<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.msdn.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Michael Howard's Web Log : Security</title><link>http://blogs.msdn.com/michael_howard/archive/tags/Security/default.aspx</link><description>Tags: Security</description><dc:language>en-US</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>Security Sessions at TechEd in Australia and New Zealand</title><link>http://blogs.msdn.com/michael_howard/archive/2009/09/06/security-sessions-at-teched-in-australia-and-new-zealand.aspx</link><pubDate>Sun, 06 Sep 2009 23:20:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9891996</guid><dc:creator>michael_HOWARD</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.msdn.com/michael_howard/comments/9891996.aspx</comments><wfw:commentRss>http://blogs.msdn.com/michael_howard/commentrss.aspx?PostID=9891996</wfw:commentRss><description>&lt;P&gt;I'm heading to TechEd Oz and NZ in a couple of hours to present the following:&lt;/P&gt;
&lt;H1 style="MARGIN: 24pt 0in 0pt"&gt;&lt;FONT size=5&gt;&lt;FONT color=#365f91&gt;&lt;FONT face=Cambria&gt;SEC312&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;The "Everything Developers Need to Know About Security" Talk&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/H1&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;DIV style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;Oz: 9/10/2009 15:30-16:45&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/DIV&gt;&lt;/LI&gt;
&lt;LI&gt;
&lt;DIV style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;SPAN style="mso-spacerun: yes"&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Calibri','sans-serif'; FONT-SIZE: 11pt; mso-ascii-theme-font: minor-latin; mso-fareast-font-family: Calibri; mso-fareast-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: 'Times New Roman'; mso-bidi-theme-font: minor-bidi; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA"&gt;NZ: 9/14/2009 14:15-15:30 &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;SPAN style="mso-spacerun: yes"&gt;
&lt;H1 style="MARGIN: 24pt 0in 0pt"&gt;&lt;FONT size=5&gt;&lt;FONT color=#365f91&gt;&lt;FONT face=Cambria&gt;SEC201&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Inside the Microsoft Security Development Lifecycle: And how you can use it!&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/H1&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;DIV style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;Oz: 9/10/2009 11:30-12:45&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/DIV&gt;&lt;/LI&gt;
&lt;LI&gt;
&lt;DIV style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;SPAN style="mso-spacerun: yes"&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Calibri','sans-serif'; FONT-SIZE: 11pt; mso-ascii-theme-font: minor-latin; mso-fareast-font-family: Calibri; mso-fareast-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: 'Times New Roman'; mso-bidi-theme-font: minor-bidi; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA"&gt;NZ: 9/15/2009 12:10-13:25 &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;/UL&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;SPAN style="mso-spacerun: yes"&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Calibri','sans-serif'; FONT-SIZE: 11pt; mso-ascii-theme-font: minor-latin; mso-fareast-font-family: Calibri; mso-fareast-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: 'Times New Roman'; mso-bidi-theme-font: minor-bidi; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA"&gt;I'm also giving a couple of half-day SDL workshops:&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;SPAN style="mso-spacerun: yes"&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Calibri','sans-serif'; FONT-SIZE: 11pt; mso-ascii-theme-font: minor-latin; mso-fareast-font-family: Calibri; mso-fareast-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: 'Times New Roman'; mso-bidi-theme-font: minor-bidi; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA"&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Calibri','sans-serif'; FONT-SIZE: 11pt; mso-ascii-theme-font: minor-latin; mso-fareast-font-family: Calibri; mso-fareast-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: 'Times New Roman'; mso-bidi-theme-font: minor-bidi; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA"&gt;
&lt;H1 style="MARGIN: 24pt 0in 0pt"&gt;&lt;FONT color=#365f91 size=5 face=Cambria&gt;SDL Workshop&lt;/FONT&gt;&lt;/H1&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;DIV style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;SPAN style="mso-spacerun: yes"&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Calibri','sans-serif'; FONT-SIZE: 11pt; mso-ascii-theme-font: minor-latin; mso-fareast-font-family: Calibri; mso-fareast-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: 'Times New Roman'; mso-bidi-theme-font: minor-bidi; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA"&gt;Oz: 9/11/2009 (I'll update once I get the time!)&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/LI&gt;
&lt;LI&gt;
&lt;DIV style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;SPAN style="mso-spacerun: yes"&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Calibri','sans-serif'; FONT-SIZE: 11pt; mso-ascii-theme-font: minor-latin; mso-fareast-font-family: Calibri; mso-fareast-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: 'Times New Roman'; mso-bidi-theme-font: minor-bidi; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA"&gt;NZ: 9/13/2009 &amp;nbsp;10:20 - 13:00&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;/UL&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;SPAN style="mso-spacerun: yes"&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Calibri','sans-serif'; FONT-SIZE: 11pt; mso-ascii-theme-font: minor-latin; mso-fareast-font-family: Calibri; mso-fareast-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: 'Times New Roman'; mso-bidi-theme-font: minor-bidi; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA"&gt;If you cannot make it to TechEd this year, a number of sessions, including SEC201 will be made available through Live Meeting. More info &lt;A href="http://www.msteched.com/australia/Public/techedlive.aspx" mce_href="http://www.msteched.com/australia/Public/techedlive.aspx"&gt;here&lt;/A&gt;.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=9891996" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/michael_howard/archive/tags/Security/default.aspx">Security</category></item><item><title>ATL, MS09-035 and the SDL </title><link>http://blogs.msdn.com/michael_howard/archive/2009/07/28/atl-ms09-035-and-the-sdl.aspx</link><pubDate>Tue, 28 Jul 2009 20:43:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9851205</guid><dc:creator>michael_HOWARD</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.msdn.com/michael_howard/comments/9851205.aspx</comments><wfw:commentRss>http://blogs.msdn.com/michael_howard/commentrss.aspx?PostID=9851205</wfw:commentRss><description>&lt;A href="http://blogs.msdn.com/sdl/archive/2009/07/28/atl-ms09-035-and-the-sdl.aspx"&gt;http://blogs.msdn.com/sdl/archive/2009/07/28/atl-ms09-035-and-the-sdl.aspx&lt;/A&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=9851205" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/michael_howard/archive/tags/Security/default.aspx">Security</category></item><item><title>Integrating the SDL process into Visual Studio</title><link>http://blogs.msdn.com/michael_howard/archive/2009/05/19/integrating-the-sdl-process-into-visual-studio.aspx</link><pubDate>Tue, 19 May 2009 19:53:27 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9628586</guid><dc:creator>michael_HOWARD</dc:creator><slash:comments>1</slash:comments><comments>http://blogs.msdn.com/michael_howard/comments/9628586.aspx</comments><wfw:commentRss>http://blogs.msdn.com/michael_howard/commentrss.aspx?PostID=9628586</wfw:commentRss><description>&lt;p&gt;I’ve been a firm believer of integrating as much security tooling as possible into the development process so developers can get on with developing code and designing solutions rather than having to constantly think about dotting the security “i”s and crossing the security “t”s. &lt;/p&gt;  &lt;p&gt;The less security “friction” the better, because the more you can automate the more progress you can make.&lt;/p&gt;  &lt;p&gt;&lt;a href="http://blogs.msdn.com/sdl/archive/2009/05/19/making-secure-code-easier.aspx"&gt;Jeremy Dallman has just announced&lt;/a&gt; that we have released the Microsoft SDL Process Template for Visual Studio Team System, and yes, it’s free.&lt;/p&gt;  &lt;p&gt;I think this is a huge step forward because now software development teams outside of Microsoft can more easily track their adherence to the SDL. &lt;/p&gt;  &lt;div style="padding-bottom: 0px; margin: 0px; padding-left: 0px; padding-right: 0px; display: inline; float: none; padding-top: 0px" id="scid:0767317B-992E-4b12-91E0-4F059A8CECA8:f9075ad3-9494-4081-b947-eec5c1cc0047" class="wlWriterEditableSmartContent"&gt;Technorati Tags: &lt;a href="http://technorati.com/tags/SDL" rel="tag"&gt;SDL&lt;/a&gt;,&lt;a href="http://technorati.com/tags/Tools" rel="tag"&gt;Tools&lt;/a&gt;&lt;/div&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=9628586" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/michael_howard/archive/tags/Security/default.aspx">Security</category></item><item><title>A Conversation About Threat Modeling</title><link>http://blogs.msdn.com/michael_howard/archive/2009/05/01/a-conversation-about-threat-modeling.aspx</link><pubDate>Fri, 01 May 2009 17:29:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9582435</guid><dc:creator>michael_HOWARD</dc:creator><slash:comments>2</slash:comments><comments>http://blogs.msdn.com/michael_howard/comments/9582435.aspx</comments><wfw:commentRss>http://blogs.msdn.com/michael_howard/commentrss.aspx?PostID=9582435</wfw:commentRss><description>&lt;P&gt;This was fun to write; in fact, other than minor edits I wrote it in a single two hour sitting with my laptop by the pool :)&lt;/P&gt;
&lt;P&gt;&lt;A href="http://msdn.microsoft.com/en-us/magazine/dd727503.aspx"&gt;http://msdn.microsoft.com/en-us/magazine/dd727503.aspx&lt;/A&gt;&lt;/P&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=9582435" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/michael_howard/archive/tags/Security/default.aspx">Security</category></item><item><title>Ken Johnson (Skywing) joins Microsoft</title><link>http://blogs.msdn.com/michael_howard/archive/2009/03/24/ken-johnson-skywing-joins-microsoft.aspx</link><pubDate>Wed, 25 Mar 2009 01:27:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9505425</guid><dc:creator>michael_HOWARD</dc:creator><slash:comments>7</slash:comments><comments>http://blogs.msdn.com/michael_howard/comments/9505425.aspx</comments><wfw:commentRss>http://blogs.msdn.com/michael_howard/commentrss.aspx?PostID=9505425</wfw:commentRss><description>&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;Following close on the heels of security experts&amp;nbsp;&lt;A href="http://blogs.msdn.com/michael_howard/archive/2008/08/18/matt-miller-joins-the-security-science-team.aspx" mce_href="http://blogs.msdn.com/michael_howard/archive/2008/08/18/matt-miller-joins-the-security-science-team.aspx"&gt;Matt Miller&lt;/A&gt;, &lt;A href="http://blogs.msdn.com/michael_howard/archive/2006/06/26/647690.aspx" mce_href="http://blogs.msdn.com/michael_howard/archive/2006/06/26/647690.aspx"&gt;Adam Shostack&lt;/A&gt; and &lt;A href="http://blogs.msdn.com/michael_howard/archive/2008/01/17/crispin-cowan-joins-the-windows-security-team.aspx" mce_href="http://blogs.msdn.com/michael_howard/archive/2008/01/17/crispin-cowan-joins-the-windows-security-team.aspx"&gt;Crispin Cowan&lt;/A&gt; joining Microsoft, I am pleased to announce that Ken Johnson, AKA Skywing, has joined our group. &lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;Ken brings an enormous amount of reverse engineering and defense-subversion skill to Microsoft. Ken will be working on anything and everything related vulnerabilities, exploits, defenses, bypassing defenses and more. Ken also maintains a blog on debugging, reverse engineering, and security-related topics (along with various personal projects) at: &lt;/FONT&gt;&lt;A href="http://www.nynaeve.net/"&gt;&lt;FONT color=#0000ff size=3 face=Calibri&gt;http://www.nynaeve.net&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=3 face=Calibri&gt;.&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;FONT size=3 face=Calibri&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;Welcome, Ken!&lt;/FONT&gt;&lt;/P&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=9505425" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/michael_howard/archive/tags/Security/default.aspx">Security</category></item><item><title>Free Download: Writing Secure Code for Windows Vista</title><link>http://blogs.msdn.com/michael_howard/archive/2008/12/30/free-download-writing-secure-code-for-windows-vista.aspx</link><pubDate>Wed, 31 Dec 2008 07:07:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9258039</guid><dc:creator>michael_HOWARD</dc:creator><slash:comments>4</slash:comments><comments>http://blogs.msdn.com/michael_howard/comments/9258039.aspx</comments><wfw:commentRss>http://blogs.msdn.com/michael_howard/commentrss.aspx?PostID=9258039</wfw:commentRss><description>&lt;P class=PreviewText&gt;"For 25 years, Microsoft Press books have focused on helping you take your skills and knowledge to the next level. Celebrate our 25th Anniversary with a "Free E-Book of the Month" offer! Simply sign up for the Microsoft Press Book Connection Newsletter for notification of offers, register, and download the selection of the month."&lt;/P&gt;
&lt;P class=PreviewText&gt;&lt;A href="http://csna01.libredigital.com/?urrs4gt63d"&gt;http://csna01.libredigital.com/?urrs4gt63d&lt;/A&gt;&lt;/P&gt;
&lt;P class=PreviewText&gt;:)&lt;/P&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=9258039" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/michael_howard/archive/tags/Security/default.aspx">Security</category><category domain="http://blogs.msdn.com/michael_howard/archive/tags/Vista/default.aspx">Vista</category></item><item><title>Secure software development practices 'not rocket science'</title><link>http://blogs.msdn.com/michael_howard/archive/2008/12/08/secure-software-development-practices-not-rocket-science.aspx</link><pubDate>Tue, 09 Dec 2008 01:09:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9185589</guid><dc:creator>michael_HOWARD</dc:creator><slash:comments>2</slash:comments><comments>http://blogs.msdn.com/michael_howard/comments/9185589.aspx</comments><wfw:commentRss>http://blogs.msdn.com/michael_howard/commentrss.aspx?PostID=9185589</wfw:commentRss><description>&lt;A href="http://searchsoftwarequality.techtarget.com/news/article/0,289142,sid92_gci1340940,00.html"&gt;http://searchsoftwarequality.techtarget.com/news/article/0,289142,sid92_gci1340940,00.html&lt;/A&gt;#&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=9185589" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/michael_howard/archive/tags/Security/default.aspx">Security</category></item><item><title>Improvements in Office Security </title><link>http://blogs.msdn.com/michael_howard/archive/2008/11/17/improvements-in-office-security.aspx</link><pubDate>Tue, 18 Nov 2008 07:59:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9116639</guid><dc:creator>michael_HOWARD</dc:creator><slash:comments>2</slash:comments><comments>http://blogs.msdn.com/michael_howard/comments/9116639.aspx</comments><wfw:commentRss>http://blogs.msdn.com/michael_howard/commentrss.aspx?PostID=9116639</wfw:commentRss><description>&lt;P&gt;David LeBlanc has an &lt;A href="http://blogs.msdn.com/david_leblanc/archive/2008/11/17/improvements-in-office-security.aspx" mce_href="http://blogs.msdn.com/david_leblanc/archive/2008/11/17/improvements-in-office-security.aspx"&gt;excellent write-up&lt;/A&gt; of the results (so far) of all the security work the Office guys have been doing over the last few years. &lt;/P&gt;
&lt;P&gt;Net: about a 50% reduction in vulns!&lt;/P&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=9116639" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/michael_howard/archive/tags/Security/default.aspx">Security</category></item><item><title>Volume 5 of the Microsoft Security Intelligence Report is out</title><link>http://blogs.msdn.com/michael_howard/archive/2008/11/03/volume-5-of-the-microsoft-security-intelligence-report-is-out.aspx</link><pubDate>Mon, 03 Nov 2008 17:16:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9033311</guid><dc:creator>michael_HOWARD</dc:creator><slash:comments>2</slash:comments><comments>http://blogs.msdn.com/michael_howard/comments/9033311.aspx</comments><wfw:commentRss>http://blogs.msdn.com/michael_howard/commentrss.aspx?PostID=9033311</wfw:commentRss><description>Volume 5 of the Microsoft Security Intelligence Report is &lt;A href="http://www.microsoft.com/security/portal/sir.aspx" mce_href="http://www.microsoft.com/security/portal/sir.aspx"&gt;now out&lt;/A&gt;, highlights include:&lt;/FONT&gt; 
&lt;UL&gt;
&lt;LI&gt;
&lt;DIV style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in" class=MsoListParagraph&gt;&lt;FONT size=3 face=Calibri&gt;Security vulnerability disclosures - Microsoft and third-party software&lt;/FONT&gt;&lt;/DIV&gt;&lt;/LI&gt;
&lt;LI&gt;
&lt;DIV style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in" class=MsoListParagraph&gt;&lt;FONT size=3 face=Calibri&gt;Vulnerability Exploits – Microsoft software&lt;/FONT&gt;&lt;/DIV&gt;&lt;/LI&gt;
&lt;LI&gt;
&lt;DIV style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in" class=MsoListParagraph&gt;&lt;FONT size=3 face=Calibri&gt;Browser-based exploits - Microsoft and third-party software &lt;/FONT&gt;&lt;/DIV&gt;&lt;/LI&gt;
&lt;LI&gt;
&lt;DIV style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in" class=MsoListParagraph&gt;&lt;FONT size=3 face=Calibri&gt;Security and privacy breaches&lt;/FONT&gt;&lt;/DIV&gt;&lt;/LI&gt;
&lt;LI&gt;
&lt;DIV style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in" class=MsoListParagraph&gt;&lt;FONT size=3 face=Calibri&gt;Malicious and potentially unwanted software trends&lt;/FONT&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;/UL&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;Volume 5 of the SIR also includes a detailed examination of the threat ecosystem which explains how threats propagate across the internet, how users become infected and the resultant impact on privacy and identity theft.&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;The one item that stood out for me was the move from successfully attacking Microsoft applications and browser objects to attacking and compromising 3rd-party applictions and browser objects.&lt;/FONT&gt;&lt;/P&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=9033311" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/michael_howard/archive/tags/Security/default.aspx">Security</category><category domain="http://blogs.msdn.com/michael_howard/archive/tags/Vista/default.aspx">Vista</category></item><item><title>Security-Related MSDN Magazine Articles</title><link>http://blogs.msdn.com/michael_howard/archive/2008/10/28/security-related-msdn-magazine-articles.aspx</link><pubDate>Tue, 28 Oct 2008 21:38:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9020695</guid><dc:creator>michael_HOWARD</dc:creator><slash:comments>1</slash:comments><comments>http://blogs.msdn.com/michael_howard/comments/9020695.aspx</comments><wfw:commentRss>http://blogs.msdn.com/michael_howard/commentrss.aspx?PostID=9020695</wfw:commentRss><description>&lt;P&gt;Bryan Sullivan and I wrote a couple of articles for this month's MSDN Magazine. If you're not aware, November focuses on Security. &lt;/P&gt;
&lt;P&gt;The two articles are:&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;A href="http://msdn.microsoft.com/en-us/magazine/cc982154.aspx"&gt;&lt;FONT size=3 face=Calibri&gt;Test Your Security IQ&lt;/FONT&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;A href="http://msdn.microsoft.com/en-us/magazine/dd148644.aspx"&gt;&lt;FONT size=3 face=Calibri&gt;Threat Models Improve Your Security Process&lt;/FONT&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal mce_keep="true"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;And there's the Agile SDL paper than I already &lt;A href="http://blogs.msdn.com/michael_howard/archive/2008/10/28/agile-sdl.aspx" mce_href="http://blogs.msdn.com/michael_howard/archive/2008/10/28/agile-sdl.aspx"&gt;mentioned&lt;/A&gt;. &lt;/P&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=9020695" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/michael_howard/archive/tags/Security/default.aspx">Security</category></item><item><title>Agile SDL</title><link>http://blogs.msdn.com/michael_howard/archive/2008/10/28/agile-sdl.aspx</link><pubDate>Tue, 28 Oct 2008 21:35:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9020691</guid><dc:creator>michael_HOWARD</dc:creator><slash:comments>2</slash:comments><comments>http://blogs.msdn.com/michael_howard/comments/9020691.aspx</comments><wfw:commentRss>http://blogs.msdn.com/michael_howard/commentrss.aspx?PostID=9020691</wfw:commentRss><description>Over the last year or so, a bunch of us in the SDL team have been working with agile groups across Microsoft to help streamline the SDL for agile methods. Bryan Sullivan &lt;A href="http://msdn.microsoft.com/en-us/magazine/dd153756.aspx" mce_href="http://msdn.microsoft.com/en-us/magazine/dd153756.aspx"&gt;wrote a paper&lt;/A&gt; for MSDN Magazine explaining where our current throughts lie. Clearly this is just the start, we have some more work to do, but we thought it would be worthwhile putting our ideas out there to get feedback and comments.&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=9020691" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/michael_howard/archive/tags/Security/default.aspx">Security</category></item><item><title>SAFECode releases "Fundamental Practices for Secure Software Development" document</title><link>http://blogs.msdn.com/michael_howard/archive/2008/10/08/safecode-releases-fundamental-practices-for-secure-software-development-document.aspx</link><pubDate>Wed, 08 Oct 2008 20:04:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8991701</guid><dc:creator>michael_HOWARD</dc:creator><slash:comments>4</slash:comments><comments>http://blogs.msdn.com/michael_howard/comments/8991701.aspx</comments><wfw:commentRss>http://blogs.msdn.com/michael_howard/commentrss.aspx?PostID=8991701</wfw:commentRss><description>&lt;P&gt;Today, &lt;A href="http://www.safecode.org/" mce_href="http://www.safecode.org/"&gt;SAFECode&lt;/A&gt; released an important document entitled, “&lt;A href="http://www.safecode.org/publications/SAFECode_Dev_Practices1008.pdf" mce_href="http://www.safecode.org/publications/SAFECode_Dev_Practices1008.pdf"&gt;Fundamental Practices for Secure Software Development&lt;/A&gt;” aimed at helping software producers create more secure software. &lt;/P&gt;
&lt;P&gt;The document is unique in that it describes what SAFECode members are doing in practice to raise the security bar; it’s not a theoretical or academic document. &lt;/P&gt;
&lt;P&gt;I believe the fact that it describes what’s used &lt;STRONG&gt;&lt;EM&gt;in practice&lt;/EM&gt;&lt;/STRONG&gt; is what makes the document important because it means the ideas in the document can be implemented in the real world regardless of the type of software under development.&lt;/P&gt;
&lt;P&gt;So take a look, and let me know what you think.&lt;BR&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Updated: &lt;/STRONG&gt;first review from &lt;A href="http://weblog.infoworld.com/stratdev/archives/2008/10/new_report_outl.html" mce_href="http://weblog.infoworld.com/stratdev/archives/2008/10/new_report_outl.html"&gt;InfoWorld&lt;/A&gt;. &lt;/P&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=8991701" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/michael_howard/archive/tags/Security/default.aspx">Security</category></item><item><title>Practical Defense in Depth</title><link>http://blogs.msdn.com/michael_howard/archive/2008/09/26/practical-defense-in-depth.aspx</link><pubDate>Fri, 26 Sep 2008 22:50:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8966965</guid><dc:creator>michael_HOWARD</dc:creator><slash:comments>1</slash:comments><comments>http://blogs.msdn.com/michael_howard/comments/8966965.aspx</comments><wfw:commentRss>http://blogs.msdn.com/michael_howard/commentrss.aspx?PostID=8966965</wfw:commentRss><description>&lt;P&gt;&amp;lt;sent from Cabo San Lucas Airport - heading back to Austin&amp;nbsp;&amp;gt;&lt;/P&gt;
&lt;P&gt;Crosstalk has &lt;A href="http://www.stsc.hill.af.mil/crosstalk/2008/09/0809howard.html" mce_href="http://www.stsc.hill.af.mil/crosstalk/2008/09/0809howard.html"&gt;published&lt;/A&gt; an article for mine regarding how we use Defense in Depth within the SDL, and in Microsoft in general. &lt;/P&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=8966965" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/michael_howard/archive/tags/Security/default.aspx">Security</category></item><item><title>SDL Evolution</title><link>http://blogs.msdn.com/michael_howard/archive/2008/09/16/sdl-evolution.aspx</link><pubDate>Wed, 17 Sep 2008 07:02:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8954824</guid><dc:creator>michael_HOWARD</dc:creator><slash:comments>2</slash:comments><comments>http://blogs.msdn.com/michael_howard/comments/8954824.aspx</comments><wfw:commentRss>http://blogs.msdn.com/michael_howard/commentrss.aspx?PostID=8954824</wfw:commentRss><description>&lt;P&gt;&amp;nbsp;&lt;STRONG&gt;UPDATED&lt;/STRONG&gt;: Added IOActive post&lt;/P&gt;
&lt;P&gt;As many of you have &lt;A href="http://blogs.msdn.com/sdl/default.aspx" mce_href="http://blogs.msdn.com/sdl/default.aspx"&gt;seen today&lt;/A&gt;, there's been plenty of press about us opening up the SDL for use by other software developers and releasing our threat modeling tool. For those of you who have no clue what the heck I'm talking about, here are a&amp;nbsp;handful of articles about what happened today:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A target=_blank href="http://news.cnet.com/8301-1009_3-10042248-83.html"&gt;Microsoft becomes high priest of secure software development&lt;/A&gt;&amp;nbsp;(C|Net)&lt;/LI&gt;
&lt;LI&gt;&lt;A target=_blank href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;amp;articleId=9114858&amp;amp;intsrc=news_ts_head"&gt;Microsoft looks to spread secure software expertise&lt;/A&gt;&amp;nbsp;(Computerworld)&lt;/LI&gt;
&lt;LI&gt;&lt;A href="http://www.darkreading.com/document.asp?doc_id=163949" mce_href="http://www.darkreading.com/document.asp?doc_id=163949 "&gt;Microsoft to Share Its Secure Development Blueprint, Threat Modeling Tool&lt;/A&gt;&amp;nbsp;(Dark Reading)&lt;/LI&gt;&lt;/UL&gt;
&lt;P&gt;I'm not sure about the "High Priest" moniker, but what the heck :)&lt;/P&gt;
&lt;P&gt;Cigital also &lt;A href="http://www.cigital.com/justiceleague/2008/09/16/strengthening-software-security-through-collaboration/" mce_href="http://www.cigital.com/justiceleague/2008/09/16/strengthening-software-security-through-collaboration/"&gt;blogged&lt;/A&gt; about the event, most notably the SDL Pro Network, and IOActive &lt;A href="http://www.ioactive.com/pdfs/ThoughtsOnMSSDL.pdf" mce_href="http://www.ioactive.com/pdfs/ThoughtsOnMSSDL.pdf"&gt;posted&lt;/A&gt; some comments too.&lt;/P&gt;
&lt;P&gt;I'm &lt;STRONG&gt;&lt;U&gt;really&lt;/U&gt;&lt;/STRONG&gt; excited to see the SDL move forward and most importantly, outward. We have learned a great deal about what it takes to make steps toward securing software. We don't expect perfection, but if more people embrace some of the principles we define in the SDL, and we have experienced and knowledgable partners scale the effort,&amp;nbsp;I think the IT world will be a substantially more secure place.&lt;/P&gt;
&lt;P&gt;-Michael&lt;/P&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=8954824" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/michael_howard/archive/tags/Security/default.aspx">Security</category></item><item><title>GOOG Chrome's use of NX/DEP</title><link>http://blogs.msdn.com/michael_howard/archive/2008/09/15/goog-chrome-s-use-of-nx-dep.aspx</link><pubDate>Mon, 15 Sep 2008 17:18:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8952595</guid><dc:creator>michael_HOWARD</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.msdn.com/michael_howard/comments/8952595.aspx</comments><wfw:commentRss>http://blogs.msdn.com/michael_howard/commentrss.aspx?PostID=8952595</wfw:commentRss><description>&lt;P&gt;Scott Hanselman has &lt;A href="http://www.hanselman.com/blog/TheWeeklySourceCode33MicrosoftOpenSourceInsideGoogleChrome.aspx" mce_href="http://www.hanselman.com/blog/TheWeeklySourceCode33MicrosoftOpenSourceInsideGoogleChrome.aspx"&gt;a look&lt;/A&gt; under Chrome's hood and how it uses the &lt;A href="http://blogs.msdn.com/michael_howard/archive/2008/01/29/new-nx-apis-added-to-windows-vista-sp1-windows-xp-sp3-and-windows-server-2008.aspx" mce_href="http://blogs.msdn.com/michael_howard/archive/2008/01/29/new-nx-apis-added-to-windows-vista-sp1-windows-xp-sp3-and-windows-server-2008.aspx"&gt;new NX/DEP APIs we added to Windows&lt;/A&gt;. &lt;/P&gt;
&lt;P&gt;Scroll about halfway down the article. &lt;/P&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=8952595" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/michael_howard/archive/tags/Security/default.aspx">Security</category></item></channel></rss>