MSMVPS.COM
The Ultimate Destination for Blogs by Current and Former Microsoft Most Valuable Professionals.

Browse Site by Tags

Showing related tags and posts accross the entire site.
  • The difference between liking and hating UAC?

    Totally unscientifically, I have carried out a poll of people who like UAC (okay, a few security geeks like myself), and those who hate UAC - mostly my wife. Something struck me as both a surprising common factor, and also a rather obvious explanation of why the two opinions are so polarised. [Note for...
    Posted to Tales from the Crypto (Weblog) by Alun Jones on 06-10-2008
    Filed under: General Security, Windows Vista, What my wife knows, UAC
  • Searching for Weak Debian / Ubuntu SSL Certificates

    I've seen a number of people promote packages that have shipped for Debian and Ubuntu, which allow users to scan their collected keys - OpenSSH or OpenSSL or OpenVPN, to discover whether they're too weak to be of any functional use. [See my earlier story on Debian and the OpenSSL PRNG ] These...
    Posted to Tales from the Crypto (Weblog) by Alun Jones on 05-22-2008
    Filed under: General Security, Programmer Hubris, Why is PKI so hard?, Alun's code
  • Debian and the OpenSSL PRNG

    [PRNG is an abbreviation for "Pseudo-Random Number Generator", a key core component of the key-generation in any cryptographic library.] A few people have already commented on the issue itself - Debian issued, in 2006, a version of their Linux build that contained a modified version of OpenSSL...
    Posted to Tales from the Crypto (Weblog) by Alun Jones on 05-15-2008
    Filed under: General Security, Programmer Hubris, Why is PKI so hard?
  • Change the Administrator account name?

    Religious debates are rarely clean or pretty. The same is true in all spheres, whether debating Christianity against Islam, Linux against Windows, or Cagney vs Lacey. In security, there are a few divisive issues that are always going to crop up. Is your datacentre network trustworthy enough to pump secret...
    Posted to Tales from the Crypto (Weblog) by Alun Jones on 05-14-2008
    Filed under: General Security
  • In Defence of the Self-Signed Certificate

    Recently I discussed using EFS as a simple, yet reliable, form of file encryption. Among the doubts raised was the following from an article by fellow MVP Deb Shinder on EFS: EFS generates a self-signed certificate. However, there are problems inherent in using self-signed certificates: Unlike a certificate...
    Posted to Tales from the Crypto (Weblog) by Alun Jones on 05-10-2008
    Filed under: General Security, Why is PKI so hard?, EFS
  • Apple Changes Update Policies - Still No Biscuit

    As I have mentioned in other posts ( Retro-bundling - another suck of the Apple , MacBook Air debuts; iTunes Pesters Me Again , Removing Apple Mobile Device Support , I didn't want iTunes - now I've got iPod, too? , etc, etc), this has long since stopped being an issue for me, because I've...
    Posted to Tales from the Crypto (Weblog) by Alun Jones on 05-09-2008
    Filed under: General Security, Programmer Hubris
  • Think like a bad guy? It's a start.

    Cool new site (and blog ) from Microsoft - http://securedeveloper.com - and it has a tag line I've heard many times before: Like that old maxim that "you need to stop fighting fires long enough to tell the architects to stop building things out of wood", thinking like a bad guy is just...
    Posted to Tales from the Crypto (Weblog) by Alun Jones on 05-06-2008
    Filed under: General Security, Programmer Hubris
  • Security Koan #3

    The security guard phoned his boss in a panic. "There's been a break-in to the site, sir. The intruders aren't anywhere to be seen, but they've got away with a bunch of equipment." "Understood - go and look at the perimeter fence, find out where they broke in, and keep watch...
    Posted to Tales from the Crypto (Weblog) by Alun Jones on 05-02-2008
    Filed under: General Security
  • UAC - The Emperor's New Clothes

    I heard a complaint the other day about UAC - User Account Control - that was new to me. Let's face it, as a Security MVP, I hear a lot of complaints about UAC - not least from my wife, who isn't happy with the idea that she can be logged on as an administrator, but she isn't really an administrator...
    Posted to Tales from the Crypto (Weblog) by Alun Jones on 04-24-2008
    Filed under: General Security, Things I Learned At Microsoft, Windows Vista, What my wife knows, Windows Server 2008
  • Silently fixing security bugs - how dare they!

    Over in " Random Things from Dark Places ", Hellnbak posts about reducing vulnerability counts by applying the SDL (Security Development Lifecycle), and makes the very reasonable point that vulnerabilities found prior to release by a scan that is part of the SDL process cannot be counted as...
    Posted to Tales from the Crypto (Weblog) by Alun Jones on 04-22-2008
    Filed under: General Security, Things I Learned At Microsoft
Page 1 of 18 (175 items) 1 2 3 4 5 Next > ... Last »


Copyright © is the original authors. Blog site is an independent site not sponsored by Microsoft. The Yoda blog server and the Brianna SQL server would like to thank www.ownwebnow.com and www.exchangedefender.com. They wouldn't be here and broadcasting without the generosity of Vlad Mazek and his companies.

Powered by Community Server (Commercial Edition), by Telligent Systems