Welcome to MSDN Blogs Sign in | Join | Help

Michael Howard's Web Log

A Simple Software Security Guy at Microsoft!

Browse by Tags

All Tags » Security   (RSS)
Security Sessions at TechEd in Australia and New Zealand
I'm heading to TechEd Oz and NZ in a couple of hours to present the following: SEC312 The "Everything Developers Need to Know About Security" Talk Oz: 9/10/2009 15:30-16:45 NZ: 9/14/2009 14:15-15:30 SEC201 Inside the Microsoft Security Development Lifecycle: Read More...
ATL, MS09-035 and the SDL
http://blogs.msdn.com/sdl/archive/2009/07/28/atl-ms09-035-and-the-sdl.aspx Read More...
Integrating the SDL process into Visual Studio
I’ve been a firm believer of integrating as much security tooling as possible into the development process so developers can get on with developing code and designing solutions rather than having to constantly think about dotting the security “i”s and Read More...
A Conversation About Threat Modeling
This was fun to write; in fact, other than minor edits I wrote it in a single two hour sitting with my laptop by the pool :) http://msdn.microsoft.com/en-us/magazine/dd727503.aspx Read More...
Ken Johnson (Skywing) joins Microsoft
Following close on the heels of security experts Matt Miller , Adam Shostack and Crispin Cowan joining Microsoft, I am pleased to announce that Ken Johnson, AKA Skywing, has joined our group. Ken brings an enormous amount of reverse engineering and defense-subversion Read More...
Free Download: Writing Secure Code for Windows Vista
"For 25 years, Microsoft Press books have focused on helping you take your skills and knowledge to the next level. Celebrate our 25th Anniversary with a "Free E-Book of the Month" offer! Simply sign up for the Microsoft Press Book Connection Newsletter Read More...
Secure software development practices 'not rocket science'
http://searchsoftwarequality.techtarget.com/news/article/0,289142,sid92_gci1340940,00.html # Read More...
Improvements in Office Security
David LeBlanc has an excellent write-up of the results (so far) of all the security work the Office guys have been doing over the last few years. Net: about a 50% reduction in vulns! Read More...
Volume 5 of the Microsoft Security Intelligence Report is out
Volume 5 of the Microsoft Security Intelligence Report is now out , highlights include: Security vulnerability disclosures - Microsoft and third-party software Vulnerability Exploits – Microsoft software Browser-based exploits - Microsoft and third-party Read More...
Security-Related MSDN Magazine Articles
Bryan Sullivan and I wrote a couple of articles for this month's MSDN Magazine. If you're not aware, November focuses on Security. The two articles are: Test Your Security IQ Threat Models Improve Your Security Process And there's the Agile SDL paper Read More...
Agile SDL
Over the last year or so, a bunch of us in the SDL team have been working with agile groups across Microsoft to help streamline the SDL for agile methods. Bryan Sullivan wrote a paper for MSDN Magazine explaining where our current throughts lie. Clearly Read More...
SAFECode releases "Fundamental Practices for Secure Software Development" document
Today, SAFECode released an important document entitled, “ Fundamental Practices for Secure Software Development ” aimed at helping software producers create more secure software. The document is unique in that it describes what SAFECode members are doing Read More...
Practical Defense in Depth
<sent from Cabo San Lucas Airport - heading back to Austin > Crosstalk has published an article for mine regarding how we use Defense in Depth within the SDL, and in Microsoft in general. Read More...
SDL Evolution
UPDATED : Added IOActive post As many of you have seen today , there's been plenty of press about us opening up the SDL for use by other software developers and releasing our threat modeling tool. For those of you who have no clue what the heck I'm talking Read More...
GOOG Chrome's use of NX/DEP
Scott Hanselman has a look under Chrome's hood and how it uses the new NX/DEP APIs we added to Windows . Scroll about halfway down the article. Read More...
More Posts Next page »
Page view tracker