X-Git-Url: http://wien.tomnetworks.com/gitweb/?a=blobdiff_plain;f=web%2Fpassport;h=3ffe0dfeef9edee06ab45146c1fc072446991f93;hb=d7ab125adb3c7cc5f1b5a7855c497db6649b6143;hp=ec7a11c91f9b039687349958ed5460420eef9680;hpb=1a1cef73cd183d0fd03026914ff1af2739f8568d;p=mono.git
diff --git a/web/passport b/web/passport
index ec7a11c91f9..3ffe0dfeef9 100644
--- a/web/passport
+++ b/web/passport
@@ -1,5 +1,17 @@
* Updates
+ Sep 20, 2001: Microsoft has just announced some changes
+ to passport that are rather interesting. This document
+ reflects the Passport system without taking into account the
+ new changes.
+
+ Read about it here.
+
+ For an analysis of security problems with passport, check http://avirubin.com/passport.html.
+ The bottom line is that you should not put any sensitive
+ information on passport.
+
I have received many comments from people, and I have updated
the page accordingly. From removing incorrect statements, to
fixing typos, to include mentions to other software pieces.
@@ -88,6 +100,11 @@
available, means that trojans or worms could be built
into the products by malicious engineers.
+ Various government officials in non-US countries also
+ have a policy that no state sensitive information can
+ be held by foreign companies in foreign soil. A natural
+ matter of national security to some.
+
* Security: With a centralized system like
Passport, imagine the repercussions of a malicious
hacker gaining access to the Passport database.
@@ -244,7 +261,7 @@
A few people have said: `Mono will allow Passport to be
available for Linux and that is bad'. This is plain
- missinformation.
+ misinformation.
Currently, you can obtain Passport for Linux from Microsoft
itself and deploy it today on your Web server. Mono does not
@@ -264,7 +281,12 @@
Nat Friedman (Ximian's co-founder) has his own ideas on how a
competing system to Passport could be designed, but I will let
- him post his own story.
+ him post his own story.
+
+** Other Passport Comments
+
+ An interesting study on the security of passport is available at: http://avirubin.com/passport.html
** Other Alternatives