About InfoWorld : Advertise : Subscribe : Contact Us : Awards : Events : Store
InfoWorld HomeNewsTest CenterOpinionsProduct GuideTechIndex
 COLUMN ARCHIVE  FORUMS
 

COLUMN

 
Window Manager
Brian Livingston

Microsoft times out

MICROSOFT WAS forced to temporarily suspend an important financial service of its Passport Wallet program for several days after a programmer showed that he could obtain users' credit card numbers and other personal information merely by sending them a single e-mail message.

   ADVERTISEMENT
  

Free IT resource

Hear how top CIOs turn change into a competitive advantage.

Sponsored by HP

Free IT resource

Try Sun servers, workstations and storage products free for 60-days.

Sponsored by Sun Microsystems

RELATED LINKS
»  Google delivers ad-supported video clips via AdSense
»  3Com waiting for details of Bain/Huawei acquisition bid
»  Indian outsourcers' U.S. shopping spree
»  Business RSS feed 

IDG ENTERPRISE NETWORK
The Broader the E-Biz, the Bigger the Lawsuit  (CIO)
Time To Change  (CIO)

TOP NEWS 


IT SOLUTION SEARCH
Marc Slemko, a Seattle developer, demonstrated that he could retrieve all of a user's cookies and use them to access that person's Passport information any time the user viewed one of Slemko's messages within 15 minutes of signing on to Hotmail (which now requires Passport).

After notifying Microsoft, and being assured that the company was temporarily taking its Express Purchase system offline on Nov. 1, Slemko published a white paper on this and other severe security problems with Passport. That paper is available at http://alive.znep.com/~marcs/passport.

I'm glad to see that a little guy can still wield some influence over the behavior of a software giant. The weakness in Passport that Slemko forced Microsoft to address was similar to, but different from, the major problem that I warned readers about a couple of months ago (see "Passport is cracked.")

That problem, which still exists, is that Windows 95, 98, and Windows Me leave a user's ID and password visible in memory, where any rogue e-mail or Trojan horse can retrieve it during a user's dial-up connection to an ISP and for 10 minutes afterward. In Slemko's case, the 15-minute vulnerability was due to a cache on Microsoft's Passport Web server.

Microsoft reduced the Passport server timeout and placed Express Purchase back online on Nov. 3. The company said in a statement that the vulnerability would not have affected users running the new Windows XP operating system.

But Microsoft didn't wait until customers had XP before requiring millions of Hotmail subscribers to use Passport to log on. There are hundreds of millions of vulnerable PCs out there and Microsoft now requires that Passport be the only way to access an increasing number of services.

In an e-mail interview, Slemko stressed that the specific hole he demonstrated isn't the point. "The issues I raised apply to the use of Passport in general, and become more and more important with every new site that uses Passport," he said.

"Passport is lacking in features that are necessary to protect the security and privacy of users with the sites deployed using it today, let alone the even higher level required if Passport is to be deployed in the pervasive way that Microsoft envisions," Slemko added. "Some of the flaws I came across are such trivial implementation flaws that you have to question Microsoft's commitment."

In other words, reducing a server timeout in no way solves the larger problem. There's more going on. I'd be interested to hear your findings, too.


Brian Livingston's latest book is Windows Me Secrets. Send tips to tips@brianlivingston.com. Go to www.iwsubscribe.com/newsletters to get Window Manager and E-Business Secrets free each week via e-mail.




RELATED SUBJECTS

Business News

MORE >


SPONSORED WHITE PAPERS
EMC - Lower costs and improve reliability-Get the EMC CLARiiON white paper!
Ciphertrust - Are you ready for Sobig.G? Learn how to protect your email systems.
CDW - Personal attention. CDW. The Right Technology. Right Away.
EMC - Explore key performance features and capabilities of EMC ControlCenter 5.1.1.
Intel - Free Intel white paper shows you how to deploy a secure wireless LAN
Cisco - FREE WHITE PAPER: BLUEPRINT to design and implement secure VPNs
Verity, Inc. - "Mass Consolidation Hits the Web-Search Market"
McDATA - Download a FREE storage consolidation white paper from McDATA(R).
Lucent Technologies - Overcoming Common Firewall Limitations
Lucent Technologies - Leverage Your Mobile High Speed Data Access. Download Free White Paper!
Nokia - Get the scoop! Mobilizing business white papers & case studies.
BMC Software - Maximize the Potential of Enterprise Data: Free white paper!
Network Associates - Free white paper - Strategies for Optimizing Network Costs and Benefits
Entrust - Manage identities across applications. Improve productivity.
Stalker Software - CommuniGate Pro - Transform your Email and Calendaring
Remedy - A NEW Gartner Research Note:Producing Quality IT Services

Search the IDG White Paper Library:


SPONSORED LINKS

INFOWORLD MARKETPLACE


» Protect Brands, Revenue & Customer Trust Online
Download this informative whitepaper to learn how you can safeguard your brands-your business-online
» SOA Whitepaper Series: Automating Process Exceptions
Register here for this valuable Webinar centering on the automation of process exceptions.
» FREE Sophos Threat Detection Test
Is your AV catching everything it should? Free virus, spyware and adware scan.
» EMC delivers high-speed image capture, storage
Learn how you can quickly capture, organize, and deliver information with EMC ApplicationXtender.
» Free Guide: Understand Business IP Telephony
Get your free 80 page IP Telephony Guide. Invaluable for evaluating VoIP systems.




 HOME  NEWS  TEST CENTER  OPINIONS  PRODUCT GUIDE  TECHINDEX   About : Advertise : Subscribe : Contact Us : Awards : Events 

Copyright © 2008, Reprints, Permissions, Licensing, IDG Network, Privacy Policy

All Rights reserved. InfoWorld is a leading publisher of technology information and product reviews on topics including viruses, phishing, worms, firewalls, security, servers, storage, networking, wireless, databases, and web services.

Computerworld :: Network World :: CIO :: PC World :: Darwin :: CMO :: CSO
IT Careers :: JavaWorld :: Macworld :: Mac Central :: Playlist :: GamePro :: GameStar :: Gamerhelp
ITWorld Canada :: Computerwoche :: Techworld UK :: tecChannel :: IDG.se :: IDG.no