<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.msdn.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Eric Jarvi : security</title><link>http://blogs.msdn.com/ejarvi/archive/tags/security/default.aspx</link><description>Tags: security</description><dc:language>en-US</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>Password Complexity</title><link>http://blogs.msdn.com/ejarvi/archive/2009/10/16/password-complexity.aspx</link><pubDate>Fri, 16 Oct 2009 19:46:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9908352</guid><dc:creator>ejarvi</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.msdn.com/ejarvi/comments/9908352.aspx</comments><wfw:commentRss>http://blogs.msdn.com/ejarvi/commentrss.aspx?PostID=9908352</wfw:commentRss><description>&lt;P&gt;Alan Myrvold has a new post on the Office 2010 engineering blog covering password complexity and related functionality in Office:&lt;/P&gt;
&lt;P&gt;&lt;A href="http://blogs.technet.com/office2010/archive/2009/10/16/enabling-password-rules-for-office-2010.aspx"&gt;http://blogs.technet.com/office2010/archive/2009/10/16/enabling-password-rules-for-office-2010.aspx&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;IMG style="WIDTH: 349px; HEIGHT: 287px" src="http://blogs.technet.com/blogfiles/office2010/WindowsLiveWriter/EnablingpasswordrulesforOffice2010_F993/image_thumb_1.png" width=349 height=287 mce_src="http://blogs.technet.com/blogfiles/office2010/WindowsLiveWriter/EnablingpasswordrulesforOffice2010_F993/image_thumb_1.png"&gt;&lt;/P&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=9908352" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/ejarvi/archive/tags/security/default.aspx">security</category></item><item><title>Risk Management</title><link>http://blogs.msdn.com/ejarvi/archive/2009/03/13/risk-management.aspx</link><pubDate>Fri, 13 Mar 2009 20:38:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9473487</guid><dc:creator>ejarvi</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.msdn.com/ejarvi/comments/9473487.aspx</comments><wfw:commentRss>http://blogs.msdn.com/ejarvi/commentrss.aspx?PostID=9473487</wfw:commentRss><description>My first article on the topic of security testing and risk management&amp;nbsp;is now published in the March 2009 issue of Testing Experience magazine, pages 28-30. &lt;BR&gt;&lt;BR&gt;&lt;A href="http://www.testingexperience.com/subscribe.php" mce_href="http://www.testingexperience.com/subscribe.php"&gt;http://www.testingexperience.com/subscribe.php&lt;/A&gt; &lt;BR&gt;(free online subscription takes you to PDF download) &lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=9473487" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/ejarvi/archive/tags/testing/default.aspx">testing</category><category domain="http://blogs.msdn.com/ejarvi/archive/tags/security/default.aspx">security</category></item><item><title>Office Security Team</title><link>http://blogs.msdn.com/ejarvi/archive/2008/07/18/office-security.aspx</link><pubDate>Fri, 18 Jul 2008 22:13:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8751979</guid><dc:creator>ejarvi</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.msdn.com/ejarvi/comments/8751979.aspx</comments><wfw:commentRss>http://blogs.msdn.com/ejarvi/commentrss.aspx?PostID=8751979</wfw:commentRss><description>&lt;P&gt;&lt;EM&gt;The Office security team typically targets memory-corruption bugs in the software like buffer overruns, integer overruns, and format strings...&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="http://www.darkreading.com/document.asp?doc_id=159305" mce_href="http://www.darkreading.com/document.asp?doc_id=159305"&gt;http://www.darkreading.com/document.asp?doc_id=159305&lt;/A&gt;&lt;/P&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=8751979" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/ejarvi/archive/tags/testing/default.aspx">testing</category><category domain="http://blogs.msdn.com/ejarvi/archive/tags/security/default.aspx">security</category></item><item><title>Security &amp; Perf Videos</title><link>http://blogs.msdn.com/ejarvi/archive/2007/11/26/security-perf-videos.aspx</link><pubDate>Mon, 26 Nov 2007 23:32:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:6534445</guid><dc:creator>ejarvi</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.msdn.com/ejarvi/comments/6534445.aspx</comments><wfw:commentRss>http://blogs.msdn.com/ejarvi/commentrss.aspx?PostID=6534445</wfw:commentRss><description>&lt;P&gt;J.D. Meier has posted a decent index of videos covering performance testing, ASP.NET 2.0, and VSTS: &lt;/P&gt;
&lt;P&gt;&lt;A href="http://blogs.msdn.com/jmeier/archive/2007/11/22/videos-security-performance-testing-and-visual-studio-team-system.aspx" mce_href="http://blogs.msdn.com/jmeier/archive/2007/11/22/videos-security-performance-testing-and-visual-studio-team-system.aspx"&gt;http://blogs.msdn.com/jmeier/archive/2007/11/22/videos-security-performance-testing-and-visual-studio-team-system.aspx&lt;/A&gt;&lt;/P&gt;
&lt;P mce_keep="true"&gt;&amp;nbsp;&lt;/P&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=6534445" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/ejarvi/archive/tags/testing/default.aspx">testing</category><category domain="http://blogs.msdn.com/ejarvi/archive/tags/security/default.aspx">security</category><category domain="http://blogs.msdn.com/ejarvi/archive/tags/development/default.aspx">development</category><category domain="http://blogs.msdn.com/ejarvi/archive/tags/performance/default.aspx">performance</category><category domain="http://blogs.msdn.com/ejarvi/archive/tags/VSTS+Tips/default.aspx">VSTS Tips</category></item><item><title>Information Assurance</title><link>http://blogs.msdn.com/ejarvi/archive/2007/10/27/information-assurance.aspx</link><pubDate>Sun, 28 Oct 2007 06:47:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:5728450</guid><dc:creator>ejarvi</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.msdn.com/ejarvi/comments/5728450.aspx</comments><wfw:commentRss>http://blogs.msdn.com/ejarvi/commentrss.aspx?PostID=5728450</wfw:commentRss><description>&lt;P&gt;&lt;STRONG&gt;The Unintended Consequences of the Information Age Lecture Series: Our Infrastructures: Online and Vulnerable?&lt;/STRONG&gt; &lt;/P&gt;
&lt;P&gt;Jointly sponsored by The Center for Information Assurance and Cybersecurity, UW-INSER, the MS Program in Strategic Planning for Critical Infrastucture, Pacific Northwest National Laboratory and the Information School, this series provides a compelling case for increased research in cybersecurity as related to critical infrastructure.&lt;/P&gt;
&lt;P&gt;Part 1 will air on UWTV at the following times:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Monday October 29 at 6pm&lt;/LI&gt;
&lt;LI&gt;Wed Oct 31 at 11pm&lt;/LI&gt;
&lt;LI&gt;Thurs November 1 at 10:30am and 7pm&lt;/LI&gt;
&lt;LI&gt;Friday Nov 2 at 4pm&lt;/LI&gt;
&lt;LI&gt;Sunday Nov 4 at 3pm&amp;nbsp;&amp;nbsp;&lt;/LI&gt;&lt;/UL&gt;
&lt;P&gt;Future airdates will be posted later on the UWTV website:&lt;BR&gt;&lt;A href="http://www.uwtv.org/programs/displayevent.aspx?rID=20354&amp;amp;fID=2095" target=_blank mce_href="http://www.uwtv.org/programs/displayevent.aspx?rID=20354&amp;amp;fID=2095"&gt;http://www.uwtv.org/programs/displayevent.aspx?rID=20354&amp;amp;fID=2095&lt;/A&gt;&lt;BR&gt;&lt;/P&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=5728450" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/ejarvi/archive/tags/testing/default.aspx">testing</category><category domain="http://blogs.msdn.com/ejarvi/archive/tags/security/default.aspx">security</category><category domain="http://blogs.msdn.com/ejarvi/archive/tags/noise/default.aspx">noise</category></item><item><title>Patterns &amp; Practices Security Videos</title><link>http://blogs.msdn.com/ejarvi/archive/2007/03/26/patterns-practices-security-videos.aspx</link><pubDate>Mon, 26 Mar 2007 17:53:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:1952653</guid><dc:creator>ejarvi</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.msdn.com/ejarvi/comments/1952653.aspx</comments><wfw:commentRss>http://blogs.msdn.com/ejarvi/commentrss.aspx?PostID=1952653</wfw:commentRss><description>&lt;P&gt;"Click Here"&lt;/P&gt;
&lt;P&gt;&lt;A href="http://blogs.msdn.com/jmeier/archive/2007/03/24/patterns-practices-security-videos.aspx"&gt;http://blogs.msdn.com/jmeier/archive/2007/03/24/patterns-practices-security-videos.aspx&lt;/A&gt;&lt;/P&gt;
&lt;P mce_keep="true"&gt;&amp;nbsp;&lt;/P&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=1952653" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/ejarvi/archive/tags/testing/default.aspx">testing</category><category domain="http://blogs.msdn.com/ejarvi/archive/tags/security/default.aspx">security</category><category domain="http://blogs.msdn.com/ejarvi/archive/tags/development/default.aspx">development</category></item><item><title>Michael Howard on the Silver Bullet Security Podcast</title><link>http://blogs.msdn.com/ejarvi/archive/2006/09/29/777607.aspx</link><pubDate>Sat, 30 Sep 2006 03:19:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:777607</guid><dc:creator>ejarvi</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.msdn.com/ejarvi/comments/777607.aspx</comments><wfw:commentRss>http://blogs.msdn.com/ejarvi/commentrss.aspx?PostID=777607</wfw:commentRss><description>&lt;P&gt;Here's the link...&lt;/P&gt;
&lt;P&gt;&lt;A href="http://www.cigital.com/silverbullet/show-006/"&gt;http://www.cigital.com/silverbullet/show-006/&lt;/A&gt;&lt;/P&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=777607" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/ejarvi/archive/tags/testing/default.aspx">testing</category><category domain="http://blogs.msdn.com/ejarvi/archive/tags/security/default.aspx">security</category><category domain="http://blogs.msdn.com/ejarvi/archive/tags/development/default.aspx">development</category></item><item><title>CERT Secure Coding Standards </title><link>http://blogs.msdn.com/ejarvi/archive/2006/09/27/773965.aspx</link><pubDate>Wed, 27 Sep 2006 19:22:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:773965</guid><dc:creator>ejarvi</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.msdn.com/ejarvi/comments/773965.aspx</comments><wfw:commentRss>http://blogs.msdn.com/ejarvi/commentrss.aspx?PostID=773965</wfw:commentRss><description>&lt;P&gt;"This web site exists to support the development of secure coding standards for commonly used programming languages such as C and C++. " &lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.securecoding.cert.org/confluence/display/seccode/CERT+Secure+Coding+Standards"&gt;https://www.securecoding.cert.org/confluence/display/seccode/CERT+Secure+Coding+Standards&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=773965" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/ejarvi/archive/tags/security/default.aspx">security</category><category domain="http://blogs.msdn.com/ejarvi/archive/tags/development/default.aspx">development</category></item><item><title>MSRC Stories</title><link>http://blogs.msdn.com/ejarvi/archive/2006/08/09/693686.aspx</link><pubDate>Thu, 10 Aug 2006 00:03:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:693686</guid><dc:creator>ejarvi</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.msdn.com/ejarvi/comments/693686.aspx</comments><wfw:commentRss>http://blogs.msdn.com/ejarvi/commentrss.aspx?PostID=693686</wfw:commentRss><description>&lt;P&gt;This article has an interesting peek into life at the Microsoft Security Response Center:&lt;/P&gt;
&lt;P&gt;&lt;A href="http://redmondmag.com/features/article.asp?EditorialsID=616"&gt;http://redmondmag.com/features/article.asp?EditorialsID=616&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;"I'm at the shop and over the radio I hear: 'The Internet was taken down today by a worm affecting SQL Server,'" recalls Toulouse. "That was the first I heard of it."&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;A few moments later, Toulouse was racing toward Redmond, the interior of his Jeep still torn open from the half-finished installation.&lt;BR&gt;&lt;/EM&gt;&lt;/P&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=693686" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/ejarvi/archive/tags/security/default.aspx">security</category></item><item><title>port 25 is open on port 80</title><link>http://blogs.msdn.com/ejarvi/archive/2006/07/07/659019.aspx</link><pubDate>Fri, 07 Jul 2006 17:03:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:659019</guid><dc:creator>ejarvi</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.msdn.com/ejarvi/comments/659019.aspx</comments><wfw:commentRss>http://blogs.msdn.com/ejarvi/commentrss.aspx?PostID=659019</wfw:commentRss><description>&lt;P&gt;Here's an interesting&amp;nbsp;blog to watch courtesy the Open Source Software Lab @ Microsoft -&amp;nbsp; &lt;A href="http://port25.technet.com/"&gt;http://port25.technet.com/&lt;/A&gt;&amp;nbsp;(for RSS - &lt;A href="http://port25.technet.com/rss.aspx"&gt;http://port25.technet.com/rss.aspx&lt;/A&gt;&amp;nbsp;)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=659019" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/ejarvi/archive/tags/security/default.aspx">security</category><category domain="http://blogs.msdn.com/ejarvi/archive/tags/development/default.aspx">development</category><category domain="http://blogs.msdn.com/ejarvi/archive/tags/noise/default.aspx">noise</category></item><item><title>bluehat links</title><link>http://blogs.msdn.com/ejarvi/archive/2006/03/21/557293.aspx</link><pubDate>Wed, 22 Mar 2006 01:52:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:557293</guid><dc:creator>ejarvi</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.msdn.com/ejarvi/comments/557293.aspx</comments><wfw:commentRss>http://blogs.msdn.com/ejarvi/commentrss.aspx?PostID=557293</wfw:commentRss><description>&lt;P&gt;Some good links if you want to check out some of the speakers and topics addressed at the last Microsoft bluehat conference:&lt;/P&gt;
&lt;P&gt;&lt;A href="http://blogs.technet.com/bluehat/archive/2006/03/21/422707.aspx"&gt;http://blogs.technet.com/bluehat/archive/2006/03/21/422707.aspx&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=557293" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/ejarvi/archive/tags/security/default.aspx">security</category></item><item><title>running with least privilege</title><link>http://blogs.msdn.com/ejarvi/archive/2005/11/30/498500.aspx</link><pubDate>Wed, 30 Nov 2005 21:45:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:498500</guid><dc:creator>ejarvi</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.msdn.com/ejarvi/comments/498500.aspx</comments><wfw:commentRss>http://blogs.msdn.com/ejarvi/commentrss.aspx?PostID=498500</wfw:commentRss><description>&lt;P&gt;"In the ongoing battle to fight internal and external threats on the corporate desktop, IT staffers may be forgetting one very potent weapon in their arsenal—system lockdown."&amp;nbsp; &lt;A href="http://www.thechannelinsider.com/print_article2/0,1217,a=166172,00.asp"&gt;http://www.thechannelinsider.com/print_article2/0,1217,a=166172,00.asp&lt;/A&gt;
&lt;P&gt;If you care about this type of thing, Aaron Margosis's blog is the place to go: &lt;a href="http://blogs.msdn.com/Aaron_Margosis/"&gt;http://blogs.msdn.com/Aaron_Margosis/&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=498500" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/ejarvi/archive/tags/security/default.aspx">security</category></item><item><title>development related security tools at SecureWorld</title><link>http://blogs.msdn.com/ejarvi/archive/2005/10/19/482860.aspx</link><pubDate>Thu, 20 Oct 2005 03:07:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:482860</guid><dc:creator>ejarvi</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.msdn.com/ejarvi/comments/482860.aspx</comments><wfw:commentRss>http://blogs.msdn.com/ejarvi/commentrss.aspx?PostID=482860</wfw:commentRss><description>&lt;P&gt;There were two vendors at &lt;A href="http://www.secureworldexpo.com/"&gt;SecureWorld &lt;/A&gt;conference today in Bellevue that might be worth checking out if you are looking for developer/tester related security products.&amp;nbsp;&amp;nbsp;They&amp;nbsp;should also be there tomorrow as well -&amp;nbsp;free registration if you are just walking the booths.&amp;nbsp; &lt;A href="http://www.securityinnovation.com"&gt;Security Innovation&lt;/A&gt; sells a fault injection tool called Holodeck and &lt;A href="http://www.spidynamics.com"&gt;SPI Dynamics&lt;/A&gt; sells a tool called WebInspect that has VSTS integration in beta right now.&amp;nbsp; &lt;/P&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=482860" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/ejarvi/archive/tags/security/default.aspx">security</category><category domain="http://blogs.msdn.com/ejarvi/archive/tags/noise/default.aspx">noise</category></item><item><title>Reducing Browser Privileges</title><link>http://blogs.msdn.com/ejarvi/archive/2005/10/05/477421.aspx</link><pubDate>Wed, 05 Oct 2005 20:41:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:477421</guid><dc:creator>ejarvi</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.msdn.com/ejarvi/comments/477421.aspx</comments><wfw:commentRss>http://blogs.msdn.com/ejarvi/commentrss.aspx?PostID=477421</wfw:commentRss><description>&lt;P&gt;"a simple yet little-known approach exists for users to avoid many of these vulnerabilities in any web browser"&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;A href="http://www.securityfocus.com/infocus/1848"&gt;http://www.securityfocus.com/infocus/1848&lt;/A&gt;&lt;/P&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=477421" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/ejarvi/archive/tags/security/default.aspx">security</category><category domain="http://blogs.msdn.com/ejarvi/archive/tags/noise/default.aspx">noise</category></item><item><title>leastprivilege.com</title><link>http://blogs.msdn.com/ejarvi/archive/2005/09/02/459703.aspx</link><pubDate>Fri, 02 Sep 2005 07:35:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:459703</guid><dc:creator>ejarvi</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.msdn.com/ejarvi/comments/459703.aspx</comments><wfw:commentRss>http://blogs.msdn.com/ejarvi/commentrss.aspx?PostID=459703</wfw:commentRss><description>&lt;P&gt;Thank to .NET Delirium for pointing out this site:&lt;/P&gt;
&lt;P&gt;&lt;a href="http://blogs.msdn.com/gduthie/archive/2005/09/01/459576.aspx"&gt;http://blogs.msdn.com/gduthie/archive/2005/09/01/459576.aspx&lt;/A&gt;&lt;/P&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=459703" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/ejarvi/archive/tags/security/default.aspx">security</category><category domain="http://blogs.msdn.com/ejarvi/archive/tags/development/default.aspx">development</category><category domain="http://blogs.msdn.com/ejarvi/archive/tags/noise/default.aspx">noise</category></item></channel></rss>