Michael Howard's Web Log
A Simple Software Security Guy at Microsoft!
January 2008 - Posts
New NX APIs added to Windows Vista SP1, Windows XP SP3 and Windows Server 2008
29 January 08 02:11 PM
In the interests of helping secure the platform, we want more people to opt-in to using Data Execution Prevention (aka DEP aka NX), and we have lowered the barrier to entry for application developers in Windows Vista SP1, Windows XP SP3 and Windows Server
Read More...
My Daughter will never be a Spy
20 January 08 07:43 PM
My kids are desperate for pets; my six-year old son wants a dog (note, a dog, not a puppy!) and my 4-year old daughter wants a cat. The worse part is my wife keeps egging the kids on, and says she'll get the a pet when I'm next out of town. Tonite I told
Read More...
Windows Vista Crypto Modules now FIPS 140-2 Certified
18 January 08 01:01 PM
The standard crypto providers such as DSSENH and RSAENH are now certified FIPS 140-2 on Windows Vista. http://csrc.nist.gov/groups/STM/cmvp/documents/140-1/1401val2008.htm has all the info.
Read More...
Crispin Cowan joins the Windows Security Team!
17 January 08 08:11 PM
I am delighted to announce that Crispin Cowan has joined the core Windows Security Team! For those of you who don’t know Crispin, Crispin is responsible for a number of very well respected Linux-based security technologies such as StackGuard, the Immunix
Read More...
Timely Microsoft Office 2003 SP3 Advice from David LeBlanc
16 January 08 01:43 PM
http://blogs.msdn.com/david_leblanc/archive/2008/01/16/a-good-reason-to-install-sp3.aspx
Read More...
Cry or Smile? You Decide...
11 January 08 11:59 AM
On Wednesday Mark Curphey emailed me about a conversation his team had with a customer. I see he has now blogged about the conversation. Here's an excerpt. When a customers [sic, you need to learn some simple grammar, Curphey!] development team was recently
Read More...
"Open-source projects certified as secure" – huh?
10 January 08 05:35 PM
I really got a chuckle out of this news item , especially this line: “Coverity, which creates automated source-code analysis tools, announced late Monday its first list of open-source projects that have been certified as free of security defects.” So
Read More...
VBootkit vs. Bitlocker in TPM mode
08 January 08 08:05 PM
One of the guys in our group, Robert Hensing has an interesting post about VBootkit and whether BitLocker in TPM offers any defense. Short answer: yes, it does. Slightly longer answer: The BitLocker guys anticiated this attack and the really long answer
Read More...
Recent Symantec and IBM vulnerabilities, giblets, banned APIs and the SDL
04 January 08 03:47 PM
I just posted some commentary on the SDL blog about some recent Symantec and IBM vulnerabilities, and how the SDL *may* have found them.
Read More...
Go
This Blog
Home
Links
Email
Tags
General
Personal
Privacy
Rant
Security
Vista
Archives
July 2008 (1)
June 2008 (1)
May 2008 (1)
April 2008 (5)
March 2008 (5)
February 2008 (4)
January 2008 (9)
December 2007 (4)
November 2007 (4)
October 2007 (6)
September 2007 (1)
August 2007 (2)
July 2007 (4)
June 2007 (13)
May 2007 (6)
April 2007 (8)
March 2007 (11)
February 2007 (4)
January 2007 (8)
December 2006 (4)
November 2006 (14)
October 2006 (5)
September 2006 (6)
August 2006 (6)
July 2006 (2)
June 2006 (7)
May 2006 (8)
April 2006 (2)
March 2006 (5)
February 2006 (6)
January 2006 (10)
December 2005 (2)
November 2005 (2)
October 2005 (1)
September 2005 (4)
August 2005 (5)
July 2005 (5)
June 2005 (3)
May 2005 (9)
April 2005 (8)
March 2005 (5)
February 2005 (9)
January 2005 (7)
December 2004 (7)
November 2004 (9)
October 2004 (11)
August 2004 (13)
July 2004 (4)
June 2004 (12)
May 2004 (17)
April 2004 (2)
March 2004 (2)
February 2004 (3)
January 2004 (2)
Syndication
RSS 2.0
Atom 1.0