<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://msmvps.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Tales from the Crypto - All Comments</title><link>http://msmvps.com/blogs/alunj/default.aspx</link><description>Alun Jones (&lt;a href="https://mvp.support.microsoft.com/default.aspx/profile=90B5EE92-9F9B-4B79-8288-60A3E648C8D9"&gt;Security MVP&lt;/a&gt;) writes about security, cryptography, SSL, PKI, and pretty much anything else that bothers him enough.</description><dc:language>en</dc:language><generator>CommunityServer 2008.5 SP2 (Build: 40407.4157)</generator><item><title>re: Removing capabilities from my first Windows Phone app</title><link>http://msmvps.com/blogs/alunj/archive/2013/01/22/1822996.aspx#1829459</link><pubDate>Sun, 05 May 2013 20:33:55 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1829459</guid><dc:creator>Till</dc:creator><description>&lt;p&gt;Arg, this is really annoying! Microsoft.Expression.Interactions.dll causes ID_CAP_MEDIALIB to be included as an app capability. Can´t remove it as I use GotoStateActions and useres are seriously complaining about it as the app doesn´t need access to the media library&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1829459" width="1" height="1"&gt;</description></item><item><title>re: Credential Provider update–Windows 8 SDK breaks a few things…</title><link>http://msmvps.com/blogs/alunj/archive/2013/04/07/1826789.aspx#1829101</link><pubDate>Wed, 01 May 2013 19:29:19 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1829101</guid><dc:creator>Mao</dc:creator><description>&lt;p&gt;There is actually a doc that explains the change in win8:&lt;/p&gt;
&lt;p&gt;&lt;a rel="nofollow" target="_new" href="http://download.microsoft.com/download/F/3/5/F3536898-FF3C-4548-8418-08D79555A0DB/Credential%20Provider%20Framework%20Changes%20in%20Windows%208.docx"&gt;download.microsoft.com/.../Credential%20Provider%20Framework%20Changes%20in%20Windows%208.docx&lt;/a&gt;&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1829101" width="1" height="1"&gt;</description></item><item><title>re: Why changing passwords should be done regularly</title><link>http://msmvps.com/blogs/alunj/archive/2009/11/02/1737241.aspx#1827881</link><pubDate>Sat, 20 Apr 2013 15:28:02 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1827881</guid><dc:creator>Alun Jones</dc:creator><description>&lt;p&gt;I actually suggest that people write down passwords if that allows them to remember longer and stronger passwords. Read &lt;a rel="nofollow" target="_new" href="http://msmvps.com/blogs/alunj/archive/2010/10/07/1779604.aspx"&gt;msmvps.com/.../1779604.aspx&lt;/a&gt;, for instance.&lt;/p&gt;
&lt;p&gt;In general, I suggest using an appropriate password safe - and I use one that works on my mobile phone as well as my desktop.&lt;/p&gt;
&lt;p&gt;The only challenge, then, becomes trying to find out what&amp;#39;s an &amp;#39;appropriate&amp;#39; password safe.&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1827881" width="1" height="1"&gt;</description></item><item><title>re: Why changing passwords should be done regularly</title><link>http://msmvps.com/blogs/alunj/archive/2009/11/02/1737241.aspx#1827226</link><pubDate>Sat, 13 Apr 2013 02:54:42 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1827226</guid><dc:creator>Hobo</dc:creator><description>&lt;p&gt;Of course, you ignore reality. With multiple systems having multiple password requirements in a business environment, you are creating an situation where users wind up keeping lists of passwords in drawers, under keyboards, last page of post-its...you get the idea. So, again, you have decreased security. Spend more time educating &amp;nbsp;users on strong passwords and enforcing rules on not sharing pwds. Of course, that requires more &amp;nbsp;effort and is not going to happen. Easier to just fall back on &amp;quot;best practices&amp;quot; and wash your hands of any responsibility when a breach occurs. &lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1827226" width="1" height="1"&gt;</description></item><item><title>re: Windows 7 Explorer may corrupt MP3 files</title><link>http://msmvps.com/blogs/alunj/archive/2010/03/07/1761214.aspx#1824676</link><pubDate>Tue, 05 Mar 2013 01:34:05 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1824676</guid><dc:creator>Anon</dc:creator><description>&lt;p&gt;I Have Just Had a Similar Problem. I tune amps and install radios, speakers, subs, etc. I save my testing tones on my laptop. Today I found out that Windows corrupted ALL of my test tones! X.XX MB files all turned into 4.05 KB files and are now ruined. Now I have to re-purchase All of my test tones! I&amp;#39;ve tried to recover them. The quality has been destroyed and is unusable for tuning purposes. Now I have to put my work on hold while I wait for new tuning cd&amp;#39;s to arrive.&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1824676" width="1" height="1"&gt;</description></item><item><title>re: XSS Hipster loved Scriptless XSS before it was cool</title><link>http://msmvps.com/blogs/alunj/archive/2012/12/14/1820958.aspx#1822400</link><pubDate>Wed, 09 Jan 2013 23:51:40 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1822400</guid><dc:creator>Alun Jones</dc:creator><description>&lt;p&gt;I should note that I&amp;#39;m not claiming to be the first to note that XSS isn&amp;#39;t all about JavaScript - and even if I&amp;#39;m chronologically first (which I strongly doubt), I wouldn&amp;#39;t say it&amp;#39;s sufficiently non-obvious that I didn&amp;#39;t expect other people to come up with it independently.&lt;/p&gt;
&lt;p&gt;I only gave one effective demonstration, that of injecting a &amp;lt;form&amp;gt; tag in order to direct user input such as username and password to an evil site. Mostly this is because I felt it sufficient to note that defences against Cross-Site Scripting which only paid attention to JavaScript execution, and not to the injection and escaping themselves, were bound to fail.&lt;/p&gt;
&lt;p&gt;If you want some other examples of how an attacker can attack by XSS without the use of JavaScript, &lt;a rel="nofollow" target="_new" href="http://lcamtuf.coredump.cx/postxss/"&gt;lcamtuf.coredump.cx/postxss&lt;/a&gt; is a good page. As a defender, however, you shouldn&amp;#39;t NEED more than one example.&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1822400" width="1" height="1"&gt;</description></item><item><title>re: Removing Apple Mobile Device Support</title><link>http://msmvps.com/blogs/alunj/archive/2007/12/17/1402585.aspx#1820697</link><pubDate>Tue, 11 Dec 2012 01:08:02 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1820697</guid><dc:creator>airone</dc:creator><description>&lt;p&gt;Thank You for your help Mr!!! I do not love Lackintosh at all and I wasn&amp;#39;t able to remove that invasive and useless &amp;quot;subliminal&amp;quot; applicatin, now I&amp;#39;m clean. Grazie! : )&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1820697" width="1" height="1"&gt;</description></item><item><title>re: EFS in a domain expires after three years</title><link>http://msmvps.com/blogs/alunj/archive/2007/03/24/efs-in-a-domain-expires-after-three-years.aspx#1819098</link><pubDate>Mon, 12 Nov 2012 16:07:19 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1819098</guid><dc:creator>Bob</dc:creator><description>&lt;p&gt;One of the first things Mat does when he joins a new company is to audit everything he can, which doesn&amp;#39;t take long. Sounds like a pretty thorough audit that, or a conveniently small company.&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1819098" width="1" height="1"&gt;</description></item><item><title>re: Changing passwords on a service, part 3</title><link>http://msmvps.com/blogs/alunj/archive/2012/02/11/1805909.aspx#1817326</link><pubDate>Tue, 25 Sep 2012 23:53:09 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1817326</guid><dc:creator>Nik</dc:creator><description>&lt;p&gt;Comrade Alun,&lt;/p&gt;
&lt;p&gt;Greetings from Russia! Nice post about changing passwords on a Windows service. &lt;/p&gt;
&lt;p&gt;If running as Local System, of course, service is going across as the computer account, and if computer account has any modify access in Active Directory, great place to start an &amp;lt;a href=&amp;quot;&lt;a rel="nofollow" target="_new" href="http://www.active-directory-privilege-escalation-security-risks.com/"&gt;www.active-directory-privilege-escalation-security-risks.com&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&amp;quot;&amp;gt;Active Directory Privilege Escalation attack&amp;lt;/a&amp;gt; - wouldn&amp;#39;t you agree comrade? ;-)&lt;/p&gt;
&lt;p&gt;Thought I would give you something to think about. &lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1817326" width="1" height="1"&gt;</description></item><item><title>re: Windows 7 Explorer may corrupt MP3 files</title><link>http://msmvps.com/blogs/alunj/archive/2010/03/07/1761214.aspx#1816179</link><pubDate>Tue, 11 Sep 2012 22:35:01 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1816179</guid><dc:creator>JOhn</dc:creator><description>&lt;p&gt;I realize this is an old thread, but this has been driving me crazy for months. An Mp3 might have 1 second from another track. The size of the copied file is exactly the same. Just a bit of bad data.&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1816179" width="1" height="1"&gt;</description></item><item><title>re: Black Hat with Amazon.com–2011 Code Challenges II</title><link>http://msmvps.com/blogs/alunj/archive/2011/08/09/1797406.aspx#1815688</link><pubDate>Thu, 30 Aug 2012 21:19:33 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1815688</guid><dc:creator>carlos</dc:creator><description>&lt;p&gt;Only a year late, but I can&amp;#39;t resist a challenge! &amp;nbsp;Did you ever post the answers anywhere? &amp;nbsp;Here&amp;#39;s my take anyway.&lt;/p&gt;
&lt;p&gt;II: Broken with negative numbers, e.g. &amp;quot;-1.2&amp;quot; gives -0.8.&lt;/p&gt;
&lt;p&gt;III: Sets auth tokens before validating the user. &amp;nbsp;If the caller doesn&amp;#39;t check the status correctly the user could be logged in with a bogus password.&lt;/p&gt;
&lt;p&gt;IV: The boolean expression should be disjunctive.&lt;/p&gt;
&lt;p&gt;V: Assuming there isn&amp;#39;t a load of external synchronization between the two functions, there&amp;#39;s no connection between the user and the command they want to execute. &amp;nbsp;Global variables combined with multithreading have a very bad smell.&lt;/p&gt;
&lt;p&gt;Oh yeah, and I: It&amp;#39;s Perl :)&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1815688" width="1" height="1"&gt;</description></item><item><title>re: Multiple CA0053 errors with Visual Studio 11 Beta</title><link>http://msmvps.com/blogs/alunj/archive/2012/03/04/1806901.aspx#1815332</link><pubDate>Tue, 21 Aug 2012 07:37:34 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1815332</guid><dc:creator>John</dc:creator><description>&lt;p&gt;Thanks!&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1815332" width="1" height="1"&gt;</description></item><item><title>re: Multiple CA0053 errors with Visual Studio 11 Beta</title><link>http://msmvps.com/blogs/alunj/archive/2012/03/04/1806901.aspx#1815266</link><pubDate>Sat, 18 Aug 2012 20:07:39 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1815266</guid><dc:creator>Terje Sandstrom</dc:creator><description>&lt;p&gt;Added a tool to fix this in multiple files.&lt;/p&gt;
&lt;p&gt;See &lt;a rel="nofollow" target="_new" href="http://visualstudiogallery.msdn.microsoft.com/471da13b-d415-4a44-a4e9-a8222316b902"&gt;visualstudiogallery.msdn.microsoft.com/471da13b-d415-4a44-a4e9-a8222316b902&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Blogpost at &lt;a rel="nofollow" target="_new" href="http://tinyurl.com/9q8nnvh"&gt;http://tinyurl.com/9q8nnvh&lt;/a&gt;&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1815266" width="1" height="1"&gt;</description></item><item><title>re: Multiple CA0053 errors with Visual Studio 11 Beta</title><link>http://msmvps.com/blogs/alunj/archive/2012/03/04/1806901.aspx#1815232</link><pubDate>Fri, 17 Aug 2012 21:14:31 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1815232</guid><dc:creator>Jonathan</dc:creator><description>&lt;p&gt;excellent, same issue with the RTM version&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1815232" width="1" height="1"&gt;</description></item><item><title>re: Error: Insufficient system resources exist to complete the API.</title><link>http://msmvps.com/blogs/alunj/archive/2006/07/26/105879.aspx#1813765</link><pubDate>Sat, 28 Jul 2012 18:25:04 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1813765</guid><dc:creator>Er. Gopal Malviya</dc:creator><description>&lt;p&gt;please delete hibernate file from your hard drive c: before do this disable hibernate option&lt;/p&gt;
&lt;p&gt;after restart the system enable hibernate option &lt;/p&gt;
&lt;p&gt;and enjoy with hibernating....&lt;/p&gt;
&lt;p&gt;Thanks&lt;/p&gt;
&lt;p&gt;Gopal Malviya&lt;/p&gt;
&lt;p&gt;9893469598&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1813765" width="1" height="1"&gt;</description></item><item><title>re: How FTP Data Connections Work Part 2 (OR: Fun With Port 20)</title><link>http://msmvps.com/blogs/alunj/archive/2009/07/13/1700796.aspx#1813374</link><pubDate>Mon, 23 Jul 2012 20:32:16 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1813374</guid><dc:creator>JB</dc:creator><description>&lt;p&gt;Interesting read, although with a recent problem with FTP from a single server ( other servers were fine ) , the FTP would only work if ALG was disabled from the client RRAS server. &lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1813374" width="1" height="1"&gt;</description></item><item><title>re: Why changing passwords should be done regularly</title><link>http://msmvps.com/blogs/alunj/archive/2009/11/02/1737241.aspx#1812687</link><pubDate>Wed, 11 Jul 2012 06:06:13 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1812687</guid><dc:creator>Craig Anderson</dc:creator><description>&lt;p&gt;So changing my password protects the system from me, rather than from outside hackers. &amp;nbsp;I don&amp;#39;t particularly like that, but it&amp;#39;s reasonable.&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1812687" width="1" height="1"&gt;</description></item><item><title>re: Multiple CA0053 errors with Visual Studio 11 Beta</title><link>http://msmvps.com/blogs/alunj/archive/2012/03/04/1806901.aspx#1810494</link><pubDate>Fri, 01 Jun 2012 05:25:22 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1810494</guid><dc:creator>Dave</dc:creator><description>&lt;p&gt;The internet is most grateful&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1810494" width="1" height="1"&gt;</description></item><item><title>re: Stupid Outlook 2007 RSS Feed Workaround</title><link>http://msmvps.com/blogs/alunj/archive/2009/07/04/1698000.aspx#1810480</link><pubDate>Thu, 31 May 2012 19:32:24 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1810480</guid><dc:creator>Robbie</dc:creator><description>&lt;p&gt;Here is another DUMB workaround (or maybe just a restatement of what you said?). I ignorantly thought I could add these feeds from the File/Data File Management/RSS buttons and manually entering them. All I got was &amp;quot;pended&amp;quot; and then gone. Workaround? RIGHT CLICK the RSS feeds button in the Navigation Pane on the left. Then paste the link in the EXACT SAME D@MN BOX and lo and behold- it works perfectly. Priceless Microsoft. Priceless.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1810480" width="1" height="1"&gt;</description></item><item><title>re: Windows 7 Explorer may corrupt MP3 files</title><link>http://msmvps.com/blogs/alunj/archive/2010/03/07/1761214.aspx#1810127</link><pubDate>Tue, 22 May 2012 21:19:02 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1810127</guid><dc:creator>dix</dc:creator><description>&lt;p&gt;Same issue here - with the garbled mp3 situation (random bits of other songs, usually located &amp;quot;nearby&amp;quot; on the file hierarchy, but always from another folder, being inserted into otherwise fine mp3&amp;#39;s). I had recently undertaken a big tag cleanup, and thought that perhaps that, or the fact I had the songs stored on an external drive, may be causing the error...but I can&amp;#39;t duplicate, and other data on the hard drive seems fine.&lt;/p&gt;
&lt;p&gt;I wonder if anyone here has tried to find *what* mp3&amp;#39;s are corrupted out of possibly thousands without listening to every one, when the problem isn&amp;#39;t zeroing out, but insertion of random data?&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1810127" width="1" height="1"&gt;</description></item></channel></rss>