Saturday, May 17, 2003

Gartner: You can't trust MS Passport

Gartner analysts claim that the recently uncovered Security Flaw Shows Microsoft Passport Identities Can't Be Trusted. The flaw allowed hackers to hijack a Passport account without the knowledge of the account owner. Gartner analysts Avivah Litan & John Pescatore claim that this means no Passport account can be trusted unless it was created and/or verified after the bug was fixed. All previous accounts must be wiped out.

Their reasoning is valid, and this is the most serious challenge MS has faced in the identity management field. The Redmondites may need to entirely re-do their authorization and authentication framework as the only way to be able to ensure both consumers and businesses that the identities claimed are accurate.

Comments: Post a Comment

© 2003-2006 The Virtual Quill, All Rights Reserved

Home

[Powered by Blogger]

-->