<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.msdn.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Georgeo Pulikkathara's Microsoft Blog : trustworthy computing</title><link>http://blogs.msdn.com/georgeop/archive/tags/trustworthy+computing/default.aspx</link><description>Tags: trustworthy computing</description><dc:language>en-US</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>Microsoft Trustworthy Developer Content Strategy</title><link>http://blogs.msdn.com/georgeop/archive/2008/07/24/microsoft-trustworthy-developer-content-strategy.aspx</link><pubDate>Thu, 24 Jul 2008 10:29:07 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8768958</guid><dc:creator>Georgeo Pulikkathara</dc:creator><slash:comments>1</slash:comments><comments>http://blogs.msdn.com/georgeop/comments/8768958.aspx</comments><wfw:commentRss>http://blogs.msdn.com/georgeop/commentrss.aspx?PostID=8768958</wfw:commentRss><wfw:comment>http://blogs.msdn.com/georgeop/rsscomments.aspx?PostID=8768958</wfw:comment><description>&lt;div class="wlWriterSmartContent" id="scid:0767317B-992E-4b12-91E0-4F059A8CECA8:7b6d5788-e809-4157-a36a-8611f3d5b334" style="padding-right: 0px; display: inline; padding-left: 0px; padding-bottom: 0px; margin: 0px; padding-top: 0px"&gt;Technorati Tags: &lt;a href="http://technorati.com/tags/developer%20content%20strategy" rel="tag"&gt;developer content strategy&lt;/a&gt;,&lt;a href="http://technorati.com/tags/privacy" rel="tag"&gt;privacy&lt;/a&gt;,&lt;a href="http://technorati.com/tags/security" rel="tag"&gt;security&lt;/a&gt;&lt;/div&gt;  &lt;p&gt;I was at my Vice President's (Scott Charney) all hands meeting last month. Scott was talking about the need to discuss online safety and Green IT to IT Pros and developers. I was taking some notes and &lt;a href="http://en.wikipedia.org/wiki/Hierarchy_of_needs"&gt;Maslow's Hierarchy of Needs&lt;/a&gt; pyramid came to mind. &lt;/p&gt;  &lt;p&gt;I thought of what Scott was saying and realized that there was a order to what we need to communicate and drive awareness for. Before we can talk about data privacy to developers and IT Professionals, it was necessary to ensure that the customers platform and applications were secure. Only then can you even think of approaching data privacy. &lt;/p&gt;  &lt;p&gt;If an ISV or a corporate development team is to consider data privacy as a requirement, then Security is mandatory. If you're a ISV or a independent software vendor, then you're going to have to answer the questions to your customers who are going to ask you the obvious question, &amp;quot;Am I safe online?&amp;quot;. &lt;/p&gt;  &lt;p&gt;Online Safety is comprised of Privacy and Security. Let's say you want to provide online safety to your customers who buy your software. You'll probably want to ensure that there is legislation/compliance in place to drive the online safety to protect the customer as well as independent software vendors to limit your liability when you've taken the time and due diligence to ensure your application development efforts coincide with the Microsoft Development Lifecycle.&lt;/p&gt;  &lt;p&gt;&lt;a href="http://blogs.msdn.com/blogfiles/georgeop/WindowsLiveWriter/8ff4540558db_407/image_2.png"&gt;&lt;img style="border-top-width: 0px; border-left-width: 0px; border-bottom-width: 0px; border-right-width: 0px" height="299" alt="image" src="http://blogs.msdn.com/blogfiles/georgeop/WindowsLiveWriter/8ff4540558db_407/image_thumb.png" width="464" border="0" /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;The way we drive awareness and provide privacy and security for customers is by ensuring that independent software vendors are utilizing the &lt;a href="http://msdn.microsoft.com/en-us/security/cc448177.aspx"&gt;Microsoft SDL&lt;/a&gt; in their software development efforts along with organization that expose customer data through online banking portals, or online account access.&lt;/p&gt;  &lt;p&gt;&lt;a href="http://blogs.msdn.com/blogfiles/georgeop/WindowsLiveWriter/8ff4540558db_407/image_4.png"&gt;&lt;img style="border-top-width: 0px; border-left-width: 0px; border-bottom-width: 0px; border-right-width: 0px" height="307" alt="image" src="http://blogs.msdn.com/blogfiles/georgeop/WindowsLiveWriter/8ff4540558db_407/image_thumb_1.png" width="470" border="0" /&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=8768958" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/georgeop/archive/tags/Developer+Security/default.aspx">Developer Security</category><category domain="http://blogs.msdn.com/georgeop/archive/tags/Security+content/default.aspx">Security content</category><category domain="http://blogs.msdn.com/georgeop/archive/tags/trustworthy+computing/default.aspx">trustworthy computing</category><category domain="http://blogs.msdn.com/georgeop/archive/tags/privacy/default.aspx">privacy</category><category domain="http://blogs.msdn.com/georgeop/archive/tags/Security+Development+Lifecycle+_2800_SDL_2900_+Model/default.aspx">Security Development Lifecycle (SDL) Model</category><category domain="http://blogs.msdn.com/georgeop/archive/tags/Green/default.aspx">Green</category></item><item><title>TechEd 2008 is coming!</title><link>http://blogs.msdn.com/georgeop/archive/2008/04/30/teched-2008-is-coming.aspx</link><pubDate>Wed, 30 Apr 2008 23:28:12 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8444814</guid><dc:creator>Georgeo Pulikkathara</dc:creator><slash:comments>1</slash:comments><comments>http://blogs.msdn.com/georgeop/comments/8444814.aspx</comments><wfw:commentRss>http://blogs.msdn.com/georgeop/commentrss.aspx?PostID=8444814</wfw:commentRss><wfw:comment>http://blogs.msdn.com/georgeop/rsscomments.aspx?PostID=8444814</wfw:comment><description>&lt;p&gt;Are you going to TechEd 2008? If so, please stop by our Security Development Lifecycle booth and chat with us about how you plan for security and threat modeling in your application design and development. &lt;/p&gt;  &lt;p&gt;&lt;a href="http://www.microsoft.com/events/teched2008/default.mspx"&gt;Microsoft TechEd 2008 Website&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;In the mean time check out&amp;#160; Adam's post on SDL and threat modeling. He's attached a PDF of his slides from his presentation at Toorcon last weekend.&lt;/p&gt;  &lt;p&gt;&lt;a href="http://blogs.msdn.com/sdl/archive/2008/04/24/sdl-threat-modeling-toorcon.aspx"&gt;Security Development Lifecycle Blog&lt;/a&gt;&lt;/p&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=8444814" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/georgeop/archive/tags/Developer+Security/default.aspx">Developer Security</category><category domain="http://blogs.msdn.com/georgeop/archive/tags/trustworthy+computing/default.aspx">trustworthy computing</category><category domain="http://blogs.msdn.com/georgeop/archive/tags/Security+Development+Lifecycle+_2800_SDL_2900_+Model/default.aspx">Security Development Lifecycle (SDL) Model</category></item><item><title>Microsoft device helps police pluck evidence from cyberscene of crime</title><link>http://blogs.msdn.com/georgeop/archive/2008/04/29/microsoft-device-helps-police-pluck-evidence-from-cyberscene-of-crime.aspx</link><pubDate>Tue, 29 Apr 2008 20:22:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8438402</guid><dc:creator>Georgeo Pulikkathara</dc:creator><slash:comments>1</slash:comments><comments>http://blogs.msdn.com/georgeop/comments/8438402.aspx</comments><wfw:commentRss>http://blogs.msdn.com/georgeop/commentrss.aspx?PostID=8438402</wfw:commentRss><wfw:comment>http://blogs.msdn.com/georgeop/rsscomments.aspx?PostID=8438402</wfw:comment><description>&lt;P&gt;What's Microsoft doing to help fight cyber crime? Check out this &lt;A href="http://seattletimes.nwsource.com/html/microsoft/2004379751_msftlaw29.html" mce_href="http://seattletimes.nwsource.com/html/microsoft/2004379751_msftlaw29.html"&gt;article&lt;/A&gt; from the Seattle Times. Here's an excerpt...&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;"....Microsoft has developed a small plug-in device that investigators can use to quickly extract forensic data from computers that may have been used in crimes.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;The COFEE, which stands for Computer Online Forensic Evidence Extractor, is a USB "thumb drive" that was quietly distributed to a handful of law-enforcement agencies last June. Microsoft General Counsel Brad Smith described its use to the 350 law-enforcement experts attending a company conference Monday.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;The device contains 150 commands that can dramatically cut the time it takes to gather digital evidence, which is becoming more important in real-world crime, as well as cyber&lt;/EM&gt;&lt;EM&gt;crime. It can decrypt passwords and analyze a computer's Internet activity, as well as data stored in the computer.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;It also eliminates the need to seize a computer itself, which typically involves disconnecting from a network, turning off the power and potentially losing data. Instead, the investigator can scan for evidence on site.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;More than 2,000 officers in 15 countries, including Poland, the Philippines, Germany, New Zealand and the United States, are using the device, which Microsoft provides free......"&lt;/EM&gt;&lt;/P&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=8438402" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/georgeop/archive/tags/trustworthy+computing/default.aspx">trustworthy computing</category></item><item><title>How Do I: Export and Import Certificates?</title><link>http://blogs.msdn.com/georgeop/archive/2008/04/24/how-do-i-export-and-import-certificates.aspx</link><pubDate>Fri, 25 Apr 2008 09:22:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8423480</guid><dc:creator>Georgeo Pulikkathara</dc:creator><slash:comments>1</slash:comments><comments>http://blogs.msdn.com/georgeop/comments/8423480.aspx</comments><wfw:commentRss>http://blogs.msdn.com/georgeop/commentrss.aspx?PostID=8423480</wfw:commentRss><wfw:comment>http://blogs.msdn.com/georgeop/rsscomments.aspx?PostID=8423480</wfw:comment><description>&lt;P&gt;We've got a series of short how to videos at the &lt;A href="http://msdn.microsoft.com/security" mce_href="http://msdn.microsoft.com/security"&gt;msdn security developer center&lt;/A&gt; that provides you quick overviews on topics such as &lt;A href="http://msdn2.microsoft.com/en-us/security/cc424865.aspx" mce_href="http://msdn2.microsoft.com/en-us/security/cc424865.aspx"&gt;how to import/export certificates&lt;/A&gt;, and &lt;A href="http://msdn2.microsoft.com/en-us/security/cc424864.aspx" mce_href="http://msdn2.microsoft.com/en-us/security/cc424864.aspx"&gt;how to get started with encryption&lt;/A&gt;. by Lamees Ayman.&lt;/P&gt;
&lt;P&gt;Let us know what you think of these videos. Helpful, too basic, or just right. I'm thinking of making more videos like this for our developer community to consume.&lt;/P&gt;
&lt;DIV class=wlWriterSmartContent id=scid:0767317B-992E-4b12-91E0-4F059A8CECA8:47f1943e-0295-4fef-a41e-d7ad09c1f6e2 style="PADDING-RIGHT: 0px; DISPLAY: inline; PADDING-LEFT: 0px; PADDING-BOTTOM: 0px; MARGIN: 0px; PADDING-TOP: 0px"&gt;Technorati Tags: &lt;A href="http://technorati.com/tags/developer%20security%20videos" rel=tag mce_href="http://technorati.com/tags/developer%20security%20videos"&gt;developer security videos&lt;/A&gt;&lt;/DIV&gt;
&lt;P&gt;Thanks, &lt;/P&gt;
&lt;P&gt;George&lt;/P&gt;
&lt;P&gt;&lt;A href="mailto:georgeop@microsoft.com" mce_href="mailto:georgeop@microsoft.com"&gt;georgeop@microsoft.com&lt;/A&gt; or (425) 707-6912&lt;/P&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=8423480" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/georgeop/archive/tags/Developer+Security/default.aspx">Developer Security</category><category domain="http://blogs.msdn.com/georgeop/archive/tags/Security+content/default.aspx">Security content</category><category domain="http://blogs.msdn.com/georgeop/archive/tags/trustworthy+computing/default.aspx">trustworthy computing</category><category domain="http://blogs.msdn.com/georgeop/archive/tags/Security+Development+Lifecycle+_2800_SDL_2900_+Model/default.aspx">Security Development Lifecycle (SDL) Model</category></item><item><title>George's Blog</title><link>http://blogs.msdn.com/georgeop/archive/2008/04/24/george-s-blog.aspx</link><pubDate>Thu, 24 Apr 2008 23:19:26 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8422662</guid><dc:creator>Georgeo Pulikkathara</dc:creator><slash:comments>1</slash:comments><comments>http://blogs.msdn.com/georgeop/comments/8422662.aspx</comments><wfw:commentRss>http://blogs.msdn.com/georgeop/commentrss.aspx?PostID=8422662</wfw:commentRss><wfw:comment>http://blogs.msdn.com/georgeop/rsscomments.aspx?PostID=8422662</wfw:comment><description>&lt;blockquote&gt;   &lt;p&gt;&lt;a href="http://blogs.msdn.com/blogfiles/georgeop/WindowsLiveWriter/GeorgesBlog_BB55/48259946I_2.jpg"&gt;&lt;img style="border-right: 0px; border-top: 0px; border-left: 0px; border-bottom: 0px" height="184" alt="48259946I" src="http://blogs.msdn.com/blogfiles/georgeop/WindowsLiveWriter/GeorgesBlog_BB55/48259946I_thumb.jpg" width="244" border="0" /&gt;&lt;/a&gt; &lt;/p&gt;    &lt;p&gt;You may remember me from my days at &lt;a href="http://blogs.msdn.com/msdnwebcasts"&gt;MSDN Webcasts&lt;/a&gt; or from when I was managing the worldwide &lt;a href="http://blogs.msdn.com/mcp"&gt;Microsoft Certified Professional Program&lt;/a&gt; at Microsoft Learning. &lt;/p&gt;    &lt;p&gt;Well I'm over here now with Jed Pickel and Jacqueline Beauchere to get the word out to our developer communities on all that Microsoft is doing around security and privacy for our customers. &lt;/p&gt;    &lt;p&gt;We're building some great security how to content that will be featured at &lt;a href="http://www.microsoft.com/security"&gt;http://www.microsoft.com/security&lt;/a&gt; as well as at &lt;a href="http://msdn.microsoft.com/security"&gt;http://msdn.microsoft.com/security&lt;/a&gt; to help you make sense of what to do when addressing security concerns with your application development efforts on Microsoft tools and technologies.&lt;/p&gt;    &lt;p&gt;Warmest Regards,&lt;/p&gt;    &lt;p&gt;Georgeo X. Pulikkathara&lt;/p&gt;    &lt;p&gt;&lt;a href="mailto:georgeop@microsoft.com"&gt;georgeop@microsoft.com&lt;/a&gt; (425) 707-6912&lt;/p&gt;&lt;/blockquote&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=8422662" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/georgeop/archive/tags/Developer+Security/default.aspx">Developer Security</category><category domain="http://blogs.msdn.com/georgeop/archive/tags/Security+content/default.aspx">Security content</category><category domain="http://blogs.msdn.com/georgeop/archive/tags/trustworthy+computing/default.aspx">trustworthy computing</category></item></channel></rss>