<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.msdn.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Some thoughts about Windows Server 2008</title><link>http://blogs.msdn.com/michael_howard/archive/2008/03/04/some-thoughts-about-windows-server-2008.aspx</link><description>Windows Server 2008 has shipped! And a fine product it is, too! Windows Server 2008 is the first Windows Server to go through the full SDL process, making it the most secure version of Windows Server to date. We raised the security bar in Windows Vista,</description><dc:language>en-US</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>MSDN Blog Postings  &amp;raquo; Some thoughts about Windows Server 2008</title><link>http://blogs.msdn.com/michael_howard/archive/2008/03/04/some-thoughts-about-windows-server-2008.aspx#8044385</link><pubDate>Wed, 05 Mar 2008 07:46:49 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8044385</guid><dc:creator>MSDN Blog Postings  » Some thoughts about Windows Server 2008</dc:creator><description>&lt;p&gt;PingBack from &lt;a rel="nofollow" target="_new" href="http://msdnrss.thecoderblogs.com/2008/03/05/some-thoughts-about-windows-server-2008/"&gt;http://msdnrss.thecoderblogs.com/2008/03/05/some-thoughts-about-windows-server-2008/&lt;/a&gt;&lt;/p&gt;
</description></item><item><title>Securitate in Windows Server 2008</title><link>http://blogs.msdn.com/michael_howard/archive/2008/03/04/some-thoughts-about-windows-server-2008.aspx#8049785</link><pubDate>Wed, 05 Mar 2008 12:36:56 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8049785</guid><dc:creator>Weblogul lui Zoli</dc:creator><description>&lt;p&gt;C&amp;#226;nd am lansat Windows Vista și Office 2007 &amp;#238;n decembrie 2006 , am amintit că dacă m-ar &amp;#238;ntreba cineva&lt;/p&gt;
</description></item><item><title>re: Some thoughts about Windows Server 2008</title><link>http://blogs.msdn.com/michael_howard/archive/2008/03/04/some-thoughts-about-windows-server-2008.aspx#8051641</link><pubDate>Wed, 05 Mar 2008 16:03:03 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8051641</guid><dc:creator>Mark Sowul</dc:creator><description>&lt;p&gt;I've mentioned this before elsewhere, but very rarely, if ever, do security bulletins mention the impact of DEP as a mitigating factor for those who have it set to OptOut (the only problem app I have is a plugin for Outlook, which means Outlook has it disabled). &amp;nbsp;For example, the infamous WMF exploit from a few years ago was blocked by DEP but that was never mentioned.&lt;/p&gt;</description></item><item><title>re: Some thoughts about Windows Server 2008</title><link>http://blogs.msdn.com/michael_howard/archive/2008/03/04/some-thoughts-about-windows-server-2008.aspx#8053096</link><pubDate>Wed, 05 Mar 2008 19:49:30 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8053096</guid><dc:creator>michael_HOWARD</dc:creator><description>&lt;p&gt;Mark, you should read a blog post that touches on this subject &lt;a rel="nofollow" target="_new" href="http://blogs.msdn.com/michael_howard/archive/2007/03/08/how-i-will-judge-windows-vista-security.aspx"&gt;http://blogs.msdn.com/michael_howard/archive/2007/03/08/how-i-will-judge-windows-vista-security.aspx&lt;/a&gt;&lt;/p&gt;
</description></item><item><title>re: Some thoughts about Windows Server 2008</title><link>http://blogs.msdn.com/michael_howard/archive/2008/03/04/some-thoughts-about-windows-server-2008.aspx#8053739</link><pubDate>Wed, 05 Mar 2008 21:25:06 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8053739</guid><dc:creator>NicoAtMicrosoft</dc:creator><description>&lt;p&gt;There's still a chance to attend one of the launch events in various cities, too! &amp;nbsp;The LA Event was fun, and Steve Ballmer's keynote was particularly nice to watch.&lt;/p&gt;
&lt;p&gt;**************&lt;/p&gt;
&lt;p&gt;Nico del Castillo&lt;/p&gt;
&lt;p&gt;Microsoft 2008 Joint Launch Team&lt;/p&gt;
&lt;p&gt;&lt;a rel="nofollow" target="_new" href="http://www.microsoft.com/2008jointlaunch"&gt;http://www.microsoft.com/2008jointlaunch&lt;/a&gt;&lt;/p&gt;</description></item><item><title>re: Some thoughts about Windows Server 2008</title><link>http://blogs.msdn.com/michael_howard/archive/2008/03/04/some-thoughts-about-windows-server-2008.aspx#8066063</link><pubDate>Thu, 06 Mar 2008 07:59:38 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8066063</guid><dc:creator>Mark Sowul</dc:creator><description>&lt;p&gt;Oh, I absolutely agree with you on judging Vista not just on vulnerabilities but the defense-in-depth mentality - I am just speaking in terms of &amp;quot;am I susceptible to this vulnerability given that it does exist&amp;quot; and rarely is DEP mentioned as a mitigating factor. &amp;nbsp;&lt;/p&gt;
&lt;p&gt;What made me think of this particularly is the new Facebook/MySpace image uploader ActiveX vulnerability - I suspect the combination of IE7 in protected mode plus the fact that it runs under DEP means I would not be vulnerable to it, since it's your usual run-of-the-mill stack buffer overrun, but rarely are these kinds of things pointed out in vulnerability notices.&lt;/p&gt;</description></item><item><title>re: Some thoughts about Windows Server 2008</title><link>http://blogs.msdn.com/michael_howard/archive/2008/03/04/some-thoughts-about-windows-server-2008.aspx#8073335</link><pubDate>Thu, 06 Mar 2008 18:58:43 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8073335</guid><dc:creator>Osama Salah</dc:creator><description>&lt;p&gt;&amp;quot;...making it the most secure version of Windows Server to date&amp;quot;&lt;/p&gt;
&lt;p&gt;how can someone make such a claim if its barely being used? You can prove its secure only by failing to break it and for that it hasn't been adopted long enough.&lt;/p&gt;
&lt;p&gt;You can only theoretically hope it is more secure because you improved your development process, but that's speculative again. Maybe the SDL implementation at MS is flawed, etc.&lt;/p&gt;
&lt;p&gt;so be careful with such statements.&lt;/p&gt;
&lt;p&gt;In all cases I do sincerely hope that Windows 2008 will offer superior security.&lt;/p&gt;</description></item><item><title>re: Some thoughts about Windows Server 2008</title><link>http://blogs.msdn.com/michael_howard/archive/2008/03/04/some-thoughts-about-windows-server-2008.aspx#8084807</link><pubDate>Fri, 07 Mar 2008 06:02:14 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8084807</guid><dc:creator>michael_HOWARD</dc:creator><description>&lt;p&gt;Osama. by looking at new security bugs that get reported to us, and noticing that they don't affect the product!&lt;/p&gt;
</description></item><item><title>re: Some thoughts about Windows Server 2008</title><link>http://blogs.msdn.com/michael_howard/archive/2008/03/04/some-thoughts-about-windows-server-2008.aspx#8088999</link><pubDate>Fri, 07 Mar 2008 09:44:43 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8088999</guid><dc:creator>Osama Salah</dc:creator><description>&lt;p&gt;that makes sense to see a trend there and make such a prognosis.&lt;/p&gt;
&lt;p&gt;In all cases I do expect a new product to be more secure than a previous one, the benchmark would be the incremental improvement achieved and judging from the new features and architectural improvements it is very promising. It will of course have a few security problems that will affect it, but such is life. Besides you need something for Windows 2010 ;-)&lt;/p&gt;
&lt;p&gt;rgds&lt;/p&gt;
&lt;p&gt;Osama Salah&lt;/p&gt;</description></item><item><title>re: Some thoughts about Windows Server 2008</title><link>http://blogs.msdn.com/michael_howard/archive/2008/03/04/some-thoughts-about-windows-server-2008.aspx#8214492</link><pubDate>Sat, 15 Mar 2008 04:03:51 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8214492</guid><dc:creator>Alistair Railton</dc:creator><description>&lt;p&gt;Yes Micheal it is a fine looking product. And I haven't bumped into your name for at least 20 years !!! Damn you must be old now :p &lt;/p&gt;
&lt;p&gt;I was suprised to see how easy it blue screened when remote administration is used. This is easy to rectify by not using vista themes on the server, however it does trigger a thought or two.&lt;/p&gt;
&lt;p&gt;If you want more information on the blue screen problem then yell out, but it seems to only happen if the aero theme is turned on, the administrator is logged into the server console and a rdp connect is performed by the administrator.&lt;/p&gt;</description></item><item><title>re: Some thoughts about Windows Server 2008</title><link>http://blogs.msdn.com/michael_howard/archive/2008/03/04/some-thoughts-about-windows-server-2008.aspx#8280839</link><pubDate>Mon, 17 Mar 2008 08:33:36 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8280839</guid><dc:creator>michael_HOWARD</dc:creator><description>&lt;p&gt;Bloody Hell, Railton!! How're you? Email me your contact info. You can send it by selecting This Blog --&amp;gt; Email at the top right of the blog.&lt;/p&gt;
</description></item></channel></rss>