Sign in
Roger's Security Blog
As Chief Security Advisor of Microsoft EMEA - lets share interesting security information
Translate This Page
Translate this page
Powered by
Microsoft® Translator
Options
About
Email Blog Author
RSS for posts
Atom
RSS for comments
OK
Blog - News
Chat directly with me if you want. Go to my
Chat
page to find a web messenger!
Search Blogs
Blog - Link List
Links to other blogs
Roger's Blog on Security
This is my other blog I just started. It will be similar content but over time more org and business focused
CSA Switzerland
The Blog of the Swiss Chief Security Advisor
CSA Russia
The Blog of the Russian Chief Securty Advisor
CSA Finland
The Blog of the Finish Chief Security Advisor
CSA Italy
The Blog of the Italian Chief Security Advisor
MS Security Response Center
Microsoft Malware Portal
Microsoft's Security Blog
Security by Numbers
Jeff's Blog on Security and Numbers
Shoaib Yousuf
One of my readers
ts/sci security
Gerhard's Marktbeobachtungen
Trustworthy Computing
Tags
Cloud
Cloud Computing
Competition
Consumer
Crime
Critical Infrastructure Protection
Cybercrime
Events/Training
Fun
Incident Response
Incidents
Industry Associations
Law Enforcement
Microsoft
Microsoft Products
Patch Management
Policies
Policy
Politics
Privacy
Processes
Security
Technology
Terrorism
Trends
Archive
Archives
May 2013
(2)
April 2013
(2)
March 2013
(1)
February 2013
(2)
January 2013
(5)
December 2012
(1)
November 2012
(1)
October 2012
(4)
September 2012
(4)
August 2012
(4)
July 2012
(1)
June 2012
(3)
May 2012
(2)
April 2012
(9)
March 2012
(2)
February 2012
(2)
January 2012
(1)
December 2011
(3)
November 2011
(6)
October 2011
(11)
September 2011
(8)
August 2011
(3)
July 2011
(4)
June 2011
(8)
May 2011
(7)
April 2011
(7)
March 2011
(13)
February 2011
(18)
January 2011
(15)
December 2010
(6)
November 2010
(15)
October 2010
(15)
September 2010
(32)
August 2010
(10)
July 2010
(14)
June 2010
(18)
May 2010
(8)
April 2010
(6)
March 2010
(22)
February 2010
(5)
January 2010
(12)
December 2009
(8)
November 2009
(7)
October 2009
(11)
September 2009
(17)
August 2009
(12)
July 2009
(12)
June 2009
(13)
May 2009
(14)
April 2009
(16)
March 2009
(11)
February 2009
(12)
January 2009
(14)
December 2008
(22)
November 2008
(13)
October 2008
(22)
September 2008
(8)
August 2008
(14)
July 2008
(4)
June 2008
(16)
May 2008
(30)
April 2008
(29)
March 2008
(19)
February 2008
(16)
January 2008
(26)
December 2007
(18)
November 2007
(23)
October 2007
(11)
September 2007
(10)
August 2007
(7)
July 2007
(11)
June 2007
(11)
May 2007
(4)
April 2007
(9)
March 2007
(8)
February 2007
(8)
January 2007
(6)
October, 2008
TechNet Blogs
>
Roger's Security Blog
>
October, 2008
Posts
Subscribe via RSS
Sort by:
Most Recent
|
Most Views
|
Most Comments
Excerpt View
|
Full Post View
Roger's Security Blog
Deploying IPsec Server and Domain Isolation using Windows Server 2008 Group Policy
Posted
over 5 years ago
by
rhalbheer
1
Comments
As you know (at least I hope that you do) we introduced Network Access Protection with Windows Server 2008. Thomas Shinder now published an article on WindowsSecurity.com about how to implement NAP and IPSec and Domain Isolation via Group Policies. It...
Roger's Security Blog
More Details on the MS08-067 Vulnerability
Posted
over 5 years ago
by
rhalbheer
1
Comments
Our security team just published an excellent post with a lot more details on the vulnerability we patched. You should definitely read it: http://blogs.technet.com/swi/archive/2008/10/23/More-detail-about-MS08-067.aspx Roger
Roger's Security Blog
Microsoft Security Assessment Tool v4.0 available
Posted
over 5 years ago
by
rhalbheer
1
Comments
I already blogged a few times on MSAT (the Microsoft Security Assessment Tool). We just released a new version for it, version 4. For those of you who do not know MSAT: MSAT is a free (stress: free) Risk Assessment Tool mainly targeted a Small and...
Roger's Security Blog
Once Again: A Scam using Microsoft’s Name to Install Malware
Posted
over 5 years ago
by
rhalbheer
0
Comments
It happens pretty often but this time it seems to be wider spread then normal as our traffic with regards to this issue is higher than usual: There is a mail circulating pretending that it is coming from Steve Lipner here at Microsoft telling you to install...
Roger's Security Blog
Hacker arrested for Video Giving Tips for ATM Skimmers
Posted
over 5 years ago
by
rhalbheer
2
Comments
It will be interesting how you see it. When I blogged on Suspended Jail for Hacking Tutorial in France , I got quite some negative feedback like “do you have nothing better to do than to go after these guys”, “why should it be illegal to publish such...
Roger's Security Blog
Armored truck robber uses Craigslist to make getaway
Posted
over 5 years ago
by
rhalbheer
0
Comments
This is really clever (sounds like Hollywood but it seems to be real): In a move that could be right out of a Hollywood movie, a brazen crook apparently used a Craigslist ad to hire a dozen unsuspecting decoys to help him make his getaway following...
Roger's Security Blog
SAFECode released „Fundamental Practices for Secure Software Development”
Posted
over 5 years ago
by
rhalbheer
0
Comments
SAFECode just released a new paper called Fundamental Practices for Secure Software Development . This is a collaboration of different people from different companies (SAP, EMC, Symantec, Juniper, Nokia and Microsoft). As you probably know, SAFECode...
Roger's Security Blog
Out of Band Security Update to be Released
Posted
over 5 years ago
by
rhalbheer
0
Comments
I guess you have seen this already but wanted to make sure that we are reaching you: We are planning to release an Out of Band Security Update today 10am Pacific Time (which is 18pm GMT). This update will affect all currently supported versions of Windows...
Roger's Security Blog
H1 OS Desktop Vulnerability Report – Get It Now
Posted
over 5 years ago
by
rhalbheer
3
Comments
You might know Jeff Jones' work on the different vulnerability reports comparing different products and vendors. Our goal is to understand and measure our progress and see where we stand with regards to the industry. Today, Jeff release his OS Desktop...
Roger's Security Blog
Some Thoughts on UAC
Posted
over 5 years ago
by
rhalbheer
0
Comments
I blogged several times already on UAC as this has been (and partly still is) a very disputed security feature in Windows Vista (which I still support!). I just found today a not really new blog post on UAC, which I think is worth reading. It is from...
Roger's Security Blog
Risk of Outsourcing (and Security Outsourcing)
Posted
over 5 years ago
by
rhalbheer
2
Comments
I am often asked about the risks of outsourcing (we often talk about processes, legal risks (e.g. Data Protection), etc.) – the list is very long. Today I read an article which touches a completely different issue: It is all about the security processes...
Roger's Security Blog
Why I do not like e-voting (part 3)
Posted
over 5 years ago
by
rhalbheer
0
Comments
It goes on and on and on: Read this one Judge Suppresses Report on Voting Machine Security Roger
Roger's Security Blog
Network Access Protection Design Guide
Posted
over 5 years ago
by
rhalbheer
0
Comments
If you are looking into deploying Network Access Protection, have a look at the recently published Network Access Protection Design Guide Roger
Roger's Security Blog
Getting Ready for TechED EMEA
Posted
over 5 years ago
by
rhalbheer
2
Comments
It is as so often, autumn is the time when all the big events are happening in EMEA. This week was RSA Europe (or I think still is) and next week I am looking forward to TechEd EMEA in Barcelona. So, I worked at RSA Europe on Monday and Tuesday on the...
Roger's Security Blog
MS08-067 Out of Band Released
Posted
over 5 years ago
by
rhalbheer
1
Comments
This is just to inform you that we just released the announced out of band security update MS08-067 . Please read the bulletin carefully and then apply the update as soon as possible Roger
Roger's Security Blog
“Stacked against hacks” in World Finance
Posted
over 5 years ago
by
rhalbheer
2
Comments
I recently had the pleasure to be part of an article in World Finance called Stacked against hacks Visit the virtual version here and go to page 60 and 61 Roger
Roger's Security Blog
Estonia’s Cyber Security Strategy
Posted
over 5 years ago
by
rhalbheer
1
Comments
Following the attacks on Estonia, they published a pretty interesting paper called Cyber Security Strategy by the Ministry of Defense in Estonia. One thing which I see again and again is that most of the people looking into such strategies conclude that...
Roger's Security Blog
Version 3 of Windows Common Criteria Documentation Available
Posted
over 5 years ago
by
rhalbheer
0
Comments
This is completely new but end of September we published the version 3 of the documentation on the Common Criteria certification for Windows XP SP2 and Windows Server 2003 R2 SP2. Read this in Tim Myer's Blog: Version 3.0 of Windows XP and Windows Server...
Roger's Security Blog
Windows 7 is called Windows 7
Posted
over 5 years ago
by
rhalbheer
0
Comments
Cool title, isn't it? And you really read this post? Well then: We announced yesterday at PDC that we now will name the next version of Windows as we code named it: Windows 7! So, you can read Mike Nash's blog post about that: http://windowsvistablog...
Roger's Security Blog
User Account Control and What We Learned
Posted
over 5 years ago
by
rhalbheer
0
Comments
It is still something, people love to blog about: User Account Control. It is one of the most discussed features in Windows Vista. Now, our engineering team published a blog about the learnings and a few things about what we are going to do in Windows...
Roger's Security Blog
Challenging the 10 Immutable Laws of Security
Posted
over 5 years ago
by
rhalbheer
0
Comments
You probably know them: The 10 Immutable Laws of Security , we published I think around 2000 and they were often cited. They are: Law #1: If a bad guy can persuade you to run his program on your computer, it's not your computer anymore Law #2...
Roger's Security Blog
Two Important Changes Today to Our Bulletin Process
Posted
over 5 years ago
by
rhalbheer
0
Comments
Today is the day! At Blackhat in August we announced two significant changes to our bulletin release process and today it is the first time this actually kicks in. Just to recapitulate: What did we change? We introduced the Microsoft Active Protections...
Page 1 of 1 (22 items)