Microsoft increases Passport security

NEWS
Microsoft began notifying Passport users on Monday night of changes that would give them more control over their accounts and increased privacy and security. The changes could eliminate two of the biggest customer gripes against Passport: That users can create accounts using bogus email addresses and that users cannot easily cancel accounts they no longer wish to keep. "Microsoft is just trying to clean up stuff," said independent security analyst Richard Smith. "They're fixing some problems here in what is a natural evolution of Passport." The Redmond, Washington-based software giant will begin making the account changes immediately but expects it to take several weeks before all Passport holders will have access to the new features. Like competing technology being developed by Sun Microsystems-sponsored Liberty Alliance, Passport is a single ID mechanism that can be used to access multiple Web sites, thus eliminating the need for users to remember many different IDs or passwords. Microsoft acquired the technology for Passport when it bought Firefly Network in April 1998. Although Microsoft shuttered Firefly in August 1999, many Firefly developers remained at Microsoft to work on Passport. Microsoft officially launched the authentication service in March 1999, later requiring its use in MSN Messenger and other Microsoft products. Microsoft uses Passport authentication for its MSN Messenger and Hotmail email services, Microsoft Developer Network (MSDN) online access and Microsoft Reader e-book purchases, among other product and service offerings. The authentication service also is a cornerstone for .Net, Microsoft's slowly evolving Web services strategy. Third parties, such as eBay and Starbucks, also use Passport authentication for delivering services. Microsoft has been working on the Passport changes for some time. "This process started a year ago, and we are going to begin rolling out service updates to Passport," said Adam Sohn, Microsoft's product manager for the .Net Platform Strategy. "It's a regular update to the service." Passport renewed
The first change only affects new account holders, who will no longer be able use a bogus email address to establish a Passport. Microsoft requires consumers to use an email address as their Passport ID, but had not mandated that the address be legitimate or belong to the account holder. Consumers signing up for new Passports will now receive an email that requires them to validate receipt of the message to permanently establish the account. "The owner of the inbox that email address belongs to can either verify that account or say, 'Hey wait a minute, someone's trying to hijack my email address,' and stop it," Sohn said. "You have a short grace period in which to verify your account." Initially that would be four days or five logins. But Microsoft could adjust the grace period, depending on user feedback. The second change could bolster Passport security. Microsoft is moving all the information viewed in a Web browser, such as the login page or member services, to servers hosted in a domain separate from the authentication components. That information would come from passport.net rather than passport.com. The two-domain mechanism also will eliminate the long, hard-to-decipher URL the user sees in the browser's Web address bar. "This enables two things," Sohn said. "No. 1, users will very easily see that URL, know that they're at the right site and that someone is not trying to spoof them. Secondly, it is a significant security step, because if someone really got malicious they would not be able to access the authentication token, since that would reside in a separate domain called passport.com." Eliminating the long URLs is an important security enhancement, Smith said. "It's good that all that gobbledygook goes away because it makes it more difficult for the bad guys to redirect you to what appears to be a legitimate Passport site but is not. But there are still some issues here," where someone could create a fake Passport page and "users aren't savvy enough to look at the address bar." Microsoft also is making it easier for people to convert a Kids Passport account into a full-fledged Passport. During the sign-up process users must give their birth date and year, but Microsoft has found too common a situation where the current date is entered in that field by accident. This automatically turns the account into a Kids Passport. The process of contacting customer service to convert the account to a full Passport could at times be burdensome, Sohn admitted. Users will now be able to convert the accounts online by providing, say, a credit card number. "We don't store that information," Sohn said. "We just go out and check that information and then, basically un-kid you." The final change addresses one of the biggest gripes made about Passport, by consumers, privacy groups and even during Microsoft's antitrust case: account cancellation. In theory, an account can be closed through Passport customer service, but some users have complained this isn't easy to do. J. Belkin, of Danville, California, said he signed up for Passport to take advantage of a 20 percent discount offered through MSN. "I found out afterward, there's no way to purge that info so I went and changed everything to nonsensical info." Microsoft will now provide a tool that will let Passport holders cancel their accounts online. "We built in the logic so we have different tasks for different kinds of Passports," Sohn said. "So if you decide you want to close your Hotmail Passport account, we're obviously going to give you a different experience than if you just want to close 'joe@passport.com.' That way you don't accidentally close an account." Microsoft started notifying Passport users of the changes around 9 p.m. (PDT) on Monday. For some Passport users, the changes are nice, but not necessary. "I don't have any real problems with Passport. I think it's a good service," said Donny Kavanagh, a Passport user from Ontario, Canada. "When it comes to having one login for all the Microsoft as well as partner Web sites then you really can't complain. It makes things a lot easier." Passport rejected Microsoft did not make the changes in response to a Federal Trade Commission (FTC) complaint about Passport, Sohn said. "This is all stuff that's been in the works for some time." In early August, Microsoft settled with the FTC over privacy problems and potential security breaches with the Passport service. The FTC responded to a July 2001 complaint filed by 14 consumer and privacy groups, including the Electronic Privacy Information Center and Junkbusters, that Passport and its accompanying Wallet service violated Section 5 of the Federal Trade Commission Act. The FTC's six-page complaint faulted Microsoft for failing to adhere to its own privacy policy, among other violations. The agency found potential problems with Passport security, although no breaches were uncovered. Microsoft agreed to government oversight for 20 years, third-party certification and stricter security measures and changes to its privacy policies and practices. Microsoft already has started that process. Windows Media Player 9 Series, which will be available in a beta, or testing, version on Wednesday, delivers a new, prominently displayed privacy options control and privacy statement. Microsoft next year plans to launch TrustBridge, a single ID service similar to Passport but built for businesses. That ID can be created through Passport; Active Directory, which is Microsoft's directory server software included with Windows 2000 Server; or through any other ID system on any operating system that supports Kerberos, a network security standard. Microsoft also plans to add Kerberos security to Passport sometime next year. Microsoft also faces other challenges wooing customers to use Passport. In April, market researcher Gartner found that the majority of consumers are distrustful of using online identity and authentication account such as Passport. Gartner found that most people sign up for an account because they are forced to, but that doesn't necessarily mean they use the IDs. Microsoft requires a Passport to use Hotmail, MSDN and other services and to use some features found in Windows XP. Gartner found concern about security of personal data, such as credit card numbers, to be one of the biggest reasons consumers resisted online authentication services. Belkin falls into that category. "I would bet there are more days in a year that we hear of some security breach for a Microsoft product than days we do not," he said. "I do trust merchants that seem to offer prompt customer service like Amazon...and in a sense, when I order stuff from their auctions and used stores, it's sort of the same thing as a Microsoft Passport -- but I trust them."
E-commerce is transforming business around the globe. Get the latest headlines at ZDNet UK's E-commerce News Section. Have your say instantly, and see what others have said. Go to the ZDNet news forum. Let the editors know what you think in the Mailroom.

Post your comment

In order to post a comment you need to be registered and logged in.

You can also log in with Facebook. Log in or create your ZDNet UK account below

  • Login

Will not be displayed with your comment

By signing up for this service, you indicate that you agree to our Terms and Conditions and have read and understood our Privacy Policy. Questions about membership? Find the answers in the Community FAQ

Get ZDNet UK's daily newsletter

Enter your email address to sign up

ZDNet UK Live

itsajob

2. Bad idea. Making up patch cables loses you your commission from the cable supplier. 3. If you tidy up, other people can understand where the...

6 hours ago by itsajob on Ten IT jobs to save up for those rare lulls
Roberto_Store

Now On Sale, Unlocked iPhone 4S / Galaxy Note In Factory Box. Roberto-Techie(UK) ”Now on Sales” Smartphone, Android,Tablets,Gadget &...

10 hours ago by Roberto_Store on Samsung Galaxy S III lined up for sale
Paul Smyth

Is this classic FUD? One thing I would definitely have notice is a Mozilla threat to stop supporting GNU/Linux.

12 hours ago by Paul Smyth via Facebook on Firefox rapid release improves Fedora Linux
UnderINK

I agree with the previous commenter wholeheartedly. I couldn't say it better myself. This is very 'Big Brother'. And while I agree with protecting...

16 hours ago by UnderINK on European e-identity plan to be unveiled this month
Simon Bisson and Mary Branscombe

Nice to see that Turing's idea of a general purpose computer doing once-hardware-powered tasks in software is now universal ;-) Mary

21 hours ago by Simon Bisson and Mary Branscombe on Software with everything
Jason Burchell

seriously now. I've only bothered to read a small bit of the comments. do me and the rest of the world a favour. stop saying it does not work or...

1 day ago by Jason Burchell via Facebook on Music industry negotiating over 24-bit downloads
Philip Charles Cohen

Read about it and weep, John Donahoe ... In addition to Visa’s V.me, there is now MasterCard’s PayPass digital wallet soon to arrive; another...

1 day ago by Philip Charles Cohen via Facebook on PayPal takes phone-based payments to the high street
apexwm

Leslie Satenstein : Where have you ever seen Mozilla even mention this? Firefox is the most popular browser in the GNU/Linux OS, so I don't see...

1 day ago by apexwm on Firefox rapid release improves Fedora Linux
songmaster

SHleG: Do you remember building a clockwork scorpion kit (I'm pretty sure I have a photo of it somewhere) — I think it was called something like...

1 day ago by songmaster on Software with everything
Chris Wortman

Good I love Yahoo! Their search engine is getting better than Google as of late. I find more of what I want on the first page, and usually within...

1 day ago by Chris Wortman via Facebook on Linux Mint 13 ramps up for KDE release
PatrickG

openhgs has made the point for Windows 8 multiple monitors without realising it! With Windows 7 you have to switch the mouse and so your focus...

1 day ago by PatrickG on Windows 8 could speed multi-monitor uptake
Leslie Satenstein

Mozilla has threatened to stop supporting Linux. I guess that UBUNTU is going with another browser. I indicated that if Mozilla stops supporting...

1 day ago by Leslie Satenstein via Facebook on Firefox rapid release improves Fedora Linux
Andy Bolstridge

Much as I abhor Microsoft's licensing practices, this is almost certainly down to purchasing IT equipment via 3rd party consultants - you get the...

1 day ago by Andy Bolstridge via Facebook on 6 million wasted licences and £1,200 PCs: welcome to government IT
Jack Schofield

@openhgs Windows users have had multiple desktops since Linus started writing Linux. They just haven't shipped as standard because not enough...

2 days ago by Jack Schofield on Windows 8 could speed multi-monitor uptake
Jack Schofield

@Phil at Cloud4 What, Microsoft gets £1,200 per PC and £1,622 per server? Gosh, I'm amazed....

2 days ago by Jack Schofield on 6 million wasted licences and £1,200 PCs: welcome to government IT
craigsc

You guys have no idea what is going on at Autonomy. Autonomy could have been a much more profitable organization. The sales operations at Autonomy...

2 days ago by craigsc on HP cuts 27,000 staff as Autonomy chief Lynch leaves
Moley

How does this impact on dual or multi booting? Seems to me to more or less prohibit this, from Windows 8 anyway. Will Grub 2 recognise Windows 8,...

2 days ago by Moley on Windows 8 start-up speed forces USB boot workaround
apexwm

I don't understand why there cannot be a slight pause during the boot process so the user can press a key. Many operating systems do this, even if...

2 days ago by apexwm on Windows 8 start-up speed forces USB boot workaround
Gavin Goodman

You can now buy the Xi3 modular computer in the UK at http://www.ocdistribution.com . This can be bought with the Tand3m software, pricing and...

2 days ago by Gavin Goodman on CES 2012: Xi3 microSERV3R
Phil at Cloud4

I agree: Mike Lynch can clearly build a business and manage strategy. I suspect the exit of Mike is more likely the end of a planned handover...

2 days ago by Phil at Cloud4 on HP cuts 27,000 staff as Autonomy chief Lynch leaves