Microsoft accused of Kerberos hijack

Microsoft's Windows 2000 implementation of open security standard Kerberos came under fire from software developers last week, after it emerged the software giant has undermined the standard with undocumented modifications.

James Middleton, Network News

Microsoft's Windows 2000 implementation of open security standard Kerberos came under fire from software developers last week, after it emerged the software giant has undermined the standard with undocumented modifications.

Open internet security standard Kerberos has been incorporated into Windows 2000 to prevent user passwords from being sent over a network, where they are vulnerable to sniffers. Controversy arose when it was discovered that in incorporating the standard, Microsoft had amended the Kerberos code to produce a version called Microsoft Kerberos.

Advertisement

But Ted Ts'o, who led the MIT development team that created Kerberos, said that Microsoft's revision of the security standard would pose serious back-end integration problems for e-businesses.

Ts'o labelled the product as a "proprietary version," and Paul Hill, current Kerberos team leader, said he objected to Microsoft participating in IETF's Kerberos working group and implementing changes before submitting them. "They are trying to create a de facto standard and make everyone comply with it. This process is not embrace-and-extend, but embrace-and-deform," said Hill.

Shanen Boettcher, Windows 2000 product manager, said Unix workstations and Windows 2000 desktops may log into a Unix Kerberos server. However, he admitted Windows 2000 desktops cannot lconnect and receive access to Windows 2000 resources. He claimed the software giant was only making use of a feature that already existed in the standard but had so far been left blank.

The data authorisation field on the Kerberos ticket is filled in by the server with access privileges, and ties the client to the Windows server.

But Boettcher admitted the change is not documented, and the contents of the field are unavailable. "We have been asked to document them, and we are trying to figure out what to do with that request," he said.

Ts'o explained that developers can't take advantage of the Microsoft changes and build them into products that work with Windows 2000. He said that if you want all the features of Windows 2000 clients, you have to use a Windows server. "No one else uses the data authorisation field this way. It's no longer an open standard," he said.

Kerberos is widely used for user identification on Unix systems. It avoids sending passwords over a network, where they may be sniffed, by sending encrypted messages from the user to a Kerberos security server. Once verification is established, an encrypted access ticket is issued to the client.

Microsoft's amended code connects client and server through a Microsoft-specific version of Kerberos.

  • Have your say
  • Send to a friend
  • Print
  • Digg
  • Reddit
  • Share

Tags:

Do you agree?

Further reading

Microsoft to use Kerberos for Passport

Analysts question software giant's motives

Gates' Passport goes open source

Passport compatability doubted by industry

Related whitepapers

Related jobs

Most watched

Social networking

Summit: How businesses should manage their brands online

In part one of V3.co.uk's interview with Dirk Singer, he dicusses social media monitoring strategies

RIM discusses new developer tools

Blackberry exec on the latest offerings for programmers

Analysis and Reports

Remote access - Three steps to getting connected

3.4 million UK professionals now work from home – is your company equipped?

Cost benefits of a global collaboration network

This white paper is a must read for organisations looking for evidence of the bottom-line benefits of high-definition video and voice communications

Poll

Impact of Information Overload poll

Impact of Information Overload poll

What is the biggest problem your firm faces as a result of the data explosion?

View poll results

Advertisement

White paper library

Keep up to date with the latest products, services and technologies from the world's leading IT companies; IThound.com brings you over 6,000 white papers, case studies and analyst reports.

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Spotlight

Alcatel-Lucent logo

Summit: Networks swamped by information overload

Alcatel-Lucent's Neal Tilley talks about how enterprises and carriers can...

EU flag

Breach notification laws get green light

Privacy rights strengthened in Europe

Richard Thomas

Summit: Richard Thomas advises on handling the data deluge

Former Information Commissioner speaks out on government databases and data...

oracle sun

War of words escalates between EU and Oracle

Commission comes out fighting after criticism from Oracle and Washington

Primary Navigation