<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.msdn.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Jonathan Hardwick : Security</title><link>http://blogs.msdn.com/jonathanh/archive/tags/Security/default.aspx</link><description>Tags: Security</description><dc:language>en-US</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>Aaaaand, we're back</title><link>http://blogs.msdn.com/jonathanh/archive/2006/01/23/aaaaand-we-re-back.aspx</link><pubDate>Tue, 24 Jan 2006 10:21:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:516677</guid><dc:creator>jonathanh</dc:creator><slash:comments>2</slash:comments><comments>http://blogs.msdn.com/jonathanh/comments/516677.aspx</comments><wfw:commentRss>http://blogs.msdn.com/jonathanh/commentrss.aspx?PostID=516677</wfw:commentRss><wfw:comment>http://blogs.msdn.com/jonathanh/rsscomments.aspx?PostID=516677</wfw:comment><description>&lt;P&gt;I’ll be making lots of updates to the &lt;A href="http://nonadmin.editme.com/" mce_href="http://nonadmin.editme.com/"&gt;nonadmin wiki&lt;/A&gt; this week. Yesterday it was three months’ worth of &lt;A href="http://nonadmin.editme.com/PressArticles" mce_href="http://nonadmin.editme.com/PressArticles"&gt;press articles about running as a non-administrator&lt;/A&gt;, and today it’s two webcasts and two whitepapers for the &lt;A href="http://nonadmin.editme.com/OtherResources" mce_href="http://nonadmin.editme.com/OtherResources"&gt;other resources&lt;/A&gt; page*.&lt;/P&gt;
&lt;P&gt;This is also a way of tricking myself into breaking a month-long backlog of blog topics. When you’ve got so much to choose from that all your energy goes into deciding why you &lt;EM&gt;shouldn’t&lt;/EM&gt; blog a particular topic first… it’s probably easier just to do it.&lt;/P&gt;
&lt;P&gt;*The update includes a new &lt;STRONG&gt;authoritative &lt;/STRONG&gt;white paper about how to start using least-privilege user accounts – so if you’re only going to read one document about LUA, &lt;A title="Applying the Principle of Least Privilege to User Accounts on Windows XP" href="http://go.microsoft.com/fwlink/?linkid=58446" mce_href="http://go.microsoft.com/fwlink/?linkid=58446"&gt;download this&lt;/A&gt;.&lt;/P&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=516677" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/jonathanh/archive/tags/Security/default.aspx">Security</category></item><item><title>More press coverage of NOT running as an administrator</title><link>http://blogs.msdn.com/jonathanh/archive/2005/06/23/more-press-coverage-of-not-running-as-an-administrator.aspx</link><pubDate>Fri, 24 Jun 2005 09:38:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:432139</guid><dc:creator>jonathanh</dc:creator><slash:comments>2</slash:comments><comments>http://blogs.msdn.com/jonathanh/comments/432139.aspx</comments><wfw:commentRss>http://blogs.msdn.com/jonathanh/commentrss.aspx?PostID=432139</wfw:commentRss><wfw:comment>http://blogs.msdn.com/jonathanh/rsscomments.aspx?PostID=432139</wfw:comment><description>&lt;P&gt;&lt;A title='"Planet Ryan, Inc"' href="http://www.planetryan.blogspot.com/" mce_href="http://www.planetryan.blogspot.com/"&gt;Ryan Naraine&lt;/A&gt; has written a nice article for eWeek about &lt;A title="&amp;quot;Users Overlook XP's Non-Admin Security&amp;quot;" href="http://www.eweek.com/article2/0%2C1759%2C1830637%2C00.asp" mce_href="http://www.eweek.com/article2/0%2C1759%2C1830637%2C00.asp"&gt;non-admin security in XP&lt;/A&gt;. He notes that Microsoft will be promoting Least-privileged User Accounts heavily in Longhorn, but that you can enjoy their added security right now – if you know where to look in Windows! &lt;/P&gt;
&lt;P&gt;The article includes commentary from security guru &lt;A href="http://blogs.msdn.com/michael_howard/default.aspx" mce_href="http://blogs.msdn.com/michael_howard/default.aspx"&gt;Michael Howard&lt;/A&gt; about the problems of user education, and a link to my own &lt;A title="Tips for running without Administrator privileges" href="http://nonadmin.editme.com/" mce_href="http://nonadmin.editme.com/"&gt;nonadmin wiki&lt;/A&gt;, where we’ve been gathering tips and best practices for the whole community to use. Most of which came from &lt;A href="http://blogs.msdn.com/aaron_margosis/archive/2005/05/19/420027.aspx" mce_href="http://blogs.msdn.com/aaron_margosis/archive/2005/05/19/420027.aspx"&gt;Aaron Margosis&lt;/A&gt;, of course :)&lt;/P&gt;
&lt;P&gt;Ryan emailed me for comments when he was writing the article, but I bowed out when I heard that he already had Michael’s feedback – Michael is a trained security spokesman, and I definitely am not. So kudos to Ryan for doing a good job of keeping all the information &lt;EM&gt;in&lt;/EM&gt; the article, but me &lt;EM&gt;out&lt;/EM&gt; of it. Definitely a pleasant encounter with the press.&lt;/P&gt;
&lt;P&gt;Mary Jo Foley picked up on the story over at Microsoft Watch (“&lt;A title='"No Need to Wait for Longhorn for LUA"' href="http://www.microsoft-watch.com/article2/0,1995,1830786,00.asp" mce_href="http://www.microsoft-watch.com/article2/0,1995,1830786,00.asp"&gt;No Need to Wait for Longhorn for LUA&lt;/A&gt;”), but in summarizing things for our ADD-prone world, she simplifies a little too far:&lt;/P&gt;
&lt;BLOCKQUOTE dir=ltr style="MARGIN-RIGHT: 0px"&gt;
&lt;P&gt;&lt;EM&gt;The company is making available new tools on a Wiki aimed at Windows users to try to help increase awareness.&lt;/EM&gt;&lt;/P&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;The tools aren’t new, the wiki has nothing to do with Microsoft (especially since it's &lt;A title='Channel 9: "Coolest Microsoft software ever!!!"' href="http://channel9.msdn.com/ShowPost.aspx?PostID=75946#75946" mce_href="http://channel9.msdn.com/ShowPost.aspx?PostID=75946#75946"&gt;powered by Linux&lt;/A&gt;), and I’m not aware of any official effort to raise awareness, but apart from that the sentence is accurate :)&lt;/P&gt;
&lt;P&gt;Oh, and thanks to everyone who noticed! Including &lt;A href="http://spaces.msn.com/members/jackrichins/Blog/cns!1pf8zoXJl1mETDxi_4pEhq5g!275.entry" mce_href="http://spaces.msn.com/members/jackrichins/Blog/cns!1pf8zoXJl1mETDxi_4pEhq5g!275.entry"&gt;Jack Richins&lt;/A&gt;, &lt;A href="http://spaces.msn.com/members/jdanielsmith/Blog/cns!1pRjebUoVh0bNLSJvrecmAEg!297.entry" mce_href="http://spaces.msn.com/members/jdanielsmith/Blog/cns!1pRjebUoVh0bNLSJvrecmAEg!297.entry"&gt;J. Daniel Smith&lt;/A&gt;, &lt;A href="http://www.peterprovost.org/archive/2005/06/23/4089.aspx" mce_href="http://www.peterprovost.org/archive/2005/06/23/4089.aspx"&gt;Peter Provost&lt;/A&gt;, and &lt;A href="http://www.thecave.com/?xml/2005_06_01_archive.xml#111955133743659470" mce_href="http://www.thecave.com/?xml/2005_06_01_archive.xml#111955133743659470"&gt;Kirby Turner&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Category: &lt;A href="http://blogs.msdn.com/jonathanh/archive/category/9234.aspx" mce_href="http://blogs.msdn.com/jonathanh/archive/category/9234.aspx"&gt;Security&lt;/A&gt;&lt;/EM&gt;&lt;/P&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=432139" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/jonathanh/archive/tags/Security/default.aspx">Security</category></item><item><title>Great things are afoot over at Channel 9</title><link>http://blogs.msdn.com/jonathanh/archive/2005/06/07/great-things-are-afoot-over-at-channel-9.aspx</link><pubDate>Wed, 08 Jun 2005 08:51:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:426615</guid><dc:creator>jonathanh</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.msdn.com/jonathanh/comments/426615.aspx</comments><wfw:commentRss>http://blogs.msdn.com/jonathanh/commentrss.aspx?PostID=426615</wfw:commentRss><wfw:comment>http://blogs.msdn.com/jonathanh/rsscomments.aspx?PostID=426615</wfw:comment><description>&lt;P&gt;Another vital resource has sprung up fully-formed on Channel 9 – the &lt;A title="Welcome to the patterns and practices Security Wiki" href="http://channel9.msdn.com/wiki/default.aspx/Channel9.PatternsAndPracticesSecurityWiki" mce_href="http://channel9.msdn.com/wiki/default.aspx/Channel9.PatternsAndPracticesSecurityWiki"&gt;Patterns and Practices Security Wiki&lt;/A&gt; (yes, this is &lt;A href="http://blogs.msdn.com/jonathanh/archive/2005/04/06/406079.aspx" mce_href="http://blogs.msdn.com/jonathanh/archive/2005/04/06/406079.aspx"&gt;yet another Microsoft wiki&lt;/A&gt;). Whether you need to deploy a secure ASP.NET 2.0 application right now, or just have a vague wish to learn some better secure coding practices, bookmark the site. Here’s why:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;The people behind it have &lt;A title="Improving Web Application Security: Threats and Countermeasures" href="http://msdn.microsoft.com/library/default.asp?url=/library/en-us/dnnetsec/html/ThreatCounter.asp" mce_href="http://msdn.microsoft.com/library/default.asp?url=/library/en-us/dnnetsec/html/ThreatCounter.asp"&gt;lots of experience&lt;/A&gt; in the area, and have made it as simple as possible to get started, with an emphasis on concrete checklists and how-tos. 
&lt;LI&gt;Ward Cunningham has given it a once-over – if you don’t know who he is, watch the Channel 9 video of &lt;A title="Ward Cunningham - How did you come up with the idea for the Wiki" href="http://channel9.msdn.com/ShowPost.aspx?PostID=7726#7726" mce_href="http://channel9.msdn.com/ShowPost.aspx?PostID=7726#7726"&gt;Ward discussing how he invented wikis&lt;/A&gt;… 
&lt;LI&gt;As &lt;A title="patterns and practices Security Wiki is now live on Channel9!" href="http://www.securecoder.com/blog/patternsPracticesSecurityWikiIsNowLiveOnChannel9.aspx" mce_href="http://www.securecoder.com/blog/patternsPracticesSecurityWikiIsNowLiveOnChannel9.aspx"&gt;Anil John&lt;/A&gt; says, it’s going to be a “living, working resource”, where the original authors can learn as much from new contributors as vice versa. Or as &lt;A title="Security Wiki" href="http://www.bbrown.info/blogs/bblog/archives/security-wiki.cfm" mce_href="http://www.bbrown.info/blogs/bblog/archives/security-wiki.cfm"&gt;Bill Brown&lt;/A&gt; puts it, “It promises to be updated more regularly than the great &lt;CITE&gt;Patterns and Practices&lt;/CITE&gt; books on the subject” :) 
&lt;LI&gt;Shortly to be linked to from &lt;A title="Microsoft Security Developer Center" href="http://msdn.microsoft.com/security" mce_href="http://msdn.microsoft.com/security"&gt;http://msdn.microsoft.com/security&lt;/A&gt;, thanks to &lt;A href="http://blogs.msdn.com/brianjo/archive/2005/06/07/426577.aspx" mce_href="http://blogs.msdn.com/brianjo/archive/2005/06/07/426577.aspx"&gt;Brian Johnson&lt;/A&gt; (gee, ya think that’ll drive some traffic?)&lt;/LI&gt;&lt;/UL&gt;
&lt;P&gt;It’s also been fun watching it gradually take shape over the past few days, via the “Recent Changes” page on the &lt;A title="Channel 9 Wiki" href="http://channel9.msdn.com/wiki/default.aspx" mce_href="http://channel9.msdn.com/wiki/default.aspx"&gt;Channel 9 wiki&lt;/A&gt;. Whoever user appleberry9 is, they sure put in a lot of late-night work!&lt;/P&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=426615" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/jonathanh/archive/tags/Security/default.aspx">Security</category></item><item><title>Lots of LUA links</title><link>http://blogs.msdn.com/jonathanh/archive/2005/05/19/lots-of-lua-links.aspx</link><pubDate>Thu, 19 May 2005 21:33:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:420098</guid><dc:creator>jonathanh</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.msdn.com/jonathanh/comments/420098.aspx</comments><wfw:commentRss>http://blogs.msdn.com/jonathanh/commentrss.aspx?PostID=420098</wfw:commentRss><wfw:comment>http://blogs.msdn.com/jonathanh/rsscomments.aspx?PostID=420098</wfw:comment><description>&lt;P&gt;&lt;EM&gt;[I originally posted this two weeks ago, but it got lost when they had to roll back the servers, and it doesn't look like the original is coming back anytime soon]&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;I’ve added a bunch of new links to the &lt;A href="http://www.flexwiki.com/" mce_href="http://www.flexwiki.com/"&gt;non-admin wiki&lt;/A&gt;, taken from various blog posts over the past month. Thanks to one and all!&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;“&lt;A href="http://blogs.msdn.com/embedded/archive/2005/04/07/406412.aspx" mce_href="http://blogs.msdn.com/embedded/archive/2005/04/07/406412.aspx"&gt;Longhorn&lt;/A&gt; &lt;A href="http://blogs.msdn.com/embedded/archive/2005/04/07/406412.aspx" mce_href="http://blogs.msdn.com/embedded/archive/2005/04/07/406412.aspx"&gt;LUA Links&lt;/A&gt;” from Andy Allred 
&lt;LI&gt;“&lt;A href="http://adminfoo.net/?q=node/120" mce_href="http://adminfoo.net/?q=node/120"&gt;Windows admins, give up your privs!&lt;/A&gt;” by bryan — includes some good advice on detecting and fixing programs that break the two most common post-install rules of LUA* 
&lt;LI&gt;“&lt;A href="http://blogs.technet.com/tonyso/archive/2005/04/10/403552.aspx" mce_href="http://blogs.technet.com/tonyso/archive/2005/04/10/403552.aspx"&gt;Tools 2 Use – Do you LUA?&lt;/A&gt;” from tonyso — with three TechNet Webcasts about securing your desktop against phishers, spammers, scammers, and other malicious software (this is also the first time I’ve seen the help address &lt;A href="mailto:lua-qa@microsoft.com" mce_href="mailto:lua-qa@microsoft.com"&gt;lua-qa@microsoft.com&lt;/A&gt; mentioned) 
&lt;LI&gt;“&lt;A href="http://msmvps.com/bradley/archive/2005/04/26/44743.aspx" mce_href="http://msmvps.com/bradley/archive/2005/04/26/44743.aspx"&gt;I flattened a box tonight&lt;/A&gt;” by Susan Bradley — from now on her kids are going to run as LUA (via &lt;A href="http://blogs.msdn.com/dmuscett/archive/2005/05/05/414922.aspx" mce_href="http://blogs.msdn.com/dmuscett/archive/2005/05/05/414922.aspx"&gt;Daniele Muscetta&lt;/A&gt;) 
&lt;LI&gt;“&lt;A href="http://msdn.microsoft.com/msdnmag/issues/05/01/SecurityBriefs/default.aspx" mce_href="http://msdn.microsoft.com/msdnmag/issues/05/01/SecurityBriefs/default.aspx"&gt;Security Enhancements in the .NET Framework 2.0&lt;/A&gt;” by Keith Brown — describes a new programmatic equivalent of RunAs in managed code (via &lt;A href="http://blogs.msdn.com/gduthie/archive/2005/02/07/368606.aspx" mce_href="http://blogs.msdn.com/gduthie/archive/2005/02/07/368606.aspx"&gt;G. Andrew Duthie&lt;/A&gt;) 
&lt;LI&gt;“&lt;A href="http://weblogs.asp.net/rhurlbut/archive/2005/04/27/404795.aspx" mce_href="http://weblogs.asp.net/rhurlbut/archive/2005/04/27/404795.aspx"&gt;TechEd: Non-Admin Development BOF&lt;/A&gt;” by Robert Hurlbut — if you’re going to &lt;A href="http://www.microsoft.com/events/teched2005/default.mspx" mce_href="http://www.microsoft.com/events/teched2005/default.mspx"&gt;Tech-Ed 2005&lt;/A&gt;, make sure to attend this Birds of a Feather Session! (also via &lt;A href="http://blogs.msdn.com/gduthie/archive/2005/04/27/412694.aspx" mce_href="http://blogs.msdn.com/gduthie/archive/2005/04/27/412694.aspx"&gt;G. Andrew Duthie&lt;/A&gt;) 
&lt;LI&gt;“&lt;A href="http://blogs.msdn.com/jmazner/archive/2005/04/12/407711.aspx" mce_href="http://blogs.msdn.com/jmazner/archive/2005/04/12/407711.aspx"&gt;Non administrator: running with least privilege&lt;/A&gt;” from Jeremy Mazner&lt;/LI&gt;&lt;/UL&gt;
&lt;P&gt;Of course, if you’re subscribed to the &lt;A href="http://nonadmin.editme.com/rss.xml" mce_href="http://nonadmin.editme.com/rss.xml"&gt;wiki’s non-admin RSS feed&lt;/A&gt;, you already know this :)&lt;/P&gt;
&lt;P&gt;* Don't write to %systemdrive%/Program Files or %windir%, and don’t write to HKEY_LOCAL_MACHINE&lt;/P&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=420098" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/jonathanh/archive/tags/Security/default.aspx">Security</category></item><item><title>Refresh build of Microsoft Windows AntiSpyware beta</title><link>http://blogs.msdn.com/jonathanh/archive/2005/02/17/refresh-build-of-microsoft-windows-antispyware-beta.aspx</link><pubDate>Thu, 17 Feb 2005 11:55:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:375146</guid><dc:creator>jonathanh</dc:creator><slash:comments>9</slash:comments><comments>http://blogs.msdn.com/jonathanh/comments/375146.aspx</comments><wfw:commentRss>http://blogs.msdn.com/jonathanh/commentrss.aspx?PostID=375146</wfw:commentRss><wfw:comment>http://blogs.msdn.com/jonathanh/rsscomments.aspx?PostID=375146</wfw:comment><description>&lt;P&gt;Microsoft’s antispyware team made version 1.0.509 available for download a couple of hours ago. You can use Help &amp;gt; About to see what you’re currently running, but unless you’re another Microsoftie with the latest internal bits, you probably don’t have this one yet :-) &lt;/P&gt;
&lt;P&gt;The only time I notice I’m running it is when it warns me about the latest piece of facehuggerware trying to install some autorun entry. Ahhh, Apple Quicktime, what would we do without you?&lt;/P&gt;
&lt;P&gt;Anyway, two thumbs up. Get it while it’s hot:&lt;/P&gt;
&lt;P&gt;&lt;A href="http://www.microsoft.com/downloads/details.aspx?FamilyId=321CD7A2-6A57-4C57-A8BD-DBF62EDA9671&amp;amp;displaylang=en" mce_href="http://www.microsoft.com/downloads/details.aspx?FamilyId=321CD7A2-6A57-4C57-A8BD-DBF62EDA9671&amp;amp;displaylang=en"&gt;http://www.microsoft.com/downloads/details.aspx?FamilyId=321CD7A2-6A57-4C57-A8BD-DBF62EDA9671&amp;amp;displaylang=en&lt;/A&gt;&lt;/P&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=375146" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/jonathanh/archive/tags/Security/default.aspx">Security</category></item><item><title>How to run as a non-administrator - announcing a new community site</title><link>http://blogs.msdn.com/jonathanh/archive/2005/02/04/how-to-run-as-a-non-administrator-announcing-a-new-community-site.aspx</link><pubDate>Sat, 05 Feb 2005 03:22:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:367492</guid><dc:creator>jonathanh</dc:creator><slash:comments>4</slash:comments><comments>http://blogs.msdn.com/jonathanh/comments/367492.aspx</comments><wfw:commentRss>http://blogs.msdn.com/jonathanh/commentrss.aspx?PostID=367492</wfw:commentRss><wfw:comment>http://blogs.msdn.com/jonathanh/rsscomments.aspx?PostID=367492</wfw:comment><description>&lt;P&gt;I’ve set up a new community web site at &lt;A href="http://nonadmin.editme.com/" mce_href="http://nonadmin.editme.com/"&gt;http://nonadmin.editme.com&lt;/A&gt;. It’s a place where anyone can share their experiences with running as a non-administrator in Windows – the good (tips, tools, and help for using a limited-user account), the bad (programs that won’t even install, let alone run, unless you’re administrator), and the ugly (workarounds and kludges). Here’s my quick attempt at a FAQ: &lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Why should you care? &lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Because running as administrator (which is unfortunately the Windows default) can be a serious security hole. If you use a limited-user account instead you’ll really reduce your computer’s “attack surface”. And if you set up your parents’ PC that way, you’ll really reduce your tech-support visits too! &lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Why bother bookmarking a new site? &lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Because while there’s lots of great information on the net about how to run as a non-administrator, there’s no single site that puts it all into one easy-to-find place. &lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Why is it a community site? &lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Because I’m lazy, and because other people are much smarter at this security stuff than I am! I can’t keep track of all the neat work going on in the community, but I &lt;EM&gt;do&lt;/EM&gt; want to learn about it from the experts. If anyone can add their expertise and experience, we all benefit. A good example of another community site is the &lt;A href="http://wus.editme.com/" mce_href="http://wus.editme.com/"&gt;Windows Update Services wiki&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;What’s already there? &lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;I’ve added content and pointers from several bloggers, including &lt;A href="http://blogs.msdn.com/aaron_margosis" mce_href="http://blogs.msdn.com/aaron_margosis"&gt;Aaron Margosis&lt;/A&gt;, &lt;A href="http://dotnetguy.techieswithcats.com/" mce_href="http://dotnetguy.techieswithcats.com/"&gt;Brad Wilson&lt;/A&gt;, &lt;A href="http://blogs.msdn.com/ejarvi" mce_href="http://blogs.msdn.com/ejarvi"&gt;Eric Jarvi&lt;/A&gt;, &lt;A href="http://blogs.msdn.com/esiu" mce_href="http://blogs.msdn.com/esiu"&gt;Eugene Siu&lt;/A&gt;, &lt;A href="http://blogs.msdn.com/gduthie" mce_href="http://blogs.msdn.com/gduthie"&gt;G. Andrew Duthie&lt;/A&gt;, &lt;A href="http://blogs.msdn.com/strawberryjamm" mce_href="http://blogs.msdn.com/strawberryjamm"&gt;Jenni Merrifield&lt;/A&gt;, &lt;A href="http://blogs.msdn.com/jhoward" mce_href="http://blogs.msdn.com/jhoward"&gt;John Howard&lt;/A&gt;, &lt;A href="http://pluralsight.com/blogs/keith/" mce_href="http://pluralsight.com/blogs/keith/"&gt;Keith Brown&lt;/A&gt;, and &lt;A href="http://blogs.msdn.com/paranoidmike/" mce_href="http://blogs.msdn.com/paranoidmike/"&gt;Mike Smith-Lonergan&lt;/A&gt;. Please add more! &lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;What about developers?&lt;/STRONG&gt; &lt;/P&gt;
&lt;P&gt;Don’t worry, there’s a section just for you. Learning to write applications that Just Work under a non-administrator account is already a requirement for getting a Windows logo, and it’s going to be even&amp;nbsp;more important under Longhorn. &lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;What’s all this talk about a wiki? &lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Shhhh… you weren’t supposed to notice! The folks at &lt;A href="http://www.editme.com/" mce_href="http://www.editme.com/"&gt;http://www.editme.com&lt;/A&gt; have done a great job at putting a user-friendly front-end on top of their wiki software, including a WYSIWYG editing control. If that is too much for you, you can just leave blog-style comments. Different strokes for different folks. &lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Didn’t Robert Scoble already blog this?&lt;/STRONG&gt; &lt;/P&gt;
&lt;P&gt;Yup – I sent out a “sneak peek” email last night, and &lt;A href="http://radio.weblogs.com/0001011/2005/02/04.html#a9323" mce_href="http://radio.weblogs.com/0001011/2005/02/04.html#a9323"&gt;he blogged it within 45 minutes&lt;/A&gt;! I had been planning to get more input from the experts over the weekend before announcing the site next Monday, but now that the secret’s out… &lt;/P&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=367492" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/jonathanh/archive/tags/Security/default.aspx">Security</category></item><item><title>Reporting false positives from Microsoft Windows Antispyware</title><link>http://blogs.msdn.com/jonathanh/archive/2005/01/06/reporting-false-positives-from-microsoft-windows-antispyware.aspx</link><pubDate>Fri, 07 Jan 2005 10:16:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:348255</guid><dc:creator>jonathanh</dc:creator><slash:comments>1</slash:comments><comments>http://blogs.msdn.com/jonathanh/comments/348255.aspx</comments><wfw:commentRss>http://blogs.msdn.com/jonathanh/commentrss.aspx?PostID=348255</wfw:commentRss><wfw:comment>http://blogs.msdn.com/jonathanh/rsscomments.aspx?PostID=348255</wfw:comment><description>&lt;P&gt;One thing I forgot to mention in my &lt;A href="http://blogs.msdn.com/jonathanh/archive/2005/01/06/348224.aspx" mce_href="http://blogs.msdn.com/jonathanh/archive/2005/01/06/348224.aspx"&gt;previous post&lt;/A&gt; is what to do when the Microsoft anti-spyware tool incorrectly reports something as being adware or spyware. &lt;/P&gt;
&lt;P&gt;If you’re just trying to get on with your work, and you’re certain that the file really &lt;EM&gt;is&lt;/EM&gt; innocent, you can tell the tool to always ignore it. If you also want to help out the Microsoft anti-spyware team, try checking &lt;A href="http://communities.microsoft.com/newsgroups/default.asp?ICP=spyware&amp;amp;sLCID=us" mce_href="http://communities.microsoft.com/newsgroups/default.asp?ICP=spyware&amp;amp;sLCID=us"&gt;microsoft.private.security.spyware.signatures&lt;/A&gt; – other people might have already seen the problem, or yours could be the first report! &lt;/P&gt;
&lt;P&gt;If you’re a vendor of a program that is being flagged as adware or spyware, and you think this decision is wrong, then fill out &lt;A href="http://www.spynet.com/vendors.aspx" mce_href="http://www.spynet.com/vendors.aspx"&gt;http://www.spynet.com/vendors.aspx&lt;/A&gt;. You can also find the criteria being used at &lt;A href="http://www.spynet.com/info_spywarecriteria.aspx" mce_href="http://www.spynet.com/info_spywarecriteria.aspx"&gt;http://www.spynet.com/info_spywarecriteria.aspx&lt;/A&gt;. Looks like there’s been no change of domain name or policy from GIANT’s original SpyNet infrastructure :-)&lt;/P&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=348255" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/jonathanh/archive/tags/Security/default.aspx">Security</category></item><item><title>Microsoft anti-virus software to complement today's beta of an anti-spyware tool</title><link>http://blogs.msdn.com/jonathanh/archive/2005/01/06/348224.aspx</link><pubDate>Fri, 07 Jan 2005 08:49:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:348224</guid><dc:creator>jonathanh</dc:creator><slash:comments>14</slash:comments><comments>http://blogs.msdn.com/jonathanh/comments/348224.aspx</comments><wfw:commentRss>http://blogs.msdn.com/jonathanh/commentrss.aspx?PostID=348224</wfw:commentRss><wfw:comment>http://blogs.msdn.com/jonathanh/rsscomments.aspx?PostID=348224</wfw:comment><description>&lt;P&gt;[Update for people finding this post through web searches: the anti-virus tool has been released as the &lt;A href="http://www.microsoft.com/downloads/details.aspx?FamilyID=ad724ae0-e72d-4f54-9ab3-75b8eb148356&amp;amp;displaylang=en"&gt;Microsoft Windows Malicious Software Removal Tool&lt;/A&gt; (KB890830). You can use that link to download it directly, but really you should be using Windows Update so that you get an automatic update to the tool every month!]&lt;/P&gt;
&lt;P&gt;In case you were hiding under a rock today, Microsoft released a beta of an anti-spyware tool based on the GIANT AntiSpyware codebase*. What seems to have been lost in all the general noise** is the &lt;STRONG&gt;other&lt;/STRONG&gt; announcement, the one about our promise of regularly updated virus-removal tools. &lt;A href="http://myitforum.techtarget.com/blog/rtrent/archive/2005/01/06/1406.aspx"&gt;Rod Trent&lt;/A&gt;&amp;nbsp;is the only guy I read who’s noticed the &lt;A href="http://www.microsoft.com/presspass/press/2005/jan05/01-06NewSolutionsPR.asp"&gt;press release&lt;/A&gt;: &lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;&lt;EM&gt;The new Microsoft Windows malicious software removal tool consolidates [our existing removal tools for Blaster, MyDoom, and Download.Ject] into a single solution. The tool will be updated on the second Tuesday of each month as part of Microsoft's monthly software security update process to respond to new viruses, worms and variants. &lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;The Microsoft Windows malicious software removal tool will be offered in the following ways: &lt;/EM&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;EM&gt;As a high-priority update through Windows Update and Auto Update. &lt;/EM&gt;
&lt;LI&gt;&lt;EM&gt;Through a simple, online interface. &lt;/EM&gt;
&lt;LI&gt;&lt;EM&gt;For larger corporate customers, a download through the Microsoft Download Center. &lt;/EM&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;Summarizing the rest of the press release:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;It’s free 
&lt;LI&gt;The first release will be &lt;STRONG&gt;next Tuesday&lt;/STRONG&gt;&lt;/LI&gt;&lt;/UL&gt;
&lt;P&gt;Oh, and the anti-spyware beta is well worth checking out – I’ve been running it for a couple of weeks. There are still plenty of fit-and-finish issues (I’ve submitted half a dozen bugs, mostly related to non-standard Windows controls and some bits that weren’t rebranded), but the core functionality is all there. Grab it from the &lt;A href="http://www.microsoft.com/athome/security/spyware/software/default.mspx"&gt;official Microsoft Windows AntiSpyware page&lt;/A&gt;, where you can also find a &lt;A href="http://www.microsoft.com/athome/security/spyware/software/faq.mspx"&gt;FAQ&lt;/A&gt;, a list of &lt;A href="http://www.microsoft.com/athome/security/spyware/software/releasenotes.mspx"&gt;Known Issues&lt;/A&gt; with the beta, and pointers to (shock horror!) &lt;A href="http://communities.microsoft.com/newsgroups/default.asp?ICP=spyware&amp;amp;sLCID=us"&gt;newsgroups&lt;/A&gt; where you can get support.&lt;/P&gt;
&lt;P&gt;*Well, technically it hit the servers last night, and several enterprising folks found the bits before the “official” news release at 9 a.m. this morning. Ahhh, what would we do without rabid fanboys? :-)&lt;/P&gt;
&lt;P&gt;**I believe &lt;A HREF="/mswanson/archive/2005/01/06/347639.aspx"&gt;Michael Swanson&lt;/A&gt; was the first on blogs.msdn.com to post about it, and gives an excellent summary of the anti-spyware tool. &lt;/P&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=348224" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/jonathanh/archive/tags/Security/default.aspx">Security</category></item></channel></rss>