I bet the entire MSN passport system is still full of holes,
I'm sure it is. If you read 2600, their current issue has a hacking m$ passport revisited.

After 2600 published their first article... m$ did something about it... but not much.

Pretty cool article though. Helps you understand why you shouldn't use cookies for authentication...