<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://msinfluentials.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Jesper's Blog - All Comments</title><link>http://msinfluentials.com/blogs/jesper/default.aspx</link><description>&lt;table&gt;&lt;tr&gt;&lt;td&gt;
	&lt;p align="center"&gt;&lt;font size="2"&gt;Obligatory file photo:&lt;/font&gt;&lt;br /&gt;
		&lt;img src="https://msinfluentials.com/blogs/jesper/jesper-new45x60.jpg" width="97" height="131" alt="" /&gt;&lt;/td&gt;&lt;td&gt;
		&lt;font face="Arial"&gt;Welcome to Jesper Johansson&amp;#39;s blog. This is my home for pontification on the web. In case this is your first time here, I have been working on information security for about 20 years, and have been writing and speaking on the topic for about 10. I am also a &lt;a href="https://mvp.support.microsoft.com/profile/Jesper"&gt;Microsoft MVP&lt;/a&gt; in Windows Security. &lt;br /&gt;My most recent book is the &lt;b&gt;Windows Server 2008 Security Resource Kit
		&lt;/b&gt;. Because I am also a scuba instructor you may find some posts related to that topic as well.  
		Just because it took me so long to get it, I also like to say that I 
		have a Ph.D. in Management Information Systems from the University of 
		Minnesota. &lt;/font&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;</description><dc:language>en</dc:language><generator>CommunityServer 2008.5 SP2 (Build: 40407.4157)</generator><item><title>White Listing already exists</title><link>http://msinfluentials.com/blogs/jesper/archive/2009/10/24/fake-anti-malware-is-apparently-microsoft-s-fault.aspx#21971</link><pubDate>Sat, 31 Oct 2009 21:25:51 GMT</pubDate><guid isPermaLink="false">91db4bc3-5a69-4a9f-94bf-eedb569902ab:21971</guid><dc:creator>Dave Jones</dc:creator><description>&lt;p&gt;White Listing already exists in Windows 7 - it is called App Locker. What is required is a way for reputable software suppliers (Microsoft?) to provide this information alongside every product they release for easy importing into Local/AD Group Policies.&lt;/p&gt;
&lt;p&gt;A version for Windows XP would be nice...&lt;/p&gt;
&lt;p&gt;Alternatively, Lumension® Application Control (formerly sanctuary) does much the same thing.&lt;/p&gt;
&lt;p&gt;Now determining who are reputable software suppliers is definitely a problem, but giving users/organizations the ability to block software based upon who made it is definitely useful.&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msinfluentials.com/aggbug.aspx?PostID=21971" width="1" height="1"&gt;</description></item><item><title>re: Fake Anti-Malware is Apparently Microsoft's Fault</title><link>http://msinfluentials.com/blogs/jesper/archive/2009/10/24/fake-anti-malware-is-apparently-microsoft-s-fault.aspx#21969</link><pubDate>Tue, 27 Oct 2009 21:43:28 GMT</pubDate><guid isPermaLink="false">91db4bc3-5a69-4a9f-94bf-eedb569902ab:21969</guid><dc:creator>Brant Gurganus</dc:creator><description>&lt;p&gt;Maybe they don&amp;#39;t want people to know real from fake because they are fake, haha.&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msinfluentials.com/aggbug.aspx?PostID=21969" width="1" height="1"&gt;</description></item><item><title>re: Fake Anti-Malware is Apparently Microsoft's Fault</title><link>http://msinfluentials.com/blogs/jesper/archive/2009/10/24/fake-anti-malware-is-apparently-microsoft-s-fault.aspx#21968</link><pubDate>Tue, 27 Oct 2009 05:24:40 GMT</pubDate><guid isPermaLink="false">91db4bc3-5a69-4a9f-94bf-eedb569902ab:21968</guid><dc:creator>Aaron Margosis</dc:creator><description>&lt;p&gt;You mean you can&amp;#39;t just look software in the eyes and tell whether it is honest?&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msinfluentials.com/aggbug.aspx?PostID=21968" width="1" height="1"&gt;</description></item><item><title>re: Fake Anti-Malware is Apparently Microsoft's Fault</title><link>http://msinfluentials.com/blogs/jesper/archive/2009/10/24/fake-anti-malware-is-apparently-microsoft-s-fault.aspx#21967</link><pubDate>Sun, 25 Oct 2009 04:40:15 GMT</pubDate><guid isPermaLink="false">91db4bc3-5a69-4a9f-94bf-eedb569902ab:21967</guid><dc:creator>mark</dc:creator><description>&lt;p&gt;I think &amp;quot;white listing&amp;quot; at some point will be the way to go. Its not ready yet from what I&amp;#39;ve heard. &lt;/p&gt;
&lt;p&gt;While educating the public seems obvious the cleverness of the criminals with the huge financial incentive seems limitless. &lt;/p&gt;
&lt;p&gt;White listing might need to be draconian basically eliminating all programs older than 5 years that haven&amp;#39;t been updated. Organizations could choose white list specific for their needs. &amp;nbsp;&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msinfluentials.com/aggbug.aspx?PostID=21967" width="1" height="1"&gt;</description></item><item><title>re: How Delegation Privileges Are Represented In Active Directory</title><link>http://msinfluentials.com/blogs/jesper/archive/2009/10/20/how-delegation-privileges-are-represented-in-active-directory.aspx#21956</link><pubDate>Thu, 22 Oct 2009 05:05:55 GMT</pubDate><guid isPermaLink="false">91db4bc3-5a69-4a9f-94bf-eedb569902ab:21956</guid><dc:creator>jesper</dc:creator><description>&lt;p&gt;Of course Harry. Corrected. Thanks for pointing it out. &lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msinfluentials.com/aggbug.aspx?PostID=21956" width="1" height="1"&gt;</description></item><item><title>re: How Delegation Privileges Are Represented In Active Directory</title><link>http://msinfluentials.com/blogs/jesper/archive/2009/10/20/how-delegation-privileges-are-represented-in-active-directory.aspx#21955</link><pubDate>Wed, 21 Oct 2009 21:13:23 GMT</pubDate><guid isPermaLink="false">91db4bc3-5a69-4a9f-94bf-eedb569902ab:21955</guid><dc:creator>Harry Johnston, MVP</dc:creator><description>&lt;p&gt;Nitpick: you mean ORed, not ANDed.&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msinfluentials.com/aggbug.aspx?PostID=21955" width="1" height="1"&gt;</description></item><item><title>re: Web Of Trust: RIP</title><link>http://msinfluentials.com/blogs/jesper/archive/2009/10/13/web-of-trust-rip.aspx#21952</link><pubDate>Sat, 17 Oct 2009 03:54:38 GMT</pubDate><guid isPermaLink="false">91db4bc3-5a69-4a9f-94bf-eedb569902ab:21952</guid><dc:creator>martin</dc:creator><description>&lt;p&gt;I see an opportunity here. Since the idea is good, why not create an independent Web of Trust program?&lt;/p&gt;
&lt;p&gt;It could be run by &lt;a rel="nofollow" target="_new" href="http://www.cacert.org/"&gt;http://www.cacert.org/&lt;/a&gt; or someone like it. What do you think?&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msinfluentials.com/aggbug.aspx?PostID=21952" width="1" height="1"&gt;</description></item><item><title>re: Web Of Trust: RIP</title><link>http://msinfluentials.com/blogs/jesper/archive/2009/10/13/web-of-trust-rip.aspx#21950</link><pubDate>Wed, 14 Oct 2009 20:26:40 GMT</pubDate><guid isPermaLink="false">91db4bc3-5a69-4a9f-94bf-eedb569902ab:21950</guid><dc:creator>Kilia</dc:creator><description>&lt;p&gt;So sad indeed. I liked being able to use WOT to see how web surfers rated websites. I have even rated a few myself. &lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msinfluentials.com/aggbug.aspx?PostID=21950" width="1" height="1"&gt;</description></item><item><title>re: Web Of Trust: RIP</title><link>http://msinfluentials.com/blogs/jesper/archive/2009/10/13/web-of-trust-rip.aspx#21949</link><pubDate>Wed, 14 Oct 2009 14:47:50 GMT</pubDate><guid isPermaLink="false">91db4bc3-5a69-4a9f-94bf-eedb569902ab:21949</guid><dc:creator>Matthew Mucker</dc:creator><description>&lt;p&gt;So when can I get a cert from &amp;quot;Jesper&amp;#39;s Web of Trust Root CA?&amp;quot;&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msinfluentials.com/aggbug.aspx?PostID=21949" width="1" height="1"&gt;</description></item><item><title>re: Passwords are here to stay</title><link>http://msinfluentials.com/blogs/jesper/archive/2009/10/10/passwords-are-here-to-stay.aspx#21946</link><pubDate>Wed, 14 Oct 2009 02:08:03 GMT</pubDate><guid isPermaLink="false">91db4bc3-5a69-4a9f-94bf-eedb569902ab:21946</guid><dc:creator>admin</dc:creator><description>&lt;p&gt;Let me know if you get this?&lt;/p&gt;
&lt;p&gt;Test.&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msinfluentials.com/aggbug.aspx?PostID=21946" width="1" height="1"&gt;</description></item><item><title>re: Passwords are here to stay</title><link>http://msinfluentials.com/blogs/jesper/archive/2009/10/10/passwords-are-here-to-stay.aspx#21945</link><pubDate>Mon, 12 Oct 2009 12:02:42 GMT</pubDate><guid isPermaLink="false">91db4bc3-5a69-4a9f-94bf-eedb569902ab:21945</guid><dc:creator>Candee</dc:creator><description>&lt;p&gt;Indeed. I remember it well.&lt;/p&gt;
&lt;p&gt;It was one (of many) practices I adopted as my own. And my told my users (and anyone else who would listen) about it. &lt;/p&gt;
&lt;p&gt;Good work!&lt;/p&gt;
&lt;p&gt;Candee&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msinfluentials.com/aggbug.aspx?PostID=21945" width="1" height="1"&gt;</description></item><item><title>re: Passwords are here to stay</title><link>http://msinfluentials.com/blogs/jesper/archive/2009/10/10/passwords-are-here-to-stay.aspx#21944</link><pubDate>Sun, 11 Oct 2009 22:13:34 GMT</pubDate><guid isPermaLink="false">91db4bc3-5a69-4a9f-94bf-eedb569902ab:21944</guid><dc:creator>Mick</dc:creator><description>&lt;p&gt;Jesper.. &amp;nbsp;The issue here isn&amp;#39;t the text, it&amp;#39;s the writer. &amp;nbsp;My biggest pet hate is journo&amp;#39;s writing about security when they have no experience in IT let alone Security. &amp;nbsp;Typically this results in what we&amp;#39;ve seen here.. misinformation provided to the public. &amp;nbsp;The Sydney Morning Herald in Australia continually do this as well and despite a constant complaints refuse to hire an IT or InfoSec Professional to pen their IT articles.&lt;/p&gt;
&lt;p&gt;It doesn&amp;#39;t matter how hard we work... our work is being undone by these clowns.&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msinfluentials.com/aggbug.aspx?PostID=21944" width="1" height="1"&gt;</description></item><item><title>re: Passwords are here to stay</title><link>http://msinfluentials.com/blogs/jesper/archive/2009/10/10/passwords-are-here-to-stay.aspx#21943</link><pubDate>Sun, 11 Oct 2009 10:28:52 GMT</pubDate><guid isPermaLink="false">91db4bc3-5a69-4a9f-94bf-eedb569902ab:21943</guid><dc:creator>Larry Seltzer</dc:creator><description>&lt;p&gt;I wrote about it then too (&lt;a rel="nofollow" target="_new" href="http://www.eweek.com/c/a/Security/Will-Passphrases-Foretell-the-Death-of-Pa55W0rd5/"&gt;www.eweek.com/.../Will-Passphrases-Foretell-the-Death-of-Pa55W0rd5&lt;/a&gt; - and I probably linked to your article).&lt;/p&gt;
&lt;p&gt;The problem with passphrases is that a lot of sites (Amazon i think is one) don&amp;#39;t let you use a long-enough password or embed spaces.&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msinfluentials.com/aggbug.aspx?PostID=21943" width="1" height="1"&gt;</description></item><item><title>re: And finally, standard user malware</title><link>http://msinfluentials.com/blogs/jesper/archive/2009/08/31/and-finally-standard-user-malware.aspx#21939</link><pubDate>Sat, 03 Oct 2009 17:48:02 GMT</pubDate><guid isPermaLink="false">91db4bc3-5a69-4a9f-94bf-eedb569902ab:21939</guid><dc:creator>Eric Eskam</dc:creator><description>&lt;p&gt;I too am surprised it has taken this long for something like this to appear. &amp;nbsp;If Firefox can install in usermode, why not malware?&lt;/p&gt;
&lt;p&gt;BTW - a handy flowchart to help users decide if they really should click to see the dancing naked pigs:&lt;/p&gt;
&lt;p&gt;&lt;a rel="nofollow" target="_new" href="http://www.intac.net/a-flowchart-to-help-you-decide-when-to-click-past-the-security-warning/"&gt;www.intac.net/a-flowchart-to-help-you-decide-when-to-click-past-the-security-warning&lt;/a&gt;&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msinfluentials.com/aggbug.aspx?PostID=21939" width="1" height="1"&gt;</description></item><item><title>re: And finally, standard user malware</title><link>http://msinfluentials.com/blogs/jesper/archive/2009/08/31/and-finally-standard-user-malware.aspx#21914</link><pubDate>Thu, 10 Sep 2009 21:21:34 GMT</pubDate><guid isPermaLink="false">91db4bc3-5a69-4a9f-94bf-eedb569902ab:21914</guid><dc:creator>Hilton Travis</dc:creator><description>&lt;p&gt;G&amp;#39;day Jesper,&lt;/p&gt;
&lt;p&gt;All theswe filth are doing is following Microsoft&amp;#39;s lead with Microsoft Live Mesh and Microsoft Vine which don&amp;#39;t install into Program Files, but into AppData\Local, therefore not requiring elevated rights.&lt;/p&gt;
&lt;p&gt;Now, this is a huge security vulnerability to me - allowing non-Admin users the ability to install applications. &amp;nbsp;WTF was Microsoft thinking?&lt;/p&gt;
&lt;p&gt;Have you tried installing Live Mesh with &amp;quot;Run as Administrator&amp;quot;? &amp;nbsp;What does the error message &amp;quot;Live Mesh: Product does not support running under an elevated account. &amp;nbsp;This class is not configured to support Elevated activation. &amp;nbsp;Error: 80080017&amp;quot;. &amp;nbsp;Now, is that an error message, as a Security professional, that scares the pants off you, or what?&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msinfluentials.com/aggbug.aspx?PostID=21914" width="1" height="1"&gt;</description></item></channel></rss>