You are here: silicon.com > Software > Security Strategy

Security Strategy

A yolk too far: Microsoft does Egg's security

Out of the frying pan into fire?

By Joey Gardiner

Published: 31 October 2001 16:25 GMT

Online bank Egg is to use Microsoft's controversial Passport authentication software to give users access to their accounts, despite widespread concern that Microsoft's security technology isn't up to the job.

Egg CIO Dana Cuffe will move over to the web-based system when a full assessment is completed, and currently has no timeframe for the move.

Analysts immediately criticised the move and claimed the system isn't good enough for banking.

Jose Lopez, research analyst for Frost and Sullivan's security division, said: "Passport is not good enough - not at all - for the purposes of online banking. Any other bank will tell you the same thing."

He cited past security problems and added: "I think many Egg customers would leave if Microsoft did its authentication."

Ian Brown, security expert and researcher at UCL, said he would not be comfortable banking at Egg if it moved to the Microsoft platform for authentication. "I would certainly think twice about my Egg account," he said.

Egg is an early adopter of Microsoft's new operating system, Windows XP, and a firm supporter of its .NET strategy, but thus far it has used Entrust technology to authenticate its customers online.

Cuffe said he planned to replace Entrust's GetAccess product with the Passport system.

He told silicon.com: "At first we will use Passport alongside GetAccess but the aim is to replace it entirely. At the moment we're still to assess and validate the system, but the assumption is that it will be rolled out."

The news is a boost to Microsoft, which has faced stern criticism in recent months for the poor security of its products as well as increasing concerns about the ramifications of Passport on user privacy and security.

Bill Malik, VP at Gartner Group, said: "This is a real coup for Microsoft. To persuade someone with the heavy fiduciary responsibilities of a bank that Passport is adequate."

Passport is the authentication system Microsoft currently uses to identify Hotmail users, but will ultimately be the way in to a wide range of .NET services, theoretically allowing a user to sign in just once for multiple services.

Passport has faced criticism both because of the nature of its design gives hackers just one entry point to a wide range of valuable information, but also because many suspect Microsoft particularly is ill-equipped to deliver such a service, given its poor record on computer security.

Microsoft was unable to provide a spokesperson to comment on the story.

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

Nick Heath Your top HR tech priorities for next year revealed How to make human resources IT work for you

Bob Tarzey Why you must rein in your power users When they do damage, it can be catastrophic to your business


  • Jobs
GPS/ RF/ Technician/ repair

A Production Technician is required with the following skills: Applicants need to have a UK/EU passport ONC/HNC in electronics or equivalent ...

New Business Senior Sales Manager-Offshore Services Sales

JOB TITLE: New Business Senior Sales Manager-Offshore Services Sales SELLING: Offshore Services SELLING TO: Telco TERRITORY: UK - Nordics - Benelux ...

Test Systems Engineer (Passive)

Assemble validate basic test systems Provide technical support to project/design engineers Education/Qualifications Essential: BTEC HNC/Degree in ...

Agenda Setters 2009
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.





Quick Sitemap Links: