R E L A T E D   C O N T E N T

Free email newsletters




ADVERTISEMENT

Microsoft to use Kerberos for Passport

Analysts question software giant's motives

Network News staff, Network IT Week 02 Oct 2001
ADVERTISEMENT

Microsoft is to base the next version of its Passport service on open source Kerberos encryption, despite its controversial history with the protocol.

In using Kerberos, Microsoft aims to beef up Passport's security, which could pave the way for rivals to produce compatible competing products, rather than proprietary rivals, which would defeat the premise of Passport.

Passport is a critical part of Microsoft's Hailstorm web services strategy and is a central store of customer information. The service means that consumers can avoid having to re-enter personal details when visiting new websites.

Rivals such as AOL are thought to be working on competitors to Passport.

But the service has come under fire from privacy advocates who say its security is easy to bypass. They also question the wisdom of having such a large base of customer information under Microsoft's protection.

As a result, the software giant has changed Passport to require less information from users wishing to open an account, and last week turned to Kerberos, a portocol developed at the Massachusetts Institute of Technology.

Microsoft's track record with Kerberos is dubious, however, leading some industry commentators to doubt whether it is looking to make Passport truly compatible with rival products.

See also:

Single-sign-on scheme launches in San Francisco  15 Jul 2002
Using the controversial security protocol Kerberos exposes network systems to attacks by hackers, a security analyst has warned.  29 Jun 2000
Kerberos, the controversial security protocol, is exposing network systems to attacks by hackers, a security analyst has warned.  28 Jun 2000
Microsoft's Windows 2000 implementation of open security standard Kerberos came under fire from software developers last week, after it emerged the software giant has undermined the standard with undocumented modifications.  15 Mar 2000

All Network Infrastructure

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
Sandiacre, Nottinghamshire, United Kingdom | NHS Midlands
Workstream Lead Requirement, Design, Build and Test (Business Analyst) Strategic IM&T - Delivery   Band 7:      £29,091 - £38,352 per annum Hours:       37.5 per week Base:         Octavia House, Sandiacre Job Ref:     973 - 080810   ... more >
Hook, Hampshire, United Kingdom | EDS
Description: This vacancy is for an information security consultant to join EDS' Information Assurance team based in Hook. The successful applicant will provide information security support to one or more of EDS' major Defence projects. ... more >
Aylesbury, Buckinghamshire, United Kingdom | Grass Roots
SQL Database Administrator - Aylesbury - £DOE Grass Roots are one of the Sunday Times Top 100 companies to work for (2007 and 2008). Established in 1980, we're part of the Grass Roots Group, which is ... more >
London, United Kingdom | MRC Centre of Epidemiology for Child Health
Senior Information Systems Consultant - £34,793 - £41,545 pa - London Applications are invited for the exciting new post of Senior Information Systems Consultant at the MRC Centre of Epidemiology for Child Health, located within the Centre ... more >
More job opportunities