Slashdot Mirror


EPIC Urges State AGs to Pursue Microsoft Passport

An anonymous submitter sent: "The Electronic Privacy Information Center has sent a letter to all state attorneys general urging them to pursue Microsoft Passport under state consumer protection laws."

6 of 244 comments (clear)

  1. Re:Customer's Information by gazbo · · Score: 4, Insightful

    The real problem here is not that Passport is evil, but that they do not trust Microsoft to be the sole Passport providers, and to not do 'unreasonable' things with the data that they could potentially collect.

    I recently went to a seminar with MS's senior systems architect (UK) talking about Passport (mainly .net though). He first said that the Passport protocol should be implementable by any provider who wants to provide this service, so it need not be Microsoft authenticating details.

    Even if you do not believe this, he made an excellent demonstration of the problems of trust. A member of the audience (anti MS - he was heckling throughout the seminar) raised a similar concern. I paraphrase the conversation here:

    Man: 'I don't trust MS's servers to keep my data safe and not abuse it'

    MS: 'Well, whose servers do you trust'

    Man: [thinks] 'Mine'

    MS: 'Everybody raise their hands if you trust your data on this man's server'

    I thought it was a nice example anyway.

  2. Tried this at the National level.... by Em+Emalb · · Score: 4, Insightful

    "We have repeatedly urged the Federal Trade Commission to investigate this matter in two separate filings, but the Commission has failed to act. We therefore urge you now to initiate an investigation under your statutory authority."

    Ok, so what they are saying is, the FCC didn't care, so we are going to attack at a lower level. While I admire their determination/wish them luck, how much will this knowledge that the FCC didn't do anything affect them? Food for thought this AM....

    --
    Sent from your iPad.
  3. Opt-In vs Opt-Out vs Passport. by Alien54 · · Score: 4, Insightful
    Much of the law seems to be based on the idea of protecting people by making things "Opt-in". An extreme practical example is that, for example, youdo not have to "opt-out" of one of any number of criminal assaults for every single person that you meet coming down the road. It is assumed the you do not want to be assaulted unless you specifically "opt-in" such as in certain sexual activities.

    This is easy enough to see in the case of spammers and mailing list types who want to assume that you want to get their junk unless you "opt-out". With thousands of advertisers, this quickly becomes unworkable.

    Now we come to MS and Passport. With the fact of Monopoly, it is possible to enforce the sale and or acceptance of other "products" because they are "part of the whole package" I beleive that in certain states, for Certain industries, you cannot enforce the sale of product number 2 as a prerequisite to purchasing product numbr one. This varies by the product. Of course, you can always say "included free" but some things that are free are not worth the price.

    In the case of a monopoly, you can enforce the acceptance of items which would not otherwise be desired, and which may be a mixed blessing to the consumer at best. I am extraorinarily wary of Paspport and the all in one wonderful world of Microsoft Productivity that it promises for people.

    Stepford Nation, indeed.

    --
    "It is a greater offense to steal men's labor, than their clothes"
  4. Privacy for dummies. Chapter 1. by Unfallen · · Score: 5, Insightful
    I have been on the receiving end of Microsoft's "Security Policy" in the past, finding myself (accidentally or deliberately, I have no idea) subscribed to several salubrious MSN forums. After several months and few non-automated replies, I finally topped receiving the e-mails, but with neither explanation of why I got them, who had done it, nor even an acknowledgement or an apology.


    Let us now put this into the context of the passport scheme - the EPIC letter states "Microsoft has indicated that the company's goal is to have every Internet user possess a Passport account", which I deem a fair summary of the situation (although, ideally, everybody would also use a Hotmail account too). Trundle along to, say, http://www.passport.com and look! See how you can sign up with ease! Get it now! Calooh! Callay!


    Now let us try to pull the same trick that was pulled on me, and that I have fortunately not seen on any well-organised mailing list outside of Redmond. Enter an e-mail address, any e-mail address (excepting MS-specific ones such as Hotmail) - even make one up that obviosuly doesn't exist, and then... Carry On! Yes! There's still no security! At least, I guess, an e-mail gets sent to the e-mail address asking you to verify it, but this seems to be purely for service embellishment:


    Please take a moment to help us verify your e-mail address. This ensures that .NET Passport can respond to you if you contact us about a service issue. In addition, some participating .NET Passport sites may require you to verify your e-mail address to take full advantage of their own services.

    Using the new obviously-fake account, I can save settings, edit my MSN etc etc much as I may or may not want to. That is not the issue. What we have here is clearly a case of theft of privacy - without even trying, anyone is able to sign up anybody else's e-mail account for a passport. Who knows what havoc this could/will cause! Not being particularly au fait with MSN, I have only circumspection, but Microsoft have an epic journey to go before they reach "Trustworthy Computing [tm]" if they fail to understand the basics of privacy and intrusion, as highlighted here.


    To conclude, I say get out there, fight it from the other end - the end that consumers will understand. Sign up as many fake and real accounts as you like to demonstrate just how fallible the system is. I'm off to see if they prevent scripting...

  5. Against the law nonetheless.. by aphor · · Score: 5, Insightful

    Regardless of whether Microsoft has been proven to abuse the power, there are laws which make it illegal to posess the ability to abuse the power. The idea comes from a legal term: "conflict of interest."

    When a person offers a service to another person in the financial/legal/medical world they are acting as an agent on behalf of the customer. Legally, that arragement has an implied "fiduciary responsibility" to the customer. That means if someone gives you the key to their account and you do something they wouldn't have agreed to, you are wrong and subject to criminal and civil liability. In the case of finances, there are EXTRA laws that say you are not even allowed to ofer such services to people if you have an interest in ripping them off (like other competing customers).

    Bill Gates comes from a long line of lawyers: his family is a lawyer family. He knows he can flout the law wherever there is grey area because he has the money to risk. If he manages to win some small legal challenge, he has stretched the law to allow more exploitation and the windfall revenue that goes with.

    When you (the US) have a big dog, you put a pinch (or shock) collar on him, and you jerk it hard (or shock him) when he *starts* to get out of line. You can let up a little, but only when he has a compelling fear of disproportionate retribution. Corporations are less like people who deserve rights, and more like dangerous, powerful animals that must be attended to with preemptive stewardship. Emotions, values, and ethics are not present in the brains of reptiles or boardrooms.

    --
    --- Nothing clever here: move along now...
  6. Re:Oh, Come On! by Diabolical · · Score: 5, Insightful

    The reason why no-one is going after AOL/TimeWarner is because they don't own 90+% of the desktop which they could use to leverage their other products.. this is all about not having a choice.. MSN is tightly integrated in XP. The browser is prominently on the desktop as is the MSN messenger software. Opening Outlook Express starts a signup session with Hotmail, etc. etc. etc... Creating a Passport account is almost done automatically if you do not know better then to use what MS prescribes.

    Now, í'm not a MS basher in the way most people do.. i am however VERY concerned about their growing stranglehold on consumer choice. Ever so slightly people are lured into a total MS dominance...

    Ah well.. i'll keep on dreaming of the old days...