Gartner: Drop Microsoft Passport

By
Follow google news

In what can only be called yet another bid for attention, market research group Gartner is advising businesses using Microsoft's Passport authentication service to stop implementing the technology. This is the second such advisory from the company is recent months; Gartner last year advised companies to stop using Internet Information Services (IIS), Microsoft's Web server. As with the IIS incident, the catalyst for this advice is a security vulnerability, and now, as then, Gartner is out of line.

Passport, you may recall, is a service Microsoft offers to allow users to create a single logon for Web sites, instant messaging, e-commerce, and other online activities. The company is moving Passport into a Web services model, and will soon release a federated trust server that will help Windows-based enterprises link internal user authentication to Passport accounts on the Internet. Microsoft claims hundreds of millions of Passport "users," but most of those are really Hotmail accounts, where a Passport account is a requirement.

Last week, Microsoft fixed a major Passport vulnerability that could have allowed hackers to usurp control of users' accounts. And this is reason Gartner is recommending that companies--specifically financial institutions, credit companies, e-commerce sites, and anyone else using Passport for "meaningful business purposes"--immediately drop Passport and wait for the November release of a Passport update, which will feature more secure authentication technologies. The parallels to Gartner's advice about IIS are staggering. Then, Gartner advises companies to immediately drop IIS until a more secure version (IIS 6, part of Windows Server 2003) was released. And then, as now, the company offered absolutely no usable advice about what companies can do in the meantime. In other words, they have identified a problem, but offer no real solution.

"We think that the recommendations Gartner makes are not constructive for customers," a Microsoft spokesperson said. "While we know that we can always do better, we believe we have a solid set of processes and procedures in place to run Passport as a trusted service.

Add iTnews as your trusted source

Got a news tip for our journalists? Share it with us anonymously here.
Tags:

Most Read Articles

Westpac brings automation and AIOps to life, chasing CPU and memory alerts

Westpac brings automation and AIOps to life, chasing CPU and memory alerts

Suncorp to have AI agents in insurance claims process as soon as this month

Suncorp to have AI agents in insurance claims process as soon as this month

Services Australia describes fraud, debt-related machine learning use cases

Services Australia describes fraud, debt-related machine learning use cases

Qld gov backs technology projects with at least $340m

Qld gov backs technology projects with at least $340m

Log In

  |  Forgot your password?