<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>MSRC Ecosystem Strategy Team : BlueHat</title><link>http://blogs.technet.com/ecostrat/archive/tags/BlueHat/default.aspx</link><description>Tags: BlueHat</description><dc:language>en-US</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>A Brussels retrospective from Oahu</title><link>http://blogs.technet.com/ecostrat/archive/2009/06/12/a-brussels-retrospective-from-oahu.aspx</link><pubDate>Fri, 12 Jun 2009 07:31:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3254070</guid><dc:creator>msrcecostrat</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/ecostrat/comments/3254070.aspx</comments><wfw:commentRss>http://blogs.technet.com/ecostrat/commentrss.aspx?PostID=3254070</wfw:commentRss><description>&lt;P&gt;&lt;div class="author"&gt;
&lt;img src="http://blogs.technet.com/photos/msrcecostrat/images/3147552/original.aspx" /&gt; 
&lt;b&gt;&lt;br/&gt;Handle:&lt;/b&gt;&lt;br /&gt;Security Blanki&lt;br /&gt;&lt;br /&gt;
&lt;b&gt;IRL: &lt;/b&gt;&lt;br /&gt;Sarah Blankinship&lt;br /&gt;&lt;br /&gt;
&lt;b&gt;Rank: &lt;/b&gt;&lt;br /&gt;Senior Security Strategist Lead&lt;br /&gt;&lt;br /&gt;
&lt;b&gt;Likes: &lt;/b&gt;&lt;br /&gt;Vuln wrangling, teams of rivals, global climate change - the hotter the better&lt;br /&gt;&lt;br /&gt;
&lt;b&gt;Dislikes: &lt;/b&gt;&lt;br /&gt;Slack jawed gawkers (girls are geeks too!), customers @ risk, egos&lt;br /&gt;&lt;br/&gt;&lt;/div&gt; 
&lt;P&gt;Aloha from the &lt;A href="http://shakacon.org/" mce_href="http://shakacon.org/"&gt;Shakacon III&lt;/A&gt;, a security conference held each year in lovely Honolulu, Hawaii! Although I’m currently in a different region of the world, talking with a completely different segment of the security ecosystem, I wanted to take a few moments to reflect on the BlueHat Security Forum EU event recently held in Brussels, Belgium. 
&lt;P&gt;&lt;A href="http://blogs.technet.com/ecostrat/archive/2009/06/02/announcing-the-bluehat-security-forum-eu-edition.aspx" mce_href="http://blogs.technet.com/ecostrat/archive/2009/06/02/announcing-the-bluehat-security-forum-eu-edition.aspx"&gt;Celene’s EcoStrat blog post&lt;/A&gt; highlighted the collaborative nature of the event and described the amazing content that was presented to the group of key EU security stakeholders. While to be a part of building a new platform for technical information exchange was a success in itself, we all have different priorities. In order to effect change, we must understand each other and work together, across technologies, organizations, and country boundaries. With the building of better collaboration in this community, we all have taken one more step in helping to secure the planet as a collective. 
&lt;P&gt;I’ve mentioned in a previous &lt;A href="http://blogs.technet.com/ecostrat/archive/2008/10/30/observations-from-the-ecostrat-isphere.aspx" mce_href="http://blogs.technet.com/ecostrat/archive/2008/10/30/observations-from-the-ecostrat-isphere.aspx"&gt;EcoStrat post&lt;/A&gt; that the EcoStrat team strives to build bridges and help folks get over them. The BlueHat Security Forum EU event was an example of bridge-building in action. It was rewarding to introduce representatives from governments, industry, and enterprises, as well as individual participants to each other. Prior to the BlueHat Security Forum, this particularly diverse group had never been in the same room discussing current security threat landscapes, understanding together the realities of securing critical national infrastructures and corporate networks alike. 
&lt;P&gt;With such a diverse collection of attendees, participants naturally had a wide-range of security priorities. Concerns ranged from targeted attacks to ID theft, defending Web applications and supply chains, developing and deploying secure coding practices to policy development, political concerns within and outside of the EU, and the list goes on. 
&lt;P&gt;Certainly the message that there is no one magic solution to security was delivered. There is still so much work to be done. It will take defense-in-depth, secure coding, securing third-party applications and proprietary applications; it will take technology &lt;B&gt;and&lt;/B&gt; people. We all understand that security can be likened to an arms race; every innovation we make in security is met by a very sophisticated collective of global malicious actors. We must be vigilant together; we must work together. 
&lt;P&gt;Mahalo for reading and here’s to another step towards achieving community-based defense. 
&lt;P&gt;Sarah &lt;/P&gt;
&lt;P&gt;&lt;SPAN class=sbmLink&gt;
&lt;TABLE cellSpacing=1 cellPadding=1 unselectable="on"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD class=sbmText class="sbmText"&gt;Share this post : &lt;/TD&gt;
&lt;TD class=sbmDim onmouseover=mOvr(this) onmouseout=mOut(this) class="sbmDim"&gt;&lt;A class=sbmDim onmouseover=mOvr(this) title="Post it to backflip" onmouseout=mOut(this) href="http://www.backflip.com/add_page_pop.ihtml?url=http://blogs.technet.com/ecostrat/archive/2009/06/12/a-brussels-retrospective-from-oahu.aspx&amp;amp;title=A Brussels retrospective from Oahu" target=_blank&gt;&lt;IMG border=0 src="http://blogs.msdn.com/blogfiles/rahulso/WindowsLiveWriter/IconsfordifferentSocialBookmarkingSites_B387/backflip4.png"&gt;&lt;/A&gt; 
&lt;TD class=sbmDim onmouseover=mOvr(this) onmouseout=mOut(this) class="sbmDim"&gt;&lt;A class=sbmDim onmouseover=mOvr(this) title="Post it to blinkbits!" onmouseout=mOut(this) href="http://www.blinkbits.com/bookmarklets/save.php?v=1&amp;amp;source_url=http://blogs.technet.com/ecostrat/archive/2009/06/12/a-brussels-retrospective-from-oahu.aspx&amp;amp;title=A Brussels retrospective from Oahu" target=_blank&gt;&lt;IMG border=0 src="http://blogs.msdn.com/blogfiles/rahulso/WindowsLiveWriter/IconsfordifferentSocialBookmarkingSites_B387/blinkbit4.png"&gt;&lt;/A&gt; 
&lt;TD class=sbmDim onmouseover=mOvr(this) onmouseout=mOut(this) class="sbmDim"&gt;&lt;A class=sbmDim onmouseover=mOvr(this) title="Post it to blogmemes" onmouseout=mOut(this) href="http://www.blogmemes.net/post.php?url=http://blogs.technet.com/ecostrat/archive/2009/06/12/a-brussels-retrospective-from-oahu.aspx&amp;amp;title=A Brussels retrospective from Oahu" target=_blank&gt;&lt;IMG border=0 src="http://blogs.msdn.com/blogfiles/rahulso/WindowsLiveWriter/IconsfordifferentSocialBookmarkingSites_B387/blogmemes4.png"&gt;&lt;/A&gt; 
&lt;TD class=sbmDim onmouseover=mOvr(this) onmouseout=mOut(this) class="sbmDim"&gt;&lt;A class=sbmDim onmouseover=mOvr(this) title="Post it to buddymark" onmouseout=mOut(this) href="http://buddymarks.com/s_add_bookmark.php?bookmark_url=http://blogs.technet.com/ecostrat/archive/2009/06/12/a-brussels-retrospective-from-oahu.aspx&amp;amp;bookmark_title=A Brussels retrospective from Oahu" target=_blank&gt;&lt;IMG border=0 src="http://blogs.msdn.com/blogfiles/rahulso/WindowsLiveWriter/IconsfordifferentSocialBookmarkingSites_B387/buddymar4.png"&gt;&lt;/A&gt; 
&lt;TD class=sbmDim onmouseover=mOvr(this) onmouseout=mOut(this) class="sbmDim"&gt;&lt;A class=sbmDim onmouseover=mOvr(this) title="Post it to complore" onmouseout=mOut(this) href="http://complore.com/?q=node/add/flexinode-5&amp;amp;url=http://blogs.technet.com/ecostrat/archive/2009/06/12/a-brussels-retrospective-from-oahu.aspx&amp;amp;title=A Brussels retrospective from Oahu" target=_blank&gt;&lt;IMG border=0 src="http://blogs.msdn.com/blogfiles/rahulso/WindowsLiveWriter/IconsfordifferentSocialBookmarkingSites_B387/complore4.png"&gt;&lt;/A&gt; 
&lt;TD class=sbmDim onmouseover=mOvr(this) onmouseout=mOut(this) class="sbmDim"&gt;&lt;A class=sbmDim onmouseover=mOvr(this) title="Post it to del.icio.us" onmouseout=mOut(this) href="http://del.icio.us/post?url=http://blogs.technet.com/ecostrat/archive/2009/06/12/a-brussels-retrospective-from-oahu.aspx&amp;amp;;title=A Brussels retrospective from Oahu" target=_blank&gt;&lt;IMG border=0 src="http://blogs.msdn.com/blogfiles/rahulso/WindowsLiveWriter/IconsfordifferentSocialBookmarkingSites_B387/deliciou4.png"&gt;&lt;/A&gt; 
&lt;TD class=sbmDim onmouseover=mOvr(this) onmouseout=mOut(this) class="sbmDim"&gt;&lt;A class=sbmDim onmouseover=mOvr(this) title="Post it to del.iri.ous!" onmouseout=mOut(this) href="http://de.lirio.us/bookmarks/sbmtool?action=add&amp;amp;address=http://blogs.technet.com/ecostrat/archive/2009/06/12/a-brussels-retrospective-from-oahu.aspx&amp;amp;title=A Brussels retrospective from Oahu" target=_blank&gt;&lt;IMG border=0 src="http://blogs.msdn.com/blogfiles/rahulso/WindowsLiveWriter/IconsfordifferentSocialBookmarkingSites_B387/deliriou4.png"&gt;&lt;/A&gt; 
&lt;TD class=sbmDim onmouseover=mOvr(this) onmouseout=mOut(this) class="sbmDim"&gt;&lt;A class=sbmDim onmouseover=mOvr(this) title="Post it to digg" onmouseout=mOut(this) href="http://digg.com/submit?phase=2&amp;amp;url=http://blogs.technet.com/ecostrat/archive/2009/06/12/a-brussels-retrospective-from-oahu.aspx&amp;amp;title=A Brussels retrospective from Oahu" target=_blank&gt;&lt;IMG border=0 src="http://blogs.msdn.com/blogfiles/rahulso/WindowsLiveWriter/IconsfordifferentSocialBookmarkingSites_B387/digg14.png"&gt;&lt;/A&gt; 
&lt;TD class=sbmDim onmouseover=mOvr(this) onmouseout=mOut(this) class="sbmDim"&gt;&lt;A class=sbmDim onmouseover=mOvr(this) title="Post it to dotnetkicks" onmouseout=mOut(this) href="http://www.dotnetkicks.com/kick/?url=http://blogs.technet.com/ecostrat/archive/2009/06/12/a-brussels-retrospective-from-oahu.aspx&amp;amp;title=A Brussels retrospective from Oahu" target=_blank&gt;&lt;IMG border=0 src="http://blogs.msdn.com/blogfiles/rahulso/WindowsLiveWriter/IconsfordifferentSocialBookmarkingSites_B387/CropperCapture154.jpg"&gt;&lt;/A&gt; 
&lt;TD class=sbmDim onmouseover=mOvr(this) onmouseout=mOut(this) class="sbmDim"&gt;&lt;A class=sbmDim onmouseover=mOvr(this) title="Post it to furl" onmouseout=mOut(this) href="http://www.furl.net/store?s=f&amp;amp;to=0&amp;amp;u=http://blogs.technet.com/ecostrat/archive/2009/06/12/a-brussels-retrospective-from-oahu.aspx&amp;amp;ti=A Brussels retrospective from Oahu" target=_blank&gt;&lt;IMG border=0 src="http://blogs.msdn.com/blogfiles/rahulso/WindowsLiveWriter/IconsfordifferentSocialBookmarkingSites_B387/furl4.png"&gt;&lt;/A&gt; 
&lt;TD class=sbmDim onmouseover=mOvr(this) onmouseout=mOut(this) class="sbmDim"&gt;&lt;A class=sbmDim onmouseover=mOvr(this) title="Post it to live" onmouseout=mOut(this) href="https://favorites.live.com/quickadd.aspx?marklet=1&amp;amp;mkt=en-us&amp;amp;url=http://blogs.technet.com/ecostrat/archive/2009/06/12/a-brussels-retrospective-from-oahu.aspx&amp;amp;title=A Brussels retrospective from Oahu" target=_blank&gt;&lt;IMG border=0 src="http://blogs.msdn.com/blogfiles/rahulso/WindowsLiveWriter/IconsfordifferentSocialBookmarkingSites_B387/live4.png"&gt;&lt;/A&gt; 
&lt;TD class=sbmDim onmouseover=mOvr(this) onmouseout=mOut(this) class="sbmDim"&gt;&lt;A class=sbmDim onmouseover=mOvr(this) title="Post it to magnolia!" onmouseout=mOut(this) href="http://ma.gnolia.com/bookmarklet/add?url=http://blogs.technet.com/ecostrat/archive/2009/06/12/a-brussels-retrospective-from-oahu.aspx&amp;amp;title=A Brussels retrospective from Oahu" target=_blank&gt;&lt;IMG border=0 src="http://blogs.msdn.com/blogfiles/rahulso/WindowsLiveWriter/IconsfordifferentSocialBookmarkingSites_B387/magnolia4.png"&gt;&lt;/A&gt; 
&lt;TD class=sbmDim onmouseover=mOvr(this) onmouseout=mOut(this) class="sbmDim"&gt;&lt;A class=sbmDim onmouseover=mOvr(this) title="Post it to netvouz!" onmouseout=mOut(this) href="http://netvouz.com/action/submitBookmark?url=http://blogs.technet.com/ecostrat/archive/2009/06/12/a-brussels-retrospective-from-oahu.aspx&amp;amp;title=A Brussels retrospective from Oahu" target=_blank&gt;&lt;IMG border=0 src="http://blogs.msdn.com/blogfiles/rahulso/WindowsLiveWriter/IconsfordifferentSocialBookmarkingSites_B387/netvouz4.png"&gt;&lt;/A&gt; 
&lt;TD class=sbmDim onmouseover=mOvr(this) onmouseout=mOut(this) class="sbmDim"&gt;&lt;A class=sbmDim onmouseover=mOvr(this) title="Post it to reddit!" onmouseout=mOut(this) href="http://reddit.com/submit?url=http://blogs.technet.com/ecostrat/archive/2009/06/12/a-brussels-retrospective-from-oahu.aspx&amp;amp;title=A Brussels retrospective from Oahu" target=_blank&gt;&lt;IMG border=0 src="http://blogs.msdn.com/blogfiles/rahulso/WindowsLiveWriter/IconsfordifferentSocialBookmarkingSites_B387/reddit4.png"&gt;&lt;/A&gt; 
&lt;TD class=sbmDim onmouseover=mOvr(this) onmouseout=mOut(this) class="sbmDim"&gt;&lt;A class=sbmDim onmouseover=mOvr(this) title="Post it to shadow" onmouseout=mOut(this) href="http://www.shadows.com/bookmark/saveLink.rails?page=http://blogs.technet.com/ecostrat/archive/2009/06/12/a-brussels-retrospective-from-oahu.aspx&amp;amp;title=A Brussels retrospective from Oahu" target=_blank&gt;&lt;IMG border=0 src="http://blogs.msdn.com/blogfiles/rahulso/WindowsLiveWriter/IconsfordifferentSocialBookmarkingSites_B387/shadows6.png"&gt;&lt;/A&gt; 
&lt;TD class=sbmDim onmouseover=mOvr(this) onmouseout=mOut(this) class="sbmDim"&gt;&lt;A class=sbmDim onmouseover=mOvr(this) title="Post it to spurl" onmouseout=mOut(this) href="http://www.spurl.net/spurl.php?v=3&amp;amp;url=http://blogs.technet.com/ecostrat/archive/2009/06/12/a-brussels-retrospective-from-oahu.aspx&amp;amp;title=A Brussels retrospective from Oahu" target=_blank&gt;&lt;IMG border=0 src="http://blogs.msdn.com/blogfiles/rahulso/WindowsLiveWriter/IconsfordifferentSocialBookmarkingSites_B387/spurl8.png"&gt;&lt;/A&gt; 
&lt;TD class=sbmDim onmouseover=mOvr(this) onmouseout=mOut(this) class="sbmDim"&gt;&lt;A class=sbmDim onmouseover=mOvr(this) title="Post it to technorati!" onmouseout=mOut(this) href="http://technorati.com/faves/?add=http://blogs.technet.com/ecostrat/archive/2009/06/12/a-brussels-retrospective-from-oahu.aspx&amp;amp;title=A Brussels retrospective from Oahu" target=_blank&gt;&lt;IMG border=0 src="http://blogs.msdn.com/blogfiles/rahulso/WindowsLiveWriter/IconsfordifferentSocialBookmarkingSites_B387/technora4.png"&gt;&lt;/A&gt; 
&lt;TD class=sbmDim onmouseover=mOvr(this) onmouseout=mOut(this) class="sbmDim"&gt;&lt;A class=sbmDim onmouseover=mOvr(this) title="Post it to wists" onmouseout=mOut(this) href="http://www.wists.com/?action=add&amp;amp;url=http://blogs.technet.com/ecostrat/archive/2009/06/12/a-brussels-retrospective-from-oahu.aspx&amp;amp;title=A Brussels retrospective from Oahu" target=_blank&gt;&lt;IMG border=0 src="http://blogs.msdn.com/blogfiles/rahulso/WindowsLiveWriter/IconsfordifferentSocialBookmarkingSites_B387/wists9.png"&gt;&lt;/A&gt; 
&lt;TD class=sbmDim onmouseover=mOvr(this) onmouseout=mOut(this) class="sbmDim"&gt;&lt;A class=sbmDim onmouseover=mOvr(this) title="Post it to yahoo!" onmouseout=mOut(this) href="http://myweb.yahoo.com/myresults/bookmarklet?u=http://blogs.technet.com/ecostrat/archive/2009/06/12/a-brussels-retrospective-from-oahu.aspx&amp;amp;t=A Brussels retrospective from Oahu" target=_blank&gt;&lt;IMG border=0 src="http://blogs.msdn.com/blogfiles/rahulso/WindowsLiveWriter/IconsfordifferentSocialBookmarkingSites_B387/yahoo9.png"&gt;&lt;/A&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;*Postings are provided "AS IS" with no warranties, and confers no rights.*&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3254070" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/ecostrat/archive/tags/BlueHat/default.aspx">BlueHat</category><category domain="http://blogs.technet.com/ecostrat/archive/tags/Community-Based+Defense/default.aspx">Community-Based Defense</category><category domain="http://blogs.technet.com/ecostrat/archive/tags/Conferences/default.aspx">Conferences</category><category domain="http://blogs.technet.com/ecostrat/archive/tags/EcoStrat/default.aspx">EcoStrat</category><category domain="http://blogs.technet.com/ecostrat/archive/tags/Security+Ecosystem/default.aspx">Security Ecosystem</category></item><item><title>Announcing the BlueHat Security Forum: EU Edition</title><link>http://blogs.technet.com/ecostrat/archive/2009/06/02/announcing-the-bluehat-security-forum-eu-edition.aspx</link><pubDate>Tue, 02 Jun 2009 08:30:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3249680</guid><dc:creator>msrcecostrat</dc:creator><slash:comments>1</slash:comments><comments>http://blogs.technet.com/ecostrat/comments/3249680.aspx</comments><wfw:commentRss>http://blogs.technet.com/ecostrat/commentrss.aspx?PostID=3249680</wfw:commentRss><description>&lt;P&gt;&lt;div class="author"&gt;
&lt;img src="http://blogs.technet.com/photos/msrcecostrat/images/3148860/original.aspx" /&gt; 
&lt;b&gt;Handle:&lt;/b&gt;&lt;br /&gt;C-Lizzle&lt;br /&gt;&lt;br /&gt;
&lt;b&gt;IRL: &lt;/b&gt;&lt;br /&gt;Celene Temkin&lt;br /&gt;&lt;br /&gt;
&lt;b&gt;Rank: &lt;/b&gt;&lt;br /&gt;Program Manager 2 &amp; BlueHat Project Manager&lt;br /&gt;&lt;br /&gt;
&lt;b&gt;Likes: &lt;/b&gt;&lt;br /&gt;Culinary warfare, BlueHat hackers and responsible disclosure&lt;br /&gt;&lt;br /&gt;
&lt;b&gt;Dislikes: &lt;/b&gt;&lt;br /&gt;Acts of hubris, MySpace, orange mocha Frappaccinos!&lt;br /&gt;&lt;br /&gt;
&lt;/div&gt; &lt;/P&gt;
&lt;P&gt;Hey folks! I know this is typically the time of year when birds are chirping, the rain is &lt;I&gt;supposed &lt;/I&gt;to be letting up, and those of you in the BlueHat network who are normally invited to attend the Spring BlueHat conference are asking yourselves, "Why did MSRC start doing the con only once a year?" The answer, of course, is pretty simple and complicated at the same time. Today marks the beginning of the next evolution of the BlueHat Security Briefings, with the launch of the &lt;B&gt;BlueHat Security Forum&lt;/B&gt; taking place at the Microsoft Executive Briefing Center in Brussels, Belgium. &lt;/P&gt;
&lt;P&gt;Following the success of the &lt;A href="http://technet.microsoft.com/en-us/security/cc261637.aspx" mce_href="http://technet.microsoft.com/en-us/security/cc261637.aspx"&gt;BlueHat Security Briefings&lt;/A&gt;, entering its 9&lt;SUP&gt;th&lt;/SUP&gt; iteration this October 22-23 at the Microsoft campus in Redmond, the BlueHat Security Forum EU event is an invitation-only gathering and network of select government and enterprise decision-makers from throughout the European Union.&amp;nbsp; Attendee country representation includes Austria, Belgium, Denmark, Finland, France, Germany, Italy, Norway, Sweden, Switzerland, and the UK.&amp;nbsp; Today’s Forum gathering in Brussels features lively presentations on the latest developments in information security from Microsoft leaders and external security researcher luminaries. 
&lt;P&gt;The primary objective of the BlueHat Security Forum is to build bridges between our Microsoft Security Leadership team, key Enterprise security stakeholders, and members of the security research community. The secondary objective is to participate in candid, actionable, and constructive dialogue with key enterprise customers that will help Microsoft produce enterprise-ready, value-laden products and services.&amp;nbsp; The BlueHat Security Forum planning team formulates discussion topics for these meetings based on current security hot topics, new research and trends. 
&lt;P&gt;Today's BlueHat Security Forum EU event agenda will address: 
&lt;P&gt;· E-crime attacks, the vulnerability economy and the global threat landscape 
&lt;P&gt;· Security in the cloud, DNS security, and the malware landscape 
&lt;P&gt;· Microsoft Security Response Center (MSRC) processes and integrating a Security Development Lifecycle (SDL) 
&lt;P&gt;And did I mention our stellar line up? J Presenters from Microsoft Trustworthy Computing include Andrew Cushman, &lt;I&gt;Director of Trustworthy Computing Security;&lt;/I&gt; David Pollington, &lt;I&gt;Director of Security, Europe&lt;/I&gt;; Vinny Gullotto&lt;I&gt;, General Manager, Microsoft Malware Protection Center; &lt;/I&gt;Alex Lucas, &lt;I&gt;Principal Security Development Lead;&lt;/I&gt; Mike Reavey,&lt;I&gt; Director of MSRC; &lt;/I&gt;and from Global Foundation Services&lt;I&gt;, &lt;/I&gt;Martin Rues&lt;I&gt;, Director for Cloud Security, Microsoft &amp;amp; &lt;/I&gt;Scott Oxley&lt;I&gt;, Lead Architect for Cloud Security, Microsoft. &lt;/I&gt;External presenters include&lt;I&gt; &lt;/I&gt;Iftach Amit&lt;I&gt;, Director, Security Research, Aladdin; &lt;/I&gt;Dragos Ruiu&lt;I&gt;,&lt;/I&gt; &lt;I&gt;CEO SecWest Conferences, Security Technology Specialist; &lt;/I&gt;Dan Kaminsky&lt;I&gt;,&lt;/I&gt; &lt;I&gt;Director of Penetration Testing, IOActive; &lt;/I&gt;and&lt;I&gt; &lt;/I&gt;Scott Stender&lt;I&gt;, Principal, iSEC Partners, Inc.&lt;/I&gt;&lt;B&gt;&lt;/B&gt; 
&lt;P&gt;We are seeking to build upon the momentum of past events by showcasing how individual strategies can intersect to offer substantial benefits and positive-sum outcomes. As with the local BlueHat conference, we are looking to demystify global and regional security threats, and to create channels for productive information exchange on common threats between the security industry, governments and researchers. Future regional BlueHat Security Forums are planned for Asia in 2010 and LATAM in 2011. 
&lt;P&gt;Next up: save the date for BlueHat v9 this October 22-23 in Redmond. Stay tuned for more updates and information to come here and on the &lt;A href="http://blogs.technet.com/bluehat/" mce_href="http://blogs.technet.com/bluehat/"&gt;BlueHat Blog&lt;/A&gt;. Be sure to check out Iftach Ian Amit’s post also coinciding with the Forum, &lt;I&gt;&lt;A href="http://blogs.technet.com/bluehat/archive/2009/06/03/getting-a-business-degree-as-part-of-security-research.aspx" mce_href="http://blogs.technet.com/bluehat/archive/2009/06/03/getting-a-business-degree-as-part-of-security-research.aspx"&gt;Getting a business degree as part of Security Research?&lt;/A&gt;&lt;/I&gt; 
&lt;P&gt;Bon chance! 
&lt;P&gt;Celene&lt;/P&gt;
&lt;P&gt;&lt;SPAN class=sbmLink&gt;&amp;nbsp; 
&lt;TABLE cellSpacing=1 cellPadding=1 unselectable="on"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD class=sbmText class="sbmText"&gt;Share this post : &lt;/TD&gt;
&lt;TD class=sbmDim onmouseover=mOvr(this) onmouseout=mOut(this) class="sbmDim"&gt;&lt;A class=sbmDim onmouseover=mOvr(this) title="Post it to backflip" onmouseout=mOut(this) href="http://www.backflip.com/add_page_pop.ihtml?url=http://blogs.technet.com/ecostrat/archive/2009/06/03/announcing-the-bluehat-security-forum-eu-edition.aspx&amp;amp;title=Announcing the BlueHat Security Forum: EU Edition" target=_blank&gt;&lt;IMG border=0 src="http://blogs.msdn.com/blogfiles/rahulso/WindowsLiveWriter/IconsfordifferentSocialBookmarkingSites_B387/backflip4.png"&gt;&lt;/A&gt; 
&lt;TD class=sbmDim onmouseover=mOvr(this) onmouseout=mOut(this) class="sbmDim"&gt;&lt;A class=sbmDim onmouseover=mOvr(this) title="Post it to blinkbits!" onmouseout=mOut(this) href="http://www.blinkbits.com/bookmarklets/save.php?v=1&amp;amp;source_url=http://blogs.technet.com/ecostrat/archive/2009/06/03/announcing-the-bluehat-security-forum-eu-edition.aspx&amp;amp;title=Announcing the BlueHat Security Forum: EU Edition" target=_blank&gt;&lt;IMG border=0 src="http://blogs.msdn.com/blogfiles/rahulso/WindowsLiveWriter/IconsfordifferentSocialBookmarkingSites_B387/blinkbit4.png"&gt;&lt;/A&gt; 
&lt;TD class=sbmDim onmouseover=mOvr(this) onmouseout=mOut(this) class="sbmDim"&gt;&lt;A class=sbmDim onmouseover=mOvr(this) title="Post it to blogmemes" onmouseout=mOut(this) href="http://www.blogmemes.net/post.php?url=http://blogs.technet.com/ecostrat/archive/2009/06/03/announcing-the-bluehat-security-forum-eu-edition.aspx&amp;amp;title=Announcing the BlueHat Security Forum: EU Edition" target=_blank&gt;&lt;IMG border=0 src="http://blogs.msdn.com/blogfiles/rahulso/WindowsLiveWriter/IconsfordifferentSocialBookmarkingSites_B387/blogmemes4.png"&gt;&lt;/A&gt; 
&lt;TD class=sbmDim onmouseover=mOvr(this) onmouseout=mOut(this) class="sbmDim"&gt;&lt;A class=sbmDim onmouseover=mOvr(this) title="Post it to buddymark" onmouseout=mOut(this) href="http://buddymarks.com/s_add_bookmark.php?bookmark_url=http://blogs.technet.com/ecostrat/archive/2009/06/03/announcing-the-bluehat-security-forum-eu-edition.aspx&amp;amp;bookmark_title=Announcing the BlueHat Security Forum: EU Edition" target=_blank&gt;&lt;IMG border=0 src="http://blogs.msdn.com/blogfiles/rahulso/WindowsLiveWriter/IconsfordifferentSocialBookmarkingSites_B387/buddymar4.png"&gt;&lt;/A&gt; 
&lt;TD class=sbmDim onmouseover=mOvr(this) onmouseout=mOut(this) class="sbmDim"&gt;&lt;A class=sbmDim onmouseover=mOvr(this) title="Post it to complore" onmouseout=mOut(this) href="http://complore.com/?q=node/add/flexinode-5&amp;amp;url=http://blogs.technet.com/ecostrat/archive/2009/06/03/announcing-the-bluehat-security-forum-eu-edition.aspx&amp;amp;title=Announcing the BlueHat Security Forum: EU Edition" target=_blank&gt;&lt;IMG border=0 src="http://blogs.msdn.com/blogfiles/rahulso/WindowsLiveWriter/IconsfordifferentSocialBookmarkingSites_B387/complore4.png"&gt;&lt;/A&gt; 
&lt;TD class=sbmDim onmouseover=mOvr(this) onmouseout=mOut(this) class="sbmDim"&gt;&lt;A class=sbmDim onmouseover=mOvr(this) title="Post it to del.icio.us" onmouseout=mOut(this) href="http://del.icio.us/post?url=http://blogs.technet.com/ecostrat/archive/2009/06/03/announcing-the-bluehat-security-forum-eu-edition.aspx&amp;amp;;title=Announcing the BlueHat Security Forum: EU Edition" target=_blank&gt;&lt;IMG border=0 src="http://blogs.msdn.com/blogfiles/rahulso/WindowsLiveWriter/IconsfordifferentSocialBookmarkingSites_B387/deliciou4.png"&gt;&lt;/A&gt; 
&lt;TD class=sbmDim onmouseover=mOvr(this) onmouseout=mOut(this) class="sbmDim"&gt;&lt;A class=sbmDim onmouseover=mOvr(this) title="Post it to del.iri.ous!" onmouseout=mOut(this) href="http://de.lirio.us/bookmarks/sbmtool?action=add&amp;amp;address=http://blogs.technet.com/ecostrat/archive/2009/06/03/announcing-the-bluehat-security-forum-eu-edition.aspx&amp;amp;title=Announcing the BlueHat Security Forum: EU Edition" target=_blank&gt;&lt;IMG border=0 src="http://blogs.msdn.com/blogfiles/rahulso/WindowsLiveWriter/IconsfordifferentSocialBookmarkingSites_B387/deliriou4.png"&gt;&lt;/A&gt; 
&lt;TD class=sbmDim onmouseover=mOvr(this) onmouseout=mOut(this) class="sbmDim"&gt;&lt;A class=sbmDim onmouseover=mOvr(this) title="Post it to digg" onmouseout=mOut(this) href="http://digg.com/submit?phase=2&amp;amp;url=http://blogs.technet.com/ecostrat/archive/2009/06/03/announcing-the-bluehat-security-forum-eu-edition.aspx&amp;amp;title=Announcing the BlueHat Security Forum: EU Edition" target=_blank&gt;&lt;IMG border=0 src="http://blogs.msdn.com/blogfiles/rahulso/WindowsLiveWriter/IconsfordifferentSocialBookmarkingSites_B387/digg14.png"&gt;&lt;/A&gt; 
&lt;TD class=sbmDim onmouseover=mOvr(this) onmouseout=mOut(this) class="sbmDim"&gt;&lt;A class=sbmDim onmouseover=mOvr(this) title="Post it to dotnetkicks" onmouseout=mOut(this) href="http://www.dotnetkicks.com/kick/?url=http://blogs.technet.com/ecostrat/archive/2009/06/03/announcing-the-bluehat-security-forum-eu-edition.aspx&amp;amp;title=Announcing the BlueHat Security Forum: EU Edition" target=_blank&gt;&lt;IMG border=0 src="http://blogs.msdn.com/blogfiles/rahulso/WindowsLiveWriter/IconsfordifferentSocialBookmarkingSites_B387/CropperCapture154.jpg"&gt;&lt;/A&gt; 
&lt;TD class=sbmDim onmouseover=mOvr(this) onmouseout=mOut(this) class="sbmDim"&gt;&lt;A class=sbmDim onmouseover=mOvr(this) title="Post it to furl" onmouseout=mOut(this) href="http://www.furl.net/store?s=f&amp;amp;to=0&amp;amp;u=http://blogs.technet.com/ecostrat/archive/2009/06/03/announcing-the-bluehat-security-forum-eu-edition.aspx&amp;amp;ti=Announcing the BlueHat Security Forum: EU Edition" target=_blank&gt;&lt;IMG border=0 src="http://blogs.msdn.com/blogfiles/rahulso/WindowsLiveWriter/IconsfordifferentSocialBookmarkingSites_B387/furl4.png"&gt;&lt;/A&gt; 
&lt;TD class=sbmDim onmouseover=mOvr(this) onmouseout=mOut(this) class="sbmDim"&gt;&lt;A class=sbmDim onmouseover=mOvr(this) title="Post it to live" onmouseout=mOut(this) href="https://favorites.live.com/quickadd.aspx?marklet=1&amp;amp;mkt=en-us&amp;amp;url=http://blogs.technet.com/ecostrat/archive/2009/06/03/announcing-the-bluehat-security-forum-eu-edition.aspx&amp;amp;title=Announcing the BlueHat Security Forum: EU Edition" target=_blank&gt;&lt;IMG border=0 src="http://blogs.msdn.com/blogfiles/rahulso/WindowsLiveWriter/IconsfordifferentSocialBookmarkingSites_B387/live4.png"&gt;&lt;/A&gt; 
&lt;TD class=sbmDim onmouseover=mOvr(this) onmouseout=mOut(this) class="sbmDim"&gt;&lt;A class=sbmDim onmouseover=mOvr(this) title="Post it to magnolia!" onmouseout=mOut(this) href="http://ma.gnolia.com/bookmarklet/add?url=http://blogs.technet.com/ecostrat/archive/2009/06/03/announcing-the-bluehat-security-forum-eu-edition.aspx&amp;amp;title=Announcing the BlueHat Security Forum: EU Edition" target=_blank&gt;&lt;IMG border=0 src="http://blogs.msdn.com/blogfiles/rahulso/WindowsLiveWriter/IconsfordifferentSocialBookmarkingSites_B387/magnolia4.png"&gt;&lt;/A&gt; 
&lt;TD class=sbmDim onmouseover=mOvr(this) onmouseout=mOut(this) class="sbmDim"&gt;&lt;A class=sbmDim onmouseover=mOvr(this) title="Post it to netvouz!" onmouseout=mOut(this) href="http://netvouz.com/action/submitBookmark?url=http://blogs.technet.com/ecostrat/archive/2009/06/03/announcing-the-bluehat-security-forum-eu-edition.aspx&amp;amp;title=Announcing the BlueHat Security Forum: EU Edition" target=_blank&gt;&lt;IMG border=0 src="http://blogs.msdn.com/blogfiles/rahulso/WindowsLiveWriter/IconsfordifferentSocialBookmarkingSites_B387/netvouz4.png"&gt;&lt;/A&gt; 
&lt;TD class=sbmDim onmouseover=mOvr(this) onmouseout=mOut(this) class="sbmDim"&gt;&lt;A class=sbmDim onmouseover=mOvr(this) title="Post it to reddit!" onmouseout=mOut(this) href="http://reddit.com/submit?url=http://blogs.technet.com/ecostrat/archive/2009/06/03/announcing-the-bluehat-security-forum-eu-edition.aspx&amp;amp;title=Announcing the BlueHat Security Forum: EU Edition" target=_blank&gt;&lt;IMG border=0 src="http://blogs.msdn.com/blogfiles/rahulso/WindowsLiveWriter/IconsfordifferentSocialBookmarkingSites_B387/reddit4.png"&gt;&lt;/A&gt; 
&lt;TD class=sbmDim onmouseover=mOvr(this) onmouseout=mOut(this) class="sbmDim"&gt;&lt;A class=sbmDim onmouseover=mOvr(this) title="Post it to shadow" onmouseout=mOut(this) href="http://www.shadows.com/bookmark/saveLink.rails?page=http://blogs.technet.com/ecostrat/archive/2009/06/03/announcing-the-bluehat-security-forum-eu-edition.aspx&amp;amp;title=Announcing the BlueHat Security Forum: EU Edition" target=_blank&gt;&lt;IMG border=0 src="http://blogs.msdn.com/blogfiles/rahulso/WindowsLiveWriter/IconsfordifferentSocialBookmarkingSites_B387/shadows6.png"&gt;&lt;/A&gt; 
&lt;TD class=sbmDim onmouseover=mOvr(this) onmouseout=mOut(this) class="sbmDim"&gt;&lt;A class=sbmDim onmouseover=mOvr(this) title="Post it to spurl" onmouseout=mOut(this) href="http://www.spurl.net/spurl.php?v=3&amp;amp;url=http://blogs.technet.com/ecostrat/archive/2009/06/03/announcing-the-bluehat-security-forum-eu-edition.aspx&amp;amp;title=Announcing the BlueHat Security Forum: EU Edition" target=_blank&gt;&lt;IMG border=0 src="http://blogs.msdn.com/blogfiles/rahulso/WindowsLiveWriter/IconsfordifferentSocialBookmarkingSites_B387/spurl8.png"&gt;&lt;/A&gt; 
&lt;TD class=sbmDim onmouseover=mOvr(this) onmouseout=mOut(this) class="sbmDim"&gt;&lt;A class=sbmDim onmouseover=mOvr(this) title="Post it to technorati!" onmouseout=mOut(this) href="http://technorati.com/faves/?add=http://blogs.technet.com/ecostrat/archive/2009/06/03/announcing-the-bluehat-security-forum-eu-edition.aspx&amp;amp;title=Announcing the BlueHat Security Forum: EU Edition" target=_blank&gt;&lt;IMG border=0 src="http://blogs.msdn.com/blogfiles/rahulso/WindowsLiveWriter/IconsfordifferentSocialBookmarkingSites_B387/technora4.png"&gt;&lt;/A&gt; 
&lt;TD class=sbmDim onmouseover=mOvr(this) onmouseout=mOut(this) class="sbmDim"&gt;&lt;A class=sbmDim onmouseover=mOvr(this) title="Post it to wists" onmouseout=mOut(this) href="http://www.wists.com/?action=add&amp;amp;url=http://blogs.technet.com/ecostrat/archive/2009/06/03/announcing-the-bluehat-security-forum-eu-edition.aspx&amp;amp;title=Announcing the BlueHat Security Forum: EU Edition" target=_blank&gt;&lt;IMG border=0 src="http://blogs.msdn.com/blogfiles/rahulso/WindowsLiveWriter/IconsfordifferentSocialBookmarkingSites_B387/wists9.png"&gt;&lt;/A&gt; 
&lt;TD class=sbmDim onmouseover=mOvr(this) onmouseout=mOut(this) class="sbmDim"&gt;&lt;A class=sbmDim onmouseover=mOvr(this) title="Post it to yahoo!" onmouseout=mOut(this) href="http://myweb.yahoo.com/myresults/bookmarklet?u=http://blogs.technet.com/ecostrat/archive/2009/06/03/announcing-the-bluehat-security-forum-eu-edition.aspx&amp;amp;t=Announcing the BlueHat Security Forum: EU Edition" target=_blank&gt;&lt;IMG border=0 src="http://blogs.msdn.com/blogfiles/rahulso/WindowsLiveWriter/IconsfordifferentSocialBookmarkingSites_B387/yahoo9.png"&gt;&lt;/A&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;*Postings are provided "AS IS" with no warranties, and confers no rights.*&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3249680" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/ecostrat/archive/tags/BlueHat/default.aspx">BlueHat</category><category domain="http://blogs.technet.com/ecostrat/archive/tags/Community-Based+Defense/default.aspx">Community-Based Defense</category><category domain="http://blogs.technet.com/ecostrat/archive/tags/Conferences/default.aspx">Conferences</category><category domain="http://blogs.technet.com/ecostrat/archive/tags/EcoStrat/default.aspx">EcoStrat</category><category domain="http://blogs.technet.com/ecostrat/archive/tags/MSRC/default.aspx">MSRC</category><category domain="http://blogs.technet.com/ecostrat/archive/tags/Security+Ecosystem/default.aspx">Security Ecosystem</category><category domain="http://blogs.technet.com/ecostrat/archive/tags/Watering+Hole/default.aspx">Watering Hole</category></item><item><title>Hack in the Box, and beyond…</title><link>http://blogs.technet.com/ecostrat/archive/2009/05/13/hack-in-the-box-and-beyond.aspx</link><pubDate>Wed, 13 May 2009 08:00:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3240341</guid><dc:creator>msrcecostrat</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/ecostrat/comments/3240341.aspx</comments><wfw:commentRss>http://blogs.technet.com/ecostrat/commentrss.aspx?PostID=3240341</wfw:commentRss><description>&lt;P&gt;&lt;B&gt;&lt;div class="author"&gt;
&lt;img src="http://blogs.technet.com/photos/msrcecostrat/images/3237005/original.aspx" /&gt; 
&lt;b&gt;Handle:&lt;/b&gt;&lt;br /&gt;EcoStrat's All-Stars&lt;br /&gt;&lt;br /&gt;
&lt;b&gt;IRL: &lt;/b&gt;&lt;br /&gt;TwC Security All-Star Guest Bloggers&lt;br /&gt;&lt;br /&gt;
&lt;b&gt;Likes: &lt;/b&gt;&lt;br /&gt;Security, Vulnerability Research &amp; Science, Defense and Responsible Disclosure&lt;br /&gt;&lt;br /&gt;
&lt;b&gt;Dislikes: &lt;/b&gt;&lt;br /&gt;0-day, FUD&lt;br /&gt;&lt;br /&gt;
&lt;/div&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P&gt;&lt;B&gt;Marhaban!&lt;/B&gt; Maarten Van Horenbeeck here from the Microsoft Security Response Center (MSRC). This is the first time I have blogged here on EcoStrat. As a Security Program Manager with MSRC, one of the roles I have is to work with security researchers, and this often involves attending security conferences to meet with you. Two weeks ago, a couple of us in Trustworthy Computing (TwC) attended the Hack in the Box (HITB) security conference in hot and sizzling Dubai, United Arab Emirates.&lt;/P&gt;
&lt;DIV style="PADDING-BOTTOM: 0px; MARGIN: 0px; PADDING-LEFT: 0px; PADDING-RIGHT: 0px; DISPLAY: inline; FLOAT: left; PADDING-TOP: 0px" id=scid:8747F07C-CDE8-481f-B0DF-C6CFD074BF67:03959000-64a4-44b7-98d8-8310d37a81a0 class=wlWriterSmartContent&gt;&lt;A title="Burj Al Arab, the second tallest hotel in the world." href="http://blogs.technet.com/blogfiles/ecostrat/WindowsLiveWriter/HackintheBoxandbeyond_75B7/burjalarab-8x6.jpg" rel=thumbnail mce_href="http://blogs.technet.com/blogfiles/ecostrat/WindowsLiveWriter/HackintheBoxandbeyond_75B7/burjalarab-8x6.jpg"&gt;&lt;IMG border=0 src="http://blogs.technet.com/blogfiles/ecostrat/WindowsLiveWriter/HackintheBoxandbeyond_75B7/burjalarab_6.png" width=337 height=446 mce_src="http://blogs.technet.com/blogfiles/ecostrat/WindowsLiveWriter/HackintheBoxandbeyond_75B7/burjalarab_6.png"&gt;&lt;/A&gt;&lt;/DIV&gt;
&lt;P&gt;There is a saying that "every word in Arabic either means itself, its opposite, or a camel." Working in the information security industry, I often use this to illustrate to my clients how a piece of code that one person considers a vulnerability, can very well be seen as valid functionality by another. As such, my Microsoft colleagues and I were very interested in learning more about other Arabic sayings that could be applied to the information security industry as a whole.&amp;nbsp; 
&lt;P&gt;Hack in the Box is a twice-annual conference, taking place in Dubai, UAE during April, and somewhat later in the year in Kuala Lumpur, Malaysia. Given our past experiences with the value of the talks at the conference, Microsoft was a Titanium sponsor of this event. 
&lt;P&gt;The Dubai conference is more intimate than the Malaysia one, but that is exactly what makes it a great way for local information security professionals to network and learn more about cutting edge security research that is taking place all across the world. Presenters ventured from as far as Indonesia, the United States, and Germany. 
&lt;P&gt;At Microsoft, I think we can safely admit that in order to pioneer security efforts, we were forced to make every single mistake in the book and learn from it. When I started with the company, I was fascinated to see that we are in fact very good at learning. When we deal with an issue, we like to understand how we can resolve similar issues more effectively in the future. As such, we don’t just attend conferences to learn, but to start up a conversation – we are interested in sharing our own experiences as well as touching base with others. 
&lt;P&gt;Microsoft employees had two presentations lined up for this event. Mark Curphey, the director of Microsoft's Information Security Tools team, had a keynote presentation on security tools and technology for effective risk management. Mark focused on how most security tools and technology available to effectively manage risk can only be described as primitive in comparison to those used in most other areas of risk management, such as online gaming or healthcare. From my own experience as a security consultant, I can echo his finding that Microsoft Office Excel is often the most effective tool risk managers have at their disposal. 
&lt;P&gt;This is a gloomy situation, given the amount of risk most organizations are exposed to, but a broad sigh of relief was voiced by the audience when Mark clarified his team is working here at Microsoft on solving just that issue. 
&lt;P&gt;After Mark's talk, Ian Hellen from Microsoft's Security Assurance team and I spoke to several attendees who wanted to learn more about how M &lt;/P&gt;
&lt;DIV style="PADDING-BOTTOM: 0px; MARGIN: 0px; PADDING-LEFT: 0px; PADDING-RIGHT: 0px; DISPLAY: inline; FLOAT: right; PADDING-TOP: 0px" id=scid:8747F07C-CDE8-481f-B0DF-C6CFD074BF67:ab83e23a-9cc4-4699-b289-8f221400a7e4 class=wlWriterSmartContent&gt;&lt;A title="Conference attendees enjoying a presentation" href="http://blogs.technet.com/blogfiles/ecostrat/WindowsLiveWriter/HackintheBoxandbeyond_75B7/conference-8x6.jpg" rel=thumbnail mce_href="http://blogs.technet.com/blogfiles/ecostrat/WindowsLiveWriter/HackintheBoxandbeyond_75B7/conference-8x6.jpg"&gt;&lt;IMG border=0 src="http://blogs.technet.com/blogfiles/ecostrat/WindowsLiveWriter/HackintheBoxandbeyond_75B7/conference_7.png" width=420 height=269 mce_src="http://blogs.technet.com/blogfiles/ecostrat/WindowsLiveWriter/HackintheBoxandbeyond_75B7/conference_7.png"&gt;&lt;/A&gt;&lt;/DIV&gt;icrosoft deals with application security issues. We understood from them that there is a lot of internal software development taking place in Dubai to support business processes, and many of the attendees asked questions about how they could make their own applications more secure. We talked to them about the Microsoft Security Development Lifecycle (SDL), which is our standardized approach to software security. If you have similar interests, you can read more about it &lt;A href="http://msdn.microsoft.com/en-us/security/cc448177.aspx" mce_href="http://msdn.microsoft.com/en-us/security/cc448177.aspx"&gt;here&lt;/A&gt;. 
&lt;P&gt;Billy Rios, one of our resident security engineers, delivered a fascinating presentation on the concept of trust relationships in Web applications, and more specifically how a disparity exists between the security models implemented in Web applications, and those implemented by the browsers that host those applications. In addition, he collaborated with Chris Evans from Google to share with the audience some of their experiences with cross-domain issues and practical man-in-the-middle attacks on SSL. 
&lt;P&gt;While there was too much content at the conference for me to discuss in depth here, I will mention some of the other highlights. 
&lt;P&gt;Roberto Preatoni from WabiSabiLabi, one of our guests at BlueHat 6, presented on cyber warfare. He refuted Marcus Ranum’s 2007 statement at HITB Malaysia that cyber warfare is an overrated issue, by calling out several examples of contemporary cyber war. He illustrated how it may not just affect nation-states but its conflicts of interest can affect industries and individual corporations as well. &lt;/P&gt;
&lt;DIV style="PADDING-BOTTOM: 0px; MARGIN: 0px; PADDING-LEFT: 0px; PADDING-RIGHT: 0px; DISPLAY: inline; FLOAT: left; PADDING-TOP: 0px" id=scid:8747F07C-CDE8-481f-B0DF-C6CFD074BF67:2bc5a680-1786-4112-a04c-9417a346bb9a class=wlWriterSmartContent&gt;&lt;A title="Dubai Creek" href="http://blogs.technet.com/blogfiles/ecostrat/WindowsLiveWriter/HackintheBoxandbeyond_75B7/dubai1-8x6.jpg" rel=thumbnail mce_href="http://blogs.technet.com/blogfiles/ecostrat/WindowsLiveWriter/HackintheBoxandbeyond_75B7/dubai1-8x6.jpg"&gt;&lt;IMG border=0 src="http://blogs.technet.com/blogfiles/ecostrat/WindowsLiveWriter/HackintheBoxandbeyond_75B7/dubai1_8.png" width=420 height=358 mce_src="http://blogs.technet.com/blogfiles/ecostrat/WindowsLiveWriter/HackintheBoxandbeyond_75B7/dubai1_8.png"&gt;&lt;/A&gt;&lt;/DIV&gt;
&lt;P&gt;Reverse engineers in the audience welcomed Sebastian Porst from Zynamics. He spoke about REIL, their Reverse Engineering Intermediate Language, and more specifically how it can be used to optimize static binary code analysis. They actually used one of our vulnerabilities, the Windows Server Service vulnerability patched in MS08-067 (read more about it &lt;A href="http://blogs.technet.com/srd/archive/2008/10/23/More-detail-about-MS08-067.aspx" mce_href="http://blogs.technet.com/srd/archive/2008/10/23/More-detail-about-MS08-067.aspx"&gt;here&lt;/A&gt; and &lt;A href="http://blogs.msdn.com/sdl/archive/2008/10/22/ms08-067.aspx" mce_href="http://blogs.msdn.com/sdl/archive/2008/10/22/ms08-067.aspx"&gt;here&lt;/A&gt;) to illustrate how their tool works. This was definitely a topic many of our own engineers are deeply interested in. 
&lt;P&gt;Another well received talk came from Wes Brown of IOActive. He provided a good primer on analyzing malicious code, and gave it a twist by describing how languages, Unicode, and even culture all make a difference and make the reverse engineer’s work just a wee bit more difficult. 
&lt;P&gt;At the end of the conference, Microsoft sponsored the sunset Post-Conference Reception, which allowed for more valuable networking opportunities. 
&lt;P&gt;Sometimes dealing with security incidents and vulnerabilities can feel like marching across a desert. Confidentiality is an unspoken requirement, and often you can only rely on your own senses, knowledge and intuition. It is a great thing that just like in Dubai, there are watering holes where we can come together and rely on each other implicitly, sharing information and improving the state of the art in our business. Thanks, Hack in the Box, for a great conference, and we’ll see you next time. &lt;B&gt;Ma’a salama.&lt;/B&gt; 
&lt;P&gt;[Editor's note: check out the BlueHat Blog for another &lt;A href="http://blogs.technet.com/bluehat/archive/2009/05/13/dune-busting-and-browser-fun-at-hitb-dubai.aspx" mce_href="http://blogs.technet.com/bluehat/archive/2009/05/13/dune-busting-and-browser-fun-at-hitb-dubai.aspx"&gt;Microsoft perspective on HITB-Dubai&lt;/A&gt;] &lt;/P&gt;
&lt;P mce_keep="true"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class=sbmLink&gt;
&lt;TABLE cellSpacing=1 cellPadding=1 unselectable="on"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD class=sbmText class="sbmText"&gt;Share this post : &lt;/TD&gt;
&lt;TD class=sbmDim onmouseover=mOvr(this) onmouseout=mOut(this) class="sbmDim"&gt;&lt;A class=sbmDim onmouseover=mOvr(this) title="Post it to backflip" onmouseout=mOut(this) href="http://www.backflip.com/add_page_pop.ihtml?url=http://blogs.technet.com/ecostrat/archive/2009/05/13/hack-in-the-box-and-beyond.aspx&amp;amp;title=Hack in the Box, and beyond..." target=_blank&gt;&lt;IMG border=0 src="http://blogs.msdn.com/blogfiles/rahulso/WindowsLiveWriter/IconsfordifferentSocialBookmarkingSites_B387/backflip4.png"&gt;&lt;/A&gt; 
&lt;TD class=sbmDim onmouseover=mOvr(this) onmouseout=mOut(this) class="sbmDim"&gt;&lt;A class=sbmDim onmouseover=mOvr(this) title="Post it to blinkbits!" onmouseout=mOut(this) href="http://www.blinkbits.com/bookmarklets/save.php?v=1&amp;amp;source_url=http://blogs.technet.com/ecostrat/archive/2009/05/13/hack-in-the-box-and-beyond.aspx&amp;amp;title=Hack in the Box, and beyond..." target=_blank&gt;&lt;IMG border=0 src="http://blogs.msdn.com/blogfiles/rahulso/WindowsLiveWriter/IconsfordifferentSocialBookmarkingSites_B387/blinkbit4.png"&gt;&lt;/A&gt; 
&lt;TD class=sbmDim onmouseover=mOvr(this) onmouseout=mOut(this) class="sbmDim"&gt;&lt;A class=sbmDim onmouseover=mOvr(this) title="Post it to blogmemes" onmouseout=mOut(this) href="http://www.blogmemes.net/post.php?url=http://blogs.technet.com/ecostrat/archive/2009/05/13/hack-in-the-box-and-beyond.aspx&amp;amp;title=Hack in the Box, and beyond..." target=_blank&gt;&lt;IMG border=0 src="http://blogs.msdn.com/blogfiles/rahulso/WindowsLiveWriter/IconsfordifferentSocialBookmarkingSites_B387/blogmemes4.png"&gt;&lt;/A&gt; 
&lt;TD class=sbmDim onmouseover=mOvr(this) onmouseout=mOut(this) class="sbmDim"&gt;&lt;A class=sbmDim onmouseover=mOvr(this) title="Post it to buddymark" onmouseout=mOut(this) href="http://buddymarks.com/s_add_bookmark.php?bookmark_url=http://blogs.technet.com/ecostrat/archive/2009/05/13/hack-in-the-box-and-beyond.aspx&amp;amp;bookmark_title=Hack in the Box, and beyond..." target=_blank&gt;&lt;IMG border=0 src="http://blogs.msdn.com/blogfiles/rahulso/WindowsLiveWriter/IconsfordifferentSocialBookmarkingSites_B387/buddymar4.png"&gt;&lt;/A&gt; 
&lt;TD class=sbmDim onmouseover=mOvr(this) onmouseout=mOut(this) class="sbmDim"&gt;&lt;A class=sbmDim onmouseover=mOvr(this) title="Post it to complore" onmouseout=mOut(this) href="http://complore.com/?q=node/add/flexinode-5&amp;amp;url=http://blogs.technet.com/ecostrat/archive/2009/05/13/hack-in-the-box-and-beyond.aspx&amp;amp;title=Hack in the Box, and beyond..." target=_blank&gt;&lt;IMG border=0 src="http://blogs.msdn.com/blogfiles/rahulso/WindowsLiveWriter/IconsfordifferentSocialBookmarkingSites_B387/complore4.png"&gt;&lt;/A&gt; 
&lt;TD class=sbmDim onmouseover=mOvr(this) onmouseout=mOut(this) class="sbmDim"&gt;&lt;A class=sbmDim onmouseover=mOvr(this) title="Post it to del.icio.us" onmouseout=mOut(this) href="http://del.icio.us/post?url=http://blogs.technet.com/ecostrat/archive/2009/05/13/hack-in-the-box-and-beyond.aspx&amp;amp;;title=Hack in the Box, and beyond..." target=_blank&gt;&lt;IMG border=0 src="http://blogs.msdn.com/blogfiles/rahulso/WindowsLiveWriter/IconsfordifferentSocialBookmarkingSites_B387/deliciou4.png"&gt;&lt;/A&gt; 
&lt;TD class=sbmDim onmouseover=mOvr(this) onmouseout=mOut(this) class="sbmDim"&gt;&lt;A class=sbmDim onmouseover=mOvr(this) title="Post it to del.iri.ous!" onmouseout=mOut(this) href="http://de.lirio.us/bookmarks/sbmtool?action=add&amp;amp;address=http://blogs.technet.com/ecostrat/archive/2009/05/13/hack-in-the-box-and-beyond.aspx&amp;amp;title=Hack in the Box, and beyond..." target=_blank&gt;&lt;IMG border=0 src="http://blogs.msdn.com/blogfiles/rahulso/WindowsLiveWriter/IconsfordifferentSocialBookmarkingSites_B387/deliriou4.png"&gt;&lt;/A&gt; 
&lt;TD class=sbmDim onmouseover=mOvr(this) onmouseout=mOut(this) class="sbmDim"&gt;&lt;A class=sbmDim onmouseover=mOvr(this) title="Post it to digg" onmouseout=mOut(this) href="http://digg.com/submit?phase=2&amp;amp;url=http://blogs.technet.com/ecostrat/archive/2009/05/13/hack-in-the-box-and-beyond.aspx&amp;amp;title=Hack in the Box, and beyond..." target=_blank&gt;&lt;IMG border=0 src="http://blogs.msdn.com/blogfiles/rahulso/WindowsLiveWriter/IconsfordifferentSocialBookmarkingSites_B387/digg14.png"&gt;&lt;/A&gt; 
&lt;TD class=sbmDim onmouseover=mOvr(this) onmouseout=mOut(this) class="sbmDim"&gt;&lt;A class=sbmDim onmouseover=mOvr(this) title="Post it to dotnetkicks" onmouseout=mOut(this) href="http://www.dotnetkicks.com/kick/?url=http://blogs.technet.com/ecostrat/archive/2009/05/13/hack-in-the-box-and-beyond.aspx&amp;amp;title=Hack in the Box, and beyond..." target=_blank&gt;&lt;IMG border=0 src="http://blogs.msdn.com/blogfiles/rahulso/WindowsLiveWriter/IconsfordifferentSocialBookmarkingSites_B387/CropperCapture154.jpg"&gt;&lt;/A&gt; 
&lt;TD class=sbmDim onmouseover=mOvr(this) onmouseout=mOut(this) class="sbmDim"&gt;&lt;A class=sbmDim onmouseover=mOvr(this) title="Post it to furl" onmouseout=mOut(this) href="http://www.furl.net/store?s=f&amp;amp;to=0&amp;amp;u=http://blogs.technet.com/ecostrat/archive/2009/05/13/hack-in-the-box-and-beyond.aspx&amp;amp;ti=Hack in the Box, and beyond..." target=_blank&gt;&lt;IMG border=0 src="http://blogs.msdn.com/blogfiles/rahulso/WindowsLiveWriter/IconsfordifferentSocialBookmarkingSites_B387/furl4.png"&gt;&lt;/A&gt; 
&lt;TD class=sbmDim onmouseover=mOvr(this) onmouseout=mOut(this) class="sbmDim"&gt;&lt;A class=sbmDim onmouseover=mOvr(this) title="Post it to live" onmouseout=mOut(this) href="https://favorites.live.com/quickadd.aspx?marklet=1&amp;amp;mkt=en-us&amp;amp;url=http://blogs.technet.com/ecostrat/archive/2009/05/13/hack-in-the-box-and-beyond.aspx&amp;amp;title=Hack in the Box, and beyond..." target=_blank&gt;&lt;IMG border=0 src="http://blogs.msdn.com/blogfiles/rahulso/WindowsLiveWriter/IconsfordifferentSocialBookmarkingSites_B387/live4.png"&gt;&lt;/A&gt; 
&lt;TD class=sbmDim onmouseover=mOvr(this) onmouseout=mOut(this) class="sbmDim"&gt;&lt;A class=sbmDim onmouseover=mOvr(this) title="Post it to magnolia!" onmouseout=mOut(this) href="http://ma.gnolia.com/bookmarklet/add?url=http://blogs.technet.com/ecostrat/archive/2009/05/13/hack-in-the-box-and-beyond.aspx&amp;amp;title=Hack in the Box, and beyond..." target=_blank&gt;&lt;IMG border=0 src="http://blogs.msdn.com/blogfiles/rahulso/WindowsLiveWriter/IconsfordifferentSocialBookmarkingSites_B387/magnolia4.png"&gt;&lt;/A&gt; 
&lt;TD class=sbmDim onmouseover=mOvr(this) onmouseout=mOut(this) class="sbmDim"&gt;&lt;A class=sbmDim onmouseover=mOvr(this) title="Post it to netvouz!" onmouseout=mOut(this) href="http://netvouz.com/action/submitBookmark?url=http://blogs.technet.com/ecostrat/archive/2009/05/13/hack-in-the-box-and-beyond.aspx&amp;amp;title=Hack in the Box, and beyond..." target=_blank&gt;&lt;IMG border=0 src="http://blogs.msdn.com/blogfiles/rahulso/WindowsLiveWriter/IconsfordifferentSocialBookmarkingSites_B387/netvouz4.png"&gt;&lt;/A&gt; 
&lt;TD class=sbmDim onmouseover=mOvr(this) onmouseout=mOut(this) class="sbmDim"&gt;&lt;A class=sbmDim onmouseover=mOvr(this) title="Post it to reddit!" onmouseout=mOut(this) href="http://reddit.com/submit?url=http://blogs.technet.com/ecostrat/archive/2009/05/13/hack-in-the-box-and-beyond.aspx&amp;amp;title=Hack in the Box, and beyond..." target=_blank&gt;&lt;IMG border=0 src="http://blogs.msdn.com/blogfiles/rahulso/WindowsLiveWriter/IconsfordifferentSocialBookmarkingSites_B387/reddit4.png"&gt;&lt;/A&gt; 
&lt;TD class=sbmDim onmouseover=mOvr(this) onmouseout=mOut(this) class="sbmDim"&gt;&lt;A class=sbmDim onmouseover=mOvr(this) title="Post it to shadow" onmouseout=mOut(this) href="http://www.shadows.com/bookmark/saveLink.rails?page=http://blogs.technet.com/ecostrat/archive/2009/05/13/hack-in-the-box-and-beyond.aspx&amp;amp;title=Hack in the Box, and beyond..." target=_blank&gt;&lt;IMG border=0 src="http://blogs.msdn.com/blogfiles/rahulso/WindowsLiveWriter/IconsfordifferentSocialBookmarkingSites_B387/shadows6.png"&gt;&lt;/A&gt; 
&lt;TD class=sbmDim onmouseover=mOvr(this) onmouseout=mOut(this) class="sbmDim"&gt;&lt;A class=sbmDim onmouseover=mOvr(this) title="Post it to spurl" onmouseout=mOut(this) href="http://www.spurl.net/spurl.php?v=3&amp;amp;url=http://blogs.technet.com/ecostrat/archive/2009/05/13/hack-in-the-box-and-beyond.aspx&amp;amp;title=Hack in the Box, and beyond..." target=_blank&gt;&lt;IMG border=0 src="http://blogs.msdn.com/blogfiles/rahulso/WindowsLiveWriter/IconsfordifferentSocialBookmarkingSites_B387/spurl8.png"&gt;&lt;/A&gt; 
&lt;TD class=sbmDim onmouseover=mOvr(this) onmouseout=mOut(this) class="sbmDim"&gt;&lt;A class=sbmDim onmouseover=mOvr(this) title="Post it to technorati!" onmouseout=mOut(this) href="http://technorati.com/faves/?add=http://blogs.technet.com/ecostrat/archive/2009/05/13/hack-in-the-box-and-beyond.aspx&amp;amp;title=Hack in the Box, and beyond..." target=_blank&gt;&lt;IMG border=0 src="http://blogs.msdn.com/blogfiles/rahulso/WindowsLiveWriter/IconsfordifferentSocialBookmarkingSites_B387/technora4.png"&gt;&lt;/A&gt; 
&lt;TD class=sbmDim onmouseover=mOvr(this) onmouseout=mOut(this) class="sbmDim"&gt;&lt;A class=sbmDim onmouseover=mOvr(this) title="Post it to wists" onmouseout=mOut(this) href="http://www.wists.com/?action=add&amp;amp;url=http://blogs.technet.com/ecostrat/archive/2009/05/13/hack-in-the-box-and-beyond.aspx&amp;amp;title=Hack in the Box, and beyond..." target=_blank&gt;&lt;IMG border=0 src="http://blogs.msdn.com/blogfiles/rahulso/WindowsLiveWriter/IconsfordifferentSocialBookmarkingSites_B387/wists9.png"&gt;&lt;/A&gt; 
&lt;TD class=sbmDim onmouseover=mOvr(this) onmouseout=mOut(this) class="sbmDim"&gt;&lt;A class=sbmDim onmouseover=mOvr(this) title="Post it to yahoo!" onmouseout=mOut(this) href="http://myweb.yahoo.com/myresults/bookmarklet?u=http://blogs.technet.com/ecostrat/archive/2009/05/13/hack-in-the-box-and-beyond.aspx&amp;amp;t=Hack in the Box, and beyond..." target=_blank&gt;&lt;IMG border=0 src="http://blogs.msdn.com/blogfiles/rahulso/WindowsLiveWriter/IconsfordifferentSocialBookmarkingSites_B387/yahoo9.png"&gt;&lt;/A&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;*Postings are provided "AS IS" with no warranties, and confers no rights.*&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3240341" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/ecostrat/archive/tags/BlueHat/default.aspx">BlueHat</category><category domain="http://blogs.technet.com/ecostrat/archive/tags/Conferences/default.aspx">Conferences</category><category domain="http://blogs.technet.com/ecostrat/archive/tags/EcoStrat/default.aspx">EcoStrat</category><category domain="http://blogs.technet.com/ecostrat/archive/tags/MSRC/default.aspx">MSRC</category><category domain="http://blogs.technet.com/ecostrat/archive/tags/Security+Development+Lifecycle+_2800_SDL_2900_/default.aspx">Security Development Lifecycle (SDL)</category><category domain="http://blogs.technet.com/ecostrat/archive/tags/Security+Ecosystem/default.aspx">Security Ecosystem</category><category domain="http://blogs.technet.com/ecostrat/archive/tags/Watering+Hole/default.aspx">Watering Hole</category></item><item><title>CanSecWest: Caution, Community at Play</title><link>http://blogs.technet.com/ecostrat/archive/2009/03/18/cansecwest-caution-community-at-play.aspx</link><pubDate>Wed, 18 Mar 2009 12:20:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3214808</guid><dc:creator>msrcecostrat</dc:creator><slash:comments>5</slash:comments><comments>http://blogs.technet.com/ecostrat/comments/3214808.aspx</comments><wfw:commentRss>http://blogs.technet.com/ecostrat/commentrss.aspx?PostID=3214808</wfw:commentRss><description>&lt;P&gt;&lt;A href="http://cansecwest.com/" mce_href="http://cansecwest.com/"&gt;CanSecWest&lt;/A&gt;, in beautiful Vancouver BC, is one of my favorite conferences each year. It’s a cozy little security con that brings together security researchers from all parts of the security ecosystem.&amp;nbsp; Like a &lt;A href="http://ph-neutral.darklab.org/" mce_href="http://ph-neutral.darklab.org/"&gt;PhNeutral&lt;/A&gt; or a &lt;A href="http://technet.microsoft.com/en-us/security/cc261637.aspx" mce_href="http://technet.microsoft.com/en-us/security/cc261637.aspx"&gt;BlueHat&lt;/A&gt;, one never quite knows what to expect out of a CanSecWest, but we do know that Microsoft products and engineers will play a prominent role. We’ll be presenting new security innovations and new tools, we’ll be watching Pwn2Own closely for possible hacks, and we’ll be happy to discuss our industry best practices in the hallway track.&amp;nbsp; &lt;/P&gt;
&lt;P&gt;&lt;div class="author"&gt;
&lt;img src="http://blogs.technet.com/photos/msrcecostrat/images/3147552/original.aspx" /&gt; 
&lt;b&gt;&lt;br/&gt;Handle:&lt;/b&gt;&lt;br /&gt;Security Blanki&lt;br /&gt;&lt;br /&gt;
&lt;b&gt;IRL: &lt;/b&gt;&lt;br /&gt;Sarah Blankinship&lt;br /&gt;&lt;br /&gt;
&lt;b&gt;Rank: &lt;/b&gt;&lt;br /&gt;Senior Security Strategist Lead&lt;br /&gt;&lt;br /&gt;
&lt;b&gt;Likes: &lt;/b&gt;&lt;br /&gt;Vuln wrangling, teams of rivals, global climate change - the hotter the better&lt;br /&gt;&lt;br /&gt;
&lt;b&gt;Dislikes: &lt;/b&gt;&lt;br /&gt;Slack jawed gawkers (girls are geeks too!), customers @ risk, egos&lt;br /&gt;&lt;br/&gt;&lt;/div&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR&gt;Security gatherings such as this allow the ecosystem to exchange information and awareness in order to become more secure. The more we know about the attacks, the better prepared we can be on defense. Presentations like Matt Miller’s “The Evolution of Microsoft's Exploit Mitigations” and Jason Shirk and Dave Weinstein’s “Automated Real-time and Post Mortem Security Crash Analysis and Categorization” demonstrate that as Microsoft learns more about an attack, we incorporate this information into techniques and tools that we share with our developer community. Stay tuned for more news and posts throughout the show. &lt;/P&gt;
&lt;P&gt;&lt;BR&gt;Again this year, CanSecWest features the Pwn2Own contest – a contest that pits researchers against technologies to see whether technology or human wins. It’s also a contest that presents interesting challenges to Microsoft and a contest which you might think Microsoft opposes. Like many other issues in the security ecosystem – it’s not that simple. The contest exemplifies two basic tenets behind the TwC Security teams’ efforts. You can’t hide from the truth (&lt;I&gt;wishing doesn’t make it so&lt;/I&gt;) and every issue is an opportunity to learn and improve. &lt;/P&gt;
&lt;P&gt;We recognize that all vendors’ products may be found vulnerable and Microsoft welcomes the contest as another opportunity to engage the security community in productive dialogue around responsible disclosure and effective security engineering. We also see that Pwn2Own provides an opportunity to educate the public and we believe it can showcase Microsoft’s security engineering efforts, both relative to our competitors and in an absolute sense. 
&lt;P&gt;The security community is offering knowledge of attacks and defenses that consumers and other vendors can use to stay safe or create more secure products. The rest of the story – and an additional measure the security community could use to evaluate vendors’ products - is what happens after the content ends. Rest assured Microsoft will take this information and apply it towards securing our networks, platforms and applications (hopefully before they ship), and to create strong response process and engineering discipline that are necessary for our communal security. And as always, the MSRC are ready to work to investigate any vulnerabilities that researchers might find during the Pwn2Own contest. 
&lt;P&gt;By the end of the contest, co-sponsor Tipping Point will be the owners of many new vulnerabilities. They value the protection of their customers and will need to work with their partners in the security ecosystem to make sure everybody is protected as quickly as possible (one more way consumers benefit).&amp;nbsp; One of the goals of responsible disclosure is for the vulnerability details to emerge at the same time that an update is available from the vulnerable vendor. The CanSecWest conference organizer also has a responsible disclosure policy, as do all of the conference organizers that the EcoStrat team is able to support worldwide each year.&lt;/P&gt;
&lt;P&gt;&lt;BR&gt;Although innovative contests put some of us in a place that is not always comfortable, it’s valuable for the ecosystem to come together with contests like Pwn2Own and Iron Chef Black Hat, to better understand and solve common issues.&amp;nbsp;&amp;nbsp; It’s yet another example of the “team of rivals” strategy.&amp;nbsp; Let the contest begin!&lt;/P&gt;
&lt;P&gt;-Sarah&lt;/P&gt;
&lt;P&gt;&lt;SPAN class=sbmLink&gt;
&lt;TABLE class="" cellSpacing=1 cellPadding=1 unselectable="on"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD class=sbmText class="sbmText"&gt;Share this post : &lt;/TD&gt;
&lt;TD class=sbmDim onmouseover=mOvr(this) onmouseout=mOut(this) class="sbmDim"&gt;&lt;A class=sbmDim onmouseover=mOvr(this) title="Post it to backflip" onmouseout=mOut(this) href="http://www.backflip.com/add_page_pop.ihtml?url=http://blogs.technet.com/ecostrat/archive/2009/03/18/cansecwest-caution-community-at-play.aspx&amp;amp;title=CanSecWest: Caution, Community at Play" target=_blank&gt;&lt;IMG src="http://blogs.msdn.com/blogfiles/rahulso/WindowsLiveWriter/IconsfordifferentSocialBookmarkingSites_B387/backflip4.png" border=0&gt;&lt;/A&gt; 
&lt;TD class=sbmDim onmouseover=mOvr(this) onmouseout=mOut(this) class="sbmDim"&gt;&lt;A class=sbmDim onmouseover=mOvr(this) title="Post it to blinkbits!" onmouseout=mOut(this) href="http://www.blinkbits.com/bookmarklets/save.php?v=1&amp;amp;source_url=http://blogs.technet.com/ecostrat/archive/2009/03/18/cansecwest-caution-community-at-play.aspx&amp;amp;title=CanSecWest: Caution, Community at Play" target=_blank&gt;&lt;IMG src="http://blogs.msdn.com/blogfiles/rahulso/WindowsLiveWriter/IconsfordifferentSocialBookmarkingSites_B387/blinkbit4.png" border=0&gt;&lt;/A&gt; 
&lt;TD class=sbmDim onmouseover=mOvr(this) onmouseout=mOut(this) class="sbmDim"&gt;&lt;A class=sbmDim onmouseover=mOvr(this) title="Post it to blogmemes" onmouseout=mOut(this) href="http://www.blogmemes.net/post.php?url=http://blogs.technet.com/ecostrat/archive/2009/03/18/cansecwest-caution-community-at-play.aspx&amp;amp;title=CanSecWest: Caution, Community at Play" target=_blank&gt;&lt;IMG src="http://blogs.msdn.com/blogfiles/rahulso/WindowsLiveWriter/IconsfordifferentSocialBookmarkingSites_B387/blogmemes4.png" border=0&gt;&lt;/A&gt; 
&lt;TD class=sbmDim onmouseover=mOvr(this) onmouseout=mOut(this) class="sbmDim"&gt;&lt;A class=sbmDim onmouseover=mOvr(this) title="Post it to buddymark" onmouseout=mOut(this) href="http://buddymarks.com/s_add_bookmark.php?bookmark_url=http://blogs.technet.com/ecostrat/archive/2009/03/18/cansecwest-caution-community-at-play.aspx&amp;amp;bookmark_title=CanSecWest: Caution, Community at Play" target=_blank&gt;&lt;IMG src="http://blogs.msdn.com/blogfiles/rahulso/WindowsLiveWriter/IconsfordifferentSocialBookmarkingSites_B387/buddymar4.png" border=0&gt;&lt;/A&gt; 
&lt;TD class=sbmDim onmouseover=mOvr(this) onmouseout=mOut(this) class="sbmDim"&gt;&lt;A class=sbmDim onmouseover=mOvr(this) title="Post it to complore" onmouseout=mOut(this) href="http://complore.com/?q=node/add/flexinode-5&amp;amp;url=http://blogs.technet.com/ecostrat/archive/2009/03/18/cansecwest-caution-community-at-play.aspx&amp;amp;title=CanSecWest: Caution, Community at Play" target=_blank&gt;&lt;IMG src="http://blogs.msdn.com/blogfiles/rahulso/WindowsLiveWriter/IconsfordifferentSocialBookmarkingSites_B387/complore4.png" border=0&gt;&lt;/A&gt; 
&lt;TD class=sbmDim onmouseover=mOvr(this) onmouseout=mOut(this) class="sbmDim"&gt;&lt;A class=sbmDim onmouseover=mOvr(this) title="Post it to del.icio.us" onmouseout=mOut(this) href="http://del.icio.us/post?url=http://blogs.technet.com/ecostrat/archive/2009/03/18/cansecwest-caution-community-at-play.aspx&amp;amp;;title=CanSecWest: Caution, Community at Play" target=_blank&gt;&lt;IMG src="http://blogs.msdn.com/blogfiles/rahulso/WindowsLiveWriter/IconsfordifferentSocialBookmarkingSites_B387/deliciou4.png" border=0&gt;&lt;/A&gt; 
&lt;TD class=sbmDim onmouseover=mOvr(this) onmouseout=mOut(this) class="sbmDim"&gt;&lt;A class=sbmDim onmouseover=mOvr(this) title="Post it to del.iri.ous!" onmouseout=mOut(this) href="http://de.lirio.us/bookmarks/sbmtool?action=add&amp;amp;address=http://blogs.technet.com/ecostrat/archive/2009/03/18/cansecwest-caution-community-at-play.aspx&amp;amp;title=CanSecWest: Caution, Community at Play" target=_blank&gt;&lt;IMG src="http://blogs.msdn.com/blogfiles/rahulso/WindowsLiveWriter/IconsfordifferentSocialBookmarkingSites_B387/deliriou4.png" border=0&gt;&lt;/A&gt; 
&lt;TD class=sbmDim onmouseover=mOvr(this) onmouseout=mOut(this) class="sbmDim"&gt;&lt;A class=sbmDim onmouseover=mOvr(this) title="Post it to digg" onmouseout=mOut(this) href="http://digg.com/submit?phase=2&amp;amp;url=http://blogs.technet.com/ecostrat/archive/2009/03/18/cansecwest-caution-community-at-play.aspx&amp;amp;title=CanSecWest: Caution, Community at Play" target=_blank&gt;&lt;IMG src="http://blogs.msdn.com/blogfiles/rahulso/WindowsLiveWriter/IconsfordifferentSocialBookmarkingSites_B387/digg14.png" border=0&gt;&lt;/A&gt; 
&lt;TD class=sbmDim onmouseover=mOvr(this) onmouseout=mOut(this) class="sbmDim"&gt;&lt;A class=sbmDim onmouseover=mOvr(this) title="Post it to dotnetkicks" onmouseout=mOut(this) href="http://www.dotnetkicks.com/kick/?url=http://blogs.technet.com/ecostrat/archive/2009/03/18/cansecwest-caution-community-at-play.aspx&amp;amp;title=CanSecWest: Caution, Community at Play" target=_blank&gt;&lt;IMG src="http://blogs.msdn.com/blogfiles/rahulso/WindowsLiveWriter/IconsfordifferentSocialBookmarkingSites_B387/CropperCapture154.jpg" border=0&gt;&lt;/A&gt; 
&lt;TD class=sbmDim onmouseover=mOvr(this) onmouseout=mOut(this) class="sbmDim"&gt;&lt;A class=sbmDim onmouseover=mOvr(this) title="Post it to furl" onmouseout=mOut(this) href="http://www.furl.net/store?s=f&amp;amp;to=0&amp;amp;u=http://blogs.technet.com/ecostrat/archive/2009/03/18/cansecwest-caution-community-at-play.aspx&amp;amp;ti=CanSecWest: Caution, Community at Play" target=_blank&gt;&lt;IMG src="http://blogs.msdn.com/blogfiles/rahulso/WindowsLiveWriter/IconsfordifferentSocialBookmarkingSites_B387/furl4.png" border=0&gt;&lt;/A&gt; 
&lt;TD class=sbmDim onmouseover=mOvr(this) onmouseout=mOut(this) class="sbmDim"&gt;&lt;A class=sbmDim onmouseover=mOvr(this) title="Post it to live" onmouseout=mOut(this) href="https://favorites.live.com/quickadd.aspx?marklet=1&amp;amp;mkt=en-us&amp;amp;url=http://blogs.technet.com/ecostrat/archive/2009/03/18/cansecwest-caution-community-at-play.aspx&amp;amp;title=CanSecWest: Caution, Community at Play" target=_blank&gt;&lt;IMG src="http://blogs.msdn.com/blogfiles/rahulso/WindowsLiveWriter/IconsfordifferentSocialBookmarkingSites_B387/live4.png" border=0&gt;&lt;/A&gt; 
&lt;TD class=sbmDim onmouseover=mOvr(this) onmouseout=mOut(this) class="sbmDim"&gt;&lt;A class=sbmDim onmouseover=mOvr(this) title="Post it to magnolia!" onmouseout=mOut(this) href="http://ma.gnolia.com/bookmarklet/add?url=http://blogs.technet.com/ecostrat/archive/2009/03/18/cansecwest-caution-community-at-play.aspx&amp;amp;title=CanSecWest: Caution, Community at Play" target=_blank&gt;&lt;IMG src="http://blogs.msdn.com/blogfiles/rahulso/WindowsLiveWriter/IconsfordifferentSocialBookmarkingSites_B387/magnolia4.png" border=0&gt;&lt;/A&gt; 
&lt;TD class=sbmDim onmouseover=mOvr(this) onmouseout=mOut(this) class="sbmDim"&gt;&lt;A class=sbmDim onmouseover=mOvr(this) title="Post it to netvouz!" onmouseout=mOut(this) href="http://netvouz.com/action/submitBookmark?url=http://blogs.technet.com/ecostrat/archive/2009/03/18/cansecwest-caution-community-at-play.aspx&amp;amp;title=CanSecWest: Caution, Community at Play" target=_blank&gt;&lt;IMG src="http://blogs.msdn.com/blogfiles/rahulso/WindowsLiveWriter/IconsfordifferentSocialBookmarkingSites_B387/netvouz4.png" border=0&gt;&lt;/A&gt; 
&lt;TD class=sbmDim onmouseover=mOvr(this) onmouseout=mOut(this) class="sbmDim"&gt;&lt;A class=sbmDim onmouseover=mOvr(this) title="Post it to reddit!" onmouseout=mOut(this) href="http://reddit.com/submit?url=http://blogs.technet.com/ecostrat/archive/2009/03/18/cansecwest-caution-community-at-play.aspx&amp;amp;title=CanSecWest: Caution, Community at Play" target=_blank&gt;&lt;IMG src="http://blogs.msdn.com/blogfiles/rahulso/WindowsLiveWriter/IconsfordifferentSocialBookmarkingSites_B387/reddit4.png" border=0&gt;&lt;/A&gt; 
&lt;TD class=sbmDim onmouseover=mOvr(this) onmouseout=mOut(this) class="sbmDim"&gt;&lt;A class=sbmDim onmouseover=mOvr(this) title="Post it to shadow" onmouseout=mOut(this) href="http://www.shadows.com/bookmark/saveLink.rails?page=http://blogs.technet.com/ecostrat/archive/2009/03/18/cansecwest-caution-community-at-play.aspx&amp;amp;title=CanSecWest: Caution, Community at Play" target=_blank&gt;&lt;IMG src="http://blogs.msdn.com/blogfiles/rahulso/WindowsLiveWriter/IconsfordifferentSocialBookmarkingSites_B387/shadows6.png" border=0&gt;&lt;/A&gt; 
&lt;TD class=sbmDim onmouseover=mOvr(this) onmouseout=mOut(this) class="sbmDim"&gt;&lt;A class=sbmDim onmouseover=mOvr(this) title="Post it to spurl" onmouseout=mOut(this) href="http://www.spurl.net/spurl.php?v=3&amp;amp;url=http://blogs.technet.com/ecostrat/archive/2009/03/18/cansecwest-caution-community-at-play.aspx&amp;amp;title=CanSecWest: Caution, Community at Play" target=_blank&gt;&lt;IMG src="http://blogs.msdn.com/blogfiles/rahulso/WindowsLiveWriter/IconsfordifferentSocialBookmarkingSites_B387/spurl8.png" border=0&gt;&lt;/A&gt; 
&lt;TD class=sbmDim onmouseover=mOvr(this) onmouseout=mOut(this) class="sbmDim"&gt;&lt;A class=sbmDim onmouseover=mOvr(this) title="Post it to technorati!" onmouseout=mOut(this) href="http://technorati.com/faves/?add=http://blogs.technet.com/ecostrat/archive/2009/03/18/cansecwest-caution-community-at-play.aspx&amp;amp;title=CanSecWest: Caution, Community at Play" target=_blank&gt;&lt;IMG src="http://blogs.msdn.com/blogfiles/rahulso/WindowsLiveWriter/IconsfordifferentSocialBookmarkingSites_B387/technora4.png" border=0&gt;&lt;/A&gt; 
&lt;TD class=sbmDim onmouseover=mOvr(this) onmouseout=mOut(this) class="sbmDim"&gt;&lt;A class=sbmDim onmouseover=mOvr(this) title="Post it to wists" onmouseout=mOut(this) href="http://www.wists.com/?action=add&amp;amp;url=http://blogs.technet.com/ecostrat/archive/2009/03/18/cansecwest-caution-community-at-play.aspx&amp;amp;title=CanSecWest: Caution, Community at Play" target=_blank&gt;&lt;IMG src="http://blogs.msdn.com/blogfiles/rahulso/WindowsLiveWriter/IconsfordifferentSocialBookmarkingSites_B387/wists9.png" border=0&gt;&lt;/A&gt; 
&lt;TD class=sbmDim onmouseover=mOvr(this) onmouseout=mOut(this) class="sbmDim"&gt;&lt;A class=sbmDim onmouseover=mOvr(this) title="Post it to yahoo!" onmouseout=mOut(this) href="http://myweb.yahoo.com/myresults/bookmarklet?u=http://blogs.technet.com/ecostrat/archive/2009/03/18/cansecwest-caution-community-at-play.aspx&amp;amp;t=CanSecWest: Caution, Community at Play" target=_blank&gt;&lt;IMG src="http://blogs.msdn.com/blogfiles/rahulso/WindowsLiveWriter/IconsfordifferentSocialBookmarkingSites_B387/yahoo9.png" border=0&gt;&lt;/A&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;*Postings are provided "AS IS" with no warranties, and confers no rights.*&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3214808" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/ecostrat/archive/tags/BlueHat/default.aspx">BlueHat</category><category domain="http://blogs.technet.com/ecostrat/archive/tags/CanSecWest/default.aspx">CanSecWest</category><category domain="http://blogs.technet.com/ecostrat/archive/tags/Conferences/default.aspx">Conferences</category><category domain="http://blogs.technet.com/ecostrat/archive/tags/EcoStrat/default.aspx">EcoStrat</category><category domain="http://blogs.technet.com/ecostrat/archive/tags/MSRC/default.aspx">MSRC</category><category domain="http://blogs.technet.com/ecostrat/archive/tags/Security+Ecosystem/default.aspx">Security Ecosystem</category></item><item><title>Observations from the EcoStrat-isphere</title><link>http://blogs.technet.com/ecostrat/archive/2008/10/30/observations-from-the-ecostrat-isphere.aspx</link><pubDate>Thu, 30 Oct 2008 10:24:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3144822</guid><dc:creator>msrcecostrat</dc:creator><slash:comments>1</slash:comments><comments>http://blogs.technet.com/ecostrat/comments/3144822.aspx</comments><wfw:commentRss>http://blogs.technet.com/ecostrat/commentrss.aspx?PostID=3144822</wfw:commentRss><description>&lt;div class="author"&gt;
&lt;img src="http://blogs.technet.com/photos/msrcecostrat/images/3147552/original.aspx" /&gt; 
&lt;b&gt;&lt;br/&gt;Handle:&lt;/b&gt;&lt;br /&gt;Security Blanki&lt;br /&gt;&lt;br /&gt;
&lt;b&gt;IRL: &lt;/b&gt;&lt;br /&gt;Sarah Blankinship&lt;br /&gt;&lt;br /&gt;
&lt;b&gt;Rank: &lt;/b&gt;&lt;br /&gt;Senior Security Strategist Lead&lt;br /&gt;&lt;br /&gt;
&lt;b&gt;Likes: &lt;/b&gt;&lt;br /&gt;Vuln wrangling, teams of rivals, global climate change - the hotter the better&lt;br /&gt;&lt;br /&gt;
&lt;b&gt;Dislikes: &lt;/b&gt;&lt;br /&gt;Slack jawed gawkers (girls are geeks too!), customers @ risk, egos&lt;br /&gt;&lt;br/&gt;&lt;/div&gt; 
&lt;P&gt;As part of the quest to help "secure the planet", our team travels over this planet a lot, and I wanted to highlight a few of the interesting security gatherings I've been to lately. 
&lt;P&gt;September brought sunshine and the &lt;A href="http://infosecuritywomen.com/" mce_href="http://infosecuritywomen.com/"&gt;&lt;FONT color=#517380&gt;Executive Women’s Forum&lt;/FONT&gt;&lt;/A&gt; (EWF). An all-women’s security event was completely refreshing and a great contrast to the usual technology scene. In addition to the great technical content, it’s always a treat to discourse with others who see computer science as a social science, Mary Anne Davidson’s &lt;A href="http://blogs.oracle.com/maryanndavidson/2008/07/synthesis_1.html" mce_href="http://blogs.oracle.com/maryanndavidson/2008/07/synthesis_1.html"&gt;&lt;FONT color=#517380&gt;blog post about synthesis&lt;/FONT&gt;&lt;/A&gt; had some great insights: 
&lt;P&gt;&lt;I&gt;One of the things I have been doing some thinking and speaking about is the idea of synthesis. More specifically, the lessons we can learn in IT security from other disciplines, such as business, economics, history (especially military history and strategy) and biology.&lt;/I&gt; 
&lt;P&gt;Hey, those are social sciences (except for biology, although its neighbor epidemiology counts). She also mentions strategy which is a subject close to my heart. :-) 
&lt;P&gt;Additionally, I had a chance to break bread with former colleagues and friends from around the planet. I got to hear from women starting their own companies or in amazing roles at their organizations -- women whom I would want as mentors, colleagues and partners. It was also eye-opening in terms of the old school/new school debate among women decision makers, the parallels we see in the male-dominated environments, centered around the question of whether it's possible to solve security ecosystem problems through regulation. The security ecosystem is like the weather – you can’t predict or control it – but you want to be prepared for it. EWF presents an opportunity to continue educating and networking with this community about the risk environment and how to mitigate threats, concurrent to ongoing policy, privacy and regulation initiatives. 
&lt;P&gt;One of my personal goals is to (paraphrasing a line on a favorite greeting card) "build bridges and help people get over them." One of those goals was realized when, in October, the Microsoft Security Response Center (MSRC) and friends went down to the Southern hemisphere for some mmmm &lt;A href="http://ba-con.com.ar/" mce_href="http://ba-con.com.ar/"&gt;&lt;FONT color=#517380&gt;BA-Con&lt;/FONT&gt;&lt;/A&gt;. Even better than bacon, was the gathering of some mavericks, if you will, including Argentinean security superstars and underground up-and-comers. The conference was the culmination of years of conversations and grassroots community partnerships between traditional "rivals": &lt;A href="http://www.coresecurity.com/" mce_href="http://www.coresecurity.com/"&gt;&lt;FONT color=#517380&gt;Core Security&lt;/FONT&gt;&lt;/A&gt;, well-known in the attack tool community, in alignment with our team and other protection providers. 
&lt;P&gt;An interesting trend we’ve noted, alongside traditional security conferences, we are starting to see the development of "micro-communities" thriving around the world with different parts of the security ecosystem overlapping. Just as &lt;A href="http://www.blackhat.com/" mce_href="http://www.blackhat.com/"&gt;&lt;FONT color=#517380&gt;Black Hat&lt;/FONT&gt;&lt;/A&gt; has its &lt;A href="https://www.defcon.org/" mce_href="https://www.defcon.org/"&gt;&lt;FONT color=#517380&gt;Defcon&lt;/FONT&gt;&lt;/A&gt;, the security conferences worldwide are realizing the value of leveraging different and respected security communities. BA-Con has &lt;A href="http://www.ekoparty.com.ar/" mce_href="http://www.ekoparty.com.ar/"&gt;&lt;FONT color=#517380&gt;ekoparty Security Conference&lt;/FONT&gt;&lt;/A&gt; and &lt;A href="http://www.xcon.xfocus.org/" mce_href="http://www.xcon.xfocus.org/"&gt;&lt;FONT color=#517380&gt;Xcon&lt;/FONT&gt;&lt;/A&gt; has &lt;A href="http://www.xkungfoo.org/" mce_href="http://www.xkungfoo.org/"&gt;&lt;FONT color=#517380&gt;XKungfoo&lt;/FONT&gt;&lt;/A&gt;, both great examples of diverse communities collaborating. Mary Anne’s post talks about the risks of a lack of "biological diversity”. By contrast, the collaboration between these communities provides illustrations of diversity from a social science perspective: language, organizational affiliation, age. 
&lt;P&gt;Each year, we also have the pleasure of *&lt;B&gt;not&lt;/B&gt;* traveling, and welcome members of the security community here to the Microsoft Corporate Campus for &lt;A href="http://technet.microsoft.com/en-us/security/cc261637.aspx" mce_href="http://technet.microsoft.com/en-us/security/cc261637.aspx"&gt;&lt;FONT color=#517380&gt;BlueHat&lt;/FONT&gt;&lt;/A&gt;. Ask the BlueHat network of past speakers or catch some &lt;A href="http://blogs.technet.com/bluehat" mce_href="http://blogs.technet.com/bluehat"&gt;&lt;FONT color=#517380&gt;great blog posts recently&lt;/FONT&gt;&lt;/A&gt;, one of the most interesting watering holes in software security is @BlueHat. Thanks to all who have helped us grow from a friendly little hacker con to a platform to educate the broader security community with the BlueHat: SDL Sessions, to give back to the developer population by releasing developer tools, and for building more relationships toward community-based defense. 
&lt;P&gt;A lot of people are surprised that we don't make a bigger deal out of BlueHat by inviting the press in. Even though BlueHat is a great story, that's not primarily how we see it. It is a network, a voice for the community, a platform to launch people, research and ideas. The interactions are different, somehow more open and sincere when folks don’t have a press audience or "preconditions". The good stuff and paradigm shifts that come out of BlueHat in the form of new awareness, collaborations and security innovations, will pay off for years to come. We aren’t willing to risk the platform for a press story. 
&lt;P&gt;There is a lot of excitement that we are making the BlueHat: SDL Sessions &lt;B&gt;public&lt;/B&gt;! That's right; you don’t have to come to BlueHat to watch a great day of security content! Thanks for the feedback and stay tuned for BlueHat: SDL Sessions releasing on TechNet, we’re working on getting them up as soon as we can. And the rumors are true: TwC will release a tool to the public within the fiscal year. 
&lt;P&gt;As a part of the MSRC, a big part of our team life these days has been releasing &lt;A href="http://go.microsoft.com/fwlink/?LinkId=130719" mce_href="http://go.microsoft.com/fwlink/?LinkId=130719"&gt;&lt;FONT color=#517380&gt;MS08-067&lt;/FONT&gt;&lt;/A&gt;* out-of-band. With the update, we are all more secure. That means that a many of your security colleagues worked 24 by 7 to get this out to you as quickly as possible. 
&lt;P&gt;Throughout my travels, a common theme in these experiences are the opportunities for shared goals and cooperation from organizations and people usually seen on different sides: security researchers and software engineers, Macs and PCs, browser developers and browser hackers, vendors and competing vendors from the infrastructure to the cloud. BlueHat has demonstrated that well-chosen strategies, while easy to overlook, offer substantial benefits and positive outcomes. It is a great example of "reaching across the aisle" to create those multivendor solutions. 
&lt;P&gt;Next: around the world in 14 days. Really! 
&lt;P&gt;Sarah 
&lt;P&gt;Security EcoStrategist 
&lt;P&gt;* As with all security updates, MS08-067 is a free download with no check for Windows Genuine Advantage. For details and a link to the software for your operating system, click here to go to the &lt;A href="http://go.microsoft.com/fwlink/?LinkId=130719" mce_href="http://go.microsoft.com/fwlink/?LinkId=130719"&gt;&lt;FONT color=#517380&gt;Microsoft TechNet Security page&lt;/FONT&gt;&lt;/A&gt;. 
&lt;P&gt;*Postings are provided "AS IS" with no warranties, and confers no rights.*&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3144822" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/ecostrat/archive/tags/BlueHat/default.aspx">BlueHat</category><category domain="http://blogs.technet.com/ecostrat/archive/tags/EcoStrat/default.aspx">EcoStrat</category><category domain="http://blogs.technet.com/ecostrat/archive/tags/Security+Development+Lifecycle+_2800_SDL_2900_/default.aspx">Security Development Lifecycle (SDL)</category><category domain="http://blogs.technet.com/ecostrat/archive/tags/Security+Ecosystem/default.aspx">Security Ecosystem</category></item><item><title>BlueHat Special, Aisle 8…</title><link>http://blogs.technet.com/ecostrat/archive/2008/10/07/bluehat-special-aisle-8.aspx</link><pubDate>Tue, 07 Oct 2008 09:22:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3133538</guid><dc:creator>msrcecostrat</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/ecostrat/comments/3133538.aspx</comments><wfw:commentRss>http://blogs.technet.com/ecostrat/commentrss.aspx?PostID=3133538</wfw:commentRss><description>&lt;div class="author"&gt;
&lt;img src="http://blogs.technet.com/photos/msrcecostrat/images/3148860/original.aspx" /&gt; 
&lt;b&gt;Handle:&lt;/b&gt;&lt;br /&gt;C-Lizzle&lt;br /&gt;&lt;br /&gt;
&lt;b&gt;IRL: &lt;/b&gt;&lt;br /&gt;Celene Temkin&lt;br /&gt;&lt;br /&gt;
&lt;b&gt;Rank: &lt;/b&gt;&lt;br /&gt;BlueHat Project Manager&lt;br /&gt;&lt;br /&gt;
&lt;b&gt;Likes: &lt;/b&gt;&lt;br /&gt;Culinary warfare, BlueHat hackers and responsible disclosure&lt;br /&gt;&lt;br /&gt;
&lt;b&gt;Dislikes: &lt;/b&gt;&lt;br /&gt;Acts of hubris, MySpace, orange mocha Frappaccinos!&lt;br /&gt;&lt;br /&gt;
&lt;/div&gt; 
&lt;P&gt;Hopefully by now you’ve seen the lead in to BlueHat v8 &lt;A href="http://blogs.technet.com/ecostrat/archive/2008/08/21/the-valley-between-black-blue.aspx" mce_href="http://blogs.technet.com/ecostrat/archive/2008/08/21/the-valley-between-black-blue.aspx"&gt;blog&lt;/A&gt; post, the official &lt;A href="http://blogs.technet.com/bluehat/archive/2008/09/15/announcing-bluehat-v8.aspx" mce_href="http://blogs.technet.com/bluehat/archive/2008/09/15/announcing-bluehat-v8.aspx"&gt;announcement&lt;/A&gt; post, and perused the spiffy, revamped &lt;A href="http://technet.microsoft.com/en-us/security/cc261637.aspx" mce_href="http://technet.microsoft.com/en-us/security/cc261637.aspx"&gt;BlueHat&lt;/A&gt; page. I’m truly amazed to see how the content has shaped up as we approach the final countdown to &lt;A href="http://technet.microsoft.com/en-us/security/cc748656.aspx" mce_href="http://technet.microsoft.com/en-us/security/cc748656.aspx"&gt;BlueHat v8: C3P0wned&lt;/A&gt; on October 16-17. It’s thrilling to see what was once a little hacker con turn into a platform to educate developers and execs with an end-to-end story. Day one of BlueHat will focus on security issues facing the ecosystem while Day two leverages the &lt;A href="http://msdn.microsoft.com/en-us/security/cc448177.aspx" mce_href="http://msdn.microsoft.com/en-us/security/cc448177.aspx"&gt;Security Development Lifecycle&lt;/A&gt; (SDL) to discuss the full cycle of proactive security and "baking security in," so to speak.&lt;/P&gt;
&lt;P&gt;BlueHat is first and foremost about educating all the Microsoft "cooks in the kitchen" so we can better understand the security space and ship more secure products. This time, Microsoft will share some of that education with the world. The BlueHat team will post publicly, for the first time ever, a day of BlueHat content. You can also count on speaker video interview podcasts, anecdotes and archives to be on the site as well.&lt;/P&gt;
&lt;P&gt;This is the fifth BlueHat I’ve had the pleasure of being a part of. I can’t help but get nostalgic, as I’ve seen the con continue to grow and pick up momentum. Microsoft and the ecosystem continue to endure some pretty significant threats, such as the recent DNS issue, ActiveX issues, etc. In addition, issues including blended threats and other vulnerabilities that affect multiple vendors demonstrate that complex threats are increasing. Understanding these trends give us a strategic call to action. We can leverage BlueHat to bring vendors, researchers, ISV’s, CERT’s (and others) together to understand complex issues and to create recipes for collaboration. It’s not just Microsoft working with other vendors on issues, but Microsoft working with the overall security community to meet these challenges. &lt;/P&gt;
&lt;P&gt;Even other companies are taking the time to create BlueHat-like conferences and events at their own facilities to help their own employees sharpen their security skills. The good folks at eBay host Red Team eBay where their security team members can meet and exchange ideas with industry experts. It’s beyond encouraging to witness other companies leading with their best foot forward in creating a melting pot of security information exchange.&lt;/P&gt;
&lt;P&gt;I can’t wait for BlueHat v8 and I encourage you all to follow the virtual trail on the &lt;A href="http://blogs.technet.com/bluehat/" mce_href="http://blogs.technet.com/bluehat/"&gt;BlueHat Blog&lt;/A&gt; and &lt;A href="http://blogs.msdn.com/sdl/" mce_href="http://blogs.msdn.com/sdl/"&gt;SDL Blog&lt;/A&gt; leading up to and during the event.&lt;/P&gt;
&lt;P&gt;-Celene Temkin&lt;/P&gt;
&lt;P&gt;*Postings are provided "AS IS" with no warranties, and confers no rights.*&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3133538" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/ecostrat/archive/tags/BlueHat/default.aspx">BlueHat</category><category domain="http://blogs.technet.com/ecostrat/archive/tags/Security+Development+Lifecycle+_2800_SDL_2900_/default.aspx">Security Development Lifecycle (SDL)</category></item><item><title>The Valley Between Black &amp; Blue</title><link>http://blogs.technet.com/ecostrat/archive/2008/08/21/the-valley-between-black-blue.aspx</link><pubDate>Thu, 21 Aug 2008 17:05:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3109817</guid><dc:creator>msrcecostrat</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/ecostrat/comments/3109817.aspx</comments><wfw:commentRss>http://blogs.technet.com/ecostrat/commentrss.aspx?PostID=3109817</wfw:commentRss><description>&lt;P&gt;&lt;div class="author"&gt;
&lt;img src="http://blogs.technet.com/photos/msrcecostrat/images/3148860/original.aspx" /&gt; 
&lt;b&gt;Handle:&lt;/b&gt;&lt;br /&gt;C-Lizzle&lt;br /&gt;&lt;br /&gt;
&lt;b&gt;IRL: &lt;/b&gt;&lt;br /&gt;Celene Temkin&lt;br /&gt;&lt;br /&gt;
&lt;b&gt;Rank: &lt;/b&gt;&lt;br /&gt;BlueHat Project Manager&lt;br /&gt;&lt;br /&gt;
&lt;b&gt;Likes: &lt;/b&gt;&lt;br /&gt;Culinary warfare, BlueHat hackers and responsible disclosure&lt;br /&gt;&lt;br /&gt;
&lt;b&gt;Dislikes: &lt;/b&gt;&lt;br /&gt;Acts of hubris, MySpace, orange mocha Frappaccinos!&lt;br /&gt;&lt;br /&gt;
&lt;/div&gt; &lt;/P&gt;
&lt;P&gt;I affectionately call this time between summer conferences, the black and blue phase, where I wear security like a Hypercolor t-shirt, changing colors depending on where we are in our conference shipping and planning cycles.&amp;nbsp; We just &lt;I&gt;shipped&lt;/I&gt; a successful &lt;A href="http://blogs.technet.com/bluehat/default.aspx" mce_href="http://blogs.technet.com/bluehat/default.aspx"&gt;&lt;FONT color=#517380&gt;Black Hat&lt;/FONT&gt;&lt;/A&gt; and we are within T-minus 60 days until &lt;A href="http://technet.microsoft.com/en-us/security/cc748656.aspx" mce_href="http://technet.microsoft.com/en-us/security/cc748656.aspx"&gt;&lt;FONT color=#517380&gt;BlueHat v8&lt;/FONT&gt;&lt;/A&gt;. &lt;/P&gt;
&lt;P&gt;Although the BlueHat v8 schedule has yet to be formally announced, there has been &lt;A href="http://www.darkreading.com/document.asp?doc_id=161633" mce_href="http://www.darkreading.com/document.asp?doc_id=161633"&gt;&lt;FONT color=#517380&gt;some early buzz&lt;/FONT&gt;&lt;/A&gt; around the speaker line up and I can assure you the two days of cutting-edge content will not disappoint. Please keep an eye out for speaker line-ups, abstracts, and bios, which will be posted on the &lt;A href="http://technet.microsoft.com/en-us/security/cc261637.aspx" mce_href="http://technet.microsoft.com/en-us/security/cc261637.aspx"&gt;&lt;FONT color=#517380&gt;BlueHat TechNet Security Briefing Page&lt;/FONT&gt;&lt;/A&gt; in the next couple of weeks. As always, keep up with the rolling thunder of the &lt;A href="http://blogs.technet.com/bluehat" mce_href="http://blogs.technet.com/bluehat"&gt;&lt;FONT color=#517380&gt;BlueHat Blog&lt;/FONT&gt;&lt;/A&gt;, which highlights internal and external BlueHat speakers from past, present, and (hint, hint) future. 
&lt;P&gt;But let’s back up for a second, what is BlueHat and what are the goals of this conference in the&amp;nbsp;ever-evolving security industry?&amp;nbsp; 
&lt;P&gt;First, we believe in educating our own because only when we truly comprehend our security reality, can we begin to defend ourselves and anticipate mitigations for the looming threats on the horizon. We educate our own by making BlueHat an invitation-only conference where our Microsoft developers, security engineers and product teams can receive security training credits for attending. Since security is not a spectator sport, we also encourage Microsoft employees to present alongside the external researchers recruited to present. We try and stay as transparent as possible with all our speakers, so none of the talks are under NDA. 
&lt;P&gt;Second, we use BlueHat as a vehicle for our partner and product teams to outreach to the security community. At every con out there, everyone knows that the “hallway track” is often the most fruitful and interesting. We seed our hallway track at BlueHat deliberately to maximize everyone’s experience. Countless introductions and targeted outreach occurs on the sidelines while the talks are going on. Researchers meet developers, speakers meet architects, CERTs meet security strategists—you name it, everyone’s engaging and the best part is it can take new relationships to a completely organic state far beyond our wildest expectations. Only at a venue like BlueHat could we pair two independent security researchers to do research on Silverlight in conjunction with the Silverlight &amp;amp; Adobe teams, and then have them present the results. Their presentation went so well that Manuel Caballero and Fukami won the “International Tag-Team Patches Award” at the BlueHat v7 Community Dinner, highlighting this alliance. 
&lt;P&gt;Third, BlueHat promotes Microsoft’s responsible disclosure policy, with the goal of coordinated release of an update and public disclosure of the vulnerability details. We also promote responsible disclosure with all of the conferences our team sponsors worldwide and ask conference organizers to promote vendor notification and the coordinated release of updates and vulnerability information. 
&lt;P&gt;The BlueHat Planning Team strategically invites security product vendors, security researchers, security officers, members of security response teams and past BlueHat speakers to engage while propelling MSRC values in real-time with a human face. 
&lt;P&gt;An almost overwhelming pupu platter of submissions sits before us; limitless in possibilities and all the better to educate our developers and execs with. Along with the great privilege of reviewing these submissions with the fellow members of the BlueHat Planning Team, comes the bittersweet burden of nailing down the final talks to exceed our audience’s expectations. The cool part is we get to immediately start working on the next BlueHat as it’s the best way to stay current on the latest trends around security and privacy. 
&lt;P&gt;- Celene Temkin, BlueHat Project Manager 
&lt;P&gt;*Postings are provided "AS IS" with no warranties, and confers no rights.*&lt;/P&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3109817" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/ecostrat/archive/tags/Black+Hat/default.aspx">Black Hat</category><category domain="http://blogs.technet.com/ecostrat/archive/tags/BlueHat/default.aspx">BlueHat</category><category domain="http://blogs.technet.com/ecostrat/archive/tags/Community-Based+Defense/default.aspx">Community-Based Defense</category><category domain="http://blogs.technet.com/ecostrat/archive/tags/Conferences/default.aspx">Conferences</category><category domain="http://blogs.technet.com/ecostrat/archive/tags/Security+Ecosystem/default.aspx">Security Ecosystem</category></item></channel></rss>