Re: izymail security

From: ccomp (compcrafty_at_hotmail.com)
Date: 05/23/03


Date: 23 May 2003 03:24:15 -0700


> I could be wrong, but the only authentication I know of that Hotmail accepts
> is a passport. There are other sites and services that also accept
> passport. Now, the izymail folks could go to one of those other services
> and masquerade as you - and Microsoft would confirm that it is, in fact,
> you.
>
> Giving up a passport seems very risky.
>
> Dave

but izymail would have the passport for hundreds of thousands of email
addresses..... do you think they would sacrifice their business and do
things with your email address and password???



Relevant Pages

  • [NEWS] Microsoft Passport Account Hijacking (Hacking Hotmail and more)
    ... Microsoft Passport Account Hijacking ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... measures and extended authentication methods have to be implemented into ... Many Web Mail Applications, such as Hotmail, ...
    (Securiteam)
  • [NT] Microsoft Passport to Trouble
    ... Microsoft Passport to Trouble ... Passport accounts currently are actually Hotmail accounts). ... It does not allow for sufficient control over the use of authentication ...
    (Securiteam)
  • RE: Passport authentication -- how can I debug it?
    ... local Passport auhtentiation server which can accept the login request and ... the passport authentication is also cookie based and ... So it seems that all the work is done by the remote passport server rather ...
    (microsoft.public.dotnet.framework.aspnet)
  • "not official .NET Passport-participating site." on 1 machine
    ... All logins to hotmail from 1 machine return error: ... "Unknown .NET Passport Site" ... All logins keep looping back to same "Change email or re- ... Seems to redirect when attempting to login. ...
    (microsoft.public.dotnet.security)
  • Re: Tell me about security/privacy issues with .NET/mono
    ... .NET passport is one thing, ... I thought they learned their lesson with Windows XP ... Passport authentication is not _required_ in .NET ... but from a .NET point of view the authentication mode is ...
    (comp.os.linux.security)