<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.msdn.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Security for Canadian Developers : Annoucements</title><link>http://blogs.msdn.com/s4cd/archive/tags/Annoucements/default.aspx</link><description>Tags: Annoucements</description><dc:language>en</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>Developer Windows Vista Security Webcast in May</title><link>http://blogs.msdn.com/s4cd/archive/2007/04/16/developer-windows-vista-security-webcast-in-may.aspx</link><pubDate>Mon, 16 Apr 2007 19:19:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:2155186</guid><dc:creator>jldavid</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.msdn.com/s4cd/comments/2155186.aspx</comments><wfw:commentRss>http://blogs.msdn.com/s4cd/commentrss.aspx?PostID=2155186</wfw:commentRss><description>&lt;P&gt;As you can tell, there is a lot of activity going on with regards to Windows Vista. On May 23rd, we will be running a webcast entitled "&lt;A class="" href="http://msevents.microsoft.com/CUI/WebCastEventDetails.aspx?EventID=1032336165&amp;amp;EventCategory=4&amp;amp;culture=en-CA&amp;amp;CountryCode=CA" target=_blank mce_href="http://msevents.microsoft.com/CUI/WebCastEventDetails.aspx?EventID=1032336165&amp;amp;EventCategory=4&amp;amp;culture=en-CA&amp;amp;CountryCode=CA"&gt;&lt;STRONG&gt;Writing Secure Applications for Windows Vista&lt;/STRONG&gt;&lt;/A&gt;". Here is an abstract of the presentation:&lt;BR&gt;&lt;BR&gt;Have you tested your application on Windows Vista? If not, it’s important that you do as it will impact the experience your users will have with the software you have developed. This is especially the case if your application writes to the registry or requires elevated privileges.&lt;/P&gt;
&lt;P&gt;The primary objective of this session is to provide developers with the necessary knowledge to successfully write secure application on Windows Vista and get familiarized with Vista’s new security model and features such as Least-privileged User Accounts (LUA), virtualization, and the User Account Control (UAC).&amp;nbsp; This session will be of interest to all &lt;BR&gt;Windows developers.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Value proposition&lt;/STRONG&gt;:&lt;BR&gt;Windows Vista incorporates many new and innovative security features. This session will provide the attendees with the following information:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;How Vista’s security enhancements may affect their application development environment&amp;nbsp; &lt;/LI&gt;
&lt;LI&gt;How to successfully write Windows Vista applications leveraging features such as UAC &lt;/LI&gt;
&lt;LI&gt;The use of tools such as FxCop and PreFAST to identify compatible issues in existing applications or in the development process.&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/LI&gt;&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;Call to Action&lt;/STRONG&gt;:&lt;BR&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Start developing secure applications on Windows Vista &lt;/LI&gt;
&lt;LI&gt;Use tools like FxCop to find compatible issues with existing applications or new applications in development &lt;/LI&gt;
&lt;LI&gt;Take advantage of the new security tidbits added to Windows Vista&lt;/LI&gt;&lt;/UL&gt;
&lt;P&gt;To sign up for the event, click on this link: &lt;A href="http://msevents.microsoft.com/CUI/WebCastEventDetails.aspx?EventID=1032336165&amp;amp;EventCategory=4&amp;amp;culture=en-CA&amp;amp;CountryCode=CA"&gt;http://msevents.microsoft.com/CUI/WebCastEventDetails.aspx?EventID=1032336165&amp;amp;EventCategory=4&amp;amp;culture=en-CA&amp;amp;CountryCode=CA&lt;/A&gt;&lt;/P&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=2155186" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/s4cd/archive/tags/Annoucements/default.aspx">Annoucements</category><category domain="http://blogs.msdn.com/s4cd/archive/tags/Security+Testing/default.aspx">Security Testing</category><category domain="http://blogs.msdn.com/s4cd/archive/tags/Announcements/default.aspx">Announcements</category><category domain="http://blogs.msdn.com/s4cd/archive/tags/Webcasts/default.aspx">Webcasts</category><category domain="http://blogs.msdn.com/s4cd/archive/tags/Windows+Vista/default.aspx">Windows Vista</category><category domain="http://blogs.msdn.com/s4cd/archive/tags/Security+On+The+Brain/default.aspx">Security On The Brain</category></item><item><title>IT Professional Security Webcasts</title><link>http://blogs.msdn.com/s4cd/archive/2007/04/16/it-professional-security-webcasts.aspx</link><pubDate>Mon, 16 Apr 2007 17:17:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:2154185</guid><dc:creator>jldavid</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.msdn.com/s4cd/comments/2154185.aspx</comments><wfw:commentRss>http://blogs.msdn.com/s4cd/commentrss.aspx?PostID=2154185</wfw:commentRss><description>&lt;P&gt;&lt;A class="" href="http://blogs.technet.com/canitpro/" target=_blank mce_href="http://blogs.technet.com/canitpro/"&gt;Rodney Buike&lt;/A&gt;, my counterpart on the IT Pro team has set up a security webcast series which may be interesting to you. Here is a description of the series and the events:&lt;/P&gt;
&lt;P&gt;With every new OS release security is improved and refined and with Windows Vista this is still the case.&amp;nbsp;There are a number of new and improved security tools and features built into Windows Vista, and a number of new tools and resources to integrate Vista into your existing environment.&amp;nbsp;Learning what these features are, how to plan for them, deploy them and manage them along with what resources are available to help is crucial to a successful deployment.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;What’s New in Vista Security - April 25th 2007&lt;/STRONG&gt; &lt;BR&gt;With all the new eye candy in Vista, the security features often get overlooked.&amp;nbsp; The first session will look at the new features, what they are, where they would be used and most importantly why you should consider implementing them.&amp;nbsp; At the end of this session you should have a good understanding of some kernel level changes and features such as User Access Control, upgrades to the Windows Vista Firewall and Security Center, BitLocker and IE7 and be ready to start implementing a secure Vista deployment.&lt;BR&gt;&lt;A href="http://msevents.microsoft.com/CUI/EventDetail.aspx?EventID=1032336945&amp;amp;Culture=en-CA"&gt;http://msevents.microsoft.com/CUI/EventDetail.aspx?EventID=1032336945&amp;amp;Culture=en-CA&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Manage Vista Security With Group Policy - May 9th 2007&lt;/STRONG&gt;&lt;BR&gt;Managing Vista via Group Policy has been improved.&amp;nbsp; With over 2400 GPO settings you have more control than ever before and tools like the GPO Accelerator can help speed the implementation of GPOs over your Vista computers and ease management of BitLocker on mobile PCs.&amp;nbsp; This session will start by giving you a refresh of GPO and OU structures and get you up to speed on the new GPO settings, the GPO Accelerator and other resources and how they can be used to lockdown and secure your environment.&lt;BR&gt;&lt;A href="http://msevents.microsoft.com/CUI/EventDetail.aspx?EventID=1032336947&amp;amp;Culture=en-CA"&gt;http://msevents.microsoft.com/CUI/EventDetail.aspx?EventID=1032336947&amp;amp;Culture=en-CA&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Manage Advanced Security Features&amp;nbsp;- May 23rd 2007&lt;/STRONG&gt;&lt;BR&gt;On top of the new GPO settings there are some new, more advanced, security features in Vista.&amp;nbsp; BitLocker is one of the popular features and we will take a deep dive into BitLocker covering TPM, key backup, management via group policy and configuration will be covered in this session.&amp;nbsp; We will also take a look at improvements to the Encrypted File System (EFS) and Rights Management Services (RMS).&lt;BR&gt;&lt;A href="http://msevents.microsoft.com/CUI/EventDetail.aspx?EventID=1032336949&amp;amp;Culture=en-CA"&gt;http://msevents.microsoft.com/CUI/EventDetail.aspx?EventID=1032336949&amp;amp;Culture=en-CA&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;We hope you can attend...cheers!&lt;/P&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=2154185" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/s4cd/archive/tags/Annoucements/default.aspx">Annoucements</category><category domain="http://blogs.msdn.com/s4cd/archive/tags/Security+Testing/default.aspx">Security Testing</category><category domain="http://blogs.msdn.com/s4cd/archive/tags/Announcements/default.aspx">Announcements</category><category domain="http://blogs.msdn.com/s4cd/archive/tags/Webcasts/default.aspx">Webcasts</category><category domain="http://blogs.msdn.com/s4cd/archive/tags/Windows+Vista/default.aspx">Windows Vista</category></item><item><title>MSDN Canada: Security Virtual Conference Recording</title><link>http://blogs.msdn.com/s4cd/archive/2006/09/29/777818.aspx</link><pubDate>Sat, 30 Sep 2006 08:12:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:777818</guid><dc:creator>dansellers</dc:creator><slash:comments>1</slash:comments><comments>http://blogs.msdn.com/s4cd/comments/777818.aspx</comments><wfw:commentRss>http://blogs.msdn.com/s4cd/commentrss.aspx?PostID=777818</wfw:commentRss><description>&lt;P&gt;As promised, &lt;A href="https://www107.livemeeting.com/cc/lmevents/view?id=msft092706jd&amp;amp;role=attend&amp;amp;pw=A23SNC" target=_blank&gt;here&lt;/A&gt; is the recording of MSDN Canada Writing Secure Code Fundamentals Virtual Conference.&amp;nbsp; &lt;/P&gt;
&lt;P&gt;Enjoy the recording and I hope to see you at our next online Security sessions on October 18th, 2006.&amp;nbsp; This will be the first of eight, one hour &lt;A href="http://msdn.microsoft.com/canada/securitylockdown/#monthlycalendar" target=_blank&gt;monthly security sessions&lt;/A&gt;.&amp;nbsp; I am excited about the next session as it will provide you the knowledge and a demonstration of various tools that one can&amp;nbsp;use to do preliminary&amp;nbsp;testing to verify if an application written by an outside firm is in fact secure.&amp;nbsp; &lt;/P&gt;
&lt;P&gt;When you ask someone if their application is secure, the answer is &lt;STRONG&gt;&lt;EM&gt;&lt;FONT color=#ff0000&gt;always&lt;/FONT&gt;&lt;/EM&gt;&lt;/STRONG&gt; yes.&amp;nbsp; Seriously, do you really think any one will say no?&amp;nbsp; Of course not as they just lost that sale and most likely future revenue.&amp;nbsp; So what is the incentive to say either "no" or&amp;nbsp;"I&amp;nbsp;do not know"?&amp;nbsp; Therefore, how do you really know if&amp;nbsp;any application is secure if you are&amp;nbsp;not going to do some&amp;nbsp;preliminary&amp;nbsp;security testing.&amp;nbsp; &lt;/P&gt;
&lt;P&gt;Don't get trapped into what you want to hear whether it is true or not.&amp;nbsp; This just leads to a false sense of security and you might as well&amp;nbsp;continue sticking your head in the sand.&lt;/P&gt;
&lt;P&gt;Below is the thought process that occurs when you ask someone if their application is secure:&lt;/P&gt;
&lt;P&gt;public static void main()&lt;/P&gt;
&lt;P&gt;{ &lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;Console.WriteLine("Is App Secure: 1=Yes 2=No 3=Not Sure");&lt;BR&gt;Console.Write("Please enter your selection: "); &lt;/P&gt;
&lt;P&gt;string s = Console.ReadLine(); &lt;/P&gt;int n = int.Parse(s);&lt;BR&gt;int revenue= 0; &lt;/BLOCKQUOTE&gt;
&lt;P&gt;&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;switch(n) &lt;BR&gt;{&lt;/P&gt;
&lt;P&gt;case 1: &lt;BR&gt;revenue+= 25,000; &lt;BR&gt;break; &lt;/P&gt;&lt;/BLOCKQUOTE&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;case 2: &lt;BR&gt;revenue+= 0; //oh wait no revenue...just kidding...&lt;BR&gt;goto case 1; //therefore say yes&lt;/P&gt;
&lt;P&gt;case 3: &lt;BR&gt;revenue+= 0; //oh wait no revenue...just kidding...&lt;BR&gt;goto case 1; //therefore say yes &lt;/P&gt;
&lt;P&gt;default: &lt;BR&gt;revenue+=0; //go for the revenue&lt;BR&gt;goto case 1; //this is the answer everyone wants to hear break; &lt;/P&gt;&lt;/BLOCKQUOTE&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;} &lt;/P&gt;&lt;/BLOCKQUOTE&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;if (revenue!= 0) &lt;BR&gt;Console.WriteLine("Thank you for your business and of course the {0} dollars. Oh and you can Trust Me too!!",revenue);&lt;/P&gt;
&lt;P&gt;}&lt;/P&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;}&lt;/P&gt;
&lt;P&gt;You can register for the October 18th on-line event&amp;nbsp;&lt;A href="https://msevents.microsoft.com/cui/WebCastEventDetails.aspx?EventID=1032308040&amp;amp;EventCategory=2&amp;amp;culture=en-ca&amp;amp;CountryCode=CA" target=_blank&gt;here&lt;/A&gt;.&lt;/P&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=777818" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/s4cd/archive/tags/Annoucements/default.aspx">Annoucements</category><category domain="http://blogs.msdn.com/s4cd/archive/tags/Post+Event+Recap/default.aspx">Post Event Recap</category></item><item><title>Half Day Virtual Security Conference--September 27th, 2006</title><link>http://blogs.msdn.com/s4cd/archive/2006/09/05/741690.aspx</link><pubDate>Wed, 06 Sep 2006 00:31:58 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:741690</guid><dc:creator>dansellers</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.msdn.com/s4cd/comments/741690.aspx</comments><wfw:commentRss>http://blogs.msdn.com/s4cd/commentrss.aspx?PostID=741690</wfw:commentRss><description>&lt;p&gt;To continue upon the success of last year MSDN Canada Security Webcasts we have raised the level up a notch or two this year.&amp;nbsp; This year will consist of two Virtual Conferences and eight Security Webcasts titled "Security Chalk Talk" occurring monthly from October 2006 to June 2007.&amp;nbsp; Furthermore, I will be producing six podcasts titled "Talkin' Security" in which we will be hearing from Security experts in Canada on a multitude of topics.&amp;nbsp; &lt;/p&gt; &lt;p&gt;&lt;a href="http://msdn.microsoft.com/canada/securitylockdown/default.aspx" target="_blank"&gt;http://msdn.Microsoft.com/Canada/securitylockdown/&lt;/a&gt;&amp;nbsp;and for the French version: &lt;a href="http://msdn.microsoft.com/canada/fr/securitylockdown/default.aspx" target="_blank"&gt;http://msdn.microsoft.com/canada/fr/securitylockdown/&lt;/a&gt;&lt;/p&gt; &lt;p&gt;The first half day Virtual Security Conference on "Writing Secure Code Fundamentals" is already upon us.&amp;nbsp; The &lt;a href="http://www.microsoft.com/canada/events/event_details_ww.aspx?event_id=1032305730" target="_blank"&gt;registration&lt;/a&gt; just went live today.&amp;nbsp; For this Virtual conference I will be joined by two members of Microsoft ACE (Security) team from Redmond.&amp;nbsp; Both the speakers &lt;a href="http://msdn.microsoft.com/canada/securitylockdown/bio.aspx" target="_blank"&gt;bios&lt;/a&gt; and &lt;a href="http://msdn.microsoft.com/canada/securitylockdown/#sessiondetails" target="_blank"&gt;sessions&lt;/a&gt; can be viewed.&lt;/p&gt; &lt;p&gt;This half-day virtual conference will focus on the well-known Application hacking exploits and some of the newer ones with technologies such as AJAX becoming more popular.&amp;nbsp; And of course a detailed look at the necessary countermeasures will be explored.&amp;nbsp; Finally, we will&amp;nbsp;wrap up the conference by talking about threat modeling and the new threat modeling tool Microsoft has released.&amp;nbsp; &lt;/p&gt; &lt;p&gt;Hope to see you out at this first ever MSDN Canada Virtual Security Conference.&lt;/p&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=741690" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/s4cd/archive/tags/Annoucements/default.aspx">Annoucements</category></item><item><title>New Security Blog for Canadian Developers</title><link>http://blogs.msdn.com/s4cd/archive/2006/08/23/716123.aspx</link><pubDate>Thu, 24 Aug 2006 07:03:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:716123</guid><dc:creator>dansellers</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.msdn.com/s4cd/comments/716123.aspx</comments><wfw:commentRss>http://blogs.msdn.com/s4cd/commentrss.aspx?PostID=716123</wfw:commentRss><description>&lt;P&gt;Welcome to this new blog dedicated 100% to Security for Canadian Developers. This blog will feature posts on a wide variety of helpful information that Developers should know to help make your applications more secure. 
&lt;P&gt;Helping me this year will be a team of Security Matter Experts consisting of Architects and Developers that work in Canadian software industry. Currently, I also have my original &lt;A href="http://blogs.msdn.com/dansellers/" target=_blank&gt;&lt;FONT color=#669966&gt;blog&lt;/FONT&gt;&lt;/A&gt; which contains a lot of helpful information on security as well as other topics. After listening to your feedback I felt it was necessary to create this new blog to make it easier to find&amp;nbsp;security related information from myself and my team of Security experts. 
&lt;P&gt;In fact my next post will be on IIS 6.0 and ASP.Net 2.0. The reason I picked this for my first topic, is because I am surprised by the number of people that believe by running the IIS 6.0 in an application pool with a low privilege account will prevent hacks against Web Applications. I wish security was that easy and this was the silver bullet everyone is searching for to prevent Web attacks. Now obviously, you want to use a low privilege account, but we need to do a lot more in terms of how we do input validation and what credentials are being passed between IIS 6.0 and our ASP.Net 2.0 applications. Stay tune to my next blog on this topic in a lot more detail.&lt;/P&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=716123" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/s4cd/archive/tags/Annoucements/default.aspx">Annoucements</category></item></channel></rss>