Slashdot Mirror


MS Sez Hailstorm To Play Nice With Others

Rocketboy writes "ZDNet has posted a story saying that Microsoft will not be the only repository of user information within Hailstorm. They claim that Hailstorm was intended all along to be a network of trusted repositories along the lines of all the banks that exchange information within their ATM networks. " One of the key points from Coursey's piece, IMHO, is "MICROSOFT SAID it does not know whether a central authority should be created to oversee the open-trust network it hopes these changes will help create. In an interview late yesterday, an executive working on the project said the company is open to an industry group--such as those already controlling Kerberos and other Internet technologies--taking the lead role if it becomes necessary. ." So, the central authority part is still being worked out - but regardless, this changes the framework of Hailstorm, if implemented.

143 comments

  1. Now life is so much safer by alen · · Score: 1

    that MS won't control all the data. They will just get every time you log in or access anything.

  2. Can I act as a repositry by barnaclebarnes · · Score: 3, Interesting

    What if an idividual wants to become a respoistry for their own information and not trust it to a central place. That way I could carry the information with me knowing it is as secure as I want it to be.

    --
    [Please type your sig here.]
    1. Re:Can I act as a repositry by markbthomas · · Score: 1

      Or you could use someone that you already trust, like say, your bank.

      To be honest I think this is a good idea. I wanted to post a comment to a story on another news site, but I needed to log in, and I just could not be bothered. If I could enter in my bank id and password safe in the knowledge that unless I indicate otherwise (on the HSBC web site) the company whose site I am visiting will only get my name and a ticket that says I am who I say I am.

      I just don't want Microsoft, or any one company, have exclusive rights over this. Choice is good. Open standards are good.

    2. Re:Can I act as a repositry by Anonymous Coward · · Score: 0

      As an individual you cannot be trusted with your own information. Only large corporations can be trusted with personal information.

      All of your brain are belong to us!!

    3. Re:Can I act as a repositry by sulli · · Score: 2

      You already do, until you use a service like Hailstorm.

      --

      sulli
      RTFJ.
  3. Does this mean Slashdot will Join up? by elliotj · · Score: 2, Funny

    When will I be able to use my MS Passport login to login to Slashdot?

    That way MS can post comments for me, and save me the time I spend thinking for myself.

    1. Re:Does this mean Slashdot will Join up? by tomknight · · Score: 1
      That way MS can post comments for me, and save me the time I spend thinking for myself.

      You're not really suggesting that most /. posters actually manage to think for themselves, surely?

      Tom.

      --
      Oh arse
    2. Re:Does this mean Slashdot will Join up? by sulli · · Score: 2

      Yes, but don't get your panties all in a knot. "They" will be posting, not "you." So if they can't be trusted with your own password, we might have an issue, otherwise, you can just disregard this message.

      --

      sulli
      RTFJ.
  4. OK, let's see the specs by Fnkmaster · · Score: 4, Interesting
    Open the standard, show us how to roll a Hailstorm server, tell us how to set up alternative Hailstorm compatible networks, come up with a process for joining the official Hailstorm network, show us how we control where our information goes.


    Microsoft is just realizing that nobody will play with their new toys if their toys take away rights that we consider sacred. They have backed out of really bad ideas in the past when enough industry and pundit criticism was leveled against them. If they will again this time, that would be great, but content-free proclamations are meaningless. I trust these guys as far as I could throw a hundreds-of-billions-of-dollar-cap company.

    1. Re:OK, let's see the specs by FatRatBastard · · Score: 2, Insightful

      If they will again this time, that would be great, but content-free proclamations are meaningless. I trust these guys as far as I could throw a hundreds-of-billions-of-dollar-cap company.

      In this case I think MS is telling the truth. They don't want to be the sole responsibility for all authentication (think of the liability they'd have). They're going to allow anyone to set up their own authentication centers. Why? Because they're going to hold ALL THE PATENT RIGHTS AROUND IT. That way they get paid whether Joe ASP buys their back end solution directly from them or from a competitor.

    2. Re:OK, let's see the specs by sporty · · Score: 1
      I think its all that and worse. Not only will we not play with their toys, they won't play with their toys. By pushing off the responsibility to someone else, MS gets less linelight. Think of it, what's worse: releasing software that's buggy or being the source of the problem?


      Think of it, do you yell at the people who invented telnet or do you yell at the person who left the daemon running allowing root access? Probably the latter since its his responsibility not to use it in the first place.

      --

      -
      ping -f 255.255.255.255 # if only

    3. Re:OK, let's see the specs by bendude · · Score: 1

      Open the standard, show us how to roll a Hailstorm server, tell us how to set up alternative Hailstorm compatible networks, come up with a process for joining the official Hailstorm network, show us how we control where our information goes.

      I just love that name, it's so warm and fuzzy, isn't it? Makes you want to work in the same market as M$, doesn't it.

      </SARCASTIC> (Oops, I was sure I closed that ages ago)

      --


      Get the Hell off my planet, you slimy mobster Bush!
    4. Re:OK, let's see the specs by Anonymous Coward · · Score: 0

      You guys are so knee-jerk anti-Microsoft it's comical. Authentication needs to be done by someone, and Microsoft is one of the few companies with the muscle to do it. Now that they have clarified/reversed/opened-up (you pick the spin) the authentication & identity storage, you *still* have bones to pick. Damned if they do play ball with others, Damned if they don't. The only course of action that would satisfy you anti-Microsoft zealots is if they donate all their cash to charity, renounce all versions of Windows, donate the code to open source, and force all employees to work for non-profits.

    5. Re:OK, let's see the specs by Salsaman · · Score: 2

      Yes and of course, it will only run with Windows 2000 as the server, and Win XP as the client.

    6. Re:OK, let's see the specs by GunFodder · · Score: 1

      Maybe that's why they're also changing the name of Hailstorm to something nicer, "My Happy Services" or something like that.

    7. Re:OK, let's see the specs by ethereal · · Score: 1

      Yes, because their liability concerns have been their overriding business principle so far...

      Nope, they want it all, they're just now discovering that there's a chance they won't get it.

      --

      Your right to not believe: Americans United for Separation of Church and

    8. Re:OK, let's see the specs by ethereal · · Score: 1

      Do not taunt "My Happy Services".

      --

      Your right to not believe: Americans United for Separation of Church and

    9. Re:OK, let's see the specs by sporty · · Score: 1
      Well, lets not forget there are other methods. You can do it with certificates. Point being is the fact THEY don't trust their products says a lot.

      What would make us happy is if they made their .net architecture open. Their implementation I care a rat's ass about. Same thing with wma, 'cept we don't care about wma that much. Real audio/video, quicktime, there are problems because the algorithms are so closed source, many don't benefit.

      Thank GOD we have kerberos and mpeg 4 :P

      --

      -
      ping -f 255.255.255.255 # if only

  5. microsoft quotes on hailstorm by 0-9a-zA-Y_.+!*'(),-$ · · Score: 0, Redundant
    This may be redundant, but these quotes have to be seen to be believed :


    ...Microsoft may be the only company in the world with the skill and clout to pull it off...


    ...the public will fully accept the HailStorm concept and Microsoft as a trusted repository within five to 10 years...


    ..Initially, HailStorm will consist of a universal password and a service...


    ...If you are in a car accident, HailStorm could automatically send your medical history and insurance information to the hospital before the ambulance arrived...


    ...Microsoft officials acknowledged the company has been vulnerable to attacks and system failures...


    ...They're the most attacked infrastructure there is on the Internet, they're the No. 1 target for hackers...


    It'll never work. There is no fucking way I'd trust anyone, let alone microsoft, with that sort, or quantity, of private information.

    --
    Everything but Z
    1. Re:microsoft quotes on hailstorm by n0rm · · Score: 0

      So now, instead of just the script kiddies attacking M$ now we'll have all of the criminals attacking too. What better place to attack if you know there are medical and financial records. Hello identity theft.

      Also, who's going to pay for the hailstorm service? When I go to another banks ATM's I get charged by both banks. Before I buy into a scheme like this I would like to see where the money is going to come from.

    2. Re:microsoft quotes on hailstorm by ch-chuck · · Score: 1

      Microsoft may be the only company in the world with the skill and clout to pull it off..

      ...translation: We have the brand name recognition, advertising budget and best legal defense in the industry, plus we can easily foist it on consumers by leveraging our patented OSMonopoly®, whether they want it or not.

      --
      try { do() || do_not(); } catch (JediException err) { yoda(err); }
  6. Big difference by pointym5 · · Score: 4, Insightful

    There's a big difference between Microsoft (and whatever johnny-come-lately fabricated trustee companies that spring up) and banks. Banks have a culture wholly different from companies like Microsoft. I'm not saying they're divine or infallible, but simply that the way they look at the world and their responsibilities for information are shaped by years and years of living within a complex web of federal and state regulations, and of sitting on the "capital" of essentially unlimited public trust. They don't "think out of the box" about ways to use information they control. The comparison to ATM networks is therefore (in my opinion) structurally accurate but misleading.

    1. Re:Big difference by gorilla · · Score: 2

      Also the banks had their seperate datastores, and worked together to interoperate. This is very different to Microsoft owning everything then allowing others to play too.

    2. Re:Big difference by JediTrainer · · Score: 4, Interesting

      There's another difference: Banks are LIABLE if they lose your information, which translates usually to you losing money.

      Microsoft has never been accountable for anything being lost in the past, by hiding behind their EULA (ie: we are not responsible for any direct or indirect losses as a result of using this product. You agree not to sue us no matter what). Well, until Microsoft guarantees unconditionally that my information is SAFE, like the banks do, I will not ever, ever trust them.

      There aren't any laws protecting me, so why should I even dip a toe into the water?

      --

      You can accomplish anything you set your mind to. The impossible just takes a little longer.
    3. Re:Big difference by Rick+the+Red · · Score: 2
      I agree with everything except your comment, "They don't 'think out of the box' about ways to use information they control." In the United States, banks now own insurance companies and other financial institutions they were previously barred from owning. As a consequence of this de-regulation Congress gave them strict guidelines to protect our privacy. The banks must inform you that they may give your private info to their new corporate bretheren. For example, your bank may give your personal information (SSN, phone number, etc.) and complete credit history (including who you wrote checks to and for how much) to their new insurance company, who can then see you're sending checks to a competitor and call you at dinner time to pitch their fabulous rates, comparing themselves to your current insurer. You must then tell the bank to go stuff sand up their ass -- if you don't tell them to not share your information, they will. Indeed, they already have, and you must trust them that when you tell them to stop they'll go around to all the other companies and tell them to please forget everything about you. Yeah, right. Like they're gonna put all that toothpaste back in the tube.

      Banks "don't think out of the box." Riiiiiight.

      ROTFLMAO!!!

      --
      If all this should have a reason, we would be the last to know.
  7. Possibility of user-controlled Hailstorm-ish serv? by Masem · · Score: 4, Insightful
    If there's a possibility that others can run services equilvalent to Hailstorm, would this not also lead to the possibility that individual users with sufficient technical know-how (namely anyone using Linux :-) could run their own Hailstorm-like server on their own box with their own security safegaurds?

    Yes, this is MS, so they might only provide a WinXX client. Yes, this is MS, so they might require you to register your client with some central authority with the ability to 'audit' the server to make sure it's up to specs.

    But it may also be as simple as having a client conform to certain specs (hopefully open), and that's it. Average Joe would probably never worry themselves with this, so they'd not lose that many customers in the first place.

    But in the end, I think it's very important that Hailstorm cannot be a necessity for web sites and that there must be a manual entry level for data when it is needed.

    --
    "Pinky, you've left the lens cap of your mind on again." - P&TB
    "I can see my house from here!" - ST:
  8. Re:Come on linux geeks. Lets see some MS bashing! by LinuxHam · · Score: 1

    How about, "and we already saw how well they played along with Kerberos.."

    you idiot troll

    --
    Intelligent Life on Earth
  9. splintered authentication networks? by count0 · · Score: 2, Interesting

    So will Hailstorm play nice with whatever the AOL collective is working on? Or will there be several authentication networks where you need an id on each to reach the full range of the Net.

    Didn't this happen with early financial systems too? I have logos for a number of money-transfer networks on the back of my ATM card (though Interac is the only one that I recognize from actual use). I'm guessing they used to be incompatible...not on the same card.

    When I'm worried about limited net access and content, I'm not talking about MSN and AOL being the only online properties...but what if the NYTimes or WSJ implement Hailstorm? And what if Sports Illustrated implements AOL's version (no question there, since it's part of the Time Warner family).

    And how will the inevitable open-source clone work? Will people try to co-opt Hailstorm, or turn away since it's MS? (my crystal ball predicts both, in two different projects)

    cheers,

    cz

    1. Re:splintered authentication networks? by leviramsey · · Score: 1
      Didn't this happen with early financial systems too? I have logos for a number of money-transfer networks on the back of my ATM card (though Interac is the only one that I recognize from actual use). I'm guessing they used to be incompatible...not on the same card.


      They still are incompatible. Anybody who has a Discover card knows this (Discover uses its own ATM network, Novus). It can be a bitch finding an ATM that's supports the Novus network.



      It's sort of like the way that DNS works: most everybody uses the InterNIC root servers, but there are some other DNS hierarchies (new.net for instance).

  10. It still makes me nervous by mikey504 · · Score: 3, Insightful

    I've seen the "We're not sure where this is headed, we're making it up as we go along" rap from these guys before.

    It's hard for me to believe that it's true that Microsoft is "betting the farm" on their Hailstorm strategy but at the same time they haven't taken the time to develop a roadmap for its deployment and maintenance.

    It's too important to them and they have too many resources devoted to it for there not to be a plan. Given that, it makes me nervous that they don't seem to be willing to share the details of that plan. That seems to indicate that they are pretty sure we won't like it.

    The best protection is to insist on open, documented interfaces to all of the components of this technology. We need to make sure that the rest of the industry remains free to develop their own components of the Hailstorm/.Net architecture with the assurance that they will interoperate. The problem is, it would take a lot of cooperation for the industry to reject any offering that doesn't meet these requirements.

    1. Re:It still makes me nervous by HiThere · · Score: 2

      The best assumption is that all press releases come from the marketing department, and that those in power are careful to shield them from any knowledge of what's really going on.

      If that's not how it works, then reality seems to be a work-alike.

      --

      I think we've pushed this "anyone can grow up to be president" thing too far.
  11. Banks already do this by Anonymous Coward · · Score: 0

    So why don't just beef up the bank's infrastructure including online password and a few extra properties and be done with it?

  12. Multiple points of failure? by n-baxley · · Score: 1

    So now there will be more targets for a potential hacker to choose from. It's not enough that Microsoft would store the data, someone with a dubious security trackrecord. Now we have an untold number of other places that can be attacked. Why doesn't anyone realise that the only safe way to do this is to store the data on secured, portable hardware that can be taken with the owner of the information?

  13. Re:Come on linux geeks. Lets see some MS bashing! by wljones · · Score: 1

    I already voted with my billfold and my feet. Microsoft products are, like the company itself and poster codeforprofit2, totally irrelevant.

  14. Perfect Terrorist Target by Anonymous Coward · · Score: 0

    What happens when some terrorist decides to take out one of these central repositories. Please don't say it's not possible, after what happened last week anything is possible.

    1. Re:Perfect Terrorist Target by mach-5 · · Score: 2

      No big deal...just a big inconvenience for all the users of the service, although I'm sure the system will be highly redundant with such large volumes of data at risk.

      Now a terrorist hacker...that's a different story.

  15. Re:Come on linux geeks. Lets see some MS bashing! by ReelOddeeo · · Score: 2

    Just bring it on, ignore all facts, just bash, bash, bash!

    How about instead, we pay attention to all the facts, and then bash, bash bash!


    ------
    Bill Gates is my shepard.
    I shall not want.
    He maketh me to lie down and pay more green.
    He leadeth me beside still blue screens.
    He rebooteth my system.
    He leads me along the path where he wants me to go today, for his own sake.
    Yea, though I walk through the shadow of the valley of silicon,
    I will fear no innovation.
    For thou art with me.
    Thy monopoly and thy lawyers they comfort me.
    Thou preparest a preannounced major upgrade before me in the presence of thy competitors.
    Thou annointest my head with service packs and hot patches.
    My hard drive runneth over.
    Surely crashes and high prices will follow me all the days of my life,
    and I shall dwell under the control of Microsoft forever.

    --

    Those who would give up liberty in exchange for security and DRM should switch to Microsoft Palladium!
  16. Plays well with others?! by randal_hicks · · Score: 1

    I am pleased to see that perhaps one day in the near future, companies might cooperate to give us something we need. Regardless of their motivation, perhaps they should get a gold star next to their name for playing well with others.

    Placing information anywhere outside of your physical control implies either a great deal of trust, or stupidity. With a financially disinterested party keeping an eye on the individual trusted federation members I think that we may soon be able to trust our personal information, which many value greater than their money, with the same level of assurance as depositing our paychecks. I think that this brings up 2 questions:

    [1] whether usage fees ala not-my-bank's ATM might be forthcoming...

    [2] Would we be able to make a withdrawl of our information and trust that it is completely removed from their computing environment? With regular backups and cache-systems, it seems rather difficult to expect not leaving behind some residual trace...

    What do you think?

  17. Architectural security? by dpilot · · Score: 2

    Is enough know about Hailstorm and Passport to know if they are architecturally capable of the security we desire?

    Plus I see mention of "The Industry Standard Kerberos 5" in the article. Of course MS Kerberos follows Kerberos 5 standards, just in a way that doesn't play with anyone else. So do we get Real Kerberos 5, or MS Kerberos here?

    What are the requirements for joining the "Trust Federation"? Who defines the requirements? Who can cast the blackball?

    --
    The living have better things to do than to continue hating the dead.
    1. Re:Architectural security? by MrBogus · · Score: 2

      MS Kerberos interoperates with MIT Kerberos for authentication purposes (who you are, such as your user name). This seems to be the sell of Passport/Hailstorm.

      Microsoft's extention was to add a NT UID (or UUID or whatever it's called), which effectively determines your authorization (what you can do). They used a field specifically designed for this purpose.

      This eleminates the need for a local /etc/passwd type (or in MS terms 'SID') mapping of user name ("root") to UID (0). If you've ever worked in an NDS or other directory environment, you'd know that the primary point of a DS is to centralize security admin, so you can see why this was a necessary step.

      Now, how this works out in Hailstorm probably depends on how you use it. For a message board or online shopping, the provider would probably just need the authentication and handle the authorization themselves (ie MS wouldn't provide the information that "CmdrTaco" is the admin of Slashdot, but would verify that CmdrTaco is who he says he is.)

      BUT .. It could be that you could 'outsource' your PDC to Microsoft and set up LAN security using Hailstorm IDs. Sound retarded, but recall that the current crop of small shop MCSEs is having difficulty groking AD, and LanMan/NT4 is going away eventually. The next step would be move Exchange (or more likely "Small Business Server") off-site and make that a service also. You can see the possiblities.

      --

      When I hear the word 'innovation', I reach for my pistol.
  18. What if... by Soko · · Score: 2

    Really guys - what if Microsoft is learning from the beating they're taking from Linux, and really want to play nice? Instead of loosing the rockets at them, maybe we should put aside our mistrust of the Redmond gang - ever so slightly - and take a serious look at working with them.

    This is the type of thing that users want - one password, and thier relevant information attached to that password. I have most of my users saying "Why do all these systems need a different password? Can't you computer guys get together?" IOW, they want convenience and simplification. Since Microsoft is going to do this anyway, assisting them will get us in the loop, as it were. Besides keeping "the enemy" closer, it can also have some benefical side effects:

    1. It will show Microsoft that when we say "Open", we mean Open for anyone, including Satan himself.
    2. It will also show them that Open Standards benefit everyone from the end user to the programmer writing APIs. They are better for business than anything propietary.
    3. Things work better with a community attitude. Maybe it will change Microsofts bastille mentality for the better.
    4. We can make sure that this is done properly - no backdoors, no worms, and as much security as possible.

    If we just slam the door on them, instead of giving an open invitaion to work with all computer users, designers and programmers, we will just fortify thier distaste for Open Source and perpetuate the silly feud that's been going on for years.

    Executive Summary: Look at thier proposal seriously instead of just dismissing it out of hand, putz.

    Soko

    --
    "Depression is merely anger without enthusiasm." - Anonymous
    1. Re:What if... by Anonymous Coward · · Score: 0

      Really guys - what if Microsoft is learning from the beating they're taking from Linux, and really want to play nice? Instead of loosing the rockets at them, maybe we should put aside our mistrust of the Redmond gang - ever so slightly - and take a serious look at working with them.

      No, we must bash teh Mirco-soft!

    2. Re:What if... by Alien54 · · Score: 2
      Well, the only problem is their history, their track record.

      I used to like their stuff, and then they lost my trust and admiration.

      That is the essential point, and it is the most damning.

      They are going to need about 5 or ten years of marketing honesty and products that don't screw with me to earn it back.

      Their behavior and attitude has made them a liability to me.

      Sorry

      --
      "It is a greater offense to steal men's labor, than their clothes"
    3. Re:What if... by anshil · · Score: 2

      'cause I guess many will be generally against a central security system, no matter which OS and from which company. 'cause playing with security is no fun.

      Now image such system beeing hacked? Can you really imagine what the outcome is? Today a central security server hacked means break down of our whole economy, one group of people having access to everything? Including your bank account passwords? Medical health info, etc. etc.

      I would be a against it even if it's a relative secure system, but additionally imaging such info running on a windows NT or XP server just gives me the creeps.

      --

      --
      Karma 50, and all I got was this lousy T-Shirt.
    4. Re:What if... by tshak · · Score: 2

      That's why your medical information and bank account passwords aren't going to be in your MS passport. This is designed for e-Commerce and personalized sites not your Online Bank.

      --

      There is no longer anything that can be done with computers that is nontrivial and clearly legal. -- Paul Phillips
    5. Re:What if... by platypus · · Score: 2
      Really guys - what if Microsoft is learning from the beating they're taking from Linux, and really want to play nice? Instead of loosing the rockets at them, maybe we should put aside our mistrust of the Redmond gang - ever so slightly - and take a serious look at working with them.

      But you can't really believe that, can you?

      I'll try to be conservative with what I say and analyze this MS that we all now:

      ms has 95%+ market share in desktop os's.

      ms has 98%+ market share in office apps.

      ms has 95%+ market share in browsers

      (let that be 90% or 99%, whatever you feel better with).

      In the last 5 years Microsoft has extended/held that share by

      1. price dumping (free browser)
      2. price dumping (preinstalled os)
      3. price dumping (silently tolerating warez and making warezing ms-products easy)
      4. market pressure by artificially introducting a "critical mass" factor via incompability, i.e. proprietary protocols (kerberos, office-formats, activex as browser components, vb-script, hidden win32 api-calls, dumping java, dumping plugin-api, dumping realplayer codecs)


      1., 2., 3. will not help them anymore, instead they will stop and are already stopping using this tactics, because they simply can cash in more. They don't gain a dime when the 95%+ of ms-user simply stay with win95,98,nt,2000 and even XP.
      On the other hand they must find a way to
      1. get existing userbase to change OS
      2. simultaneously prevent existing userbase to change to non-ms operating systems.

      Add to that that ms has to fear that their capability to "innovate" might not be as competitive as it perhaps once was, because there are hungry companies/developer communities out there to get them (sun/staroffice, kde, gnome, linux etc.). Plus the fact that the territory where one can "innovate" is shrinking. That indicates that the consumer software market is going to a market where the price is the main selling point - because "real" (needed) features will be more and more omnipresent in all offers.
      For instance, the only important "feature" that MS-office has that star-office hasn't is, well, it's msoffice (file compability) - see point 4 above.

      MS has everything to loose if it opens up it's protocols and API's and it has everything to loose if it doesn't. But the second alternative at least gives them a chance to win - and win big time. As for the first alternative - an "open" .net will in the end give a way to interoperate with everything they have, it would crush their stranglehold to every market.

      So, we don't even need to go into details where they pretended to play fair before and didn't (html, xml, soap, kerberos) or where there is talk that they will kill existing interoperability (CIFS), I think it's clear they can't play fair.

    6. Re:What if... by Anonymous Coward · · Score: 0

      People who posted online knew the difference between "lose" and "loose". I can't believe how many people use the wrong one.

    7. Re:What if... by the_2nd_coming · · Score: 1

      exactly, look how long it took IBM to get back the trust they once had in the market.

      --



      I am the Alpha and the Omega-3
    8. Re:What if... by tshak · · Score: 2

      Please come back later when you have some facts to present. Oh, and I'd like to see you easily "warez" what's considered the most sophisticated anti-piracy measures in the business (esp. mass piracy via dupped CD's). Time to roll out your holograph printer.

      --

      There is no longer anything that can be done with computers that is nontrivial and clearly legal. -- Paul Phillips
    9. Re:What if... by Anonymous Coward · · Score: 0

      WTF are you talking about? since when do you need to totaly duplicate the holograms on the CD to make them work? I have a copy of Office 2k enterprise edition that does not need a reg code and does not call home to tell daddy bill where it is. I also have a copy of VS 6.0 premium that allows the same. those are the second and third in command of MSs empire and I can make 10 million copies that will operate the same as the legal ones. also, when I did use windows, I never bought it, my buddy always snagged me a copy from the warrze IRC and copying a windows CD-rom from a legal copy is not difficult at all either, just include the reg code on the surface of the CD.

      I would say that is sufficent to show how simple it has been to copy MS software. now however, they must protect their profits since they have no growing room in the market. that is what the XPs are all about. just wait until the VS .net and VS XP is released, perfect compliments to the XP brotheren.

    10. Re:What if... by platypus · · Score: 1

      I take this as a compliment, cause I know if you had an idea that english is not my native language, you would have refrained from being so anal. ok?

    11. Re:What if... by platypus · · Score: 1

      Did I say pirating and selling and imitating, or warezing?
      Why should any home user need the fucking holograph?
      To pin it on a wall in his restroom?
      How hard is it to warez a software from a company which uses so ingenious serials like

      111-11111
      123-45678

      throughout the entire product line (back in the days of office 97 IIRC)

      Yes, ms did try to go against mass-piracy, but they didn't do anything against pirated software for home users.

    12. Re:What if... by Anonymous Coward · · Score: 0

      Good point that the hologram program was entirely aimed at rogue OEMs and other retail rip-off artists.

      While MS was churning out their super snazzy hologram CDs, they were happily spamming anyone with an MSDN subscription ($1500/year, IIRC) anything they wanted. Pretty much any office on the program is up-to-their-neck in Office and Windows CDs, most of which require NO serial number. That has changed with the XP line of products tho.

    13. Re:What if... by tshak · · Score: 1

      Because the highest volumes of piracy doesn't happen when one of us geeks downloads the copy or borrows it from a friend and get's a serial. The poster was suggesting that MS was flooding the market on purpose by letting mass-piracy takes place. I'm saying, that's BS.

      --

      There is no longer anything that can be done with computers that is nontrivial and clearly legal. -- Paul Phillips
    14. Re:What if... by platypus · · Score: 2

      The poster was suggesting that MS was flooding the market on purpose by letting mass-piracy takes place. I'm saying, that's BS

      Yeah, exactly

    15. Re:What if... by HiThere · · Score: 2

      Sure. I'm willing. All they have to do is GPL the code. BSD would probably be ok, though I'd have a few reservations. Or MPL+GPL+... Or Artistic.

      But I'd prefer GPL.

      --

      I think we've pushed this "anyone can grow up to be president" thing too far.
    16. Re:What if... by tshak · · Score: 1

      No, this is not a staw man. It would be if I contended that everything he said in his statements where wrong simply based on the fact that his weakest argument (piracy) was false. Rather, I was simply stating that the vast majority of his post was clearly not factual and would be observed as such by any reasonable person. In light of this, it is a waste of time for me to contest each argument. Instead, I fairly demonstrated how ludicrous his piracy argument was. If one is to make such ludicrous claims, it is apparent to me that they have gone out of thier way to push an agenda, regardless of factual basis.

      --

      There is no longer anything that can be done with computers that is nontrivial and clearly legal. -- Paul Phillips
    17. Re:What if... by platypus · · Score: 1


      If one is to make such ludicrous claims, it is apparent to me that they have gone out of thier way to push an agenda, regardless of factual basis.

      Obviously you didn't even read the post accurate up to the sender.
      It was me the whole time! Your he is me.
      And you have an offensive way of discussing, you're mis-stating (sp?) things most of the time - I gave examples to everything in my post.
      What should I do?
      Should I cite a certain document? ok, done.

      To be true, I just browsed your comment history and found out that you seem reasonable. That's why I don't want you to dismiss arguments because you think there's an agenda behind it. I'm writing this from IE here which I think does the best job for my work. I control who gets to use what system in our company and everyone can use the os he wants - everyone uses windows - and it' s ok. I have no agenda, but I don't trust microsoft, securitywise and otherwise.

    18. Re:What if... by tshak · · Score: 1

      Right, I wasn't paying attention to the name, just the arguments. I don't mean to offend you, however, to say that "MS dumped Java", and that "MS allows rampent piracy" so on and so forth is just plain wrong. MS has a HUGE anti-piracy deptartment and Sun and MS settled that MS's VM was illigal! And you have to admit that the entire spirit of your post was not to state facts (even if some of it was factual), but to slam MS.

      --

      There is no longer anything that can be done with computers that is nontrivial and clearly legal. -- Paul Phillips
  19. Microsoft Security by spike666 · · Score: 1

    I think you can infer that Microsoft is really acknowledging that they have big ole security holes in their products. When they say they will open up the Hailstorm services (oops, i mean what Microsoft "meant to do all along") it really means, "well we know some hacker is going to break in and publish all the information anyways, so its not really a 'secure' means of keeping this information. oh and, can you find some other people to run it for us so we arent liable?"

    spike
    "help help! i'm all tangled up in the .Net!"

    1. Re:Microsoft Security by alen · · Score: 2, Insightful

      Actually I meant that they will be paid every time a transaction is performed. Kind of like the royalties they get with some online photo processing operations.I'm not very good at proofreading.

      The challenge for Microsoft is to find a recurring revenue stream. Jack Welch says don't let anyone get between you and your customers. Bill Gates listened, and others didn't. They are letting Microsoft get between them and their customers.

  20. Oh now this is funny... by weslocke · · Score: 2

    an executive working on the project said the company is open to an industry group--such as those already controlling Kerberos

    And I wonder if they would treat it the way they treated the Kerberos oversight group? You know, that "Hey decide whatever you want, but we're doing it our way. Ain't market-share wonderful?" way.

    --

    'Life is like a spoonful of Drain-O, it feels good on the way down but leaves you feeling hollow inside'
  21. BLAME MICROSOFT! by Desco · · Score: 1

    Microsoft vulnerabilities (aka "innovations") are responsible for every worm/virus we've seen in the past few months: Code Red, Code Blue, SirCam, Apost, and Nimda. Why aren't they under any fire from the media, watchdog groups, or the general public?!?

    1. Re:BLAME MICROSOFT! by leviramsey · · Score: 1
      Microsoft vulnerabilities (aka "innovations") are responsible for every worm/virus we've seen in the past few months: Code Red, Code Blue, SirCam, Apost, and Nimda. Why aren't they under any fire from the media, watchdog groups, or the general public?!?


      Also to blame are the trained monkeys masquerading as Windows admins who don't know how to install a fscking patch!

    2. Re:BLAME MICROSOFT! by Dog+and+Pony · · Score: 1

      First off, 99% of media don't know sh*t about sh*t. They do not make any deeper research, they just blow up some huge headlines about "Most dangerous virus ever", and then they quote some random security guy that says some vague things, usually someone from Symantec or MacAfee that has every reason to blow the issue up.

      They usually mention that mac users aren't affected, as if that was the only othe computer.

      And they always call outlook viruses "email viruses", IIS viruses for "Web server viruses" etc.

      Most of the time, they just don't know better. And as long as media does not, or chose not to, the general public will not either.

      All media wants is readers/viewers. They don't care about facts such as who is responsible, they want headlines. That should be painfully obvious by now.

  22. But Why? by (void*) · · Score: 2
    It seems that the debate has suddenly taken on a moralistic tone that has neatly sidestepped the various issues.


    But before we go there - let us first join hands in praise to tell MS that this is a right step in that direction. There are lots of responses we could take, and LISTEN UP: We don't have to jump into anything. We all have to compromise to reach a solution, but we shouldn't have to bet the farm on this. The compromise can take various forms.


    So what is the issue? The question concerns technical issues of the Hailstorm protocol. It is not just about who is in control.


    In other words, let us take the "white paper" approach. Can MS do that? One that allows us to review and alllow the security experts to scrutinize the technical details and design of the whole setup? If MS can take this step, then I should like to say that would remove most of the security concerns of Hailstorm.


    And for that debate, I would like to ask the first question. What is the point of Hailstorm? How is Hailstorm different from say, the Mozilla Personal Security Manager, wherein, the user stores his data on his computer, and has simplified but yet customizable controls as to who receives what data?


    Secondly, isn't aggregating these data a security flaw itself? Remember that security is not one issue itself, but encompasses issues of authentication, identity, integrity and all that. Given this setup, itn't the chance of idenity theft greater? Part of the security of setup we have is that no one single company knows everything about an arbitrary person. They may know your credit card n umber and hence your financial records, but they may not know your hair color. Meanwhile, some government agency may have your bloodtype, but they don't have your financial information. Isn't Passport a step in the wrong direction, in such a case?

  23. I am Scared by VEGETA_GT · · Score: 1

    More of my banking done through something designed by microsoft, now that's a scary thought

    my 2 cents plus 2 more

    1. Re:I am Scared by rebelcool · · Score: 2
      I assure you, a great deal (if not most) of your banking data is stored in MS-sql databases.

      I write software for a financial services company, we do most of our work with MS-sql because thats what most banks use.

      --

      -

    2. Re:I am Scared by tshak · · Score: 2

      I know. And now that Great Plains has been purchased by MS, most medium to larger sized businesses will be running their ledgers and payroll from MSSQL and MS software. But, hey, why look at the facts?

      --

      There is no longer anything that can be done with computers that is nontrivial and clearly legal. -- Paul Phillips
  24. Hailstorm looks cool, wish I had more data by sachachua · · Score: 2
    Hailstorm admittedly looks cool. The Microsoft press room has a couple of articles and press releases. I'd love to have a really nice web-based calendar/whatever else...

    But if Microsoft is going to charge for the service, how does that work?

  25. what about certs and and smartcards by heyeq · · Score: 1

    Whatever happened to the widespeard notion of giving every person (affordable) digital certificates on a smartcard, and putting a smartcard reader in every machine?
    There's already a chain of trust established that no-one seems to have a problem with these days, just like we don't have problems with trusting banks with our money, and there's the key that identifies me uniquely and PROVES that I am who I say I am.

    Also, this way I can install some software on my machine to manage my own information, and set the levels of sharing I wish to enable for sites and services.
    For sites/services that require additional information, I can then choose to share or hide that information.

    The way I see it, everyone's just sort of sitting around like a tree-huggin' hippy, waiting for Microsoft to roll this out, and then bitching and moaning about it. I have to admire Microsoft, not for the way they are going about their strategies, but rather that they have strategies and have the guts to stake some or all of their business on those strategies. I unfortunately do not see nearly the same level of risk being played by other companies, e.g. for Sun's Java ONE technology, which is meant to be a direct competitor. And neither do I see anybody else making nearly as much use of their corporate PR machines.

    Anyway, the main point here is using existing technology: Digital Certificates. make them cheap, put them everywhere, and you don't have to rely on a Microsoft-provided service.
    I'm sure even Linux users would be happy with that.

  26. Here's an even better idea! by Kamel+Jockey · · Score: 1

    We can have Al Gore be the repository for the information. He will keep it safe in a lockbox!

    --
    In case of fire, do not use elevator. Use water!
    1. Re:Here's an even better idea! by Si · · Score: 1

      Score: -1, Nearly A Year Too Late To Be Funny.

      --


      Why is it that many people who claim to support standards have such atrocious spelling and grammar?
  27. It's not who YOU trust... by Bilbo · · Score: 2
    The question is not, who do you trust, but who do other people trust.

    The whole point of a central repository for this sort of information is for the benefit the the site you are trying to access, so that they can verify from some trusted source that you are who you say you are. Anyone can set up their own repository and say that they are someone else. However, if the site can go to some trusted source (either Microsoft, or a large bank, or whatever), then they can be certain that you are who they think you are, and have permission to use credit card numbers or access confidential information or perform transactions, etc...

    The benefit to the customer is not trust, but the "convenience" of a single login, and not having to remember a fistful of different username/password pairs for all the sites they deal with.

    --
    Your Servant, B. Baggins
    1. Re:It's not who YOU trust... by the_2nd_coming · · Score: 1

      that is why I think a buissness would benifit much more from a system like this for its LAN than a WAN would. either dotGNU or this piece of crap.

      --



      I am the Alpha and the Omega-3
  28. So, what is in it for me? by Dog+and+Pony · · Score: 1

    Maybe I missed the whole point, but...

    I am not that interested. I'm fully content with remembering a few passwords, entering my email where necessary and so forth. So what interests me the absolute most is, will this Ban me from places if I decide not to play along? Or can I access stuff anyways, but I'll have to enter my credentials myself (like I do today)?

    The only secure place I need and want is my bank, and they have a nifty little code generator that protects my account, and I can do all the basic stuff that way.

    What do I gain from this? What do I lose? What do I lose if I don't participate?

    Please help a guy that needs to do some more reading up. :)

  29. Goatse.cx warning for above "news" link by Bilbo · · Score: 2

    ugh...

    --
    Your Servant, B. Baggins
  30. Sez!? by Mike+Connell · · Score: 3, Insightful

    Is it really necessary to use words like "Sez" in the story title?

    It's "News for Nerds", not "Newz 4 Nurdz"

    1. Re:Sez!? by Anonymous Coward · · Score: 0
      Actually, I believe it was a rather clever allusion to Microsoft as the mob. You know as in,

      "So I sez to myself, self I sez, deez Open Source loonies really gots it comin to dem."

      Even slashdot editors can subtle occasionally.

    2. Re:Sez!? by Anonymous Coward · · Score: 0

      Relax lamer. hehe

    3. Re:Sez!? by Anonymous Coward · · Score: 0
      no, it's N3W$ 4 N3r4$

      Post Comment Lameness filter encountered. Your comment violated the postercomment compression filter. Comment aborted

  31. Re:Come on linux geeks. Lets see some MS bashing! by Joseppi+Blauinski · · Score: 1

    Micro$erf Trolls -- the more I hear/read their thoughts, the more I disklike them. I've noticed a common attribute among them all: they typically have *NOT* used anything other than Micro$oft junk.

  32. This changes nothing by BroadbandBradley · · Score: 2

    Microsoft has yet to sign any of the major players to join its trust federation

    in some form or another, MS will decide who gets to run .net services and who doesn't. This BS about " These two changes--which Microsoft says aren't changes at all, but rather a clarification of what the company planned to do all along" is utter crap. Had this been what they've been planning all along, they would've made this "clarification" a long time ago. I'm going to bet that you'd better buy a copy of Win2K to run services and pay dearly for it!!! MS should be stopped, really stopped. They OWN our government, and are doing everything they can to confuse issues and LOOK like they're playing nice.
    just format your drive now and install Linux, you'l be glad you did. Don't give those MS MF'ers a cent of your cash.
    I wouldn't put the terrorist attacks past MS as a way to downplay the ongoing monopoly proceedings.

  33. cross-application session data by mydigitalself · · Score: 1

    that's what in it for you. hailstorm is essentially a platform to host components (like EJBs). passport makes it possible for components in hailstorm to exchange exposed data so that they can interoperate.

    an example. if your bank uses hailstorm and you authenticate with passport and amazon.com uses hailstorm and passport authentication - you would be able to (once your've authenticated with passport) just click buy and amazon's components could invoke components on your bank with your passport id and say "give me the money now".

    i know you can save your profile and everything on amazon and so you may still ask "so what's in it for me". that was just the first example that came to mind and if you can see the advantages of such an interoperative infrastructure then here.

    and, yes, there are probably risks and stuff involved but lets let it evolve and give it a chance.

    1. Re:cross-application session data by lsdino · · Score: 1

      that's what in it for you. hailstorm is essentially a platform to host components (like EJBs). passport makes it possible for components in hailstorm to exchange exposed data so that they can interoperate.

      Actually hailstorm is a set of web services (which is SOAP over HTTP) which are basically a set of core services (like calendaring, document storage, a wallet and other stuff - see this). The platform to host components like EJBs is really more what ASP.NET/.NET Frameworks are for (which of course includes C# and all that fun stuff (there's a quick summary here).

      an example. if your bank uses hailstorm and you authenticate with passport and amazon.com uses hailstorm and passport authentication - you would be able to (once your've authenticated with passport) just click buy and amazon's components could invoke components on your bank with your passport id and say "give me the money now".

      Well, this could be done through a web service, but it doesn't necessarily have to be hailstorm. For example, your bank could have a web service running on their Linux box with Apache, or thier IBM mainframe, or whatever... They just need to communicate via SOAP, and it's documented and standardized. It's all XML, so no one should have too many problems with it.

      i know you can save your profile and everything on amazon and so you may still ask "so what's in it for me". that was just the first example that came to mind and if you can see the advantages of such an interoperative infrastructure then here. [thinkgeek.com]

      And so the profile is one of the Hailstorm web serivces ("myProfile").

      and, yes, there are probably risks and stuff involved but lets let it evolve and give it a chance.

  34. This news is not any good by Captain_Frisk · · Score: 2

    If the same information is stored in several different servers, doesn't that just provide more points of failure?

    It seems to me that either everyone should either keep their information independently (the current system), which results in data replication, not to mention countless points of failure...
    or...
    Have one person keep this information... but it seems like that isn't such a popular thing here.

    Captain_Frisk

  35. One Big Waffle by Ms.Taken · · Score: 1

    I'm sorry, but all I see in this 'news' is Microsoft's spin doctors working overtime to try to defuse opposition.

    "On the Internet, this means that an AOL or Yahoo login could someday be just as valid for accessing Microsoft's MSN..."

    Or they may never be valid at all.

    "the company is open to an industry group...taking the lead role if it becomes necessary."

    Not that they're going to allow it, they're just willing to discuss it right now.

    "As the story develops and more questions are asked, some of this may change, but at a high level this appears to be Microsoft responding to critics."

    Nothing in this article is necessarily true, but rest assured that Microsoft is doing its best to convince you to trust them.

    "Microsoft has yet to sign any of the major players to join its trust federation, although talks are supposed to be underway. If companies like AOL see this as a valid attempt to make the handling of user security and personal information into new Internet standards, they might join. Or they might abstain simply to try to gain some competitive leverage over Microsoft."

    If none of this ever happens and Microsoft retains its lock on user info, blame AOL.

  36. how typical by mydigitalself · · Score: 1

    >I wouldn't put the terrorist attacks past MS as a way to downplay the ongoing monopoly proceedings.

    oh. i can't believe that statement! that's the sort of rant that gives linux an evil-geek-virus-writing-socialist-spotty-nerd-angr y-teenager name. well done, you are really helping to spread the word.

    1. Re:how typical by BroadbandBradley · · Score: 2

      I really believe that MS is that EVIL. nothing to do with Linux, and the attacks are a terrible tragedy. I really feel for all of those affected.
      Let me ask you this, if you had 100 BILLION DOLLARS in your PERSONAL bank account, wouldn't you retire or at least dedicate your time to doing good for those around you? Good old Bill just wants another 100 Billion Dollars. If greed on that level isn't evil, I don't know what is.

    2. Re:how typical by Anonymous Coward · · Score: 0

      dedicate your time to doing good for those around you?

      Ever hear of the Bill and Melinda Gates Foundation? The one that's already put tens of billions to work for immunizations, scholarships and the like? Remember, Bill continues to contribute to that, and all of his money (except for a relatively paltry couple of million for his kids) goes there eventually.

      Bill's time isn't worth much as a donation. His money is. So increasing his net worth, in the end, is the way he can do the most good.

      Or is it evil because he's helping non-Americans?

    3. Re:how typical by tshak · · Score: 2

      Score: -1 Flamebait

      Money isn't everything. If I had $100 billion, I would still program. Heck, I'd probably program more because I could afford the resources to start my own company and code what I want to code.

      --

      There is no longer anything that can be done with computers that is nontrivial and clearly legal. -- Paul Phillips
    4. Re:how typical by BroadbandBradley · · Score: 2

      sure you'd still code out of the love of coding, but would your code be intent on locking people in to using ONLY YOUR code?

    5. Re:how typical by Anonymous Coward · · Score: 0

      Tens of billions? Learn to count.

  37. This changes nothing by rabtech · · Score: 2

    This changes nothing in regards to Hailstorm. It only changes some people's incorrect perceptions of it. Hailstorm, and the entire .NET framework itself, is extensible by any third party, and always has been. It is simply unfortunate that people are so reactionary whenever Microsoft proposes anything.

    If you want to provide authentication via non-Microsoft means, write a .NET plugin for hailstorm using the documented interface, and then the system will use your authentication method rather than some other (like Passport).

    I just want to emphasise that this is only surprise news for those who failed to take the time to understand Hailstorm and .NET previously.

    --
    Natural != (nontoxic || beneficial)
  38. Mod parent up. by tshak · · Score: 2

    Good question. I think that MS should release a PR to developers regarding the planned Kerberos implementation, since in the past "open Kerberos" ment open to all who used their implementation of it!

    --

    There is no longer anything that can be done with computers that is nontrivial and clearly legal. -- Paul Phillips
  39. Hmm... Kerberos by Stultsinator · · Score: 1


    Would that be the same Microsoft that "Embraced" and "Extended" Kerberos, despite there being an industry-wide controlling organization?

    Sure, create a Hailstorm standards organization all nice and proper. Just as long as they answer to Microsoft (and don't dare compete with them.)

  40. Since When is a Hail Storm a good thing? by Anonymous Coward · · Score: 0

    I'm just baffled by this. Hail Storms can wreak desctruction across a wide area. So to MSFT's HailStorm will wreak desctruction. How can a company long known for security lapses, breaches, negligence ever be trusted with significant data?

    if you do trust them, you'll end up getting pounded when the storm hits.

    But no worries for me, as they won't have any of my data.

  41. trusted network? by duplicatedAccount · · Score: 1

    Why not build a trusted network on a free platform (Askemos). There should always be a choice.

  42. I can't believe they mentioned Kerberos. by just+dave · · Score: 1

    I cannot believe they mention kerberos after their
    effort to put proprietary, non interoperable data
    in the kerberos protocol. Not only that, but the
    fact that they rejected efforts (at least for
    6 months to a year) by the kerberos standard
    bearers at MIT to to keep the specification
    interoperable.

    They actually offered to work with microsoft to
    accomodate extensions to the protocol and Microsoft wouldn't have it.

    Take a look at this post from Ted Ts'o in 1997:
    http://diswww.mit.edu:8008/menelaus.mit.edu/kerb er os/10954

    Do you really think Microsoft has changed, especially now that they have the government on
    their side?

    -Dave

    1. Re:I can't believe they mentioned Kerberos. by Salsaman · · Score: 2

      Yes and remember they even tried to sue /. because somebody posted their *copyrighted* amendments here...

    2. Re:I can't believe they mentioned Kerberos. by Anonymous Coward · · Score: 0

      Take a look at this post from Ted Ts'o in 1997:
      http://diswww.mit.edu:8008/menelaus.mit.edu/kerb er os/10954


      Ooops -

      "Server error (500)
      The discuss backend server returned the following error:
      Discuss request failed: Meeting does not exist (32201987)"

  43. Lots of data ... by King+Of+Chat · · Score: 1

    ... if we can store any personal data, how much pr0n can their servers hold? What - can't put that much in one account? Just open up another one - we can script that...

    On second thoughts, if they're thinking of folks dumping their MS Turd docs in there, they must be thinking of a lot of space.

    --
    This sig made only from recycled ASCII
    1. Re:Lots of data ... by Anonymous Coward · · Score: 0

      User profile stores will be about ~2k of data (depending on how well .net surfaces), each increment of 2k will cost 0.016 cents (the price of bandwidth and memory). Basically we dont have that much right now, its more intellectual ownership at this point. Each transaction will cost a bit as well - we start of by making it free for a while - the use of XP, MSN will cover the first 2 years, thenafter our price model incurs the proliference of Linux MacOS / AOL Mindspring. Our plan is to go to a transaction based model as Bill has specified two years ago. Megaservices, and transaction fees thats where were going, and guess what....you fools are letting us do it! Cause we give you more and more candy, we aquire cheap software houses and market them to their upper limits.

      Our VAR channels - the guys who think they make bucks servicing our software are clueless! We have you all.

      Sound good? We thank you for your time, cause we already made some $ out of you.

  44. Two quotes by iphayd · · Score: 1

    These two changes--which Microsoft says aren't changes at all, but rather a clarification of what the company planned to do all along

    - The article

    "History has stopped. Nothing exists except an endless present in which the Party is always right. I know, or course, that the past is falsified, but it would never be possible for me to prove it, even when I did the falsification myself. After the thing is done, no evidence ever remains. The only evidence is inside my own mind, and I don't know with any certainty that any other human being shares my memories"

    - Orwell "1984"

  45. Re:Come on linux geeks. Lets see some MS bashing! by codeforprofit2 · · Score: 1

    Yeah! Give me more dollarsighns in Micro$oft, more more more!

  46. Don't believe them by Rev+Snow · · Score: 1
    Don't believe them.

    Those Klingon bastards killed my son. </kirk>

    1. Re:Don't believe them by grylnsmn · · Score: 1

      I've never trusted Klingons, and I never will. I can never forgive them for the death of my boy.

  47. Microsoft lied in the court of law. by novastyli · · Score: 1

    They would say anything.
    I don't think it wise to trust them.

    1. Re:Microsoft lied in the court of law. by Salsaman · · Score: 2

      Not only did they lie, they also falsified evidence.

  48. For whom the cluephone rings by Trailer+Trash · · Score: 1

    Ultimately, people within Microsoft must understand that they don't have the skills within their organization to run something this important all by themselves. Look at the last two years:

    1. Didn't pay bill for Passport.com, service down for two days, they were mostly unaware of the problem and couldn't solve it on their own. If not for Slashdot, it's difficult to say how long it would have been down.
    2. DNS down for two days. How does a company of that size have a problem like this?
    3. MSN Messenger down for a week. Think about that. An entire week. Again, how does this happen?

    The first two items would have disabled their whole service. The third just shows that they don't have the competence required to run such an important service. They need to not only have a network of repositories, they need to gracefully bow out of being part of that network.

    Michael

  49. Why would you want just one password? by tresstatus · · Score: 1

    ?!?!?!? This makes no sense. Doesn't everyone realize that it's much more secure to use different passwords on every thing you do? So in other words, if someone cracks one of your password (assuming you only have one) then they have access to all of your data. This doesn't seem like a very safe idea to me.

    --
    stephen
    1. Re:Why would you want just one password? by Mike+A. · · Score: 1

      For people who don't have encyclopedic memories (which is to say, normal people), multiple passwords are actually less secure than a single password, because ordinary users will either use the same password for everything anyway, use simple easy-to-guess (and easy-to-dictionary-attack) passwords, or write them down.

      --

      --
      Do I look like I speak for my employer?
  50. Pardon my Cynicism by 4of12 · · Score: 2

    "In an interview late yesterday, an executive working on the project said the company is open to an industry group--such as those already controlling Kerberos and other Internet technologies--taking the lead role if it becomes necessary. ."

    But I suspect that as events unfold it will be found that an impartial central authority will hold us back from getting the full user experience of MS Innovation.

    Certainly it has been the case that standard Kerberos was found "insufficient" for Active Directory and required "improvement".

    Don't get me wrong. I'm not saying that standards are never in need of improvement. I'm just saying that I don't want the improved standard to be controlled by an entity with other interests. Interests that can conflict with the kind of impartiality and pure technical focus that such standards control deserves.

    --
    "Provided by the management for your protection."
  51. Re:Come on linux geeks. Lets see some MS bashing! by codeforprofit2 · · Score: 1

    Yeah, thats the spirit! Bash!

  52. and while they're there by buzban · · Score: 1

    i suspect they'll want to check your serial numbers and what browser you're using and what office suite you're using...

  53. Re:Come on linux geeks. Lets see some MS bashing! by codeforprofit2 · · Score: 1

    Na, what good do facts do. Just keep on bashing!

  54. Benefits of running a private server? by mcc · · Score: 2

    (Warning: if the following post turns out to be nonsense, please forgive me.)

    Let's say that 2002 comes, and hailstorm becomes something that has a point (beyond ensuring Microsoft gets to have SOMETHING installed by default in WinXP that they can charge a monthly fee for and that the average user won't be able to figure out how to turn off), and GNUStorm 0.6 or whatever gets written, and i install it on my Mac OS X box in my dorm and register my dormroom computer as my authentication authority.

    How much flexibility will this hypothetical GNUStorm server have? Is the hailstorm protocol such that if i was running an authentication server, i could flexibly determine exactly what information and when that a given site is given about me? In what way? Oh, hell, is there ANY POINT AT ALL to hailstorm besides not having to type in your personal information/preferred password to every website, and making sure you don't make up 90% of the information you put on webforms? Is there ANYTHING hailstorm does that a web browser with a good autocomplete feature doesn't do?

    And if i *could* limit who gets what information, would there be any point, since the sites will all be using the same backhanded information-sharing tactics they use now? If i use hailstorm once to sign onto MSN messenger, and i decide not to let microsoft.com's hailstorm server have any information besides the username and password they use to authenticate, couldn't they just contact some site that they partially own and that shipped me something once, say "hey, what do you have on this username", and get a full readout of my name, address, etc..? Umm.. i'm pretty sure that that last sentence doesn't make a whole lot of sense, but you get what i mean.. right?

    If i am misunderstanding what Hailstorm is, i apologize, and request that someone more informed can set me straight. You'll have to excuse me, Microsoft seems to be working very hard to make sure everyone is as misinformed as they could possibly be as to the nature of .NET..

    1. Re:Benefits of running a private server? by tve · · Score: 1

      Could you please stop analyzing Hailstorm? Once people realize it's some sort of glorified identd+finger we'll never get them to give up their privacy!

      --

      If there is hope, it lies in the trolls.
    2. Re:Benefits of running a private server? by mcc · · Score: 1

      Hmm. Interesting way of putting it..

      Except the thing is: Glorified identd+finger actually sounds like a pretty good idea, to me. I could go for that. I'd be happier just integrating that functionality into Jabber, though.. I mean, as long as we're putting talk(1) there, you might as well go all the way :)

      Well, whatever.

  55. A Further Announcement by Anonymous Coward · · Score: 0
    In a long-awaited announcement, Ossama bin Laden today announced his willingness to work with U.S. authorities to improve airport security.


    A bin-Laden spokesperson stated, "We've long seen bin-Laden Enterprises as a leader in the area of airport security and air-traffic control. We can sent those babies wherever we want to. But we're good guys - we just want to help people get to where they should go."


    The spokesperson refused requests for further details. "This isn't really the time now. I'm sure we can work out the details over time, so we can help bring U.S. air travel, and the U.S. economy, to where it ought to be."


    Cooperation is essential, the spokesperson emphasized. "We'll gladly work with whoever wants to cooperate with us. However, if we have to, we will go it alone."


    So far, there is no response from the U.S. government.

  56. Like a bank... oh yeah by Anonymous Coward · · Score: 0

    I've always thought that Hailstorm/Passport type transactions should be heavily regulated-- banks are, insurance companies are, --why trust an electronic transaction provider (oh boy new acronym ETP) to do the right thing without regulation?

    This fits in quite well with the idea of controlling Microsoft's monopolistic behavior -- except there isn't any regulatory body...

    oh well, that's a minor detail.

  57. XNS is better! by Anonymous Coward · · Score: 0

    Forget Hailstorm/Passport. Use XNS (http://xns.org) instead.

  58. MS Marketing/World Conquest by amitti · · Score: 1

    Rejected, resent, whatever..
    <BR>
    <BR>We don't want this! And Microsoft &lt;B&gt;&lt;I&gt;KNOWS&lt;/I&gt;&lt;/B&gt; we don't want it. Their entire marketing stategy depends entirely on their ability to brainwash dim witted Americans and this still Amazes me after all of these years.
    <BR>
    <BR>They have enough power now controling the most widely used desktop OS for consumers, just imagine if they had control of our information, our banks, government websites.. They want all of this, and they'll stop of nothing to get it. They're starting it right now with all of the new stuff in XP, they slowly slip in new evil code and introduce it so you're not immediatly repused.
    <BR>
    <BR>Look at Internet Explorer for example. I've used this for 5 years (until recently as Mozilla build have greatly improved) and I've always wondered why the hell when I type something stupid it forwarded me so some asp on msn.com. I would have loved to edit that out of the registry just because it has that potential to become MSEvil 1.0 but I never could find it. (I don't believe it's in the registry, it appears to be hard coded into IE, don't take my word on it though) About two weeks ago when I typed something stupid it reports it to MSN and tells me what I most likely wanted and does a MSN search. I'm not running MSN Explorer (hell no!), I thought I was running just plain old Internet Explorer but it appears I can't run that anymore..
    <BR>
    <BR>Luckily Mozilla is really becoming a well rounded peice of software now so this doesn't pose a problem. This doesn't always work though. I'm still running Outlook and I'm a bit afriad of what they have hidden (laying dormat) in there. I really havn't found anything as an alternative yet that can handle the amount of email I receive daily. (around 300+ messages, most of which I need to save and archive) So, until then, who know if I'm being watched, I don't know whats in that source anymore than the other guy..
    <BR>
    <BR>I appoligize for the long message, however I feel this rant was well founded after years of enduring Microsoft software. Linux is calling, and I mean REALLY calling, I use it through SSH all day, but I still don't have the software I need to all me to move altogether.
    <BR>
    <BR>-Mitti

    1. Re:MS Marketing/World Conquest by lsdino · · Score: 1

      Look at Internet Explorer for example. I've used this for 5 years (until recently as Mozilla build have greatly improved) and I've always wondered why the hell when I type something stupid it forwarded me so some asp on msn.com. I would have loved to edit that out of the registry just because it has that potential to become MSEvil 1.0 but I never could find it. (I don't believe it's in the registry, it appears to be hard coded into IE, don't take my word on it though) About two weeks ago when I typed something stupid it reports it to MSN and tells me what I most likely wanted and does a MSN search. I'm not running MSN Explorer (hell no!), I thought I was running just plain old Internet Explorer but it appears I can't run that anymore..

      That would be the "Search from Address Bar" option that you're objecting to. The option is set in Tools->Internet Options->Advanced, and there's "Search From Address Bar" with a "When Searching" option with 4 choices, one of those is Do not search from the address bar. Or that's at least the way it is in IE 6, I would assume it's not a new option though...

  59. Reuters story with more info by Larne · · Score: 1
    Available here as well as probably other places.

    The article says that MS is looking to work with AOL on this. Oh, joy.

    It also quotes MS as saying:
    Microsoft said it would extend its Passport identification service to other Web site operators and companies by supporting Kerberos 5.0 -- another authentication service developed at the Massachusetts Institute of Technology
    Of course, I'm sure we can all guess which version of Kerberos they'll be using...
  60. MS open? by Anonymous Coward · · Score: 0

    anyone remember this hoopla? Just a few weeks after Java was announced MS swore up and down to anyone who would listen that they would make activex open. 5 years later, .... ???
    http://news.cnet.com/news/0,10000,0-1003-200-313 30 3,00.html

    MS open?

  61. No its not that just one authority by Anonymous Coward · · Score: 0

    Look, is MS has all passwords/credentials where do you think the concentration of firepower will be? hmmmmm...

  62. Exactly by Passacaglia · · Score: 1

    Running a version of Kerberos on the Internet makes sense for some applications, perhaps e-commerce; as long as the people running the authentication servers are competent about reliability and security, and those people must be trustworthy, and not have conflicts of inerest over privacy.

    Microsoft should be nowhere near those servers.

  63. M$ ba$hing! by Joseppi+Blauinski · · Score: 1

    Mo$t Intelligent Cu$tomer$ Reali$e Our $oftware Only Fool$ Teenager$
    ... is that enough for ya bunkie?