Since moving to a team that handles the user accounts for everyone who uses any of Microsoft's web property, I've started to take a much more informed look at how I use my own account credentials and which web sites and applications I hand over those credentials to.
Angus Logan posted a great summary of the way Microsoft and Windows Live handles credential capture, which is worth a detailed read by everyone:
No Microsoft web site will ask you for your Live ID credentials except login.live.com (and accounts.live.com when linking accounts).
Any other web site which asks you for your credentials may not be evil.com but they could be sloppy coders or they could be hacked -- putting your credentials at risk of being stolen.
This equates to the First Law of Password Hygiene:
Only hand over your account credentials to your Identity Provider (for example, Windows Live ID),
Copyright © 2002-2008 Jorgen Thelin.
All rights reserved.
This weblog is licensed under a
Creative Commons License.