<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.msdn.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Windows Vista Security – A Bigger Picture</title><link>http://blogs.msdn.com/michael_howard/archive/2006/06/12/windows-vista-security-a-bigger-picture.aspx</link><description>A couple of people have asked about the relationship between /GS , SAL and ASLR in Windows Vista. Here’s my perspective, and it’s much bigger than just /GS, SAL and ASLR alone. There are two overarching goals at work – the first is to reduce the number</description><dc:language>en-US</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>re: Windows Vista Security – A Bigger Picture</title><link>http://blogs.msdn.com/michael_howard/archive/2006/06/12/windows-vista-security-a-bigger-picture.aspx#628705</link><pubDate>Tue, 13 Jun 2006 00:54:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:628705</guid><dc:creator>bob hir</dc:creator><description>Thanks for the above, very informative...I have one question though wouldn't the Stack randomization and ASLR work counter to caching techniques involving caching what is requested and more of what is nearby with the expectation that the &amp;quot;more&amp;quot; will be called into play shortly also..&lt;br&gt;&lt;br&gt;I'm not a programmer, and approaching this from a level of someone whom reads alot about windows and processor internals type stuff, and may very well not be understanding all this correctly..</description></item><item><title>tuxedo-es.org &amp;raquo; Microsoft Windows Vista beta-2build 5384: Vista-Probe 0.1 results</title><link>http://blogs.msdn.com/michael_howard/archive/2006/06/12/windows-vista-security-a-bigger-picture.aspx#629052</link><pubDate>Tue, 13 Jun 2006 06:28:12 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:629052</guid><dc:creator>tuxedo-es.org » Microsoft Windows Vista beta-2build 5384: Vista-Probe 0.1 results</dc:creator><description>PingBack from &lt;a rel="nofollow" target="_new" href="http://www.tuxedo-es.org/blog/2006/06/13/microsoft-windows-vista-beta-2build-5384-vista-probe-01-results/"&gt;http://www.tuxedo-es.org/blog/2006/06/13/microsoft-windows-vista-beta-2build-5384-vista-probe-01-results/&lt;/a&gt;</description></item><item><title>re: Windows Vista Security – A Bigger Picture</title><link>http://blogs.msdn.com/michael_howard/archive/2006/06/12/windows-vista-security-a-bigger-picture.aspx#629397</link><pubDate>Tue, 13 Jun 2006 15:49:49 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:629397</guid><dc:creator>Vasu</dc:creator><description>Michael;&lt;br&gt; Regarding your statement;&lt;br&gt;&amp;quot;I want to make one thing really clear; in my opinion, the overall effect of these defenses is greater than the sum of the parts.&amp;quot;&lt;br&gt; Uh.. that is hard to believe if you state like that (or coming from a Microsoft guy :) ). It should be more like&lt;br&gt;&amp;quot;According to mathematics (which is the universal truth), the the overall effect of these defenses is greater than the sum of the parts&amp;quot;&lt;br&gt; In math it is called Bayes' Theorem.&lt;br&gt; Very nice summary of the important security features. Thanks :)&lt;br&gt;&lt;br&gt;--Vasu.</description></item><item><title>Windows Vista : Threat-driven Design combined with Security Quality Process</title><link>http://blogs.msdn.com/michael_howard/archive/2006/06/12/windows-vista-security-a-bigger-picture.aspx#632479</link><pubDate>Thu, 15 Jun 2006 19:58:34 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:632479</guid><dc:creator>Think Security - Jeff Jones Security Blog </dc:creator><description>What is the difference between foundational security and security features?&lt;br&gt;Name 3 security companies.&amp;amp;amp;nbsp;...</description></item><item><title>Defense In Depth: The Bigger Picture of Windows Vista Security</title><link>http://blogs.msdn.com/michael_howard/archive/2006/06/12/windows-vista-security-a-bigger-picture.aspx#632601</link><pubDate>Thu, 15 Jun 2006 21:38:52 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:632601</guid><dc:creator>Robert McLaws: FunWithCoding.NET - Windows Vista Edition</dc:creator><description>Microsoft Security Expert Michael Howard provides a very technical explanation of the security strategies...</description></item><item><title>Italia SW  &amp;raquo; Archivio   &amp;raquo; Windows Vista News della Settimana</title><link>http://blogs.msdn.com/michael_howard/archive/2006/06/12/windows-vista-security-a-bigger-picture.aspx#632728</link><pubDate>Thu, 15 Jun 2006 23:11:43 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:632728</guid><dc:creator>Italia SW  » Archivio   » Windows Vista News della Settimana</dc:creator><description>PingBack from &lt;a rel="nofollow" target="_new" href="http://www.italiasw.com/windows-vista-news-della-settimana/"&gt;http://www.italiasw.com/windows-vista-news-della-settimana/&lt;/a&gt;</description></item><item><title>re: Windows Vista Security – A Bigger Picture</title><link>http://blogs.msdn.com/michael_howard/archive/2006/06/12/windows-vista-security-a-bigger-picture.aspx#634060</link><pubDate>Fri, 16 Jun 2006 16:47:23 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:634060</guid><dc:creator>Kannan</dc:creator><description>I have a question on /GS , was windows xp sp2 compiled with this option ?</description></item><item><title>re: Windows Vista Security – A Bigger Picture</title><link>http://blogs.msdn.com/michael_howard/archive/2006/06/12/windows-vista-security-a-bigger-picture.aspx#634232</link><pubDate>Fri, 16 Jun 2006 19:11:21 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:634232</guid><dc:creator>michael_HOWARD</dc:creator><description>Kannan, yes it was. But we have tweaked /GS again for Windows Vista :)</description></item><item><title>re: Windows Vista Security – A Bigger Picture</title><link>http://blogs.msdn.com/michael_howard/archive/2006/06/12/windows-vista-security-a-bigger-picture.aspx#636204</link><pubDate>Sun, 18 Jun 2006 22:03:43 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:636204</guid><dc:creator>bartosz</dc:creator><description>hi michael, what flag in PE header will ensure random image base?</description></item><item><title>The Windows Vista Technician | Help &amp;#038; Information &amp;raquo; Windows Vista Security - Technical Explanation</title><link>http://blogs.msdn.com/michael_howard/archive/2006/06/12/windows-vista-security-a-bigger-picture.aspx#636433</link><pubDate>Mon, 19 Jun 2006 04:51:34 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:636433</guid><dc:creator>The Windows Vista Technician | Help &amp; Information » Windows Vista Security - Technical Explanation</dc:creator><description>PingBack from &lt;a rel="nofollow" target="_new" href="http://www.vistatechnician.com/38/windows-vista-security-technical-explanation/"&gt;http://www.vistatechnician.com/38/windows-vista-security-technical-explanation/&lt;/a&gt;</description></item><item><title>Cl??rigo  &amp;raquo; Blog Archive   &amp;raquo; (In)Seguridad en Vista</title><link>http://blogs.msdn.com/michael_howard/archive/2006/06/12/windows-vista-security-a-bigger-picture.aspx#663498</link><pubDate>Wed, 12 Jul 2006 19:28:10 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:663498</guid><dc:creator>Cl??rigo  » Blog Archive   » (In)Seguridad en Vista</dc:creator><description>PingBack from &lt;a rel="nofollow" target="_new" href="http://clerigo.alucardx.net/index.php/2006/07/12/inseguridad-en-vista/"&gt;http://clerigo.alucardx.net/index.php/2006/07/12/inseguridad-en-vista/&lt;/a&gt;</description></item><item><title>Symantec: Crying Wolf on Windows Vista</title><link>http://blogs.msdn.com/michael_howard/archive/2006/06/12/windows-vista-security-a-bigger-picture.aspx#678153</link><pubDate>Tue, 25 Jul 2006 22:24:48 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:678153</guid><dc:creator>Robert McLaws: FunWithCoding.NET - Windows Vista Edition</dc:creator><description>Symantec is so pissed at Microsoft for competing against it with OneCare, and for reducing the need for...</description></item><item><title>Windows Vista x64 Security - Pt 1</title><link>http://blogs.msdn.com/michael_howard/archive/2006/06/12/windows-vista-security-a-bigger-picture.aspx#687044</link><pubDate>Thu, 03 Aug 2006 02:52:51 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:687044</guid><dc:creator>Think Security - Jeff Jones Security Blog </dc:creator><description>&lt;br&gt;I recently took home a build of Windows Vista for my home machine, which happens to be a dual processor...</description></item><item><title>Windows Vista Download -  &amp;raquo; Blog Archive   &amp;raquo; Symantec: Crying Wolf on Windows Vista</title><link>http://blogs.msdn.com/michael_howard/archive/2006/06/12/windows-vista-security-a-bigger-picture.aspx#687486</link><pubDate>Thu, 03 Aug 2006 15:35:18 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:687486</guid><dc:creator>Windows Vista Download -  » Blog Archive   » Symantec: Crying Wolf on Windows Vista</dc:creator><description>PingBack from &lt;a rel="nofollow" target="_new" href="http://www.windowsvistadownload.co.uk/?p=38"&gt;http://www.windowsvistadownload.co.uk/?p=38&lt;/a&gt;</description></item><item><title>Finala WESC 2006 minus zero</title><link>http://blogs.msdn.com/michael_howard/archive/2006/06/12/windows-vista-security-a-bigger-picture.aspx#811790</link><pubDate>Tue, 10 Oct 2006 12:31:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:811790</guid><dc:creator>La treaba! v3</dc:creator><description>&lt;p&gt;Ca observator cel mai bine realizezi c&amp;amp;acirc;t de mult s-a lucrat la un proiect &amp;amp;icirc;n seara/noaptea&lt;/p&gt;
</description></item><item><title>Symantec's "The Mac OS X Threat Landscape: An Overview"</title><link>http://blogs.msdn.com/michael_howard/archive/2006/06/12/windows-vista-security-a-bigger-picture.aspx#1081462</link><pubDate>Wed, 15 Nov 2006 19:35:32 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:1081462</guid><dc:creator>Michael Howard's Web Log</dc:creator><description>&lt;p&gt;This is probably the most in-depth analysis of Mac OS X security I've ever read. It's a worthwhile read.&lt;/p&gt;
</description></item><item><title>Lessons Learned from MS07-029: The DNS RPC Interface Buffer Overrun</title><link>http://blogs.msdn.com/michael_howard/archive/2006/06/12/windows-vista-security-a-bigger-picture.aspx#3587568</link><pubDate>Thu, 28 Jun 2007 20:34:17 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:3587568</guid><dc:creator>The Security Development Lifecycle</dc:creator><description>&lt;p&gt;Hi, Michael Howard here (again). Before I get started on this post, I want to set some expectations.&lt;/p&gt;
</description></item></channel></rss>