Sign In
MSDN Blogs
Microsoft Blog Images
More ...
Common Tasks
Blog Home
Email Blog Author
RSS for comments
RSS for posts
Atom
Search
Advanced search options...
Search In:
Everything
Blogs
Forums
People
Groups
Places
Pages
Date range:
All Time
Last Year
Last 6 Months
Last 3 Months
Last Month
Last Week
Last Two Days
Tags
build
Coffee
dotWord
Film
HD DVD
HDi
IgnoreMe
iHD
mango
Mix
MIX10
Music
Office
Pages
Philosophy
Privacy
Randomness
Script
Security
Silverlight
TechEd
Visual Studio
VSTO
WordBlogX
WP7S
Archives
Archives
October 2011
(1)
September 2011
(1)
August 2011
(2)
July 2011
(3)
May 2011
(2)
April 2011
(1)
March 2011
(2)
February 2011
(1)
December 2010
(1)
October 2010
(2)
September 2010
(1)
August 2010
(10)
July 2010
(4)
June 2010
(3)
May 2010
(3)
April 2010
(1)
March 2010
(9)
February 2010
(1)
February 2008
(2)
January 2008
(4)
December 2007
(3)
October 2007
(2)
September 2007
(2)
August 2007
(1)
July 2007
(1)
June 2007
(3)
May 2007
(2)
April 2007
(1)
March 2007
(1)
February 2007
(3)
January 2007
(2)
November 2006
(3)
October 2006
(2)
September 2006
(4)
August 2006
(2)
July 2006
(8)
June 2006
(4)
May 2006
(11)
April 2006
(8)
March 2006
(6)
September 2005
(1)
August 2005
(6)
July 2005
(5)
June 2005
(3)
March 2005
(1)
February 2005
(4)
January 2005
(3)
December 2004
(6)
November 2004
(6)
October 2004
(6)
September 2004
(3)
August 2004
(2)
July 2004
(9)
June 2004
(7)
May 2004
(1)
April 2004
(10)
March 2004
(9)
February 2004
(13)
January 2004
(22)
December 2003
(20)
November 2003
(14)
October 2003
(22)
September 2003
(17)
August 2003
(3)
July 2003
(6)
Blog - Title
Security
MSDN Blogs
>
Peter Torr's Blog
>
Security
Subscribe via RSS
Sort by:
Most Recent
|
Most Views
|
Most Comments
Excerpt View
|
Full Post View
Peter Torr's Blog
Updating Firefox as non-admin
Posted
over 6 years ago
by
Peter Torr - MSFT
2
Comments
Firefox , like all web browsers, needs to be regularly updated to keep up with security patches . Version 1.5 has an auto-update feature built-in, but unfortunately if you're not running as a local Administrator (at least in Windows), it doesn't work...
Peter Torr's Blog
When facts get in the way of a good argument
Posted
over 6 years ago
by
Peter Torr - MSFT
3
Comments
I've wanted to write this blog for a long time, but never gotten around to it. It's a very simple observation, but one that too many people fail to make. Maybe something will come of it :-) Oftentimes you will see something like the following on...
Peter Torr's Blog
Why not use hashes for the Anti-Phishing Filter?
Posted
over 7 years ago
by
Peter Torr - MSFT
0
Comments
Several people have asked why Internet Explorer 7 will send "real" URLs instead of hashes to the AP (Anti-Phishing) server. That's a good question, and I know it's a good question because it's the same thing just about everybody at Microsoft (including...
Peter Torr's Blog
Blindly trusting detection tools
Posted
over 7 years ago
by
Peter Torr - MSFT
6
Comments
Imagine I have a house cleaner that comes in once a week to clean the house. After a while I start to notice that my house smells "fishy", but my house cleaner has just the ticket -- the all-new FishBeGone (TM) cleaner & fragrance that gets rid of...
Peter Torr's Blog
What is Microsoft doing for security?
Posted
over 7 years ago
by
Peter Torr - MSFT
5
Comments
A recent comment on the IE Blog made it pretty apparent that not everybody is aware of Microsoft's efforts around security. Michael Howard has mentioned the Security Developme n t Lifecyle before, but in case you don't want to read the entire document...
Peter Torr's Blog
HELLO? CAN YOU HEAR ME?!?
Posted
over 7 years ago
by
Peter Torr - MSFT
0
Comments
As most of my friends know, I'm a pretty jumpy person. And, of course, most of those same friends like to exploit that fact for their own amusement from time to time (thanks to J e f f for almost running me over the other day). The fact that I lose 5...
Peter Torr's Blog
IE Blog
Posted
over 7 years ago
by
Peter Torr - MSFT
2
Comments
For those of you who haven't already heard, the IE team has a blog and recently they've started to talk about some of the cool features to be found in IE 7 Beta 1 (or planned for RTM). I've been working pretty closely with the IE team for some time...
Peter Torr's Blog
The Evil Problem
Posted
over 7 years ago
by
Peter Torr - MSFT
6
Comments
Over on the IE Blog, a commenter made a very good point -- why is it that IE flags scripts as “potentially bad”? That’s very confusing to the average user, and they have no way of knowing whether or not the script really is bad or not (and therefore whether...
Peter Torr's Blog
Malicious vs Spoofed Servers
Posted
over 7 years ago
by
Peter Torr - MSFT
0
Comments
Curious Caroline writes: Dear Peter , I have a friend who was talking to a security tester the other day, and apparently the tester said that having a "malicious server" is different than having a "spoofed" server. How is that...
Peter Torr's Blog
Adding URLs to an application securely
Posted
over 7 years ago
by
Peter Torr - MSFT
1
Comments
An Anonymous Reader writes: Dear Peter, I am writing a desktop application that contains links to external websites inside the "Help" menu, as is common with many applications such as Internet Explorer and Microsoft Office. I...
Peter Torr's Blog
Dear Diary...
Posted
over 7 years ago
by
Peter Torr - MSFT
0
Comments
I haven't really blogged in a while, mostly because it's hard to blog about the kind of work I do right now (improving the security of unreleased products). But, I thought to myself, one way to share some of my experience with all you great folks would...
Peter Torr's Blog
So that's what happens...
Posted
over 7 years ago
by
Peter Torr - MSFT
2
Comments
Today I did something I haven't done in a long time: I downloaded and installed some unsigned code while running as a local administrator on my home computer. I had to stare at the Security Warning dialog from Windows for quite a few moments before...
Peter Torr's Blog
Mozilla now signs Firefox downloads
Posted
over 7 years ago
by
Peter Torr - MSFT
13
Comments
A little bird recently told me some good news -- Mozilla Firefox is now digitally signed by "Mozilla Foundation." This means that Windows customers who want to download the self-installing executable with Internet Explorer can do so and be sure that what...
Peter Torr's Blog
Guerrilla Threat Modelling (or 'Threat Modeling' if you're American)
Posted
over 7 years ago
by
Peter Torr - MSFT
20
Comments
A crash-course in developing Data Flow Diagrams in support of software threat models...
Peter Torr's Blog
High-Level Threat Modelling Process
Posted
over 7 years ago
by
Peter Torr - MSFT
10
Comments
The following is a (slightly modified) version of a document I wrote for the VSTO team way back in the day. You might find it useful as you plan threat modelling for your product(s). You should of course read the Threat Modelling book from Microsoft Press...
Peter Torr's Blog
Inheritance Demands for Interfaces
Posted
over 7 years ago
by
Peter Torr - MSFT
11
Comments
I'm cheating here by re-posting an e-mail I sent the other day... but hey, you don't expect me to come up with new content for this blog do you? :-) Here is a deliberately contrived example of why you might need to protect interfaces with inheritance...
Peter Torr's Blog
I love Slashdot
Posted
over 8 years ago
by
Peter Torr - MSFT
244
Comments
The comments from my last post are still coming in thick and fast. Thanks to everyone who didn't just swear at me (and if I didn't approve your comment, it was because it had too much profanity in it). First things first: I was wrong about uninstalling...
Peter Torr's Blog
How can I trust Firefox?
Posted
over 8 years ago
by
Peter Torr - MSFT
1,408
Comments
[Fixed issues with images; sorry] [Removed the clear=all problem; thanks for pointing it out] [Added a follow-up post here ] Recently, a lot of volunteers donated money to the Firefox project to pay for a two-page advert in the New York Times . If only...
Peter Torr's Blog
Career Update
Posted
over 8 years ago
by
Peter Torr - MSFT
18
Comments
Just thought I’d let people know that I have moved from the Visual Studio Tools for Office team to the Secure Windows Initiative team. Exactly what that means for my blogging activities, I don’t yet know. I haven’t really been doing much of...
Peter Torr's Blog
AllowPartiallyTrustedCallers and AppDomain Boundaries
Posted
over 8 years ago
by
Peter Torr - MSFT
2
Comments
Continuing on from yesterday's post on creating pa r tially-trusted AppDomains , I had a bit of an e-mail exchange with Robert Hurlbut of Hurlbut Consulting . He wanted me to divulge all my secrets about AppDomains to him over e-mail, but I do intend...
Peter Torr's Blog
Creating a partially-trusted AppDomain
Posted
over 8 years ago
by
Peter Torr - MSFT
4
Comments
Shawn has some great blog entries on how to create restricted (or "sandboxed") AppDomains in the CLR by setting up custom AppDomain policy. Perhaps not surprisingly, this is one of the techniques used by Visual Studio Tools for Office to ensure that untrusted...
Peter Torr's Blog
Dr. Strongname, or: How I Learned to Stop Worrying and Love the URL
Posted
over 8 years ago
by
Peter Torr - MSFT
9
Comments
One of the problems with the Trustworthy Computing initiative is that many of our products have become harder to use as a result, either due to configuration changes or documentation changes. For example, Windows Server 2003 now ships with pretty much...
Peter Torr's Blog
Show me the money!
Posted
over 8 years ago
by
Peter Torr - MSFT
4
Comments
A member of the VSTO team just came to my office and asked, "Is it bad to trust all Office documents on the Local Intranet?" That's a good question, and after answering it for him I thought it was also worth blogging about (plus I'm hanging around...
Peter Torr's Blog
Threat Models in Action
Posted
over 8 years ago
by
Peter Torr - MSFT
0
Comments
As you probably know, the first Visual Studio "Whidbey" beta was released a few months ago, and we are hard at work finishing the product for release sometime... soon. ish. As you also probably know, Microsoft is now threat-modelling all new components...
Peter Torr's Blog
Windows Update, Automatic Update, and SAFER
Posted
over 8 years ago
by
Peter Torr - MSFT
5
Comments
Jeroen points out an annoying problem with the new version of Windows Update in his last comment -- it doesn't work from a RunAs-ed Internet Explorer session. This is a known problem with Windows Update that will hopefully be addressed in a future...
Page 1 of 4 (83 items)
1
2
3
4