<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Roger's Security Blog : TechEd EMEA</title><link>http://blogs.technet.com/rhalbheer/archive/tags/TechEd+EMEA/default.aspx</link><description>Tags: TechEd EMEA</description><dc:language>en-US</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>Videos about the latest Security Development Lifecycle</title><link>http://blogs.technet.com/rhalbheer/archive/2008/12/15/videos-about-the-latest-security-development-lifecycle.aspx</link><pubDate>Mon, 15 Dec 2008 21:42:55 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3169213</guid><dc:creator>rhalbh</dc:creator><slash:comments>1</slash:comments><comments>http://blogs.technet.com/rhalbheer/comments/3169213.aspx</comments><wfw:commentRss>http://blogs.technet.com/rhalbheer/commentrss.aspx?PostID=3169213</wfw:commentRss><wfw:comment>http://blogs.technet.com/rhalbheer/rsscomments.aspx?PostID=3169213</wfw:comment><description>&lt;p&gt;I know that this is not particularly news but nevertheless it could well be that the non-developers out there have not yet seen this. During TechEd EMEA for Developers we announced several things around SDL and had some speeches. Some of them are public including interviews with people like Michael Howard:&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;Video on the &lt;a target="_blank" href="http://mfile.akamai.com/14853/wmv/microsofttec.download.akamai.com/14853/TechEdOnline/Videos/446_low.asx"&gt;Announcements we made&lt;/a&gt; &lt;/li&gt;    &lt;li&gt;&lt;a target="_blank" href="http://blogs.msdn.com/sdl/archive/2008/11/10/sdl-announcements-at-teched-emea.aspx"&gt;Dave Ladd’s Blog posts about the Announcements&lt;/a&gt; &lt;/li&gt;    &lt;li&gt;&lt;a target="_blank" href="http://mfile.akamai.com/14853/wmv/microsofttec.download.akamai.com/14853/TechEdOnline/Videos/452_low.asx"&gt;Walkthrough of the latest Threat Modeling Tool we have available&lt;/a&gt; &lt;/li&gt;    &lt;li&gt;&lt;a target="_blank" href="http://mfile.akamai.com/14853/wmv/microsofttec.download.akamai.com/14853/TechEdOnline/Videos/455_low.asx"&gt;Top 10 Security Peeves&lt;/a&gt; (they are really good and you should look at the discussion – it is just a few minutes)       &lt;ul&gt;       &lt;li&gt;Think like an attacker &lt;/li&gt;        &lt;li&gt;No one would ever attack this &lt;/li&gt;        &lt;li&gt;That’s a solved problem &lt;/li&gt;        &lt;li&gt;If we would just focus on quality &lt;/li&gt;        &lt;li&gt;My app is behind a firewall &lt;/li&gt;        &lt;li&gt;Giblet &lt;/li&gt;        &lt;li&gt;That’s wrong &lt;/li&gt;        &lt;li&gt;It’s all C’s fault &lt;/li&gt;        &lt;li&gt;Unlocked Workstations &lt;/li&gt;        &lt;li&gt;Airport Security &lt;/li&gt;     &lt;/ul&gt;   &lt;/li&gt; &lt;/ul&gt;  &lt;p&gt;So, it is really good :)&lt;/p&gt;  &lt;p&gt;Roger&lt;/p&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3169213" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/rhalbheer/archive/tags/Security/default.aspx">Security</category><category domain="http://blogs.technet.com/rhalbheer/archive/tags/Microsoft/default.aspx">Microsoft</category><category domain="http://blogs.technet.com/rhalbheer/archive/tags/Processes/default.aspx">Processes</category><category domain="http://blogs.technet.com/rhalbheer/archive/tags/TechEd+EMEA/default.aspx">TechEd EMEA</category></item><item><title>Safe Social Networking</title><link>http://blogs.technet.com/rhalbheer/archive/2008/11/09/safe-social-networking.aspx</link><pubDate>Mon, 10 Nov 2008 00:32:23 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3150134</guid><dc:creator>rhalbh</dc:creator><slash:comments>1</slash:comments><comments>http://blogs.technet.com/rhalbheer/comments/3150134.aspx</comments><wfw:commentRss>http://blogs.technet.com/rhalbheer/commentrss.aspx?PostID=3150134</wfw:commentRss><wfw:comment>http://blogs.technet.com/rhalbheer/rsscomments.aspx?PostID=3150134</wfw:comment><description>&lt;p&gt;I am often asked by a lot of people what my view is on the social networks like Facebook and what I think about it. Well, the most important points first: I am using social networks myself as I like them to keep an eye on people I might lose otherwise. However, I am really careful putting too much information on these networks (like pictures) as I want to keep my privacy.&lt;/p&gt;  &lt;p&gt;We now released &lt;a target="_blank" href="http://www.microsoft.com/protect/yourself/phishing/socialnet.mspx"&gt;10 tips for social networking safety&lt;/a&gt; which I think are pretty good and might even be used by your teen kids as well.&lt;/p&gt;  &lt;p&gt;Roger&lt;/p&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3150134" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/rhalbheer/archive/tags/Security/default.aspx">Security</category><category domain="http://blogs.technet.com/rhalbheer/archive/tags/Microsoft/default.aspx">Microsoft</category><category domain="http://blogs.technet.com/rhalbheer/archive/tags/Consumer/default.aspx">Consumer</category><category domain="http://blogs.technet.com/rhalbheer/archive/tags/TechEd+EMEA/default.aspx">TechEd EMEA</category></item><item><title>The Next Version of ISA Server (“live” from TechEd EMEA)</title><link>http://blogs.technet.com/rhalbheer/archive/2008/11/04/the-next-version-of-isa-server-live-from-teched-emea.aspx</link><pubDate>Tue, 04 Nov 2008 15:34:11 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3147153</guid><dc:creator>rhalbh</dc:creator><slash:comments>2</slash:comments><comments>http://blogs.technet.com/rhalbheer/comments/3147153.aspx</comments><wfw:commentRss>http://blogs.technet.com/rhalbheer/commentrss.aspx?PostID=3147153</wfw:commentRss><wfw:comment>http://blogs.technet.com/rhalbheer/rsscomments.aspx?PostID=3147153</wfw:comment><description>&lt;p&gt;If is once again one of these posts with the start like “I am just sitting in a session…”. Actually I had some time today to visit sessions and look into some things I have never seen. We often have discussions around the future of our products and what we in the field think should be in there. Then you see just slide ware but sometimes it is not too easy to keep up with the pace of the developers in all the products and see what they are actually developing and how it looks today.&lt;/p&gt;  &lt;p&gt;Therefore I took the opportunity to sit in a session on&lt;em&gt;”he Next Version of ISA Serve: A Sneak Peak Demo&lt;/em&gt; &lt;/p&gt;  &lt;p&gt;Let me give you an update on it (no particular order, just the way I saw it today):&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;ISA Server will be renamed in Threat Management Gateway and will be part of the Forefront Suite. Therefore TMG (the new abbreviation for Threat Management Gateway) will collaborate and share information with the other Forefront products in your network (e.g. Forefront Client Security, NAP etc) in order to assess the threats and protect information. This would mean that if a client sends out information to the Internet on an unusual level, we will block it, but it into Quarantine and Scan it… Way cool.      &lt;ul&gt;       &lt;li&gt;It you want to, you can block encrypted zip-files :) &lt;/li&gt;     &lt;/ul&gt;   &lt;/li&gt;    &lt;li&gt;Web Protection:      &lt;ul&gt;       &lt;li&gt;Scan files that are downloaded by the users for malware and block them on the gateway by the TMG server.          &lt;ul&gt;           &lt;li&gt;We can even inspect outbound SSL traffic as we are bridging SSL on the server if you want it. The user is informed that SSL will be inspected. This is very important from a privacy perspective. So, with this technology we can block invalid or expired certs. Last but not least here, you can exclude certain sites or site groups (e.g. Finance and Banking) from the SSL inspection. So, you can configure it the way that you do not inspect the traffic but the certificate will be validated or nothing is done at all. &lt;/li&gt;            &lt;li&gt;For large files, the user gets a page to inform him/her that the file is downloaded by the TMG server and scanned there. If it is ok, it is forwarded to the client. Whether this is kicked off it decided by the download time (more than 10s). &lt;/li&gt;            &lt;li&gt;We can handle files in cache as well. &lt;/li&gt;         &lt;/ul&gt;       &lt;/li&gt;        &lt;li&gt;We include URL filtering          &lt;ul&gt;           &lt;li&gt;Block sites you do not want the users to browse to &lt;/li&gt;            &lt;li&gt;We can even categorize sites (e.g. to categorize them as &lt;em&gt;Malicious&lt;/em&gt;) and you can override the setting as you need. &lt;/li&gt;         &lt;/ul&gt;       &lt;/li&gt;     &lt;/ul&gt;   &lt;/li&gt;    &lt;li&gt;Logging and Reporting      &lt;ul&gt;       &lt;li&gt;The console itself still looks very similar to what you are used to from ISA Server 2006 – there is no need to change a lot, isn’t it? &lt;/li&gt;        &lt;li&gt;We enhanced logging with e.g. the information we just touched upon above. &lt;/li&gt;        &lt;li&gt;There is a new node called &lt;em&gt;Web Access Policy&lt;/em&gt; where you configure all the different policies above. There is even a really good wizard to deploy these policies. &lt;/li&gt;     &lt;/ul&gt;   &lt;/li&gt;    &lt;li&gt;Active Protection Technology (Network Intrusion System from Microsoft Research named GAPA)      &lt;ul&gt;       &lt;li&gt;GAPA will be part of Forefront Client Security as well. &lt;/li&gt;        &lt;li&gt;As I said above, there will be quite some ways to protect your network from attacks. By determining unusual behavior we can block traffic from infected machines and in addition we would be able to kick off actions in the rest of the product suite. &lt;/li&gt;        &lt;li&gt;We will deliver signatures to help you a little bit in order to gain some time before you patch as we learned that the average customer needs more than a month to deploy a security update. To be clear here: &lt;strong&gt;This does not replace proper patch management!&lt;/strong&gt; &lt;/li&gt;     &lt;/ul&gt;   &lt;/li&gt;    &lt;li&gt;Network Access Protection      &lt;ul&gt;       &lt;li&gt;We include NAP into the VPN part of the product. We had quarantine in the VPN implementation of ISA Server 2004 already. However, for a lot of customers that took them a long time to deploy as they had to write customer scripts. With NAP you can build on the same technology you can deploy on your network and it is much easier than the scripting version. However, do not just switch it on – this is a project not just a feature….. &lt;/li&gt;        &lt;li&gt;The nice thing is that you not only check the machine during the logon but during the whole session. So, if the machine falls out of compliance during a session, it is taken into quarantine, fixed and brought back to the network again.. &lt;/li&gt;     &lt;/ul&gt;   &lt;/li&gt;    &lt;li&gt;Array Support      &lt;ul&gt;       &lt;li&gt;You will be able to take two Standard server, join them and have an array. There will still be an Enterprise version to manage multiple arrays but for smaller deployments, this is definitely good news. &lt;/li&gt;     &lt;/ul&gt;   &lt;/li&gt;    &lt;li&gt;And a lot more &lt;/li&gt; &lt;/ul&gt;  &lt;p&gt;As I said: This is way cool…&lt;/p&gt;  &lt;p&gt;I am looking forward to getting my hands on the final product!!!!&lt;/p&gt;  &lt;p&gt;Roger&lt;/p&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3147153" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/rhalbheer/archive/tags/Security/default.aspx">Security</category><category domain="http://blogs.technet.com/rhalbheer/archive/tags/Microsoft+Products/default.aspx">Microsoft Products</category><category domain="http://blogs.technet.com/rhalbheer/archive/tags/TechEd+EMEA/default.aspx">TechEd EMEA</category></item><item><title>Live from the TechEd EMEA Keynote</title><link>http://blogs.technet.com/rhalbheer/archive/2008/11/03/live-from-the-teched-emea-keynote.aspx</link><pubDate>Mon, 03 Nov 2008 17:30:30 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3146486</guid><dc:creator>rhalbh</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/rhalbheer/comments/3146486.aspx</comments><wfw:commentRss>http://blogs.technet.com/rhalbheer/commentrss.aspx?PostID=3146486</wfw:commentRss><wfw:comment>http://blogs.technet.com/rhalbheer/rsscomments.aspx?PostID=3146486</wfw:comment><description>&lt;p&gt;I did this already last year and will do it again just now: I am sitting in the keynote of TechEd EMEA and just wanted to make sure you get all the security-related (and just cool) announcements of the keynote as “real-time” as possible. In addition I am trying to give you my view on it as well as far as possible:&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;We talked about Windows Server 2008 R2 and the corresponding Hyper-V implementation. One of the features we will introduce there is Live Migration which means the migration from one host to another without interruption. This is a feature a lot of customers are asking for.&lt;/li&gt;    &lt;li&gt;System Center Virtual Machine Manager is introducing a feature called Performance and Resource Optimizer, which is an advisor to you which helps you to make sure you keep your SLAs and it helps you to make best use of your resources and helps you to do server consolidation&lt;/li&gt;    &lt;li&gt;In virtualization we will separate the applications from the OSs. So, you will have a vhd for the OS and a vhd for the application! That’s way cool if you think about patching and updating – that’s the way we look at the datacenter in the future.&lt;/li&gt;    &lt;li&gt;System Center will be extended past the Windows border to Linux, Sun OS, AIX… In order to do that we joined the OpenPegasus steering committee to work with them to leverage this code.&lt;/li&gt;    &lt;li&gt;We talked about Software and Services. Mainly we showed how to move part of your AD and Exchange to a managed online service.&lt;/li&gt; &lt;/ul&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;In addition, not in the keynote, you can expect to see a lot of information on &lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;Our Security Intelligence Report v5&lt;/li&gt;    &lt;li&gt;Forefront Client Security v2&lt;/li&gt;    &lt;li&gt;Identity Lifecycle Manager v2&lt;/li&gt;    &lt;li&gt;…&lt;/li&gt; &lt;/ul&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;Roger&lt;/p&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3146486" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/rhalbheer/archive/tags/Microsoft/default.aspx">Microsoft</category><category domain="http://blogs.technet.com/rhalbheer/archive/tags/TechEd+EMEA/default.aspx">TechEd EMEA</category></item><item><title>Getting Ready for TechED EMEA</title><link>http://blogs.technet.com/rhalbheer/archive/2008/10/29/getting-ready-for-teched-emea.aspx</link><pubDate>Wed, 29 Oct 2008 23:34:20 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3144253</guid><dc:creator>rhalbh</dc:creator><slash:comments>2</slash:comments><comments>http://blogs.technet.com/rhalbheer/comments/3144253.aspx</comments><wfw:commentRss>http://blogs.technet.com/rhalbheer/commentrss.aspx?PostID=3144253</wfw:commentRss><wfw:comment>http://blogs.technet.com/rhalbheer/rsscomments.aspx?PostID=3144253</wfw:comment><description>&lt;p&gt;It is as so often, autumn is the time when all the big events are happening in EMEA. This week was RSA Europe (or I think still is) and next week I am looking forward to TechEd EMEA in Barcelona. &lt;/p&gt;  &lt;p&gt;So, I worked at RSA Europe on Monday and Tuesday on the two stories with went live with (the &lt;a href="http://blogs.technet.com/rhalbheer/archive/2008/10/27/h1-os-desktop-vulnerability-report-get-it-now.aspx"&gt;Desktop OS Vulnerability Report&lt;/a&gt; and the Lottery Scam Announcement) and now I am preparing for TechEd EMEA. Next week, there will be a very interesting week in Barcelona. There a people coming over from the Forefront team (I have seen screenshots of beta 2 of Forefront – join these sessions, it is worth it), from the Malware Protection Center (we will launch the Security Intelligence Report) and so on. So, watch my blog, I will do my best to give you the news here.&lt;/p&gt;  &lt;p&gt;Yes, and last but definitely not least, I will run a session on Wednesday:&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;SEC203: End-to-End Trust: The Internet - a safer place to work, play, learn and do business (10:45 - 12:00)&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;&lt;em&gt;Threats change, criminals evolve new ways of stealing money, and valuable data and trust in the Internet continues to come under attack. It's a classic tale of good versus evil with the future of the Internet at stake. The industry is faced with a challenge - either secure the Internet and gain users' trust or lose control to the bad guys and see the value of one of man's greatest inventions dwindle. This session will give you insight into next generation security and Trustworthy Computing's vision for creating an Internet we can trust from end-to-end.&lt;/em&gt;&lt;/p&gt;  &lt;p&gt;and immediately after I will be in the Ask the Expert’s area. So if you want to know about End to End Trust or just want to come by for a chat, you know where to find me.&lt;/p&gt;  &lt;p&gt;One question to you: IN order to keep my blog updated during TechEd EMEA, does anybody know a good Blog Writer for Windows Mobile 6? I was not able to find something which is really worth the installation…&lt;/p&gt;  &lt;p&gt;Roger &lt;/p&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3144253" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/rhalbheer/archive/tags/Microsoft/default.aspx">Microsoft</category><category domain="http://blogs.technet.com/rhalbheer/archive/tags/TechEd+EMEA/default.aspx">TechEd EMEA</category></item></channel></rss>