MSN Australia admits privacy breach

MSN Australia has admitted users remain at risk from a privacy hole, despite having known about the vulnerability since Tuesday.

A spokesperson at MSN's Australian arm has confirmed it had been aware of the vulnerability since a posting was made on Bugtraq, a security mailing list, on Tuesday yet is still looking for a solution.

-To the best of our knowledge no MSN users have been affected," the spokesperson said.

According to the posting, MSN Messenger or Windows Messenger on XP could be used to obtain personal information about a user from any Web site, in any domain.

Richard Burton, who posted details of the vulnerability on Bugtraq, said that by using JavaScript anyone can obtain a user's Messenger display name, and the display names of their contacts.

-For users who have a sensible and accurate display name this should be considered a privacy issue," he said.

Burton also alleges that for anyone who has not set a display name it will mean revealing their e-mail address.

In his posting Burton recommended users set a display name so that there address isn't easily obtainable. He has also made suggestions to Microsoft about how it could fix the vulnerabilities.

MSN said it would be looking at a solution this week.

Advertisement

Talkback 0 comments

Latest Videos

Sponsored content

Power Centre - Content from our premier sponsors

Blogs

  • Suzanne Tindal Sick of broken tender sites
    Some of the state governments desperately need to invest in more user-friendly tender sites so that looking for information on government tenders doesn't have to be a game of blind man's bluff.
  • Array Cyberwar: What is it good for?
    In this week's episode, Cyberwar. What is Australia's place in the world of digital warfare? What are the implications for the NBN?
  • Array Is wholesale-only backhaul just a pipedream?
    The potential acquisition of Pipe Networks by SP Telemedia has raised the question about whether vertically integrated backhaul providers will mean higher wholesale prices for ISP customers.
  • More blogs »

Tags

Back to top

Featured