Roger's Security Blog

As Chief Security Advisor of Microsoft EMEA - lets share interesting security information

April, 2008

Posts
  • Roger's Security Blog

    Microsoft Diagnostics and Recovery Toolset

    • 11 Comments
    Well, we call it simply DaRT. You know the feeling: A machine does not boot anymore, crashed, has a virus you cannot clean with the OS in a running state or any of the other nightmare scenarios in daily operations of computers. Since quite some time there...
  • Roger's Security Blog

    Security Updates and Exploits

    • 5 Comments
    As you may know, we announced version four of the Microsoft Security Intelligence Report earlier this week. Amongst the many interesting findings is data which relates to software vulnerability exploits. I wanted to highlight these as Shoaib, one of my...
  • Roger's Security Blog

    Public Testing for Office

    • 2 Comments
    Are you working on Office System 2007? Ever looked for a command, you knew in 2003 exactly where it is but you were unable to locate it? Well, do not get me wrong: Since I am used to the Ribbon, I love it – really. And my wife is all of a sudden able...
  • Roger's Security Blog

    End-To-End Trust: We want your Feedback

    • 2 Comments
    You probably saw my blog post on End-To-End Trust last week. This week at RSA Craig Mundie, Microsoft's Chief Research and Strategy Officer, talked about our ideas and views on this topic. In parallel, we announced the availability of a Whitepaper on...
  • Roger's Security Blog

    The ideal profile of a CSO

    • 2 Comments
    I was in Bratislava this week for an IDC Conference. During these kind of events I often talk to the press as well. Additionally I had this time the opportunity to talk to a pretty well-known blogger in Slovakia called Jozef Vyskoč . You may have a look...
  • Roger's Security Blog

    0-Day-Patch – An new Metric for Security?

    • 2 Comments
    The Federal Institute of Technology in Zurich released a study at Blackhat, which is definitely worth looking into. Now, let's be serious: They looked at a metric they call 0-Day-Patch being the number of patches a vendor is able to release at the...
  • Roger's Security Blog

    Security Intelligence Report v4 – Live and Ready to be Read

    • 1 Comments
    As you (hopefully) know, we publish a Security Intelligence Report every 6 month and today we just released version 4. Let me give you some key findings before you go and read it J Basically the intent of the report is, to provide a comprehensive overview...
  • Roger's Security Blog

    “The Security Business has no Future” (Quote by IBM)

    • 1 Comments
    This is actually an interesting statement. If you had ever to deal with the press you know how these headlines are composed. It might be that the person actually made the sentence in this way – the question is whether he meant it so absolute. Nevertheless...
  • Roger's Security Blog

    How long does it take to hack a Power Plant?

    • 1 Comments
    I start to get scared – more and more. Back in September I blogged on Critical Infrastructure Protection – Live which shows what would happen if somebody would be able to tamper with power generators. Now, during RSA there was a guy called Ira Winkler...
  • Roger's Security Blog

    Security Compliance Management – Beta Available

    • 1 Comments
    Compliance is the theme of the day at the moment. We often even see the Security Officers starting to report to the head of compliance. So, if you are interested in this, we just launched the Security Compliance Management Beta for you to download....
  • Roger's Security Blog

    SDL and End to End Trust

    • 1 Comments
    Last week we published – as you hopefully know – our "End to End Trust" whitepaper. If not, please read my blog post on it J Now, Eric Bidstrup just commented on End to End Trust in the light of the Security Development Lifecycle (or better: the other...
  • Roger's Security Blog

    Blogging on MOSS 2007 (SharePoint)

    • 1 Comments
    As you probably realized, I stopped the series "How I secure my Infrastructure" as the hit rate on the corresponding posts have been pretty low. However, if I have something which I think is interesting and/or cool, I will still add a post. This one has...
  • Roger's Security Blog

    Best Practices for Microsoft PKI & Certificate Management

    • 0 Comments
    You might know Brian Komar. He wrote numerous books on PKI and Certificate Management and he is a well-known speaker at quite some events like TechEd and IT Forum. Now, nCipher organized a Webimar on Best Practices for Microsoft PKI & Certificate...
  • Roger's Security Blog

    Securing your Web Browser

    • 0 Comments
    Cert.org published guidance on how to secure your browser. Here you would find them if you are interested: Securing Your Web Browser I am just not clear, how the browsing experience for my mom and dad would be… Roger
  • Roger's Security Blog

    The recent IIS Attacks

    • 0 Comments
    There has been a lot of discussions in different blogs on the attacks on IIS servers. Microsoft Security Response Center has publised a post on it: Questions about Web Server Attacks Roger
  • Roger's Security Blog

    The Death of the DMZ = The Death of the Castle

    • 0 Comments
    Since quite some time we are talking about the "Death of the DMZ". This seems a little bit provocative but I am convinced that it is coming very closer to the truth. Do not get me wrong: I do not think that you should replace your firewall with routers...
  • Roger's Security Blog

    How to use a Cellphone

    • 0 Comments
    :-) Roger
  • Roger's Security Blog

    Building a faster Internet

    • 0 Comments
    Does not solve any of the security problems (challenges?) but it sounds promising anyway Building A Faster Internet Roger
  • Roger's Security Blog

    Forefront Codename “Stirling” Beta ready for Download

    • 0 Comments
    I had the opportunity to see the Beta of our next generation of Forefront environment the first time last week and I think that it rocks. Have a look yourself and/or download the beta: http://www.microsoft.com/forefront/stirling/en/us/default.aspx ...
  • Roger's Security Blog

    All the Vista SP1 Features where you have time to read them :-)

    • 0 Comments
    I just found this blog post: In Japan there is toilet paper with all the Vista SP1 features on it…. At least, there you have time to read Windows Vista SP1 Toilet Paper - It's really available now Roger
  • Roger's Security Blog

    How to do security in Development

    • 0 Comments
    Michael Howard just pointed us to a resource that could be interesting for you as well – it was new to me at least J We have a set of short videos (3-10 min.) on how to address some security challenges in development: "How Do I?" Videos for Security...
  • Roger's Security Blog

    Security Risks of VoIP

    • 0 Comments
    Internet Telephony Has Security Problems : This was an interesting read this morning for different reasons: First of all, it is not surprising (even if we would not have known the problems it would have to be expected). I liked the statement: The...
  • Roger's Security Blog

    Where next? – Watch out for RSA

    • 0 Comments
    We are six years into Trustworthy Computing (TwC). When we launched it, we said a number of things: "It is a 10-year vision". Well, that's something we have had to update. As long as there are criminals out there using the Internet to steal, Trustworthy...
  • Roger's Security Blog

    Office Binary Formats on the Web

    • 0 Comments
    I just wanted to make you aware that we put the Office Binary Formats on the web. We did this for interoperability reasons but often this can be very useful for forensics as well: Microsoft Office Binary (doc, xls, ppt) File Formats Roger
  • Roger's Security Blog

    Hacking Back?

    • 0 Comments
    Pretty often there is a discussion how far it is allowed to hack back. I was just reading an interesting post called Hackers Could Become The Hacked? which I wanted to share with you Roger
Page 1 of 2 (29 items) 12