<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/atom.xsl" media="screen"?><feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-US"><title type="html">Security Minded - from Kai the Security Guy</title><subtitle type="html">Some thoughts on security (and other stuff) from a Microsoft security professional</subtitle><id>http://blogs.technet.com/b/kaiaxford/atom.aspx</id><link rel="alternate" type="text/html" href="http://blogs.technet.com/b/kaiaxford/" /><link rel="self" type="application/atom+xml" href="http://blogs.technet.com/b/kaiaxford/atom.aspx" /><generator uri="http://telligent.com" version="5.6.50428.7875">Telligent Evolution Platform Developer Build (Build: 5.6.50428.7875)</generator><updated>2008-09-10T05:42:00Z</updated><entry><title>Farewell! Kai Axford is Leaving Microsoft</title><link rel="alternate" type="text/html" href="http://blogs.technet.com/b/kaiaxford/archive/2009/12/29/farewell-kai-axford-is-leaving-microsoft.aspx" /><id>http://blogs.technet.com/b/kaiaxford/archive/2009/12/29/farewell-kai-axford-is-leaving-microsoft.aspx</id><published>2009-12-29T17:07:23Z</published><updated>2009-12-29T17:07:23Z</updated><content type="html">&lt;p&gt;&lt;img style="display: inline; margin-left: 0px; margin-right: 0px" title="empty_stage.jpg" alt="empty_stage.jpg" align="left" src="http://ts1.mm.bing.net/images/thumbnail.aspx?q=1331780853744&amp;amp;id=05743ebe03f9256fb530d62e459f1435&amp;amp;url=http%3a%2f%2fmuseduc.files.wordpress.com%2f2007%2f10%2fempty_stage.jpg" width="165" height="139" /&gt;&lt;/p&gt;  &lt;p&gt;Friends,&lt;/p&gt;  &lt;p&gt;After 10 years of working for the greatest software company in the world, I will be leaving Microsoft. I strongly believe that God directs our paths and His plan for me has been confirmed by the amazing opportunities He has provided for my family here in Texas. My wife and I moved around a lot during our childhood and we decided early on we would like to put down roots in Texas. This decision, while not easy, will allow us to honor that decision, and also allow me to grow in my information security career.&lt;/p&gt;  &lt;p&gt;During my time at Microsoft, I’ve made some great friends inside the company, but also outside when speaking at various events. I have had the unique opportunity to meet some of the most passionate and intelligent technical people in the world and have learned from each of you. During my time at Microsoft, I was able to travel the world, work on many great teams, win some awards (thanks to those great teams), complete my MBA, start a family, and most importantly, meet the most beautiful woman in the world, who became my wife. &lt;/p&gt;  &lt;p&gt;I am so excited about the next steps in my life, but I am sorry to leave the people here behind.&amp;#160; To all those who’ve followed me over the years, I wish you and your families the very best for 2010 and the future! &lt;/p&gt;  &lt;p&gt;You can catch up with me and all my new adventures at my new blog: &lt;a title="http://kaiaxford.wordpress.com/" href="http://kaiaxford.wordpress.com/"&gt;http://kaiaxford.wordpress.com/&lt;/a&gt;&lt;/p&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3302948" width="1" height="1"&gt;</content><author><name>TechNet Archive</name><uri>http://blogs.technet.com/reinstallmypc_4000_hotmail.com/ProfileUrlRedirect.ashx</uri></author><category term="Microsoft" scheme="http://blogs.technet.com/b/kaiaxford/archive/tags/Microsoft/" /><category term="People" scheme="http://blogs.technet.com/b/kaiaxford/archive/tags/People/" /></entry><entry><title>New Editor of the Microsoft Technical Audiences Security Newsletter</title><link rel="alternate" type="text/html" href="http://blogs.technet.com/b/kaiaxford/archive/2009/08/17/new-editor-of-the-microsoft-technical-audiences-security-newsletter.aspx" /><id>http://blogs.technet.com/b/kaiaxford/archive/2009/08/17/new-editor-of-the-microsoft-technical-audiences-security-newsletter.aspx</id><published>2009-08-17T19:17:55Z</published><updated>2009-08-17T19:17:55Z</updated><content type="html">&lt;p&gt;Well, in case you don’t subscribe, I’m now the official editor of the &lt;a href="http://technet.microsoft.com/en-us/security/dd162324.aspx" target="_blank"&gt;Microsoft Technical Audience Security Newsletter&lt;/a&gt;. It’s nice to actually get a security professional as the actual owner of the newsletter, and hopefully I’ll be able to weed out the material that’s not related to our topic. That being said, we also want to start including some material that is pertinent to you not only in a “hard skill, how do I install/configure Microsoft’s Product X?”, but we also want to be sure that we have some good information out there that will assist you in the current economic situation that we now find ourselves. Yes, even the once booming world of information security has been hit by the bad economy. To that end, I would like to start covering some things like professional career advice, how to build those business skills, how to tweak your resume, etc. I think these will all be of great benefit. &lt;/p&gt;  &lt;p&gt;Also, I want to hear your &lt;strong&gt;valid&lt;/strong&gt; feedback. Don’t email me about how you ‘re sent in money to some Nigerian prince and you haven’t seen your money since. Also, don’t fire up an email to ask me why your machine tends to BSOD with a STOP 0x7E when you install that driver you wrote in your garage. If I don’t see valid suggestions about topics to discuss or ways to make this security newsletter better….it’s getting deleted. &lt;/p&gt;  &lt;p&gt;This month we’re talking about database security. Good ‘ol SQL Injection. Get ready….it’s going to be a fun ride.&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;- Kai &lt;/p&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3274237" width="1" height="1"&gt;</content><author><name>TechNet Archive</name><uri>http://blogs.technet.com/reinstallmypc_4000_hotmail.com/ProfileUrlRedirect.ashx</uri></author></entry><entry><title>Is Cloud Computing Really Risk Transference?</title><link rel="alternate" type="text/html" href="http://blogs.technet.com/b/kaiaxford/archive/2009/02/18/is-cloud-computing-really-risk-transference.aspx" /><id>http://blogs.technet.com/b/kaiaxford/archive/2009/02/18/is-cloud-computing-really-risk-transference.aspx</id><published>2009-02-19T00:07:15Z</published><updated>2009-02-19T00:07:15Z</updated><content type="html">&lt;p&gt;The current buzz in the technology industry is all about this idea of Cloud Computing. It goes by many many names but we’ll just stick with this one to eliminate confusion. Sure, it’s a great idea and vendors are talking about “moving your data to the cloud” where someone else can manage your data, provide better uptimes, manage the patching process, etc. Unfortunately, as a security guy, I tend to look at the idea of cloud computing from a risk perspective…and it just isn’t fluffy cumulus clouds that I see…it’s more like the picture you see here.&lt;img style="border-bottom: 0px; border-left: 0px; margin: 0px 0px 5px; display: inline; border-top: 0px; border-right: 0px" title="hurricane-francis" border="0" alt="hurricane-francis" align="left" src="http://blogs.technet.com/blogfiles/kaiaxford/WindowsLiveWriter/IsCloudComputingReallyRiskTransference_D4A0/hurricane-francis_3.jpg" width="371" height="257" /&gt;&lt;/p&gt;  &lt;p&gt;From the security perspective, it appears to be nothing more than a matter of &lt;a href="http://en.wikipedia.org/wiki/Risk_management#Risk_transfer" target="_blank"&gt;risk transference&lt;/a&gt;, very similar to what any good insurance policy will do for you. Companies are trying to be quick to market with their Cloud Computing Security Strategies, but I’ve yet to hear anyone truly identify the risk that this will solve. At the end of the day, it comes down to two simple questions that either your CSO or Legal Department will most assuredly ask: &lt;/p&gt;  &lt;p&gt;&lt;font color="#0000ff"&gt;Who ends up being liable for the data that’s stored in the cloud when it’s breached? &lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font color="#0000ff"&gt;Who’s name and signature is going to be at the end of the Breach Notification letter you’ll send to your customers?&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;I’ve been doing a lot of research on the topic of “cloud computing security” the last few weeks, as I prep for my session at &lt;a href="http://www.msteched.com/teched/default.aspx?WT.srch=1&amp;amp;mode=1&amp;amp;CR_ID=-1&amp;amp;CR_TC=9MIUMGEXBBD0NBD" target="_blank"&gt;TechEd North America 2009&lt;/a&gt; entitled “&lt;strong&gt;Securing the Cloud&lt;/strong&gt;”. I have to tell you, I don’t see a lot of companies agreeing to become liable if &lt;strong&gt;&lt;u&gt;your&lt;/u&gt;&lt;/strong&gt; data gets breached on &lt;strong&gt;&lt;u&gt;their&lt;/u&gt;&lt;/strong&gt; network. I’m not sure how this really differs from putting your money in a bank, rather than in your mattress. The bank (through the powers of the FDIC) ensure my money up to a certain amount. Will my cloud vendor do the same?&lt;/p&gt;  &lt;p&gt;Of course, with all new things, old problems still exist.&amp;#160; How is that 3rd party auditors going to successfully conduct an external audit of your data, when the data and controls aren’t even on the premises? “&lt;em&gt;Well, Mr... Sarbanes-Oxley Audit Master, I’d love to show the controls that we have in place to remain compliant with 404, but the data isn’t actually here. Perhaps you can contact our cloud provider to find out the controls &lt;u&gt;they’re&lt;/u&gt; using to keep my customer data secure.”&lt;/em&gt; That probably isn’t go to go over to well. Remember, you can delegate authority, but not responsibility.&lt;/p&gt;  &lt;p&gt;I just want to be sure that we are all really giving this a lot of thought before we start dumping our data up to some unknown entity in the clouds. There are plenty of positive things that cloud computing provides, but at what cost? I’ll take the extra time to patch my enterprise’s servers if it means keeping my data close. &lt;/p&gt;  &lt;p&gt;As someone who travels extensively talking to security professionals, I learned long ago that I don’t have all the answers….and this is no exception. Let’s start a dialogue through the comments. &lt;strong&gt;&lt;font color="#0000ff"&gt;What risks do you see with regard to moving to a cloud computing infrastructure and is your business headed that way?&amp;#160; &lt;/font&gt;&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;Also, before I forget….I’ve found a really great cloud computing security blog called &lt;a href="http://cloudsecurity.org"&gt;http://cloudsecurity.org&lt;/a&gt;. Two thumbs up! Check it out. &lt;/p&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3204243" width="1" height="1"&gt;</content><author><name>TechNet Archive</name><uri>http://blogs.technet.com/reinstallmypc_4000_hotmail.com/ProfileUrlRedirect.ashx</uri></author><category term="Compliance" scheme="http://blogs.technet.com/b/kaiaxford/archive/tags/Compliance/" /><category term="Electronic Discovery" scheme="http://blogs.technet.com/b/kaiaxford/archive/tags/Electronic+Discovery/" /><category term="Security Management" scheme="http://blogs.technet.com/b/kaiaxford/archive/tags/Security+Management/" /><category term="Small Business Security" scheme="http://blogs.technet.com/b/kaiaxford/archive/tags/Small+Business+Security/" /><category term="IT Pro" scheme="http://blogs.technet.com/b/kaiaxford/archive/tags/IT+Pro/" /><category term="Crime" scheme="http://blogs.technet.com/b/kaiaxford/archive/tags/Crime/" /><category term="Cloud Computing" scheme="http://blogs.technet.com/b/kaiaxford/archive/tags/Cloud+Computing/" /></entry><entry><title>Sweetie…can I make some security modifications to the car?</title><link rel="alternate" type="text/html" href="http://blogs.technet.com/b/kaiaxford/archive/2009/02/16/sweetie-can-i-make-some-security-modifications-to-the-car.aspx" /><id>http://blogs.technet.com/b/kaiaxford/archive/2009/02/16/sweetie-can-i-make-some-security-modifications-to-the-car.aspx</id><published>2009-02-16T19:26:21Z</published><updated>2009-02-16T19:26:21Z</updated><content type="html">&lt;p&gt;This is just too awesome to miss. I always enjoy a good video, especially when it relates to security. I just recently bought a new SUV (traded in the 2004 Mustang GT convertible) with the new baby and now I’m very sad that I forgot to ask for this option when I did. The guys at &lt;a href="http://www.dillonaero.com/" target="_blank"&gt;DillonAero&lt;/a&gt; did a great job with this new vehicle. Makes you wonder what those cars in the presidential motorcade are for. &lt;/p&gt; &lt;iframe height="480" src="http://silverlight.services.live.com/invoke/61568/MiniGunCar/iframe.html" frameborder="0" width="640" scrolling="no"&gt;&lt;/iframe&gt;  &lt;p&gt;Not to mention, this would pretty much clear up the problem of non-IT people parking in the “IT Department” parking spot. &lt;/p&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3202989" width="1" height="1"&gt;</content><author><name>TechNet Archive</name><uri>http://blogs.technet.com/reinstallmypc_4000_hotmail.com/ProfileUrlRedirect.ashx</uri></author><category term="Physical Security" scheme="http://blogs.technet.com/b/kaiaxford/archive/tags/Physical+Security/" /><category term="Funny Stuff" scheme="http://blogs.technet.com/b/kaiaxford/archive/tags/Funny+Stuff/" /><category term="Jack Bauer" scheme="http://blogs.technet.com/b/kaiaxford/archive/tags/Jack+Bauer/" /><category term="Video" scheme="http://blogs.technet.com/b/kaiaxford/archive/tags/Video/" /></entry><entry><title>ALERT: $250,000 Reward</title><link rel="alternate" type="text/html" href="http://blogs.technet.com/b/kaiaxford/archive/2009/02/12/alert-250-000-reward.aspx" /><id>http://blogs.technet.com/b/kaiaxford/archive/2009/02/12/alert-250-000-reward.aspx</id><published>2009-02-13T05:15:34Z</published><updated>2009-02-13T05:15:34Z</updated><content type="html">&lt;p&gt;&lt;b&gt;REDMOND, Wash. — Feb. 12, 2009 —&lt;/b&gt; Today, Microsoft Corp. announced a partnership with technology industry leaders and academia to implement a coordinated, global response to the &lt;a href="http://technet.microsoft.com/en-us/security/dd452420.aspx" target="_blank"&gt;Conficker&lt;/a&gt; (aka Downadup) worm. Together with security researchers, Internet Corporation for Assigned Names and Numbers (ICANN) and operators within the Domain Name System, Microsoft coordinated a response designed to disable domains targeted by Conficker. Microsoft also announced a $250,000 reward for information that results in the arrest and conviction of those responsible for illegally launching the Conficker malicious code on the Internet. &lt;/p&gt;  &lt;p&gt;“As part of Microsoft’s ongoing security efforts, we constantly look for ways to use a diverse set of tools and develop methodologies to protect our customers,” said George Stathakopoulos, general manager of the Trustworthy Computing Group at Microsoft. “By combining our expertise with that of the broader community we can expand the boundaries of defense to better protect people worldwide.”&lt;/p&gt;  &lt;p&gt;As cyberthreats have rapidly evolved, a greater level of industry coordination and new tactics for communication and threat mitigation are required. To optimize the multiple initiatives being employed across the security industry and within academia, Microsoft helped unify these broad efforts to implement a community-based defense to disrupt the spread of Conficker. &lt;/p&gt;  &lt;p&gt;Along with Microsoft, organizations involved in this collaborative effort include ICANN, NeuStar, VeriSign, CNNIC, Afilias, Public Internet Registry, Global Domains International Inc., M1D Global, AOL, Symantec, F-Secure, ISC, researchers from Georgia Tech, the Shadowserver Foundation, Arbor Networks and Support Intelligence.&lt;/p&gt;  &lt;p&gt;“The best way to defeat potential botnets like Conficker/Downadup is by the security and Domain Name System communities working together,” said Greg Rattray, chief Internet security advisor at ICANN. “ICANN represents a community that’s all about coordinating those kinds of efforts to keep the Internet globally secure and stable.” &lt;/p&gt;  &lt;p&gt;“Microsoft’s approach combines technology innovation and effective cross-sector partnerships to help protect people from cybercriminals,” Stathakopoulos said. “We hope these efforts help to contain the threat posed by Conficker, as well as hold those who illegally launch malware accountable.” &lt;/p&gt;  &lt;p&gt;More information about how to protect yourself from Conficker can be found at &lt;a href="http://www.microsoft.com/conficker"&gt;http://www.microsoft.com/conficker&lt;/a&gt;. Customers interested in learning more about staying safe online can visit &lt;a href="http://www.microsoft.com/protect"&gt;http://www.microsoft.com/protect&lt;/a&gt;. &lt;/p&gt;  &lt;p&gt;Microsoft’s reward offer stems from the company’s recognition that the Conficker worm is a criminal attack. Microsoft wants to help the authorities catch the criminals responsible for it. Residents of any country are eligible for the reward, according to the laws of that country, because Internet viruses affect the Internet community worldwide. Individuals with information about the Conficker worm should contact their international law enforcement agencies. &lt;/p&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3201610" width="1" height="1"&gt;</content><author><name>TechNet Archive</name><uri>http://blogs.technet.com/reinstallmypc_4000_hotmail.com/ProfileUrlRedirect.ashx</uri></author><category term="Malware" scheme="http://blogs.technet.com/b/kaiaxford/archive/tags/Malware/" /><category term="Frosty Things" scheme="http://blogs.technet.com/b/kaiaxford/archive/tags/Frosty+Things/" /><category term="Forensics" scheme="http://blogs.technet.com/b/kaiaxford/archive/tags/Forensics/" /><category term="Microsoft" scheme="http://blogs.technet.com/b/kaiaxford/archive/tags/Microsoft/" /><category term="Crime" scheme="http://blogs.technet.com/b/kaiaxford/archive/tags/Crime/" /></entry><entry><title>Hyper-V Security Guide goes Beta</title><link rel="alternate" type="text/html" href="http://blogs.technet.com/b/kaiaxford/archive/2009/02/06/hyper-v-security-guide-goes-beta.aspx" /><id>http://blogs.technet.com/b/kaiaxford/archive/2009/02/06/hyper-v-security-guide-goes-beta.aspx</id><published>2009-02-06T22:34:36Z</published><updated>2009-02-06T22:34:36Z</updated><content type="html">&lt;p&gt;Well, I told everyone last year on my Virtualization Security Tour that this thing was coming out soon! Well, we released a Beta of the document on our &lt;a href="https://connect.microsoft.com/InvitationUse.aspx?ProgramID=2699&amp;amp;InvitationID=TET-THVC-6CWK&amp;amp;SiteID=715" target="_blank"&gt;Beta site&lt;/a&gt;, which you should join if you haven’t already. One of my jobs is to help do technical review of documents/slides internally for our &lt;em&gt;Security Content Review Board&lt;/em&gt;. I just got the request today and have started looking it over…and now you can review it as well! Sweetness. I’d love to hear your comments!&lt;/p&gt;  &lt;p&gt;You should also take a look at the TechNet article entitled &lt;a href="http://technet.microsoft.com/en-us/library/dd283088.aspx" target="_blank"&gt;Planning for Hyper-V Security&lt;/a&gt; which was just updated on 2/4/2009.&lt;/p&gt;  &lt;p&gt;&lt;img style="border-right-width: 0px; display: block; float: none; border-top-width: 0px; border-bottom-width: 0px; margin-left: auto; border-left-width: 0px; margin-right: auto" title="" border="0" alt="" src="http://blogs.technet.com/blogfiles/kaiaxford/WindowsLiveWriter/HyperVSecurityGuidegoesBeta_A2BB/image_3.png" width="632" height="484" /&gt; &lt;/p&gt;  &lt;p align="center"&gt;&lt;strong&gt;&lt;font color="#0000ff"&gt;The Hyper-V Security Architecture..love it!&lt;/font&gt;&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;Also, don’t forget to check out the wonderfully and amazing article on virtualization security titled &lt;a href="http://technet.microsoft.com/en-us/library/cc974514.aspx" target="_blank"&gt;Security in a Virtual World&lt;/a&gt;, written by some guy with Hemingway type writing skillz. It talks about things to consider in your VM deployments.&amp;#160; It’s not about how to obtain the next set of epic gear in &lt;em&gt;World of Warcraft&lt;/em&gt; (which is a whole ‘nother type of “virtual security”).&lt;/p&gt;  &lt;p&gt;I’m currently out speaking at some internal Microsoft conferences, but I’ll be back next week!&lt;/p&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3198302" width="1" height="1"&gt;</content><author><name>TechNet Archive</name><uri>http://blogs.technet.com/reinstallmypc_4000_hotmail.com/ProfileUrlRedirect.ashx</uri></author><category term="Microsoft" scheme="http://blogs.technet.com/b/kaiaxford/archive/tags/Microsoft/" /><category term="IT Pro" scheme="http://blogs.technet.com/b/kaiaxford/archive/tags/IT+Pro/" /><category term="Virtualization" scheme="http://blogs.technet.com/b/kaiaxford/archive/tags/Virtualization/" /></entry><entry><title>Hello Baby!</title><link rel="alternate" type="text/html" href="http://blogs.technet.com/b/kaiaxford/archive/2009/02/01/hello-baby.aspx" /><id>http://blogs.technet.com/b/kaiaxford/archive/2009/02/01/hello-baby.aspx</id><published>2009-02-02T07:09:55Z</published><updated>2009-02-02T07:09:55Z</updated><content type="html">&lt;p&gt;&lt;strong&gt;&lt;font color="#0000ff"&gt;&lt;u&gt;Frantic in Dallas&lt;/u&gt;&lt;/font&gt;&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;I’m back…after a long absence.&lt;/p&gt;  &lt;p&gt;The last 3 months or so have been crazy in my life. After my trip to London and Edinburgh in mid-September, I returned home patiently awaiting the delivery of our son in late-October. We went to the doctor on Monday, September 29th and the sonogram looked great. No worries. I was slotted to go to New York on Wednesday of that week. I asked the doc if it was okay for me to head out on Tuesday, speak on Wednesday, and then return Wednesday night. A quick turnaround. “&lt;em&gt;Go&lt;/em&gt;”, he said, “&lt;em&gt;this baby isn’t coming until late October, right on schedule&lt;/em&gt;.” I generally trust doctors, so I kissed my wife goodbye and headed to New York. &lt;/p&gt;  &lt;p&gt;I got a voicemail from my wife as I landed in Cincinnati to change planes: &lt;strong&gt;&lt;font color="#ff0000" size="4"&gt;“GET HOME NOW!&amp;quot;&lt;/font&gt;&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;I immediately call home, but my wife is being admitted to the hospital, and I can’t reach her. I get in touch with her parents and am told everything is okay with her, but she had to be admitted and I needed to get back. I then begin calling American Airlines trying frantically trying to arrange a return flight. I got hold of my wife and was assured that she was okay. I got in late and immediately rushed to the hospital. &lt;/p&gt;  &lt;p&gt;Our first child was born on October 2nd, 2008. (He is currently in training to join the Green Bay Packers in 2031.)&lt;/p&gt;  &lt;p&gt;&lt;img style="border-right-width: 0px; display: block; float: none; border-top-width: 0px; border-bottom-width: 0px; margin-left: auto; border-left-width: 0px; margin-right: auto" title="random 011" border="0" alt="random 011" src="http://blogs.technet.com/blogfiles/kaiaxford/WindowsLiveWriter/Hello_B0FB/random%20011_3.jpg" width="644" height="483" /&gt; &lt;/p&gt;  &lt;p&gt;After his birth I had 4 weeks of vacation and 4 weeks of parental leave. Now that we’re in 2009, I’ve dug myself out of email and now I’m ready to hit the ground running. &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;u&gt;&lt;font color="#0000ff"&gt;So What Ya Working On, Kai?&lt;/font&gt;&lt;/u&gt;&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;Well first let me say that I have been spared the first round of layoffs that we announced a few weeks ago. Unfortunately, I have several good friends who were let go. My thoughts are with them and their families. Let’s hope this economy thing fixes itself sooner than later.&lt;/p&gt;  &lt;p&gt;I’ve also been working on getting sessions submitted for TechEd 2009. Here’s the ones I submitted and their status. Love to hear what you think about the sessions. Are these good ideas or what would you like to see?&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;SECURING THE CLOUD&lt;/strong&gt; &lt;font color="#008040"&gt;&lt;strong&gt;(APPROVED)        &lt;br /&gt;&lt;/strong&gt;&lt;/font&gt;==========================     &lt;br /&gt;You've heard the buzzwords for the computing that takes place outside the walls of your company - Cloud Computing, Software as a Service (SaaS), Grid Computing, Storage in the Cloud, etc. Have you considered the security risks that such a paradigm shift presents to your business? Security is one of the biggest hurdles preventing the move to &amp;quot;computing in the cloud&amp;quot;. Join Kai Axford, a Sr. Security Strategist with Microsoft's Trustworthy Computing Group as he identifies and discusses the IT security risks such a move could have on your organization.&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;SECURING WINDOWS ESSENTIAL BUSINESS SERVER 2008&lt;/strong&gt; &lt;font color="#008040"&gt;&lt;strong&gt;(APPROVED)&lt;/strong&gt;&lt;/font&gt;     &lt;br /&gt;===================================================     &lt;br /&gt;It's about time! Microsoft has just released the multi-server solution targeting the mid-size business after years of enterprise and small business love. Your thinking about making the move to EBS...but what about security? Is this a &amp;quot;full featured&amp;quot; Forefront TMG? How do the filters work in my Exchange Server security? What flavor or System Center do I get and how do I use it? Join Kai Axford, a Sr. Security Strategist with Microsoft's Trustworthy Computing Group as he demonstrates and discusses this mid-size product in a highly interactive and engaging session.&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;SECURITY FINANCE FOR IT SECURITY GEEKS: GET THE BUDGET YOU REALLY WANT! &lt;/strong&gt;&lt;font color="#ffff00"&gt;&lt;strong&gt;(PENDING)        &lt;br /&gt;&lt;/strong&gt;&lt;/font&gt;===================================================================     &lt;br /&gt;IT security people understand technologies and security risks. Too often we miss out on getting the budgets we want and need, simply because we don't know how to justify the project to the non-technical bean counters. In this session, you'll learn some simple capital budgeting and project justification methods such as NPV and IRR that CFOs love. We'll show you how you can use tried and true financial analysis to prove that you really do need that bright shiny firewall appliance. Heavy on the geek, light on the finance.&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;THE SECURITY SHOW v2.0&lt;/strong&gt; &lt;strong&gt;&lt;font color="#ffff00"&gt;(PENDING)&lt;/font&gt;&lt;/strong&gt;     &lt;br /&gt;============================&lt;/p&gt;  &lt;p&gt;Are you tired of Death By Powerpoint? Too much Microsoft lecture with little time for questions? Afraid of another monotone PM talking about some (yawn) topic? Then check out &amp;quot;The Security Show v2.0&amp;quot;!!! This interesting talk show format brings together the top security minds discussing the toughest security issues of today. The best part is we allow you to get involved and interact with the guests. Don't delay! Limited seats are available for this daily show! &lt;/p&gt;  &lt;p&gt;DAY 1: The Cybercriminal Underground    &lt;br /&gt;DAY 2: SDL and Why Should I Care?     &lt;br /&gt;DAY 3: Inside the Microsoft Security Response Center     &lt;br /&gt;DAY 4: Chat with a Ninja&lt;/p&gt;  &lt;p&gt;Thoughts?    &lt;/p&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3195648" width="1" height="1"&gt;</content><author><name>TechNet Archive</name><uri>http://blogs.technet.com/reinstallmypc_4000_hotmail.com/ProfileUrlRedirect.ashx</uri></author><category term="Security Management" scheme="http://blogs.technet.com/b/kaiaxford/archive/tags/Security+Management/" /><category term="Microsoft" scheme="http://blogs.technet.com/b/kaiaxford/archive/tags/Microsoft/" /><category term="Travel" scheme="http://blogs.technet.com/b/kaiaxford/archive/tags/Travel/" /><category term="Small Business Security" scheme="http://blogs.technet.com/b/kaiaxford/archive/tags/Small+Business+Security/" /><category term="People" scheme="http://blogs.technet.com/b/kaiaxford/archive/tags/People/" /><category term="FBI" scheme="http://blogs.technet.com/b/kaiaxford/archive/tags/FBI/" /><category term="The Security Show" scheme="http://blogs.technet.com/b/kaiaxford/archive/tags/The+Security+Show/" /><category term="Tech-Ed 2009" scheme="http://blogs.technet.com/b/kaiaxford/archive/tags/Tech_2D00_Ed+2009/" /></entry><entry><title>Big Bang Machine Hacked!</title><link rel="alternate" type="text/html" href="http://blogs.technet.com/b/kaiaxford/archive/2008/09/15/big-bang-machine-hacked.aspx" /><id>http://blogs.technet.com/b/kaiaxford/archive/2008/09/15/big-bang-machine-hacked.aspx</id><published>2008-09-15T15:00:33Z</published><updated>2008-09-15T15:00:33Z</updated><content type="html">&lt;p&gt;&lt;a href="http://www.foxnews.com/#"&gt;&lt;img alt="" src="http://www.foxnews.com/images/386665/0_63_doomsday_collider02.jpg" /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&lt;a target="_blank" href="http://www.timesonline.co.uk/tol/news/uk/science/article4744329.ece"&gt;Well, apparently no one planned any information security with the super collider.&lt;/a&gt; I love the quote from this guy who is obviously not a security guy “&lt;em&gt;We don’t know who they were but there seems to be no harm done.&lt;/em&gt;” Right. No harm done. We’re sorta sure.&lt;/p&gt;  &lt;p&gt;Time to buy a tin-foil hat.&lt;/p&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3124279" width="1" height="1"&gt;</content><author><name>TechNet Archive</name><uri>http://blogs.technet.com/reinstallmypc_4000_hotmail.com/ProfileUrlRedirect.ashx</uri></author><category term="Security Management" scheme="http://blogs.technet.com/b/kaiaxford/archive/tags/Security+Management/" /><category term="Industrial Espionage" scheme="http://blogs.technet.com/b/kaiaxford/archive/tags/Industrial+Espionage/" /><category term="IT Pro" scheme="http://blogs.technet.com/b/kaiaxford/archive/tags/IT+Pro/" /><category term="Crime" scheme="http://blogs.technet.com/b/kaiaxford/archive/tags/Crime/" /></entry><entry><title>Batten Down the Hatches Texas!</title><link rel="alternate" type="text/html" href="http://blogs.technet.com/b/kaiaxford/archive/2008/09/10/batten-down-the-hatches-texas.aspx" /><id>http://blogs.technet.com/b/kaiaxford/archive/2008/09/10/batten-down-the-hatches-texas.aspx</id><published>2008-09-11T03:03:11Z</published><updated>2008-09-11T03:03:11Z</updated><content type="html">&lt;p&gt;&lt;a href="http://blogs.technet.com/blogfiles/kaiaxford/WindowsLiveWriter/BattenDowntheHatchesTexas_EFCD/clip_image002_2.jpg"&gt;&lt;img style="border-bottom: 0px; border-left: 0px; border-top: 0px; border-right: 0px" title="clip_image002" border="0" alt="clip_image002" src="http://blogs.technet.com/blogfiles/kaiaxford/WindowsLiveWriter/BattenDowntheHatchesTexas_EFCD/clip_image002_thumb.jpg" width="644" height="443" /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;Well, I’ve been pretty much just keeping only a cursory interest in &lt;strong&gt;Hurricane Ike&lt;/strong&gt; once my family on the East Coast was going to be safe. Now I have to pay attention again.&lt;/p&gt;  &lt;p&gt;A friend of mine sent me this today, which means my flight on Saturday will either be arriving early or departing really really late (if at all). I may be trying to stock up on bottled water. I’m sure &lt;a target="_blank" href="http://blogs.technet.com/keithcombs/archive/2008/09/07/how-to-stay-warm-in-the-winter.aspx"&gt;Keith will have to buy a generator to keep his 3 monitors running&lt;/a&gt;. I love to torment my team in Redmond when they send pictures of 3-foot snow drifts in January…by sending them pictures of the wind blowing a few leaves in my pool in Dallas. &lt;/p&gt;  &lt;p&gt;Looks like they may be getting the last laugh.&lt;/p&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3122225" width="1" height="1"&gt;</content><author><name>TechNet Archive</name><uri>http://blogs.technet.com/reinstallmypc_4000_hotmail.com/ProfileUrlRedirect.ashx</uri></author><category term="Frosty Things" scheme="http://blogs.technet.com/b/kaiaxford/archive/tags/Frosty+Things/" /><category term="Travel" scheme="http://blogs.technet.com/b/kaiaxford/archive/tags/Travel/" /></entry><entry><title>The Last Episode on Physical Security!</title><link rel="alternate" type="text/html" href="http://blogs.technet.com/b/kaiaxford/archive/2008/09/10/the-last-episode-on-physical-security.aspx" /><id>http://blogs.technet.com/b/kaiaxford/archive/2008/09/10/the-last-episode-on-physical-security.aspx</id><published>2008-09-10T13:42:00Z</published><updated>2008-09-10T13:42:00Z</updated><content type="html">&lt;p&gt;&lt;/p&gt;  &lt;p&gt;This wraps up the 4-part series where I discuss physical security at Microsoft with one of the guys who keeps you safe when you visit Redmond or any other of the many Microsoft campuses around the world. Thanks Johnny for making us all feel safe when we step onto the campus and thanks for sharing your terrific story of security convergence and how that happens here. &lt;/p&gt; &lt;iframe height="400" src="http://silverlight.services.live.com/invoke/61568/SS3Pt4/iframe.html" frameborder="0" width="500" scrolling="no"&gt;&lt;/iframe&gt;  &lt;p&gt;I have one more series still in the bag, and it’s about How Microsoft IT Does Smart Cards, where will sit down and find out the challenges we faced in deploying smart cards to 80,000+ employees around the world. Good stuff for sure!&lt;/p&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3120034" width="1" height="1"&gt;</content><author><name>TechNet Archive</name><uri>http://blogs.technet.com/reinstallmypc_4000_hotmail.com/ProfileUrlRedirect.ashx</uri></author><category term="Physical Security" scheme="http://blogs.technet.com/b/kaiaxford/archive/tags/Physical+Security/" /><category term="Security Management" scheme="http://blogs.technet.com/b/kaiaxford/archive/tags/Security+Management/" /><category term="Microsoft" scheme="http://blogs.technet.com/b/kaiaxford/archive/tags/Microsoft/" /><category term="Events" scheme="http://blogs.technet.com/b/kaiaxford/archive/tags/Events/" /><category term="People" scheme="http://blogs.technet.com/b/kaiaxford/archive/tags/People/" /><category term="IT Pro" scheme="http://blogs.technet.com/b/kaiaxford/archive/tags/IT+Pro/" /><category term="Tech-Ed 2008" scheme="http://blogs.technet.com/b/kaiaxford/archive/tags/Tech_2D00_Ed+2008/" /><category term="Video" scheme="http://blogs.technet.com/b/kaiaxford/archive/tags/Video/" /><category term="The Security Show" scheme="http://blogs.technet.com/b/kaiaxford/archive/tags/The+Security+Show/" /></entry></feed>