Sign in
Steve Riley on Security
Formerly of Microsoft's Trustworthy Computing Group.
Translate This Page
Translate this page
Powered by
Microsoft® Translator
Options
About
Email Blog Author
RSS for posts
Atom
RSS for comments
OK
Search Blogs
Tags
access technologies
authentication
blogging
conferences and seminars
configuration
email
encryption
false claims
malware
my book
networking
protection
public policy
risk mitigation
security myths
security policies
security science
security theater
spam
TechEd
things that make me angry
things that make me laugh
things that make me worried
threats
Windows Vista
Archive
Archives
August 2009
(1)
May 2009
(1)
February 2009
(1)
January 2009
(5)
December 2008
(1)
November 2008
(1)
October 2008
(2)
September 2008
(6)
August 2008
(2)
June 2008
(2)
April 2008
(1)
February 2008
(7)
January 2008
(1)
November 2007
(1)
October 2007
(3)
September 2007
(5)
August 2007
(2)
July 2007
(4)
May 2007
(2)
April 2007
(1)
February 2007
(1)
January 2007
(3)
December 2006
(2)
November 2006
(3)
October 2006
(2)
September 2006
(6)
August 2006
(1)
July 2006
(3)
June 2006
(1)
May 2006
(2)
April 2006
(2)
March 2006
(5)
February 2006
(2)
January 2006
(3)
November 2005
(5)
September 2005
(4)
August 2005
(2)
July 2005
(5)
June 2005
(5)
April 2005
(3)
March 2005
(2)
February 2005
(2)
January 2005
(1)
TechNet Blogs
>
Steve Riley on Security
Posts
Subscribe via RSS
Sort by:
Most Recent
|
Most Views
|
Most Comments
Excerpt View
|
Full Post View
Steve Riley on Security
It's time to stop playing war games in the name of "security"
Posted
over 7 years ago
by
TechNet Archive
4
Comments
Really interesting article. Military mindset no longer applicable in our line of work http://searchsecurity.techtarget.com/columnItem/0,294698,sid14_gci1171862,00.html My favorite bit: "Obviously, secrecy is important to business, as is the ability...
Steve Riley on Security
File under: "You've got to be kidding!"
Posted
over 7 years ago
by
TechNet Archive
3
Comments
Today I upgraded the brain on my i-mate K-JAM. Which, of course, requires a hard reset, meaning that I get to spend a relaxing day re-installing and configuring all my applications. Usually when I do this (too frequently, it seems) I browse around for...
Steve Riley on Security
Domain controller security: it starts at layer zero
Posted
over 7 years ago
by
TechNet Archive
8
Comments
Recently I seem to have had the same conversation over and over again, in places as far apart as Jakarta, Winnipeg, and Berlin. The question is usually worded like this: "What happens if someone steals one of my domain controllers?" There is...
Steve Riley on Security
A CEO who should be fired
Posted
over 7 years ago
by
TechNet Archive
9
Comments
So the CEO of an important customer of ours (no, I won't tell you who it is) claims to be, um, "very technical" and therefore keeps his own Windows domain and refuses to be part of the corporate forest. Go ahead, take a moment to express your astonishment;...
Steve Riley on Security
Update to my appearances
Posted
over 7 years ago
by
TechNet Archive
0
Comments
Some dates have changed: we had to move the days for the Southeast Asia roadshow in Viet Nam. Also, I'm speaking at MEDC (Mobile and Embedded DevCon) this year -- a presentation on how Microsoft's IT department secures mobile computing. I've updated the...
Steve Riley on Security
Remote Access Quarantine (TechNet Magazine article)
Posted
over 7 years ago
by
TechNet Archive
9
Comments
http://www.microsoft.com/technet/technetmag/issues/2006/03/SecurityWatch/default.aspx In those good old easy-to-manage pre-mobility days, personal computers presented few actual threats to a network. Sure, there was the occasional virus you’d get from...
Steve Riley on Security
It's me, and here's my proof: why identity and authentication must remain distinct
Posted
over 7 years ago
by
TechNet Archive
7
Comments
My February Security Management column is posted: http://www.microsoft.com/technet/community/columns/secmgmt/sm0206.mspx No matter what kinds of technological or procedural advancements occur, certain principles of computer science will remain ...
Steve Riley on Security
Security summits and seminars around the world
Posted
over 7 years ago
by
TechNet Archive
17
Comments
Wow! After what seemed like a too-short month off (December), the work has resumed with vigorous intensity. Here are my public appearances in the coming weeks and months: 24 Jan : Beyond the Firewall security seminar in Jakarta 7-8 Feb : I.T. Professional...
Steve Riley on Security
What motivates a journalist?
Posted
over 7 years ago
by
TechNet Archive
4
Comments
OK, I have to unload a burden here. I often interact with the tech press in various places throughout the world. I've had wonderful, productive meetings with many fine journalists. New Zealand and Malaysia particularly stand out in my memory. However...
Steve Riley on Security
Return on security investment
Posted
over 7 years ago
by
TechNet Archive
16
Comments
Soon I will begin a research project into quantifying and expressing return on security investment. From conversations I've had with many conference attendees, there's a need for developing a basic understanding of how to measure ROSI so that budget money...
Steve Riley on Security
New site at the top of my favorites list
Posted
over 8 years ago
by
TechNet Archive
4
Comments
You know, stupid security abounds. I just discovered this site today, and I plan to become a regular visitor -- and probably a contributor, too! I encourage you to explore it and enjoy. Oh, some advice: it probably would be unwise to read an offline archived...
Steve Riley on Security
How to secure your wireless network
Posted
over 8 years ago
by
TechNet Archive
4
Comments
I'm now a contributing editor for TechNet Magazine . Everyone with a TechNet subscription automatically receives it; if you don't have one, you can still get the magazine free . The magazine's published three issues so far: Winter 2005 , Spring 2005 ...
Steve Riley on Security
But I can't test! My boss won't let me
Posted
over 8 years ago
by
TechNet Archive
1
Comments
Yesterday I mentioned that there's no substitute for doing your own testing of updates. I mentioned virtualization is your friend -- building a model of your environment using Virtual PC and Virtual Server will save you a lot of money and it's something...
Steve Riley on Security
When security breaks things
Posted
over 8 years ago
by
TechNet Archive
14
Comments
Now that the furor has waned, I want to comment on MS05-051. For those of you who don't memorize bulletin numbers (I am part of that set; Susan Bradley , for example, isn't, hehe), this is the security update that fixed a number of vulnerabilities found...
Steve Riley on Security
My music
Posted
over 8 years ago
by
TechNet Archive
5
Comments
Those of you who've seen me speak at various events know that I like to play my own music before the presentations begin. In industry parlance, this is called "walk-in music." My experience, though, is that many times the music they provide is better...
Steve Riley on Security
The Internet routes around outages -- and censorship, too
Posted
over 8 years ago
by
TechNet Archive
3
Comments
Have you seen this yet? " Grokster ruling begins the good fight " If you haven't, it's worth your time to read -- it's a terrible shibboleth for a U.S. "national firewall." Coursey is promoting the idea that all U.S. Internet access should pass through...
Steve Riley on Security
Some videos of me
Posted
over 8 years ago
by
TechNet Archive
6
Comments
Microsoft UK has posted videos of various European events of the past year. Various speakers are featured, including Andreas Luther, Dennis Karlinsky, Eileen Brown, Graham Calladine, Jesper Johansson, John Craddock, Justin Alderson, Kalpit Jain, Kimberly...
Steve Riley on Security
Cluelessness abounds
Posted
over 8 years ago
by
TechNet Archive
2
Comments
So yesterday I received a rather interesting email. Subject: "INFOSEC Scholarships & Fellowships for PhD or MS + Free CISSP Exam Prep Events." Hm, I didn't know that "information security" suddenly became an all-caps acronym. How come no one asks...
Steve Riley on Security
Lousy security
Posted
over 8 years ago
by
TechNet Archive
2
Comments
Lousy security is all around us, and I'm not even thinking about airport security here (which, I admit, i love griping about). Here I have in mind lousy computer security. And lest you think I'm proceeding to engage in naval-gazing introspection, no ...
Steve Riley on Security
Jesper finally got a blog up!
Posted
over 8 years ago
by
TechNet Archive
5
Comments
Well, after several months of griping (what else is new? hehe), Jesper's finally started a blog. And he's got some scathing criticism of how people commonly abuse audiences with PowerPoint. Good reading! Check him out at http://blogs.technet.com/jesper_johansson...
Steve Riley on Security
August article: 802.1X on wired networks considered harmful
Posted
over 8 years ago
by
TechNet Archive
16
Comments
Several months ago I learned from Svyatoslav Pidgorny, Microsoft MVP for security, about a problem in 802.1X that makes it essentially useless for protecting wired networks from rogue machines. Initially I was a bit skeptical, but the attack he described...
Steve Riley on Security
Tools in the proposed consumer security book
Posted
over 8 years ago
by
TechNet Archive
1
Comments
Oh, I forgot to mention that we're planning some tools for the consumer book , too. The first will help you set yourself up as a least-privileged user. It would detect how you're running now, create an account for managing the system and running games...
Steve Riley on Security
Idea for second book -- "Stay safe online: computer security at home"
Posted
over 8 years ago
by
TechNet Archive
16
Comments
Jesper and I are planning a second book. We've noticed a distinct dearth of useful, actionable, and non-scare-mongering computer security resources for home users. A few of the books we've seen are hopelessly bad, really. Either they rapidly forget their...
Steve Riley on Security
Updated TechEd worldwide -- new China dates
Posted
over 8 years ago
by
TechNet Archive
3
Comments
The dates for TechEd China have changed (venue issues), and I've added another city. Here's the updated list: Europe , in Amsterdam (4-8 July) Japan, in Yokohama (2-5 August) Asia , in Singapore (24-26 August) New Zealand , in Auckland (28-31 August...
Steve Riley on Security
Airport security silliness
Posted
over 8 years ago
by
TechNet Archive
5
Comments
So today (Thursday 21 July 2005) I flew from Seattle to Dallas for a customer meeting. Since it's a short one-day affair, I packed my small carry-on size suitcase. In it was a pair of shoes, one pants, one shorts, two shirts, a toiletry bag, and my collection...
Page 4 of 5 (114 items)
1
2
3
4
5