<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://msmvps.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Jesper Johansson's Blog</title><link>http://msmvps.com/blogs/jesper/default.aspx</link><description>This is a mirror of the blog located at http://msinfluentials.com/blogs/jesper/Default.aspx</description><dc:language>en</dc:language><generator>CommunityServer 2008.5 SP2 (Build: 40407.4157)</generator><item><title>Fake Anti-Malware is Apparently Microsoft's Fault</title><link>http://msmvps.com/blogs/jesper/archive/2009/10/24/fake-anti-malware-is-apparently-microsoft-s-fault.aspx</link><pubDate>Sat, 24 Oct 2009 17:20:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1734828</guid><dc:creator>Jesper's Blog</dc:creator><slash:comments>0</slash:comments><description>Munir Kotadia, an IT Journalist in Australia, has finally managed to figure out how to blame Microsoft for the fake anti-malware epidemic. Apparently, the reason is that &amp;quot;Microsoft could save the world from fake security applications by introducing...(&lt;a href="http://msmvps.com/blogs/jesper/archive/2009/10/24/fake-anti-malware-is-apparently-microsoft-s-fault.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1734828" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/jesper/archive/tags/Security+Pontification/default.aspx">Security Pontification</category></item><item><title>How Delegation Privileges Are Represented In Active Directory</title><link>http://msmvps.com/blogs/jesper/archive/2009/10/20/how-delegation-privileges-are-represented-in-active-directory.aspx</link><pubDate>Wed, 21 Oct 2009 04:21:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1733882</guid><dc:creator>Jesper's Blog</dc:creator><slash:comments>0</slash:comments><description>One of the last areas where more tool support is needed is in monitoring the various attributes in Active Directory (AD). Recently I got curious about the delegation flags, and, more to the point, how to tell which accounts have been trusted for delegation...(&lt;a href="http://msmvps.com/blogs/jesper/archive/2009/10/20/how-delegation-privileges-are-represented-in-active-directory.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1733882" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/jesper/archive/tags/Windows+Security/default.aspx">Windows Security</category></item><item><title>Web Of Trust: RIP</title><link>http://msmvps.com/blogs/jesper/archive/2009/10/14/web-of-trust-rip.aspx</link><pubDate>Wed, 14 Oct 2009 05:16:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1732277</guid><dc:creator>Jesper's Blog</dc:creator><slash:comments>0</slash:comments><description>It&amp;#39;s official. I just received an e-mail from Thawte notifying me that, as of November 16, 2009, the most innovative and useful idea in PKI since its inception, the Web of Trust , will die. Thawte was founded 14 years ago by Mark Shuttleworth. The...(&lt;a href="http://msmvps.com/blogs/jesper/archive/2009/10/14/web-of-trust-rip.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1732277" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/jesper/archive/tags/Security+Pontification/default.aspx">Security Pontification</category><category domain="http://msmvps.com/blogs/jesper/archive/tags/Thinking+differently/default.aspx">Thinking differently</category></item><item><title>Passwords are here to stay</title><link>http://msmvps.com/blogs/jesper/archive/2009/10/11/passwords-are-here-to-stay.aspx</link><pubDate>Sun, 11 Oct 2009 05:54:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1731533</guid><dc:creator>Jesper's Blog</dc:creator><slash:comments>0</slash:comments><description>At least for the short to medium term. That is the, quite obvious, conclusion drawn in a Newsweek article entitled &amp;quot;Building a Better Password.&amp;quot; The article goes inside the CyLab at Carnegie-Mellon University to understand how passwords may...(&lt;a href="http://msmvps.com/blogs/jesper/archive/2009/10/11/passwords-are-here-to-stay.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1731533" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/jesper/archive/tags/Security/default.aspx">Security</category></item><item><title>And finally, standard user malware</title><link>http://msmvps.com/blogs/jesper/archive/2009/09/01/and-finally-standard-user-malware.aspx</link><pubDate>Tue, 01 Sep 2009 06:21:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1719824</guid><dc:creator>Jesper's Blog</dc:creator><slash:comments>0</slash:comments><description>Today I finally got wind of my first piece of true standard user malware. MS Antispyware 2008 has turned standard user. The version in question installs the binaries in c:\documents and settings\all users\application data\&amp;lt;something&amp;gt;, and makes...(&lt;a href="http://msmvps.com/blogs/jesper/archive/2009/09/01/and-finally-standard-user-malware.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1719824" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/jesper/archive/tags/Security/default.aspx">Security</category><category domain="http://msmvps.com/blogs/jesper/archive/tags/Security+Pontification/default.aspx">Security Pontification</category><category domain="http://msmvps.com/blogs/jesper/archive/tags/Least+Privilege/default.aspx">Least Privilege</category></item><item><title>Microsoft Poland Empowers White People</title><link>http://msmvps.com/blogs/jesper/archive/2009/08/26/microsoft-poland-empowers-white-people.aspx</link><pubDate>Wed, 26 Aug 2009 05:53:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1718237</guid><dc:creator>Jesper's Blog</dc:creator><slash:comments>0</slash:comments><description>In an absolutely astonishing move Microsoft&amp;#39;s Polish subsidiary decided to do some photoshopping on its Business Productivity Infrastructure page to tailor it to the Polish market. Here you can see the U.S. original . In one of the least sensitive...(&lt;a href="http://msmvps.com/blogs/jesper/archive/2009/08/26/microsoft-poland-empowers-white-people.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1718237" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/jesper/archive/tags/Thinking+differently/default.aspx">Thinking differently</category></item><item><title>Is it ActiveX that is the problem?</title><link>http://msmvps.com/blogs/jesper/archive/2009/08/09/is-it-activex-that-is-the-problem.aspx</link><pubDate>Sun, 09 Aug 2009 20:04:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1714573</guid><dc:creator>Jesper's Blog</dc:creator><slash:comments>0</slash:comments><description>Last week, an expert from Verizon, nee Cybertrust, posted a note about the Active Template Library (ATL) security vulnerability over on the Verizon Business Security Blog . For home users, the phone company now advises you to use a different browser,...(&lt;a href="http://msmvps.com/blogs/jesper/archive/2009/08/09/is-it-activex-that-is-the-problem.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1714573" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/jesper/archive/tags/Security+Pontification/default.aspx">Security Pontification</category></item><item><title>Warning: The software you are installing does not match your mental model</title><link>http://msmvps.com/blogs/jesper/archive/2009/07/21/warning-the-software-you-are-installing-does-not-match-your-mental-model.aspx</link><pubDate>Tue, 21 Jul 2009 05:10:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1709954</guid><dc:creator>Jesper's Blog</dc:creator><slash:comments>0</slash:comments><description>This morning I talked to my dad. After a few minutes of polite small talk, I heard the 10 little words I have come to dread: &amp;ldquo;I had some problems with my computer the other day.&amp;rdquo; The video card on his laptop had died. The screen was just black...(&lt;a href="http://msmvps.com/blogs/jesper/archive/2009/07/21/warning-the-software-you-are-installing-does-not-match-your-mental-model.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1709954" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/jesper/archive/tags/Thinking+differently/default.aspx">Thinking differently</category></item><item><title>Steve Riley Lands On His Feet</title><link>http://msmvps.com/blogs/jesper/archive/2009/07/10/steve-riley-lands-on-his-feet.aspx</link><pubDate>Fri, 10 Jul 2009 23:13:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1709955</guid><dc:creator>Jesper's Blog</dc:creator><slash:comments>0</slash:comments><description>In May, in one of the more inexplicable moves this year, Microsoft laid off my good friend Steve Riley, four days before he was to deliver half a dozen presentations at TechEd. Fortunately, it did not take Steve long to find a new gig. This Monday, he...(&lt;a href="http://msmvps.com/blogs/jesper/archive/2009/07/10/steve-riley-lands-on-his-feet.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1709955" width="1" height="1"&gt;</description></item><item><title>A better, more reliable, work-around for the Microsoft Video Control Vulnerability</title><link>http://msmvps.com/blogs/jesper/archive/2009/07/10/a-better-more-reliable-work-around-for-the-microsoft-video-control-vulnerability.aspx</link><pubDate>Fri, 10 Jul 2009 06:09:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1709956</guid><dc:creator>Jesper's Blog</dc:creator><slash:comments>0</slash:comments><description>For the past few days I&amp;#39;ve been following the Microsoft Video Control Vulnerability with interest. Basically, it&amp;#39;s another vulnerable ActiveX control that needs killbitted. Last night, Microsoft posted a work-around which involves using a Group...(&lt;a href="http://msmvps.com/blogs/jesper/archive/2009/07/10/a-better-more-reliable-work-around-for-the-microsoft-video-control-vulnerability.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1709956" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/jesper/archive/tags/Windows+Security/default.aspx">Windows Security</category><category domain="http://msmvps.com/blogs/jesper/archive/tags/Windows+Vista/default.aspx">Windows Vista</category><category domain="http://msmvps.com/blogs/jesper/archive/tags/Mitigations/default.aspx">Mitigations</category><category domain="http://msmvps.com/blogs/jesper/archive/tags/Windows+Server+2008/default.aspx">Windows Server 2008</category></item><item><title>Are Identity Theft Services Worth The Cost?</title><link>http://msmvps.com/blogs/jesper/archive/2009/03/23/are-identity-theft-services-worth-the-cost.aspx</link><pubDate>Tue, 24 Mar 2009 04:01:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1680843</guid><dc:creator>Jesper's Blog</dc:creator><slash:comments>0</slash:comments><description>The Consumer Federation of America just published a report on identity theft services entitled &amp;quot; Are Identity Theft Services Worth The Cost? &amp;quot; The conclusion is that many are not, and that regulation is needed in that industry. It is a very...(&lt;a href="http://msmvps.com/blogs/jesper/archive/2009/03/23/are-identity-theft-services-worth-the-cost.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1680843" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/jesper/archive/tags/Privacy/default.aspx">Privacy</category></item><item><title>Please do not e-mail my social security number</title><link>http://msmvps.com/blogs/jesper/archive/2009/01/27/please-do-not-e-mail-my-social-security-number.aspx</link><pubDate>Wed, 28 Jan 2009 05:38:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1666496</guid><dc:creator>Jesper's Blog</dc:creator><slash:comments>0</slash:comments><description>Recently I had a very interesting incident. I wrote an article some time in 2008 and the publisher paid me a little bit of money for it. That means the publisher must send a report to the Internal Revenue Service (IRS - the U.S. tax department) reporting...(&lt;a href="http://msmvps.com/blogs/jesper/archive/2009/01/27/please-do-not-e-mail-my-social-security-number.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1666496" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/jesper/archive/tags/Security/default.aspx">Security</category><category domain="http://msmvps.com/blogs/jesper/archive/tags/Security+Pontification/default.aspx">Security Pontification</category></item><item><title>Kip Hawley: "No, the TSA is Necessary Because This is War!"</title><link>http://msmvps.com/blogs/jesper/archive/2008/12/24/kip-hawley-quot-no-the-tsa-is-necessary-because-this-is-war-quot.aspx</link><pubDate>Wed, 24 Dec 2008 10:44:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1657653</guid><dc:creator>Jesper's Blog</dc:creator><slash:comments>0</slash:comments><description>CBS News did a story a few days ago on the Transportation Security Administration (TSA). Basically it was a tit-for-tat between Bruce Schneier , security pontificator extraordinaire, and Kip Hawley, the administrator of the TSA. Mr. Hawley&amp;#39;s maintans...(&lt;a href="http://msmvps.com/blogs/jesper/archive/2008/12/24/kip-hawley-quot-no-the-tsa-is-necessary-because-this-is-war-quot.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1657653" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/jesper/archive/tags/Security+Pontification/default.aspx">Security Pontification</category></item><item><title>One "Hacker" Attempts to Rule The World</title><link>http://msmvps.com/blogs/jesper/archive/2008/12/24/one-quot-hacker-quot-attempts-to-rule-the-world.aspx</link><pubDate>Wed, 24 Dec 2008 10:40:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1657654</guid><dc:creator>Jesper's Blog</dc:creator><slash:comments>0</slash:comments><description>Wired, always a source for amusement and interesting literature, just carried a story on a &amp;quot;hacker&amp;quot; (the magazine&amp;#39;s use of the term equates to &amp;quot;criminal&amp;quot;) who attempted to dominate the market in stolen credit cards. It&amp;#39;s a...(&lt;a href="http://msmvps.com/blogs/jesper/archive/2008/12/24/one-quot-hacker-quot-attempts-to-rule-the-world.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1657654" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/jesper/archive/tags/Security+Pontification/default.aspx">Security Pontification</category></item><item><title>You need to manually undo your MS08-078 mitigations</title><link>http://msmvps.com/blogs/jesper/archive/2008/12/18/you-need-to-manually-undo-your-ms08-078-mitigations.aspx</link><pubDate>Thu, 18 Dec 2008 17:57:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1657155</guid><dc:creator>Jesper's Blog</dc:creator><slash:comments>0</slash:comments><description>Normal 0 false false false EN-US X-NONE X-NONE MicrosoftInternetExplorer4 &amp;lt;!-- /* Font Definitions */ @font-face {font-family:&amp;quot;Cambria Math&amp;quot;; panose-1:2 4 5 3 5 4 6 3 2 4; mso-font-alt:&amp;quot;Calisto MT&amp;quot;; mso-font-charset:0; mso-generic...(&lt;a href="http://msmvps.com/blogs/jesper/archive/2008/12/18/you-need-to-manually-undo-your-ms08-078-mitigations.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1657155" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/jesper/archive/tags/Windows+Security/default.aspx">Windows Security</category><category domain="http://msmvps.com/blogs/jesper/archive/tags/Windows+Vista/default.aspx">Windows Vista</category><category domain="http://msmvps.com/blogs/jesper/archive/tags/Mitigations/default.aspx">Mitigations</category></item><item><title>Lock your USB Token</title><link>http://msmvps.com/blogs/jesper/archive/2008/12/16/lock-your-usb-token.aspx</link><pubDate>Tue, 16 Dec 2008 07:10:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1656835</guid><dc:creator>Jesper's Blog</dc:creator><slash:comments>0</slash:comments><description>Recently, Lev Bolotin of Clevx gave me a production sample of a USB token with a keypad on it. It&amp;#39;s a pretty neat idea for certain uses. My immediate thought went to BitLocker in Windows Vista. You can store the BitLocker key on a USB stick, but you...(&lt;a href="http://msmvps.com/blogs/jesper/archive/2008/12/16/lock-your-usb-token.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1656835" width="1" height="1"&gt;</description></item><item><title>Believe it or not; DRM for Zune is down!</title><link>http://msmvps.com/blogs/jesper/archive/2008/12/16/believe-it-or-not-drm-for-zune-is-down.aspx</link><pubDate>Tue, 16 Dec 2008 06:21:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1656836</guid><dc:creator>Jesper's Blog</dc:creator><slash:comments>0</slash:comments><description>Shocking, yes, I know, but in only four hours this evening Microsoft has managed to alienate over 150 additional customers with its insistence on Digital Rights Management (DRM). This time it is the DRM component of the Zune store that is down, according...(&lt;a href="http://msmvps.com/blogs/jesper/archive/2008/12/16/believe-it-or-not-drm-for-zune-is-down.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1656836" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/jesper/archive/tags/Security+Pontification/default.aspx">Security Pontification</category></item><item><title>What do you think, should I do it?</title><link>http://msmvps.com/blogs/jesper/archive/2008/11/16/what-do-you-think-should-i-do-it.aspx</link><pubDate>Sun, 16 Nov 2008 16:44:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1654260</guid><dc:creator>Jesper's Blog</dc:creator><slash:comments>0</slash:comments><description>I get a fair bit of blog spam - comments advertising everything from sexual enhancers to fake anti-malware. This one just came in this morning: Sweet! I can turn off all the blog spam just by e-mailing the criminals? Or, could it possibly be that this...(&lt;a href="http://msmvps.com/blogs/jesper/archive/2008/11/16/what-do-you-think-should-i-do-it.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1654260" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/jesper/archive/tags/Security+Pontification/default.aspx">Security Pontification</category></item><item><title>Fun Experiences at Airport Security</title><link>http://msmvps.com/blogs/jesper/archive/2008/11/15/fun-experiences-at-airport-security.aspx</link><pubDate>Sat, 15 Nov 2008 16:13:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1654207</guid><dc:creator>Jesper's Blog</dc:creator><slash:comments>0</slash:comments><description>For a while I&amp;#39;ve been thinking about writing something about interesting times I&amp;#39;ve had at various airport security checkpoints; security theater, as they have come to be known. There is the obvious shoe removal arguments and the ill-defined rules...(&lt;a href="http://msmvps.com/blogs/jesper/archive/2008/11/15/fun-experiences-at-airport-security.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1654207" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/jesper/archive/tags/Security+Pontification/default.aspx">Security Pontification</category></item><item><title>XP Antivirus in the News</title><link>http://msmvps.com/blogs/jesper/archive/2008/11/07/xp-antivirus-in-the-news.aspx</link><pubDate>Fri, 07 Nov 2008 10:05:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1653375</guid><dc:creator>Jesper's Blog</dc:creator><slash:comments>0</slash:comments><description>Several helpful people just pointed me to some articles on XP Antivirus and its various variants. In case you do not remember, XP Antivirus was the subject of an article I wrote for The Register a few months back. It turns out that the scammers got hacked...(&lt;a href="http://msmvps.com/blogs/jesper/archive/2008/11/07/xp-antivirus-in-the-news.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1653375" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/jesper/archive/tags/Windows+Security/default.aspx">Windows Security</category></item></channel></rss>