Microsoft Defends Passport To Privacy Group 250
securitas writes: "CNET reports that Microsoft is defending Passport as safe and secure in a presentation to the Center for Democracy and Technology. Other organizations such as the Electronic Privacy Information Center, Junkbusters and even the U.S. government may be lobbied by MS this week to fend off a Federal Trade Commission complaint filed by 15 consumer and privacy groups that charges unfair and deceptive practices."
security and privacy a difficult issue (Score:5, Insightful)
The problem is that they haven't had any success protecting it anyway. To be completely fair, neither has anyone else. The other difficulty is that although I would trust MS rather than JRV to protect my data, the necessity of distribution and interaction opens up a whole new class of security holes that no one has even thought of before.
The unfortunate truth is that right now the only way to protect your privacy online is not to give out any information, and that Passport will do exactly nothing to remedy this situation.
Selective paranoids (Score:4, Insightful)
Re:security and privacy a difficult issue (Score:3, Insightful)
I disagree.
Just because I am truthfull when entering my age on one site doesn't mean I want to be on another site. If both ask for my age, and both use passport, I'd have to use two passport accounts to achive my age-deception! And that defeats the whole purpose.
Age is just a trivial example. What info (and how much info) most people give out varies greatly between sites. How does it benefit me, the end user, to have all my info in one place? I can remember passwords, so that one-password argument is no good.
And, even if I wanted one place for all my info, M$ would be the last company I would want to administer it.
Re:Selective paranoids (Score:5, Insightful)
"fallen" dotcoms are, by definition, no longer in bussiness. Complaining about them won't do any good. Microsoft, on the other hand, is very much in bussiness. Their passport service has a bad track record. There is no indication that microsoft has made any major changes in response to the barrage of criticism it has received. It's growing, and in the future you will undoubtedly see more sites where a passport login is required for certain features. That is why its important to be paranoid about this threat now.
Re:Hmm.. (Score:3, Insightful)
Sure, my current passport account is filled with bogus info and is mostly used for hotmail and sometimes msn communities. But the idea is that the passport login will be required for more legit/official uses such as the MSN HomeAdvisor, financial sites, and maybe even ecommerce. Sites that you'd ordinarily give real info to will soon be using passport. And that sucks.
Only trust those you can physically get to (Score:3, Insightful)
"I'm calling at international rates from Outthebackofstan, I've been on hold for three hours, and why don't you ^%#$%#^ read your email?"
"Oh, I'm sorry, you have the wrong department, this is the Pacific USA only support line. Please dial this number again in another eleven hours and the people supporting your region will be here. Have a nice day" (To co-worker: "Another commie towelhead") click."
Re:One password, multiple accounts, low security (Score:5, Insightful)
Scenerio 1: User always uses the same login/password everywhere they go.
If you obtained that username and password, you'd be able to log into any service *that you know they use*. You would not be able to log into any random service unless that user happened to have been there before.
Scenerio 2: Passport.
If you obtain their Passport login and password, you could log into services *the user has never logged into before*. I'll admit I don't know much about how Passport works, but it seems that you'd be able to use their credit cards and other personal information at any Passport-enabled site...
So even though users may choose non-secure passwords and use the same info at many sites, you still would have to know what services the user has signed up with. Passport eliminates that obstacle.
Re:One password, multiple accounts, low security (Score:3, Insightful)
A service pack? Abject denial?
It's simple... if you're providing an online service, you need to supply the best protection possible to your clients. And there is no indication that M$ has the slightest clue on how to do this.
Kierthos
great idea, but not for /valuable/ passwords; ENUM (Score:3, Insightful)
But no way would I use a single password for important stuff. And there's the problem: MS obviously wants to force you to use it for /everything/. So then you can have your whole identity stolen by the first criminal who watches over your shoulder while you type in your password.
It's also scary to ponder that next they'd probably force you to use it with ENUM [cconvergence.com], a new scheme we're going to have shoved down our throats, which involves linking the DNS database to the database of phone numbers.
Privacy will be protected, or passport won't work (Score:2, Insightful)
The success of the passport system, and quite possibly their
What's even more interesting, to me, is the fact Microsoft is using it's very large distribution channel to advertise and promote services in which it's competing against non-monopolistic companies. Messenger vs. ICQ (and others), Hotmail vs. many free email services, etc. I can't help but wonder if the FTC will look into this, rather than just the special interest groups concern.
great idea(l)s (Score:4, Insightful)
what I can't figure out is why this company, which is supposedly on the brink of launching this massive, multi-tiered platform that is
I mean, come on, the username/password combo was maybe reasonable in the days when everyone had exactly one shell account. but today when everyone is expected to remember a user/pass combo for every one of a dozen or so websites they want to log into, the weakness of this paradigm has hit pretty hard. simply put: people can't remember them all, which means they either write them down lots of places (prett damn insecure) or use the same username/password for each account (even worse).
and MS has made THIS the lynchpin of their security model?
why couldn't MS use some of their much vaunted "monopoly power" to "leverage" an authentication system that actually matched the sophistication of the rest of
my suggestion: the medium which most people are accustomed to carrying that is intimately tied to their financial and personal data is the credit card. my MS "Passport" could be a physical smartcard that held authentication data, encryption keys...hell, anything. each copy of XP (and each bundled OEM copy) would include a small USB device that could read this card, maybe that was designed to mount onto the side of the monitor so it would stay out of the way.
YES this would be a major move, and it would stir things up a little. but when it is clearly called for, WHY NOT? people would just carry another little card in their wallet, the reader device would be small and dirt cheap (in that volume, most anything is) and in a year we would forget what we did without them. we have calling cards, and credit cards,and ATM cards...where is my computer card?
in any case, tying their much-heralded
Single Point of Failer, but needed... (Score:3, Insightful)
1. Use the same password on all 10 anyway
2. Use grossly easy passwords so that they can remember them
3. A combo of 1 and 2.
With a Passport like concept, there's only one account to remember. Maybe then consumers will find it reasonable to memorize a secure password. Either way, a centralized system is needed for identification. As a web developer for 5+ years, customers don't want to fill out the same crap each time they visit a site, and if they could just type in their passport info to authorize access to certain private information, they'd do it. Now, it's up to us to come do the social and technological engineering to make this happen safely, and securely.
Re:security and privacy a difficult issue (Score:2, Insightful)
Multiple passwords are *not* more secure (Score:5, Insightful)
Unfortunately, that's just not true. Usability research has shown certain facts about passwords again and again. In particular, as soon as you start forcing users to remember several passwords, they immediately start using obvious and easy to remember passwords, or writing them down in a readily accessible location. Clearly, this does not improve security.
Having a single sign-in, with a single, genuinely cryptic ID and password, is far more secure than twenty different authentication schemes for different facilities. Of course you rely on the keeper of that information to keep your data in a trustworthy fashion, but you have that problem anyway. At least with a single secure sign-in the average five year old can't guess everyone's ludicrously simple password.
Re:Multiple passwords are *not* more secure (Score:5, Insightful)
Good usability research involves observing the people who are actually going to use your product, using your product. If those people are stupid enough to dump your hot drinks on themselves, you need to design a product that stops them doing it. What you don't need to do is complain that they are stupid.
This is the point. If you're designing a product, whatever it may be, and you want to sell it to a particular market, then your personal opinion on what that market should do is totally irrelevant. Your preconceived ideas about how they should behave are totally irrelevant. You have to watch what they do do and how they do behave, and adjust your product accordingly. If you don't, your product will not be a success, and all the ego in the world won't change that.
Hmm, what are the alternatives? (Score:3, Insightful)
I think a nice solution would be a kind of "PassPouch", based on public-key crypto, etc. A pouch would contain arbitrary number of passwords. To authenticate a user, a service would need your pouch password to open the pouch, and then use its site-password to authenticate a security cookie in the pouch. Well, something like this. You could have multiple pouches, and a pouch could be stored in your personal computer, or in any "PouchServer", based on for example LDAP. There probably already are such systems, but I haven't noticed any so far (I don't know much about the topic).
Re:Single Point of Failer, but needed... (Score:3, Insightful)
Why couldn't you store the required info in an (encrypted) store on your machine and use that to answer the types of requests you are talking about. Same result to the end user without having all this information in some remote store.
You could go further and set the system to autmoatically answer requests in some cases (perhaps in cases where the site has a P3P policy meeting certain conditions, etc.) and you could have every response be part of a digitally signed package that provided a "paper-trail" of exactly what you shared with that site and what purpose they claimed they would use it for.
Much better solution, without MS holding all my data.
Re:Passport - Great idea, iffy implementation. (Score:3, Insightful)
Regarding several comments... (Score:3, Insightful)
Okay. On a small scale, it might make sense. This is not a small scale. This is microsoft. The Internet was not built so one company could control it; it's independent. MS is doing this to corner the e-commerce market. I don't want to let them do that. They are already free to compete fairly with everyone else.
Regarding the comment about Windows XP product activation containing a GUID (which should scare everyeone). I refuse to buy a product that requries me to 'authorize' it's use with the company I bought it from. It's wrong. I paid for it, like a product, at the store. It's mine to use. I should not in any way have to deal anymore with the creator unless I choose to.
Regarding Passport in general... using it for hotmail? MSN messenger? Fine. That's great. But let's not get carried away. I won't give MS my financial information, ever.
Re:I will NEVER trust passport... (Score:2, Insightful)
Doesn't America have one of these? Has anyone actually challenged MS to provide a printed breakdown?
every single Free Passport is an asset to Microsof (Score:2, Insightful)