<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Steve Riley on Security : blogging</title><link>http://blogs.technet.com/steriley/archive/tags/blogging/default.aspx</link><description>Tags: blogging</description><dc:language>en-US</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>Blog relocated again</title><link>http://blogs.technet.com/steriley/archive/2009/08/19/blog-relocated-again.aspx</link><pubDate>Thu, 20 Aug 2009 01:02:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3275119</guid><dc:creator>Steve Riley</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/steriley/comments/3275119.aspx</comments><wfw:commentRss>http://blogs.technet.com/steriley/commentrss.aspx?PostID=3275119</wfw:commentRss><wfw:comment>http://blogs.technet.com/steriley/rsscomments.aspx?PostID=3275119</wfw:comment><description>Just a quick update, to make sure everyone knows. I've moved my blog from MSInfluentials to WordPress.com. Please update your aggregators/bookmarks/favorites to &lt;a href="http://stvrly.wordpress.com" target="_blank" mce_href="http://stvrly.wordpress.com"&gt;http://stvrly.wordpress.com&lt;/a&gt;. I've posted the reasoning for my move, as well as a description of my personal foray into the cloud, over there.&lt;br&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3275119" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/steriley/archive/tags/blogging/default.aspx">blogging</category></item><item><title>Comments, administrivia, and the future of the “infosec professional”</title><link>http://blogs.technet.com/steriley/archive/2008/10/15/comments-administrivia-and-the-future-of-the-infosec-professional.aspx</link><pubDate>Thu, 16 Oct 2008 01:29:13 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3136996</guid><dc:creator>Steve Riley</dc:creator><slash:comments>14</slash:comments><comments>http://blogs.technet.com/steriley/comments/3136996.aspx</comments><wfw:commentRss>http://blogs.technet.com/steriley/commentrss.aspx?PostID=3136996</wfw:commentRss><wfw:comment>http://blogs.technet.com/steriley/rsscomments.aspx?PostID=3136996</wfw:comment><description>&lt;p&gt;Back when the spam was spiraling out of control, I configured my blog to close comments after 90 days. I’ve removed the limitation now, for two reasons: the spam is under control, and I wanted to reply to a comment made to my post on IPsec/IPv6 direct connect.&lt;/p&gt;  &lt;p&gt;On &lt;a target="_blank" href="http://blogs.technet.com/steriley/archive/2008/06/25/directly-connect-to-your-corpnet-with-ipsec-and-ipv6.aspx#3104911"&gt;13 August, jcorey&lt;/a&gt; asked about how to deal with those who firmly believe that the only answer to any security problem is to inspect everything at the edge. This is an important question, and I wanted to give Joe an answer. (You might have to scroll down when you click the previous link, it seems that linking to individual comments is broken.)&lt;/p&gt;  &lt;p&gt;Today, &lt;a target="_blank" href="http://blogs.technet.com/steriley/archive/2008/06/25/directly-connect-to-your-corpnet-with-ipsec-and-ipv6.aspx#3136984"&gt;15 October, I&lt;/a&gt; wrote a little thesis as an answer to his question. I’m calling it out in a separate post because I want to make sure those of you with aggregators that don’t update when posts receive new comments still have a chance to reply with your thoughts. I’ll also repost it here:&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;jcorey-- You've nailed the biggest obstacle to deploying something like direct connect. Many security professionals have been taught that there simply is, and never will be, a process or technology that allows you to trust anything that originates from outside your corpnet. These professionals cling to this belief, and have been the cause that allowed the whole “detection” market to bloom. &lt;/p&gt;    &lt;p&gt;Let me be clear: this total lack of trustworthiness is no longer absolutely true. Of course there will be times when unknown machines will be used by known and unknown people to access your information. But what about one particular subset -- known humans, with known portable computers -- can't we do something better than treat them as toxic invaders? &lt;/p&gt;    &lt;p&gt;Indeed we can. And that's what I'm proposing with direct connect. The technology -- managed, of course, with the right processes -- exists so that you can extend the trust to known computers even though you don't trust the network they're connected to. This is because you have mechanisms that: &lt;/p&gt;    &lt;p&gt;1. Allow you to configure the machine according to your requirements (domain join, group policy) &lt;/p&gt;    &lt;p&gt;2. Dictate computer and user authentication requirements (IPsec policies, smart cards) &lt;/p&gt;    &lt;p&gt;3. Limit what the users of these machines can do (UAC, non-admin, Forefront Client Security, Windows Firewall, even software restriction policies) &lt;/p&gt;    &lt;p&gt;4. Validate the health of machines initiating incoming connections and remediate if necessary (NAP, System Center Configuration Manager) &lt;/p&gt;    &lt;p&gt;5. Limit the threat of attacks against stolen computers (domain logon, smart cards, BitLocker with TPM) &lt;/p&gt;    &lt;p&gt;With the robust authentication, validation, configuration, and control mechanisms available to you, I simply don't see that there's any need to fall back to “detection” now. Detection technologies were -- and remain -- necessary for the times when we have no clue about the health of client computers and when we had no way to gauge the intent of the users. But it is truly reflective of a head-in-the-sand mentality to assume that this is a complete description of what's capable today. &lt;/p&gt;    &lt;p&gt;You know, someone once asked me what it takes to be a security professional. I answered that there are two primary elements: &lt;strong&gt;become a networking/packet wonk&lt;/strong&gt;, and &lt;strong&gt;be willing to change your opinions&lt;/strong&gt; when the right evidence comes along. Indeed, I suspect that many security folk have forgotten the need to keep their wonikness updated, which in turn makes them resist new ideas regardless of the strength of the evidence. I'm not very proud of what I just wrote, because I loathe generalities, but I'm not sure what else to think here. Sigh.&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;Joe’s question is important and strikes at the foundation of what it means to be a security professional today. I’m eager to continue this conversation, because it’s reflective of what I sense to be a radical shift in our jobs—we are, or should be, no longer the wolf-crying propeller-head who sits in the basement and twiddles with the firewall. Instead, our job should be defined as one who’s charged with protecting the organization’s information from attack, while maximizing its utility to authorized users, according to the principles of least privilege. Your thoughts?&lt;/p&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3136996" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/steriley/archive/tags/blogging/default.aspx">blogging</category><category domain="http://blogs.technet.com/steriley/archive/tags/infosec+as+a+profession/default.aspx">infosec as a profession</category></item><item><title>Who is "dodacrazy" and what is a "montize buddy"?</title><link>http://blogs.technet.com/steriley/archive/2008/09/11/who-is-dodacrazy-and-what-is-a-montize-buddy.aspx</link><pubDate>Fri, 12 Sep 2008 01:53:55 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3122715</guid><dc:creator>Steve Riley</dc:creator><slash:comments>4</slash:comments><comments>http://blogs.technet.com/steriley/comments/3122715.aspx</comments><wfw:commentRss>http://blogs.technet.com/steriley/commentrss.aspx?PostID=3122715</wfw:commentRss><wfw:comment>http://blogs.technet.com/steriley/rsscomments.aspx?PostID=3122715</wfw:comment><description>&lt;p&gt;Check this out:&lt;/p&gt;  &lt;p&gt;&lt;a title="http://blogs.technet.com/steriley/archive/2008/06/25/directly-connect-to-your-corpnet-with-ipsec-and-ipv6.aspx#3122377" href="http://blogs.technet.com/steriley/archive/2008/06/25/directly-connect-to-your-corpnet-with-ipsec-and-ipv6.aspx#3122377" target="_blank"&gt;http://blogs.technet.com/steriley/archive/2008/06/25/directly-connect-to-your-corpnet-with-ipsec-and-ipv6.aspx#3122377&lt;/a&gt;&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;Hey Steve you and your montize buddy Scott will soon have your hands full after the federal officers come down on your data scams and as for your educational acts i'm not buying it and if others are willing to trade your data for their profits guess there are fools born everyday tunnels oh I see drug dealers right Stevo&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;Normally I delete spam from my comments, and have occasionally deleted mindless ranting criticism (I encourage vigorous discussion of ideas, but won't allow personal attacks). However, this guy's comment is just...weird.&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;What's a &amp;quot;montize buddy Scott&amp;quot;? I know lots of Scotts, and once even admired a particular &amp;quot;Montgomery Scot.&amp;quot; But &amp;quot;montize&amp;quot;? Maybe it's a new kind of malt.&lt;/li&gt;    &lt;li&gt;I don't believe I'm perpetuating any data scams, none that I know of, anyway. If any of you, my readers, feel that I'm scamming your data, I guess I haven't concealed that fact well enough. Oops, sorry! We'll have to add another item to the constantly-growing list of &lt;a href="http://www.privacyrights.org/ar/ChronDataBreaches.htm" target="_blank"&gt;data breaches&lt;/a&gt;.&lt;/li&gt;    &lt;li&gt;While it's true that some of my conference appearances aren't free, no one is certainly forced to buy any of my &amp;quot;educational acts.&amp;quot; A lot of my presentations you can &lt;a href="http://www.microsoft.com/emea/spotlight/result_search.aspx?speaker=20&amp;amp;product=0&amp;amp;rating=0&amp;amp;x=72&amp;amp;y=13" target="_blank"&gt;download for free&lt;/a&gt;!&lt;/li&gt;    &lt;li&gt;I never look in tunnels for my supplies, they're too dark and you can never be totally certain of what you're getting.&lt;/li&gt; &lt;/ul&gt;  &lt;p&gt;Thanks, dodacrazy, for a good Thursday morning laugh!&lt;/p&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3122715" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/steriley/archive/tags/blogging/default.aspx">blogging</category><category domain="http://blogs.technet.com/steriley/archive/tags/things+that+make+me+laugh/default.aspx">things that make me laugh</category></item><item><title>Tweet!</title><link>http://blogs.technet.com/steriley/archive/2008/06/26/tweet.aspx</link><pubDate>Fri, 27 Jun 2008 08:52:18 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3079175</guid><dc:creator>Steve Riley</dc:creator><slash:comments>1</slash:comments><comments>http://blogs.technet.com/steriley/comments/3079175.aspx</comments><wfw:commentRss>http://blogs.technet.com/steriley/commentrss.aspx?PostID=3079175</wfw:commentRss><wfw:comment>http://blogs.technet.com/steriley/rsscomments.aspx?PostID=3079175</wfw:comment><description>&lt;p&gt;The other day an office mate asked, &amp;quot;Do you twitter?&amp;quot; Sorting through the various snarky remarks that immediately popped to mind, I replied that I didn't think anyone would find my routine bits all that interesting. He suggested otherwise: that it would be a convenient place to record quick ideas. So I am &lt;a href="http://twitter.com/steveriley" target="_blank"&gt;now indeed twittering&lt;/a&gt;. Check out the link on the right of this blog. For those using an RSS/ATOM aggravator, you'll want &lt;a title="http://twitter.com/statuses/user_timeline/15237105.rss" href="http://twitter.com/statuses/user_timeline/15237105.rss"&gt;http://twitter.com/statuses/user_timeline/15237105.rss&lt;/a&gt;.&lt;/p&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3079175" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/steriley/archive/tags/blogging/default.aspx">blogging</category></item><item><title>Playing around with my blog</title><link>http://blogs.technet.com/steriley/archive/2007/09/26/playing-around-with-my-blog.aspx</link><pubDate>Wed, 26 Sep 2007 21:40:21 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:2053437</guid><dc:creator>Steve Riley</dc:creator><slash:comments>3</slash:comments><comments>http://blogs.technet.com/steriley/comments/2053437.aspx</comments><wfw:commentRss>http://blogs.technet.com/steriley/commentrss.aspx?PostID=2053437</wfw:commentRss><wfw:comment>http://blogs.technet.com/steriley/rsscomments.aspx?PostID=2053437</wfw:comment><description>&lt;p&gt;In the right-hand column I've added a new section with four interesting bits of info for you:&lt;/p&gt; &lt;ul&gt; &lt;li&gt;A &lt;a href="http://www.clustrmaps.com/" target="_blank"&gt;ClustrMap&lt;/a&gt;, that shows the locations around the world where people read my blog from. I registered the thing back in December 2006, but just figured out how to add it to the blog software a few days ago.  &lt;li&gt;My bookmarks from &lt;a href="http://del.icio.us/" target="_blank"&gt;del.icio.us&lt;/a&gt;. I just started this yesterday and I've put in some links that many of you ask about. I'll update it from time to time, enjoy.  &lt;li&gt;The current &lt;a href="http://www.homelandstupidity.us/" target="_blank"&gt;Homeland Stupidity&lt;/a&gt; threat rating. Yes, it's intended to spoof the Homeland Security national threat level, which as we all know doesn't provide anything actionable for ordinary citizens. This website has some good commentary that'll make your blood boil.  &lt;li&gt;&lt;a href="http://www.technorati.com/" target="_blank"&gt;Technorati&lt;/a&gt; stuff--authority display (which isn't working, maybe it takes a while?), reaction counts and link, and a button for you to add me to your Technorati favorites.&lt;/li&gt;&lt;/ul&gt; &lt;p&gt;As time goes on, I'll probably add more. Hope you find this useful.&lt;/p&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=2053437" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/steriley/archive/tags/blogging/default.aspx">blogging</category></item><item><title>My blog is not a forum for advertisements</title><link>http://blogs.technet.com/steriley/archive/2006/09/30/My-blog-is-not-a-forum-for-advertisements.aspx</link><pubDate>Sun, 01 Oct 2006 08:17:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:460221</guid><dc:creator>Steve Riley</dc:creator><slash:comments>9</slash:comments><comments>http://blogs.technet.com/steriley/comments/460221.aspx</comments><wfw:commentRss>http://blogs.technet.com/steriley/commentrss.aspx?PostID=460221</wfw:commentRss><wfw:comment>http://blogs.technet.com/steriley/rsscomments.aspx?PostID=460221</wfw:comment><description>&lt;P&gt;&lt;FONT face="book antiqua,palatino" size=3&gt;It's bad enough that the blasted spammers pollute the value of blogs and open forums by hijacking them with their nefarious comments for questionable pharmaceuticals claiming to extend&amp;nbsp;particular body parts. I have recently received, only via private email so far, exhortations to explore mostly unknown security products claiming to magically eliminate a variety of security pains. (OK, I'm exaggerating. I doubt magic is involved.)&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="book antiqua,palatino" size=3&gt;I've continued to endure the spam and have kept my comments open and unmoderated indefinitely. Fortunately, Telligent is putting some additional anti-spam measures in place. But folks, please don't use my blog to sell&amp;nbsp;me or anyone else any&amp;nbsp;products, ok? That's what your own web sites are for. :)&lt;/FONT&gt;&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=460221" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/steriley/archive/tags/advertising/default.aspx">advertising</category><category domain="http://blogs.technet.com/steriley/archive/tags/blogging/default.aspx">blogging</category><category domain="http://blogs.technet.com/steriley/archive/tags/spam/default.aspx">spam</category><category domain="http://blogs.technet.com/steriley/archive/tags/things+that+make+me+angry/default.aspx">things that make me angry</category></item><item><title>This is a test...this is only a test.</title><link>http://blogs.technet.com/steriley/archive/2006/09/02/This-is-a-test_2E002E002E00_this-is-only-a-test_2E00_.aspx</link><pubDate>Sat, 02 Sep 2006 11:12:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:453610</guid><dc:creator>Steve Riley</dc:creator><slash:comments>2</slash:comments><comments>http://blogs.technet.com/steriley/comments/453610.aspx</comments><wfw:commentRss>http://blogs.technet.com/steriley/commentrss.aspx?PostID=453610</wfw:commentRss><wfw:comment>http://blogs.technet.com/steriley/rsscomments.aspx?PostID=453610</wfw:comment><description>&lt;P&gt;Ah, it's a wonderful Saturday afternoon here in Singapore. I just finished up some customer meetings in Bangkok and Manila this week, and TechEd Asia starts next week in Kuala Lumpur. So I'm hanging out Singapore for the weekend, spending some time with friends and relaxing between events.&lt;/P&gt;
&lt;P&gt;Thought I'd give the new &lt;A href="http://ideas.live.com/programpage.aspx?versionid=4372c8c2-b76f-4d44-aea1-9835b61d8dc1" target=_blank mce_href="http://ideas.live.com/programpage.aspx?versionid=4372c8c2-b76f-4d44-aea1-9835b61d8dc1"&gt;Windows Live Writer&lt;/A&gt; a try, to see how well it integrates with the Telligent blogging system used by TechNet and MSDN. I'll post this now and take a look at the results.&lt;/P&gt;
&lt;P&gt;[...time passes...]&lt;/P&gt;
&lt;P&gt;Well waddya know it works! I guess maybe I'll stick with this for a while then. Sure beats the built-in Telligent editor.&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=453610" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/steriley/archive/tags/blogging/default.aspx">blogging</category></item><item><title>F*#$!@g spam!</title><link>http://blogs.technet.com/steriley/archive/2006/05/31/F_2A002300240021004000_g-spam_2100_.aspx</link><pubDate>Wed, 31 May 2006 22:31:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:431562</guid><dc:creator>Steve Riley</dc:creator><slash:comments>16</slash:comments><comments>http://blogs.technet.com/steriley/comments/431562.aspx</comments><wfw:commentRss>http://blogs.technet.com/steriley/commentrss.aspx?PostID=431562</wfw:commentRss><wfw:comment>http://blogs.technet.com/steriley/rsscomments.aspx?PostID=431562</wfw:comment><description>&lt;P&gt;Yeah, it's been a while since I've written a post, and I have some ideas I'll get to once the prep work for TechEd this year settles down a bit.&lt;/P&gt;
&lt;P&gt;But look -- why in the world do the freaking spammers have to start targetting &lt;EM&gt;blogs&lt;/EM&gt; now? I keep my comments open and unmoderated because I'm generally opposed to censorship. I really don't want to have to switch to moderated comments. But I'm getting a bit tired of the spam that appears here.&lt;/P&gt;
&lt;P&gt;We all keep drowning in the stuff because spam works, obviously. Why? Because somebody, somewhere, is actually &lt;STRONG&gt;buying penis enlargement pills!&lt;/STRONG&gt; &amp;lt;grumble&amp;nbsp;grumble&amp;gt;&amp;nbsp;If it's you, do us all a favor: &lt;EM&gt;please stop!&lt;/EM&gt;&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=431562" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/steriley/archive/tags/blogging/default.aspx">blogging</category><category domain="http://blogs.technet.com/steriley/archive/tags/spam/default.aspx">spam</category><category domain="http://blogs.technet.com/steriley/archive/tags/things+that+make+me+angry/default.aspx">things that make me angry</category></item><item><title>www.steveriley.ms is down</title><link>http://blogs.technet.com/steriley/archive/2006/05/07/www.steveriley.ms-is-down.aspx</link><pubDate>Mon, 08 May 2006 07:41:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:427514</guid><dc:creator>Steve Riley</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/steriley/comments/427514.aspx</comments><wfw:commentRss>http://blogs.technet.com/steriley/commentrss.aspx?PostID=427514</wfw:commentRss><wfw:comment>http://blogs.technet.com/steriley/rsscomments.aspx?PostID=427514</wfw:comment><description>That web site runs on WinISP, an experimental ISP hosted for Microsoft employees to use for testing. WinISP is having problems of late, as many of you have written to me in emails. I'm looking for a new home for my PowerPoints and recordings; once I find it, I'll post a note here in the blog. Sorry for the inconvenience, folks...&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=427514" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/steriley/archive/tags/blogging/default.aspx">blogging</category></item><item><title>Yes, I'm alive</title><link>http://blogs.technet.com/steriley/archive/2005/01/12/Yes_2C00_-I_2700_m-alive.aspx</link><pubDate>Wed, 12 Jan 2005 23:53:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:351709</guid><dc:creator>Steve Riley</dc:creator><slash:comments>4</slash:comments><comments>http://blogs.technet.com/steriley/comments/351709.aspx</comments><wfw:commentRss>http://blogs.technet.com/steriley/commentrss.aspx?PostID=351709</wfw:commentRss><wfw:comment>http://blogs.technet.com/steriley/rsscomments.aspx?PostID=351709</wfw:comment><description>&lt;P&gt;And am finally gonna start posting some things here, starting with many of my recent presentations. Please see &lt;A href="http://www.steveriley.ms/" mce_href="http://www.steveriley.ms"&gt;http://www.steveriley.ms&lt;/A&gt; and click the "Presentations" link in the left side column. There you'll find PPTs for most of the sessions I've delivered in the past couple years. If you need something you can't find, just let me know.&lt;/P&gt;
&lt;P&gt;BTW, a friend of mine in New Zealand set up that web site a while ago for me. He's Nick MacKechnie, a technical account manager in Auckland. Thanks Nick!&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=351709" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/steriley/archive/tags/blogging/default.aspx">blogging</category></item></channel></rss>