March 2007 - Posts

A Real-world Windows Vista BitLocker Tip
24 March 07 08:51 AM
Like a good Microsoft security citizen I installed BitLocker on my Infineon TPM-enabled laptop ages ago, well before we shipped the OS in late 2006. The nice thing is that I don't even know BitLocker is ‘doing its thing’ as there is no performance degradation Read More...
Postedby michael_HOWARD | 13 Comments    
Filed under: ,
Symantec: Microsoft-authored code will become more difficult to exploit
22 March 07 09:22 AM
From Symantec: With the advent of Vista and the continued use of the Security Development Lifecycle, it is likely that Microsoft-authored code will become more difficult to exploit. As a result, attackers may turn their focus to common third-party applications Read More...
Postedby michael_HOWARD | 1 Comments    
Filed under: ,
Surprise, Microsoft Listed as Most Secure OS
21 March 07 09:01 PM
Wow, the folks from Symantec claim "Microsoft is doing better overall than its leading commercial competitors [in security]" http://www.internetnews.com/security/article.php/3667201 Read More...
Postedby michael_HOWARD | 5 Comments    
Filed under:
Windows Vista - 90 Day Vulnerability Report
21 March 07 02:11 PM
Jeff Jones just posted a blog looking at vulnerability counts in various operating systems after 90 days of product release. It's an interesting read. Read More...
Postedby michael_HOWARD | 0 Comments    
Filed under:
David LeBlanc now has a blog
20 March 07 09:16 AM
David is one of the most insightful security guys I know. Wicked smart, and damned opinionated, but who isn't? http://blogs.msdn.com/david_leblanc/ Read More...
Postedby michael_HOWARD | 2 Comments    
Filed under:
I think I have a blackhat in my midst
19 March 07 03:50 PM
A few weeks back I wrote how my 5 year old son, Blake, decided to hack into our computer. Well, it gets better. Blake is reading pretty well now, and can write too. But he still comes across words he needs to sound out phonetically. Yesterday, my wife Read More...
Postedby michael_HOWARD | 8 Comments    
Filed under:
My Take on Windows Vista Security “Vulnerabilities”
16 March 07 05:04 PM
I love looking at and analyzing security bugs, but I also enjoy observing how people react to knowledge of security bugs. Over the last few weeks, I’ve seen a number of interesting articles about Windows Vista security that made me smile. So I thought Read More...
Postedby michael_HOWARD | 16 Comments    
Filed under: , ,
How I will judge Windows Vista Security
08 March 07 08:50 PM
Before I get started, I want to point out this is my opinion, not necessarily anyone else’s viewpoint. Now that we have shipped Windows Vista and researchers are starting to prod and probe for security bugs, I want to spend a couple of minutes to explain Read More...
Postedby michael_HOWARD | 13 Comments    
Filed under: ,
UAC Deep dive over on Channel9
08 March 07 08:31 PM
Chris Corio and Jonathan Schwartz did an hour-long deep dive into the UAC architecture, goals and issues over on Channel9. I've known Jon for more years than I care to remember, and he is one of the smartest guys I know, but don't tell him I said that! Read More...
Postedby michael_HOWARD | 1 Comments    
Filed under: ,
List of Banned APIs now available
08 March 07 12:19 PM
We have just published the list of SDL-banned APIs, and their replacements. http://msdn2.microsoft.com/en-us/library/bb288454.aspx Read More...
Postedby michael_HOWARD | 14 Comments    
Filed under:
New Book: Writing Secure Code for Windows Vista
03 March 07 01:34 PM
Even though we (kinda) promised our wives we wouldn’t do it, David LeBlanc and I have just wrapped up another book, Writing Secure Code for Windows Vista . (ISBN: 9780735623934, ISBN-10: 0-7356-2393-7.) It should be available around mid-April 2007. It’s Read More...
Postedby michael_HOWARD | 14 Comments    
Filed under: ,
Page view tracker