Passport Flaw Exposes User Info
Microsoft is working to fix hole that could reveal credit card info.
Scarlet Pruitt, IDG News Service
Microsoft has scrambled to shut down a flaw in its Passport service that could potentially reveal users' critical personal information, a company spokesperson confirmed Thursday.
The flaw, which was reported to the company late Wednesday, was located in the service's password recovery system and would allow attackers to change an account password if they knew the user name.
Adam Sohn, a product manager with the Passport team, said Thursday that the flaw has been shut down and that the company is working to quickly fix the matter.
Serious Situation
While Sohn said a preliminary investigation suggested that the vulnerability was not seriously exploited, it could potentially pose a large security threat to Passport users who store critical personal information such as credit card information with the service to access various online sites and services without having to retype information.
The vulnerability was in the function that allowed users to request a forgotten Passport password via e-mail. By tricking the system into initiating an e-mail password reset process, a malicious attacker could then request that the password be sent to a different e-mail address, Sohn said.
Microsoft has turned off this feature while it fixes the problem, and users requesting a forgotten password were instructed to use other means, such as going through the customer service support page.
Sohn said that the problem should be fixed "within hours" and that the company is actively investigating the matter.
Laptop Showcase
The Best of PC World
Dell Fast Track
-
Free Next Day Business Shipping on Dell's Most Popular Systems
Over 35% off Dell’s most popular systems. Delivered in 48 hours with free next business day shipping! Ends 12/22 at 3 PM CST
People who read this also read:
Best Prices on Security Software
Norton Internet Security 2010 - 3 UsersPrice: $26.30
Norton Internet Security 2010 - 3 UserPrice: $26.30
Internet Security 2010Price: $31.91
Norton 360 Version 3.0 - 3 LicensesPrice: $39.99
Total Protection 2010 - 3 UserPrice: $26.97
Norton 360 Version 3Price: $38.74
- Perfect Printing Solutions Find just the right All-in-One Printer for you from HP. Visit the HP Resource Center.
- Acer Laptop Center Forget the Mouse...check out the next generation multi-gesture touch screen technology from Acer.
- Dell Shopping Center Check out great deals from Dell!
Cameras
Camcorders
Cell Phones
Components
Desktops
HDTV
Home Theater
GPS
Laptops
Monitors
MP3 Players
Networking &
Printers
Storage





