Latest Comments
"when i login to face book it tells me i am cookies enabled what does this mean"
by celeste | Nov 21, 2008 5:15 PM
 
"Hi this is the mail I received Brett Karpman show details Nov 17 (3 days ago) Reply Atten..."
by Rodney Churchyard | Nov 20, 2008 6:13 PM
 
"security through obscurity...shows how detached HIPAA is from reality."
by priceOfFishInChina | Nov 20, 2008 1:19 PM
 
"Umm. no. The 6.5 product is mounting the offline VM image and performing a scan for patch ..."
by eric | Nov 20, 2008 8:15 AM
 
"it's great i tried it"
by divyacharan | Nov 20, 2008 12:24 AM

Microsoft's CardSpace ID technology: breached

  • Email a Friend
  • Print Page
By Jim Carr
Jun 2, 2008 11:56 AM
Tags: Microsoft's | CardSpace | ID | technology: | breached
The technique essentially co-opts part of the CardSpace technology, which Microsoft believes can reduce problems such as identity theft plaguing internet users. Microsoft has said it plans to integrate CardSpace with OpenID, an open-source standard also designed to toughen up internet security.

CardSpace, which ships with Microsoft's Windows Vista operating system, operates in tandem with a browser when a user visits a website requesting information such as names, addresses or credit card numbers. In the CardSpace scenario, users can store their personal information on their own PC or use a third-party identity provider's service.

CardSpace maintains a list of virtual ID cards, which can be "self-issued" cards stored on the user's PC or "managed" cards stored by the ID provider. When a website asks for personal information, the user selects one of the cards.

When users rely on an ID provider for authenticating with a website, the provider issues a token to the website rather than passing the user's individual information along. This is where the security researchers, from the Horst Gortz Institute for IT Security at Ruhr University in Bochum, Germany, have uncovered a flaw in the process.

The security researchers, students Sebastian Gajek and Xuan Chen and Jorg Schwenk, a professor and chairman of network and data security at the institute, have shown it is possible to intercept the authentication token from CardSpace. The technique requires directing users to a malicious web server.

According to the researchers, an attacker would have to modify the victim's domain name server (DNS) settings -- a hacker technique called pharming -- and direct the visitor to the malicious web server, which then captures the authentication token. A hacker could then use the token to access or send sensitive information to the original website.

This proof-of-concept technique has not been used to attack people. The attack can be easily replicated, according to the Horst Gortz Institute. According to the researchers, it is realistic to expect real-world attacks against CardSpace in the near future.

Microsoft did not respond to SCMagazineUS.com's request for comment.

See original article on SC Magazine US

 
Ads by Google
Thoughts on this article? Add a comment below.
Be the first to comment on this article.

Report this comment as offensive:

   * Indicates information we require to process your submission.

Name: *
Email: *
Reason for offense: *
Your report will not be displayed.  
Name:
*
 
Email:
(will not be displayed)
*
 
Comment:
(HTML not permitted)
*
 
Validation
*

Enter the code you see below:

 

 
 
 
 
 
Tripwire - Click here to win an iTouch
 
 
 
Vulnerabilities & Exploits Whitepapers