<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Security e Virtualization Blog di Feliciano Intini (e il suo team PCfSV2) : 0.1.1.1 End to End Trust</title><link>http://blogs.technet.com/feliciano_intini/archive/tags/0.1.1.1+End+to+End+Trust/default.aspx</link><description>Tags: 0.1.1.1 End to End Trust</description><dc:language>en-US</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>Attenti ai rischi del file sharing tramite reti peer-to-peer: esempio di WinRAR 3.8 farcito di malware</title><link>http://blogs.technet.com/feliciano_intini/archive/2008/10/07/attenti-ai-rischi-del-file-sharing-tramite-reti-peer-to-peer-esempio-di-winrar-3-8-farcito-di-malware.aspx</link><pubDate>Tue, 07 Oct 2008 12:07:29 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3133349</guid><dc:creator>Feliciano Intini</dc:creator><slash:comments>5</slash:comments><comments>http://blogs.technet.com/feliciano_intini/comments/3133349.aspx</comments><wfw:commentRss>http://blogs.technet.com/feliciano_intini/commentrss.aspx?PostID=3133349</wfw:commentRss><description>Sto seguendo con interesse, come molti credo, la vicenda che coinvolge The Pirate Bay : cominciano a delinearsi le dinamiche complesse di interazione tra temi sociali, economici e tecnologici di cui detto a proposito della discussione End to End Trust...(&lt;a href="http://blogs.technet.com/feliciano_intini/archive/2008/10/07/attenti-ai-rischi-del-file-sharing-tramite-reti-peer-to-peer-esempio-di-winrar-3-8-farcito-di-malware.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3133349" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/Malware+and+Attack+analysis/default.aspx">Malware and Attack analysis</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/0.1.1.1+End+to+End+Trust/default.aspx">0.1.1.1 End to End Trust</category></item><item><title>Microsoft Enterprise Circle: Video interviste sulla sicurezza</title><link>http://blogs.technet.com/feliciano_intini/archive/2008/09/22/microsoft-enterprise-circle-video-interviste-sulla-sicurezza.aspx</link><pubDate>Mon, 22 Sep 2008 19:32:14 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3126862</guid><dc:creator>Feliciano Intini</dc:creator><slash:comments>1</slash:comments><comments>http://blogs.technet.com/feliciano_intini/comments/3126862.aspx</comments><wfw:commentRss>http://blogs.technet.com/feliciano_intini/commentrss.aspx?PostID=3126862</wfw:commentRss><description>La pagina &amp;quot; Enterprise Circle &amp;quot; di Microsoft Italia &amp;#232; un portale di accesso ad una serie di risorse pensate per l'IT management di aziende grandi e medio/grandi. L'edizione di settembre presenta una sezione speciale dedicata alla sicurezza...(&lt;a href="http://blogs.technet.com/feliciano_intini/archive/2008/09/22/microsoft-enterprise-circle-video-interviste-sulla-sicurezza.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3126862" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/0.1.1.1+End+to+End+Trust/default.aspx">0.1.1.1 End to End Trust</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/Anti-Malware/default.aspx">Anti-Malware</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/z-Video/default.aspx">z-Video</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/Anti-Spam/default.aspx">Anti-Spam</category></item><item><title>In futuro prevarrà la Positive Security?</title><link>http://blogs.technet.com/feliciano_intini/archive/2008/09/22/in-futuro-prevarr-la-positive-security.aspx</link><pubDate>Mon, 22 Sep 2008 13:27:50 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3126745</guid><dc:creator>Feliciano Intini</dc:creator><slash:comments>3</slash:comments><comments>http://blogs.technet.com/feliciano_intini/comments/3126745.aspx</comments><wfw:commentRss>http://blogs.technet.com/feliciano_intini/commentrss.aspx?PostID=3126745</wfw:commentRss><description>Alzi la mano chi di voi sa dire al volo cosa sia la &amp;quot; Positive Security &amp;quot;. Io confesso di averlo appreso da pochissimo: anche se il suo significato &amp;#232; abbastanza intuibile, questo termine non sembra ancora molto diffuso (wikipedia non ha...(&lt;a href="http://blogs.technet.com/feliciano_intini/archive/2008/09/22/in-futuro-prevarr-la-positive-security.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3126745" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/Windows+Vista+Security/default.aspx">Windows Vista Security</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/Security+Management/default.aspx">Security Management</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/Forefront+Client+Security/default.aspx">Forefront Client Security</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/Windows+Server+2008+Security/default.aspx">Windows Server 2008 Security</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/Windows+XP+Security/default.aspx">Windows XP Security</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/0.1.1.1+End+to+End+Trust/default.aspx">0.1.1.1 End to End Trust</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/Positive+Security/default.aspx">Positive Security</category></item><item><title>Black Hat 2008: Microsoft Security Vulnerability Research (MSVR)</title><link>http://blogs.technet.com/feliciano_intini/archive/2008/09/08/black-hat-2008-microsoft-security-vulnerability-research-msvr.aspx</link><pubDate>Mon, 08 Sep 2008 17:23:29 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3120991</guid><dc:creator>Feliciano Intini</dc:creator><slash:comments>2</slash:comments><comments>http://blogs.technet.com/feliciano_intini/comments/3120991.aspx</comments><wfw:commentRss>http://blogs.technet.com/feliciano_intini/commentrss.aspx?PostID=3120991</wfw:commentRss><description>Riprendendo il filo da dove l'avevo interrotto (scappando in ferie ;-) mi restava da condividere l'ultimo annuncio fatto da Microsoft in occasione del Black Hat 2008 , che, tra l'altro, non mi sembra sia stato ripreso da altre fonti informative: Microsoft...(&lt;a href="http://blogs.technet.com/feliciano_intini/archive/2008/09/08/black-hat-2008-microsoft-security-vulnerability-research-msvr.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3120991" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/4.0+Application+Security/default.aspx">4.0 Application Security</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/Security+Update+Management/default.aspx">Security Update Management</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/0.0.0.0+Microsoft+Strategy+and+Initiatives/default.aspx">0.0.0.0 Microsoft Strategy and Initiatives</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/Security+Development+Lifecycle+_2800_SDL_2900_/default.aspx">Security Development Lifecycle (SDL)</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/0.1.0.0+Security+and+Privacy/default.aspx">0.1.0.0 Security and Privacy</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/0.1.1.1+End+to+End+Trust/default.aspx">0.1.1.1 End to End Trust</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/Responsible_2F00_full+disclosure/default.aspx">Responsible/full disclosure</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/0.1.1.0+Trustworthy+Computing+_2800_TwC_2900_+/default.aspx">0.1.1.0 Trustworthy Computing (TwC) </category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/Security+Ecosystem/default.aspx">Security Ecosystem</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/Vulnerability+Handling/default.aspx">Vulnerability Handling</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/Black+Hat/default.aspx">Black Hat</category></item><item><title>Black Hat 2008: Microsoft Active Protections Program (MAPP)</title><link>http://blogs.technet.com/feliciano_intini/archive/2008/08/06/black-hat-2008-microsoft-active-protections-program-mapp.aspx</link><pubDate>Wed, 06 Aug 2008 19:06:53 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3100764</guid><dc:creator>Feliciano Intini</dc:creator><slash:comments>7</slash:comments><comments>http://blogs.technet.com/feliciano_intini/comments/3100764.aspx</comments><wfw:commentRss>http://blogs.technet.com/feliciano_intini/commentrss.aspx?PostID=3100764</wfw:commentRss><description>Come per l'annuncio del Microsoft Exploitability Index nel post precedente , anche per quest'annuncio pu&amp;#242; essere utile darvi un po' di indicazioni storiche e di contesto. Forse, infatti, non tutti sanno che fino ad ora l'approccio di Microsoft nel...(&lt;a href="http://blogs.technet.com/feliciano_intini/archive/2008/08/06/black-hat-2008-microsoft-active-protections-program-mapp.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3100764" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/8.0+Security+Foundations+_2800_Processes_2900_/default.aspx">8.0 Security Foundations (Processes)</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/Security+Update+Management/default.aspx">Security Update Management</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/0.0.0.0+Microsoft+Strategy+and+Initiatives/default.aspx">0.0.0.0 Microsoft Strategy and Initiatives</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/0.1.0.0+Security+and+Privacy/default.aspx">0.1.0.0 Security and Privacy</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/0.1.1.1+End+to+End+Trust/default.aspx">0.1.1.1 End to End Trust</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/0.1.1.0+Trustworthy+Computing+_2800_TwC_2900_+/default.aspx">0.1.1.0 Trustworthy Computing (TwC) </category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/Security+Ecosystem/default.aspx">Security Ecosystem</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/Vulnerability+Handling/default.aspx">Vulnerability Handling</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/Black+Hat/default.aspx">Black Hat</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/Microsoft+Active+Protections+Program+_2800_MAPP_2900_/default.aspx">Microsoft Active Protections Program (MAPP)</category></item><item><title>Black Hat 2008: si parte con il nuovo blog del team MSRC Ecosystem Strategy!</title><link>http://blogs.technet.com/feliciano_intini/archive/2008/08/05/black-hat-2008-si-parte-con-il-nuovo-blog-del-team-msrc-ecosystem-strategy.aspx</link><pubDate>Tue, 05 Aug 2008 13:00:07 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3098771</guid><dc:creator>Feliciano Intini</dc:creator><slash:comments>12</slash:comments><comments>http://blogs.technet.com/feliciano_intini/comments/3098771.aspx</comments><wfw:commentRss>http://blogs.technet.com/feliciano_intini/commentrss.aspx?PostID=3098771</wfw:commentRss><description>Ho appena lanciato su MClips la chiave di lettura dell'importante partecipazione di Microsoft all'evento di sicurezza pi&amp;#249; atteso dell'anno, il Black Hat ! Black Hat 2008: &amp;#232; tempo di Community-Based Defense! Come ho indicato, sar&amp;#224; una settimana...(&lt;a href="http://blogs.technet.com/feliciano_intini/archive/2008/08/05/black-hat-2008-si-parte-con-il-nuovo-blog-del-team-msrc-ecosystem-strategy.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3098771" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/0.0.0.0+Microsoft+Strategy+and+Initiatives/default.aspx">0.0.0.0 Microsoft Strategy and Initiatives</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/z-Eventi/default.aspx">z-Eventi</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/0.1.0.0+Security+and+Privacy/default.aspx">0.1.0.0 Security and Privacy</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/z-MClips/default.aspx">z-MClips</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/0.1.1.1+End+to+End+Trust/default.aspx">0.1.1.1 End to End Trust</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/0.1.1.0+Trustworthy+Computing+_2800_TwC_2900_+/default.aspx">0.1.1.0 Trustworthy Computing (TwC) </category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/Security+Ecosystem/default.aspx">Security Ecosystem</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/Vulnerability+Handling/default.aspx">Vulnerability Handling</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/Black+Hat/default.aspx">Black Hat</category></item><item><title>Parlerò di "End to End Trust" all'ISSA Security Conference 2008</title><link>http://blogs.technet.com/feliciano_intini/archive/2008/06/09/parler-di-end-to-end-trust-all-issa-security-conference-2008.aspx</link><pubDate>Mon, 09 Jun 2008 15:37:03 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3068165</guid><dc:creator>Feliciano Intini</dc:creator><slash:comments>2</slash:comments><comments>http://blogs.technet.com/feliciano_intini/comments/3068165.aspx</comments><wfw:commentRss>http://blogs.technet.com/feliciano_intini/commentrss.aspx?PostID=3068165</wfw:commentRss><description>&amp;#160; Forse &amp;#232; meglio dire che accenner&amp;#242; all' argomento , vista la breve durata del mio intervento dal titolo &amp;quot; Establishing End to End Trust &amp;quot;, ma d'altra parte era giusto e inevitabile, considerando la ricca e interessante agenda...(&lt;a href="http://blogs.technet.com/feliciano_intini/archive/2008/06/09/parler-di-end-to-end-trust-all-issa-security-conference-2008.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3068165" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/0.0.0.0+Microsoft+Strategy+and+Initiatives/default.aspx">0.0.0.0 Microsoft Strategy and Initiatives</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/z-Eventi/default.aspx">z-Eventi</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/0.1.0.0+Security+and+Privacy/default.aspx">0.1.0.0 Security and Privacy</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/0.1.1.1+End+to+End+Trust/default.aspx">0.1.1.1 End to End Trust</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/Digital+Forensic+Analysis/default.aspx">Digital Forensic Analysis</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/Security+Certifications/default.aspx">Security Certifications</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/0.1.1.0+Trustworthy+Computing+_2800_TwC_2900_+/default.aspx">0.1.1.0 Trustworthy Computing (TwC) </category></item><item><title>Annunciato il Microsoft Security Cooperation Program for CERTs (SCPCert)</title><link>http://blogs.technet.com/feliciano_intini/archive/2008/05/21/annunciato-il-microsoft-security-cooperation-program-for-certs-scpcert.aspx</link><pubDate>Wed, 21 May 2008 13:04:22 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3058484</guid><dc:creator>Feliciano Intini</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/feliciano_intini/comments/3058484.aspx</comments><wfw:commentRss>http://blogs.technet.com/feliciano_intini/commentrss.aspx?PostID=3058484</wfw:commentRss><description>&lt;p&gt;&lt;font face="Calibri" size="3"&gt;La conferenza &lt;a href="http://conference.auscert.org.au/conf2008" target="_blank"&gt;AusCERT2008&lt;/a&gt; (&lt;em&gt;Asia Pacific Information Technology Security Conference&lt;/em&gt;) organizzata dall'&lt;a href="http://www.auscert.org.au/" target="_blank"&gt;&lt;strong&gt;AusCERT&lt;/strong&gt;&lt;/a&gt; (il CERT australiano, uno dei pi&amp;#249; attivi e rinomati a livello internazionale) &amp;#232; stata l'occasione ideale per &lt;a href="http://www.microsoft.com/Presspass/press/2008/may08/05-20SCPCERTPR.mspx" target="_blank"&gt;annunciare&lt;/a&gt; la nascita di un nuovo programma di collaborazione tra Microsoft e il settore pubblico espressamente dedicata ai CERT (ossia ai Computer Emergency Response Team, gli enti dedicati alla gestione delle emergenze di sicurezza informatica): il &lt;strong&gt;&lt;a href="http://www.microsoft.com/Presspass/press/2008/may08/05-20SCPCERTPR.mspx" target="_blank"&gt;Microsoft Security Cooperation Program for CERTs (SCPCert)&lt;/a&gt;&lt;/strong&gt;&amp;#160;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font face="Calibri" size="3"&gt;L'&lt;strong&gt;SCPCert&lt;/strong&gt; si affianca ad altri due programmi analoghi &lt;/font&gt;&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;&lt;font face="Calibri" size="3"&gt;l'&lt;strong&gt;SCPe, &lt;/strong&gt;il &lt;strong&gt;Security Cooperation Program for Education&lt;/strong&gt;, (nato nel 2006) dedicato agli enti universitari&lt;/font&gt;&lt;/li&gt;    &lt;li&gt;&lt;font face="Calibri" size="3"&gt;l'&lt;strong&gt;SCPg&lt;/strong&gt;, il &lt;strong&gt;Security Cooperation Program for Governments&lt;/strong&gt;, il padre del programma SCP (nato nel febbraio del 2005) dedicato agli enti e alle agenzie governative&lt;/font&gt;&lt;/li&gt; &lt;/ul&gt;  &lt;p&gt;&lt;font face="Calibri" size="3"&gt;Lo scopo di queste iniziative &amp;#232; semplice: creare una partnership gratuita per lo scambio di informazioni e di collaborazione sui temi della risposta alle emergenze di sicurezza informatica, della mitigazione di attacchi e della &lt;em&gt;security awareness&lt;/em&gt; dei cittadini. L'insieme dei &lt;a href="http://www.microsoft.com/industry/publicsector/government/programs/SCP.mspx" target="_blank"&gt;programmi &lt;strong&gt;SCP&lt;/strong&gt;&lt;/a&gt; &amp;#232; a sua volta parte del pi&amp;#249; ampio impegno di Microsoft alla collaborazione trasversale con gli attori pi&amp;#249; importanti nella gestione della risposta alle emergenze di sicurezza, la &lt;a href="http://www.microsoft.com/security/msra/default.mspx" target="_blank"&gt;&lt;strong&gt;Microsoft Security Response Alliance (MSRA)&lt;/strong&gt;&lt;/a&gt;, che include, oltre all'SCP:&lt;/font&gt;&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;&lt;font face="Calibri" size="3"&gt;la &lt;strong&gt;Global Infrastructure Alliance for Internet Safety (GIAIS)&lt;/strong&gt;, che riunisce i pi&amp;#249; importanti Internet Service Provider &lt;/font&gt;&lt;/li&gt;    &lt;li&gt;&lt;font face="Calibri" size="3"&gt;la &lt;strong&gt;Microsoft Virus Initiative (MVI)&lt;/strong&gt; e la &lt;strong&gt;Virus Information Alliance (VIA)&lt;/strong&gt;, con i produttori e i ricercatori anti-malware&lt;/font&gt;&lt;/li&gt;    &lt;li&gt;&lt;font face="Calibri" size="3"&gt;la &lt;b&gt;Microsoft Security Support Alliance (MSSA)&lt;/b&gt;, con i produttori OEM.&lt;/font&gt;&lt;/li&gt; &lt;/ul&gt;  &lt;p&gt;&lt;font face="Calibri" size="3"&gt;Tutti gli investimenti riposti in queste iniziative confermano un punto importante della strategia di sicurezza di Microsoft: si riconosce, come ribadito dalla recente iniziativa dell'&lt;a href="http://blogs.technet.com/feliciano_intini/archive/2008/04/14/l-evoluzione-del-trustworthy-computing-end-to-end-trust-e2e.aspx" target="_blank"&gt;&lt;strong&gt;End To End Trust&lt;/strong&gt;&lt;/a&gt;, di non poter indirizzare da soli in modo efficace tutte le diverse problematiche che concorrono alla sicurezza di Internet, e che &amp;#232; necessario un efficiente lavoro di squadra. Queste alleanze sono intanto importanti per la realizzazione di un canale di comunicazione che finora era assente, e tutti sappiamo quanto sia importante l'aspetto di una rapida comunicazione rispetto alle emergenze di sicurezza.&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font face="Calibri" size="3"&gt;Se qualcuno tra voi &amp;#232; parte di uno di questi enti e desidera saperne di pi&amp;#249; pu&amp;#242; contattarmi tramite il blog per ulteriori dettagli.&lt;/font&gt;&lt;/p&gt; &lt;span class="sbmLink"&gt;   &lt;table cellspacing="1" cellpadding="1"&gt;&lt;tbody&gt;       &lt;tr&gt;         &lt;td class="sbmText"&gt;Share this post : &lt;/td&gt;          &lt;td class="sbmDim" onmouseover="mOvr(this)" onmouseout="mOut(this)"&gt;&lt;a class="sbmDim" onmouseover="mOvr(this)" title="Post it to del.icio.us" onmouseout="mOut(this)" href="http://del.icio.us/post?url=http://blogs.technet.com/feliciano_intini/archive/2008/05/21/annunciato-il-microsoft-security-cooperation-program-for-certs-scpcert.aspx&amp;amp;;title=Annunciato il Microsoft Security Cooperation Program for CERTs (SCPCert)" target="_blank"&gt;&lt;img src="http://blogs.msdn.com/blogfiles/rahulso/WindowsLiveWriter/IconsfordifferentSocialBookmarkingSites_B387/deliciou4.png" border="0" /&gt;&lt;/a&gt;&lt;/td&gt;          &lt;td class="sbmDim" onmouseover="mOvr(this)" onmouseout="mOut(this)"&gt;&lt;a class="sbmDim" onmouseover="mOvr(this)" title="Post it to digg" onmouseout="mOut(this)" href="http://digg.com/submit?phase=2&amp;amp;url=http://blogs.technet.com/feliciano_intini/archive/2008/05/21/annunciato-il-microsoft-security-cooperation-program-for-certs-scpcert.aspx&amp;amp;title=Annunciato il Microsoft Security Cooperation Program for CERTs (SCPCert)" target="_blank"&gt;&lt;img src="http://blogs.msdn.com/blogfiles/rahulso/WindowsLiveWriter/IconsfordifferentSocialBookmarkingSites_B387/digg14.png" border="0" /&gt;&lt;/a&gt;&lt;/td&gt;          &lt;td class="sbmDim" onmouseover="mOvr(this)" onmouseout="mOut(this)"&gt;&lt;a class="sbmDim" onmouseover="mOvr(this)" title="Post it to live" onmouseout="mOut(this)" href="https://favorites.live.com/quickadd.aspx?marklet=1&amp;amp;mkt=en-us&amp;amp;url=http://blogs.technet.com/feliciano_intini/archive/2008/05/21/annunciato-il-microsoft-security-cooperation-program-for-certs-scpcert.aspx&amp;amp;title=Annunciato il Microsoft Security Cooperation Program for CERTs (SCPCert)" target="_blank"&gt;&lt;img src="http://blogs.msdn.com/blogfiles/rahulso/WindowsLiveWriter/IconsfordifferentSocialBookmarkingSites_B387/live4.png" border="0" /&gt;&lt;/a&gt;&lt;/td&gt;          &lt;td class="sbmDim" onmouseover="mOvr(this)" onmouseout="mOut(this)"&gt;&lt;a class="sbmDim" onmouseover="mOvr(this)" title="Post it to technorati!" onmouseout="mOut(this)" href="http://technorati.com/faves/?add=http://blogs.technet.com/feliciano_intini/archive/2008/05/21/annunciato-il-microsoft-security-cooperation-program-for-certs-scpcert.aspx&amp;amp;title=Annunciato il Microsoft Security Cooperation Program for CERTs (SCPCert)" target="_blank"&gt;&lt;img src="http://blogs.msdn.com/blogfiles/rahulso/WindowsLiveWriter/IconsfordifferentSocialBookmarkingSites_B387/technora4.png" border="0" /&gt;&lt;/a&gt;&lt;/td&gt;          &lt;td class="sbmDim" onmouseover="mOvr(this)" onmouseout="mOut(this)"&gt;&lt;a class="sbmDim" onmouseover="mOvr(this)" title="Post it to yahoo!" onmouseout="mOut(this)" href="http://myweb.yahoo.com/myresults/bookmarklet?u=http://blogs.technet.com/feliciano_intini/archive/2008/05/21/annunciato-il-microsoft-security-cooperation-program-for-certs-scpcert.aspx&amp;amp;t=Annunciato il Microsoft Security Cooperation Program for CERTs (SCPCert)" target="_blank"&gt;&lt;img src="http://blogs.msdn.com/blogfiles/rahulso/WindowsLiveWriter/IconsfordifferentSocialBookmarkingSites_B387/yahoo9.png" border="0" /&gt;&lt;/a&gt;&lt;/td&gt;       &lt;/tr&gt;     &lt;/tbody&gt;&lt;/table&gt; &lt;/span&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3058484" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/8.0+Security+Foundations+_2800_Processes_2900_/default.aspx">8.0 Security Foundations (Processes)</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/0.0.0.0+Microsoft+Strategy+and+Initiatives/default.aspx">0.0.0.0 Microsoft Strategy and Initiatives</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/Security+Incident+Response/default.aspx">Security Incident Response</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/Security+Management/default.aspx">Security Management</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/0.1.0.0+Security+and+Privacy/default.aspx">0.1.0.0 Security and Privacy</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/0.1.1.1+End+to+End+Trust/default.aspx">0.1.1.1 End to End Trust</category></item><item><title>L'evoluzione del Trustworthy Computing: End to End Trust (E2E)</title><link>http://blogs.technet.com/feliciano_intini/archive/2008/04/14/l-evoluzione-del-trustworthy-computing-end-to-end-trust-e2e.aspx</link><pubDate>Mon, 14 Apr 2008 11:55:04 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3036460</guid><dc:creator>Feliciano Intini</dc:creator><slash:comments>9</slash:comments><comments>http://blogs.technet.com/feliciano_intini/comments/3036460.aspx</comments><wfw:commentRss>http://blogs.technet.com/feliciano_intini/commentrss.aspx?PostID=3036460</wfw:commentRss><description>&lt;p&gt;&lt;font face="Calibri" size="3"&gt;&lt;a href="http://www.microsoft.com/mscorp/twc/endtoendtrust/default.mspx" target="_blank"&gt;&lt;img style="border-right: 0px; border-top: 0px; border-left: 0px; border-bottom: 0px" height="157" alt="End_To_End_Trust" src="http://blogs.technet.com/blogfiles/feliciano_intini/WindowsLiveWriter/LevoluzionedelTrustworthyComputingEndtoE_108DC/End_To_End_Trust_3.jpg" width="524" border="0" /&gt;&lt;/a&gt;&amp;#160;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font face="Calibri" size="3"&gt;Nello &lt;a href="http://blogs.technet.com/feliciano_intini/archive/2008/04/09/rsa-conference-2008-rilasciata-la-beta-di-forefront-stirling.aspx"&gt;scorso post&lt;/a&gt; quando vi ho stuzzicato ad attendere il post successivo (che &amp;#232; poi questo... ;-) ho commesso un errore involontario, ma per certi versi un &lt;em&gt;lapsus&lt;/em&gt;&amp;#160;&lt;em&gt;freudiano.&lt;/em&gt; Vi ho anticipato che vi avrei parlato &amp;quot;&lt;u&gt;degli elementi della nuova strategia Microsoft in area sicurezza&lt;/u&gt;&amp;quot; ma di fatto quello di cui Craig Mundie ha &lt;a href="http://www.microsoft.com/presspass/press/2008/apr08/04-08RSA2008PR.mspx"&gt;parlato&lt;/a&gt; all'RSA Conference 2008, da un lato non si pu&amp;#242; definire esattamente &amp;quot;la &lt;strong&gt;nuova&lt;/strong&gt; strategia&amp;quot;, dall'altro io credo che rappresenti &lt;u&gt;un passaggio storico fondamentale nell'evoluzione dell'atteggiamento della mia cara Microsoft sul tema Sicurezza, rivoluzionario quanto l'avvio della strategia &lt;strong&gt;&lt;a href="http://www.microsoft.com/mscorp/twc/default.mspx"&gt;Trustworthy Computing&lt;/a&gt;&lt;/strong&gt;&lt;/u&gt; avvenuto nel 2002. &lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font face="Calibri" size="3"&gt;Questa visione strategica ha un nome, &amp;quot;&lt;strong&gt;End to End Trust&lt;/strong&gt;&amp;quot;, e rappresenta la proposta di Microsoft di avviare &lt;u&gt;una discussione aperta&lt;/u&gt; su &lt;u&gt;cosa sia necessario fare per migliorare il futuro di Internet, per quanto riguarda gli aspetti di &lt;strong&gt;Security&lt;/strong&gt; &amp;amp; &lt;strong&gt;Privacy&lt;/strong&gt;&lt;/u&gt;. Purtroppo Internet non &amp;#232; nata avendoli come requisiti di progetto: il fatto che ora queste due caratteristiche siano un problema evidente &amp;#232; sotto gli occhi di tutti. Microsoft intende dare una svolta a questo difetto &amp;quot;strutturale&amp;quot; e chiede l'aiuto di tutti per concordare un piano di azione che possa cambiare le regole del gioco preservando i diritti riconosciuti che gli utenti esercitano sul web.&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font face="Calibri" size="3"&gt;Per la prima volta Microsoft si presenta senza una soluzione tecnologica in tasca e sceglie la strada di una proposizione di architettura e di metodo presentata tramite un breve &lt;em&gt;&lt;strong&gt;white paper&lt;/strong&gt;&lt;/em&gt; di 20 pagine (da leggere assolutamente!), e di un confronto tramite un &lt;em&gt;&lt;strong&gt;forum&lt;/strong&gt;&lt;/em&gt; aperto alla discussione, entrambi raggiungibili al &lt;a href="http://www.microsoft.com/mscorp/twc/endtoendtrust/default.mspx" target="_blank"&gt;sito&lt;strong&gt; End to End Trust&lt;/strong&gt;&lt;/a&gt; creato per questa iniziativa.&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font face="Calibri" size="3"&gt;In estrema sintesi, questa proposta indica una strada percorribile:&lt;/font&gt;&lt;/p&gt;  &lt;ol&gt;   &lt;li&gt;&lt;font face="Calibri" size="3"&gt;migliorare gli aspetti di &lt;strong&gt;autenticazione&lt;/strong&gt;, creando un cosiddetto &amp;quot;&lt;strong&gt;Trusted Stack&lt;/strong&gt;&amp;quot;; abilitare la possibilit&amp;#224; di autenticazione robusta a tutti i livelli logici dei soggetti che interagiscono su Internet: &lt;u&gt;hardware, software, persone e dati&lt;/u&gt;.&lt;/font&gt;&lt;/li&gt;    &lt;li&gt;&lt;font face="Calibri" size="3"&gt;migliorare la capacit&amp;#224; di tracciare gli eventi (&lt;strong&gt;audit&lt;/strong&gt;) per poter responsabilizzare chi esegue delle azioni (&lt;strong&gt;accountability&lt;/strong&gt;); allo stesso tempo fornire alle persone maggiore &lt;strong&gt;controllo&lt;/strong&gt; sulle proprie identit&amp;#224; digitali per garantire una maggiore tutela della propria &lt;strong&gt;Privacy&lt;/strong&gt;.&lt;/font&gt;&lt;/li&gt; &lt;/ol&gt;  &lt;p&gt;&lt;font face="Calibri" size="3"&gt;La proposta per&amp;#242; non si limita a fornire spunti in ambito tecnologico, riconoscendo che il successo di una tale &lt;em&gt;reingegnerizzazione di Internet&lt;/em&gt; non possa essere affrontata senza una &lt;u&gt;convergenza di interessi sociali, politici ed economici&lt;/u&gt;.&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font face="Calibri" size="3"&gt;Un post &amp;#232; davvero riduttivo per esaurire l'analisi dei vari temi sollevati dalla strategia di &lt;strong&gt;End to End Trust&lt;/strong&gt;, e p&lt;/font&gt;&lt;font face="Calibri" size="3"&gt;roprio per l'importanza di questa discussione &lt;/font&gt;&lt;font face="Calibri" size="3"&gt;ho deciso che dedicher&amp;#242; una serie di post sul tema, augurandomi di avervi come partecipanti attivi nello scambio di opinioni che cercher&amp;#242; di stimolare. Ci sono aspetti che non mancheranno di sollevare delle considerazioni critiche (dal punto di vista tecnologico, per esempio, sar&amp;#224; interessante dibattere sugli aspetti dei dispositivi hardware che &lt;u&gt;potrebbero&lt;/u&gt; utilizzare i chip TPM per essere considerati &lt;em&gt;Trusted Device&lt;/em&gt;). &lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font face="Calibri" size="3"&gt;Vi lascio quindi con il compito di leggere il &lt;a href="http://download.microsoft.com/download/7/2/3/723a663c-652a-47ef-a2f5-91842417cab6/Establishing_End_to_End_Trust.pdf" target="_blank"&gt;white paper&lt;/a&gt;... a presto!&lt;/font&gt;&lt;/p&gt; &lt;span class="sbmLink"&gt;   &lt;table cellspacing="1" cellpadding="1"&gt;&lt;tbody&gt;       &lt;tr&gt;         &lt;td class="sbmText"&gt;Share this post : &lt;/td&gt;          &lt;td class="sbmDim" onmouseover="mOvr(this)" onmouseout="mOut(this)"&gt;&lt;a class="sbmDim" onmouseover="mOvr(this)" title="Post it to del.icio.us" onmouseout="mOut(this)" href="http://del.icio.us/post?url=http://blogs.technet.com/feliciano_intini/archive/2008/04/14/l-evoluzione-del-trustworthy-computing-end-to-end-trust-e2e.aspx&amp;amp;;title=L'evoluzione del Trustworthy Computing: End to End Trust (E2E)" target="_blank"&gt;&lt;img src="http://blogs.msdn.com/blogfiles/rahulso/WindowsLiveWriter/IconsfordifferentSocialBookmarkingSites_B387/deliciou4.png" border="0" /&gt;&lt;/a&gt;&lt;/td&gt;          &lt;td class="sbmDim" onmouseover="mOvr(this)" onmouseout="mOut(this)"&gt;&lt;a class="sbmDim" onmouseover="mOvr(this)" title="Post it to digg" onmouseout="mOut(this)" href="http://digg.com/submit?phase=2&amp;amp;url=http://blogs.technet.com/feliciano_intini/archive/2008/04/14/l-evoluzione-del-trustworthy-computing-end-to-end-trust-e2e.aspx&amp;amp;title=L'evoluzione del Trustworthy Computing: End to End Trust (E2E)" target="_blank"&gt;&lt;img src="http://blogs.msdn.com/blogfiles/rahulso/WindowsLiveWriter/IconsfordifferentSocialBookmarkingSites_B387/digg14.png" border="0" /&gt;&lt;/a&gt;&lt;/td&gt;          &lt;td class="sbmDim" onmouseover="mOvr(this)" onmouseout="mOut(this)"&gt;&lt;a class="sbmDim" onmouseover="mOvr(this)" title="Post it to live" onmouseout="mOut(this)" href="https://favorites.live.com/quickadd.aspx?marklet=1&amp;amp;mkt=en-us&amp;amp;url=http://blogs.technet.com/feliciano_intini/archive/2008/04/14/l-evoluzione-del-trustworthy-computing-end-to-end-trust-e2e.aspx&amp;amp;title=L'evoluzione del Trustworthy Computing: End to End Trust (E2E)" target="_blank"&gt;&lt;img src="http://blogs.msdn.com/blogfiles/rahulso/WindowsLiveWriter/IconsfordifferentSocialBookmarkingSites_B387/live4.png" border="0" /&gt;&lt;/a&gt;&lt;/td&gt;          &lt;td class="sbmDim" onmouseover="mOvr(this)" onmouseout="mOut(this)"&gt;&lt;a class="sbmDim" onmouseover="mOvr(this)" title="Post it to technorati!" onmouseout="mOut(this)" href="http://technorati.com/faves/?add=http://blogs.technet.com/feliciano_intini/archive/2008/04/14/l-evoluzione-del-trustworthy-computing-end-to-end-trust-e2e.aspx&amp;amp;title=L'evoluzione del Trustworthy Computing: End to End Trust (E2E)" target="_blank"&gt;&lt;img src="http://blogs.msdn.com/blogfiles/rahulso/WindowsLiveWriter/IconsfordifferentSocialBookmarkingSites_B387/technora4.png" border="0" /&gt;&lt;/a&gt;&lt;/td&gt;          &lt;td class="sbmDim" onmouseover="mOvr(this)" onmouseout="mOut(this)"&gt;&lt;a class="sbmDim" onmouseover="mOvr(this)" title="Post it to yahoo!" onmouseout="mOut(this)" href="http://myweb.yahoo.com/myresults/bookmarklet?u=http://blogs.technet.com/feliciano_intini/archive/2008/04/14/l-evoluzione-del-trustworthy-computing-end-to-end-trust-e2e.aspx&amp;amp;t=L'evoluzione del Trustworthy Computing: End to End Trust (E2E)" target="_blank"&gt;&lt;img src="http://blogs.msdn.com/blogfiles/rahulso/WindowsLiveWriter/IconsfordifferentSocialBookmarkingSites_B387/yahoo9.png" border="0" /&gt;&lt;/a&gt;&lt;/td&gt;       &lt;/tr&gt;     &lt;/tbody&gt;&lt;/table&gt; &lt;/span&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3036460" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/0.0.0.0+Microsoft+Strategy+and+Initiatives/default.aspx">0.0.0.0 Microsoft Strategy and Initiatives</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/0.1.0.0+Security+and+Privacy/default.aspx">0.1.0.0 Security and Privacy</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/0.1.1.1+End+to+End+Trust/default.aspx">0.1.1.1 End to End Trust</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/Privacy/default.aspx">Privacy</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/0.1.1.0+Trustworthy+Computing+_2800_TwC_2900_+/default.aspx">0.1.1.0 Trustworthy Computing (TwC) </category></item></channel></rss>