R E L A T E D   C O N T E N T
ADVERTISEMENT

Microsoft accused of Kerberos hijack

Microsoft's Windows 2000 implementation of open security standard Kerberos came under fire from software developers last week, after it emerged the software giant has undermined the standard with undocumented modifications.

James Middleton, Network News, Network IT Week 15 Mar 2000
ADVERTISEMENT

Microsoft's Windows 2000 implementation of open security standard Kerberos came under fire from software developers last week, after it emerged the software giant has undermined the standard with undocumented modifications.

Open internet security standard Kerberos has been incorporated into Windows 2000 to prevent user passwords from being sent over a network, where they are vulnerable to sniffers. Controversy arose when it was discovered that in incorporating the standard, Microsoft had amended the Kerberos code to produce a version called Microsoft Kerberos.

But Ted Ts'o, who led the MIT development team that created Kerberos, said that Microsoft's revision of the security standard would pose serious back-end integration problems for e-businesses.

Ts'o labelled the product as a "proprietary version," and Paul Hill, current Kerberos team leader, said he objected to Microsoft participating in IETF's Kerberos working group and implementing changes before submitting them. "They are trying to create a de facto standard and make everyone comply with it. This process is not embrace-and-extend, but embrace-and-deform," said Hill.

Shanen Boettcher, Windows 2000 product manager, said Unix workstations and Windows 2000 desktops may log into a Unix Kerberos server. However, he admitted Windows 2000 desktops cannot lconnect and receive access to Windows 2000 resources. He claimed the software giant was only making use of a feature that already existed in the standard but had so far been left blank.

The data authorisation field on the Kerberos ticket is filled in by the server with access privileges, and ties the client to the Windows server.

But Boettcher admitted the change is not documented, and the contents of the field are unavailable. "We have been asked to document them, and we are trying to figure out what to do with that request," he said.

Ts'o explained that developers can't take advantage of the Microsoft changes and build them into products that work with Windows 2000. He said that if you want all the features of Windows 2000 clients, you have to use a Windows server. "No one else uses the data authorisation field this way. It's no longer an open standard," he said.

Kerberos is widely used for user identification on Unix systems. It avoids sending passwords over a network, where they may be sniffed, by sending encrypted messages from the user to a Kerberos security server. Once verification is established, an encrypted access ticket is issued to the client.

Microsoft's amended code connects client and server through a Microsoft-specific version of Kerberos.

See also:

Analysts question software giant's motives  02 Oct 2001
Passport compatability doubted by industry  20 Sep 2001

All Ecommerce

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
| Aston Carter
Java, J2EE, Developer, Spring, Hibernate, London, city, Graduate. This is an amazing opportunity to join a successful city based team working at the cutting edge of development. My client is looking for strong Java/J2EE developers ... more >
| Aston Carter
E-Commerce, Greenfield, Agile, Java, J2EE, , JavaScript, SQL, London, City Graduate This is an exceptional opportunity for a talented Java, J2EE developer keen to work in a successful development team within arguable the best agile ... more >
| Rullion Computer Personnel Ltd
2nd Line Support Analyst London £35, 000 to £40, 500 My client is a global market leader in the Internet Applications Industry. The company is continually progressing and looking for areas of growth and this ... more >
| Rullion Computer Personnel Ltd
Security Architect / Information Security Specialist – St Albans - Global Leader - Shine At The Highest Level Security Solution Architect / Information Security Architect required by renowned blue-chip organisation offering the finest security projects ... more >
More job opportunities