Roger's Security Blog

As Chief Security Advisor of Microsoft EMEA - lets share interesting security information

Posts
  • Roger's Security Blog

    Buy Your Enigma

    • 2 Comments
    It is probably the most important and known encryption device ever: The Enigma – the machine that had a strong influence on WWII. Now you can buy your Enigma on e-bay: http://cgi.ebay.com/ws/eBayISAPI.dll?ViewItem&item=270146949978 Roger
  • Roger's Security Blog

    Stepto becoming a Gamer :-)

    • 0 Comments
    If you are working with Microsoft and security you definitely know him – Stephen Toulouse one of the long-term people you know from Microsoft's security units. He worked within the Microsoft Security Response Center as one of our key spokespersons and...
  • Roger's Security Blog

    New Version of the Nigeria Scam

    • 0 Comments
    I love that one: Somebody sends e-mails to Hotmail users that their account would expire and they should renew it – the attacker gets UserID/Password… Then a mail is sent on behalf of the user to their friends to tell them that they are stuck in Nigeria...
  • Roger's Security Blog

    It’s All the User’s Fault

    • 0 Comments
    Isn't it true? Don't we always say that there is a PICNIC problem (Problem in Chair, not in Computer)? When we talk about security we often talk about the user – and this is right so. But do we always give the user what he needs to protect their information...
  • Roger's Security Blog

    Only the Easiest Way is the Secure Way

    • 6 Comments
    We, being security professionals, are often "just" looking for the most secure way to implement a certain task. Often we tend to forget the user when we implement these measures. I once visited a customer showing me their ultimately secure solution to...
  • Roger's Security Blog

    How to React on Malware Attacks

    • 0 Comments
    Often the Small and Medium Businesses do not have IT resources available and it they have, the person is a IT Generalist. We try to help these kind of people to get structured and organized around the core security challenges. Therefore we published yesterday...
  • Roger's Security Blog

    Windows Live OneCare 2.0 Beta available

    • 3 Comments
    Looking at my father's PC I always faced the same problem: I wanted to give him a solution that actually took care of his PC without having me too often involved J . Some time ago, we had some particular solutions: Backup (use the backup in Windows...
  • Roger's Security Blog

    Malware Portal Live

    • 0 Comments
    I blogged about three important announcements we made a few months ago ( http://blogs.technet.com/rhalbheer/archive/2007/04/25/three-microsoft-announcements.aspx ). The different malware teams are ramping up heavily and I am looking forward to working...
  • Roger's Security Blog

    Vulnerability Auction

    • 7 Comments
    I wrote several times already about responsible disclosure and irresponsible disclosure. My point on that is clear: Every vendor has to have transparent and clear processes to handle vulnerabilities. These processes ensure that there will be a timely...
  • Roger's Security Blog

    Crime on SecondLife - a Surprise?

    • 0 Comments
    There were recently different articles about crime on SecondLife . What is interesting to me is that a lot of these started to express their surprise.In certain blogs I read statements like: SecondLife is so cool, how could somebody even think of this...
  • Roger's Security Blog

    Europe, Middle East and Africa after 100 days

    • 0 Comments
    Before I actually start with content, let me briefly give you some background: I took the role of the Chief Security Advisor (CSA) in EMEA (Europe, Middle East and Africa) after having been 5 years the CSA in Switzerland. I went through all the nice challenges...
  • Roger's Security Blog

    6 Month Windows Vista Vulnerability Report

    • 0 Comments
    Jeff just posted his next version of the Windows Vista Vulnerability report to his blog. He is now looking at the first six months of Windows Vista and how the vulnerabilities developed compared to Windows XP and some other Operating Systems. Happy...
  • Roger's Security Blog

    OEMs: Join in to "Secure by Default"

    • 0 Comments
    I recently purchased a PC for my parents and then started to install it – well actually used the OEM installation to get it up and running with Windows Vista Home Premium. I was pretty surprised how easy it was to actually have a running system (I usually...
  • Roger's Security Blog

    Security Standards Portal

    • 0 Comments
    ITU just launched a pretty interesting portal: If you were ever looking for a standard in the security space (not only ITU standards) go and see this portal: ICT Security Standards Roadmap Roger
  • Roger's Security Blog

    Digital Phishnet Conference 2007

    • 1 Comments
    Last week the first Digital Phishnet Conference in Europe took place in Berlin. Basically Digital Phishnet is an initiative to help to exchange information about Phishing-Sites in order to help enforcement. This is the core mission: Supporting Law Enforcement...
  • Roger's Security Blog

    Windows Vista Recovery Console and the Password

    • 5 Comments
    Every once in a while I am left scratching my head. Over the last few days a few blog postings have popped up on a subject and I am at a loss to understand why. I’m not the only one – several security industry colleagues have been in touch and have said...
  • Roger's Security Blog

    Fake Microsoft Security Bulletin

    • 0 Comments
    It happens again: There seems to be a faked message giving users the impression that we are sending it out taking into account that it is “Update Tuesday” tomorrow. And they are still successful! Just to stress it once again: We are never, never, never...
  • Roger's Security Blog

    Antiforensics

    • 0 Comments
    A pretty interesting article about a guy trying to find a network compromise - he actually did, knowing that there is close to no chance to find the criminal behind the attack. By the way, the criminal only got access to two years worth of credit card...
  • Roger's Security Blog

    Bill's 1987 Prediction on 2007

    • 0 Comments
    Actually I did not want to blog about this, but when I read this article, I had to. This is a quote from an article written in 1987 making people predict the future - 2007. Look at Bill's prediction and enjoy: http://blog.seattlepi.nwsource.com/microsoft...
  • Roger's Security Blog

    Security Trends on our Malware Portal

    • 0 Comments
    I recently blogged about three major announcements we made: http://blogs.technet.com/rhalbheer/archive/2007/04/25/three-microsoft-announcements.aspx On that I got some comments (public and private) and some wishes. Thank you all forthis feedback. I...
  • Roger's Security Blog

    The Consumer has to assess Risks

    • 0 Comments
    Recently during an event at a University, I had the pleasure to participate in a panel discussion and it did not take too long until I was heavily in disagreement with the professors there. The reason? It became a discussion around consumer security and...
  • Roger's Security Blog

    Introducing Microsoft Office Isolated Conversion Environment

    • 0 Comments
    Over the last few months it became evident: The attacks are moving up the stack. We see less and less attacks on the operating systems but much, much more on the application. This is a trend that was basically predicted and unfortunately in this case...
  • Roger's Security Blog

    Changes to Advanced Notification and Security Bulletins

    • 0 Comments
    Over the last few years, often when I met customers I asked them several question: Are you happy with our monthly Security Update rhythm? How do you see the quality of the Security Updates? Any feedback to the Security Bulletins? Often...
  • Roger's Security Blog

    My Visit to Bluehat

    • 1 Comments
    This week I am staying on the Campus in Redmond for internal meetings. By accident it happened to me that our Bluehat briefings are taking place and I had a chance to attend the Executive Day this afternoon. If you want to know more about Bluehat, visit...
  • Roger's Security Blog

    Analysis of ANI vulnerability

    • 0 Comments
    Michael Howard did a very good analysis of the ANI vulnerability and showed what we learned and where we will improve SDL (the Security Development Lifecycle). He posted that on our new SDL bog: http://blogs.msdn.com/sdl/archive/2007/04/26/lessons-learned...
Page 31 of 33 (805 items) «2930313233