Sign in
Michael Howard's Web Log
A Simple Software Security Guy at Microsoft!
Translate This Page
Translate this page
Powered by
Microsoft® Translator
Options
Email Blog Author
RSS for posts
Atom
RSS for comments
OK
Search
Tags
General
Pages
Personal
Privacy
Rant
Security
Vista
Archive
Archives
September 2009
(1)
July 2009
(1)
May 2009
(2)
March 2009
(1)
December 2008
(2)
November 2008
(3)
October 2008
(3)
September 2008
(7)
August 2008
(5)
July 2008
(3)
June 2008
(1)
May 2008
(1)
April 2008
(5)
March 2008
(5)
February 2008
(4)
January 2008
(9)
December 2007
(4)
November 2007
(4)
October 2007
(6)
September 2007
(1)
August 2007
(2)
July 2007
(4)
June 2007
(13)
May 2007
(6)
April 2007
(8)
March 2007
(11)
February 2007
(4)
January 2007
(8)
December 2006
(4)
November 2006
(15)
October 2006
(5)
September 2006
(6)
August 2006
(6)
July 2006
(2)
June 2006
(7)
May 2006
(8)
April 2006
(2)
March 2006
(5)
February 2006
(6)
January 2006
(10)
December 2005
(2)
November 2005
(2)
October 2005
(1)
September 2005
(4)
August 2005
(5)
July 2005
(5)
June 2005
(3)
May 2005
(9)
April 2005
(8)
March 2005
(5)
February 2005
(9)
January 2005
(7)
December 2004
(7)
November 2004
(9)
October 2004
(11)
August 2004
(13)
July 2004
(4)
June 2004
(12)
May 2004
(17)
April 2004
(2)
March 2004
(2)
February 2004
(3)
January 2004
(2)
Posts
Subscribe via RSS
Sort by:
Most Recent
|
Most Views
|
Most Comments
Excerpt View
|
Full Post View
Michael Howard's Web Log
Hardening Stack-based Buffer Overrun Detection in VC++ 2005 SP1
Posted
over 6 years ago
by
Michael Howard
9
Comments
As y’all know, the Visual C++ /GS compiler flag adds prolog and epilog code to certain functions to help detect some classes of stack based buffer overruns at runtime. In VC++ 2005, the code looks like this: Function prolog sub esp, 8 mov eax...
Michael Howard's Web Log
A Real-world Windows Vista BitLocker Tip
Posted
over 6 years ago
by
Michael Howard
13
Comments
Like a good Microsoft security citizen I installed BitLocker on my Infineon TPM-enabled laptop ages ago, well before we shipped the OS in late 2006. The nice thing is that I don't even know BitLocker is ‘doing its thing’ as there is no performance degradation...
Michael Howard's Web Log
Symantec: Microsoft-authored code will become more difficult to exploit
Posted
over 6 years ago
by
Michael Howard
1
Comments
From Symantec: With the advent of Vista and the continued use of the Security Development Lifecycle, it is likely that Microsoft-authored code will become more difficult to exploit. As a result, attackers may turn their focus to common third-party...
Michael Howard's Web Log
Surprise, Microsoft Listed as Most Secure OS
Posted
over 6 years ago
by
Michael Howard
5
Comments
Wow, the folks from Symantec claim "Microsoft is doing better overall than its leading commercial competitors [in security]" http://www.internetnews.com/security/article.php/3667201
Michael Howard's Web Log
Windows Vista - 90 Day Vulnerability Report
Posted
over 6 years ago
by
Michael Howard
0
Comments
Jeff Jones just posted a blog looking at vulnerability counts in various operating systems after 90 days of product release. It's an interesting read.
Michael Howard's Web Log
David LeBlanc now has a blog
Posted
over 6 years ago
by
Michael Howard
2
Comments
David is one of the most insightful security guys I know. Wicked smart, and damned opinionated, but who isn't? http://blogs.msdn.com/david_leblanc/
Michael Howard's Web Log
I think I have a blackhat in my midst
Posted
over 6 years ago
by
Michael Howard
8
Comments
A few weeks back I wrote how my 5 year old son, Blake, decided to hack into our computer. Well, it gets better. Blake is reading pretty well now, and can write too. But he still comes across words he needs to sound out phonetically. Yesterday, my...
Michael Howard's Web Log
My Take on Windows Vista Security “Vulnerabilities”
Posted
over 6 years ago
by
Michael Howard
16
Comments
I love looking at and analyzing security bugs, but I also enjoy observing how people react to knowledge of security bugs. Over the last few weeks, I’ve seen a number of interesting articles about Windows Vista security that made me smile. So I thought...
Michael Howard's Web Log
How I will judge Windows Vista Security
Posted
over 6 years ago
by
Michael Howard
13
Comments
Before I get started, I want to point out this is my opinion, not necessarily anyone else’s viewpoint. Now that we have shipped Windows Vista and researchers are starting to prod and probe for security bugs, I want to spend a couple of minutes to explain...
Michael Howard's Web Log
UAC Deep dive over on Channel9
Posted
over 6 years ago
by
Michael Howard
1
Comments
Chris Corio and Jonathan Schwartz did an hour-long deep dive into the UAC architecture, goals and issues over on Channel9. I've known Jon for more years than I care to remember, and he is one of the smartest guys I know, but don't tell him I said that...
Michael Howard's Web Log
List of Banned APIs now available
Posted
over 6 years ago
by
Michael Howard
14
Comments
We have just published the list of SDL-banned APIs, and their replacements. http://msdn2.microsoft.com/en-us/library/bb288454.aspx
Michael Howard's Web Log
New Book: Writing Secure Code for Windows Vista
Posted
over 6 years ago
by
Michael Howard
14
Comments
Even though we (kinda) promised our wives we wouldn’t do it, David LeBlanc and I have just wrapped up another book, Writing Secure Code for Windows Vista . (ISBN: 9780735623934, ISBN-10: 0-7356-2393-7.) It should be available around mid-April 2007...
Michael Howard's Web Log
How to get a US Passport in 1.5h Hours
Posted
over 6 years ago
by
Michael Howard
12
Comments
This is a true story. Last Thursday I flew from RSA in San Francisco back to Seattle. When I got back I helped my wife pack the bags for our trip to New Zealand. At about midnight, after we'd done all the packing, I got the passports out of the safe...
Michael Howard's Web Log
UAC BS
Posted
over 6 years ago
by
Michael Howard
20
Comments
Howdy once again from RSA. It's raining. So much for sunny California! Jeff and I just gave our talk about Windows Vista Security Engineering. It was a packed room. In fact, when we got to the room we saw a bunch of people milling around outside. We...
Michael Howard's Web Log
Something Windows Vista Parental Controls cannot protect against
Posted
over 6 years ago
by
Michael Howard
16
Comments
Howdy from RSA in San Francisco - I just got here, and I have a talk tomorrow morning @ 9AM about Windows Vista Security Engineering. Now to the topic of this post. One of my favorite features in Windows Vista is Parental Controls. I like the feature...
Michael Howard's Web Log
What is it that makes security hard?
Posted
over 6 years ago
by
Michael Howard
10
Comments
I’ve been asked this question numerous times, often in the guise of a question like, “why can’t you guys simply fix the security problem?” or “reliability and scalability problems are understood and solvable, why can’t you do the same with security?”...
Michael Howard's Web Log
Security Features vs. Convenience
Posted
over 6 years ago
by
Michael Howard
1
Comments
Jim Allchin has a great blog post about some of the design issues we went through and tradeoffs we made in Windows Vista around DEP, UAC, IE and so on. It's a long, but worthwhile read .
Michael Howard's Web Log
A couple of interesting security blog posts
Posted
over 6 years ago
by
Michael Howard
9
Comments
Jeff has an uncanny ability to dig into details that most folks gloss over: Exposed? : Examining Secunia Unpatched Warnings - Part 3 I have to concur with Kai: People like this just frost me: Security considered a burden for users
Michael Howard's Web Log
How not to write secure Web apps - and get to see Steve Jobs for Free!
Posted
over 6 years ago
by
Michael Howard
1
Comments
This blog post outlines a bug in the macworld.com web site that allowed the blogger to get a Platinum Pass into MacWorld to see the Jobs' keynote. I'm assuming the story is true! If it's not, it is still a fascinating read about insecure code.
Michael Howard's Web Log
Why Windows Vista is unaffected by the VML Bug
Posted
over 6 years ago
by
Michael Howard
12
Comments
MS07-004 does not affect Windows Vista, even though the coding bug is there. Why? The bug is an integer overflow calling C++ operator::new, but the affected component vgx.dll is compiled with the C++ compiler available in Visual Studio 2005 that automatically...
Michael Howard's Web Log
Windows Live OneCare v1.5 is released to manufacturing
Posted
over 6 years ago
by
Michael Howard
5
Comments
This is great news. OneCare is one of my all-time-fave products. I love it because it was built knowing that the target user is no security expert. It wasn't built by geeks for geeks. Everyone in my immediate family uses OneCare because (to quote my...
Michael Howard's Web Log
My Take on Visual Studio 2005 SP1 and Windows Vista
Posted
over 6 years ago
by
Michael Howard
11
Comments
Over the last couple of days, many people have asked for my take on the fact that Visual Studio 2005 SP1 requires admin privileges to run on Windows Vista, and pops up a dialog saying so when it starts up. So, here’s my take, and I don't work for...
Michael Howard's Web Log
Visual Studio 2005 Service Pack 1 Update for Windows Vista Beta Available
Posted
over 6 years ago
by
Michael Howard
14
Comments
From the blurb: During the development of Windows Vista, several key investments were made to vastly improve overall quality, security, and reliability from previous versions of Windows. While we have made tremendous investments in Windows Vista...
Michael Howard's Web Log
eXPired Poster Available!
Posted
over 6 years ago
by
Michael Howard
28
Comments
First, a very Happy New Year to you all...! Second, due to incredibly popular demand, I managed to find the eXPired poster. I have added it as an attachment at the end of this blog post. Enjoy.
Michael Howard's Web Log
Online Security Sessions from TechEd IT Forum Available
Posted
over 7 years ago
by
Michael Howard
5
Comments
Knowing the Enemy - A lightning demonstration on how hackers attack networks http://www.microsoft.com/emea/itsshowtime/sessionh.aspx?videoid=351 Marcus Murray, Senior Security Architect, Truesec Advanced Malware Cleaning http://www.microsoft.com/emea...
Page 5 of 14 (341 items)
«
3
4
5
6
7
»