<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Roger's Security Blog : OpenSource</title><link>http://blogs.technet.com/rhalbheer/archive/tags/OpenSource/default.aspx</link><description>Tags: OpenSource</description><dc:language>en-US</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>SharePoint External Collaboration Toolkit moved to Codeplex</title><link>http://blogs.technet.com/rhalbheer/archive/2009/10/14/sharepoint-external-collaboration-toolkit-moved-to-codeplex.aspx</link><pubDate>Wed, 14 Oct 2009 11:20:59 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3286762</guid><dc:creator>rhalbh</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/rhalbheer/comments/3286762.aspx</comments><wfw:commentRss>http://blogs.technet.com/rhalbheer/commentrss.aspx?PostID=3286762</wfw:commentRss><wfw:comment>http://blogs.technet.com/rhalbheer/rsscomments.aspx?PostID=3286762</wfw:comment><description>&lt;p&gt;Quite a while ago I blogged about the SharePoint External Collaboration Toolkit. I just wanted to make you aware that this toolkit is now moved to Codeplex and can be found here: &lt;a title="http://cks.codeplex.com/" href="http://cks.codeplex.com/"&gt;http://cks.codeplex.com/&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;Roger&lt;/p&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3286762" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/rhalbheer/archive/tags/Microsoft+Products/default.aspx">Microsoft Products</category><category domain="http://blogs.technet.com/rhalbheer/archive/tags/Microsoft/default.aspx">Microsoft</category><category domain="http://blogs.technet.com/rhalbheer/archive/tags/OpenSource/default.aspx">OpenSource</category></item><item><title>Google Chrome and Silent Patching</title><link>http://blogs.technet.com/rhalbheer/archive/2009/05/11/google-chrome-and-silent-patching.aspx</link><pubDate>Mon, 11 May 2009 04:58:49 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3238546</guid><dc:creator>rhalbh</dc:creator><slash:comments>18</slash:comments><comments>http://blogs.technet.com/rhalbheer/comments/3238546.aspx</comments><wfw:commentRss>http://blogs.technet.com/rhalbheer/commentrss.aspx?PostID=3238546</wfw:commentRss><wfw:comment>http://blogs.technet.com/rhalbheer/rsscomments.aspx?PostID=3238546</wfw:comment><description>&lt;p&gt;This morning I opened one of the Swiss Sunday newspapers and Google Chrome made it to the front-page with a “best practice approach” for deploying security updates. In the article itself it was claimed that Chrome is one of the best browsers with regards to security as the deploy patches silently, without letting the user know, even if Chrome is not running and there is no way to disable this. Here are some of similar stories:&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;&lt;a href="http://www.thetechherald.com/article.php/200919/3594/Report-Using-silent-updates-boosts-browser-security" target="_blank"&gt;Report: Using silent updates boosts browser security&lt;/a&gt;&lt;/li&gt;    &lt;li&gt;&lt;a href="http://robmensching.com/blog/posts/2008/9/10/Google-Chrome.-updates-without-asking"&gt;Google Chrome... updates without asking.&lt;/a&gt;&lt;/li&gt;    &lt;li&gt;&lt;a href="http://www.favbrowser.com/google-is-wise-chrome-updates-silently/" target="_blank"&gt;Google is Wise, Chrome Updates Silently&lt;/a&gt;&lt;/li&gt; &lt;/ul&gt;  &lt;p&gt;Give me a break here.&lt;/p&gt;  &lt;p&gt;I am really tired of hearing those things. When Chrome shipped, three things actually hit my inbox:&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;Chrome was shipped (in a Beta) with a few pretty significant vulnerabilities in, which were known for quite a while (like the carpet bombing flaw). The excuse by Google was “it is just a beta”. Tell me please, how you would comment if we would have done the same with Windows 7.&lt;/li&gt;    &lt;li&gt;I got quite some mails by angry customers and journalists telling me that Chrome found a way around User Account Control as Chrome installs without UAC kicking in. Journalists called as they claimed to have found “a severe vulnerability”, customers called as they were angry with us as Chrome simply popped up all over the place in their network even though their user were non-admin. Well, well, Chrome simply installs an executable in the user context. Directories which the user has write permissions. So, for sure Chrome can install – really bad practice in my opinion.&lt;/li&gt;    &lt;li&gt;There was a pretty strange paragraph in the EULA which was then removed later.&lt;/li&gt; &lt;/ul&gt;  &lt;p&gt;And now the silent patching. A few years back, when we designed Windows XP SP2 we talked about switching Automatic Updates on by default. This caused a lot of people screaming and telling us that it is unacceptable to switch AU on by default (which we actually do in the meantime). We recently updated the Windows Update client – and it caused a lot of you to scream and tell us that it is unacceptable for us to silently update a component on Windows. And we heard you loud and clear. &lt;strong&gt;And now I hear that Chrome is best practice because they silently fix security vulns? And you cannot even switch this off?&lt;/strong&gt; So, what is the policy the industry shall follow?&lt;/p&gt;  &lt;p&gt;I agree that the most secure way for consumers would be to automatically fix security vulns. This is actually what I tell my parents: Simply install security updates. This is for consumers and &lt;u&gt;there is an option&lt;/u&gt;. Not having an option is unacceptable – at least for me. Additionally, again for the consumer, having Anti-Malware being part of the Operating System out of the box and enable by default would be desirable. However, this is not acceptable today for competition reasons. &lt;/p&gt;  &lt;p&gt;So, what I do not get is why people do not look at these problems holistically and more from a policy perspective rather than from a company by company perspective. Silently installing components without even giving me the option to choose is not acceptable today for me – but I want to have the option to do it if I want.&lt;/p&gt;  &lt;p&gt;And finally: I would question the enterprise-readiness of such software. At least, I would never deploy it in an enterprise environment.&lt;/p&gt;  &lt;p&gt;Roger&lt;/p&gt;&lt;div class="wlWriterHeaderFooter" style="text-align:left; margin:0px; padding:4px 0px 4px 0px;"&gt;&lt;a href="http://digg.com/submit?url=http%3a%2f%2fblogs.technet.com%2frhalbheer%2farchive%2f2009%2f05%2f11%2fgoogle-chrome-and-silent-patching.aspx&amp;amp;title=Google+Chrome+and+Silent+Patching"&gt;&lt;img src="http://digg.com/img/badges/100x20-digg-button.png" width="100" height="20" alt="Digg This" title="Digg This" border="0" style="border: 0" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3238546" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/rhalbheer/archive/tags/Security/default.aspx">Security</category><category domain="http://blogs.technet.com/rhalbheer/archive/tags/Policy/default.aspx">Policy</category><category domain="http://blogs.technet.com/rhalbheer/archive/tags/Microsoft/default.aspx">Microsoft</category><category domain="http://blogs.technet.com/rhalbheer/archive/tags/OpenSource/default.aspx">OpenSource</category><category domain="http://blogs.technet.com/rhalbheer/archive/tags/Competition/default.aspx">Competition</category></item><item><title>Mozilla Patches Fastest. NOT!</title><link>http://blogs.technet.com/rhalbheer/archive/2009/03/09/mozilla-patches-fastest-not.aspx</link><pubDate>Mon, 09 Mar 2009 12:08:58 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3210684</guid><dc:creator>rhalbh</dc:creator><slash:comments>1</slash:comments><comments>http://blogs.technet.com/rhalbheer/comments/3210684.aspx</comments><wfw:commentRss>http://blogs.technet.com/rhalbheer/commentrss.aspx?PostID=3210684</wfw:commentRss><wfw:comment>http://blogs.technet.com/rhalbheer/rsscomments.aspx?PostID=3210684</wfw:comment><description>&lt;p&gt;I only believe the statistics I forged myself &lt;img alt="smile_regular" src="http://spaces.live.com/rte/emoticons/smile_regular.gif" /&gt;&lt;/p&gt;  &lt;p&gt;So, once more, there is a debate on which browser is the most secure, who fixed which vulnerabilities how fast. The Secunia Report 2008 was just published and it seems that this injects once more the fire about browser security.&lt;/p&gt;  &lt;p&gt;Out Jeff Jones just posted at CIO.com his view on the statistics. If you like looking into figures, there you go: Mozilla &lt;a href="http://www.cio.com/article/483270/Mozilla_Patches_Fastest._NOT_?page=1&amp;amp;taxonomyId=1419" target="_blank"&gt;Patches Fastest. NOT!&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;Roger&lt;/p&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3210684" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/rhalbheer/archive/tags/Security/default.aspx">Security</category><category domain="http://blogs.technet.com/rhalbheer/archive/tags/Microsoft/default.aspx">Microsoft</category><category domain="http://blogs.technet.com/rhalbheer/archive/tags/Processes/default.aspx">Processes</category><category domain="http://blogs.technet.com/rhalbheer/archive/tags/OpenSource/default.aspx">OpenSource</category></item><item><title>Converter from Office Binary files to OpenXML</title><link>http://blogs.technet.com/rhalbheer/archive/2008/02/17/converter-from-office-binary-files-to-openxml.aspx</link><pubDate>Sun, 17 Feb 2008 17:59:23 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:2902854</guid><dc:creator>rhalbh</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/rhalbheer/comments/2902854.aspx</comments><wfw:commentRss>http://blogs.technet.com/rhalbheer/commentrss.aspx?PostID=2902854</wfw:commentRss><wfw:comment>http://blogs.technet.com/rhalbheer/rsscomments.aspx?PostID=2902854</wfw:comment><description>&lt;p&gt;We are supporting a project on SourceForge to write an OpenSource translator for Office Binary files (doc, xls, ppt) to the OpenXML specification. See the initialization &lt;a href="http://b2xtranslator.sourceforge.net/"&gt;here&lt;/a&gt;.
&lt;/p&gt;&lt;p&gt;Roger&lt;/p&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=2902854" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/rhalbheer/archive/tags/Microsoft+Products/default.aspx">Microsoft Products</category><category domain="http://blogs.technet.com/rhalbheer/archive/tags/OpenSource/default.aspx">OpenSource</category></item></channel></rss>