{"id":1588,"date":"2003-05-22T05:50:34","date_gmt":"2003-05-22T03:50:34","guid":{"rendered":"https:\/\/destinationcyber.com\/?p=1588"},"modified":"2003-05-22T05:50:34","modified_gmt":"2003-05-22T03:50:34","slug":"le-gartner-group-senerve-oubliez-passport","status":"publish","type":"post","link":"https:\/\/destinationcyber.com\/?p=1588","title":{"rendered":"Le Gartner Group s&rsquo;\u00e9nerve : &lsquo;Oubliez Passport&rsquo;!"},"content":{"rendered":"<p class=\"post_excerpt\">L&rsquo;institut d&rsquo;analyse n&rsquo;y va pas de main morte: la faille de s\u00e9curit\u00e9 d\u00e9couverte la semaine derni\u00e8re d\u00e9cr\u00e9dibilise le syst\u00e8me d&rsquo;authentification de Microsoft <\/p>\n<p>La d\u00e9couverte d&rsquo;une \u00e9norme faille de s\u00e9curit\u00e9 dans Passport, rep\u00e9r\u00e9 en quatre minutes par un chercheur pakistanais, n&rsquo;en finit pas d&rsquo;avoir des cons\u00e9quences n\u00e9fastes sur le syst\u00e8me de Microsoft. Apr\u00e8s une certaine g\u00eane exprim\u00e9e par la firme de Redmond, c&rsquo;est au tour du Gartner de jeter de l&rsquo;huile sur le feu. Rappelons que Passport est un syst\u00e8me d&rsquo;authentification qui doit permettre d&rsquo;acc\u00e9der \u00e0 une vari\u00e9t\u00e9 de services Web (dont MSN, Hotmail&#8230;) via le m\u00eame mot de passe et identifiants. Des dizaines de millions d&rsquo;internautes commencent \u00e0 l&rsquo;utiliser chaque jour.<\/p>\n<p>Le redout\u00e9 cabinet d&rsquo;analyses n&rsquo;y va pas par quatre chemins. Il recommande ainsi \u00abaux institutions financi\u00e8res, fournisseurs de cartes de cr\u00e9dit et toute autre entreprise utilisant Passport de mani\u00e8re significative, de bloquer imm\u00e9diatement toutes les connexions au syst\u00e8me Passport. (&#8230;) Ou investir dans un syst\u00e8me d&rsquo;authentification additionnel et plus s\u00e9curis\u00e9 pour tous les comptes Passport\u00bb. Cela a le m\u00e9rite d&rsquo;\u00eatre clair: pour travailler en s\u00e9curit\u00e9, oubliez Passport!<\/p>\n<p>Faille \u00ab\u00a0majeure\u00a0\u00bb<br \/>\nLa faille de s\u00e9curit\u00e9 a \u00e9t\u00e9 qualifi\u00e9e de \u00ab\u00a0majeure\u00a0\u00bb par le Gartner qui conseille tout simplement \u00ab\u00a0d&rsquo;attendre au moins six mois pour se reconnecter au service, ou du moins jusqu&rsquo;\u00e0 ce que Microsoft prouve que ses protections sont ad\u00e9quates\u00a0\u00bb. <\/p>\n<p>Chez Microsoft, on indique que le probl\u00e8me a \u00e9t\u00e9 r\u00e9gl\u00e9 rapidement et que l&rsquo;avis du Gartner est \u00ab\u00a0excessif\u00a0\u00bb. <\/p>\n<p>[source &#8211; Silicon.fr]&nbsp;Olivier Chicheportiche  <\/p>\n","protected":false},"excerpt":{"rendered":"<p>L&rsquo;institut d&rsquo;analyse n&rsquo;y va pas de main morte: la faille de s\u00e9curit\u00e9 d\u00e9couverte la semaine derni\u00e8re d\u00e9cr\u00e9dibilise le syst\u00e8me d&rsquo;authentification de Microsoft <\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_citadela_custom_class":"","footnotes":""},"categories":[15],"tags":[],"class_list":["post-1588","post","type-post","status-publish","format-standard","hentry","category-securite"],"_links":{"self":[{"href":"https:\/\/destinationcyber.com\/index.php?rest_route=\/wp\/v2\/posts\/1588","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/destinationcyber.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/destinationcyber.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/destinationcyber.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/destinationcyber.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1588"}],"version-history":[{"count":0,"href":"https:\/\/destinationcyber.com\/index.php?rest_route=\/wp\/v2\/posts\/1588\/revisions"}],"wp:attachment":[{"href":"https:\/\/destinationcyber.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1588"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/destinationcyber.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1588"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/destinationcyber.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1588"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}