<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.msdn.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Engineering Windows 7 : E7Blog</title><link>http://blogs.msdn.com/e7/archive/tags/E7Blog/default.aspx</link><description>Tags: E7Blog</description><dc:language>en-US</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>Update on UAC</title><link>http://blogs.msdn.com/e7/archive/2009/02/05/update-on-uac.aspx</link><pubDate>Thu, 05 Feb 2009 11:00:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9397722</guid><dc:creator>e7blog</dc:creator><slash:comments>81</slash:comments><comments>http://blogs.msdn.com/e7/comments/9397722.aspx</comments><wfw:commentRss>http://blogs.msdn.com/e7/commentrss.aspx?PostID=9397722</wfw:commentRss><description>&lt;P&gt;Hi, Jon DeVaan here to talk to you about the recent UAC feedback we’ve been receiving.&lt;/P&gt;
&lt;P&gt;Most of our work finishing Windows 7 is focused on responding to feedback. The UAC feedback is interesting on a few dimensions of engineering decision making process. I thought that exploring those dimensions would make for an interesting e7 blog entry. This is our third discussion about UAC and for those interested in the evolution of the feature in Windows it is worth seeing the two previous posts (&lt;A href="http://blogs.msdn.com/e7/archive/2008/10/08/user-account-control.aspx" mce_href="http://blogs.msdn.com/e7/archive/2008/10/08/user-account-control.aspx"&gt;post #1&lt;/A&gt; and &lt;A href="http://blogs.msdn.com/e7/archive/2009/01/15/user-account-control-uac-quick-update.aspx" mce_href="http://blogs.msdn.com/e7/archive/2009/01/15/user-account-control-uac-quick-update.aspx"&gt;post #2&lt;/A&gt;) and also reading the comments from many of you.&lt;/P&gt;
&lt;P&gt;We are flattered by the response to the Windows 7 beta so far and working hard at further refining the product based on feedback and telemetry as we work towards the Release Candidate. For all of us working on Windows it is humbling to know that our work affects so many people around the world. The recent feedback is showing us just how much passion people have for Windows! Again we are humbled and excited to be a part of an amazing community of people working to bring the value of computing to a billion people around the world. Thank you very much for all of the thoughts and comments you have contributed so far.&lt;/P&gt;
&lt;P&gt;UAC is one of those features that has a broad spectrum of viewpoints with advocates staking out both “ends” of the spectrum as well as all points in between, and often doing so rather stridently. In this case we might represent the ends of the spectrum as “security” on one end and “usability” on the other. Of course, this is not in reality a bi-polar issue. There is a spectrum of perfectly viable design points in between. Security experts around the world have lived with this basic tension forever, and there have certainly been systems designed to be so secure that they are secure from the people who are supposed to benefit from them. A personal example I have, is that my bank recently changed the security regimen on its online banking site. It is so convoluted I am switching banks. Seriously!&lt;/P&gt;
&lt;P&gt;&lt;B&gt;Clarifying Misperceptions&lt;/B&gt;&lt;/P&gt;
&lt;P&gt;As people have commented on our current UAC design (and people have commented on those comments) it is clear that there is conflation of a few things, and a set of misperceptions that need to be cleared up before we talk about the engineering decisions made on UAC. These engineering decisions have been made while we carry forth our &lt;A href="http://msdn.microsoft.com/en-us/library/ms995349.aspx" mce_href="http://msdn.microsoft.com/en-us/library/ms995349.aspx"&gt;secure development lifecycle principles&lt;/A&gt; pioneered in Windows XP SP2, and most importantly the principle of “secure by default” as part of SD3+C. Windows 7 upholds those principles and does so with a renewed focus on making sure everyone feels they are in control of their PC experience as we have talked about in many posts.&lt;/P&gt;
&lt;P&gt;The first issue to untangle is about the difference between malware making it onto a PC and being run, versus what it can do once it is running. There has been no report of a way for malware to make it onto a PC without consent. All of the feedback so far concerns the behavior of UAC once malware has found its way onto the PC and is running. Microsoft’s position that the reports about UAC do not constitute a vulnerability is because the reports have not shown a way for malware to get onto the machine in the first place without express consent. Some people have taken the, “it’s not a vulnerability” position to mean we aren’t taking the other parts of the issue seriously. Please know we take all of the feedback we receive seriously.&lt;/P&gt;
&lt;P&gt;The word “vulnerability” has a very specific meaning in the security area. Microsoft has one of the leading security agencies in the world in the &lt;A href="http://www.microsoft.com/msrc" mce_href="http://www.microsoft.com/msrc"&gt;Microsoft Security Response Center&lt;/A&gt; (&lt;A href="mailto:secure@microsoft.com" mce_href="mailto:secure@microsoft.com"&gt;secure@microsoft.com&lt;/A&gt;) which monitors the greater ecosystem for security threats and manages the response to any threat or vulnerability related to Microsoft products. By any definition that is generally accepted across the world wide security community, the recent feedback does not represent a vulnerability since it does not allow the malicious software to reach the computer in the first place.&lt;/P&gt;
&lt;P&gt;It is worth pointing out the defenses that exist in Windows Vista that keep malware from getting on the PC in the first place. In using Internet Explorer (other browsers have similar security steps as well) when attempting to browse to a .vbs file or .exe file, for example, the person will see the prompts below:&lt;/P&gt;
&lt;P&gt;&lt;A href="http://blogs.msdn.com/blogfiles/e7/WindowsLiveWriter/UpdateonUAC_140FD/clip_image002_2.jpg" mce_href="http://blogs.msdn.com/blogfiles/e7/WindowsLiveWriter/UpdateonUAC_140FD/clip_image002_2.jpg"&gt;&lt;IMG style="BORDER-BOTTOM: 0px; BORDER-LEFT: 0px; DISPLAY: inline; BORDER-TOP: 0px; BORDER-RIGHT: 0px" title=clip_image002 border=0 alt=clip_image002 src="http://blogs.msdn.com/blogfiles/e7/WindowsLiveWriter/UpdateonUAC_140FD/clip_image002_thumb.jpg" width=388 height=286 mce_src="http://blogs.msdn.com/blogfiles/e7/WindowsLiveWriter/UpdateonUAC_140FD/clip_image002_thumb.jpg"&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="http://blogs.msdn.com/blogfiles/e7/WindowsLiveWriter/UpdateonUAC_140FD/clip_image004_2.jpg" mce_href="http://blogs.msdn.com/blogfiles/e7/WindowsLiveWriter/UpdateonUAC_140FD/clip_image004_2.jpg"&gt;&lt;IMG style="BORDER-BOTTOM: 0px; BORDER-LEFT: 0px; DISPLAY: inline; BORDER-TOP: 0px; BORDER-RIGHT: 0px" title=clip_image004 border=0 alt=clip_image004 src="http://blogs.msdn.com/blogfiles/e7/WindowsLiveWriter/UpdateonUAC_140FD/clip_image004_thumb.jpg" width=467 height=255 mce_src="http://blogs.msdn.com/blogfiles/e7/WindowsLiveWriter/UpdateonUAC_140FD/clip_image004_thumb.jpg"&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Internet Explorer 8 has also introduced many new features to thwart malware distribution (see &lt;A href="http://blogs.msdn.com/ie/archive/2008/08/29/trustworthy-browsing-with-ie8-summary.aspx" mce_href="http://blogs.msdn.com/ie/archive/2008/08/29/trustworthy-browsing-with-ie8-summary.aspx"&gt;http://blogs.msdn.com/ie/archive/2008/08/29/trustworthy-browsing-with-ie8-summary.aspx&lt;/A&gt; ). One of my favorites is the &lt;A href="http://blogs.msdn.com/ie/archive/2008/07/02/ie8-security-part-iii-smartscreen-filter.aspx" mce_href="http://blogs.msdn.com/ie/archive/2008/07/02/ie8-security-part-iii-smartscreen-filter.aspx"&gt;SmartScreen® Filter&lt;/A&gt; which helps people understand when they are about to visit a malicious site. There are other features visible and hidden that make getting malware onto a PC much more difficult.&lt;/P&gt;
&lt;P&gt;&lt;B&gt;&lt;A href="http://blogs.msdn.com/blogfiles/e7/WindowsLiveWriter/UpdateonUAC_140FD/clip_image006_2.jpg" mce_href="http://blogs.msdn.com/blogfiles/e7/WindowsLiveWriter/UpdateonUAC_140FD/clip_image006_2.jpg"&gt;&lt;IMG style="BORDER-BOTTOM: 0px; BORDER-LEFT: 0px; DISPLAY: inline; BORDER-TOP: 0px; BORDER-RIGHT: 0px" title=clip_image006 border=0 alt=clip_image006 src="http://blogs.msdn.com/blogfiles/e7/WindowsLiveWriter/UpdateonUAC_140FD/clip_image006_thumb.jpg" width=393 height=358 mce_src="http://blogs.msdn.com/blogfiles/e7/WindowsLiveWriter/UpdateonUAC_140FD/clip_image006_thumb.jpg"&gt;&lt;/A&gt;&lt;/B&gt; &lt;BR&gt;A SmartScreen® display from IE 8&lt;/P&gt;
&lt;P&gt;Additionally, if one attempts to open an attachment in a modern email program (such as Windows Live Mail) the malware file is blocked:&lt;/P&gt;
&lt;P&gt;&lt;A href="http://blogs.msdn.com/blogfiles/e7/WindowsLiveWriter/UpdateonUAC_140FD/clip_image008_2.jpg" mce_href="http://blogs.msdn.com/blogfiles/e7/WindowsLiveWriter/UpdateonUAC_140FD/clip_image008_2.jpg"&gt;&lt;IMG style="BORDER-BOTTOM: 0px; BORDER-LEFT: 0px; DISPLAY: inline; BORDER-TOP: 0px; BORDER-RIGHT: 0px" title=clip_image008 border=0 alt=clip_image008 src="http://blogs.msdn.com/blogfiles/e7/WindowsLiveWriter/UpdateonUAC_140FD/clip_image008_thumb.jpg" width=521 height=196 mce_src="http://blogs.msdn.com/blogfiles/e7/WindowsLiveWriter/UpdateonUAC_140FD/clip_image008_thumb.jpg"&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Much of the recent feedback has failed to take into account the ways that Windows 7 is better than Windows Vista at preventing malware from reaching the PC in the first place. In Windows 7 we have continued to focus on improving the ability to stop malware before it is installed or running on a PC.&lt;/P&gt;
&lt;P&gt;The second issue to untangle is about the difference in behavior between different UAC settings. In Windows 7, we have four settings for the UAC feature: “Never Notify,” “Notify me only when programs try to make changes to my computer (without desktop dimming),” “Notify me only when programs try to make changes to my computer (with desktop dimming),” and “Always Notify.” In Windows Vista there were only two choices, the equivalent of “Never Notify” and “Always Notify.” The Vista UI made it difficult for people to choose “Never Notify” and thus choosing between extremes in the implementation. Windows 7 offers you more choice and control over this feature, which is particularly interesting to many of you based on the feedback we have received.&lt;/P&gt;
&lt;P&gt;The recent feedback on UAC is about the behavior of the “Notify me only when programs try to make changes to my computer” settings. The feedback has been clear it is not related to UAC set to “Always Notify.” So if anyone says something like, “UAC is broken,” it is easy to see they are mischaracterizing the feedback.&lt;/P&gt;
&lt;P&gt;&lt;B&gt;The Purpose of UAC&lt;/B&gt;&lt;/P&gt;
&lt;P&gt;We are listening to the feedback on how “Notify me only when…” works in Windows 7. It is important to bring in some additional context when explaining our design choice. We choose our default settings to serve a broad range of customers, based on the feedback we have received about improving UAC as a whole. We have learned from our customers participating in the Customer Experience Improvement Program, Windows Feedback Panel, user surveys, user in field testing, and in house usability testing that the benefit of the information provided by the UAC consent dialog decreases substantially as the number of notifications increases. So for the general population, we know we have to present only key information to avoid the reflex to “answer yes”.&lt;/P&gt;
&lt;P&gt;One important thing to know is that UAC is not a security boundary. UAC helps people be more secure, but it is not a cure all. UAC helps most by being the prompt before software is installed. This part of UAC is in full force when the “Notify me only when…” setting is used. UAC also prompts for other system wide changes that require administrator privileges which, considered in the abstract, would seem to be an effective counter-measure to malware after it is running, but the practical experience is that its effect is limited. For example, clever malware will avoid operations that require elevation. There are other human behavior factors which were discussed in our earlier blog posts (&lt;A href="http://blogs.msdn.com/e7/archive/2008/10/08/user-account-control.aspx" mce_href="http://blogs.msdn.com/e7/archive/2008/10/08/user-account-control.aspx"&gt;post #1&lt;/A&gt; and &lt;A href="http://blogs.msdn.com/e7/archive/2009/01/15/user-account-control-uac-quick-update.aspx" mce_href="http://blogs.msdn.com/e7/archive/2009/01/15/user-account-control-uac-quick-update.aspx"&gt;post #2&lt;/A&gt;).&lt;/P&gt;
&lt;P&gt;UAC also helps software developers improve their programs to run without requiring administrator privileges. The most effective way to secure a system against malware is to run with standard user privileges. As more software works well without administrator privileges, more people will run as standard user. We expect that anyone responsible for a set of Windows 7 machines (such as IT Administrators or the family helpdesk worker (like me!)) will administer them to use standard user accounts. The recent feedback has noted explicitly that running as standard user works well. Administrators also have Group Policy at their disposal to enforce the UAC setting to “Always Notify” if they choose to manage their machines with administrator accounts instead of standard user accounts.&lt;/P&gt;
&lt;P&gt;Recapping the discussion so far, we know that the recent feedback does not represent a security vulnerability because malicious software would already need to be running on the system. We know that Windows 7 and IE8 together provide improved protection for users to prevent malware from making it onto their machines. We know that the feedback does not apply to the “Always Notify” setting of UAC; and we know that UAC is not 100% effective at stopping malware once it is running. One might ask, why does the “Notify me only when…” setting exist, and why is it the default?&lt;/P&gt;
&lt;P&gt;&lt;B&gt;Customer-Driven Engineering&lt;/B&gt;&lt;/P&gt;
&lt;P&gt;The creation of the “Notify me only when…” setting and our choice of it as the default is a design choice along the spectrum inherent in security design as mentioned above. Before we started Windows 7 we certainly had a lot of feedback about how the Vista UAC feature displayed too many prompts. The new UAC setting is designed to be responsive to this feedback. A lot of the recent feedback has been of the form of, “I’ll set it to ‘Always Notify,’ but ‘regular people’ also need to be more secure.” I am sure security conscious people feel that way, and I am glad that Windows 7 has the setting that works great for their needs. But what do these so called “regular people” want? How to choose the default, while honoring our secure design principles, for these people is a very interesting question.&lt;/P&gt;
&lt;P&gt;In making our choice for the default setting for the Windows 7 beta we monitored the behavior of two groups of regular people running the M3 build. Half were set to “Notify me only when…” and half to “Always Notify.” We analyzed the results and attitudes of these people to inform our choice. This study, along with our data from the Customer Experience Improvement Program, Windows Feedback Panel, user surveys, and in house usability testing, informed our choice for the beta, and informed the way we want to use telemetry from the beta to validate our final choice for the setting.&lt;/P&gt;
&lt;P&gt;A key metric that came out of the study was the threshold of two prompts during a session. (A session is the time from power up to power down, or a day, whichever is shorter.) If people see more than two prompts in a session they feel that the prompts are irritating and interfering with their use of the computer. In comparing the two groups we found that the group with the “Always Notify” setting was nearly four times as likely to have sessions with more than two prompts (a 1 in 6.7 chance vs a 1 in 24 chance). We gathered the statistic for how many people in the sample had malware make it onto their machine (as measured by defender cleaning) and found there was no meaningful difference in malware infestation rates between the two groups. We will continue to collect data during the beta to see if these results hold true in a much broader study. &lt;/P&gt;
&lt;P&gt;We are very happy with the positive feedback we have received about UAC from beta testers and individual users overall. This helps us validate our “regular people” focus in terms of the trade-offs we continue to consider in this design choice. We will continue to monitor the feedback and our telemetry data to continue to improve our design choices on UAC.&lt;/P&gt;
&lt;P&gt;So as you can see there is a lot of depth to the discussion of UAC and the improvements made in Windows 7 in UAC itself and in improving ways to prevent malware from ever reaching a PC. We are working hard to be responsive to the feedback we received from Vista to provide the right usability and security for people of all types. We believe we’ve made good progress and are listening carefully to the feedback on our UAC changes. Again please accept our most sincere thanks for the passion and feedback on Windows 7. While we cannot implement features the way each and every one of you might wish, we are listening and making a sincere effort to properly weigh all points of view. Our goal is to create a useful, useable, and secure Windows for all types of people.&lt;/P&gt;
&lt;P&gt;Jon&lt;/P&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=9397722" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/e7/archive/tags/E7Blog/default.aspx">E7Blog</category><category domain="http://blogs.msdn.com/e7/archive/tags/Security/default.aspx">Security</category><category domain="http://blogs.msdn.com/e7/archive/tags/Design/default.aspx">Design</category></item><item><title>Welcome to Engineering Windows 7</title><link>http://blogs.msdn.com/e7/archive/2008/08/14/welcome.aspx</link><pubDate>Thu, 14 Aug 2008 21:20:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8867564</guid><dc:creator>e7blog</dc:creator><slash:comments>345</slash:comments><comments>http://blogs.msdn.com/e7/comments/8867564.aspx</comments><wfw:commentRss>http://blogs.msdn.com/e7/commentrss.aspx?PostID=8867564</wfw:commentRss><description>&lt;P&gt;Welcome to our first post on a new blog from Microsoft—the Engineering Windows 7 blog, or E7 for short. E7 is hosted by the two senior engineering managers for the Windows 7 product, &lt;A href="http://www.microsoft.com/presspass/exec/devaan/" mce_href="http://www.microsoft.com/presspass/exec/devaan/"&gt;Jon DeVaan&lt;/A&gt; and &lt;A href="http://www.microsoft.com/presspass/exec/ssinofsky/" mce_href="http://www.microsoft.com/presspass/exec/ssinofsky/"&gt;Steven Sinofsky&lt;/A&gt;. Jon and Steven, along with members of the engineering team will post, comment, and participate in this blog.&lt;/P&gt;
&lt;P&gt;Beginning with this post together we are going to start looking forward towards the “Windows 7” project. We know there are tons of questions about the specifics of the project and strong desire to know what’s in store for the next major release of Windows. Believe us, we are just as excited to start talking about the release. Over the past 18 months since Windows Vista’s broad availability, the team has been hard at work creating the next Windows product.&lt;/P&gt;
&lt;P&gt;The audience of enthusiasts, bloggers, and those that are the most passionate about Windows represent the folks we are dedicating this blog to. With this blog we’re opening up a two-way discussion about &lt;I&gt;how&lt;/I&gt; we are making Windows 7. Windows has all the challenges of every large scale software project—picking features, designing them, developing them, and delivering them with high quality. Windows has an added challenge of doing so for an extraordinarily diverse set of customers. As a team and as individuals on the team we continue to be humbled by this responsibility.&lt;/P&gt;
&lt;P&gt;We strongly believe that success for Windows 7 includes an open and honest, and two-way, discussion about how we balance all of these interests and deliver software on the scale of Windows. We promise and will deliver such a dialog with this blog.&lt;/P&gt;
&lt;P&gt;Planning a product like Windows involves systematic learning from customers of all types. In terms of planning the release we’ve been working with a wide variety of customers and partners (PC makers, hardware developers, enterprise customers, developers, and more) since the start of the project. We also continue our broad consumer learning through telemetry (Customer Experience Improvement Program), usability studies, and more. One area this blog will soon explore is all the different ways we learn from customers and the marketplace that inform the release.&lt;/P&gt;
&lt;P&gt;We have two significant events for developers and the overall ecosystem around Windows this fall. The Professional Developers Conference (&lt;A href="http://www.microsoft.com/pdc" mce_href="http://www.microsoft.com/pdc"&gt;PDC&lt;/A&gt;) on October 27 and the Windows Hardware Engineering Conference (&lt;A href="http://www.microsoft.com/winhec" mce_href="http://www.microsoft.com/winhec"&gt;WinHEC&lt;/A&gt;) the following week both represent the first venues where we will provide in-depth technical information about Windows 7. This blog will provide context over the next 2+ months with regular posts about the behind the scenes development of the release and continue through the release of the product.&lt;/P&gt;
&lt;P&gt;In leading up to this blog we have seen a lot of discussion in blogs about what Microsoft might be trying to accomplish by maintaining a little bit more control over the communication around Windows 7 (some might say that this is a significant understatement). We, as a team, definitely learned some lessons about “disclosure” and how we can all too easily get ahead of ourselves in talking about features before our understanding of them is solid. Our intent with Windows 7 and the pre-release communication is to make sure that we have a reasonable degree of confidence in what we talk about when we do talk. Again, top of mind for us is the responsibility we feel to make sure we are not stressing priorities, churning resource allocations, or causing strategic confusion among the tens of thousands of partners and customers who care deeply and have much invested in the evolution of Windows.&lt;/P&gt;
&lt;P&gt;Related to disclosure is the idea of how we make sure not to set expectations around the release that end up disappointing you—features that don’t make it, claims that don’t stick, or support we don’t provide. Starting from the first days of developing Windows 7, we have committed as a team to “promise and deliver”. That’s our goal—share with you what we’re going to get done, why we’re doing it, and deliver it with high quality and on time.&lt;/P&gt;
&lt;P&gt;We’re excited about this blog. As active bloggers on Microsoft’s intranet we are both looking forward to turning our attention and blogging energies towards the community outside Microsoft. We know the ins and outs of blogging and expect to have fun, provide great information, and also make a few mistakes. We know we’ll misspeak or what we say will be heard differently than we intended. We’re not worried. All we ask is that we have a dialog based on mutual respect and the shared goal of making a great release of Windows 7.&lt;/P&gt;
&lt;P&gt;Our intent is to post “regularly”. We’ll watch the comments and we will definitely participate both in comments and potentially in follow-up posts as required. We will make sure that members of the Windows 7 development team represent themselves as such as well. While we want to keep the dialog out in the open, please feel free to use email to &lt;A href="mailto:steven.sinofsky@microsoft.com" mce_href="mailto:steven.sinofsky@microsoft.com"&gt;steven.sinofsky@microsoft.com&lt;/A&gt; should you wish to. In particular, email is a good way to suggest topics we might have a chance to discuss on the blog.&lt;/P&gt;
&lt;P&gt;With that, we conclude our welcome post and ask you to stay tuned and join us in this dialog about the engineering of Windows 7.&lt;/P&gt;
&lt;P&gt;Steven and Jon&lt;/P&gt;
&lt;P&gt;Please note the availability of this blog in several other languages via the links on the nav pane. These posts are also created by members of our development team and we welcome dialog on these sites as well. We will continue to expand the list in other languages based on feedback.&lt;/P&gt;
&lt;P mce_keep="true"&gt;&amp;nbsp;&lt;/P&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=8867564" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/e7/archive/tags/E7Blog/default.aspx">E7Blog</category></item><item><title>Guidelines on Comments </title><link>http://blogs.msdn.com/e7/archive/2008/08/14/comments.aspx</link><pubDate>Thu, 14 Aug 2008 18:59:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8867180</guid><dc:creator>e7blog</dc:creator><slash:comments>97</slash:comments><comments>http://blogs.msdn.com/e7/comments/8867180.aspx</comments><wfw:commentRss>http://blogs.msdn.com/e7/commentrss.aspx?PostID=8867180</wfw:commentRss><description>&lt;P&gt;As the community participates in the E7 blog, we want to offer some guidelines on how we are going handle comments in general.&amp;nbsp; Our primary goal is for this to be a place for open discussion about Windows Engineering, so we don’t want to have lots of overhead and process.&lt;/P&gt;
&lt;P&gt;We love comments.&amp;nbsp; We know everyone on the Windows team will be watching for comments and is looking forward to the dialog.&amp;nbsp; We will work to make sure that Microsoft employees represents themselves as such, especially if they work on Windows.&lt;/P&gt;
&lt;P&gt;Things we want to see in comments:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Lots of good interesting responses on&amp;nbsp;Windows and the posts on E7Blog&lt;/LI&gt;
&lt;LI&gt;Keep it on topic &lt;/LI&gt;
&lt;LI&gt;Keep it respectful &lt;/LI&gt;
&lt;LI&gt;Keep it fun&lt;/LI&gt;&lt;/UL&gt;
&lt;P mce_keep="true"&gt;Things that will get comments edited/deleted: &lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;DIV mce_keep="true"&gt;Offensive or abusive language or behavior&lt;/DIV&gt;&lt;/LI&gt;
&lt;LI&gt;
&lt;DIV mce_keep="true"&gt;Misrepresentation (i.e., claiming to be somebody you're not) - if you don't want to use your real name, that's fine, as long as your "handle" isn't offensive, abusive, or misrepresentative&lt;/DIV&gt;&lt;/LI&gt;
&lt;LI&gt;
&lt;DIV mce_keep="true"&gt;&lt;BR&gt;Blog-spam of any kind &lt;/DIV&gt;&lt;/LI&gt;&lt;/UL&gt;
&lt;P&gt;We hope these rules will keep the discussion lively and on topic.&amp;nbsp; &lt;/P&gt;
&lt;P&gt;Steven and Jon&lt;/P&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=8867180" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/e7/archive/tags/E7Blog/default.aspx">E7Blog</category></item></channel></rss>