When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works.

Microsoft works to fix MSN privacy flaw

Thanks neo1980 for posting this in our Back page News on the forums.

Microsoft is putting the final touches on a patch to limit an MSN Messenger feature that allowed any Web site to grab a visitor's IM nickname and buddy list.

While representatives for the Microsoft Network have said no customers have fallen prey to the potential privacy problem, the group plans to release early next week an updated version of MSN Messenger that fixes the problem.

"In order to implement the fix, customers will have to upgrade to the next version of MSN messenger," a representative for the software behemoth said on Friday.

The issue occurs because Microsoft designed MSN Messenger to allow JavaScript contained in Web pages to access a customer's buddy list and, for certain Microsoft sites, the e-mail addresses of the person.

Software engineer Richard Burton highlighted the privacy implications of the feature in a post to SecurityFocus' BugTraq mailing list recently.

"It appears to have been intended as a feature so they could put in nice customizations on their Web sites," said the U.K.-based programmer on Friday. "I only raised it as a potential, so I don't think people need to panic."

The ill-conceived feature comes at a poor time for the software giant. Last month, Chairman Bill Gates wrote a companywide memo spurring employees to make security and privacy their top priorities.

News source: C|Net News.com

Report a problem with article
Next Article

Windows XP Patch: Dynamic Update 1.2

Previous Article

Taking the ICQ knocking sound into the offline world