<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" 
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	>

<channel>
	<title>My Security Planet &#187; Michael Howard's Web Log</title>
	<link>http://rgaucher.info/planet/</link>
	<description>My Security Planet &#187; Michael Howard's Web Log</description>
	<generator>Gregarius 0.5.4</generator>
	<language>en</language>
	<item>
		<title>Michael Howard's Web Log: Security Sessions at TechEd in Australia and New Zealand</title>
		<link>http://blogs.msdn.com/michael_howard/archive/2009/09/06/security-sessions-at-teched-in-australia-and-new-zealand.aspx</link>
		<pubDate>Sun, 06 Sep 2009 15:20:00 -0500</pubDate>
		<guid>http://blogs.msdn.com/michael_howard/archive/2009/09/06/security-sessions-at-teched-in-australia-and-new-zealand.aspx</guid>
		<content:encoded><![CDATA[	<p>
  I'm heading to TechEd Oz and NZ in a couple of hours to present the following:
</p>SEC312&nbsp; The "Everything Developers Need to Know About Security" Talk&nbsp;
<ul>
  <li>Oz: 9/10/2009 15:30-16:45&nbsp;
  </li>
  <li>NZ: 9/14/2009 14:15-15:30
  </li>
</ul>SEC201&nbsp; Inside the Microsoft Security Development Lifecycle: And how you can use it!&nbsp;&nbsp;
<ul>
  <li>Oz: 9/10/2009 11:30-12:45&nbsp;
  </li>
  <li>NZ: 9/15/2009 12:10-13:25
  </li>
</ul>
<p>
  I'm also giving a couple of half-day SDL workshops:
</p>SDL Workshop
<ul>
  <li>Oz: 9/11/2009 (I'll update once I get the time!)
  </li>
  <li>NZ: 9/13/2009 &nbsp;10:20 - 13:00
  </li>
</ul>
<p>
  If you cannot make it to TechEd this year, a number of sessions, including SEC201 will be made available through Live Meeting. More info <a href="http://www.msteched.com/australia/Public/techedlive.aspx">here</a>.
</p><img alt="" src="http://blogs.msdn.com/aggbug.aspx?PostID=9891996" /> ]]></content:encoded>
</item>
<item>
		<title>Michael Howard's Web Log: ATL, MS09-035 and the SDL </title>
		<link>http://blogs.msdn.com/michael_howard/archive/2009/07/28/atl-ms09-035-and-the-sdl.aspx</link>
		<pubDate>Tue, 28 Jul 2009 12:43:00 -0500</pubDate>
		<guid>http://blogs.msdn.com/michael_howard/archive/2009/07/28/atl-ms09-035-and-the-sdl.aspx</guid>
		<content:encoded><![CDATA[	<a href="http://blogs.msdn.com/sdl/archive/2009/07/28/atl-ms09-035-and-the-sdl.aspx">[blogs.msdn.com]</a><img alt="" src="http://blogs.msdn.com/aggbug.aspx?PostID=9851205" /> ]]></content:encoded>
</item>
<item>
		<title>Michael Howard's Web Log: Integrating the SDL process into Visual Studio</title>
		<link>http://blogs.msdn.com/michael_howard/archive/2009/05/19/integrating-the-sdl-process-into-visual-studio.aspx</link>
		<pubDate>Tue, 19 May 2009 11:53:27 -0500</pubDate>
		<guid>http://blogs.msdn.com/michael_howard/archive/2009/05/19/integrating-the-sdl-process-into-visual-studio.aspx</guid>
		<content:encoded><![CDATA[	<p>
  I’ve been a firm believer of integrating as much security tooling as possible into the development process so developers can get on with developing code and designing solutions rather than having to constantly think about dotting the security “i”s and crossing the security “t”s.
</p>
<p>
  The less security “friction” the better, because the more you can automate the more progress you can make.
</p>
<p>
  <a href="http://blogs.msdn.com/sdl/archive/2009/05/19/making-secure-code-easier.aspx">Jeremy Dallman has just announced</a> that we have released the Microsoft SDL Process Template for Visual Studio Team System, and yes, it’s free.
</p>
<p>
  I think this is a huge step forward because now software development teams outside of Microsoft can more easily track their adherence to the SDL.
</p>Technorati Tags: <a href="http://technorati.com/tags/SDL">SDL</a>,<a href="http://technorati.com/tags/Tools">Tools</a><img alt="" src="http://blogs.msdn.com/aggbug.aspx?PostID=9628586" /> ]]></content:encoded>
</item>
<item>
		<title>Michael Howard's Web Log: A Conversation About Threat Modeling</title>
		<link>http://blogs.msdn.com/michael_howard/archive/2009/05/01/a-conversation-about-threat-modeling.aspx</link>
		<pubDate>Fri, 01 May 2009 09:29:00 -0500</pubDate>
		<guid>http://blogs.msdn.com/michael_howard/archive/2009/05/01/a-conversation-about-threat-modeling.aspx</guid>
		<content:encoded><![CDATA[	<p>
  This was fun to write; in fact, other than minor edits I wrote it in a single two hour sitting with my laptop by the pool :)
</p>
<p>
  <a href="http://msdn.microsoft.com/en-us/magazine/dd727503.aspx">[msdn.microsoft.com]</a>
</p><img alt="" src="http://blogs.msdn.com/aggbug.aspx?PostID=9582435" /> ]]></content:encoded>
</item>
<item>
		<title>Michael Howard's Web Log: Ken Johnson (Skywing) joins Microsoft</title>
		<link>http://blogs.msdn.com/michael_howard/archive/2009/03/24/ken-johnson-skywing-joins-microsoft.aspx</link>
		<pubDate>Tue, 24 Mar 2009 17:27:00 -0500</pubDate>
		<guid>http://blogs.msdn.com/michael_howard/archive/2009/03/24/ken-johnson-skywing-joins-microsoft.aspx</guid>
		<content:encoded><![CDATA[	<p>
  Following close on the heels of security experts&nbsp;<a href="http://blogs.msdn.com/michael_howard/archive/2008/08/18/matt-miller-joins-the-security-science-team.aspx">Matt Miller</a>, <a href="http://blogs.msdn.com/michael_howard/archive/2006/06/26/647690.aspx">Adam Shostack</a> and <a href="http://blogs.msdn.com/michael_howard/archive/2008/01/17/crispin-cowan-joins-the-windows-security-team.aspx">Crispin Cowan</a> joining Microsoft, I am pleased to announce that Ken Johnson, AKA Skywing, has joined our group.
</p>
<p>
  &nbsp;
</p>
<p>
  Ken brings an enormous amount of reverse engineering and defense-subversion skill to Microsoft. Ken will be working on anything and everything related vulnerabilities, exploits, defenses, bypassing defenses and more. Ken also maintains a blog on debugging, reverse engineering, and security-related topics (along with various personal projects) at: <a href="http://www.nynaeve.net/">http://www.nynaeve.net</a>.
</p>
<p>
  &nbsp;
</p>
<p>
  Welcome, Ken!
</p><img alt="" src="http://blogs.msdn.com/aggbug.aspx?PostID=9505425" /> ]]></content:encoded>
</item>
<item>
		<title>Michael Howard's Web Log: Free Download: Writing Secure Code for Windows Vista</title>
		<link>http://blogs.msdn.com/michael_howard/archive/2008/12/30/free-download-writing-secure-code-for-windows-vista.aspx</link>
		<pubDate>Tue, 30 Dec 2008 22:07:00 -0600</pubDate>
		<guid>http://blogs.msdn.com/michael_howard/archive/2008/12/30/free-download-writing-secure-code-for-windows-vista.aspx</guid>
		<content:encoded><![CDATA[	<p>
  "For 25 years, Microsoft Press books have focused on helping you take your skills and knowledge to the next level. Celebrate our 25th Anniversary with a "Free E-Book of the Month" offer! Simply sign up for the Microsoft Press Book Connection Newsletter for notification of offers, register, and download the selection of the month."
</p>
<p>
  <a href="http://csna01.libredigital.com/?urrs4gt63d">[csna01.libredigital.com]</a>
</p>
<p>
  :)
</p><img alt="" src="http://blogs.msdn.com/aggbug.aspx?PostID=9258039" /> ]]></content:encoded>
</item>
<item>
		<title>Michael Howard's Web Log: Secure software development practices 'not rocket science'</title>
		<link>http://blogs.msdn.com/michael_howard/archive/2008/12/08/secure-software-development-practices-not-rocket-science.aspx</link>
		<pubDate>Mon, 08 Dec 2008 16:09:00 -0600</pubDate>
		<guid>http://blogs.msdn.com/michael_howard/archive/2008/12/08/secure-software-development-practices-not-rocket-science.aspx</guid>
		<content:encoded><![CDATA[	<a href="http://searchsoftwarequality.techtarget.com/news/article/0,289142,sid92_gci1340940,00.html">[searchsoftwarequality.techtarget.com]</a>#<img alt="" src="http://blogs.msdn.com/aggbug.aspx?PostID=9185589" /> ]]></content:encoded>
</item>
<item>
		<title>Michael Howard's Web Log: A Proactive Approach to Building a Successful Security Development Lifecycle Program</title>
		<link>http://blogs.msdn.com/michael_howard/archive/2008/11/19/a-proactive-approach-to-building-a-successful-security-development-lifecycle-program.aspx</link>
		<pubDate>Wed, 19 Nov 2008 19:49:00 -0600</pubDate>
		<guid>http://blogs.msdn.com/michael_howard/archive/2008/11/19/a-proactive-approach-to-building-a-successful-security-development-lifecycle-program.aspx</guid>
		<content:encoded><![CDATA[	<p>
  At this point most of you have heard about the Microsoft SDL and some of activities and deliverables associated with it.
</p>
<p>
  However, I still receive a number of questions, specifically, how and where development organizations can start deploying SDL.
</p>
<p>
  Good news!&nbsp;&nbsp;
</p>
<p>
  One of the new <a href="http://msdn.microsoft.com/en-us/security/dd219581.aspx">Microsoft SDL Pro Network</a>&nbsp;members, <a href="http://www.securityinnovation.com/">Security Innovation</a>,&nbsp;has invited me to address this and other SDL questions at an <a href="https://www124.livemeeting.com/lrs/ol_1580/Registration.aspx?pageName=jspjs7230jld9wbf">upcoming webcast</a>&nbsp;titled “A Proactive Approach to Building a Successful Security Development Lifecycle Program.”
</p>
<p>
  SI&nbsp;also invited Jon Oltsik, an analyst from the Enterprise Strategy Group, to present his <a href="http://www.enterprisestrategygroup.com/ESGPublications/BriefPopup.asp?ReportID=1093">point of view</a>&nbsp;on the value of the SDL to development organizations. &nbsp;It should be an interesting event, and will hopefully answer many of the questions I have received from the field. &nbsp;If we don’t address your questions during our presentations, there is going to be Q&amp;A at the end …<br />
  &nbsp;<br />
  If you are interested in attending this live web event, it is going to take place TOMORROW Thursday, November 20th, at 1:00pm ET, and you can register for it <a href="https://www124.livemeeting.com/lrs/ol_1580/Registration.aspx?pageName=jspjs7230jld9wbf">here</a>.&nbsp;&nbsp;
</p>
<p>
  Hope you can make it!
</p><img alt="" src="http://blogs.msdn.com/aggbug.aspx?PostID=9126973" /> ]]></content:encoded>
</item>
<item>
		<title>Michael Howard's Web Log: Improvements in Office Security </title>
		<link>http://blogs.msdn.com/michael_howard/archive/2008/11/17/improvements-in-office-security.aspx</link>
		<pubDate>Mon, 17 Nov 2008 22:59:00 -0600</pubDate>
		<guid>http://blogs.msdn.com/michael_howard/archive/2008/11/17/improvements-in-office-security.aspx</guid>
		<content:encoded><![CDATA[	<p>
  David LeBlanc has an <a href="http://blogs.msdn.com/david_leblanc/archive/2008/11/17/improvements-in-office-security.aspx">excellent write-up</a> of the results (so far) of all the security work the Office guys have been doing over the last few years.
</p>
<p>
  Net: about a 50% reduction in vulns!
</p><img alt="" src="http://blogs.msdn.com/aggbug.aspx?PostID=9116639" /> ]]></content:encoded>
</item>
<item>
		<title>Michael Howard's Web Log: Volume 5 of the Microsoft Security Intelligence Report is out</title>
		<link>http://blogs.msdn.com/michael_howard/archive/2008/11/03/volume-5-of-the-microsoft-security-intelligence-report-is-out.aspx</link>
		<pubDate>Mon, 03 Nov 2008 08:16:00 -0600</pubDate>
		<guid>http://blogs.msdn.com/michael_howard/archive/2008/11/03/volume-5-of-the-microsoft-security-intelligence-report-is-out.aspx</guid>
		<content:encoded><![CDATA[	Volume 5 of the Microsoft Security Intelligence Report is <a href="http://www.microsoft.com/security/portal/sir.aspx">now out</a>, highlights include:
<ul>
  <li>Security vulnerability disclosures - Microsoft and third-party software
  </li>
  <li>Vulnerability Exploits – Microsoft software
  </li>
  <li>Browser-based exploits - Microsoft and third-party software
  </li>
  <li>Security and privacy breaches
  </li>
  <li>Malicious and potentially unwanted software trends
  </li>
</ul>
<p>
  Volume 5 of the SIR also includes a detailed examination of the threat ecosystem which explains how threats propagate across the internet, how users become infected and the resultant impact on privacy and identity theft.
</p>
<p>
  &nbsp;
</p>
<p>
  The one item that stood out for me was the move from successfully attacking Microsoft applications and browser objects to attacking and compromising 3rd-party applictions and browser objects.
</p><img alt="" src="http://blogs.msdn.com/aggbug.aspx?PostID=9033311" /> ]]></content:encoded>
</item>


</channel>
</rss>
