPER - Oracle, UNIX/Linux, Java -Cambridge, Southeast

Additionally, candidates must be able to work under their own initiative as well as being part of a wider team. The Person The ideal candidate must ...

Borland C++ Developer, Based in Tewkesbury, Salary up to 38,000

The type of person that will fit well in to the business will be someone who can work under their own initiative who is a self starter and likes ...

Sentry Posts Blog

Mobile Security Expert: Your Camera Ph...

Mobile Security Expert: Your Camera Phone Got Hacked Author: Eric Everson, Founder MyMobiSafe.com Have you ever heard someone say “I’d like to be a fly on the wall in that room.”?... More

Post a comment

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment

Featured Talkback

I wonder, who needs .asia domain? I cannot imagine, what would be useful for Microsoft.asia? Toyota.asia? Then let's register .europe (if .eu is too short). Or perhaps Microsoft.southamerica, Dell.australiaandnewzealand, Coca-Cola.africa... Sound funny? Then why not just use the global and country domains? Or perhaps it is time to drop the domains at all?

By: LadyRoot

Read full story:
Businesses advised to register .asia domains