<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.msdn.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>The First Step on the Road to More Secure Software is admitting you have a Problem</title><link>http://blogs.msdn.com/b/sdl/archive/2008/02/21/the-first-step-on-the-road-to-more-secure-software-is-admitting-you-have-a-problem.aspx</link><description>Hi, Michael here. 
 I am always bemused when Jeff Jones performs in-depth security vulnerability analysis and reports his findings , not because of the content of his findings, but because of the incredible arm-chair commentary that follows. 
 Jeff</description><dc:language>en-US</dc:language><generator>Telligent Evolution Platform Developer Build (Build: 5.6.50428.7875)</generator><item><title>Oh No! Security Metrics!</title><link>http://blogs.msdn.com/b/sdl/archive/2008/02/21/the-first-step-on-the-road-to-more-secure-software-is-admitting-you-have-a-problem.aspx#8407904</link><pubDate>Fri, 18 Apr 2008 16:08:15 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8407904</guid><dc:creator>The Security Development Lifecycle</dc:creator><description>&lt;p&gt;Hello, Michael here. A colleague sent me a link to a blog post from a couple of days ago: Pete Lindstrom&lt;/p&gt;
&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=8407904" width="1" height="1"&gt;</description></item><item><title>Microsoft SDL Process – in detail</title><link>http://blogs.msdn.com/b/sdl/archive/2008/02/21/the-first-step-on-the-road-to-more-secure-software-is-admitting-you-have-a-problem.aspx#8373345</link><pubDate>Thu, 10 Apr 2008 00:45:32 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8373345</guid><dc:creator>The Security Development Lifecycle</dc:creator><description>&lt;p&gt;Hello all – Dave here… I am currently at RSA and decided to take a few moments to blog about some updates&lt;/p&gt;
&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=8373345" width="1" height="1"&gt;</description></item><item><title>Sempre a proposito di sicurezza...</title><link>http://blogs.msdn.com/b/sdl/archive/2008/02/21/the-first-step-on-the-road-to-more-secure-software-is-admitting-you-have-a-problem.aspx#8350076</link><pubDate>Wed, 02 Apr 2008 09:45:06 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8350076</guid><dc:creator>Normal people bore me!</dc:creator><description>&lt;p&gt;Sempre a proposito di sicurezza...&lt;/p&gt;
&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=8350076" width="1" height="1"&gt;</description></item><item><title>re: The First Step on the Road to More Secure Software is admitting you have a Problem</title><link>http://blogs.msdn.com/b/sdl/archive/2008/02/21/the-first-step-on-the-road-to-more-secure-software-is-admitting-you-have-a-problem.aspx#8132443</link><pubDate>Mon, 10 Mar 2008 17:33:34 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8132443</guid><dc:creator>SDL Team</dc:creator><description>&lt;p&gt;Responding to Igor - the only posts we screen are spam, I don't see any reply from you listed in the blog logs. We encourage open and objective dialog. &lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=8132443" width="1" height="1"&gt;</description></item><item><title>Securitate in Windows Server 2008</title><link>http://blogs.msdn.com/b/sdl/archive/2008/02/21/the-first-step-on-the-road-to-more-secure-software-is-admitting-you-have-a-problem.aspx#8049795</link><pubDate>Wed, 05 Mar 2008 12:37:17 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8049795</guid><dc:creator>Weblogul lui Zoli</dc:creator><description>&lt;p&gt;C&amp;#226;nd am lansat Windows Vista și Office 2007 &amp;#238;n decembrie 2006 , am amintit că dacă m-ar &amp;#238;ntreba cineva&lt;/p&gt;
&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=8049795" width="1" height="1"&gt;</description></item><item><title>re: The First Step on the Road to More Secure Software is admitting you have a Problem</title><link>http://blogs.msdn.com/b/sdl/archive/2008/02/21/the-first-step-on-the-road-to-more-secure-software-is-admitting-you-have-a-problem.aspx#8045306</link><pubDate>Wed, 05 Mar 2008 08:29:12 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8045306</guid><dc:creator>Igor Levicki</dc:creator><description>&lt;p&gt;I posted a reply yesterday but seeing it is not up, it seems there is some censorship going on here.&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=8045306" width="1" height="1"&gt;</description></item><item><title>re: The First Step on the Road to More Secure Software is admitting you have a Problem</title><link>http://blogs.msdn.com/b/sdl/archive/2008/02/21/the-first-step-on-the-road-to-more-secure-software-is-admitting-you-have-a-problem.aspx#8036584</link><pubDate>Wed, 05 Mar 2008 01:06:18 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8036584</guid><dc:creator>TF_kj</dc:creator><description>&lt;p&gt;Sorry, one last question that I forgot:&lt;/p&gt;
&lt;p&gt;3. How many vulnerabilities are fixed silently in patch updates? Does anyone at Microsoft record patched vulnerabilities that are not publicly reported?&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=8036584" width="1" height="1"&gt;</description></item><item><title>re: The First Step on the Road to More Secure Software is admitting you have a Problem</title><link>http://blogs.msdn.com/b/sdl/archive/2008/02/21/the-first-step-on-the-road-to-more-secure-software-is-admitting-you-have-a-problem.aspx#8036463</link><pubDate>Wed, 05 Mar 2008 01:00:23 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8036463</guid><dc:creator>TF_kj</dc:creator><description>&lt;p&gt;Michael, great post. I like the bullets:&lt;/p&gt;
&lt;p&gt;* Microsoft recognized it needed to improve security.&lt;/p&gt;
&lt;p&gt;* Bill said so (as did the rest of senior management)&lt;/p&gt;
&lt;p&gt;* Our group swung into action and helped the rest of the company come up to speed on security issues.&lt;/p&gt;
&lt;p&gt;* The Microsoft development processes changed to adopt the SDL&lt;/p&gt;
&lt;p&gt;I respect the process changes that you guys have implemented. Great to see Msoft participate at BlackHat too. &lt;/p&gt;
&lt;p&gt;There always will be vuln in your code, but you guys have made progress. Congrats.&lt;/p&gt;
&lt;p&gt;Couple other things:&lt;/p&gt;
&lt;p&gt;1. How come it took Bill so long to address the glaring security problems in Microsoft's products and development processes? &lt;/p&gt;
&lt;p&gt;2. UAC has gotta go.&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=8036463" width="1" height="1"&gt;</description></item><item><title>Security Development Lifecycle trumps code complexity</title><link>http://blogs.msdn.com/b/sdl/archive/2008/02/21/the-first-step-on-the-road-to-more-secure-software-is-admitting-you-have-a-problem.aspx#8011611</link><pubDate>Tue, 04 Mar 2008 01:41:42 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8011611</guid><dc:creator>Microsoft</dc:creator><description>&lt;p&gt;&lt;a rel="nofollow" target="_new" href="http://weblog.infoworld.com/securityadviser/archives/2008/02/security_develo.htmlFebruary"&gt;http://weblog.infoworld.com/securityadviser/archives/2008/02/security_develo.htmlFebruary&lt;/a&gt; 29, 2008In&lt;/p&gt;
&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=8011611" width="1" height="1"&gt;</description></item><item><title>re: The First Step on the Road to More Secure Software is admitting you have a Problem</title><link>http://blogs.msdn.com/b/sdl/archive/2008/02/21/the-first-step-on-the-road-to-more-secure-software-is-admitting-you-have-a-problem.aspx#8006715</link><pubDate>Mon, 03 Mar 2008 20:48:19 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8006715</guid><dc:creator>SDL Team</dc:creator><description>&lt;p&gt;Igor - I agree with very little of what you said! &lt;/p&gt;
&lt;p&gt;Sure there are fixes in Vista made because of SP2 hindsight, but there are a lot of bugs that DON'T affect Vista because we made so many important wholesale code changes. We also added SAL annotations to Vista code that helped us track down bugs. I think analyzing XP vs Vista is perhaps the most honest comparison because the code is similar. &lt;/p&gt;
&lt;p&gt;The point about this being a publicitiy stuff is again incorrect. And the open source guys DO need some direction to strengthen their code. One guy can't do it.&lt;/p&gt;
&lt;p&gt;As for &amp;quot;You have also (wrongly) suggested that they do not admit the problem of (in)security, and that only you do.&amp;quot; Show me some text ANYWHERE stating from &amp;lt;some guy at Software Shop A&amp;gt; stating that &amp;lt;Software Shop A&amp;gt; has security bugs. What you said sounds like only Microsoft has security bugs!&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=8006715" width="1" height="1"&gt;</description></item></channel></rss>