Feeds

Microsoft signs up VeriSign to secure .NET

And HailStorm hits Network Solutions domain reg business

  • alert
  • submit to reddit

Protecting users from Firesheep and other Sidejacking attacks with SSL

VeriSign is to provide authentication and security technologies within future .NET offerings. And in return VeriSign will use Microsoft's HailStorm suite of fee-based services throughout its business.

The deal means that HailStorm, which has been criticised by privacy and security experts, will find its way into VeriSign's Network Solutions domain registration operation, which will be moved onto Windows 2000 servers along with the rest of VeriSign's business.

HailStorm, which is currently in development, is designed to enable users to access their personal information from any location and any device through the use single sign-on and authentication system based on Microsoft's Passport.

The companies will work together to integrate VeriSign's Personal Trust Agent technology, which provides users with a tool to manage their digital credentials and preferences, as part of Microsoft's Passport authentication, single sign-in and secure messaging capabilities.

Microsoft's agreement with VeriSign is designed to give confidence to users that Web-based services on online transactions can be made secure, however doubts over Redmond's patchy security record mean Microsoft will need to do a great deal to convince the market on this.

Let's not forget that in March Microsoft had to admit that VeriSign issued two certificates in its name to a scam artist posing as a Microsoft employee. The certificates were of the sort used to digitally sign programs and the group who obtained the certificates might use them to trick users into running malicious code, signing Trojan horses and viruses with Microsoft's name.

That, and Microsoft's failure to keep the digital certificate on one of its own ecommerce sites up to date hardly inspires confidence. And that's before we even get to consider the fear that the deal may be a key part in a plan by Microsoft to extend its dominance of the desktop into the Internet market.

On the positive side the deal does imply that Microsoft is beginning to recognise that security is a factor that might affect the uptake of its technology, and not something that should be easily traded off against making products easier to use. If improving security becomes linked in the minds of senior execs in Redmond to increased sales we might actually end up with more secure products. ®

External Links

Microsoft and VeriSign Announce .NET Alliance

Related Stories

Microsoft fails to renew its digital certificate
Microsoft vexed by falsified certs
UK govt new encryption system only works with MS kit
Investors mis-interpret McAfee/MS .NET deal
MS proprietary tech undermines HailStorm - analyst
Pay-to-Play: Microsoft erects .NET tollgate

The next step in data security

More from The Register

next story
Israeli spies rebel over mass-snooping on innocent Palestinians
'Disciplinary treatment will be sharp and clear' vow spy-chiefs
Infosec geniuses hack a Canon PRINTER and install DOOM
Internet of Stuff securo-cockups strike yet again
THREE QUARTERS of Android mobes open to web page spy bug
Metasploit module gobbles KitKat SOP slop
'Speargun' program is fantasy, says cable operator
We just might notice if you cut our cables
Apple Pay is a tidy payday for Apple with 0.15% cut, sources say
Cupertino slurps 15 cents from every $100 purchase
YouTube, Amazon and Yahoo! caught in malvertising mess
Cisco says 'Kyle and Stan' attack is spreading through compromised ad networks
Hackers pop Brazil newspaper to root home routers
Step One: try default passwords. Step Two: Repeat Step One until success
Greater dev access to iOS 8 will put us AT RISK from HACKERS
Knocking holes in Apple's walled garden could backfire, says securo-chap
prev story

Whitepapers

Providing a secure and efficient Helpdesk
A single remote control platform for user support is be key to providing an efficient helpdesk. Retain full control over the way in which screen and keystroke data is transmitted.
Saudi Petroleum chooses Tegile storage solution
A storage solution that addresses company growth and performance for business-critical applications of caseware archive and search along with other key operational systems.
Security and trust: The backbone of doing business over the internet
Explores the current state of website security and the contributions Symantec is making to help organizations protect critical data and build trust with customers.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.
Security for virtualized datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.