The phishing attacks last week on Hotmail were actually compromising Microsoft Live ID accounts. These credentials give a user access to multiple services including Hotmail, Messenger, Xbox Live, Office Online and Skydrive, and Bing.

What this shows is that a single phished email username and password could result in a user’s business data being compromised, their backed up documents or business documents being exposed, and their search results visible. Financial losses could also occur if an Xbox Live account were compromised.

There have been many efforts to push forward with broader federated identity systems such as OpenID and Liberty Alliance. You can start to see the dangers inherent with such systems if passwords can easily be phished.

The more that these systems get federated, the more crucial it is going to be for them to support, or even require, strong two-factor authentication in addition to usernames and passwords. As enterprise services and even government services move into the cloud, this requirement will become even more crucial.

Similar Posts:

  • Share/Bookmark