10 Years of Trustworthy Computing at Microsoft

Before joining Microsoft a little bit more than 10 years ago, I ran a team at PricewarehoureCoopers on e-Business Risk Management – classical security consulting in the Internet bubble time. When I announced that I will leave PwC and join Microsoft, I got interesting reactions (and remember, this was 2001). Mainly they were along . . . → Read More: 10 Years of Trustworthy Computing at Microsoft

A Security Comparison: Microsoft Office vs. Oracle Openoffice

Actually, there is not much to say about this. It is a blog post by CanegieMellon called A Security Comparison: Microsoft Office vs. Oracle Openoffice and just does what it says. However, I do not particularly like the security comparison of products built solely on vulnerabilities as this shows only one side of the equation . . . → Read More: A Security Comparison: Microsoft Office vs. Oracle Openoffice

Six “New” Attack Vectors

Reading this article Six New Hacks That Will Make Your CSO Cringe made me think as it has a few fairly interesting approaches:

Fake Phone Networks: I am wondering how much work it takes to do it. If the effort is not too high, I am not (yet) too worried about it. But still, for . . . → Read More: Six “New” Attack Vectors

Security Intelligence Report v9 is online

Usually I blog intensively on the release of the Security Intelligence Report. However, this time I am out of office and have just little time to give you insight. We spent a lot of work to make it more comprehensive and give you a more stable view over quite some time. So there is a . . . → Read More: Security Intelligence Report v9 is online

How to Detect a Hacker Attack

I read an article called that way but then had to realize that it did not really address, what I expected. Why? Well, because it does not cover the key challenge in my opinion but… . . . → Read More: How to Detect a Hacker Attack

Stuxnet: Future of warfare? Or just lax security?

What is your view?: Stuxnet: Future of warfare? Or just lax security?

Roger

Advisory for the ASP.NET Vulnerability

We are basically asking the industry to follow a Coordinated Vulnerability Disclosure and are therefore not in favor of public vulnerability disclosure as it puts the industry unnecessarily at risk.

Recently there was a vulnerability in ASP.NET publically disclosed. We released an advisory and you should look into implementing the suggested workaround: Vulnerability in ASP.NET . . . → Read More: Advisory for the ASP.NET Vulnerability

The Importance of Application Security

I think I told the story thousands of time and everybody knows it but I will do it the 1001st time now . When I joined Microsoft and became what is the Chief Security Advisor for Switzerland today, we had an airlift for Windows Server 2003. The Product Manager in Switzerland asked me to keynote . . . → Read More: The Importance of Application Security

Assessing the risk of the August security updates

This month it is pretty important to read the Security Research and Defense blog post: Assessing the risk of the August security updates

It might help you to get an overview on the biggest release ever

Roger

Microsoft and Adobe: Collaboration Against Threats

You know my opinion on collaboration between countries, on public-private-partnerships as well as on collaboration between companies.

Since quite a while we run a program called MAPP – the Microsoft Active Protections Program, where we share vulnerability information with security vendors to help them to get signatures out to our joint customers the moment we . . . → Read More: Microsoft and Adobe: Collaboration Against Threats

Calendar

February 2012
M T W T F S S
« Jan    
 12345
6789101112
13141516171819
20212223242526
272829