fes' WebLog

Introduction

Now that I've posted something, it is probably worth introducing who I am.  My name is Frank Swiderski, and I've been with Microsoft for about two years now.  Prior to that, I worked for the security consulting firm @stake, Inc.  For the past four years, I've worked in commercial software security.  This includes your standard security auditing and design sorts of activities:  penetration testing, code review, tool creation, of course threat modeling, and so on.  Before @stake, I was employed by the Department of Defense (both as a civilian and a contractor) for about three years, where I also did some security work.

If my name is at all familiar, it could be because:

  • You used @stake WebProxy 1.0 (I was the primary developer on this).
  • You've tried out the Threat Modeling Tool from the downloads area at microsoft.com (I was also the developer on this).
  • You ordered the Threat Modeling book from MSPress (I was co-author).
  • You've seen my very unfortunate page on the Texas A&M OS/2 users' group web site (http://os2www.tamu.edu/os2/systems/frank.html).  I really wish someone would take that down.  :)

That's the summary.  The bits and pieces can be filled in with google or a small bit of social engineering work.

This posting is provided "AS IS" with no warranties, and confers no rights.

 

 

Published Thursday, July 01, 2004 11:15 AM by fes

Comments

 

Robert Hurlbut's .Net Blog said:

July 1, 2004 2:31 PM
 

Robert Hurlbut's .Net Blog said:

July 1, 2004 2:39 PM
 

Dominick said:

Hi Frank,

in fact - i regularly use webproxy for penetration testing. very nice tool!

see you on windev - i am doing a talk on penetration testing there - and yes - i will show webproxy :)

bye
dominick
July 1, 2004 12:54 PM
 

Introduction said:

November 27, 2007 10:41 PM
Anonymous comments are disabled

© 2009 Microsoft Corporation. All rights reserved. Terms of Use  |  Trademarks  |  Privacy Statement
Microsoft
Page view tracker