Sign in
Michael Howard's Web Log
A Simple Software Security Guy at Microsoft!
Translate This Page
Translate this page
Powered by
Microsoft® Translator
Options
Email Blog Author
RSS for posts
Atom
RSS for comments
OK
Search
Tags
General
Pages
Personal
Privacy
Rant
Security
Vista
Archive
Archives
September 2009
(1)
July 2009
(1)
May 2009
(2)
March 2009
(1)
December 2008
(2)
November 2008
(3)
October 2008
(3)
September 2008
(7)
August 2008
(5)
July 2008
(3)
June 2008
(1)
May 2008
(1)
April 2008
(5)
March 2008
(5)
February 2008
(4)
January 2008
(9)
December 2007
(4)
November 2007
(4)
October 2007
(6)
September 2007
(1)
August 2007
(2)
July 2007
(4)
June 2007
(13)
May 2007
(6)
April 2007
(8)
March 2007
(11)
February 2007
(4)
January 2007
(8)
December 2006
(4)
November 2006
(15)
October 2006
(5)
September 2006
(6)
August 2006
(6)
July 2006
(2)
June 2006
(7)
May 2006
(8)
April 2006
(2)
March 2006
(5)
February 2006
(6)
January 2006
(10)
December 2005
(2)
November 2005
(2)
October 2005
(1)
September 2005
(4)
August 2005
(5)
July 2005
(5)
June 2005
(3)
May 2005
(9)
April 2005
(8)
March 2005
(5)
February 2005
(9)
January 2005
(7)
December 2004
(7)
November 2004
(9)
October 2004
(11)
August 2004
(13)
July 2004
(4)
June 2004
(12)
May 2004
(17)
April 2004
(2)
March 2004
(2)
February 2004
(3)
January 2004
(2)
Posts
Subscribe via RSS
Sort by:
Most Recent
|
Most Views
|
Most Comments
Excerpt View
|
Full Post View
Michael Howard's Web Log
"Open-source projects certified as secure" – huh?
Posted
over 5 years ago
by
Michael Howard
13
Comments
I really got a chuckle out of this news item , especially this line: “Coverity, which creates automated source-code analysis tools, announced late Monday its first list of open-source projects that have been certified as free of security defects...
Michael Howard's Web Log
VBootkit vs. Bitlocker in TPM mode
Posted
over 5 years ago
by
Michael Howard
2
Comments
One of the guys in our group, Robert Hensing has an interesting post about VBootkit and whether BitLocker in TPM offers any defense. Short answer: yes, it does. Slightly longer answer: The BitLocker guys anticiated this attack and the really long answer...
Michael Howard's Web Log
Recent Symantec and IBM vulnerabilities, giblets, banned APIs and the SDL
Posted
over 5 years ago
by
Michael Howard
1
Comments
I just posted some commentary on the SDL blog about some recent Symantec and IBM vulnerabilities, and how the SDL *may* have found them.
Michael Howard's Web Log
Common Criteria: Is it Safe?
Posted
over 6 years ago
by
Michael Howard
1
Comments
My colleague, Eric Bidstrup, has posted a thought provoking commentary about the Common Criteria. I think it's fair to say Eric is simply voicing what a great many people think about the (lack of) value of CC.
Michael Howard's Web Log
It's Official: Jeff Jones has *WWAYYY* Too Much Time on His Hands
Posted
over 6 years ago
by
Michael Howard
2
Comments
I think I'm a girl-elf in this , however!
Michael Howard's Web Log
Counterpoint to my SDL post
Posted
over 6 years ago
by
Michael Howard
1
Comments
David has an interesting counterpoint post to my SDL post this morning. As expected he makes some valid observations.
Michael Howard's Web Log
Security is not all about Security Updates
Posted
over 6 years ago
by
Michael Howard
1
Comments
I just posted an article about the SDL goals over on the SDL blog. http://blogs.msdn.com/sdl/archive/2007/12/17/security-is-not-all-about-security-updates.aspx
Michael Howard's Web Log
Today's Dilbert :)
Posted
over 6 years ago
by
Michael Howard
7
Comments
Perhaps I should change my name to "Mordac" From http://www.dilbert.com/comics/dilbert/archive/images/dilbert2007113333116.gif
Michael Howard's Web Log
Reminder: Microsoft Security Intelligence Report - Webcast on Wed 7 Nov
Posted
over 6 years ago
by
Michael Howard
2
Comments
Wednesday, November 07, 2007 10:00 AM Pacific Time Support WebCast: Microsoft Security Intelligence Report: Latest trends in vulnerabilities, malware, and potentially unwanted software
Michael Howard's Web Log
Oracle’s Original Unbreakable Paper
Posted
over 6 years ago
by
Michael Howard
4
Comments
I know a lot of you have heard of, or know of, Oracle’s Unbreakable claims. I’m not going to get into the religious, technical or emotional claims around “Unbreakable”, but a few days ago I went to dig up the paper and couldn’t find it, so I searched...
Michael Howard's Web Log
I'm at TechEd in Barcelona this week
Posted
over 6 years ago
by
Michael Howard
2
Comments
I'll be there all week, I have a bunch of talks: SEC201 - The Security Development Lifecycle (5 November 2007 Start: 17:45 Finish: 19:00 Room: Room 123 ) SEC202 - Threat Modeling (6 November 2007 Start: 10:45 Finish: 12:00 Room: Room 116 ) ...
Michael Howard's Web Log
New Microsoft Security Intelligence Report Available
Posted
over 6 years ago
by
Michael Howard
1
Comments
The latest Security Intelligence Report is now available. To quote the Web page: The Microsoft Security Intelligence Report (SIR) provides an in-depth perspective on the changing threat landscape including software vulnerability disclosures and...
Michael Howard's Web Log
Dev Tip: Opening Commonly-Accessed Files
Posted
over 6 years ago
by
Michael Howard
14
Comments
When I'm writing code, there's one file I need to access constantly - WinError.h, the file that lists all the Windows errors constants. SSSSoooo... I had to find a way to get to the file which is buried somewhere in the C:\Program Files\blah blah\Visual...
Michael Howard's Web Log
News Items that Interested me this Week
Posted
over 6 years ago
by
Michael Howard
5
Comments
Each week (ok, mostly every week!) I'll post news items that interested me... Security analysis of Checkpoint firewall Of interest is the way around RedHat's ExecShield buffer overflow defense. http://www.pentest.es/checkpoint_hack.pdf Abusing chroot...
Michael Howard's Web Log
Lessons Learned from Five Years of Building More Secure Software
Posted
over 6 years ago
by
Michael Howard
1
Comments
The annual Security issue of MSDN Magazine is now available. This year I wrote a piece about some of the lessons we've learned about building more secure software. I think this is the first article I have written in a long time that has no code samples...
Michael Howard's Web Log
Update on the Threat Modeling Process
Posted
over 6 years ago
by
Michael Howard
1
Comments
At Microsoft, we have been using various forms of threat modeling for years now, and we're always learning new ways to improve the process. By "improve" I mean make the process faster, a more efficient use of time and easier to understand. Heading this...
Michael Howard's Web Log
Bluehat Audio Available
Posted
over 6 years ago
by
Michael Howard
2
Comments
http://download.microsoft.com/download/3/2/0/3205AD8C-A0AA-40F0-8998-256B7583D400/DanKaminsky.wma http://download.microsoft.com/download/3/2/0/3205AD8C-A0AA-40F0-8998-256B7583D400/HalvarFlake.wma http://download.microsoft.com/download/3/2/0/3205AD8C...
Michael Howard's Web Log
New Version of Application Verifier (appverif) available
Posted
over 6 years ago
by
Michael Howard
2
Comments
AppVerif is one of my favorite run-time analysis tools for unmanaged Windows apps, it's also an SDL-required tool. An update is now available at http://www.microsoft.com/downloads/details.aspx?familyid=bd02c19c-1250-433c-8c1b-2619bd93b3a2&displaylang...
Michael Howard's Web Log
Update on DropMyRights
Posted
over 6 years ago
by
Michael Howard
9
Comments
It's been a long time since I looked at DropMyRights, a little tool I wrote forever ago to lower a user's privilege level on versions of WIndows prior to Windows Vista. Michael Horowitz has just posted a couple of blog posts about DMR stating that everyone...
Michael Howard's Web Log
Privacy Tip o' the Day
Posted
over 6 years ago
by
Michael Howard
18
Comments
I'm stunned at how much private data the average citizen will divulge. I was buying some stuff yesterday, and the clerk at the checkout asked the customer in front of me for her phone #, which she was quite happy to give. Next, I was signing up for gym...
Michael Howard's Web Log
Some of us won't be at Blackhat
Posted
over 6 years ago
by
Michael Howard
3
Comments
I am sitting at Austin airport about to catch a plane to Redmond to help a cadre of us deliver Windows 7 security training, and I just realized something. Yet again, and highly reminiscent of my post from last year , I won't be at Blackhat this year...
Michael Howard's Web Log
Iron Chef at BlackHat
Posted
over 6 years ago
by
Michael Howard
1
Comments
Eric Bidstrup has just posted some commentary about Iron Chef at Blackhat event over on the SDL blog. By the way, what the heck is an "iron chef" anyway?
Michael Howard's Web Log
Inspect Your Gadget
Posted
over 6 years ago
by
Michael Howard
3
Comments
Dave Ross and I recently wrote an article on the in's & out's of writing secure gadgets for Windows Vista. Because gadgets are considered full-trust applications, you must understand some gadget security basics.
Michael Howard's Web Log
Windows Vista Integrity Paper
Posted
over 6 years ago
by
Michael Howard
2
Comments
Howdy from a little coffee shop (no, not Starbucks) at the entrance to our subdivison in Austin! I can't wait to get broadband up and running at the house! Peter Brundrett, the PM behind the integrity levels work in Windows Vista has written a very...
Michael Howard's Web Log
My Last Day in Redmond
Posted
over 6 years ago
by
Michael Howard
15
Comments
Well, today is my last day in Redmond. It's pretty sad, but I'm really looking forward to being in Austin. It's been a long stretch selling the house, buying a house, dealing with builders (if you're considering building, let me know, and I'll give you...
Page 3 of 14 (341 items)
1
2
3
4
5
»