Sign in
Microsoft Security Blog
The official Microsoft blog for discussing industry and Microsoft security topics.
Home
About
View More Blogs
Ecosystem Strategy Blog
Microsoft Accessibility Blog
Microsoft BlueHat Blog
Microsoft Malware Protection Center Blog
Microsoft Security Blog
Microsoft Security Response Center Blog
Security Development Lifecycle Blog
Security Research & Defense Blog
Security Tips & Talk Blog
Trustworthy Computing Blog
TechNet Blogs
>
Microsoft Security Blog
Follow Us
RSS for Posts
@msftsecurity
Security@Microsoft
Security Newsletter
TwC Blogs Windows Phone Application
Get on-the-go access to the latest insights featured on our Trustworthy Computing blogs.
Twitter @msftsecurity
Monthly Archives
Archives
May 2013
(4)
April 2013
(8)
March 2013
(6)
February 2013
(10)
January 2013
(13)
December 2012
(7)
November 2012
(7)
October 2012
(9)
September 2012
(11)
August 2012
(13)
July 2012
(7)
June 2012
(6)
May 2012
(13)
April 2012
(10)
March 2012
(21)
February 2012
(7)
January 2012
(7)
December 2011
(9)
November 2011
(8)
October 2011
(7)
September 2011
(13)
August 2011
(12)
July 2011
(9)
June 2011
(5)
May 2011
(5)
April 2011
(1)
March 2011
(7)
February 2011
(5)
December 2010
(1)
May 2010
(1)
April 2010
(2)
March 2010
(16)
February 2010
(3)
December 2009
(1)
November 2009
(1)
September 2009
(1)
July 2009
(2)
June 2009
(3)
April 2009
(8)
March 2009
(2)
February 2009
(4)
January 2009
(2)
December 2008
(1)
November 2008
(4)
October 2008
(1)
September 2008
(1)
August 2008
(5)
June 2008
(5)
May 2008
(4)
April 2008
(6)
March 2008
(4)
February 2008
(1)
January 2008
(1)
December 2007
(1)
November 2007
(5)
October 2007
(5)
September 2007
(2)
August 2007
(1)
July 2007
(1)
June 2007
(7)
May 2007
(4)
April 2007
(1)
March 2007
(4)
February 2007
(10)
January 2007
(10)
December 2006
(1)
November 2006
(6)
October 2006
(11)
September 2006
(7)
August 2006
(5)
July 2006
(9)
June 2006
(9)
May 2006
(10)
April 2006
(3)
Subscribe via RSS
Sort by:
Most Recent
|
Most Views
|
Most Comments
Excerpt View
|
Full Post View
Microsoft Security Blog
2008 Pwn2Own Winner says Safari is an Easy Target
Posted
over 4 years ago
by
Jeff Jones - MSFT
1
Comments
Apple Inc.'s Safari is the juiciest target in the upcoming PWN2OWN hacking contest, last year's winner predicted today. "It's an easy target," said Charlie Miller, the vulnerability researcher who last year walked off with a $10,000 cash prize for breaking into an Apple laptop just a few minutes into the contest. PWNOWN is slated for its third appearance at the CanSecWest security conference later this month in Vancouver, British Columbia. "It might be because I'm biased about the...
Microsoft Security Blog
Firefox in 2008 – No Single Version Available for The Full Year?
Posted
over 4 years ago
by
Jeff Jones - MSFT
7
Comments
I’ve been busy doing analysis for the next article in my cio.com Firefox series of articles, looking at vulnerability disclosures during 2007 and 2008 and I stumbled upon a little factoid that I had not previously noticed – no single version of Firefox was available for the full year of 2008. In retrospect, I should have known this would happen, given the Mozilla policy of supporting the predecessor version for 6 months after a new release. Here is what the timeline looks like: In my interactions...
Microsoft Security Blog
Feb09 Security Bulletin SDL Benefit Summary
Posted
over 4 years ago
by
Jeff Jones - MSFT
2
Comments
Summaries from previous months: Jan09 Security Bulletin SDL Benefit Summary When I do analysis and reports on Microsoft products, I typically look for where the Security Development Lifecycle (SDL) has helped to provide improvement and provide some stats on that. This year, I decided to try and do this monthly to make it easier for me that when I do it all at once. This report is my attempt to capture and share that information. I hope you find it useful. February Summary First, here...
Microsoft Security Blog
Perception: Case in Point
Posted
over 4 years ago
by
Jeff Jones - MSFT
3
Comments
I love it when a good, real-life example falls right into your lap. As you know from my recent posts, I’ve been doing a series of articles probing Mozilla and Firefox security claims. I think I’ve been pretty open about why, but I always seem to get pushback around the idea that there might be some false perceptions out there that I want to push back on. Well, yesterday, Ed Burnette posted a blog entry on his ZDnet blog titled Firefox 3.0.6 fixes 69 bugs, some critical . This is of course...
Microsoft Security Blog
CIO.COM: Mozilla and “Counting Still Easy…”
Posted
over 4 years ago
by
Jeff Jones - MSFT
1
Comments
[DISCLOSURE for those who don’t read about boxes: I work for Microsoft.] I admit that I enjoy discussing issues and digging into claims to see if I can find fractures or flaws in logic. When I ran product management teams for companies in previous roles, I would always review our draft product glossies and papers and generate a lot of red ink, providing feedback like “we can’t make this claim, we have no evidence to support it.” There are some countries where that is a particular concern (though...
Microsoft Security Blog
Brian Krebs Blog on ‘at Risk’ Chart Methodology
Posted
over 4 years ago
by
Jeff Jones - MSFT
1
Comments
I am a couple of articles into my series: Can Mozilla Support Claims of Firefox Being the Most Secure Web Browser? , and Can Mozilla Support Claims of Firefox Being the Most Secure Web Browser? (Part 2) In part 2, I probed Mozilla’s usage of an ‘at risk’ chart to claim that their customers were only exposed to unpatched vulnerabilities for nine days in 2006. With some quick research, I came up with enough vulnerabilities to show that Firefox users were vulnerable to unpatched security...
Microsoft Security Blog
CIO.COM: Can Mozilla Support Their Security Claims?
Posted
over 4 years ago
by
Jeff Jones - MSFT
28
Comments
Mozilla bills Firefox as the most secure Web browser on the planet, but is it really? Follow along with this series and see if the claims hold up to close scrutiny. Today, I started a multi-part article series on cio.com (Security landing page: http://www.cio.com/topic/1419/Security ) probing Mozilla’s claims of security superiority. My plan is to post up a new article every few days probing aspects of claims they’ve made either on the Firefox security page or in some other public forum. As...
Microsoft Security Blog
IEEE Security & Privacy: Estimating Software Vulnerabilities
Posted
over 5 years ago
by
Jeff Jones - MSFT
2
Comments
I thought I had posted this link in the past, but it turns out I did not, so ... Last summer (2007), one of my papers was published in IEEE Security & Privacy, which describes a method for estimating the number of disclosed but unfixed vulnerabilities in some version of software utilizing publicly available data. The citation reference is: Jeffrey R. Jones, "Estimating Software Vulnerabilities," IEEE Security & Privacy , vol. 5, no. 4, 2007, pp. 28-32. IEEE kindly made the paper...
Microsoft Security Blog
New XBox 360 Avatars
Posted
over 5 years ago
by
Jeff Jones - MSFT
1
Comments
So, near the end of last week, I fired up my Xbox and downloaded the new “experience” – a massive update to the UI, which includes avatars. Lots of cool new stuff, but when I checked out my friend’s avatars, now that was really cool. This *is* stepto . ;-) If you know him, then no further explanation is necessary. If you don’t, check out the picture on his blog header…
Microsoft Security Blog
SIRV5 Vulnerability Trends Webcast - 2 of 2 - Microsoft Trends
Posted
over 5 years ago
by
Jeff Jones - MSFT
1
Comments
With the recent release of v5 of the Security Intelligence Report, I decided to produce a couple of webcast videos where I present my findings to you directly in a brief presentation. In this second one, I go over the vulnerability disclosure trends for vulnerabilities affecting Microsoft products. 1H08 Vulnerability Trends - Part 2 - Microsoft To see all of my videos on http://edge.technet.com , click here ( http://edge.technet.com/Tags/SecurityGuy/ ). Best regards, Jeff
Page 29 of 43 (429 items)
«
27
28
29
30
31
»