<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://msinfluentials.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Thoughts on Security by Obscurity</title><link>http://msinfluentials.com/blogs/jesper/archive/2008/05/13/thoughts-on-security-by-obscurity.aspx</link><description>This has not really been that normal a week for me, but at least another article made it into print. The June 2008 issue of TechNet Magazine is headlined by an article I wrote with my friend Roger Grimes, Security Adviser for Infoworld , on Security by</description><dc:language>en</dc:language><generator>CommunityServer 2008.5 SP2 (Build: 40407.4157)</generator><item><title>re: Thoughts on Security by Obscurity</title><link>http://msinfluentials.com/blogs/jesper/archive/2008/05/13/thoughts-on-security-by-obscurity.aspx#8679</link><pubDate>Mon, 16 Jun 2008 16:45:09 GMT</pubDate><guid isPermaLink="false">91db4bc3-5a69-4a9f-94bf-eedb569902ab:8679</guid><dc:creator>markk02474@gmail.com</dc:creator><description>&lt;p&gt;Microsoft&amp;#39;s security by obscurity:&lt;/p&gt;
&lt;p&gt;&amp;quot;The API utilized to register a firewall with the WSC can be obtained by contacting Microsoft at wscisv@microsoft.com. A Non-Disclosure Agreement (NDA) is required for the disclosure of this API due to security concerns.&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;a rel="nofollow" target="_new" href="http://msdn.microsoft.com/en-us/library/bb190942"&gt;msdn.microsoft.com/.../bb190942&lt;/a&gt;(VS.85).aspx&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msinfluentials.com/aggbug.aspx?PostID=8679" width="1" height="1"&gt;</description></item><item><title>re: Thoughts on Security by Obscurity</title><link>http://msinfluentials.com/blogs/jesper/archive/2008/05/13/thoughts-on-security-by-obscurity.aspx#8644</link><pubDate>Fri, 13 Jun 2008 02:21:26 GMT</pubDate><guid isPermaLink="false">91db4bc3-5a69-4a9f-94bf-eedb569902ab:8644</guid><dc:creator>markk02474@gmail.com</dc:creator><description>&lt;p&gt;Perhaps you can make Vista Firewall/NLA/RAS interactions less obscure? You gave a sample rule for VPN connections: netsh advfirewall firewall add rule name=&amp;quot;Allow CIFS on VPN interfaces&amp;quot; dir=out action=allow enable=yes profile=public localIP=any remoteIP=any remoteport=445 protocol=TCP interfacetype=RAS&lt;/p&gt;
&lt;p&gt;Now, if I use such rules on 5,000 user machines needing VPN access, won&amp;#39;t DSL (PPPoE), and dialup connections also be considered RAS connections and &amp;nbsp;match? Some number of users will be exposed using their home connections, right?&lt;/p&gt;
&lt;p&gt;Network Awareness is poorly documented. What&amp;#39;s the algorithm? Its triggered when an interface comes up and uses DHCP and gateway mac address info, but will it be triggered when I use a 3rd party VPN client shim driver to connect? Will it notice the routing change and new default gateway?&lt;/p&gt;
&lt;p&gt;I learned security through obscurity when I used the ITS operating system - some things haven&amp;#39;t changed!&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msinfluentials.com/aggbug.aspx?PostID=8644" width="1" height="1"&gt;</description></item><item><title>re: Thoughts on Security by Obscurity</title><link>http://msinfluentials.com/blogs/jesper/archive/2008/05/13/thoughts-on-security-by-obscurity.aspx#8279</link><pubDate>Sun, 18 May 2008 06:34:17 GMT</pubDate><guid isPermaLink="false">91db4bc3-5a69-4a9f-94bf-eedb569902ab:8279</guid><dc:creator>Victor Constanstinescu - MVP</dc:creator><description>&lt;p&gt;Not sure why the talkback didn&amp;#39;t work. Here it is: &lt;a rel="nofollow" target="_new" href="http://victor-youngun.blogspot.com/2008/05/great-debate-security-by-obscurity.html"&gt;victor-youngun.blogspot.com/.../great-debate-security-by-obscurity.html&lt;/a&gt;&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msinfluentials.com/aggbug.aspx?PostID=8279" width="1" height="1"&gt;</description></item></channel></rss>