Computerworld
Quick Menu
Search



Ads by TechWords

See your link here


Subscribe to our e-mail newsletters
For more info on a specific newsletter, click the title. Details will be displayed in a new window.
Finance
Security
Computerworld Daily News (First Look and Wrap-Up)
Computerworld Blogs Newsletter
The Weekly Top 10
More E-Mail Newsletters 
Computerworld 2007Subscribe to Computerworld
40 years of the most authoritative source of news and information for IT leaders.

Update: FTC, Microsoft reach settlement on Passport probe

 

Sign up to receive Privacy Resource Alerts

August 8, 2002 (Computerworld) -- Microsoft Corp. will have to increase security and privacy for personal information collected by its Passport single sign-on Web services and be subject to independent compliance audits for Passport every two years under a settlement announced today by the U.S. Federal Trade Commission (FTC).
In a case that began last year when privacy groups raised concerns about inadequate security in several versions of Passport, the FTC today announced that Microsoft has agreed to stop misrepresenting the security of Passport and the kinds of personal information it collects about users.
"Privacy and security promises must be kept," said FTC Chairman Timothy Muris at a news conference in Washington announcing the settlement. "It's good business, it's the law, and we'll take action against companies that do not keep their promises."
Under the settlement, Microsoft has agreed to implement a comprehensive information security program for its Passport products, which include Passport, Passport Wallet and Kids Passport. The company will also have to undergo a compliance audit by a qualified third party every other year to ensure that the security and privacy of Passport are maintained.
No security breaches were uncovered by the FTC's investigation, but the potential for problems was present in the software, Muris said.
Specifically, the FTC said Microsoft misrepresented the security and privacy provided by parental controls in the version of Passport aimed at children, called Kids Passport. The controls apparently didn't allow parents to limit the personal information used or collected about their children, according to the FTC.
The agreement stipulates that Microsoft is prohibited from making any such misrepresentations in the future about the privacy and security controls related to Passport.
"When you make security promises as Microsoft did, they were in effect saying they had reasonable and effective security measures," Muris said. "We felt those promises were deceptive."
The company also apparently collected more user information than it said it was collecting, including a history log of Passport sites and the times when they were visited by users.
Although no fines were imposed as part of the settlement, the company would be subject to fines of $11,000 per violation, per day if it is found to violate the terms of the agreement.
Normally, administrative cases such as this don't carry fines, Muris said. But in this case, the potential for fines is included, Muris said.
"We got the relief that we wanted here," he said. "Certainly we want the world to be aware, when companies make these promises, they must keep them. We have other investigations under way."
The FTC didn't weigh in on the allegation that Passport was too closely tied into the Windows XP operating

Continued...
1 | 2 | NEXT  



Print this Story Send Us Feedback E-mail this Story Digg! Digg this Story Slashdot this Story
Mozilla updates Firefox 3.1 with Alpha 2 build
Microsoft explains Seinfeld-Windows TV ad: just a 'teaser'
Mozilla: Firefox is faster than Chrome
More top stories...
iPhone 3G owner sues Apple, AT&T over dropped calls, app crashes
At 10, Google reiterates commitment to CIOs
Analysts: Google spreading itself too thin
Users of Windows XP SP3 who try out IE8 Beta 2 won't be able to uninstall either one under certain circumstances.
Google has gone from innovative upstart to fat-and-happy industry leader in what seems like record time. Preston Gralla explains.
Microsoft's latest beta of IE8 includes better tab management, new services such as Web Slices and Accelerators, and the new 'porn mode.'
These leading-edge graduate schools are moving at the pace of the IT workplace, delivering coursework that's relevant to today's IT professionals.
Reviews, analyses, how-tos, visual tours, hot issues and predictions about Microsoft's new OS.
Four years from now, the IT field will be a vastly different place. Will you be ready?
All Zones
Application Performance Zone
Business Continuity Zone
The File Data Management Zone
Security Management Zone
ITIL Best Practices Zone
The SAS Zone
Business Intelligence and Analytics Zone
Windows Protection Zone
Identity & Security Management Zone

Ads by TechWords

See your link here
From Laggard to Leader: Transforming the Data Center
From Laggard to Leader: Transforming the Data Center
Register for this complimentary live webcast today!
Go to the webcast 
Learn-Fast Guide: Software as a Service is Growing Up
Download this Computerworld Executive Briefing, a $195 value, for free! Compliments of Akamai.
(Source: Computerworld) SaaS is here to stay as an application delivery channel. You will be using it, but will you do so wisely? This Learn-Fast Guide will prepare you for software delivered over the Web. From security issues to contract negotiations, there's a lot to consider ... and a lot to gain.
Download this executive briefing download
Windows® Enterprise Data Protection with Symantec Backup Exec™
Get this white paper now!
(Source: Symantec) With data protection becoming more distributed and IT resources increasingly constrained, businesses need a centralized data protection strategy that can manage multiple backup and recovery jobs. Learn how to address these critical enterprise challenges with dynamic disk-based data protection.
Download this white paper go
White Papers
Read up on the latest ideas and technologies from companies that sell hardware, software and services.
Death to PST: Hidden Cost of Email Mismanagement
Extend, Replace, or Convert; which is the best way forward for COBOL Applications?
The Trend from Unix to Linux in SAP Data Centers
View more whitepapers