On CHOW: Easy Thanksgiving for beginners
BNET Business Network:
BNET
TechRepublic
ZDNet

By Robert Lemos
Posted on ZDNet News: May 8, 2003 6:12:00 PM

Microsoft security and product teams worked overnight to fix a flaw in the password reset feature of the Passport identity service that threatened to compromise millions of accounts.

By 8 a.m. PST Thursday, the company had replaced the service with a more secure version, one that should have been there in the first place, said Adam Sohn, product manager for Microsoft's Passport team.

"It was something that slipped through the reviews," he said. Sohn added that the feature had been around since September 2002 and that Microsoft is currently investigating to what degree the flaw may have been exploited by online vandals to grab user accounts.

The issue, which was first reported by CNET News.com, is perhaps the largest vulnerability known to have slipped through Microsoft's security reviews since the company began its Trustworthy Computing Initiative aimed at, among other things, reducing software vulnerabilities.

Microsoft has touted Passport as a technological centerpiece in its Web services future. Passport accounts are central repositories for a person's online data, including personal information such as birthdays, credit card numbers and shipping addresses. The accounts are pitched as a single key for a customer's accounts, allowing for easier purchasing of items online. Microsoft estimates that there are 200 million active Passport accounts.

The security issue, apparently discovered by a Pakistani security consultant and student, became public knowledge late Wednesday night after the student sent details to the Full-Disclosure security mailing list.

"It is so simple that it is funny," wrote the student, who used the name Muhammad Faisal Rauf Danka. He claimed to have tried to contact Microsoft through several different e-mail accounts, including security@microsoft.com.

Sohn said that account is the general e-mail account for Microsoft's corporate security teams, not its product security. The e-mail eventually was forwarded to the Microsoft Security Response Center, but not before the company had already heard of the issue from CNET News.com.

"You live and learn," Sohn said. "We will obviously take a hard look to make sure that if something is sent through the nonstandard channels, and it is real, we are all over it."

SponsoredWhite Papers, Webcasts, and Downloads

Talkback

Add your opinion
advertisement
Premier Vendor Content Whitepapers, webcasts & resources from our Power Center Sponsors
Reduce risk. Reduce complexity. Increase reliability.
A simplified IT environment isn't just less complex. It's also more reliable. Standardize on a single Linux platform with SUSE Linux Enterprise from Novell, and get the world's most interoperable Linux
Learn more >>
Learn more about tools to grow your business
The Business Essentials Guide provides you useful tools and templates to help grow your business and save you time with automated shipping solutions.
Save time with the UPS Business Essentials Guide
Microsoft Dynamics CRM Online - Free Six-Month Trial for Eligible Organizations
Microsoft Dynamics CRM Online provides fast online access, simple contact management and better sales performance for a low monthly cost - the best value on the market today.
Learn more about the free, six-month trial offer>>
Keep Up With The Latest In Document Management with The DocuMentor.
Doc delivers the scoop on today's enterprise content management, printer maintenance, and all other issues related to document management. It's the DocuMentor Blog.
Learn more >>
Reduce risk. Reduce complexity. Increase reliability.
A simplified IT environment isn't just less complex. It's also more reliable. Standardize on a single Linux platform with SUSE Linux Enterprise from Novell, and get the world's most interoperable Linux
Learn more >>
The best support in the Linux business
If Linux is going to power your mission-critical applications, you'd better have the best support known to business. Novell was rated the top provider of Linux technical support.
Learn more >>

White Papers, Webcasts, and Downloads