Correcting the fundamental flaw in the Microsoft Passport 
      Approach
   
  news alert 
    (excerpt)
  
  
  
  London, UK - 12 May 2003, 11:30 GMT - Last weeks revelation 
    by a Pakistani researcher - Muhammad Faisal Rauf Danka - that, by typing in 
    a certain Microsoft web address together with the appropriate command, a malevolent 
    could access and modify the information held on any Microsoft Passport account, 
    is unlikely to be the last discovery of a critical vulnerability. The mi2g
    Intelligence Unit expects confidence in online trading to decline if there 
    is a failure to initiate a radical overhaul of the prevailing approach and 
    practices.
    
  
  [CONTINUES]
  
  If you are already a member 
    of the Inner Sanctum you should have been emailed a full copy. To retrieve 
    the original article please fill out the order 
    form.
  [Country specific Intelligence Briefings provide a detailed insight into 
    the range and depth of digital attacks taking place and include the impact 
    of the start of the war with Iraq. They can be ordered from the 
    Intelligence Unit]