Gartner: Drop Microsoft Passport

By
Follow google news

In what can only be called yet another bid for attention, market research group Gartner is advising businesses using Microsoft's Passport authentication service to stop implementing the technology. This is the second such advisory from the company is recent months; Gartner last year advised companies to stop using Internet Information Services (IIS), Microsoft's Web server. As with the IIS incident, the catalyst for this advice is a security vulnerability, and now, as then, Gartner is out of line.

Passport, you may recall, is a service Microsoft offers to allow users to create a single logon for Web sites, instant messaging, e-commerce, and other online activities. The company is moving Passport into a Web services model, and will soon release a federated trust server that will help Windows-based enterprises link internal user authentication to Passport accounts on the Internet. Microsoft claims hundreds of millions of Passport "users," but most of those are really Hotmail accounts, where a Passport account is a requirement.

Last week, Microsoft fixed a major Passport vulnerability that could have allowed hackers to usurp control of users' accounts. And this is reason Gartner is recommending that companies--specifically financial institutions, credit companies, e-commerce sites, and anyone else using Passport for "meaningful business purposes"--immediately drop Passport and wait for the November release of a Passport update, which will feature more secure authentication technologies. The parallels to Gartner's advice about IIS are staggering. Then, Gartner advises companies to immediately drop IIS until a more secure version (IIS 6, part of Windows Server 2003) was released. And then, as now, the company offered absolutely no usable advice about what companies can do in the meantime. In other words, they have identified a problem, but offer no real solution.

"We think that the recommendations Gartner makes are not constructive for customers," a Microsoft spokesperson said. "While we know that we can always do better, we believe we have a solid set of processes and procedures in place to run Passport as a trusted service.

Add iTnews as your trusted source

Got a news tip for our journalists? Share it with us anonymously here.
Tags:

Most Read Articles

CBA onboards customers with NFC scans of ePassports

CBA onboards customers with NFC scans of ePassports

NDIS Commission to have a new intelligent risk engine by August

NDIS Commission to have a new intelligent risk engine by August

Services Australia describes fraud, debt-related machine learning use cases

Services Australia describes fraud, debt-related machine learning use cases

Rest Super simplifies staff access to IT, HR and information

Rest Super simplifies staff access to IT, HR and information

Log In

  |  Forgot your password?