About InfoWorld : Advertise : Subscribe : Contact Us : Awards : Events : Store
InfoWorld HomeNewsTest CenterOpinionsProduct GuideTechIndex
 COLUMN ARCHIVE  FORUMS
 

COLUMN

 
Window Manager
Brian Livingston

Your Passport, please

I REVEALED ON Sept. 10 that Windows 9x and Me store your user name and password as plain text in memory every time you dial an ISP and store the text for 10 minutes after you've disconnected. Many PCs are silently infected with Trojan horses that can easily read this information. People who use Microsoft's Passport authentication system, as all Hotmail customers are required to do, are likely to choose the same password for Passport and their dial-up account. With this password, a hacker can access any credit card numbers or other accounts that Passport has recorded.

   ADVERTISEMENT
  

Free IT resource

Open Source Business Conference (OSBC) May 22-23, 2007

Sponsored by OSBC

Free IT resource

TechNet: More ways to know it, share it, and keep it running.

Sponsored by Microsoft

RELATED LINKS
»  Canonical chases deals to ship Ubuntu Server preinstalled
»  Sun delivers first UltraSparc T2-based servers
»  IT trainer offers master's degree for hackers
»  Platforms RSS feed 

IDG ENTERPRISE NETWORK
More Operating Systems News...  (ComputerWorld)
CrossOver Office aims to ease a switch to Linux  (ComputerWorld)

TOP NEWS 


IT SOLUTION SEARCH
This scenario was first discovered by Bugtoaster.com, a Windows testing site. Let me assure you that I didn't disclose this security weakness before Microsoft had a chance to patch it. The flaw was discussed with several Microsoft executives back in February, according to Bugtoaster CTO Dave Thomas. The software giant apparently decided not to issue a patch because users can upgrade to Windows NT/2000/XP, all of which correctly encrypt the sensitive information.

In response to that column, reader Dan Ryan wrote, "You shouldn't lump together technical problems with design decisions you don't agree with. If users aren't vigilant about keeping passwords unique, that's hardly Microsoft's fault."

Let me clarify: Using a single password to access your personal and financial accounts is central to Passport, which XP almost requires you to use. This is a design decision I don't agree with. The bundling of Passport with XP is certain to cause more e-commerce sites and Windows 9x and Me users to adopt the authentication scheme. Deciding not to issue a patch for all the Windows 9x and Me users is a technical decision I don't agree with.

Brian Seitz, a spokesman at Microsoft's PR firm, Waggoner Edstrom, wrote, "It's certainly true that a Trojan horse program could compromise the user's security. However, this has nothing to do with Passport -- in fact, it's simply a restatement of the First Immutable Law of Security: If a bad guy can persuade you to run his program on your computer, it's not your computer anymore."

Seitz listed several steps Microsoft has taken to make it harder for a worm to run mobile code on a PC: the Outlook E-mail Security Update, part of the Outlook 2000 Service Pack 2 and Office XP; the inclusion in Windows XP of Internet Connection Firewall and Software Restriction Policies (which can be configured to prohibit mobile code); and Outlook Express 6.0, which includes security changes similar to Outlook 2000 SP2.

Yes, XP and the latest versions of Outlook and Outlook Express do close some security holes. But Microsoft required all Hotmail users to switch to Passport, not just the ones who have the safer, upgraded programs -- and that exposes the passwords of Windows 9x and Me users to risk.


Brian Livingston's latest book is Windows Me Secrets. Send tips to tips@brianlivingston.com. Go to www.iwsubscribe.com/newsletters to get Window Manager and E-Business Secrets free each week via e-mail.




RELATED SUBJECTS

Operating Systems

MORE >


SPONSORED WHITE PAPERS
EMC - Lower costs and improve reliability-Get the EMC CLARiiON white paper!
Ciphertrust - Are you ready for Sobig.G? Learn how to protect your email systems.
CDW - Personal attention. CDW. The Right Technology. Right Away.
EMC - Explore key performance features and capabilities of EMC ControlCenter 5.1.1.
Intel - Free Intel white paper shows you how to deploy a secure wireless LAN
Cisco - FREE WHITE PAPER: BLUEPRINT to design and implement secure VPNs
Verity, Inc. - "Mass Consolidation Hits the Web-Search Market"
McDATA - Download a FREE storage consolidation white paper from McDATA(R).
Lucent Technologies - Overcoming Common Firewall Limitations
Lucent Technologies - Leverage Your Mobile High Speed Data Access. Download Free White Paper!
Nokia - Get the scoop! Mobilizing business white papers & case studies.
BMC Software - Maximize the Potential of Enterprise Data: Free white paper!
Network Associates - Free white paper - Strategies for Optimizing Network Costs and Benefits
Entrust - Manage identities across applications. Improve productivity.
Stalker Software - CommuniGate Pro - Transform your Email and Calendaring
Remedy - A NEW Gartner Research Note:Producing Quality IT Services

Search the IDG White Paper Library:


SPONSORED LINKS

INFOWORLD MARKETPLACE


» Apply BPM and ITIL at your IT Help Desk
ServiceWise brings BPM to complete IT service while eliminating integration cost. Learn more here.
» Find Consulting Jobs
Access Pre-Qualified Projects from Top Businesses. Register Now!
» Virtualization Planning & Analysis White paper
How to analyze workload, business and technical constraints & plan for successful deployments
» SOA Whitepaper Series: Automating Process Exceptions
Register here for this valuable Webinar centering on the automation of process exceptions.




 HOME  NEWS  TEST CENTER  OPINIONS  PRODUCT GUIDE  TECHINDEX   About : Advertise : Subscribe : Contact Us : Awards : Events 

Copyright © 2008, Reprints, Permissions, Licensing, IDG Network, Privacy Policy

All Rights reserved. InfoWorld is a leading publisher of technology information and product reviews on topics including viruses, phishing, worms, firewalls, security, servers, storage, networking, wireless, databases, and web services.

Computerworld :: Network World :: CIO :: PC World :: Darwin :: CMO :: CSO
IT Careers :: JavaWorld :: Macworld :: Mac Central :: Playlist :: GamePro :: GameStar :: Gamerhelp
ITWorld Canada :: Computerwoche :: Techworld UK :: tecChannel :: IDG.se :: IDG.no