main
Report a problem

Microsoft works to fix MSN privacy flaw

Steven Parker   on 08 February 2002 - 22:46 · no comments & 445 views

Advertisement (Why?)
Thanks neo1980 for posting this in our Back page News on the forums.
Microsoft is putting the final touches on a patch to limit an MSN Messenger feature that allowed any Web site to grab a visitor's IM nickname and buddy list.

While representatives for the Microsoft Network have said no customers have fallen prey to the potential privacy problem, the group plans to release early next week an updated version of MSN Messenger that fixes the problem.

"In order to implement the fix, customers will have to upgrade to the next version of MSN messenger," a representative for the software behemoth said on Friday.

The issue occurs because Microsoft designed MSN Messenger to allow JavaScript contained in Web pages to access a customer's buddy list and, for certain Microsoft sites, the e-mail addresses of the person.

Software engineer Richard Burton highlighted the privacy implications of the feature in a post to SecurityFocus' BugTraq mailing list recently.

"It appears to have been intended as a feature so they could put in nice customizations on their Web sites," said the U.K.-based programmer on Friday. "I only raised it as a potential, so I don't think people need to panic."

The ill-conceived feature comes at a poor time for the software giant. Last month, Chairman Bill Gates wrote a companywide memo spurring employees to make security and privacy their top priorities.

News source: C|Net News.com

Post a comment · Send to friend Comments · There are no additional comments

Commenting has either been disabled on this article or you are not logged in. Click here to login or register, its free!

Note: Anonymous commenting is disabled in order to keep the quality of responses to a high standard.

Advertisement (Why?)