<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.msdn.com/utility/FeedStylesheets/atom.xsl" media="screen"?><feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en"><title type="html">Steve's Identity Corner </title><subtitle type="html" /><id>http://blogs.msdn.com/stwood/atom.xml</id><link rel="alternate" type="text/html" href="http://blogs.msdn.com/stwood/default.aspx" /><link rel="self" type="application/atom+xml" href="http://blogs.msdn.com/stwood/atom.xml" /><generator uri="http://communityserver.org" version="2.1.61025.2">Community Server</generator><updated>2006-06-16T20:14:00Z</updated><entry><title>Gone Phishing !</title><link rel="alternate" type="text/html" href="http://blogs.msdn.com/stwood/archive/2006/06/17/634774.aspx" /><id>http://blogs.msdn.com/stwood/archive/2006/06/17/634774.aspx</id><published>2006-06-17T02:53:00Z</published><updated>2006-06-17T02:53:00Z</updated><content type="html">&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;FONT face=Calibri&gt;Over the last few years we have all experienced the constant barrage of Phishing attacks. These are not only a pain for all of us as end users, as we carefully pick through our email trying to figure out what’s real and what isn’t, but also an unending headache for those trying to run the commercial web sites we link to. &lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&lt;/SPAN&gt;So let’s take a step back for a moment &lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&lt;/SPAN&gt;to look at how these attacks are possible, after all we’re smart people we shouldn’t be fooled that easily …. &lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;FONT face=Calibri&gt;There are three distinct steps to any Phishing attack for the sake of making this simple let’s just call them &lt;I style="mso-bidi-font-style: normal"&gt;Casting the Bait&lt;/I&gt;, &lt;I style="mso-bidi-font-style: normal"&gt;Reeling in the Catch&lt;/I&gt; and &lt;I style="mso-bidi-font-style: normal"&gt;Stealing the Prize&lt;/I&gt;. &lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;FONT face=Calibri&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;&lt;I style="mso-bidi-font-style: normal"&gt;Casting the Bait&lt;/I&gt;&lt;/B&gt; – since the initial goal of the phisher is to get you to go to their web site the first thing to do is to deliver you a URL in an email message. This email has to convince you that not only is it from a real company but that you should take the additional action of clicking on the link it contains. We’ve all seen the “there has been a change in your account details and we need you to verify them” email, complete with nice graphics and company logo’s from a familiar company. The first few times we see these we naively &lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&lt;/SPAN&gt;click on the link and off we go to who knows where to try and verify our account details. Of course given the amount of spam we all receive it’s not surprising that at times it’s hard for us to tell the good mail from the bad. In recent years many efforts have been made to reduce the amount of spam and as the junk mail filters have become more sophisticated we are weeding out a lot more than we used to, but there is still more work to be done.&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;FONT face=Calibri&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;&lt;I style="mso-bidi-font-style: normal"&gt;Reeling in the Catch&lt;/I&gt;&lt;/B&gt; – have you ever thought about how easy it is to fake a web site, think about that for a moment if I go up to any webtsite today I bet I can copy half their logo’s and art work straight off of their home page. In no time at all a half decent web designer could mock up a site that is close enough to the real thing to fool 90% of the people who saw it. In fact that’s what &lt;/FONT&gt;&lt;A href="http://www.deas.harvard.edu/~rachna/papers/why_phishing_works.pdf"&gt;&lt;FONT color=#800080&gt;&lt;FONT face=Calibri&gt;Researchers at &lt;/FONT&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Verdana','sans-serif'"&gt;&lt;FONT size=3&gt;Harvard University and UC Berkeley&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=3&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Verdana','sans-serif'"&gt; &lt;/SPAN&gt;&lt;FONT face=Calibri&gt;did in order to do some research on Phishing. Now compare that with how hard it is to fake a real brick and mortar business, say a bank or a book store. One of the reasons so many people get phished is because it is very hard for most users to tell the difference between a fake site and the real site. In fact many users today have no idea what any of the so called security measure’s we have in place today even mean. Ask some of your non-technical friends to explain what an SSL certificate is and how they can tell when a site has one. Now ask them how they know that’s a real cert and not one that was issued to a spurious company in Nigeria. On the whole we as an industry have come up pretty short in terms of protecting our users from going to sites that they can’t identify.&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;FONT face=Calibri&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;&lt;I style="mso-bidi-font-style: normal"&gt;Stealing the Prize&lt;/I&gt;&lt;/B&gt; – in many cases the prize is your username and password. Firstly this is because the Phisher can now get access to the site that they faked, secondly the chances are you also use that username and password other places, and they are going to go after those too. But wait I hear you cry, I have several password that I use on different sites depending on the value associated with an account. So imagine this, you get tricked into going to a fake site, it asks you for your username and password, you type them in and “User Authentication Failed, please try again”. So you think to yourself maybe I used one of my other username and password pairs, so you try again, failed. Eventually you think maybe I just typed the password wrong the first time! So you re-enter it and the site lets you in (and redirects you to the real site), now the Phishing site not only has the username and password for the site they faked, but chances are they also stole the other 4 combinations you use. And yes this happened to someone I know, oops. So username and passwords aren’t solving the problem today of how we get users to authenticate to our sites. And we need to keep it simple enough that all users from the technically savvy to novice users can just as easily and securely authenticate, without the need for username and password.&lt;/FONT&gt;&lt;/P&gt;&lt;SPAN style="FONT-SIZE: 11pt; FONT-FAMILY: 'Calibri','sans-serif'; mso-ascii-theme-font: minor-latin; mso-fareast-font-family: Calibri; mso-fareast-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: 'Times New Roman'; mso-bidi-theme-font: minor-bidi; mso-fareast-language: EN-US; mso-ansi-language: EN-US; mso-bidi-language: AR-SA"&gt;&lt;FONT size=3&gt;So as you can see the method of attack is pretty straight forward and if wasn’t for the fact that we prefer to operate on the right side of the law, I’m sure we could all make a pretty decent living doing it. One of the big challenges for us as an industry is that it covers multiple technologies email clients, browsers, SSL certificates and user authentication systems, all of which may be provided by different vendors, any one of which doesn’t feel like they can solve the problem. Over the next few weeks I’m going to cover each of these topics and explain the work that we are doing here at Microsoft to address &lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&lt;/SPAN&gt;these issues and in addition other industry wide efforts I come across. I’m not saying that we can stop these attacks completely but by changing the rules a little we can at least start to fight back. Lets face it we are dealing with some pretty sophisticated criminals intent on stealing from all of us if they can, we just have to make it a lot harder for them to do their job.&lt;/FONT&gt;&lt;/SPAN&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=634774" width="1" height="1"&gt;</content><author><name>stwood</name><uri>http://blogs.msdn.com/members/stwood.aspx</uri></author></entry><entry><title>To Blog or not to Blog that was the question!</title><link rel="alternate" type="text/html" href="http://blogs.msdn.com/stwood/archive/2006/06/16/634439.aspx" /><id>http://blogs.msdn.com/stwood/archive/2006/06/16/634439.aspx</id><published>2006-06-16T22:14:00Z</published><updated>2006-06-16T22:14:00Z</updated><content type="html">&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;FONT face=Calibri&gt;Well for the longest time I have resisted the temptation to leap into the blogging arena, but no more, the question is answered. My name is Steven Woodward and I am a Technical Evangelist in the Windows Server evangelism team here in Redmond. Within the team I am one of the evangelists who covers Identity and Access Management (the others being &lt;/FONT&gt;&lt;A href="http://blogs.msdn.com/vbertocci/"&gt;&lt;FONT face=Calibri color=#ffa500&gt;Vittorio Bertocci&lt;/FONT&gt;&lt;/A&gt;&lt;FONT face=Calibri&gt;, &lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&lt;/SPAN&gt;Donovan Follette and &lt;/FONT&gt;&lt;A href="http://blogs.msdn.com/nigelwa/"&gt;&lt;FONT face=Calibri color=#ffa500&gt;Nigel Watling&lt;/FONT&gt;&lt;/A&gt;&lt;FONT face=Calibri&gt;). For the last year I have been working on &lt;/FONT&gt;&lt;A href="http://msdn.microsoft.com/winfx/reference/infocard/default.aspx?pull=/library/en-us/dnwebsrv/html/identitymetasystem.asp"&gt;&lt;FONT face=Calibri color=#ffa500&gt;The Identity Metasystem&lt;/FONT&gt;&lt;/A&gt;&lt;FONT face=Calibri&gt;&lt;FONT color=#ffa500&gt; &lt;/FONT&gt;and &lt;/FONT&gt;&lt;A href="http://channel9.msdn.com/showpost.aspx?postid=181080"&gt;&lt;FONT face=Calibri color=#ffa500&gt;InfoCard&lt;/FONT&gt;&lt;/A&gt;&lt;FONT face=Calibri&gt;&lt;FONT color=#ffa500&gt; &lt;/FONT&gt;now called Windows CardSpace™ (which keeps the marketing folks happy but I’m just going to call it CardSpace), during which time I have presented to and met with many in the industry to discuss our vision for how to improve user authentication and identification. During that time I have also had the honor to work with &lt;/FONT&gt;&lt;A href="http://www.identityblog.com/"&gt;&lt;FONT face=Calibri color=#ffa500&gt;Kim Cameron&lt;/FONT&gt;&lt;/A&gt;&lt;FONT face=Calibri&gt;, the man behind the vision, whose desire for openness and inclusion with respect to the Identity Metasystem has&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;driven much of the industry momentum we see now.&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;FONT face=Calibri&gt;I’ve learned a lot over the last year about how people plan to use this technology, other projects that are being worked on in parallel both within Microsoft and in the rest of the industry, and I’m going to use this as the place to share my thoughts and get feedback from you on where we are heading.&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;FONT face=Calibri&gt;For those not familiar with The Identity Metasystem or CardSpace here are two simple explanations of what they are and how they relate. &lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;FONT face=Calibri&gt;&lt;I style="mso-bidi-font-style: normal"&gt;The Identity Metasystem&lt;/I&gt; is a mechanism for using a subset of the WS-* protocols to publish the security policy of a web site or service, exchange this information with a user and retrieve security credentials that match those policies from an identity provider. &lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;FONT face=Calibri&gt;&lt;I style="mso-bidi-font-style: normal"&gt;CardSpace&lt;/I&gt; is the Windows client component of the Identity Metasystem which presents those security credentials to the user in a friendly, easy to understand user interface, aka an Identity Selector.&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;FONT face=Calibri&gt;Since all of the WS-* protocols are released publicly there are many other initiatives, other than Microsoft’s, working on to develop interoperable solutions, there are also other initiatives to develop Identity Selector’s for other platforms, look for more on these in the coming weeks.&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;FONT face=Calibri&gt;You can find out even more information by going over to our newly created &lt;/FONT&gt;&lt;A href="http://www.netfx3.com/"&gt;&lt;FONT face=Calibri color=#ffa500&gt;community site&lt;/FONT&gt;&lt;/A&gt;&lt;FONT face=Calibri&gt;&lt;FONT color=#ffa500&gt; &lt;/FONT&gt;that covers all of the NetFX 3.0 technologies (WCF, WF, WPF and CardSpace). &lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&lt;/SPAN&gt;There you will find links to whitepapers, samples and guides&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;on how to get started.&lt;/FONT&gt;&lt;/P&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=634439" width="1" height="1"&gt;</content><author><name>stwood</name><uri>http://blogs.msdn.com/members/stwood.aspx</uri></author></entry></feed>