<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://msinfluentials.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Jesper's Blog</title><link>http://msinfluentials.com/blogs/jesper/default.aspx</link><description>&lt;table&gt;&lt;tr&gt;&lt;td&gt;
	&lt;p align="center"&gt;&lt;font size="2"&gt;Obligatory file photo:&lt;/font&gt;&lt;br /&gt;
		&lt;img src="https://msinfluentials.com/blogs/jesper/jesper-new45x60.jpg" width="97" height="131" alt="" /&gt;&lt;/td&gt;&lt;td&gt;
		&lt;font face="Arial"&gt;Welcome to Jesper Johansson&amp;#39;s blog. This is my home for pontification on the web. In case this is your first time here, I have been working on information security for about 20 years, and have been writing and speaking on the topic for about 10. I am also a &lt;a href="https://mvp.support.microsoft.com/profile/Jesper"&gt;Microsoft MVP&lt;/a&gt; in Windows Security. &lt;br /&gt;My most recent book is the &lt;b&gt;Windows Server 2008 Security Resource Kit
		&lt;/b&gt;. Because I am also a scuba instructor you may find some posts related to that topic as well.  
		Just because it took me so long to get it, I also like to say that I 
		have a Ph.D. in Management Information Systems from the University of 
		Minnesota. &lt;/font&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;</description><dc:language>en</dc:language><generator>CommunityServer 2008.5 SP2 (Build: 40407.4157)</generator><item><title>2010 PADI Instructor Manual Available Online Now</title><link>http://msinfluentials.com/blogs/jesper/archive/2010/02/11/2010-padi-instructor-manual-available-online-now.aspx</link><pubDate>Fri, 12 Feb 2010 05:52:00 GMT</pubDate><guid isPermaLink="false">91db4bc3-5a69-4a9f-94bf-eedb569902ab:22037</guid><dc:creator>jesper</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msinfluentials.com/blogs/jesper/rsscomments.aspx?PostID=22037</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msinfluentials.com/blogs/jesper/commentapi.aspx?PostID=22037</wfw:comment><comments>http://msinfluentials.com/blogs/jesper/archive/2010/02/11/2010-padi-instructor-manual-available-online-now.aspx#comments</comments><description>&lt;p&gt;&lt;strong&gt;Update February 15, 2010&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;PADI has finally locked down access to the members site to users who are actually PADI members, making the instructor manual unavailable unless you are a member. Apparently it was not supposed to be publicly available even though the authentication system on the site was reported broken over two years ago and it has been wide open until now.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Original Post:&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;If you are a PADI dive professional, or are considering being one, you may be interested in the &lt;a href="http://www.padimembers.com/members/shared/digitalinstructormanual/default.htm"&gt;2010 Digital Instructor Manual&lt;/a&gt;. PADI graciously posted it online for free, allowing anyone, not just instructors, to access it. If you are interested in taking the instructor exam this year, this is great news since it saves you the money it used to cost to buy the manual.&lt;/p&gt;
&lt;p&gt;The new version of the manual contains all the standards but not all the details on how to teach the courses that used to be in the manual in the past. Those are now in separate guides instead. &lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msinfluentials.com/aggbug.aspx?PostID=22037" width="1" height="1"&gt;</description><category domain="http://msinfluentials.com/blogs/jesper/archive/tags/Diving/default.aspx">Diving</category></item><item><title>Fake Anti-Malware is Apparently Microsoft's Fault</title><link>http://msinfluentials.com/blogs/jesper/archive/2009/10/24/fake-anti-malware-is-apparently-microsoft-s-fault.aspx</link><pubDate>Sat, 24 Oct 2009 17:20:00 GMT</pubDate><guid isPermaLink="false">91db4bc3-5a69-4a9f-94bf-eedb569902ab:21965</guid><dc:creator>jesper</dc:creator><slash:comments>4</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msinfluentials.com/blogs/jesper/rsscomments.aspx?PostID=21965</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msinfluentials.com/blogs/jesper/commentapi.aspx?PostID=21965</wfw:comment><comments>http://msinfluentials.com/blogs/jesper/archive/2009/10/24/fake-anti-malware-is-apparently-microsoft-s-fault.aspx#comments</comments><description>&lt;p&gt;Munir Kotadia, an IT Journalist in Australia, has finally managed to figure out how to blame Microsoft for the fake anti-malware epidemic. Apparently, the reason is that&lt;a href="http://www.itnews.com.au/News/158689,commentary-microsoft-can-help-kill-fake-antivirus-threat.aspx"&gt; &amp;quot;Microsoft could save the world from fake security applications by introducing a whitelist for apps from legitimate security firms&amp;quot;&lt;/a&gt;&amp;nbsp;and, presumably, has neglected to do so out of sheer malice.&lt;/p&gt;
&lt;p&gt;I&amp;#39;m clearly not a thinker at the same level as Munir; maybe that is why I don&amp;#39;t fully get this white list he proposes. Does he want one only of security software? How would you identify security software? I can see only two ways. The first is to detect software that behaves like security software. If you scan files for viruses, hook certain APIs, quarantine things occassionally, and throw frequent&amp;nbsp;incomprehensible warnings, you must be security software. The problem is, the fake ones only do the latter of those four. If you use heuristic detection of security software it would be absolutely trivial for the fake packages to not trip the warnings. They just have to&amp;nbsp;avoid behaving like security software. Of course, if they actually DID behave like security software, we would not have this problem, would we? &lt;/p&gt;
&lt;p&gt;&amp;nbsp;The second approach I can think of is&amp;nbsp;to have&amp;nbsp;all security software to identify themselves as such, both the fake and the real. They could set some bit in the application manifest, the file which describes the application. I propose that it should look like this:&lt;/p&gt;
&lt;p&gt;&lt;span style="font-family:Courier New;"&gt;&amp;lt;?xml version=&amp;quot;1.0&amp;quot; encoding=&amp;quot;UTF-8&amp;quot; standalone=&amp;quot;yes&amp;quot;?&amp;gt;&lt;br /&gt;&amp;lt;assembly xmlns=&amp;quot;urn:schemas-microsoft-com:asm.v1&amp;quot; manifestVersion=&amp;quot;1.0&amp;quot;&amp;gt;&lt;br /&gt;&amp;nbsp; &amp;lt;assemblyIdentity type=&amp;quot;win32&amp;quot; &lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; name=&amp;quot;RBU.FakeAntiMalware.MyCurrentVersion&amp;quot; &lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; version=&amp;quot;6.0.0.0&amp;quot; &lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; processorArchitecture=&amp;quot;x86&amp;quot; &lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; publicKeyToken=&amp;quot;0000000000000000&amp;quot;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family:Courier New;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;strong&gt;securitySoftware=&amp;quot;True&amp;quot;&lt;/strong&gt;&lt;br /&gt;&amp;nbsp; /&amp;gt;&lt;br /&gt;&amp;lt;/assembly&amp;gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;Note the flag in the manifest above that identifies this package as security software. Now Microsoft can just&amp;nbsp;compare the name of the package against a list of known good software and if it does not match, block it. This extremely simple mechanism&amp;nbsp;works&amp;nbsp;just as well as the &amp;quot;evil bit&amp;quot;: &lt;a href="http://www.ietf.org/rfc/rfc3514.txt"&gt;http://www.ietf.org/rfc/rfc3514.txt&lt;/a&gt;. In fact, if we simply&amp;nbsp;change the manifest like this, we can avoid the whole white list altogether:&lt;/p&gt;
&lt;p&gt;&lt;span style="font-family:Courier New;"&gt;&amp;lt;?xml version=&amp;quot;1.0&amp;quot; encoding=&amp;quot;UTF-8&amp;quot; standalone=&amp;quot;yes&amp;quot;?&amp;gt;&lt;br /&gt;&amp;lt;assembly xmlns=&amp;quot;urn:schemas-microsoft-com:asm.v1&amp;quot; manifestVersion=&amp;quot;1.0&amp;quot;&amp;gt;&lt;br /&gt;&amp;nbsp; &amp;lt;assemblyIdentity type=&amp;quot;win32&amp;quot; &lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; name=&amp;quot;RBU.FakeAntiMalware.MyCurrentVersion&amp;quot; &lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; version=&amp;quot;6.0.0.0&amp;quot; &lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; processorArchitecture=&amp;quot;x86&amp;quot; &lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; publicKeyToken=&amp;quot;0000000000000000&amp;quot;&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;strong&gt;malicious=&amp;quot;True&amp;quot;&lt;/strong&gt;&lt;br /&gt;&amp;nbsp; /&amp;gt;&lt;br /&gt;&amp;lt;/assembly&amp;gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;There you have it! Microsoft should make it part of the logo guidelines&amp;nbsp;to require all malicious software to identify itself as malicious. Problem solved! You may go back to surfing the intarwebs now.&lt;/p&gt;
&lt;p&gt;The sharp-eyed security experts in the crowd may have spotted a minor flaw in this scheme, however. What if the malicious software refuses to identify itself? Curses to them! Maybe we need something better. Perhaps Munir&amp;#39;s whitelist is to be a whitelist of all software? That would be simpler to be sure. In fact, using Software Restriction Policies (SRP), which has been built into&amp;nbsp;Windows for years, we can restrict which software can run. Now all we need is our whitelist. Of course, as Munir points out, it is Microsoft&amp;#39;s responsibility to produce that whitelist. &lt;/p&gt;
&lt;p&gt;Producing the whitelist would be conceptually simple. Microsoft would simply have to create a division that ingested all third party software, tested it, and validated it as non-malicious.&amp;nbsp;DOMUS (The Department of Made Up Statistics) estimate the number of&amp;nbsp;third-party applications for Windows at somewhere between 5 and 10 million, including&amp;nbsp;shareware, freeware, open source, commercial applications, in-house developed applications, line of business applications, the kiosk applications that drive your ATM, your gas pump, your car, and probably a space craft or two. In order to avoid becoming an&amp;nbsp;impediment deployment, Microsoft would have to test all such software for malice, with an SLA of 24-48 hours, yet guarantee that software does not turn malicious after several weeks or months. It would also need to ensure that any updates do not introduce malicious functionality. In other words, to meet these requirements, Microsoft would need to do just two things: (a) develop a method of time travel, and (b) hire and train all of China to analyze software for malicicous action. I&amp;#39;m sure the Trustworthy Computing division is working on both problems. &lt;/p&gt;
&lt;p&gt;I am not arguing that reputation scoring does not have some promise, which is what Symantec&amp;#39;s Rob Pregnall was actually talking about, and which Munir turned into an indictment of Microsoft. However, reputation systems are not only&amp;nbsp;fallible and can be relatively easily manipulated. Without consumers actually understanding what the reputation score means, and learning how to value it over the naked dancing pigs, it will never help. Again, it comes down&amp;nbsp;to how we&amp;nbsp;educate consumers on how to be safe online and why, instead of scaring them into buying more anti-malware software. I may be mistaken, but I was under the impression that the reason Freedom of the Press is a cherished human right is because the Press is there to educate the public. Why is the press, along with government and the IT Industry, not doing more to educate the&amp;nbsp;public on how to tell real from fake?&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msinfluentials.com/aggbug.aspx?PostID=21965" width="1" height="1"&gt;</description><category domain="http://msinfluentials.com/blogs/jesper/archive/tags/Security+Pontification/default.aspx">Security Pontification</category></item><item><title>How Delegation Privileges Are Represented In Active Directory</title><link>http://msinfluentials.com/blogs/jesper/archive/2009/10/20/how-delegation-privileges-are-represented-in-active-directory.aspx</link><pubDate>Wed, 21 Oct 2009 04:21:00 GMT</pubDate><guid isPermaLink="false">91db4bc3-5a69-4a9f-94bf-eedb569902ab:21953</guid><dc:creator>jesper</dc:creator><slash:comments>2</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msinfluentials.com/blogs/jesper/rsscomments.aspx?PostID=21953</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msinfluentials.com/blogs/jesper/commentapi.aspx?PostID=21953</wfw:comment><comments>http://msinfluentials.com/blogs/jesper/archive/2009/10/20/how-delegation-privileges-are-represented-in-active-directory.aspx#comments</comments><description>&lt;p&gt;One of the last areas where more tool support is needed is in monitoring the various attributes in Active Directory (AD). Recently I got curious about the delegation flags, and, more to the point, how to tell which accounts have been trusted for delegation. This could be of great import if, for instance, you have to produce reports of privileged accounts.&lt;/p&gt;
&lt;p&gt;&lt;a href="http://support.microsoft.com/default.aspx/kb/305144"&gt;KB 305144&lt;/a&gt; gives a certain amount of detail about how delegation rights are presented in Active Directory. However, it is unclear from that article&amp;nbsp;how to discover accounts trusted for full delegation, as opposed to those trusted only for constrained delegation; and the various flags with &amp;quot;DELEGATION&amp;quot;&amp;nbsp;in them are&amp;nbsp;not as clearly explained as I would like. Nor was I able to&amp;nbsp;glean any insight into this from the various security guides and recommendations for Windows.&amp;nbsp;I asked around, and got great answers from &lt;a href="http://adopenstatic.com/blog"&gt;Ken Schaefer&lt;/a&gt;. By spinning up a Windows Server 2003 Domain Controller in &lt;a href="http://aws.amazon.com/ec2/"&gt;Amazon EC2&lt;/a&gt;&amp;nbsp;and running a few tests, I was able to verify that Ken was indeed correct. &lt;/p&gt;
&lt;p&gt;Delegation rights are represented in the userAccountControl flag on the account object in AD, whether a user or a computer account. There are a couple of different flags involved, however. Here are the values set in various circumstances:&lt;/p&gt;
&lt;p&gt;For a computer account, the default userAccountControl flag value is 0x1020, which is equivalent to the WORKSTATION_TRUST_ACCOUNT &amp;amp; PASSWD_NOTREQD values being set. A user account is set to 0x200 (NORMAL_ACCOUNT) by default.&lt;/p&gt;
&lt;p&gt;When you enable full delegation, 0x80000, or TRUSTED_FOR_DELEGATION, gets ORed to the userAccountControl flag. This is irrespective of domain functional level. In other words, in a Windows 2000 compatible domain, checking the &amp;quot;Trusted for delegation&amp;quot; box; and, in higher functional levels, checking &amp;quot;Trust this computer for delegation to any service&amp;quot;&amp;nbsp;using the &amp;quot;Kerberos Only&amp;quot; setting, both result in the same flag being set. The same flag is set on user accounts when you check the &amp;quot;Account is trusted for delegation&amp;quot; checkbox.&lt;/p&gt;
&lt;p&gt;In a Windows Server 2003 or higher functional level domain you gain the ability to trust an account for delegation only to specific services: &lt;a href="http://technet.microsoft.com/en-us/library/cc739587(WS.10).aspx"&gt;constrained delegation&lt;/a&gt;. If you configure constrained delegation using Kerberos only, the userAccountControl value is not changed at all. The account simply gets a list of services it can delegate to in the msDS-AllowedToDelegateTo flag. &lt;/p&gt;
&lt;p&gt;However, if you configure constrained delegation using any protocol, the userAccountControl value gets ORed with 0x1000000, or TRUSTED_TO_AUTH_FOR_DELEGATION.&lt;/p&gt;
&lt;p&gt;There is also a flag in userAccountControl called NOT_DELEGATED. This flag is set when you check the box &amp;quot;Account is sensitive and cannot be delegated.&amp;quot;&lt;/p&gt;
&lt;p&gt;This tie-back to the graphical user interface, as well as explanation of the various flags, should help an auditor construct a query that lists all accounts trusted for delegation in an arbitrary domain. Obviously, any account with TRUSTED_FOR_DELEGATION set should be considered extremely sensitive; as sensitive as a Domain Controller or Enterprise Admin account. An account with TRUSTED_TO_AUTH_FOR_DELEGATION set is probably less sensitive, depending on which specific services it can connect to, but still quite sensitive as it can use other protocols than Kerberos. Finally, and least sensitive of those accounts trusted for some form of delegation, are those that are only permitted to delegate to specific services using Kerberos. &lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msinfluentials.com/aggbug.aspx?PostID=21953" width="1" height="1"&gt;</description><category domain="http://msinfluentials.com/blogs/jesper/archive/tags/Windows+Security/default.aspx">Windows Security</category></item><item><title>Web Of Trust: RIP</title><link>http://msinfluentials.com/blogs/jesper/archive/2009/10/13/web-of-trust-rip.aspx</link><pubDate>Wed, 14 Oct 2009 05:16:00 GMT</pubDate><guid isPermaLink="false">91db4bc3-5a69-4a9f-94bf-eedb569902ab:21947</guid><dc:creator>jesper</dc:creator><slash:comments>3</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msinfluentials.com/blogs/jesper/rsscomments.aspx?PostID=21947</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msinfluentials.com/blogs/jesper/commentapi.aspx?PostID=21947</wfw:comment><comments>http://msinfluentials.com/blogs/jesper/archive/2009/10/13/web-of-trust-rip.aspx#comments</comments><description>&lt;p&gt;It&amp;#39;s official. I just received an e-mail from &lt;a href="http://www.thawte.com/"&gt;Thawte&lt;/a&gt; notifying me that, as of November 16, 2009, the most innovative and useful idea in PKI since its inception, the&lt;a href="http://www.thawte.com/secure-email/web-of-trust-wot/index.html?click=main-nav-products-wot"&gt; Web of Trust&lt;/a&gt;, will die. &lt;/p&gt;
&lt;p&gt;Thawte was founded 14 years ago by Mark Shuttleworth. The primary purpose was to get around the then-current U.S. export restrictions on cryptography. Shuttleworth also had an idea that drew from PGP: rather than force everyone who wanted an e-mail certificate to get verified by some central entity - and pay for the privilege - why not have them verified by a distributed verification system, similar to the key signing system used by PGP, but more controlled. This was the Web of Trust. Anyone can get a free e-mail certificate, but to get your name in it instead of the default &amp;quot;Thawte FreeMail User&amp;quot; you had to get &amp;quot;notarized&amp;quot; by at least 2 people (or 1, if you managed to meet Shuttleworth himself or a few select others). The Web of Trust was a point-based system, and if you received 100 points (requiring at least three notary signatures) you became a notary yourself. The really cool idea was that it created a manageable system of trust based not so much on the six degrees of separation as on the fact that most of us are inherently trustworthy beings. &lt;/p&gt;
&lt;p&gt;In 1999 Shuttleworth sold Thawte to Verisign for enough money for him to take a joyride into space, found the Ubuntu project, and to live without worries about money for the rest of his own life and that of several of his descendants. Verisign, of course, is in the business of printing money, only&amp;nbsp;in the form of digital certificates, and certainly not in giving anything away for free.&amp;nbsp;Not that there is anything inherently wrong with that, but it iscertainly at odds with Thawte&amp;#39;s free&amp;nbsp;service,&amp;nbsp;so it was really just a matter of time before&amp;nbsp;the latter&amp;nbsp;was disbanded. WIth it goes the Web of Trust. &lt;/p&gt;
&lt;p&gt;Finally, on November 16, 2009,&amp;nbsp;the Web of Trust will be removed as a free competitor to Verisign&amp;#39;s&amp;nbsp;paid service&amp;nbsp;that does the same thing. It will be a sad day indeed.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msinfluentials.com/aggbug.aspx?PostID=21947" width="1" height="1"&gt;</description><category domain="http://msinfluentials.com/blogs/jesper/archive/tags/Security+Pontification/default.aspx">Security Pontification</category><category domain="http://msinfluentials.com/blogs/jesper/archive/tags/Thinking+differently/default.aspx">Thinking differently</category></item><item><title>Passwords are here to stay</title><link>http://msinfluentials.com/blogs/jesper/archive/2009/10/10/passwords-are-here-to-stay.aspx</link><pubDate>Sun, 11 Oct 2009 05:54:00 GMT</pubDate><guid isPermaLink="false">91db4bc3-5a69-4a9f-94bf-eedb569902ab:21941</guid><dc:creator>jesper</dc:creator><slash:comments>4</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msinfluentials.com/blogs/jesper/rsscomments.aspx?PostID=21941</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msinfluentials.com/blogs/jesper/commentapi.aspx?PostID=21941</wfw:comment><comments>http://msinfluentials.com/blogs/jesper/archive/2009/10/10/passwords-are-here-to-stay.aspx#comments</comments><description>&lt;p&gt;At least for the short to medium term. That is the, quite obvious, conclusion drawn in a Newsweek article entitled &lt;a href="http://www.newsweek.com/id/217014/"&gt;&amp;quot;Building a Better Password.&amp;quot;&lt;/a&gt;&amp;nbsp; The article goes inside the CyLab at Carnegie-Mellon University to understand how passwords may one day be replaced. It is interesting reading all around.&lt;/p&gt;
&lt;p&gt;The article is not without some &amp;quot;really?&amp;quot; moments though, such as this quote:&lt;/p&gt;
&lt;p&gt;&lt;em&gt;The idea of passphrases isn&amp;#39;t new. But no one has ever told you about it, because over the years, complexity&amp;mdash;mandating a mix of letters, numbers, and punctuation that AT&amp;amp;T researcher William Cheswick derides as &amp;quot;eye-of-newt, witches&amp;#39;-brew password fascism&amp;quot;&amp;mdash;somehow became the sole determinant of password strength.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;Actually, I do believe &lt;a href="http://technet.microsoft.com/en-us/library/cc512613.aspx"&gt;someone did tell you about it&lt;/a&gt;. Five years ago now, in fact. &lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msinfluentials.com/aggbug.aspx?PostID=21941" width="1" height="1"&gt;</description><category domain="http://msinfluentials.com/blogs/jesper/archive/tags/Security/default.aspx">Security</category></item><item><title>And finally, standard user malware</title><link>http://msinfluentials.com/blogs/jesper/archive/2009/08/31/and-finally-standard-user-malware.aspx</link><pubDate>Tue, 01 Sep 2009 06:21:00 GMT</pubDate><guid isPermaLink="false">91db4bc3-5a69-4a9f-94bf-eedb569902ab:21907</guid><dc:creator>jesper</dc:creator><slash:comments>4</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msinfluentials.com/blogs/jesper/rsscomments.aspx?PostID=21907</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msinfluentials.com/blogs/jesper/commentapi.aspx?PostID=21907</wfw:comment><comments>http://msinfluentials.com/blogs/jesper/archive/2009/08/31/and-finally-standard-user-malware.aspx#comments</comments><description>&lt;p&gt;Today I finally got wind of my first piece of true standard user malware. &lt;a href="http://www.theregister.co.uk/2008/08/22/anatomy_of_a_hack/"&gt;MS Antispyware 2008&lt;/a&gt; has turned standard user. The version in question installs the binaries in c:\documents and settings\all users\application data\&amp;lt;something&amp;gt;, and makes itself resident by infecting HKCU\...\Run. Curiously, the legitimate anti-malware program (one of the top 3) failed to detect the infector.&lt;/p&gt;
&lt;p&gt;Obviously, this version is much easier to remove than the ones that require admin privileges. However, MS Antispyware is not about being hard to remove. It just needs to run until the user pays for the privilege, and more than likely, even as a standard user, many people will fall for it. &lt;/p&gt;
&lt;p&gt;On a somewhat unrelated note, just as I was wondering who would fall for these types of scams, I met a real person that did; a not-particularly-well-off disabled retiree who was scammed out of $5000 by an organized crime ring that claims to have won you a lottery, as long as you just pay them for the ticket first. That particular scam was run partially by phone and partially online. And, the scumbags apparently didn&amp;#39;t think they had scammed her out of enough money so they kept calling her even after she sent them the money. I advised her to call &lt;a href="http://www.atg.wa.gov/fileacomplaint.aspx"&gt;Rob McKenna&amp;#39;s&lt;/a&gt; office (Attorney General of Washington State). Mr. McKenna&amp;#39;s office stated that they felt horrible for her. Apparently that was about all the comfort they could give. I must say that level of action was not particularly impressive, and does not really live up to &lt;a href="http://www.atg.wa.gov/Default.aspx"&gt;Mr. McKenna&amp;#39;s campaign promises of cracking down on scammers&lt;/a&gt;.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msinfluentials.com/aggbug.aspx?PostID=21907" width="1" height="1"&gt;</description><category domain="http://msinfluentials.com/blogs/jesper/archive/tags/Security+Pontification/default.aspx">Security Pontification</category><category domain="http://msinfluentials.com/blogs/jesper/archive/tags/Least+Privilege/default.aspx">Least Privilege</category><category domain="http://msinfluentials.com/blogs/jesper/archive/tags/Security/default.aspx">Security</category></item><item><title>Microsoft Poland Empowers White People</title><link>http://msinfluentials.com/blogs/jesper/archive/2009/08/25/microsoft-poland-empowers-white-people.aspx</link><pubDate>Wed, 26 Aug 2009 05:53:00 GMT</pubDate><guid isPermaLink="false">91db4bc3-5a69-4a9f-94bf-eedb569902ab:21898</guid><dc:creator>jesper</dc:creator><slash:comments>3</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msinfluentials.com/blogs/jesper/rsscomments.aspx?PostID=21898</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msinfluentials.com/blogs/jesper/commentapi.aspx?PostID=21898</wfw:comment><comments>http://msinfluentials.com/blogs/jesper/archive/2009/08/25/microsoft-poland-empowers-white-people.aspx#comments</comments><description>&lt;p&gt;In an absolutely astonishing move Microsoft&amp;#39;s Polish subsidiary decided to do some photoshopping on its Business Productivity Infrastructure page to tailor it to the Polish market. &lt;a href="http://www.microsoft.com/businessproductivity/default.mspx"&gt;Here you can see the U.S. original&lt;/a&gt;. In one of the least sensitive moves this year, the Polish subsidiary decided that black people in Poland do not need to be empowered, so &lt;a href="http://pokazywarka.pl/msmurzyn/"&gt;here you can see what its version of that page looked like&lt;/a&gt; for a few hours today. As you can see from&lt;a href="http://www.microsoft.com/poland/businessproductivity/default.mspx"&gt; the current version on the Polish site&lt;/a&gt;, someone with a bit more human sensitivity than a teaspoon, and an I.Q. that is at least room temperature (celsius), decided to fix it. This evening Microsoft empowers everyone equally - even in Poland. &lt;/p&gt;
&lt;p&gt;&lt;a href="http://photoshopdisasters.blogspot.com/2009/08/microsoft-poland-at-least-they-left.html"&gt;Photoshop Disasters&lt;/a&gt; has a very good before and after picture too.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msinfluentials.com/aggbug.aspx?PostID=21898" width="1" height="1"&gt;</description><category domain="http://msinfluentials.com/blogs/jesper/archive/tags/Thinking+differently/default.aspx">Thinking differently</category></item><item><title>Is it ActiveX that is the problem?</title><link>http://msinfluentials.com/blogs/jesper/archive/2009/08/09/is-it-activex-that-is-the-problem.aspx</link><pubDate>Sun, 09 Aug 2009 20:04:00 GMT</pubDate><guid isPermaLink="false">91db4bc3-5a69-4a9f-94bf-eedb569902ab:21825</guid><dc:creator>jesper</dc:creator><slash:comments>5</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msinfluentials.com/blogs/jesper/rsscomments.aspx?PostID=21825</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msinfluentials.com/blogs/jesper/commentapi.aspx?PostID=21825</wfw:comment><comments>http://msinfluentials.com/blogs/jesper/archive/2009/08/09/is-it-activex-that-is-the-problem.aspx#comments</comments><description>&lt;p&gt;Last week, an expert from Verizon, nee Cybertrust, posted a note about the &lt;a href="http://www.microsoft.com/technet/security/Bulletin/MS09-035.mspx"&gt;Active Template Library&lt;/a&gt; (ATL) security vulnerability over on the &lt;a href="http://securityblog.verizonbusiness.com/2009/07/28/activex-risk/"&gt;Verizon Business Security Blog&lt;/a&gt;. For home users, the phone company now advises you to use a different browser, ostensibly because IE and ActiveX are inherently insecure. I felt that quite missed the point that (a) browsers are software, and (b) all software has vulnerabilities, and (c) extension technologies in browsers add functionality, which (d) is implemented in the form of software, and therefore (e) introduce additional vulnerabilities. Just because Internet Explorer&amp;#39;s extension technology is called ActiveX does not mean it inherently has any more, or less, vulnerabilities than the extension technologies in other browsers. ActiveX received a, deservedly, horrible reputation when it first came out about ten years ago. Since then Microsoft has actually put a lot of effort into securing the user&amp;#39;s browsing experience, but for some reason, people keep dragging up old vulnerabilities from many years ago as proof that Microsoft does not care about security. Doing so is unfair and denigrates what is probably most comprehensive software security program in the industry.&lt;/p&gt;
&lt;p&gt;So, I decided to try to make that claim in the comments. That generated a response from &amp;quot;Nathan Anderson,&amp;quot; who did not bother really reading what I wrote, used a flawed interpretation of data to &amp;quot;prove&amp;quot; that Firefox and Chrome are far more secure than IE, ignored &lt;a href="http://msdn.microsoft.com/en-us/library/bb250462%28VS.85%29.aspx"&gt;Low Rights IE&lt;/a&gt;, and concluded by, in essence, calling me an idiot. &lt;/p&gt;
&lt;p&gt;My comment also generated a response from Dave Kennedy, who appears to have been the original poster, and who thinks I went too far.&lt;/p&gt;
&lt;p&gt;At this point, I&amp;#39;d probably do better to ignore the discussion, but Mr Kennedy posited a very interesting question, and I thought I&amp;#39;d like to explore it a little. Here it is:&lt;br /&gt;&lt;i&gt;&amp;quot;How many millions of dollars have been lost and thousands of individuals have become the victims of identity fraud that can be laid squarely at the feet of criminal exploitation of vulnerable ActiveX controls?&amp;quot;&lt;/i&gt;&lt;/p&gt;
&lt;p&gt;I don&amp;#39;t know. How many? And how does it compare with the number of millions of dollars lost because users click on things they shouldn&amp;#39;t, while running as admins? How does it compare with the number of millions of dollars lost due to vulnerable versions of Flash and Acrobat; which are vulnerable on all browsers? All of those would be fantastic statistics to have. If anyone has them, I&amp;#39;d love to see them.&lt;/p&gt;
&lt;p&gt;To the Nathans of the world: I never said Firefox and Chrome are less secure than IE. All I pointed out was that they do not benefit from a sandbox the way IE does on Vista and Win7. They could. Easily. Stripping privileges out of a token and setting an integrity level is quite simple. The difficult part is really just to build an escalation method to be able to perform tasks outside the sandbox.&amp;nbsp; It is just that their respective manufacturers have chosen not to implement this functionality. I really wish they had. It would greatly improve the difficulty of exploiting either browser.&lt;/p&gt;
&lt;p&gt;In addition, Firefox, etc, may not have ActiveX, but they have other extension mechanisms, and a vulnerable extension is a vulnerable extension, whether it is ActiveX or not. It is correct that Chrome has fewer vulnerabilities than either Firefox or IE, but a reasonable argument can be made that it is because of how long it has been out and the amount of attention from security researchers it has received so far. Chrome is not yet a year old. In that time, Chrome 1.x and 2.x have racked up 9 advisories (12 vulnerabilities), according to Secunia. I included both versions because of how fast they were released. It provides a more accurate measure of the impact on the end user. Chrome 3.x is still considered a preview release as far as I can tell, so I excluded it. Firefox 3 (the only supported Firefox version for most of the one-year timeframe) had 9 advisories in 2009 so far, and an additional 5 in late 2008. Internet Explorer 7 in that timeframe has 6.&amp;nbsp; &lt;/p&gt;
&lt;p&gt;Based on these figures, I would submit there is no statistically significant difference between the three browsers. I am not trying to minimize the ATL vulnerability, which was sloppy in the extreme, and I am not trying to denigrate either Firefox or Chrome, as I use and enjoy both, although mostly Firefox, which I used to write this post. I am simply saying that all software has vulnerabilities, and that the attackers will be opportunistic enough to exploit any or all of them if it is necessary to meet their needs. &lt;/p&gt;
&lt;p&gt;Vulnerability counting misses the point entirely though. All the bad guys need is one unpatched vulnerability. Furthermore, that vulnerability can reside in the browser, or in anything else running in the browser.The common add-ins, such as Flash and Acrobat, have vulnerabilities regardless of which browser they are running in. Even if the user has a fully patched and non-vulnerable browser, all the attacker needs is one unpatched add-in. Adding a new browser requires adding new add-ins, so now you have two copies of Flash to maintain, two copies of Acrobat to maintain, and another browser.Simply adding more software to maintain does not make people more secure. Most users would probably be far better off maintaining only one browser and spending the additional effort on learning how to browse more securely.&lt;/p&gt;
&lt;p&gt;Finally, whether a computer is fully patched or not; whether a browser or its extensions are full of holes or not; the most vulnerable part of any system is almost always the user. Humans are still at v. 1.0 and there have not been a single security patch issued for them yet. There has been no Trustworthy Computing Initiative to stamp out security vulnerabilities in people. Therefore, the easiest way to hack anything is almost always to ask a legitimate user to do it for you. Simply present the user with something he values more than an intangible and incomprehensible security benefit, and your job is done. Many of the attacks today do not even use software vulnerabilities. It is more reliable and less expensive to exploit the user directly.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msinfluentials.com/aggbug.aspx?PostID=21825" width="1" height="1"&gt;</description><category domain="http://msinfluentials.com/blogs/jesper/archive/tags/Security+Pontification/default.aspx">Security Pontification</category></item><item><title>Warning: The software you are installing does not match your mental model</title><link>http://msinfluentials.com/blogs/jesper/archive/2009/07/20/warning-the-software-you-are-installing-does-not-match-your-mental-model.aspx</link><pubDate>Tue, 21 Jul 2009 05:10:00 GMT</pubDate><guid isPermaLink="false">91db4bc3-5a69-4a9f-94bf-eedb569902ab:21771</guid><dc:creator>jesper</dc:creator><slash:comments>14</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msinfluentials.com/blogs/jesper/rsscomments.aspx?PostID=21771</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msinfluentials.com/blogs/jesper/commentapi.aspx?PostID=21771</wfw:comment><comments>http://msinfluentials.com/blogs/jesper/archive/2009/07/20/warning-the-software-you-are-installing-does-not-match-your-mental-model.aspx#comments</comments><description>&lt;p&gt;This morning I talked to my dad. After a few minutes of polite small talk, I heard the 10 little words I have come to dread: &amp;ldquo;I had some problems with my computer the other day.&amp;rdquo; The video card on his laptop had died. The screen was just black. He has a Dell Vostro, so he called Dell Technical Support. They sent a contractor technician out; with a motherboard. The technician, having no real qualifications other than the need for a job; and no real training other than how to fill out the repair paperwork, installed the motherboard. Three days later he returned with the video card the computer actually needed, and the computer started again.&lt;br /&gt;&lt;br /&gt;At this point, the following conversation ensued:&lt;br /&gt;&lt;br /&gt;Dad: When I started the computer I got an error message&lt;br /&gt;&lt;br /&gt;Me: What did the message say?&lt;br /&gt;&lt;br /&gt;Dad: How should I know? It was written for &amp;ldquo;people&amp;rdquo; like you. I didn&amp;rsquo;t understand a word of it. It just said something about some software not working and it should be reinstalled&lt;br /&gt;&lt;br /&gt;Me: Which software?&lt;br /&gt;&lt;br /&gt;Dad: I don&amp;rsquo;t know. I told you, I didn&amp;rsquo;t understand it.&lt;br /&gt;&lt;br /&gt;Me: So what did you do?&lt;br /&gt;&lt;br /&gt;Dad: I figured it must have been Windows. Windows never works properly, so that made sense. I thought if I reinstalled Windows it would all work.&lt;br /&gt;&lt;br /&gt;Me: And&amp;hellip;?&lt;br /&gt;&lt;br /&gt;Dad: Now Office doesn&amp;rsquo;t work.&lt;br /&gt;&lt;br /&gt;Me: When you say &amp;ldquo;reinstalled Windows&amp;rdquo; did you do an in-place upgrade?&lt;br /&gt;&lt;br /&gt;Dad: Can you restate that again in Human?&lt;br /&gt;&lt;br /&gt;Me: Did you upgrade Windows?&lt;br /&gt;&lt;br /&gt;Dad: No, the upgrade option was grayed out.&lt;br /&gt;&lt;br /&gt;At this point, if, like me, you are a cubicle-dwelling, bespectacled nerd with the social skills of a turnip you know exactly what happened. He created a new side-by-side installation of Windows. Sure enough, in the C:\Windows.Old folder were his old Users folder, his old Windows folder, his Program Files folder, and all the other contents of his hard drive. I pointed this out to him to explain what happened.&lt;br /&gt;&lt;br /&gt;This is when Dad drew the completely logical assumption: &amp;ldquo;OK, so if I just copy the Microsoft Office folder from there to C:\Program Files it will work?&amp;rdquo;&lt;br /&gt;&lt;br /&gt;No. It won&amp;rsquo;t. It would if software were designed for the humans that actually use it. Unfortunately, it is not. It is designed by and for the same people: cubicle-dwelling bespectacled nerds with the social skills of turnips; people who have never spent any significant time interacting with humans, and who have never met any of the real users who will use the products they design. If we had actually met and interacted at length with real people at any point over the past 15 years, we probably would have realized already that designing a &amp;ldquo;program&amp;rdquo; that consists of 3,829 files, spread over 60 folders, is not how people expect it to work. That, by the way, is not a random figure. It is the number of files and folders in C:\Program Files\Microsoft Office on my laptop. Lest you were now to say that someone else knows better, iTunes vomits 2,718 files over 1064 folders, in two different hierarchies. Why don&amp;rsquo;t you try to move either to your cavernous external hard drive to save space and see how well that works?&lt;br /&gt;&lt;br /&gt;Is it that my dad was being illogical? No. Moving the Office folder would indeed be incredibly logical; totally rational in fact. If you bought a new file cabinet, you could easily take the files out of the old file cabinet, put them in the new one, and they actually still remain readable! You could even take one of your old pens, scribble a note on them in the process, and a year later you can read the note! Amazing that ain&amp;rsquo;t it? If file cabinets were computers you certainly could try to remove the file from the computer. It would prompt you with a dialog asking if you really wanted to do that, once per character on the page. Once you accepted the prompts, you could insert the file into the new cabinet. When you tried to read it, however, you would find that the ink fell onto the floor between the two file cabinets. The magic fixative that keeps the ink on the paper works only as long as the paper stays in the old file cabinet.&lt;br /&gt;&lt;br /&gt;We have a mental model consisting of physical, tangible things. There is a school of thought in Cognitive Science that believes the basic wiring of the human brain was forged in caves. Our brains were designed to address the biggest concerns of the day: evading the saber-toothed cat, spearing a wooly mammoth for dinner, and, for at least half the population, clubbing a suitable mate to drag home to the cave. (Presumably, the other half of the population lived in fear of getting clubbed and dragged away). Our brains were not exactly wired to understand the convoluted product management decisions that resulted in almost four thousand files and thousands of directories. And they certainly were not wired to understand that all those files and directories are utterly useless without the settings, which are stored elsewhere &amp;ndash; in a place that does not really exist &amp;ndash; and are joined to the file system manifestation of the software only in the very loosest sense of the word.&lt;br /&gt;&lt;br /&gt;&amp;nbsp;Every time I boot Windows these days &amp;ndash; and especially Windows 7 &amp;ndash; I feel like the software is designed to be some kind of punishment. It&amp;rsquo;s meant to exact revenge on us for the designers being bullied in elementary school. So much of the software we software engineers design feels vindictive, counter-intuitive, and illogical. When the users finally figure out basic interaction styles, we change it all. When people finally learn that you can click on things on the quick launch menu to start them, we get the bastardized task bar in Windows 7 that only activates existing copies. When we finally figure out how to make find things on the start menu it becomes polluted with several hundred useless icons like iSCSI Initiator. Rather than features to make it easy to use, we bloat software up with new features because that&amp;rsquo;s what the computer journalists look for. I keep hoping for a release of a major piece of software that just works; that is elegant, that shows thoughtfulness in how the software was plumbed together, and that is designed from the ground up not to add new features but to be intuitive to the poor people who have to use it. Unfortunately, I never will. &amp;ldquo;Intuitive&amp;rdquo;, &amp;ldquo;elegant&amp;rdquo;, and &amp;ldquo;just works&amp;rdquo; are words you never see in computer journals, except maybe in Macworld.&amp;nbsp; &lt;br /&gt;&lt;br /&gt;Sometimes I feel like the only piece of software ever designed to work EXACTLY the way its intended users expected it to work is Solitaire. Predictably, my sources tell me that Microsoft laid off the guy who wrote it in May.&lt;br /&gt;&lt;br /&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msinfluentials.com/aggbug.aspx?PostID=21771" width="1" height="1"&gt;</description><category domain="http://msinfluentials.com/blogs/jesper/archive/tags/Thinking+differently/default.aspx">Thinking differently</category></item><item><title>Steve Riley Lands On His Feet</title><link>http://msinfluentials.com/blogs/jesper/archive/2009/07/10/steve-riley-lands-on-his-feet.aspx</link><pubDate>Fri, 10 Jul 2009 23:13:00 GMT</pubDate><guid isPermaLink="false">91db4bc3-5a69-4a9f-94bf-eedb569902ab:21737</guid><dc:creator>jesper</dc:creator><slash:comments>6</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msinfluentials.com/blogs/jesper/rsscomments.aspx?PostID=21737</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msinfluentials.com/blogs/jesper/commentapi.aspx?PostID=21737</wfw:comment><comments>http://msinfluentials.com/blogs/jesper/archive/2009/07/10/steve-riley-lands-on-his-feet.aspx#comments</comments><description>&lt;p&gt;In May, in one of the more inexplicable moves this year, Microsoft laid off my good friend Steve Riley, four days before he was to deliver half a dozen presentations at TechEd. Fortunately, it did not take Steve long to find a new gig. This Monday, he starts as the latest &lt;a href="https://msinfluentials.com:443/blogs/steveriley/archive/2009/07/10/my-new-gig-amazon-web-services.aspx"&gt;Evangelist &amp;amp; Strategist for Amazon Web Services&lt;/a&gt;! &lt;/p&gt;
&lt;p&gt;I&amp;#39;m very very happy for Steve, and very excited about what he can do in that role. Web Services are where the future is, and Steve is extremely well suited to the role. Please join me in wishing him good luck!&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msinfluentials.com/aggbug.aspx?PostID=21737" width="1" height="1"&gt;</description></item><item><title>A better, more reliable, work-around for the Microsoft Video Control Vulnerability</title><link>http://msinfluentials.com/blogs/jesper/archive/2009/07/09/a-better-more-reliable-work-around-for-the-microsoft-video-control-vulnerability.aspx</link><pubDate>Fri, 10 Jul 2009 06:09:00 GMT</pubDate><guid isPermaLink="false">91db4bc3-5a69-4a9f-94bf-eedb569902ab:21731</guid><dc:creator>jesper</dc:creator><slash:comments>5</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msinfluentials.com/blogs/jesper/rsscomments.aspx?PostID=21731</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msinfluentials.com/blogs/jesper/commentapi.aspx?PostID=21731</wfw:comment><comments>http://msinfluentials.com/blogs/jesper/archive/2009/07/09/a-better-more-reliable-work-around-for-the-microsoft-video-control-vulnerability.aspx#comments</comments><description>&lt;p&gt;For the past few days I&amp;#39;ve been following the &lt;a href="http://www.microsoft.com/technet/security/advisory/972890.mspx"&gt;Microsoft Video Control Vulnerability&lt;/a&gt; with interest. Basically, it&amp;#39;s another vulnerable ActiveX control that needs killbitted. Last night, &lt;a href="http://blogs.msdn.com/askie/archive/2009/07/08/quick-and-dirty-group-policy-adm-template-to-implement-the-workaround-from-kb972890.aspx"&gt;Microsoft posted a work-around&lt;/a&gt; which involves using a Group Policy ADM template (ADM is the template format that was deprecated in Vista and Windows Server 2008). Unfortunately, the template &lt;a href="http://support.microsoft.com/default.aspx/kb/555934"&gt;tattoos &lt;/a&gt;the registry, which is not really recommended. &lt;/p&gt;
&lt;p&gt;I contemplated for a while writing a work-around for this issue, but then remembered that I actually did; almost three years ago. The workaround I wrote then, for  &lt;a href="https://msinfluentials.com:443/blogs/jesper/archive/2006/09/29/Set-KillBit-on-Arbitrary-ActiveX-Controls-with-Group-Policy.aspx"&gt;another ActiveX vulnerability&lt;/a&gt; will not tattoo the registry, and will be much simpler to deploy with an Enterprise Management System. Just take the CLSIDs from &lt;a href="http://www.microsoft.com/technet/security/advisory/972890.mspx"&gt;the advisory&lt;/a&gt; (there are 45 of them) and run my script that many times with the -k switch. If you wish to revert the change, run the same script with the -r switch.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msinfluentials.com/aggbug.aspx?PostID=21731" width="1" height="1"&gt;</description><category domain="http://msinfluentials.com/blogs/jesper/archive/tags/Windows+Security/default.aspx">Windows Security</category><category domain="http://msinfluentials.com/blogs/jesper/archive/tags/Windows+Vista/default.aspx">Windows Vista</category><category domain="http://msinfluentials.com/blogs/jesper/archive/tags/Mitigations/default.aspx">Mitigations</category><category domain="http://msinfluentials.com/blogs/jesper/archive/tags/Windows+Server+2008/default.aspx">Windows Server 2008</category></item><item><title>Are Identity Theft Services Worth The Cost?</title><link>http://msinfluentials.com/blogs/jesper/archive/2009/03/23/are-identity-theft-services-worth-the-cost.aspx</link><pubDate>Tue, 24 Mar 2009 04:01:00 GMT</pubDate><guid isPermaLink="false">91db4bc3-5a69-4a9f-94bf-eedb569902ab:12740</guid><dc:creator>jesper</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msinfluentials.com/blogs/jesper/rsscomments.aspx?PostID=12740</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msinfluentials.com/blogs/jesper/commentapi.aspx?PostID=12740</wfw:comment><comments>http://msinfluentials.com/blogs/jesper/archive/2009/03/23/are-identity-theft-services-worth-the-cost.aspx#comments</comments><description>&lt;p&gt;The Consumer Federation of America just published a report on identity theft services entitled &amp;quot;&lt;a href="http://www.consumerfed.org/pdfs/ID_THEFT_REPORT.pdf"&gt;Are Identity Theft Services Worth The Cost?&lt;/a&gt;&amp;quot; The conclusion is that many are not, and that regulation is needed in that industry. It is a very interesting read. &lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msinfluentials.com/aggbug.aspx?PostID=12740" width="1" height="1"&gt;</description><category domain="http://msinfluentials.com/blogs/jesper/archive/tags/Privacy/default.aspx">Privacy</category></item><item><title>Please do not e-mail my social security number</title><link>http://msinfluentials.com/blogs/jesper/archive/2009/01/27/please-do-not-e-mail-my-social-security-number.aspx</link><pubDate>Wed, 28 Jan 2009 05:38:00 GMT</pubDate><guid isPermaLink="false">91db4bc3-5a69-4a9f-94bf-eedb569902ab:12570</guid><dc:creator>jesper</dc:creator><slash:comments>12</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msinfluentials.com/blogs/jesper/rsscomments.aspx?PostID=12570</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msinfluentials.com/blogs/jesper/commentapi.aspx?PostID=12570</wfw:comment><comments>http://msinfluentials.com/blogs/jesper/archive/2009/01/27/please-do-not-e-mail-my-social-security-number.aspx#comments</comments><description>&lt;p&gt;Recently I had a very interesting incident. I wrote an article some time in 2008 and the publisher paid me a little bit of money for it. That means the publisher must send a report to the Internal Revenue Service (IRS - the U.S. tax department) reporting that they paid me, as well as send me a form called a 1099 form that I can use to report this money on my tax return.&lt;/p&gt;
&lt;p&gt;A few days ago the comptroller for the publisher sent me an e-mail asking for my social security number (my national ID number for any non-Americans that are unfamiliar with the term). As is my custom, I responded that I really do not care to e-mail my social security number, but if he gives me a phone number I will gladly call him and let him know. This he did. I called, and within 15 minutes of the call I received a form California DE 542 in the mail. The DE 542 is required by the state of California when money is paid to a contractor, or a contract is entered into to pay money to a contractor. Its purpose is to permit the state to track payments to parents who do not pay their child support. Not only do I not need this form as I am not a resident of California; it also contains, you guessed it:&lt;/p&gt;
&lt;p&gt;my social security number.&lt;/p&gt;
&lt;p&gt;At this point I started wondering what part of &amp;quot;I do not wish to have my social security number transmitted by clear-text e-mail&amp;quot; was unclear. I sent a message to the sender that informed&amp;nbsp;him that this could quite possibly be considered a data breach and require notification under &lt;a href="http://www.leg.wa.gov/pub/billinfo/2005-06/Htm/Bills/Session%20Law%202005/6043-S.SL.htm"&gt;Washington State SSB 6043&lt;/a&gt;, which requires formal breach notification. As of today, I am still awaiting a response. Any response. &lt;/p&gt;
&lt;p&gt;Just because I felt like griping to someone, I forwarded the e-mail to my favorite accountant. Her response was &amp;quot;yeah, I know lots of CPA firms who e-mail around unencrypted 1040s.&amp;quot; (A &amp;quot;1040&amp;quot; is the U.S. federal tax return form). I was absolutely floored. Last week credit card processor &lt;a href="http://news.cnet.com/8301-1009_3-10146275-83.html"&gt;Heartland&lt;/a&gt; reported that they had experienced what may very well be the largest data breach in world history. Many banks are replacing every single one of their credit cards because of it. In fact, I took a call from a distressed bank manager just this morning asking whether it would be prudent to do so (the answer was &amp;quot;yes&amp;quot;). Yet, does that not pale in comparison to the number of unencrypted 1040s e-mailed around by tens of thousands of accountants every year, and the untold millions other tax-related forms that traverse unencrypted network channels? &lt;/p&gt;
&lt;p&gt;If you steal my credit card number, I can call the bank and ask them to issue me a new number. A few days later, I have a new card. The bad guy can, at worst, incur a few hundred dollars in charges, maybe a few thousand if they are really lucky. Yet, credit card data is somehow seen as the primary piece of data that needs protection. How many news reports have you read that discuss a computer breach and include the words &amp;quot;no credit card numbers appear to have been compromised?&amp;quot; Have we completely lost sight of the fact that there may be other pieces of information that need protection? &lt;/p&gt;
&lt;p&gt;Consider the corollary. If you steal my social security number, you can take over my house, get any number of credit cards in my name, give me a criminal record, get a driver&amp;#39;s license in my name... And, how do I clean it up? If I call the Social Security Administration and ask for a new number because my existing number has been compromised they would simply laugh at me. Only in exceptionally rare circumstances do they issue new numbers. In some states I am permitted, if my social security number has been compromised, to put in a credit report freeze, but the burden is on &lt;strong&gt;me&lt;/strong&gt;, as the victim, to prove that my information has been compromised before I can get a freeze. If I am deemed worthy of getting the barn door closed after the horses have fled, I get to pay $30-60, per freeze, per credit bureau, requested by certified mail. And each freeze may only be good for 90 days. That&amp;#39;s only in some states. Other states prohibit credit freezes, and a few, more progressive ones, actually permit consumers to close the barn door &lt;em&gt;before&lt;/em&gt; the horses run away. The freeze usually still costs money, and usually is still time-limited, and usually still requires that you use certified mail to each credit bureau to request it. Fortunately, you can &amp;quot;thaw&amp;quot; the freeze&amp;nbsp;by making a single phone call and typing in a four-digit pin. &lt;/p&gt;
&lt;p&gt;What is wrong with this picture? Why are accountants and comptrollers still e-mailing around the source data - social security numbers; while we as consumers&amp;nbsp;only seem to care about the derived data - the credit card number? Why is there a Payment Card Industry (PCI) Data Security Standard that, while widely ignored, attempts to set data protection standards for cardholder data;&amp;nbsp;but no Social Security Number security standard that establishes requirements for protection of social security numbers and liability for anyone who compromises someone else&amp;#39;s Social Security Number? &lt;/p&gt;
&lt;p&gt;Why do we not see any Attorney&amp;#39;s General up in arms over that one? Who is going to help me protect the source data? &lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msinfluentials.com/aggbug.aspx?PostID=12570" width="1" height="1"&gt;</description><category domain="http://msinfluentials.com/blogs/jesper/archive/tags/Security+Pontification/default.aspx">Security Pontification</category><category domain="http://msinfluentials.com/blogs/jesper/archive/tags/Security/default.aspx">Security</category></item><item><title>Kip Hawley: "No, the TSA is Necessary Because This is War!"</title><link>http://msinfluentials.com/blogs/jesper/archive/2008/12/24/kip-hawley-quot-no-the-tsa-is-necessary-because-this-is-war-quot.aspx</link><pubDate>Wed, 24 Dec 2008 10:44:00 GMT</pubDate><guid isPermaLink="false">91db4bc3-5a69-4a9f-94bf-eedb569902ab:12371</guid><dc:creator>jesper</dc:creator><slash:comments>6</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msinfluentials.com/blogs/jesper/rsscomments.aspx?PostID=12371</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msinfluentials.com/blogs/jesper/commentapi.aspx?PostID=12371</wfw:comment><comments>http://msinfluentials.com/blogs/jesper/archive/2008/12/24/kip-hawley-quot-no-the-tsa-is-necessary-because-this-is-war-quot.aspx#comments</comments><description>&lt;p&gt;&lt;a href="http://www.cbsnews.com/stories/2008/12/18/60minutes/main4675524.shtml"&gt;CBS News did a story a few days ago&lt;/a&gt; on the &lt;a href="http://www.tsa.gov"&gt;Transportation Security Administration&lt;/a&gt; (TSA). Basically it was a tit-for-tat between &lt;a href="http://www.schneier.com/"&gt;Bruce Schneier&lt;/a&gt;, security pontificator extraordinaire, and Kip Hawley, the administrator of the TSA. Mr. Hawley&amp;#39;s maintans that the TSA provides a necessary service because we are at war, and the obvious battleground, apparently, is airplanes. Surely, we must all realize that just because the terrorists used airplanes once, they can&amp;#39;t possibly have enough imagination to go for another target next time. Mr. Schneier, wisely, disagrees, points out all the flaws in what the TSA does, and calls the whole thing &amp;quot;Security Theater;&amp;quot; a term whose origins are not entirely undisputed, but that is beside the point.&lt;/p&gt;
&lt;p&gt;The interesting thing with this story is that neither of Messrs. Schneier and Hawley were quoted as addressing the currently most glaring flaw in the entire air transportation security apparatus. If one of our enemies actually wanted to terrorize the populace, why take on the risk of blowing up another plane? Just for fun, head on down to your local airport this week. Walk into the terminal area and take a look at the security line. At Dulles (IAD), Los Angeles (LAX), Chicago (ORD), Denver (DEN), Atlanta (ATL), John F. Kennedy (JFK), etc, the picture is the same. There will, at any given moment, be 500 to 1,000 people in line. &lt;/p&gt;
&lt;p&gt;It took 5 terrorists per plane (four on one plane) to blow up the planes on September 11, 2001. Together, they managed to kill 2,751 people. That&amp;#39;s&amp;nbsp; 145 victims per attacker. Take those 19 terrorists, strap them full of explosives, and position them strategically &lt;i&gt;in the lines the TSA has created leading up to the security checkpoints&lt;/i&gt;. I guarantee you that each one of them will kill 145 people, or more. Better still, have them get in line with a bag full of explosives, then leave the bag and step out of line. They will probably have two to three minutes to make a get-away before the bag explodes before anyone even so much as looks at those bags. One might even have more if one chats up the people next to oneself in line to watch the bag while the attacker runs to the restroom. Suddenly, we have the prospect of a devastating, coordinated attack that is far more insidious, far more deadly, and far more difficult to prevent, than the attacks of September 11. This one you can&amp;#39;t inspect away. You can&amp;#39;t put a security checkpoint to get into the security checkpoint. &lt;i&gt;&lt;/i&gt;&lt;/p&gt;
&lt;p&gt;&lt;i&gt;The TSA, single-handedly, created this vulnerability&lt;/i&gt; by making the airport security checkpoints so incredibly inefficient (and, one might add, ineffective) that the lines leading up to them back up with hundreds, or, in the case of Dulles, even thousands, of people. If the terrorists really wanted to erode confidence in our transportation infrastructure, why not make the security checkpoints the most dangerous part of it?&lt;/p&gt;
&lt;p&gt;Mr. Hawley, in your final few weeks, how are you going to protect the public you are sworn to protect from this attack? How are you going to prioritize our safety while we are waiting in line so that your spiffily dressed officers can declare us as posing no risk to the traveling public?&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msinfluentials.com/aggbug.aspx?PostID=12371" width="1" height="1"&gt;</description><category domain="http://msinfluentials.com/blogs/jesper/archive/tags/Security+Pontification/default.aspx">Security Pontification</category></item><item><title>One "Hacker" Attempts to Rule The World</title><link>http://msinfluentials.com/blogs/jesper/archive/2008/12/24/one-quot-hacker-quot-attempts-to-rule-the-world.aspx</link><pubDate>Wed, 24 Dec 2008 10:40:00 GMT</pubDate><guid isPermaLink="false">91db4bc3-5a69-4a9f-94bf-eedb569902ab:12368</guid><dc:creator>jesper</dc:creator><slash:comments>1</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msinfluentials.com/blogs/jesper/rsscomments.aspx?PostID=12368</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msinfluentials.com/blogs/jesper/commentapi.aspx?PostID=12368</wfw:comment><comments>http://msinfluentials.com/blogs/jesper/archive/2008/12/24/one-quot-hacker-quot-attempts-to-rule-the-world.aspx#comments</comments><description>&lt;p&gt;Wired, always a source for amusement and interesting literature, just carried &lt;a href="http://www.wired.com/techbiz/people/magazine/17-01/ff_max_butler?currentPage=7"&gt;a story on a &amp;quot;hacker&amp;quot;&lt;/a&gt; (the magazine&amp;#39;s use of the term equates to &amp;quot;criminal&amp;quot;) who attempted to dominate the market in stolen credit cards. It&amp;#39;s a neat story about an unsavory character who is not going to get enough prison time.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;If you are too busy to read it, here is a synopsis:&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;Once upon a time, there lived in a far away land an evil dark lord. He lived in a dark castle with all kinds of dark objects around him. His most priced possession was the Mirror of Omniscience, which let him see into the lives of everyone else in the kingdom. His highest ambition was to take over the world and become ruler over all the land.&lt;br /&gt;..&lt;br /&gt;Luckily, there was a handsome and strong prince who wanted to preserve the beauty and way of life in this delightful communist enclave. The prince was deeply in love with the most beautiful woman in the whole kingdom. However, the dark lord had imprisoned her soul in his dark castle. So, the handsome prince set out to rescue her and save the kingdom from the impending disaster.&lt;br /&gt;...&lt;br /&gt;and the handsome prince broke the Mirror of Omniscience, and they all lived happily ever after.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msinfluentials.com/aggbug.aspx?PostID=12368" width="1" height="1"&gt;</description><category domain="http://msinfluentials.com/blogs/jesper/archive/tags/Security+Pontification/default.aspx">Security Pontification</category></item></channel></rss>