<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Steve Riley on Security : the trade press</title><link>http://blogs.technet.com/steriley/archive/tags/the+trade+press/default.aspx</link><description>Tags: the trade press</description><dc:language>en-US</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>Must be a slow news day: reporter writes 100% crap</title><link>http://blogs.technet.com/steriley/archive/2006/10/03/Must-be-a-slow-news-day_3A00_-reporter-writes-100_2500_-crap.aspx</link><pubDate>Tue, 03 Oct 2006 21:12:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:461362</guid><dc:creator>Steve Riley</dc:creator><slash:comments>6</slash:comments><comments>http://blogs.technet.com/steriley/comments/461362.aspx</comments><wfw:commentRss>http://blogs.technet.com/steriley/commentrss.aspx?PostID=461362</wfw:commentRss><wfw:comment>http://blogs.technet.com/steriley/rsscomments.aspx?PostID=461362</wfw:comment><description>&lt;P&gt;&lt;FONT face="book antiqua,palatino" size=3&gt;Imagine my surprise to read that &lt;/FONT&gt;&lt;A class="" href="http://www.itweek.co.uk/itweek/news/2165364/nap-kicked-vista" target=_blank mce_href="http://www.itweek.co.uk/itweek/news/2165364/nap-kicked-vista"&gt;&lt;FONT face="book antiqua,palatino" size=3&gt;Microsoft is removing NAP from Windows Vista&lt;/FONT&gt;&lt;/A&gt;&lt;FONT face="book antiqua,palatino" size=3&gt;! Does this&amp;nbsp;guy actually get paid money to write this drivel? The particular folks quoted in the article all have their own agendas, of course.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="book antiqua,palatino" size=3&gt;News flash: we aren't dropping NAP. It's in the product now, we're actually running it on part of our own corporate network. And soon you'll get to enjoy the benefits of NAP in your own environments, too.&lt;/FONT&gt;&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=461362" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/steriley/archive/tags/Windows+Vista/default.aspx">Windows Vista</category><category domain="http://blogs.technet.com/steriley/archive/tags/NAP/default.aspx">NAP</category><category domain="http://blogs.technet.com/steriley/archive/tags/false+claims/default.aspx">false claims</category><category domain="http://blogs.technet.com/steriley/archive/tags/the+trade+press/default.aspx">the trade press</category><category domain="http://blogs.technet.com/steriley/archive/tags/things+that+make+me+angry/default.aspx">things that make me angry</category><category domain="http://blogs.technet.com/steriley/archive/tags/things+that+make+me+laugh/default.aspx">things that make me laugh</category></item><item><title>Yes, everyone knows you're a dog</title><link>http://blogs.technet.com/steriley/archive/2006/09/07/Yes_2C00_-everyone-knows-you_2700_re-a-dog.aspx</link><pubDate>Thu, 07 Sep 2006 18:17:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:454645</guid><dc:creator>Steve Riley</dc:creator><slash:comments>2</slash:comments><comments>http://blogs.technet.com/steriley/comments/454645.aspx</comments><wfw:commentRss>http://blogs.technet.com/steriley/commentrss.aspx?PostID=454645</wfw:commentRss><wfw:comment>http://blogs.technet.com/steriley/rsscomments.aspx?PostID=454645</wfw:comment><description>&lt;P&gt;Amazing how long the legs are on the AOL search debacle. Of course, we in the online community often beat such storeis to death, if only because they deserve it!&lt;/P&gt;
&lt;P&gt;Recently Kim Cameron &lt;A href="http://www.identityblog.com/?p=536" mce_href="http://www.identityblog.com/?p=536"&gt;posted&lt;/A&gt; the search history of user 16006693, which flits&amp;nbsp;"from politics, to retirement, to politics, to religion, to sex, quickly back to religion (repent!), to food, and finally to heartburn." Why is it interesting? Probably because each and every one of us can find a bit of ourselves in user 16006693 (well, OK, not all of us; I know I'm not anywhere close!).&lt;/P&gt;
&lt;P&gt;Check it out; don't hurt yourself too much from laughing:&lt;/P&gt;
&lt;P&gt;16006693 nak&lt;BR&gt;16006693 nack&lt;BR&gt;16006693 sharona&lt;BR&gt;16006693 knack&lt;BR&gt;16006693 knack downloads&lt;BR&gt;16006693 oakrige boys&lt;BR&gt;16006693 oakridge boys&lt;BR&gt;16006693 oakridge boys downloads free&lt;BR&gt;16006693 jokes about dick cheney&lt;BR&gt;16006693 jokes about dick cheney but not george bush&lt;BR&gt;16006693 dick cheney creep&lt;BR&gt;16006693 dick cheney dickhead&lt;BR&gt;16006693 rummy dickhead&lt;BR&gt;16006693 where is iraq&lt;BR&gt;16006693 where is lebenon&lt;BR&gt;16006693 his bullets&lt;BR&gt;16006693 his bullies&lt;BR&gt;16006693 shiits&lt;BR&gt;16006693 shee-ites&lt;BR&gt;16006693 bush appruval&lt;BR&gt;16006693 bush approvel&lt;BR&gt;16006693 bush drops below&lt;BR&gt;16006693 dead reporters&lt;BR&gt;16006693 dead reporters fotos&lt;BR&gt;16006693 dead reporters pix&lt;BR&gt;16006693 disembowled reporters pix&lt;BR&gt;16006693 disembowled new york times&lt;BR&gt;16006693 love thine enemas&lt;BR&gt;16006693 love thine enemies&lt;BR&gt;16006693 bible quote of the day&lt;BR&gt;16006693 insperation from bible&lt;BR&gt;16006693 george bush great president&lt;BR&gt;16006693 george w bush great president&lt;BR&gt;16006693 dream on&lt;BR&gt;16006693 oakridge boys lyrics dream on&lt;BR&gt;16006693 how to run country&lt;BR&gt;16006693 how to run country when not really inerested&lt;BR&gt;16006693 people to run country for you&lt;BR&gt;16006693 over work&lt;BR&gt;16006693 overwork&lt;BR&gt;16006693 stress&lt;BR&gt;16006693 best place to retire&lt;BR&gt;16006693 places like crawford but without cindy sheehan&lt;BR&gt;16006693 crawford the town not cindy crawford&lt;BR&gt;16006693 crawford tx&lt;BR&gt;16006693 like crawford tx but not so hot&lt;BR&gt;16006693 best places to retire not hot&lt;BR&gt;16006693 best places to retire global warming&lt;BR&gt;16006693 global warming mith&lt;BR&gt;16006693 global warming myth&lt;BR&gt;16006693 crawford hot&lt;BR&gt;16006693 cindy crawford hot&lt;BR&gt;16006693 rice hot&lt;BR&gt;16006693 rice hot not recipes&lt;BR&gt;16006693 rice naked&lt;BR&gt;16006693 rice nude&lt;BR&gt;16006693 bible quotes resisting temptation&lt;BR&gt;16006693 oakridge boys i’ll be true to you&lt;BR&gt;16006693 oakridge boys trying to love two women&lt;BR&gt;16006693 rice and beans&lt;BR&gt;16006693 tex mex&lt;BR&gt;16006693 tex mex not music&lt;BR&gt;16006693 tex mex takeout&lt;BR&gt;16006693 tex mex takeout dc&lt;BR&gt;16006693 heart burn&lt;BR&gt;16006693 heartburn&amp;nbsp;&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=454645" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/steriley/archive/tags/the+trade+press/default.aspx">the trade press</category><category domain="http://blogs.technet.com/steriley/archive/tags/identity/default.aspx">identity</category><category domain="http://blogs.technet.com/steriley/archive/tags/threats/default.aspx">threats</category><category domain="http://blogs.technet.com/steriley/archive/tags/things+that+make+me+laugh/default.aspx">things that make me laugh</category><category domain="http://blogs.technet.com/steriley/archive/tags/public+policy/default.aspx">public policy</category><category domain="http://blogs.technet.com/steriley/archive/tags/things+that+make+me+worried/default.aspx">things that make me worried</category></item><item><title>Ah, the joys of speaking about pre-release software!</title><link>http://blogs.technet.com/steriley/archive/2006/09/06/Ah_2C00_-the-joys-of-speaking-about-pre_2D00_release-software_2100_.aspx</link><pubDate>Wed, 06 Sep 2006 12:26:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:454283</guid><dc:creator>Steve Riley</dc:creator><slash:comments>4</slash:comments><comments>http://blogs.technet.com/steriley/comments/454283.aspx</comments><wfw:commentRss>http://blogs.technet.com/steriley/commentrss.aspx?PostID=454283</wfw:commentRss><wfw:comment>http://blogs.technet.com/steriley/rsscomments.aspx?PostID=454283</wfw:comment><description>&lt;P&gt;Two weeks ago I delivered my Windows Vista System Integrity presentation at the TechEds in New Zealand (Auckland) and Australia (Sydney). It was largely the same as the presention at TechEds in America and India, but updated to reflect changes made in the product between the time I wrote the presentation and now.&lt;/P&gt;
&lt;P&gt;Pre-release&amp;nbsp;software is like that: it changes. And when you give presentations on beta software, you rely on the&amp;nbsp;details you have to give the most accurate information possible. But there is, of course, no guarantee that functionality as explained in the presentation will exactly match what's delivered when the final product is released. And indeed, in my &lt;A href="http://blogs.technet.com/steriley/archive/2006/07/21/442870.aspx" target=_blank mce_href="http://blogs.technet.com/steriley/archive/2006/07/21/442870.aspx"&gt;post on mandatory integrity control&lt;/A&gt;, I mentioned some changes.&lt;/P&gt;
&lt;P mce_keep="true"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT size=4&gt;Code integrity and signatures&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;The latest version of the presentation includes more details on code integrity and code signing. Previously I had described code integrity as applying to &lt;EM&gt;all&lt;/EM&gt; binaries in the operating system; in fact, code integrity applies to the following:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;All code loaded into a protected process 
&lt;LI&gt;Modules implementing cryptographic functions 
&lt;LI&gt;Modules loaded into the software licensing service&lt;/LI&gt;&lt;/UL&gt;
&lt;P&gt;Kernel mode creates special cases that vary depending on the edition of Windows. For &lt;STRONG&gt;64-bit&lt;/STRONG&gt;:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;All kernel mode code loaded anywhere at any time must be signed -- applies to drivers and non-drivers&lt;/LI&gt;&lt;/UL&gt;
&lt;P&gt;For &lt;STRONG&gt;32-bit&lt;/STRONG&gt;, &lt;EM&gt;non-driver&lt;/EM&gt; kernel mode code doesn't require a signature. For &lt;EM&gt;drivers,&lt;/EM&gt; the allow/warn/block behavior of prior versions of Windows is gone. Windows Vista raises a warning if you attempt to install a driver without a signature (only if you're an administrator; standard users can't install unsigned drivers). Drivers with signatures install without prompts. Signatures can come in three forms:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Manufacturers can obtain WHQL signatures from Microsoft as part of the Windows logo program; this indicates a certain level of quality 
&lt;LI&gt;Manufacturers can sign drivers themselves; this indicates authenticity but nothing about quality 
&lt;LI&gt;IT departments can self-sign drivers; this allows organizations to silently deploy approved drivers, even if they otherwise lack signatures&lt;/LI&gt;&lt;/UL&gt;
&lt;P&gt;For more information, read the whitepapers for &lt;A href="http://www.microsoft.com/whdc/winlogo/drvsign/pnp-driver.mspx" target=_blank mce_href="http://www.microsoft.com/whdc/winlogo/drvsign/pnp-driver.mspx"&gt;32-bit plug-and-play drivers&lt;/A&gt; and &lt;A href="http://www.microsoft.com/whdc/system/platform/64bit/kmsigning.mspx" target=_blank mce_href="http://www.microsoft.com/whdc/system/platform/64bit/kmsigning.mspx"&gt;64-bit kernel mode code&lt;/A&gt;.&lt;/P&gt;
&lt;P mce_keep="true"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT size=4&gt;Protected processes and high definition content&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;The Protected Media Path (PMP), part of the new Windows &lt;A href="http://windowssdk.msdn.microsoft.com/en-us/library/ms694197.aspx" target=_blank mce_href="http://windowssdk.msdn.microsoft.com/en-us/library/ms694197.aspx"&gt;Media Foundation&lt;/A&gt;, contains two protected processes. PMP provides a&amp;nbsp;more robust&amp;nbsp;playback environment for high definition rights-protected content. Code integrity checks that&amp;nbsp;all protected processes have&amp;nbsp;valid certificates and that&amp;nbsp;they haven't been revoked.&lt;/P&gt;
&lt;P&gt;Based on some details provided to me, I stated that in only 32-bit Windows Vista, next generation high definition protected content will not play at all; 64-bit is the platform for playing back such content. Then I added some conjecture: the media companies wanted this because&amp;nbsp;the risk of unsigned kernel mode code present in memory could thwart content protection.&lt;/P&gt;
&lt;P&gt;Turns out that my information and my conjecture&amp;nbsp;weren't correct. Windows will never decide not to play content. PMP itself isn't monitored by code integrity, but it does consume the output of a report generated by the operating system about unsigned code in memory. When you load next generation high definition protected content into a playback application, Windows reports the status of kernel mode drivers loaded into memory: the names of the drivers and whether each of those drivers is signed.&lt;/P&gt;
&lt;P&gt;Based on that report, the playback application -- not Windows -- decides what to do: it will either play the content or raise an error and refuse to play. It's also possible for the content itself to indicate what to do, based on instructions contained within the content's embedded license.&lt;/P&gt;
&lt;P&gt;Unfortuantely, my initial explanation sparked the interest of a journalist. Originally he was going to write that Microsoft has dropped support for BluRay and HD-DVD movies. I never said that, of course, although I can see how it's easy to leap to that conclusion. Even after I met with the journalist, to ensure he understood the details (as I knew them at the time), his article still generated some controversy: I got Slashdotted!&lt;/P&gt;
&lt;P mce_keep="true"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT size=4&gt;Keeping you informed&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;I guess that's the risk you take in a job like mine. It's a risk I'm willing to take, because I still believe I have the coolest job in the world: helping&amp;nbsp;you learn everything&amp;nbsp;you can about how to design and operate environments using Microsoft technology as safely and securely as possible.&lt;/P&gt;
&lt;P&gt;Fortunately, mechanisms like this blog allow us to ensure that you, our customers, get the most up-to-date information we can give you. Now that I understand how PMP functions with respect to code integrity, I can let all of you know here, as well as ensure that future deliveries of the system integrity presentation will be as accurate as possible.&lt;/P&gt;
&lt;P&gt;As always, I extend my sincere gratitute to everyone who takes time to attend my presentations. It means more to me than you'll ever know. I look forward to continuing to see familiar faces at events around the world, and also meeting new folks too. :)&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=454283" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/steriley/archive/tags/Windows+Vista/default.aspx">Windows Vista</category><category domain="http://blogs.technet.com/steriley/archive/tags/the+trade+press/default.aspx">the trade press</category><category domain="http://blogs.technet.com/steriley/archive/tags/protection/default.aspx">protection</category><category domain="http://blogs.technet.com/steriley/archive/tags/TechEd/default.aspx">TechEd</category></item><item><title>What motivates a journalist?</title><link>http://blogs.technet.com/steriley/archive/2006/01/18/What-motivates-a-journalist_3F00_.aspx</link><pubDate>Thu, 19 Jan 2006 02:52:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:417695</guid><dc:creator>Steve Riley</dc:creator><slash:comments>4</slash:comments><comments>http://blogs.technet.com/steriley/comments/417695.aspx</comments><wfw:commentRss>http://blogs.technet.com/steriley/commentrss.aspx?PostID=417695</wfw:commentRss><wfw:comment>http://blogs.technet.com/steriley/rsscomments.aspx?PostID=417695</wfw:comment><description>&lt;P&gt;OK, I have to unload a burden here.&lt;/P&gt;
&lt;P&gt;I often interact with the tech press in various places throughout the world. I've had wonderful, productive meetings with many fine journalists. New Zealand and Malaysia particularly stand out in my memory. However, a thing has happened today that, while not affecting my relationships with individual journalists, irritates me about tech reporting in general.&lt;/P&gt;
&lt;P&gt;Take a look at this:&amp;nbsp;"&lt;A href="http://news.com.com/Windows+Wi-Fi+patch+could+be+long+time+coming/2100-1002_3-6028275.html?tag=cd.lede" mce_href="http://news.com.com/Windows+Wi-Fi+patch+could+be+long+time+coming/2100-1002_3-6028275.html?tag=cd.lede"&gt;Windows Wi-Fi patch could be a long time in coming&lt;/A&gt;."&amp;nbsp;It describes a "vulnerability" recently reported by a researcher at a security conference. c|net also &lt;A href="http://news.com.com/Windows+Wi-Fi+vulnerability+discovered/2100-1029_3-6027399.html?tag=nl" mce_href="http://news.com.com/Windows+Wi-Fi+vulnerability+discovered/2100-1029_3-6027399.html?tag=nl"&gt;wrote about this two days ago&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;I'm disappointed at the seemingly superficial reporting here. Mark Loveless (the researcher) has discovered a way to confuse unsuspecting people simply by taking advantage of a feature in Windows. He has &lt;I&gt;not&lt;/I&gt; discovered a vulnerability. There's no error in either code or the default configuration here.&lt;/P&gt;
&lt;P&gt;Today's article implies that a bad guy can get access to any system he wants to. Thing is, the default configuration won't permit that. You have to run as local admin and deliberately misconfigure your wireless settings for a bad guy to connect to your computer -- and when you do this, Windows warns you multiple times about potential threats.&lt;/P&gt;
&lt;P&gt;It saddens me that, rather than truly analyzing the researcher's report, the journalist simply chose to report "yet another vulnerability."&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=417695" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/steriley/archive/tags/false+claims/default.aspx">false claims</category><category domain="http://blogs.technet.com/steriley/archive/tags/the+trade+press/default.aspx">the trade press</category><category domain="http://blogs.technet.com/steriley/archive/tags/things+that+make+me+angry/default.aspx">things that make me angry</category><category domain="http://blogs.technet.com/steriley/archive/tags/wireless/default.aspx">wireless</category></item></channel></rss>