Slashdot Mirror


MS Sez Hailstorm To Play Nice With Others

Rocketboy writes "ZDNet has posted a story saying that Microsoft will not be the only repository of user information within Hailstorm. They claim that Hailstorm was intended all along to be a network of trusted repositories along the lines of all the banks that exchange information within their ATM networks. " One of the key points from Coursey's piece, IMHO, is "MICROSOFT SAID it does not know whether a central authority should be created to oversee the open-trust network it hopes these changes will help create. In an interview late yesterday, an executive working on the project said the company is open to an industry group--such as those already controlling Kerberos and other Internet technologies--taking the lead role if it becomes necessary. ." So, the central authority part is still being worked out - but regardless, this changes the framework of Hailstorm, if implemented.

47 of 143 comments (clear)

  1. Can I act as a repositry by barnaclebarnes · · Score: 3, Interesting

    What if an idividual wants to become a respoistry for their own information and not trust it to a central place. That way I could carry the information with me knowing it is as secure as I want it to be.

    --
    [Please type your sig here.]
    1. Re:Can I act as a repositry by sulli · · Score: 2

      You already do, until you use a service like Hailstorm.

      --

      sulli
      RTFJ.
  2. Does this mean Slashdot will Join up? by elliotj · · Score: 2, Funny

    When will I be able to use my MS Passport login to login to Slashdot?

    That way MS can post comments for me, and save me the time I spend thinking for myself.

    1. Re:Does this mean Slashdot will Join up? by sulli · · Score: 2

      Yes, but don't get your panties all in a knot. "They" will be posting, not "you." So if they can't be trusted with your own password, we might have an issue, otherwise, you can just disregard this message.

      --

      sulli
      RTFJ.
  3. OK, let's see the specs by Fnkmaster · · Score: 4, Interesting
    Open the standard, show us how to roll a Hailstorm server, tell us how to set up alternative Hailstorm compatible networks, come up with a process for joining the official Hailstorm network, show us how we control where our information goes.


    Microsoft is just realizing that nobody will play with their new toys if their toys take away rights that we consider sacred. They have backed out of really bad ideas in the past when enough industry and pundit criticism was leveled against them. If they will again this time, that would be great, but content-free proclamations are meaningless. I trust these guys as far as I could throw a hundreds-of-billions-of-dollar-cap company.

    1. Re:OK, let's see the specs by FatRatBastard · · Score: 2, Insightful

      If they will again this time, that would be great, but content-free proclamations are meaningless. I trust these guys as far as I could throw a hundreds-of-billions-of-dollar-cap company.

      In this case I think MS is telling the truth. They don't want to be the sole responsibility for all authentication (think of the liability they'd have). They're going to allow anyone to set up their own authentication centers. Why? Because they're going to hold ALL THE PATENT RIGHTS AROUND IT. That way they get paid whether Joe ASP buys their back end solution directly from them or from a competitor.

    2. Re:OK, let's see the specs by Salsaman · · Score: 2

      Yes and of course, it will only run with Windows 2000 as the server, and Win XP as the client.

  4. Big difference by pointym5 · · Score: 4, Insightful

    There's a big difference between Microsoft (and whatever johnny-come-lately fabricated trustee companies that spring up) and banks. Banks have a culture wholly different from companies like Microsoft. I'm not saying they're divine or infallible, but simply that the way they look at the world and their responsibilities for information are shaped by years and years of living within a complex web of federal and state regulations, and of sitting on the "capital" of essentially unlimited public trust. They don't "think out of the box" about ways to use information they control. The comparison to ATM networks is therefore (in my opinion) structurally accurate but misleading.

    1. Re:Big difference by gorilla · · Score: 2

      Also the banks had their seperate datastores, and worked together to interoperate. This is very different to Microsoft owning everything then allowing others to play too.

    2. Re:Big difference by JediTrainer · · Score: 4, Interesting

      There's another difference: Banks are LIABLE if they lose your information, which translates usually to you losing money.

      Microsoft has never been accountable for anything being lost in the past, by hiding behind their EULA (ie: we are not responsible for any direct or indirect losses as a result of using this product. You agree not to sue us no matter what). Well, until Microsoft guarantees unconditionally that my information is SAFE, like the banks do, I will not ever, ever trust them.

      There aren't any laws protecting me, so why should I even dip a toe into the water?

      --

      You can accomplish anything you set your mind to. The impossible just takes a little longer.
    3. Re:Big difference by Rick+the+Red · · Score: 2
      I agree with everything except your comment, "They don't 'think out of the box' about ways to use information they control." In the United States, banks now own insurance companies and other financial institutions they were previously barred from owning. As a consequence of this de-regulation Congress gave them strict guidelines to protect our privacy. The banks must inform you that they may give your private info to their new corporate bretheren. For example, your bank may give your personal information (SSN, phone number, etc.) and complete credit history (including who you wrote checks to and for how much) to their new insurance company, who can then see you're sending checks to a competitor and call you at dinner time to pitch their fabulous rates, comparing themselves to your current insurer. You must then tell the bank to go stuff sand up their ass -- if you don't tell them to not share your information, they will. Indeed, they already have, and you must trust them that when you tell them to stop they'll go around to all the other companies and tell them to please forget everything about you. Yeah, right. Like they're gonna put all that toothpaste back in the tube.

      Banks "don't think out of the box." Riiiiiight.

      ROTFLMAO!!!

      --
      If all this should have a reason, we would be the last to know.
  5. Possibility of user-controlled Hailstorm-ish serv? by Masem · · Score: 4, Insightful
    If there's a possibility that others can run services equilvalent to Hailstorm, would this not also lead to the possibility that individual users with sufficient technical know-how (namely anyone using Linux :-) could run their own Hailstorm-like server on their own box with their own security safegaurds?

    Yes, this is MS, so they might only provide a WinXX client. Yes, this is MS, so they might require you to register your client with some central authority with the ability to 'audit' the server to make sure it's up to specs.

    But it may also be as simple as having a client conform to certain specs (hopefully open), and that's it. Average Joe would probably never worry themselves with this, so they'd not lose that many customers in the first place.

    But in the end, I think it's very important that Hailstorm cannot be a necessity for web sites and that there must be a manual entry level for data when it is needed.

    --
    "Pinky, you've left the lens cap of your mind on again." - P&TB
    "I can see my house from here!" - ST:
  6. splintered authentication networks? by count0 · · Score: 2, Interesting

    So will Hailstorm play nice with whatever the AOL collective is working on? Or will there be several authentication networks where you need an id on each to reach the full range of the Net.

    Didn't this happen with early financial systems too? I have logos for a number of money-transfer networks on the back of my ATM card (though Interac is the only one that I recognize from actual use). I'm guessing they used to be incompatible...not on the same card.

    When I'm worried about limited net access and content, I'm not talking about MSN and AOL being the only online properties...but what if the NYTimes or WSJ implement Hailstorm? And what if Sports Illustrated implements AOL's version (no question there, since it's part of the Time Warner family).

    And how will the inevitable open-source clone work? Will people try to co-opt Hailstorm, or turn away since it's MS? (my crystal ball predicts both, in two different projects)

    cheers,

    cz

  7. It still makes me nervous by mikey504 · · Score: 3, Insightful

    I've seen the "We're not sure where this is headed, we're making it up as we go along" rap from these guys before.

    It's hard for me to believe that it's true that Microsoft is "betting the farm" on their Hailstorm strategy but at the same time they haven't taken the time to develop a roadmap for its deployment and maintenance.

    It's too important to them and they have too many resources devoted to it for there not to be a plan. Given that, it makes me nervous that they don't seem to be willing to share the details of that plan. That seems to indicate that they are pretty sure we won't like it.

    The best protection is to insist on open, documented interfaces to all of the components of this technology. We need to make sure that the rest of the industry remains free to develop their own components of the Hailstorm/.Net architecture with the assurance that they will interoperate. The problem is, it would take a lot of cooperation for the industry to reject any offering that doesn't meet these requirements.

    1. Re:It still makes me nervous by HiThere · · Score: 2

      The best assumption is that all press releases come from the marketing department, and that those in power are careful to shield them from any knowledge of what's really going on.

      If that's not how it works, then reality seems to be a work-alike.

      --

      I think we've pushed this "anyone can grow up to be president" thing too far.
  8. Re:Come on linux geeks. Lets see some MS bashing! by ReelOddeeo · · Score: 2

    Just bring it on, ignore all facts, just bash, bash, bash!

    How about instead, we pay attention to all the facts, and then bash, bash bash!


    ------
    Bill Gates is my shepard.
    I shall not want.
    He maketh me to lie down and pay more green.
    He leadeth me beside still blue screens.
    He rebooteth my system.
    He leads me along the path where he wants me to go today, for his own sake.
    Yea, though I walk through the shadow of the valley of silicon,
    I will fear no innovation.
    For thou art with me.
    Thy monopoly and thy lawyers they comfort me.
    Thou preparest a preannounced major upgrade before me in the presence of thy competitors.
    Thou annointest my head with service packs and hot patches.
    My hard drive runneth over.
    Surely crashes and high prices will follow me all the days of my life,
    and I shall dwell under the control of Microsoft forever.

    --

    Those who would give up liberty in exchange for security and DRM should switch to Microsoft Palladium!
  9. Architectural security? by dpilot · · Score: 2

    Is enough know about Hailstorm and Passport to know if they are architecturally capable of the security we desire?

    Plus I see mention of "The Industry Standard Kerberos 5" in the article. Of course MS Kerberos follows Kerberos 5 standards, just in a way that doesn't play with anyone else. So do we get Real Kerberos 5, or MS Kerberos here?

    What are the requirements for joining the "Trust Federation"? Who defines the requirements? Who can cast the blackball?

    --
    The living have better things to do than to continue hating the dead.
    1. Re:Architectural security? by MrBogus · · Score: 2

      MS Kerberos interoperates with MIT Kerberos for authentication purposes (who you are, such as your user name). This seems to be the sell of Passport/Hailstorm.

      Microsoft's extention was to add a NT UID (or UUID or whatever it's called), which effectively determines your authorization (what you can do). They used a field specifically designed for this purpose.

      This eleminates the need for a local /etc/passwd type (or in MS terms 'SID') mapping of user name ("root") to UID (0). If you've ever worked in an NDS or other directory environment, you'd know that the primary point of a DS is to centralize security admin, so you can see why this was a necessary step.

      Now, how this works out in Hailstorm probably depends on how you use it. For a message board or online shopping, the provider would probably just need the authentication and handle the authorization themselves (ie MS wouldn't provide the information that "CmdrTaco" is the admin of Slashdot, but would verify that CmdrTaco is who he says he is.)

      BUT .. It could be that you could 'outsource' your PDC to Microsoft and set up LAN security using Hailstorm IDs. Sound retarded, but recall that the current crop of small shop MCSEs is having difficulty groking AD, and LanMan/NT4 is going away eventually. The next step would be move Exchange (or more likely "Small Business Server") off-site and make that a service also. You can see the possiblities.

      --

      When I hear the word 'innovation', I reach for my pistol.
  10. What if... by Soko · · Score: 2

    Really guys - what if Microsoft is learning from the beating they're taking from Linux, and really want to play nice? Instead of loosing the rockets at them, maybe we should put aside our mistrust of the Redmond gang - ever so slightly - and take a serious look at working with them.

    This is the type of thing that users want - one password, and thier relevant information attached to that password. I have most of my users saying "Why do all these systems need a different password? Can't you computer guys get together?" IOW, they want convenience and simplification. Since Microsoft is going to do this anyway, assisting them will get us in the loop, as it were. Besides keeping "the enemy" closer, it can also have some benefical side effects:

    1. It will show Microsoft that when we say "Open", we mean Open for anyone, including Satan himself.
    2. It will also show them that Open Standards benefit everyone from the end user to the programmer writing APIs. They are better for business than anything propietary.
    3. Things work better with a community attitude. Maybe it will change Microsofts bastille mentality for the better.
    4. We can make sure that this is done properly - no backdoors, no worms, and as much security as possible.

    If we just slam the door on them, instead of giving an open invitaion to work with all computer users, designers and programmers, we will just fortify thier distaste for Open Source and perpetuate the silly feud that's been going on for years.

    Executive Summary: Look at thier proposal seriously instead of just dismissing it out of hand, putz.

    Soko

    --
    "Depression is merely anger without enthusiasm." - Anonymous
    1. Re:What if... by Alien54 · · Score: 2
      Well, the only problem is their history, their track record.

      I used to like their stuff, and then they lost my trust and admiration.

      That is the essential point, and it is the most damning.

      They are going to need about 5 or ten years of marketing honesty and products that don't screw with me to earn it back.

      Their behavior and attitude has made them a liability to me.

      Sorry

      --
      "It is a greater offense to steal men's labor, than their clothes"
    2. Re:What if... by anshil · · Score: 2

      'cause I guess many will be generally against a central security system, no matter which OS and from which company. 'cause playing with security is no fun.

      Now image such system beeing hacked? Can you really imagine what the outcome is? Today a central security server hacked means break down of our whole economy, one group of people having access to everything? Including your bank account passwords? Medical health info, etc. etc.

      I would be a against it even if it's a relative secure system, but additionally imaging such info running on a windows NT or XP server just gives me the creeps.

      --

      --
      Karma 50, and all I got was this lousy T-Shirt.
    3. Re:What if... by tshak · · Score: 2

      That's why your medical information and bank account passwords aren't going to be in your MS passport. This is designed for e-Commerce and personalized sites not your Online Bank.

      --

      There is no longer anything that can be done with computers that is nontrivial and clearly legal. -- Paul Phillips
    4. Re:What if... by platypus · · Score: 2
      Really guys - what if Microsoft is learning from the beating they're taking from Linux, and really want to play nice? Instead of loosing the rockets at them, maybe we should put aside our mistrust of the Redmond gang - ever so slightly - and take a serious look at working with them.

      But you can't really believe that, can you?

      I'll try to be conservative with what I say and analyze this MS that we all now:

      ms has 95%+ market share in desktop os's.

      ms has 98%+ market share in office apps.

      ms has 95%+ market share in browsers

      (let that be 90% or 99%, whatever you feel better with).

      In the last 5 years Microsoft has extended/held that share by

      1. price dumping (free browser)
      2. price dumping (preinstalled os)
      3. price dumping (silently tolerating warez and making warezing ms-products easy)
      4. market pressure by artificially introducting a "critical mass" factor via incompability, i.e. proprietary protocols (kerberos, office-formats, activex as browser components, vb-script, hidden win32 api-calls, dumping java, dumping plugin-api, dumping realplayer codecs)


      1., 2., 3. will not help them anymore, instead they will stop and are already stopping using this tactics, because they simply can cash in more. They don't gain a dime when the 95%+ of ms-user simply stay with win95,98,nt,2000 and even XP.
      On the other hand they must find a way to
      1. get existing userbase to change OS
      2. simultaneously prevent existing userbase to change to non-ms operating systems.

      Add to that that ms has to fear that their capability to "innovate" might not be as competitive as it perhaps once was, because there are hungry companies/developer communities out there to get them (sun/staroffice, kde, gnome, linux etc.). Plus the fact that the territory where one can "innovate" is shrinking. That indicates that the consumer software market is going to a market where the price is the main selling point - because "real" (needed) features will be more and more omnipresent in all offers.
      For instance, the only important "feature" that MS-office has that star-office hasn't is, well, it's msoffice (file compability) - see point 4 above.

      MS has everything to loose if it opens up it's protocols and API's and it has everything to loose if it doesn't. But the second alternative at least gives them a chance to win - and win big time. As for the first alternative - an "open" .net will in the end give a way to interoperate with everything they have, it would crush their stranglehold to every market.

      So, we don't even need to go into details where they pretended to play fair before and didn't (html, xml, soap, kerberos) or where there is talk that they will kill existing interoperability (CIFS), I think it's clear they can't play fair.

    5. Re:What if... by tshak · · Score: 2

      Please come back later when you have some facts to present. Oh, and I'd like to see you easily "warez" what's considered the most sophisticated anti-piracy measures in the business (esp. mass piracy via dupped CD's). Time to roll out your holograph printer.

      --

      There is no longer anything that can be done with computers that is nontrivial and clearly legal. -- Paul Phillips
    6. Re:What if... by platypus · · Score: 2

      The poster was suggesting that MS was flooding the market on purpose by letting mass-piracy takes place. I'm saying, that's BS

      Yeah, exactly

    7. Re:What if... by HiThere · · Score: 2

      Sure. I'm willing. All they have to do is GPL the code. BSD would probably be ok, though I'd have a few reservations. Or MPL+GPL+... Or Artistic.

      But I'd prefer GPL.

      --

      I think we've pushed this "anyone can grow up to be president" thing too far.
  11. Oh now this is funny... by weslocke · · Score: 2

    an executive working on the project said the company is open to an industry group--such as those already controlling Kerberos

    And I wonder if they would treat it the way they treated the Kerberos oversight group? You know, that "Hey decide whatever you want, but we're doing it our way. Ain't market-share wonderful?" way.

    --

    'Life is like a spoonful of Drain-O, it feels good on the way down but leaves you feeling hollow inside'
  12. But Why? by (void*) · · Score: 2
    It seems that the debate has suddenly taken on a moralistic tone that has neatly sidestepped the various issues.


    But before we go there - let us first join hands in praise to tell MS that this is a right step in that direction. There are lots of responses we could take, and LISTEN UP: We don't have to jump into anything. We all have to compromise to reach a solution, but we shouldn't have to bet the farm on this. The compromise can take various forms.


    So what is the issue? The question concerns technical issues of the Hailstorm protocol. It is not just about who is in control.


    In other words, let us take the "white paper" approach. Can MS do that? One that allows us to review and alllow the security experts to scrutinize the technical details and design of the whole setup? If MS can take this step, then I should like to say that would remove most of the security concerns of Hailstorm.


    And for that debate, I would like to ask the first question. What is the point of Hailstorm? How is Hailstorm different from say, the Mozilla Personal Security Manager, wherein, the user stores his data on his computer, and has simplified but yet customizable controls as to who receives what data?


    Secondly, isn't aggregating these data a security flaw itself? Remember that security is not one issue itself, but encompasses issues of authentication, identity, integrity and all that. Given this setup, itn't the chance of idenity theft greater? Part of the security of setup we have is that no one single company knows everything about an arbitrary person. They may know your credit card n umber and hence your financial records, but they may not know your hair color. Meanwhile, some government agency may have your bloodtype, but they don't have your financial information. Isn't Passport a step in the wrong direction, in such a case?

  13. Hailstorm looks cool, wish I had more data by sachachua · · Score: 2
    Hailstorm admittedly looks cool. The Microsoft press room has a couple of articles and press releases. I'd love to have a really nice web-based calendar/whatever else...

    But if Microsoft is going to charge for the service, how does that work?

  14. It's not who YOU trust... by Bilbo · · Score: 2
    The question is not, who do you trust, but who do other people trust.

    The whole point of a central repository for this sort of information is for the benefit the the site you are trying to access, so that they can verify from some trusted source that you are who you say you are. Anyone can set up their own repository and say that they are someone else. However, if the site can go to some trusted source (either Microsoft, or a large bank, or whatever), then they can be certain that you are who they think you are, and have permission to use credit card numbers or access confidential information or perform transactions, etc...

    The benefit to the customer is not trust, but the "convenience" of a single login, and not having to remember a fistful of different username/password pairs for all the sites they deal with.

    --
    Your Servant, B. Baggins
  15. Goatse.cx warning for above "news" link by Bilbo · · Score: 2

    ugh...

    --
    Your Servant, B. Baggins
  16. Sez!? by Mike+Connell · · Score: 3, Insightful

    Is it really necessary to use words like "Sez" in the story title?

    It's "News for Nerds", not "Newz 4 Nurdz"

  17. This changes nothing by BroadbandBradley · · Score: 2

    Microsoft has yet to sign any of the major players to join its trust federation

    in some form or another, MS will decide who gets to run .net services and who doesn't. This BS about " These two changes--which Microsoft says aren't changes at all, but rather a clarification of what the company planned to do all along" is utter crap. Had this been what they've been planning all along, they would've made this "clarification" a long time ago. I'm going to bet that you'd better buy a copy of Win2K to run services and pay dearly for it!!! MS should be stopped, really stopped. They OWN our government, and are doing everything they can to confuse issues and LOOK like they're playing nice.
    just format your drive now and install Linux, you'l be glad you did. Don't give those MS MF'ers a cent of your cash.
    I wouldn't put the terrorist attacks past MS as a way to downplay the ongoing monopoly proceedings.

  18. This news is not any good by Captain_Frisk · · Score: 2

    If the same information is stored in several different servers, doesn't that just provide more points of failure?

    It seems to me that either everyone should either keep their information independently (the current system), which results in data replication, not to mention countless points of failure...
    or...
    Have one person keep this information... but it seems like that isn't such a popular thing here.

    Captain_Frisk

  19. This changes nothing by rabtech · · Score: 2

    This changes nothing in regards to Hailstorm. It only changes some people's incorrect perceptions of it. Hailstorm, and the entire .NET framework itself, is extensible by any third party, and always has been. It is simply unfortunate that people are so reactionary whenever Microsoft proposes anything.

    If you want to provide authentication via non-Microsoft means, write a .NET plugin for hailstorm using the documented interface, and then the system will use your authentication method rather than some other (like Passport).

    I just want to emphasise that this is only surprise news for those who failed to take the time to understand Hailstorm and .NET previously.

    --
    Natural != (nontoxic || beneficial)
  20. Mod parent up. by tshak · · Score: 2

    Good question. I think that MS should release a PR to developers regarding the planned Kerberos implementation, since in the past "open Kerberos" ment open to all who used their implementation of it!

    --

    There is no longer anything that can be done with computers that is nontrivial and clearly legal. -- Paul Phillips
  21. Re:Microsoft Security by alen · · Score: 2, Insightful

    Actually I meant that they will be paid every time a transaction is performed. Kind of like the royalties they get with some online photo processing operations.I'm not very good at proofreading.

    The challenge for Microsoft is to find a recurring revenue stream. Jack Welch says don't let anyone get between you and your customers. Bill Gates listened, and others didn't. They are letting Microsoft get between them and their customers.

  22. Re:how typical by BroadbandBradley · · Score: 2

    I really believe that MS is that EVIL. nothing to do with Linux, and the attacks are a terrible tragedy. I really feel for all of those affected.
    Let me ask you this, if you had 100 BILLION DOLLARS in your PERSONAL bank account, wouldn't you retire or at least dedicate your time to doing good for those around you? Good old Bill just wants another 100 Billion Dollars. If greed on that level isn't evil, I don't know what is.

  23. Re:I am Scared by rebelcool · · Score: 2
    I assure you, a great deal (if not most) of your banking data is stored in MS-sql databases.

    I write software for a financial services company, we do most of our work with MS-sql because thats what most banks use.

    --

    -

  24. Pardon my Cynicism by 4of12 · · Score: 2

    "In an interview late yesterday, an executive working on the project said the company is open to an industry group--such as those already controlling Kerberos and other Internet technologies--taking the lead role if it becomes necessary. ."

    But I suspect that as events unfold it will be found that an impartial central authority will hold us back from getting the full user experience of MS Innovation.

    Certainly it has been the case that standard Kerberos was found "insufficient" for Active Directory and required "improvement".

    Don't get me wrong. I'm not saying that standards are never in need of improvement. I'm just saying that I don't want the improved standard to be controlled by an entity with other interests. Interests that can conflict with the kind of impartiality and pure technical focus that such standards control deserves.

    --
    "Provided by the management for your protection."
  25. Re:Perfect Terrorist Target by mach-5 · · Score: 2

    No big deal...just a big inconvenience for all the users of the service, although I'm sure the system will be highly redundant with such large volumes of data at risk.

    Now a terrorist hacker...that's a different story.

  26. Benefits of running a private server? by mcc · · Score: 2

    (Warning: if the following post turns out to be nonsense, please forgive me.)

    Let's say that 2002 comes, and hailstorm becomes something that has a point (beyond ensuring Microsoft gets to have SOMETHING installed by default in WinXP that they can charge a monthly fee for and that the average user won't be able to figure out how to turn off), and GNUStorm 0.6 or whatever gets written, and i install it on my Mac OS X box in my dorm and register my dormroom computer as my authentication authority.

    How much flexibility will this hypothetical GNUStorm server have? Is the hailstorm protocol such that if i was running an authentication server, i could flexibly determine exactly what information and when that a given site is given about me? In what way? Oh, hell, is there ANY POINT AT ALL to hailstorm besides not having to type in your personal information/preferred password to every website, and making sure you don't make up 90% of the information you put on webforms? Is there ANYTHING hailstorm does that a web browser with a good autocomplete feature doesn't do?

    And if i *could* limit who gets what information, would there be any point, since the sites will all be using the same backhanded information-sharing tactics they use now? If i use hailstorm once to sign onto MSN messenger, and i decide not to let microsoft.com's hailstorm server have any information besides the username and password they use to authenticate, couldn't they just contact some site that they partially own and that shipped me something once, say "hey, what do you have on this username", and get a full readout of my name, address, etc..? Umm.. i'm pretty sure that that last sentence doesn't make a whole lot of sense, but you get what i mean.. right?

    If i am misunderstanding what Hailstorm is, i apologize, and request that someone more informed can set me straight. You'll have to excuse me, Microsoft seems to be working very hard to make sure everyone is as misinformed as they could possibly be as to the nature of .NET..

  27. Re:how typical by tshak · · Score: 2

    Score: -1 Flamebait

    Money isn't everything. If I had $100 billion, I would still program. Heck, I'd probably program more because I could afford the resources to start my own company and code what I want to code.

    --

    There is no longer anything that can be done with computers that is nontrivial and clearly legal. -- Paul Phillips
  28. Re:I am Scared by tshak · · Score: 2

    I know. And now that Great Plains has been purchased by MS, most medium to larger sized businesses will be running their ledgers and payroll from MSSQL and MS software. But, hey, why look at the facts?

    --

    There is no longer anything that can be done with computers that is nontrivial and clearly legal. -- Paul Phillips
  29. Re:I can't believe they mentioned Kerberos. by Salsaman · · Score: 2

    Yes and remember they even tried to sue /. because somebody posted their *copyrighted* amendments here...

  30. Re:Microsoft lied in the court of law. by Salsaman · · Score: 2

    Not only did they lie, they also falsified evidence.

  31. Re:how typical by BroadbandBradley · · Score: 2

    sure you'd still code out of the love of coding, but would your code be intent on locking people in to using ONLY YOUR code?