<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.msdn.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Some final thoughts on Threat Modeling...</title><link>http://blogs.msdn.com/b/larryosterman/archive/2007/10/01/some-final-thoughts-on-threat-modeling.aspx</link><description>I want to wrap up the threat modeling posts with a summary and some comments on the entire process. Yeah, I know I should have done this last week, but I got distracted :). 
 First, a summary of the threat modeling posts: 
 Part 1: Threat Modeling,</description><dc:language>en-US</dc:language><generator>Telligent Evolution Platform Developer Build (Build: 5.6.50428.7875)</generator><item><title>Threat Modeling</title><link>http://blogs.msdn.com/b/larryosterman/archive/2007/10/01/some-final-thoughts-on-threat-modeling.aspx#5464918</link><pubDate>Tue, 16 Oct 2007 01:54:33 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:5464918</guid><dc:creator>Noticias externas</dc:creator><description>&lt;p&gt;I&amp;amp;#39;ve been reading a set of posts by Larry (who used to work just down the hall from me...) on threat&lt;/p&gt;
&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=5464918" width="1" height="1"&gt;</description></item><item><title>Threat Modeling</title><link>http://blogs.msdn.com/b/larryosterman/archive/2007/10/01/some-final-thoughts-on-threat-modeling.aspx#5464881</link><pubDate>Tue, 16 Oct 2007 01:46:55 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:5464881</guid><dc:creator>Eric Gunnerson's C# Compendium</dc:creator><description>&lt;p&gt;I've been reading a set of posts by Larry (who used to work just down the hall from me...) on threat&lt;/p&gt;
&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=5464881" width="1" height="1"&gt;</description></item><item><title>re: Some final thoughts on Threat Modeling...</title><link>http://blogs.msdn.com/b/larryosterman/archive/2007/10/01/some-final-thoughts-on-threat-modeling.aspx#5264674</link><pubDate>Wed, 03 Oct 2007 19:39:24 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:5264674</guid><dc:creator>Larry Osterman [MSFT]</dc:creator><description>&lt;p&gt;Gabe: Absolutely. &amp;nbsp;There's absolutely nothing that a botnet client does that can't be done by a normal user. &amp;nbsp;It sucks, but it's true.&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=5264674" width="1" height="1"&gt;</description></item><item><title>re: Some final thoughts on Threat Modeling...</title><link>http://blogs.msdn.com/b/larryosterman/archive/2007/10/01/some-final-thoughts-on-threat-modeling.aspx#5264587</link><pubDate>Wed, 03 Oct 2007 19:35:49 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:5264587</guid><dc:creator>Gabe</dc:creator><description>&lt;p&gt;LUA is great, but it doesn't solve the malware problem. Once everybody is running as LUA, the malware writers will just make malware that runs correctly as LUA also.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=5264587" width="1" height="1"&gt;</description></item><item><title>Threat Modeling</title><link>http://blogs.msdn.com/b/larryosterman/archive/2007/10/01/some-final-thoughts-on-threat-modeling.aspx#5246774</link><pubDate>Tue, 02 Oct 2007 22:43:57 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:5246774</guid><dc:creator>Wampiryczny blog</dc:creator><description>&lt;p&gt;Larry Osterman na swoim blogu zamieścił serię artykuł&amp;#243;w na ten temat. Ciężkie, ale warte poznania. Nawet mimo tego, że David LeBlanc na temat przydatności threat modellingu ma nieco inne zdanie, choć wcale nie jednoznacznie negatywne. Temat i&lt;/p&gt;
&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=5246774" width="1" height="1"&gt;</description></item><item><title>re: Some final thoughts on Threat Modeling...</title><link>http://blogs.msdn.com/b/larryosterman/archive/2007/10/01/some-final-thoughts-on-threat-modeling.aspx#5243686</link><pubDate>Tue, 02 Oct 2007 18:14:02 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:5243686</guid><dc:creator>Larry Osterman [MSFT]</dc:creator><description>&lt;p&gt;eam: You're absolutely right. &amp;nbsp;And we've known that most malware written today is stopped completely by LUA. &amp;nbsp;UAC is the first step towards forcing users to run with LUA.&lt;/p&gt;
&lt;p&gt;The good news is that applications are starting to get a clue and the forcing function appears to be working.&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=5243686" width="1" height="1"&gt;</description></item><item><title>re: Some final thoughts on Threat Modeling...</title><link>http://blogs.msdn.com/b/larryosterman/archive/2007/10/01/some-final-thoughts-on-threat-modeling.aspx#5243325</link><pubDate>Tue, 02 Oct 2007 17:58:02 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:5243325</guid><dc:creator>Eam</dc:creator><description>&lt;p&gt;Larry:&lt;/p&gt;
&lt;p&gt;I'm not debating the usefulness of threat modeling, and I think you've done a great job explaining it here.&lt;/p&gt;
&lt;p&gt;My point is that, while it's nice Microsoft is trying to &amp;quot;enable the transition&amp;quot; to normal accounts, there's no real security until they actually *make* the transition.&lt;/p&gt;
&lt;p&gt;Here Jeff Atwood finds that a number of drive-by downloads just don't work as a limited user, even on a vulnerable browser:&lt;/p&gt;
&lt;p&gt;&lt;a rel="nofollow" target="_new" href="http://www.codinghorror.com/blog/archives/000891.html"&gt;http://www.codinghorror.com/blog/archives/000891.html&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;There's not even a &amp;quot;Malware detected, cancel or allow?&amp;quot; prompt, which most regular people would not read and dismiss with a quick &amp;quot;allow.&amp;quot;&lt;/p&gt;
&lt;p&gt;Even if Microsoft modeled all sorts of threats and made perfect software, people are still going to run poor-quality third party applications. If those apps are running with admin privileges, the user is in trouble.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=5243325" width="1" height="1"&gt;</description></item><item><title>re: Some final thoughts on Threat Modeling...</title><link>http://blogs.msdn.com/b/larryosterman/archive/2007/10/01/some-final-thoughts-on-threat-modeling.aspx#5242927</link><pubDate>Tue, 02 Oct 2007 17:36:40 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:5242927</guid><dc:creator>Eam</dc:creator><description>&lt;p&gt;John: You're absolutely correct. My mistake.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=5242927" width="1" height="1"&gt;</description></item><item><title>re: Some final thoughts on Threat Modeling...</title><link>http://blogs.msdn.com/b/larryosterman/archive/2007/10/01/some-final-thoughts-on-threat-modeling.aspx#5241356</link><pubDate>Tue, 02 Oct 2007 14:27:48 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:5241356</guid><dc:creator>John C. Kirk</dc:creator><description>&lt;p&gt;Eam, Larry: I think you may both be confusing LUA (Limited User Account) with UAC (User Account Control). If you don't want people to run as admin (which I agree with), then LUA is the alternative, i.e. they should have limited accounts!&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=5241356" width="1" height="1"&gt;</description></item><item><title>re: Some final thoughts on Threat Modeling...</title><link>http://blogs.msdn.com/b/larryosterman/archive/2007/10/01/some-final-thoughts-on-threat-modeling.aspx#5240836</link><pubDate>Tue, 02 Oct 2007 13:29:52 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:5240836</guid><dc:creator>G</dc:creator><description>&lt;p&gt;By the way, did you realize you have been slashdotted?&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=5240836" width="1" height="1"&gt;</description></item></channel></rss>