|
EVERYONE who has used WebTV - Security Notice
I just found out terrible news. For months, my ex-girlfriend has had access to my hotmail inbox. While I understand that any email account with a webserver is inherently insecure, the ease of breaking into this account is shocking. She doesn't even own a computer! And of course, Microsoft calls it a 'feature'.
Months ago, I logged onto my girlfriend's MSNTV, and since her account needed a password that she didn't want to share with me, she set up my own account. This account was for my already existing hotmail address and passport. Then I checked my mail that evening, and perhaps twice more weeks after that. Afterward I changed my password from a PC, assuming that since the WebTV had no knowledge or awareness of my new password, my account would be safe. Wrong! Using the 'administrator' style privledges afforded to the primary account of a webtv address (username@webtv.net) she completely bypassed the need for my password under the guise of 'parental control'! The implications of this are that once you have logged onto someone else's WebTV or MSNTV the passport account, email, etc. is never secure until you delete account yourself.
I use passport on sites outside of MSN, including eBay. This could potentially compromise a lot of stuff. I'm busy trying to figure out who to write to at microsoft, but I felt I needed to make the rest of the world aware of this, to minimize the threat to those who may have already made the mistake I made.
|