Sign in
Michael Howard's Web Log
A Simple Software Security Guy at Microsoft!
Translate This Page
Translate this page
Powered by
Microsoft® Translator
Options
Email Blog Author
RSS for posts
Atom
RSS for comments
OK
Search
Tags
General
Pages
Personal
Privacy
Rant
Security
Vista
Archive
Archives
September 2009
(1)
July 2009
(1)
May 2009
(2)
March 2009
(1)
December 2008
(2)
November 2008
(3)
October 2008
(3)
September 2008
(7)
August 2008
(5)
July 2008
(3)
June 2008
(1)
May 2008
(1)
April 2008
(5)
March 2008
(5)
February 2008
(4)
January 2008
(9)
December 2007
(4)
November 2007
(4)
October 2007
(6)
September 2007
(1)
August 2007
(2)
July 2007
(4)
June 2007
(13)
May 2007
(6)
April 2007
(8)
March 2007
(11)
February 2007
(4)
January 2007
(8)
December 2006
(4)
November 2006
(15)
October 2006
(5)
September 2006
(6)
August 2006
(6)
July 2006
(2)
June 2006
(7)
May 2006
(8)
April 2006
(2)
March 2006
(5)
February 2006
(6)
January 2006
(10)
December 2005
(2)
November 2005
(2)
October 2005
(1)
September 2005
(4)
August 2005
(5)
July 2005
(5)
June 2005
(3)
May 2005
(9)
April 2005
(8)
March 2005
(5)
February 2005
(9)
January 2005
(7)
December 2004
(7)
November 2004
(9)
October 2004
(11)
August 2004
(13)
July 2004
(4)
June 2004
(12)
May 2004
(17)
April 2004
(2)
March 2004
(2)
February 2004
(3)
January 2004
(2)
Posts
Subscribe via RSS
Sort by:
Most Recent
|
Most Views
|
Most Comments
Excerpt View
|
Full Post View
Michael Howard's Web Log
Security Sessions at TechEd in Australia and New Zealand
Posted
over 4 years ago
by
Michael Howard
0
Comments
I'm heading to TechEd Oz and NZ in a couple of hours to present the following: SEC312 The "Everything Developers Need to Know About Security" Talk Oz: 9/10/2009 15:30-16:45 NZ: 9/14/2009 14:15-15:30 SEC201 Inside the Microsoft Security...
Michael Howard's Web Log
ATL, MS09-035 and the SDL
Posted
over 4 years ago
by
Michael Howard
0
Comments
http://blogs.msdn.com/sdl/archive/2009/07/28/atl-ms09-035-and-the-sdl.aspx
Michael Howard's Web Log
Integrating the SDL process into Visual Studio
Posted
over 4 years ago
by
Michael Howard
1
Comments
I’ve been a firm believer of integrating as much security tooling as possible into the development process so developers can get on with developing code and designing solutions rather than having to constantly think about dotting the security “i”s and...
Michael Howard's Web Log
A Conversation About Threat Modeling
Posted
over 4 years ago
by
Michael Howard
2
Comments
This was fun to write; in fact, other than minor edits I wrote it in a single two hour sitting with my laptop by the pool :) http://msdn.microsoft.com/en-us/magazine/dd727503.aspx
Michael Howard's Web Log
Ken Johnson (Skywing) joins Microsoft
Posted
over 4 years ago
by
Michael Howard
7
Comments
Following close on the heels of security experts Matt Miller , Adam Shostack and Crispin Cowan joining Microsoft, I am pleased to announce that Ken Johnson, AKA Skywing, has joined our group. Ken brings an enormous amount of reverse engineering...
Michael Howard's Web Log
Free Download: Writing Secure Code for Windows Vista
Posted
over 5 years ago
by
Michael Howard
4
Comments
"For 25 years, Microsoft Press books have focused on helping you take your skills and knowledge to the next level. Celebrate our 25th Anniversary with a "Free E-Book of the Month" offer! Simply sign up for the Microsoft Press Book Connection Newsletter...
Michael Howard's Web Log
Secure software development practices 'not rocket science'
Posted
over 5 years ago
by
Michael Howard
2
Comments
http://searchsoftwarequality.techtarget.com/news/article/0,289142,sid92_gci1340940,00.html #
Michael Howard's Web Log
A Proactive Approach to Building a Successful Security Development Lifecycle Program
Posted
over 5 years ago
by
Michael Howard
1
Comments
At this point most of you have heard about the Microsoft SDL and some of activities and deliverables associated with it. However, I still receive a number of questions, specifically, how and where development organizations can start deploying SDL....
Michael Howard's Web Log
Improvements in Office Security
Posted
over 5 years ago
by
Michael Howard
2
Comments
David LeBlanc has an excellent write-up of the results (so far) of all the security work the Office guys have been doing over the last few years. Net: about a 50% reduction in vulns!
Michael Howard's Web Log
Volume 5 of the Microsoft Security Intelligence Report is out
Posted
over 5 years ago
by
Michael Howard
2
Comments
Volume 5 of the Microsoft Security Intelligence Report is now out , highlights include: Security vulnerability disclosures - Microsoft and third-party software Vulnerability Exploits – Microsoft software Browser-based exploits - Microsoft...
Michael Howard's Web Log
Security-Related MSDN Magazine Articles
Posted
over 5 years ago
by
Michael Howard
1
Comments
Bryan Sullivan and I wrote a couple of articles for this month's MSDN Magazine. If you're not aware, November focuses on Security. The two articles are: Test Your Security IQ Threat Models Improve Your Security Process And there's the Agile...
Michael Howard's Web Log
Agile SDL
Posted
over 5 years ago
by
Michael Howard
2
Comments
Over the last year or so, a bunch of us in the SDL team have been working with agile groups across Microsoft to help streamline the SDL for agile methods. Bryan Sullivan wrote a paper for MSDN Magazine explaining where our current throughts lie. Clearly...
Michael Howard's Web Log
SAFECode releases "Fundamental Practices for Secure Software Development" document
Posted
over 5 years ago
by
Michael Howard
4
Comments
Today, SAFECode released an important document entitled, “ Fundamental Practices for Secure Software Development ” aimed at helping software producers create more secure software. The document is unique in that it describes what SAFECode members are...
Michael Howard's Web Log
Practical Defense in Depth
Posted
over 5 years ago
by
Michael Howard
1
Comments
<sent from Cabo San Lucas Airport - heading back to Austin > Crosstalk has published an article for mine regarding how we use Defense in Depth within the SDL, and in Microsoft in general.
Michael Howard's Web Log
Twitter Feed
Posted
over 5 years ago
by
Michael Howard
3
Comments
I've been doing this Twitter thing for a while now - I really like it, folks can get a feel for what you're up to each day. If you're interested, you can see what I'm up to by clicking 'Follow' at http://twitter.com/michael_howard
Michael Howard's Web Log
SDL Evolution
Posted
over 5 years ago
by
Michael Howard
2
Comments
UPDATED : Added IOActive post As many of you have seen today , there's been plenty of press about us opening up the SDL for use by other software developers and releasing our threat modeling tool. For those of you who have no clue what the heck I'm...
Michael Howard's Web Log
James Whittaker has a blog
Posted
over 5 years ago
by
Michael Howard
1
Comments
SDL alumnus James Whittaker has a blog. I meant to write a note on this weeks ago, but I kinda got busy! Anyway, if you're a tester, or have a passing interest in test, James is one of the best and you should learn from him. He's the author or coauthor...
Michael Howard's Web Log
GOOG Chrome's use of NX/DEP
Posted
over 5 years ago
by
Michael Howard
0
Comments
Scott Hanselman has a look under Chrome's hood and how it uses the new NX/DEP APIs we added to Windows . Scroll about halfway down the article.
Michael Howard's Web Log
Kim Cameron on GOOGs single sign on design vulnerability
Posted
over 5 years ago
by
Michael Howard
1
Comments
I spoke with Kim Cameron a few days ago about Google's single sign-on (SSO) design bug . I wanted his take on the bug because he's one of the best in the area of identity, single sign-on etc etc... his response can only be described as scathing.
Michael Howard's Web Log
Katie Moussouris joins the SDL team
Posted
over 5 years ago
by
Michael Howard
1
Comments
Dave Ladd just posted a note about Katie joing the ever-growing SDL team. For you twitter freaks out there she's @k8em0 :) Welcome, Katie...
Michael Howard's Web Log
SDL and the XSS Filter
Posted
over 5 years ago
by
Michael Howard
1
Comments
Close on the heels of David Ross' XSS defense in IE8 beta 2, my boss, Steve Lipner just posted an article looking at XSS filter from an SDL perspective. While I'm on the subject of XSS and Dave, if XSS is an area of interest to you, you really should...
Michael Howard's Web Log
Overlong UTF-8 Escapes Bite
Posted
over 5 years ago
by
Michael Howard
6
Comments
Every once in a while a security bug pops up that really piques my interest, and a new directory traversal bug that affects Apache Tomcat (http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2938) most certainly made me take notice because I haven...
Michael Howard's Web Log
Matt Miller Joins the Security Science Team!
Posted
over 5 years ago
by
Michael Howard
7
Comments
Good news! Matt Miller, author of plenty of cutting-edge security research, including my fave “ A Brief History of Exploitation Techniques and Mitigations on Windows ” has joined the Security Science team to work on improved ways to find security vulnerabilities...
Michael Howard's Web Log
Security is bigger than finding and fixing bugs
Posted
over 5 years ago
by
Michael Howard
1
Comments
I just wrapped up a post over on the SDL blog with some comments about an article on Google's security work.
Michael Howard's Web Log
How Very True
Posted
over 5 years ago
by
Michael Howard
3
Comments
http://twitter.com/alexsotirov/statuses/882866444
Page 1 of 14 (341 items)
1
2
3
4
5
»