New Passport privacy tied to IE 6

Daily Newsletters

Sign up to ZDNet UK's daily newsletter.

NEWS
Microsoft will soon be offering better privacy and security for online consumers, but at a price: exclusive use -- for now -- of the company's forthcoming Internet Explorer 6.0 Web browser. Microsoft executives said on Wednesday that the company's Passport authentication service will soon support an emerging privacy standard called Platform for Privacy Preferences, or P3P. The standard is advocated by the World Wide Web Consortium, a Web standards body, and was adopted by Microsoft in June for use in its software. P3P allows Web users to define what types of information they are willing to give, as well as whether they mind sharing that information with outside parties. Internet surfers will receive a warning before visiting sites that go beyond the stated level. P3P is "a good thing, because it establishes a set of standards and guidelines vendors have to comply with" regarding privacy, said David Smith, an analyst with Gartner. "More privacy is always a good thing, and Microsoft is offering more privacy." But the P3P features can work only if consumers have installed IE 6, said Brian Arbogast, a vice president of Microsoft's Personal Services Division. In negotiating contracts with new partners, Microsoft is requiring companies that plan to use the Passport service to support P3P, he added. Microsoft has built P3P into its own Web sites and will support it in IE 6, said Adam Sohn, product manager for Microsoft's .Net strategy. "The W3C is evangelising this, and we're evangelising it," he added. "It's good for consumers to manage their privacy." Passport is a key component of Microsoft's upcoming .Net and HailStorm Web services initiatives and is required for using some of Windows XP's newest features, such as Windows Messenger, a communications console featuring instant messaging, videoconferencing and application sharing. IE 6 is integrated into Microsoft's forthcoming Windows XP operating system, and it will soon be available as a download from Microsoft's Web site for users of older versions of Windows and other supported operating systems. Because Passport authentication is done using a Web browser, people using competing products, such as AOL's Netscape 6.1 or Opera, would not be able to use the enhancements unless those browsers are also made P3P-compliant. The same restriction would apply to older versions of Internet Explorer. Microsoft and rival AOL Time Warner are battling for control of technology such as Passport that makes it easier to navigate the Web and make purchases online. AOL's recent $100m (£70m) investment in online retailer Amazon.com was seen as a deal aimed at boosting AOL's own "e-wallet" technology and as a direct means of competing against Passport, according to sources. Restricting the use of the new security and privacy features to IE 6 users "would be a mistake", said Guernsey Research analyst Chris LeTocq. "It doesn't make sense for Microsoft to shut out the largest part of its installed base from Passport services." Increasing Passport's reliance on Microsoft's latest Web browser, which is in turn tied to its latest operating system, could also increase the legal groundswell building around the authentication service -- and Microsoft's overall product strategy -- despite what Microsoft claims is a sound technological justification for the move. In June, a federal appeals court found Microsoft guilty of anti-competitive behaviour by its commingling of IE and Windows code. The IE 6 requirement with Passport is "likely to give people the message that Microsoft hasn't changed its behaviour one iota on account of being found guilty by the Court of Appeals -- same old full speed ahead," said Bob Lande, a professor at the University of Baltimore School of Law. Microsoft's interest in P3P predates the antitrust case originally brought by the Justice Department and 20 states -- it was one of the company's interests in its April 1998 acquisition of Firefly Network. Although Microsoft shuttered Firefly in August 1999, many developers remained onboard to work on Passport. The Redmond, Washington-based software giant officially launched the authentication service in March 1999, later requiring its use in MSN Messenger, Microsoft Reader e-books and access to paid Microsoft Developer Network online services, among other places. More than 200 companies have signed on to the Passport service, including Starbucks, RadioShack, Blue Nile, 1-800-Flowers.com, Office Depot, Office Max, Victoria's Secret and Hilton.com, as well as all of Microsoft's MSN properties and its travel site, Expedia, Microsoft said. Passport facilitates some 2 billion authentications a month, Microsoft claims. Microsoft's competitors and trustbusters started attacking Passport even before the US Court of Appeals for the District of Columbia Circuit upheld eight separate antitrust violations against the company. Passport is one of several technologies -- including media-player software and instant messaging -- under fire because they are integrated into Windows XP. In an interview last month, Iowa Attorney General Tom Miller said the "integration restricts what OEMs (original equipment makers) can do" in customising Windows XP for their customers. In another attack, a group of 10 privacy organisations in July asked that the Federal Trade Commission delay Windows XP's scheduled 25 October launch. The groups argued that Passport and other technologies that are part of Microsoft's .Net software-as-a-service strategy violate individuals' privacy. Passport has also come under fire from privacy experts. Part of the technology's allure is its single sign-on method. Passport uses one email address and password to authenticate users and give them access to a variety of Web-based services -- some delivered by Microsoft and others from third parties, such as American Express Blue Card. The potential for failure But that single point of access also has the potential to be a single point of failure. Privacy experts warn that someone obtaining a Passport user's email address and password could access all of that user's services. In an indictment of Passport's security, AT&T Labs researchers David Kormann and Aviel Rubin faulted Microsoft's decision to convert Hotmail user IDs and passwords into Passport credentials. "Any compromised account, and for that matter any future compromise of Hotmail, could result in abuse of their account at these other merchants," they wrote in their report. Kormann and Rubin also faulted other aspects of Passport's single sign-on approach, including its use of encryption keys and the ability of bogus merchants to set up phony Web stores. Microsoft hopes to quell some of these criticisms by offering additional security features for its partner Web sites, such as banks, whose security needs are more stringent, Arbogast said. The new security features "offer a second level of authentication", he explained. "It can prompt you for a four-digit PIN (personal information number) or ask you a set of three different questions you have to answer." Arbogast reiterated Microsoft's contention that the company is concerned about security and privacy. Microsoft's Passport is not collecting user information, and the company's Passport partners are not sharing Passport user information with Microsoft, he said. Microsoft is relying heavily on Passport for its forthcoming new Web services strategy called HailStorm, which has been billed as a way for subscribers to access their email, personal contact list, schedule and other Web services -- such as shopping, banking and entertainment -- through a variety of devices, such as PCs, cell phones and handhelds, from any location. In addition to the P3P support slated for later this year, Arbogast said Microsoft later this month will add support for Passport use on cell phones and personal digital assistants that offer Internet service through WAP (wireless application protocol), a technology used to help cell phone users view Web pages. When HailStorm services are available, people with new mobile phones will be able to upload their contact list into their new phones without having to program each name and number, said Chris Payne, also a vice president of Microsoft's Personal Services Division. Microsoft will provide tools that will allow its Passport partners to sign on people to the Passport service, Sohn said. For example, when a service provider signs on a new cell phone user, it can now give the customer a Passport account as well, Sohn said. Later this year, Passport users will also be allowed to change their member name, according to Microsoft's Arbogast. In the past, people who wanted to change their member name had to re-register, and all their previous information was lost. Now they can switch member names but still have their information stored, Arbogast said. In the future, Microsoft will add Passport to smart-card technology as well as to biometrics, an emerging technology by which people are identified based on their physical characteristics or movements. It will also support digital certificates, Microsoft executives said. See the DoJ/Microsoft News Section for the latest headlines. See the Software News Section for full coverage. Have your say instantly, and see what others have said. Click on the TalkBack button and go to the Microsoft forum. Let the editors know what you think in the Mailroom. And read other letters.

Post your comment

In order to post a comment you need to be registered and logged in.

You can also log in with Facebook. Log in or create your ZDNet UK account below

  • Login

Will not be displayed with your comment

By signing up for this service, you indicate that you agree to our Terms and Conditions and have read and understood our Privacy Policy. Questions about membership? Find the answers in the Community FAQ

Get ZDNet UK's daily newsletter

Enter your email address to sign up

ZDNet UK Live

GrueMaster

Nice review and very informative. One thing I'd like to add (in reply to whs001's 1st question), the main reason to have the same interface from...

27 minutes ago by GrueMaster on A tale of two distros: Ubuntu and Linux Mint
Frederick Wrigley

I'be been using Mint 12 since the RC came out, and I am far more happy with the Cinnamon, the Mate, and, yes (with extensions), theGnome 3...

1 hour ago by Frederick Wrigley via Facebook on A tale of two distros: Ubuntu and Linux Mint
bdantas

Excellent article. One small correction, though--although a fresh installation of Linux Mint 12 will, indeed, provide the user with a version of...

2 hours ago by bdantas on A tale of two distros: Ubuntu and Linux Mint
Alan Ralph

In related news, the ISPs club together to get the members of the Home Affairs Select Committee (ya goofed on that part, ZDNet UK) copies of "The...

2 hours ago by Alan Ralph via Facebook on MPs urge ISPs to take down terrorist material
Alan Ralph

In related news, the ISPs club together to get the members of the Home Affairs Select Committee (ya goofed on that part, ZDNet UK) copies of "The...

3 hours ago by Alan Ralph via Facebook on MPs urge ISPs to take down terrorist material
Moley

For Gnome 2 die-hards, it is possible to add icons to the bottom panel (or top top panel, if you prefer) which provide the exact Gnome 2...

3 hours ago by Moley on A tale of two distros: Ubuntu and Linux Mint
ramwellian

Your comments would seem pretty naive and immature. Your 'solution' appears to be, "gee, let's all just give in to the hackers and give them...

3 hours ago by ramwellian on Cloud computing security: no more oxymoron?
BugStalker

"Interesting thought ... If you installed Win7 as a dual boot on a machine that previously only had Linux, and it wrecked your Linux installation,...

4 hours ago by BugStalker on Windows 7 Declares War on GRUB
whs001

This is an excellent summary of Ubuntu and Mint and the interface differences between them. Most such articles take a very partisan position for...

4 hours ago by whs001 on A tale of two distros: Ubuntu and Linux Mint
Moley

@ewallace. Not so clear. Anyone can obtain the text, for example from here http://www.ustr.gov/webfm_send/2379. I support ACTA so long as it and...

4 hours ago by Moley on ACTA: Facts, misconceptions and questions
45283

I think WinRT is fantastic. I just wish it was an option for people that didn't want to go through Microsoft's App Store with its attendant...

7 hours ago by 45283 on Why Windows 8 needs architectural hygiene for WOA
Burn-IT

Nine people? £30m? Who's back pocket is that lot going in? And IF they say it is for new buildings, what about all the ones the government has...

8 hours ago by Burn-IT on Police set to launch three £30m e-crime hubs
ewallace

Just to be clear, nobody knows what is in the text of ACTA, here is a photograph of the text of ACTA http://twitpic.com/8h9iju as submitted to the...

8 hours ago by ewallace on ACTA: Facts, misconceptions and questions
fgvrg56

Unfortunately main issue is that ASUS is refusing to accept that they make some mistake on this version of asus Transformer prime. 1 - GPS sensor...

10 hours ago by fgvrg56 on Asus Eee Pad Transformer Prime Wi-Fi & GPS problems?
Ben Woods

@Marcus A fair question. Just talked with Archos which said it was working on an announcement for next week....

11 hours ago by Ben Woods on Archos confirms G9 Ice Cream Sandwich update schedule
Marcus Karlsson

Any update on this, considering the claimed "first week of February"?

12 hours ago by Marcus Karlsson via Facebook on Archos confirms G9 Ice Cream Sandwich update schedule
apexwm

Bill Goodrich : Just as al_langevin pointed out, with Windows Server 2008 there is no Services for Macintosh anymore. It's gone, not available....

20 hours ago by apexwm on Windows Server 2008 drops the ball for Mac compatibility
txtrainguy

Replying to an old topic that I'm currently facing with my CEO (who is on a Mac). Our servers are primarily Windows Servers, office is about...

1 day ago by txtrainguy on Windows Server 2008 drops the ball for Mac compatibility
k0tcs3

Sure, that makes perfect sense. Pay wrong-doers money and thank them for breaching your security and pointing out your flaws, that would surely...

1 day ago by k0tcs3 on US indicts Romanian over NASA climate change hack
Random_Error

I think he's referring specifically to Android apps, as Apple do regulate their App Store, but Google seem to let any old crap onto the Android store!

1 day ago by Random_Error on RIM: BlackBerry will keep 'garbage' apps out of store