<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
		xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd"
	xmlns:media="http://search.yahoo.com/mrss/"
>

<channel>
	<title>Network Security Blog &#187; Microsoft</title>
	<atom:link href="http://www.mckeay.net/category/microsoft/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.mckeay.net</link>
	<description>The views of one man on security, privacy and anything else that catches his attention.  The views expressed on this blog do not reflect the views of my employer or anyone other than myself.</description>
	<lastBuildDate>Wed, 01 Feb 2012 20:45:53 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=</generator>
	<copyright>2006-2007 </copyright>
	<managingEditor>martin@mckeay.net (Network Security Blog)</managingEditor>
	<webMaster>martin@mckeay.net (Network Security Blog)</webMaster>
	<ttl>1440</ttl>
	<image>
		<url>http://mckeay.net/wp-content/plugins/podpress/images/networksecuritylogo144.jpg</url>
		<title>Network Security Blog</title>
		<link>http://www.mckeay.net</link>
		<width>144</width>
		<height>144</height>
	</image>
	<itunes:subtitle></itunes:subtitle>
	<itunes:summary>The views of one man on security, privacy and anything else that catches his attention</itunes:summary>
	<itunes:keywords></itunes:keywords>
	<itunes:category text="Society &#38; Culture" />
	<itunes:author>Network Security Blog</itunes:author>
	<itunes:owner>
		<itunes:name>Network Security Blog</itunes:name>
		<itunes:email>martin@mckeay.net</itunes:email>
	</itunes:owner>
	<itunes:block>no</itunes:block>
	<itunes:explicit>no</itunes:explicit>
	<itunes:image href="http://mckeay.net/wp-content/plugins/podpress/images/networksecuritylogo300.jpg" />
		<item>
		<title>Open Tabs 11/04/11</title>
		<link>http://www.mckeay.net/2011/11/04/open-tabs-110411/</link>
		<comments>http://www.mckeay.net/2011/11/04/open-tabs-110411/#comments</comments>
		<pubDate>Fri, 04 Nov 2011 15:56:01 +0000</pubDate>
		<dc:creator>Martin</dc:creator>
				<category><![CDATA[Cloud]]></category>
		<category><![CDATA[Government]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[PCI]]></category>
		<category><![CDATA[Risk]]></category>

		<guid isPermaLink="false">http://www.mckeay.net/2011/11/04/open-tabs-110411/</guid>
		<description><![CDATA[It&#8217;s almost time to hop in the car and head for #BSidesDFW (I even think in hashtags some days) in about an hour.&#160; I find it annoying that I have to leave the house about 3 hours before my flight to have any chance of making it, since it takes 90 minutes to get to [...]]]></description>
			<content:encoded><![CDATA[<p>It&#8217;s almost time to hop in the car and head for <a target="_blank" href="http://www.securitybsides.com/w/page/36779575/BSidesDFW-2011">#BSidesDFW</a> (I even think in hashtags some days) in about an hour.&nbsp; I find it annoying that I have to leave the house about 3 hours before my flight to have any chance of making it, since it takes 90 minutes to get to the airport and about 45 minutes to get through the TSA checkpoint most of the time.&nbsp; I was joking around on Twitter earlier this week and said I&#8217;d vote for the first Presidential candidate, Republican or Democrat, who promised to abolish the TSA; it turned out that <a target="_blank" href="http://articles.latimes.com/2011/jul/06/news/la-pn-ron-paul-tsa-20110706">Ron Paul had already made that promise</a>, but we&#8217;ll see if he&#8217;s still slugging it out by the time the primaries roll around.&nbsp; In any case, I need to get packed up and head out.&nbsp; I&#8217;m going to try to get a few interviews at BSidesDFW for the podcast, since there are so many interesting people speaking tomorrow.&nbsp; </p>
<p><b>Open Tabs 11/04/11:</b>
<ul>
<li><a target="_blank" href="http://blogs.technet.com/b/msrc/archive/2011/11/03/untrusted-certificate-store-to-be-updated.aspx">Untrusted Certificate Store to be updated</a> &#8211; Microsoft delists another certificate authority</li>
<li><a target="_blank" href="http://www.usajobs.gov/GetJob/PrintPreview/301181700">DHS looking for a new CISO</a> &#8211; If you want the role, more power to you!&nbsp; I wouldn&#8217;t touch it with a 10&#8242; pole, personally</li>
<li><a target="_blank" href="http://www.darkreading.com/blog/231902307/security-ostriches-and-disintermediation.html">Security Ostriches and Disintermediation</a> &#8211; Big words from Mike Rothman about HD Moore&#8217;s Law</li>
<li><a target="_blank" href="http://www.google.com/hostednews/ap/article/ALeqM5jGuH2XxQaLndlUL9ZyCHrblyaUKA">CIA following Twitter, Facebook</a> &#8211; Why would this surprise anyone in the security field?</li>
<li><a target="_blank" href="http://www.reuters.com/article/2011/11/04/us-china-usa-cyber-idUSTRE7A31FW20111104">China scorns U.S. cyber espionage charges</a> &#8211; Another big surprise, China is denying any wrong doing and acting all indignant.&nbsp;&nbsp;</li>
<li><a target="_blank" href="http://www.bloomberg.com/news/2011-11-03/syria-crackdown-gets-italy-firm-s-aid-with-u-s-europe-spy-gear.html">Syria crackdown aided by U.S.-Europe spy gear</a> &#8211; There&#8217;s more and more evidence that US technologies are being used to support oppressive regimes.&nbsp; And I don&#8217;t think it will stop any time soon.&nbsp;</li>
<li><a target="_blank" href="http://net-security.org/secworld.php?id=11889">Most firms don&#8217;t coordinate security planning</a> &#8211; We need to learn to integrate better with the board room, that&#8217;s a fact.</li>
<li><a target="_blank" href="https://www.infosecisland.com/security-videos-view/17810-Hacker-Halted-Mike-Dahn-and-Martin-McKeay-on-Compliance-in-the-Cloud.html">Mike Dahn and me from Hacker Halted</a> &#8211; I&#8217;m going to close my eyes and ears, I can&#8217;t stand to see myself in video.&nbsp; </li>
</ul>
<p><iframe src="http://player.vimeo.com/video/31447901?title=0&amp;byline=0&amp;portrait=0" webkitallowfullscreen="" allowfullscreen="" width="550" frameborder="0" height="309"></iframe></p>

<span class="slashdigglicious">
<a href="http://slashdot.org/bookmark.pl?url=http%3A%2F%2Fwww.mckeay.net%2F2011%2F11%2F04%2Fopen-tabs-110411%2F&amp;title=Open+Tabs+11%2F04%2F11" title="Slashdot It!"><img src="http://slashdot.org/favicon.ico" height="16" width="16" alt="[Slashdot]" /></a>
<a href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fwww.mckeay.net%2F2011%2F11%2F04%2Fopen-tabs-110411%2F&amp;title=Open+Tabs+11%2F04%2F11" title="Digg This Story"><img src="http://digg.com/favicon.ico" width="16" height="16" alt="[Digg]" /></a>
<a href="http://reddit.com/submit?url=http%3A%2F%2Fwww.mckeay.net%2F2011%2F11%2F04%2Fopen-tabs-110411%2F&amp;title=Open+Tabs+11%2F04%2F11" title="Reddit"><img src="http://reddit.com/favicon.ico" width="16" height="16" alt="[Reddit]" /></a>
<a href="http://del.icio.us/post?url=http%3A%2F%2Fwww.mckeay.net%2F2011%2F11%2F04%2Fopen-tabs-110411%2F&amp;title=Open+Tabs+11%2F04%2F11" title="Save to del.icio.us" onclick="window.open('http://del.icio.us/post?v=4&amp;noui&amp;jump=close&amp;url=http%3A%2F%2Fwww.mckeay.net%2F2011%2F11%2F04%2Fopen-tabs-110411%2F&amp;title=Open+Tabs+11%2F04%2F11', 'delicious', 'toolbar=no,width=700,height=400'); return false;"><img src="http://images.del.icio.us/static/img/delicious.small.gif" width="16" height="16" alt="[del.icio.us]" /></a>
<a href="http://www.facebook.com/share.php?u=http%3A%2F%2Fwww.mckeay.net%2F2011%2F11%2F04%2Fopen-tabs-110411%2F" title="Share on Facebook"><img src="http://www.facebook.com/favicon.ico" width="16" height="16" alt="[Facebook]" /></a>
<a href="http://technorati.com/faves?add=http%3A%2F%2Fwww.mckeay.net%2F2011%2F11%2F04%2Fopen-tabs-110411%2F" title="Add to my Technorati Favorites"><img src="http://technorati.com/favicon.ico" width="16" height="16" alt="[Technorati]" /></a>
<a href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http%3A%2F%2Fwww.mckeay.net%2F2011%2F11%2F04%2Fopen-tabs-110411%2F&amp;title=Open+Tabs+11%2F04%2F11" title="Save to Google Bookmarks"><img src="http://www.google.com/favicon.ico" width="16" height="16" alt="[Google]" /></a>
<a href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fwww.mckeay.net%2F2011%2F11%2F04%2Fopen-tabs-110411%2F&amp;title=Open+Tabs+11%2F04%2F11" title="Stumble it!"><img src="http://www.stumbleupon.com/favicon.ico" width="16" height="16" alt="[StumbleUpon]" /></a>
</span>]]></content:encoded>
			<wfw:commentRss>http://www.mckeay.net/2011/11/04/open-tabs-110411/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Network Security Podcast, Episode 216</title>
		<link>http://www.mckeay.net/2010/10/04/asking-the-right-questions-about-tokenization-2/</link>
		<comments>http://www.mckeay.net/2010/10/04/asking-the-right-questions-about-tokenization-2/#comments</comments>
		<pubDate>Mon, 04 Oct 2010 12:55:00 +0000</pubDate>
		<dc:creator>Martin</dc:creator>
				<category><![CDATA[General]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Podcast]]></category>
		<category><![CDATA[Security Advisories]]></category>

		<guid isPermaLink="false">http://www.mckeay.net/2010/10/04/asking-the-right-questions-about-tokenization-2/</guid>
		<description><![CDATA[Despite catching some kind of ConFlu at HacKid, Zach manages to join Martin for a sniffle-filled show. Rich is off in London, speaking at RSA Europe 2010 (or, well, sleeping). Network Security Podcast, Episode 216, October 12, 2010 Time: 32:45 Show Notes: HacKid Conference &#8211; Boston 2010 (wrap-up by SecBarbie) Don&#8217;t expect to peer into [...]]]></description>
			<content:encoded><![CDATA[<p>Despite catching some kind of ConFlu at <a href="http://www.hackid.org/">HacKid</a>,  Zach manages to join Martin for a sniffle-filled show. Rich is off in  London, speaking at RSA Europe 2010 (or, well, sleeping).</p>
<p><a href="http://traffic.libsyn.com/mckeay/nsp-101210-ep216.mp3">Network Security Podcast, Episode 216, October 12, 2010<br />
 Time: 32:45</a></p>
<p>Show Notes:</p>
<ul>
<li><a href="http://www.secsocial.com/blog/?p=449">HacKid Conference &ndash; Boston 2010</a> (wrap-up by <a href="http://twitter.com/secbarbie">SecBarbie</a>)</li>
<li><a href="http://www.networkworld.com/news/2010/100710-google-cloud-security.html">Don&#8217;t expect to peer into Google cloud services security</a></li>
<li><a href="http://www.npr.org/templates/story/story.php?storyId=130451369">The Zombie Network: Beware &#8216;Free Public WiFi&#8217;</a></li>
<li><a href="http://www.zdnet.com/blog/security/patch-tuesday-critical-flaws-haunt-microsoft-office-ie-browser/7447?tag=nl.e589">Patch Tuesday: Critical flaws haunt Microsoft Office, IE browser</a></li>
<li>Tonight&rsquo;s Music:&nbsp; <a href="http://www.musicalley.com/music/listeners/artistdetails.php?BandHash=104e963c7e7e827169aae917cf273341">Bored by Robin Tymm</a></li>
</ul>

<span class="slashdigglicious">
<a href="http://slashdot.org/bookmark.pl?url=http%3A%2F%2Fwww.mckeay.net%2F2010%2F10%2F04%2Fasking-the-right-questions-about-tokenization-2%2F&amp;title=Network+Security+Podcast%2C+Episode+216" title="Slashdot It!"><img src="http://slashdot.org/favicon.ico" height="16" width="16" alt="[Slashdot]" /></a>
<a href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fwww.mckeay.net%2F2010%2F10%2F04%2Fasking-the-right-questions-about-tokenization-2%2F&amp;title=Network+Security+Podcast%2C+Episode+216" title="Digg This Story"><img src="http://digg.com/favicon.ico" width="16" height="16" alt="[Digg]" /></a>
<a href="http://reddit.com/submit?url=http%3A%2F%2Fwww.mckeay.net%2F2010%2F10%2F04%2Fasking-the-right-questions-about-tokenization-2%2F&amp;title=Network+Security+Podcast%2C+Episode+216" title="Reddit"><img src="http://reddit.com/favicon.ico" width="16" height="16" alt="[Reddit]" /></a>
<a href="http://del.icio.us/post?url=http%3A%2F%2Fwww.mckeay.net%2F2010%2F10%2F04%2Fasking-the-right-questions-about-tokenization-2%2F&amp;title=Network+Security+Podcast%2C+Episode+216" title="Save to del.icio.us" onclick="window.open('http://del.icio.us/post?v=4&amp;noui&amp;jump=close&amp;url=http%3A%2F%2Fwww.mckeay.net%2F2010%2F10%2F04%2Fasking-the-right-questions-about-tokenization-2%2F&amp;title=Network+Security+Podcast%2C+Episode+216', 'delicious', 'toolbar=no,width=700,height=400'); return false;"><img src="http://images.del.icio.us/static/img/delicious.small.gif" width="16" height="16" alt="[del.icio.us]" /></a>
<a href="http://www.facebook.com/share.php?u=http%3A%2F%2Fwww.mckeay.net%2F2010%2F10%2F04%2Fasking-the-right-questions-about-tokenization-2%2F" title="Share on Facebook"><img src="http://www.facebook.com/favicon.ico" width="16" height="16" alt="[Facebook]" /></a>
<a href="http://technorati.com/faves?add=http%3A%2F%2Fwww.mckeay.net%2F2010%2F10%2F04%2Fasking-the-right-questions-about-tokenization-2%2F" title="Add to my Technorati Favorites"><img src="http://technorati.com/favicon.ico" width="16" height="16" alt="[Technorati]" /></a>
<a href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http%3A%2F%2Fwww.mckeay.net%2F2010%2F10%2F04%2Fasking-the-right-questions-about-tokenization-2%2F&amp;title=Network+Security+Podcast%2C+Episode+216" title="Save to Google Bookmarks"><img src="http://www.google.com/favicon.ico" width="16" height="16" alt="[Google]" /></a>
<a href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fwww.mckeay.net%2F2010%2F10%2F04%2Fasking-the-right-questions-about-tokenization-2%2F&amp;title=Network+Security+Podcast%2C+Episode+216" title="Stumble it!"><img src="http://www.stumbleupon.com/favicon.ico" width="16" height="16" alt="[StumbleUpon]" /></a>
</span>]]></content:encoded>
			<wfw:commentRss>http://www.mckeay.net/2010/10/04/asking-the-right-questions-about-tokenization-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://traffic.libsyn.com/mckeay/nsp-101210-ep216.mp3" length="0" type="audio/mpeg" />
	</item>
		<item>
		<title>Network Security Podcast, Episode 192</title>
		<link>http://www.mckeay.net/2010/04/06/network-security-podcast-episode-192/</link>
		<comments>http://www.mckeay.net/2010/04/06/network-security-podcast-episode-192/#comments</comments>
		<pubDate>Wed, 07 Apr 2010 03:51:15 +0000</pubDate>
		<dc:creator>Martin</dc:creator>
				<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.mckeay.net/2010/04/06/network-security-podcast-episode-192/</guid>
		<description><![CDATA[Martin, Rich, and Zach talk with special guest Katie Moussouris, Senior Security Strategist at the Microsoft Security Response Center. Katie has been doing some work on ISO work item 29147 (&#8220;Responsible Vulnerability Disclosure&#8221;) and shares with us her experiences in this process, as well as her thoughts on software security improvement. Oh, and Rich gawks [...]]]></description>
			<content:encoded><![CDATA[<p>Martin, Rich, and Zach talk with special guest <a target="_blank" href="http://blogs.msdn.com/katie_moussouris">Katie Moussouris</a>, Senior Security Strategist at the <a target="_blank" href="http://www.microsoft.com/Security/msrc/default.aspx">Microsoft Security Response Center</a>. Katie has been doing some work on ISO work item 29147 (&#8220;Responsible Vulnerability Disclosure&#8221;) and shares with us her experiences in this process, as well as her thoughts on software security improvement. Oh, and Rich gawks about some new gadget which shan&#8217;t be named.&nbsp; We went a little long tonight because Katie has so much experience in the real world, but we think it was worth it.</p>
<p><a href="http://media.libsyn.com/media/mckeay/nsp-040610-ep192.mp3" target="_blank">Network  Security Podcast, Episode 192, April 6, 2010<br />Time:&nbsp; 40:25<br /></a><br />Show Notes:
<ul>
<li><a href="http://www.sudosecure.net/archives/636">Are PDF&#8217;s Worm-able?</a></li>
<li><a href="http://searchsecurity.techtarget.com/news/article/0,289142,sid14_gci1508039,00.html?track=sy160&amp;utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed:+techtarget/Searchsecurity/SecurityWire+%28SearchSecurity+:+Security+Wire+Daily+News%29">Security spending finds misaligned IT security budgets</a></li>
<li><a href="http://blogs.msdn.com/katie_moussouris/archive/2009/11/15/iso-what-you-did-last-summer.aspx">ISO What You Did Last Summer</a></li>
<li>Tonight’s Music: <a href="http://music.podshow.com/music/listeners/artistdetails.php?BandHash=67a91475979daeea3ea83f481993b41f">(Imagine the girlfriends I&#8217;d have) If I Still Had Hair by The Public Good</a></li>
<p></ul>

<span class="slashdigglicious">
<a href="http://slashdot.org/bookmark.pl?url=http%3A%2F%2Fwww.mckeay.net%2F2010%2F04%2F06%2Fnetwork-security-podcast-episode-192%2F&amp;title=Network+Security+Podcast%2C+Episode+192" title="Slashdot It!"><img src="http://slashdot.org/favicon.ico" height="16" width="16" alt="[Slashdot]" /></a>
<a href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fwww.mckeay.net%2F2010%2F04%2F06%2Fnetwork-security-podcast-episode-192%2F&amp;title=Network+Security+Podcast%2C+Episode+192" title="Digg This Story"><img src="http://digg.com/favicon.ico" width="16" height="16" alt="[Digg]" /></a>
<a href="http://reddit.com/submit?url=http%3A%2F%2Fwww.mckeay.net%2F2010%2F04%2F06%2Fnetwork-security-podcast-episode-192%2F&amp;title=Network+Security+Podcast%2C+Episode+192" title="Reddit"><img src="http://reddit.com/favicon.ico" width="16" height="16" alt="[Reddit]" /></a>
<a href="http://del.icio.us/post?url=http%3A%2F%2Fwww.mckeay.net%2F2010%2F04%2F06%2Fnetwork-security-podcast-episode-192%2F&amp;title=Network+Security+Podcast%2C+Episode+192" title="Save to del.icio.us" onclick="window.open('http://del.icio.us/post?v=4&amp;noui&amp;jump=close&amp;url=http%3A%2F%2Fwww.mckeay.net%2F2010%2F04%2F06%2Fnetwork-security-podcast-episode-192%2F&amp;title=Network+Security+Podcast%2C+Episode+192', 'delicious', 'toolbar=no,width=700,height=400'); return false;"><img src="http://images.del.icio.us/static/img/delicious.small.gif" width="16" height="16" alt="[del.icio.us]" /></a>
<a href="http://www.facebook.com/share.php?u=http%3A%2F%2Fwww.mckeay.net%2F2010%2F04%2F06%2Fnetwork-security-podcast-episode-192%2F" title="Share on Facebook"><img src="http://www.facebook.com/favicon.ico" width="16" height="16" alt="[Facebook]" /></a>
<a href="http://technorati.com/faves?add=http%3A%2F%2Fwww.mckeay.net%2F2010%2F04%2F06%2Fnetwork-security-podcast-episode-192%2F" title="Add to my Technorati Favorites"><img src="http://technorati.com/favicon.ico" width="16" height="16" alt="[Technorati]" /></a>
<a href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http%3A%2F%2Fwww.mckeay.net%2F2010%2F04%2F06%2Fnetwork-security-podcast-episode-192%2F&amp;title=Network+Security+Podcast%2C+Episode+192" title="Save to Google Bookmarks"><img src="http://www.google.com/favicon.ico" width="16" height="16" alt="[Google]" /></a>
<a href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fwww.mckeay.net%2F2010%2F04%2F06%2Fnetwork-security-podcast-episode-192%2F&amp;title=Network+Security+Podcast%2C+Episode+192" title="Stumble it!"><img src="http://www.stumbleupon.com/favicon.ico" width="16" height="16" alt="[StumbleUpon]" /></a>
</span>]]></content:encoded>
			<wfw:commentRss>http://www.mckeay.net/2010/04/06/network-security-podcast-episode-192/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://media.libsyn.com/media/mckeay/nsp-040610-ep192.mp3" length="38808720" type="audio/mpeg" />
	</item>
		<item>
		<title>Ethics of spilled COFEE</title>
		<link>http://www.mckeay.net/2009/11/08/ethics-of-spilled-cofee/</link>
		<comments>http://www.mckeay.net/2009/11/08/ethics-of-spilled-cofee/#comments</comments>
		<pubDate>Sun, 08 Nov 2009 17:06:11 +0000</pubDate>
		<dc:creator>Martin</dc:creator>
				<category><![CDATA[Government]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Security Advisories]]></category>
		<category><![CDATA[Simple Security]]></category>

		<guid isPermaLink="false">http://www.mckeay.net/2009/11/08/ethics-of-spilled-cofee/</guid>
		<description><![CDATA[Last year Microsoft released a tool called COFEE (Computer Online Forensic Evidence Extractor) to law enforcement agencies around the nation and around the world a couple of years ago.&#160; While COFEE is a professional tool, it&#8217;s meant for the average police officer who may not have a lot of experience with computers; you just plug [...]]]></description>
			<content:encoded><![CDATA[<p>Last year Microsoft released a tool called <a href="http://www.microsoft.com/industry/government/solutions/cofee/default.aspx">COFEE (Computer Online Forensic Evidence Extractor) </a>to law enforcement agencies around the nation and around the world a <a href="http://www.slashgear.com/microsoft-cofee-security-key-sucks-criminal-data-from-locked-down-pcs-2911404/">couple of years ago</a>.&nbsp; While COFEE is a professional tool, it&#8217;s meant for the average police officer who may not have a lot of experience with computers; you just plug a USB key with COFEE installed and if autorun is enabled on the computer, it will run a series of diagnostics, writes a report and generally gives a quick and dirty analysis of the computer.&nbsp; It&#8217;s not an exhaustive tool and most of the commands and tools the COFEE uses are things that you already have on your computer and could run manually any time you want.&nbsp; It&#8217;s a tool law enforcement officers need and should have, and it&#8217;s been a pretty closely guarded tool &#8211; until now.</p>
<p>In the last 48 hours, a user on the what.cd uploaded torrent of COFEE and made it available for any user to download.&nbsp; Which, of course, means that it&#8217;s now available on any number of bittorrent sites.&nbsp; The site it was originally found on did something they rarely do and <a href="http://torrentfreak.com/cofee-forensic-tool-leaks-to-what-cd-admins-ban-it-091108/">took the torrent offline</a>, but it was already too late and the tool is in the wild.&nbsp; Even if many of the bittorent sites agree to pull the torrent, there&#8217;s enough users who have the file and enough sites that will be uncooperative that it&#8217;s very unlikely that this djinni can be put back in the bottle.&nbsp; The fact that this tool has been a big mystery before now has made it very enticing, but getting your hands on a copy has been limited to a very few people who were in law enforcement or had friends that were.</p>
<p>It needs to be pointed out that is owned and jealously guarded by Microsoft.&nbsp; I won&#8217;t be surprised if they start going after people to get this removed from the Internet.&nbsp; Surprisingly the folks at What.cd say they took down the torrent on their own, with no prompting from either Microsoft or law enforcement.&nbsp; It may be that they decided the amount of attention it could draw to a site like theirs was more than they were willing to itself.&nbsp; Or it could be they did it for altruistic reasons, but I&#8217;m more willing to believe in the former than the latter.</p>
<p>Now that the COFEE has been spilled into the tubes of the Interweb thingy, what are our moral and ethical responsibilities as security professionals concerning the tool?&nbsp; Should we ignore it and hope the police can pull it off the bittorrent sites before everyone and their brother have a copy?&nbsp; Should we be reporting people who make it available?&nbsp; Or should we be reviewing the tool ourselves and proposing ways to make it better?&nbsp; This is a tool that&#8217;s aimed at letting police officers who are computer novices collect valuable forensics information using applications that are available natively in Windows and creating a simple report for future reference.&nbsp; While this is interesting, it&#8217;s nothing top secret or even that revolutionary.&nbsp; I suspect the main reason it was only available to law enforcement officers was to keep the malware creators and hackers from the limits of COFEE and figuring ways to prevent it from collecting anything if they ever have their own computers compromised.&nbsp; </p>
<p>Personally I think the tool&#8217;s been leaked and rather than try to get it back, law enforcement and the security community should be concentrating on providing an even better tool that will do everything COFEE can do and more using open source tools.&nbsp; There are any number of forensics tools already out there that will do a very good job of evaluating a desktop&#8217;s running configuration that could be made at least as easy to use as COFEE; the hard part would probably be getting law enforcement agents to accept something that didn&#8217;t have a huge name like Microsoft behind it.&nbsp; For example, if a limited version of <a href="http://remote-exploit.org/">Backtrack </a>was created that would run when you plug a USB key into the computer, the amount of data collected could be greatly increased.&nbsp; </p>
<p>If there are already other tools available that can easily and cheaply provide law enforcement with forensics evidence they can use in court, I don&#8217;t know of them and would appreciate some pointers.&nbsp; If not, someone needs to create something and make it available to law enforcement, especially if it&#8217;s something that&#8217;s easy for a computer neophyte to use.&nbsp; I don&#8217;t think that having COFEE leaked reduces it&#8217;s effectiveness or makes it harder for law enforcement to use, but I believe that the open source community can create a better tool and make it available to everyone without feeling a need to keep it&#8217;s capabilities secret.&nbsp; </p>
<p>&nbsp; </p>
<p>
<div class="zemanta-pixie"><img class="zemanta-pixie-img" alt="" src="http://img.zemanta.com/pixy.gif?x-id=b5325024-a872-8219-8766-8ab772ee687d" /></div>

<span class="slashdigglicious">
<a href="http://slashdot.org/bookmark.pl?url=http%3A%2F%2Fwww.mckeay.net%2F2009%2F11%2F08%2Fethics-of-spilled-cofee%2F&amp;title=Ethics+of+spilled+COFEE" title="Slashdot It!"><img src="http://slashdot.org/favicon.ico" height="16" width="16" alt="[Slashdot]" /></a>
<a href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fwww.mckeay.net%2F2009%2F11%2F08%2Fethics-of-spilled-cofee%2F&amp;title=Ethics+of+spilled+COFEE" title="Digg This Story"><img src="http://digg.com/favicon.ico" width="16" height="16" alt="[Digg]" /></a>
<a href="http://reddit.com/submit?url=http%3A%2F%2Fwww.mckeay.net%2F2009%2F11%2F08%2Fethics-of-spilled-cofee%2F&amp;title=Ethics+of+spilled+COFEE" title="Reddit"><img src="http://reddit.com/favicon.ico" width="16" height="16" alt="[Reddit]" /></a>
<a href="http://del.icio.us/post?url=http%3A%2F%2Fwww.mckeay.net%2F2009%2F11%2F08%2Fethics-of-spilled-cofee%2F&amp;title=Ethics+of+spilled+COFEE" title="Save to del.icio.us" onclick="window.open('http://del.icio.us/post?v=4&amp;noui&amp;jump=close&amp;url=http%3A%2F%2Fwww.mckeay.net%2F2009%2F11%2F08%2Fethics-of-spilled-cofee%2F&amp;title=Ethics+of+spilled+COFEE', 'delicious', 'toolbar=no,width=700,height=400'); return false;"><img src="http://images.del.icio.us/static/img/delicious.small.gif" width="16" height="16" alt="[del.icio.us]" /></a>
<a href="http://www.facebook.com/share.php?u=http%3A%2F%2Fwww.mckeay.net%2F2009%2F11%2F08%2Fethics-of-spilled-cofee%2F" title="Share on Facebook"><img src="http://www.facebook.com/favicon.ico" width="16" height="16" alt="[Facebook]" /></a>
<a href="http://technorati.com/faves?add=http%3A%2F%2Fwww.mckeay.net%2F2009%2F11%2F08%2Fethics-of-spilled-cofee%2F" title="Add to my Technorati Favorites"><img src="http://technorati.com/favicon.ico" width="16" height="16" alt="[Technorati]" /></a>
<a href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http%3A%2F%2Fwww.mckeay.net%2F2009%2F11%2F08%2Fethics-of-spilled-cofee%2F&amp;title=Ethics+of+spilled+COFEE" title="Save to Google Bookmarks"><img src="http://www.google.com/favicon.ico" width="16" height="16" alt="[Google]" /></a>
<a href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fwww.mckeay.net%2F2009%2F11%2F08%2Fethics-of-spilled-cofee%2F&amp;title=Ethics+of+spilled+COFEE" title="Stumble it!"><img src="http://www.stumbleupon.com/favicon.ico" width="16" height="16" alt="[StumbleUpon]" /></a>
</span>]]></content:encoded>
			<wfw:commentRss>http://www.mckeay.net/2009/11/08/ethics-of-spilled-cofee/feed/</wfw:commentRss>
		<slash:comments>8</slash:comments>
		</item>
		<item>
		<title>Get your free Windows 7 Beta</title>
		<link>http://www.mckeay.net/2009/01/08/get-your-free-windows-7-beta/</link>
		<comments>http://www.mckeay.net/2009/01/08/get-your-free-windows-7-beta/#comments</comments>
		<pubDate>Thu, 08 Jan 2009 16:23:52 +0000</pubDate>
		<dc:creator>Martin</dc:creator>
				<category><![CDATA[Microsoft]]></category>

		<guid isPermaLink="false">http://www.mckeay.net/2009/01/08/get-your-free-windows-7-beta/</guid>
		<description><![CDATA[This is a real offer, Microsoft is letting MSDN, TechBeta and TechNet customers download beta versions of Windows 7.&#160; They say it&#8217;s less resource intensive than Vista, so maybe I&#8217;ll try it on my wife&#8217;s computer when we replace it.&#160; Though I&#8217;m not sure she&#8217;d let me survive the experience if it made a new [...]]]></description>
			<content:encoded><![CDATA[<p>This is a real offer, <a href="http://www.microsoft.com/presspass/press/2009/jan09/01-07CES09PR.mspx">Microsoft is letting MSDN, TechBeta and TechNet customers download beta versions of Windows 7</a>.&nbsp; They say it&#8217;s less resource intensive than Vista, so maybe I&#8217;ll try it on my wife&#8217;s computer when we replace it.&nbsp; Though I&#8217;m not sure she&#8217;d let me survive the experience if it made a new computer that&#8217;s less stable then the one she has now.&nbsp; My other option is to create a virtual machine on my main system.&nbsp; If my experience with Vista is any way to measure it though, Windows 7 will painfully slow and unusable.&nbsp; This makes me glad I subscribed to TechNet.</p>

<span class="slashdigglicious">
<a href="http://slashdot.org/bookmark.pl?url=http%3A%2F%2Fwww.mckeay.net%2F2009%2F01%2F08%2Fget-your-free-windows-7-beta%2F&amp;title=Get+your+free+Windows+7+Beta" title="Slashdot It!"><img src="http://slashdot.org/favicon.ico" height="16" width="16" alt="[Slashdot]" /></a>
<a href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fwww.mckeay.net%2F2009%2F01%2F08%2Fget-your-free-windows-7-beta%2F&amp;title=Get+your+free+Windows+7+Beta" title="Digg This Story"><img src="http://digg.com/favicon.ico" width="16" height="16" alt="[Digg]" /></a>
<a href="http://reddit.com/submit?url=http%3A%2F%2Fwww.mckeay.net%2F2009%2F01%2F08%2Fget-your-free-windows-7-beta%2F&amp;title=Get+your+free+Windows+7+Beta" title="Reddit"><img src="http://reddit.com/favicon.ico" width="16" height="16" alt="[Reddit]" /></a>
<a href="http://del.icio.us/post?url=http%3A%2F%2Fwww.mckeay.net%2F2009%2F01%2F08%2Fget-your-free-windows-7-beta%2F&amp;title=Get+your+free+Windows+7+Beta" title="Save to del.icio.us" onclick="window.open('http://del.icio.us/post?v=4&amp;noui&amp;jump=close&amp;url=http%3A%2F%2Fwww.mckeay.net%2F2009%2F01%2F08%2Fget-your-free-windows-7-beta%2F&amp;title=Get+your+free+Windows+7+Beta', 'delicious', 'toolbar=no,width=700,height=400'); return false;"><img src="http://images.del.icio.us/static/img/delicious.small.gif" width="16" height="16" alt="[del.icio.us]" /></a>
<a href="http://www.facebook.com/share.php?u=http%3A%2F%2Fwww.mckeay.net%2F2009%2F01%2F08%2Fget-your-free-windows-7-beta%2F" title="Share on Facebook"><img src="http://www.facebook.com/favicon.ico" width="16" height="16" alt="[Facebook]" /></a>
<a href="http://technorati.com/faves?add=http%3A%2F%2Fwww.mckeay.net%2F2009%2F01%2F08%2Fget-your-free-windows-7-beta%2F" title="Add to my Technorati Favorites"><img src="http://technorati.com/favicon.ico" width="16" height="16" alt="[Technorati]" /></a>
<a href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http%3A%2F%2Fwww.mckeay.net%2F2009%2F01%2F08%2Fget-your-free-windows-7-beta%2F&amp;title=Get+your+free+Windows+7+Beta" title="Save to Google Bookmarks"><img src="http://www.google.com/favicon.ico" width="16" height="16" alt="[Google]" /></a>
<a href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fwww.mckeay.net%2F2009%2F01%2F08%2Fget-your-free-windows-7-beta%2F&amp;title=Get+your+free+Windows+7+Beta" title="Stumble it!"><img src="http://www.stumbleupon.com/favicon.ico" width="16" height="16" alt="[StumbleUpon]" /></a>
</span>]]></content:encoded>
			<wfw:commentRss>http://www.mckeay.net/2009/01/08/get-your-free-windows-7-beta/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Investing in my career</title>
		<link>http://www.mckeay.net/2008/12/18/investing-in-my-career/</link>
		<comments>http://www.mckeay.net/2008/12/18/investing-in-my-career/#comments</comments>
		<pubDate>Thu, 18 Dec 2008 14:33:12 +0000</pubDate>
		<dc:creator>Martin</dc:creator>
				<category><![CDATA[General]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Simple Security]]></category>

		<guid isPermaLink="false">http://www.mckeay.net/2008/12/18/investing-in-my-career/</guid>
		<description><![CDATA[I made two fairly major purchases this week, even though I had to use the credit card to make them, something I hate doing.&#160; Both are aimed at promoting my long term health, one physical, the other career.&#160; The first was to get a small amount of exercise equipment and order the DVD&#8217;s for the [...]]]></description>
			<content:encoded><![CDATA[<p>I made two fairly major purchases this week, even though I had to use the credit card to make them, something I hate doing.&nbsp; Both are aimed at promoting my long term health, one physical, the other career.&nbsp; The first was to get a small amount of exercise equipment and order the DVD&#8217;s for the P90x system.&nbsp; I&#8217;m sure anyone who&#8217;s following the security guys in <a href="http://www.twitter.com/mckeay">Twitter</a> has heard more than their fair share about P90x lately and Chris Hoff has gone so far as to create a new blog of his own to <a href="http://rationalsecurity.typepad.com/p90x/">monitor his progress with the P90x system</a>.&nbsp; I probably won&#8217;t go as far as he has with the blog, but I think I will follow his example and take a &#8216;Week 0&#8242; picture and occasional pictures after that.&nbsp; I&#8217;m not starting the program until after Christmas myself, mostly because I&#8217;ll be heading out for the in-laws for a week and don&#8217;t want to start something this hard then stop for a week.</p>
<p>The second purchase I made was to get myself a membership in <a href="http://technet.microsoft.com/en-us/default.aspx">Microsoft&#8217;s Technet Plus</a>.&nbsp; I&#8217;ve had access to TN+ several times before through employers and I&#8217;d used it a lot to build and rebuild servers, test out new programs and generally learn aspects of Microsoft programs I wouldn&#8217;t normally have access to.&nbsp; Unluckily the last time I had access to TN+ was just after XP came out and when Vista came out the only reason I got to try it at all was that I happened to recieve a copy of Vista Ultimate at an event I attended.&nbsp; Not that I ever successful upgraded a system to Vista, but at least I got to try.</p>
<p>The truth is, TN+ is also a tax writeoff for me.&nbsp; I haven&#8217;t earned much from Google Ads this year, but it&#8217;s more than the cost of the TN+ subscription and this will help me conteract what little tax burden there is.&nbsp; But more importantly, this is an investment in my own continuing education for security and technology.&nbsp; I work from home and while I get a chance to see different networks and OS&#8217;s with every new client, it&#8217;s not the same as getting your hands into the guts of a server and administering it yourself.&nbsp; </p>
<p>So I&#8217;m viewing the purchase of TN+ as in investment in my technical skills for the future.&nbsp; And that&#8217;s how I&#8217;m selling it to my wife as well.&nbsp; I put a lot of time in to reading blogs, writing my own blog and creating the podcast, but the amount of money I&#8217;ve put into furthering my skills has been minimal the last few years.&nbsp; My training comes through going to events like RSA, Black Hat and Defcon.&nbsp; I don&#8217;t have a lot of time and energy to read security books, but several of the publishers occasionally send me those to read and review.&nbsp; I often think about investing in a Masters Degree.&nbsp; It&#8217;d be expensive and time consuming, but it&#8217;s a piece of paper that helps you go a lot further in life than a BS will.&nbsp; But until my wife finishes her own college courses and gets a job, any further courses for me will have to wait.</p>
<p>What other venues should I be spending money on to further my career as<br />
a security professional?&nbsp; Is there something I&#8217;m neglecting that might<br />
eventually catch up to me?&nbsp; How are you investing in your career?&nbsp; Are you investing in your career monetarily or are you making your investments in time and energy instead?&nbsp; I know there are a lot of people out there who are beginning their careers who are curious about how to get into security, but I&#8217;m wondering how the people who&#8217;ve been in the field for years are continuing to improve their skills and preparing for that next step up or making themselves as &#8216;recession proof&#8217; as possible.&nbsp; I don&#8217;t think anyone in this field can afford to say they&#8217;re resting on their laurels.</p>

<span class="slashdigglicious">
<a href="http://slashdot.org/bookmark.pl?url=http%3A%2F%2Fwww.mckeay.net%2F2008%2F12%2F18%2Finvesting-in-my-career%2F&amp;title=Investing+in+my+career" title="Slashdot It!"><img src="http://slashdot.org/favicon.ico" height="16" width="16" alt="[Slashdot]" /></a>
<a href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fwww.mckeay.net%2F2008%2F12%2F18%2Finvesting-in-my-career%2F&amp;title=Investing+in+my+career" title="Digg This Story"><img src="http://digg.com/favicon.ico" width="16" height="16" alt="[Digg]" /></a>
<a href="http://reddit.com/submit?url=http%3A%2F%2Fwww.mckeay.net%2F2008%2F12%2F18%2Finvesting-in-my-career%2F&amp;title=Investing+in+my+career" title="Reddit"><img src="http://reddit.com/favicon.ico" width="16" height="16" alt="[Reddit]" /></a>
<a href="http://del.icio.us/post?url=http%3A%2F%2Fwww.mckeay.net%2F2008%2F12%2F18%2Finvesting-in-my-career%2F&amp;title=Investing+in+my+career" title="Save to del.icio.us" onclick="window.open('http://del.icio.us/post?v=4&amp;noui&amp;jump=close&amp;url=http%3A%2F%2Fwww.mckeay.net%2F2008%2F12%2F18%2Finvesting-in-my-career%2F&amp;title=Investing+in+my+career', 'delicious', 'toolbar=no,width=700,height=400'); return false;"><img src="http://images.del.icio.us/static/img/delicious.small.gif" width="16" height="16" alt="[del.icio.us]" /></a>
<a href="http://www.facebook.com/share.php?u=http%3A%2F%2Fwww.mckeay.net%2F2008%2F12%2F18%2Finvesting-in-my-career%2F" title="Share on Facebook"><img src="http://www.facebook.com/favicon.ico" width="16" height="16" alt="[Facebook]" /></a>
<a href="http://technorati.com/faves?add=http%3A%2F%2Fwww.mckeay.net%2F2008%2F12%2F18%2Finvesting-in-my-career%2F" title="Add to my Technorati Favorites"><img src="http://technorati.com/favicon.ico" width="16" height="16" alt="[Technorati]" /></a>
<a href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http%3A%2F%2Fwww.mckeay.net%2F2008%2F12%2F18%2Finvesting-in-my-career%2F&amp;title=Investing+in+my+career" title="Save to Google Bookmarks"><img src="http://www.google.com/favicon.ico" width="16" height="16" alt="[Google]" /></a>
<a href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fwww.mckeay.net%2F2008%2F12%2F18%2Finvesting-in-my-career%2F&amp;title=Investing+in+my+career" title="Stumble it!"><img src="http://www.stumbleupon.com/favicon.ico" width="16" height="16" alt="[StumbleUpon]" /></a>
</span>]]></content:encoded>
			<wfw:commentRss>http://www.mckeay.net/2008/12/18/investing-in-my-career/feed/</wfw:commentRss>
		<slash:comments>7</slash:comments>
		</item>
		<item>
		<title>Microsoft giving police tools they can get for themselves</title>
		<link>http://www.mckeay.net/2008/04/30/microsoft-giving-police-tools-they-can-get-for-themselves/</link>
		<comments>http://www.mckeay.net/2008/04/30/microsoft-giving-police-tools-they-can-get-for-themselves/#comments</comments>
		<pubDate>Wed, 30 Apr 2008 14:27:23 +0000</pubDate>
		<dc:creator>Martin</dc:creator>
				<category><![CDATA[Government]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Cofee]]></category>
		<category><![CDATA[USB Switchblade]]></category>

		<guid isPermaLink="false">http://www.mckeay.net/2008/04/30/microsoft-giving-police-tools-they-can-get-for-themselves/</guid>
		<description><![CDATA[This was looking like it could have been a great story for the conspiracy theorists in all of us: Microsoft is helping law enforcement agencies by giving them USB keys with forensics tools to help with cybercrime investigations. It can &#8216;decrypt passwords and analyze a computer&#8217;s internet activity&#8217;, something every good law enforcement agent needs. [...]]]></description>
			<content:encoded><![CDATA[<p>This was looking like it could have been a great story for the conspiracy theorists in all of us: Microsoft is helping law enforcement agencies by giving them USB keys with forensics tools to help with cybercrime investigations.  It can &#8216;decrypt passwords and analyze a computer&#8217;s internet activity&#8217;, something every good law enforcement agent needs.  The <a href="http://seattletimes.nwsource.com/html/microsoft/2004379751_msftlaw29.html">Computer Online Forensic Evidence Extractor (Cofee)</a> offers up 150 commands (what do they mean by &#8216;command&#8217;? Is that 150 tools or one tool with 150 commands?) and makes it easier for beleaguered cops to perform an investigation.</p>
<p>A number of people, most notably <a href="http://techdirt.com/articles/20080429/095514977.shtml">Mike Masnick</a>, have jumped to the conclusion that this offers some sort of back door to law enforcement.  <a href="http://blogs.zdnet.com/Bott/?p=435">Ed Bott fires back</a> calling this inflammatory and rants a bit against the echo chamber that is the blogosphere.  I can see why Mike would jump to the conclusion he did, that Microsoft was offering up some special sauce for criminal investigators, but as Ed points out, the tools included on the USB drive are all available elsewhere, MS has just made easier by putting them on one USB key. </p>
<p>Ed also points out another thing:  the bad guys have had USB keys that do most, if not all, of the same things for years.  The USB Switchblade works wonders, is freely available and probably is more dangerous than any of the tools in the Cofee suite.  I wouldn&#8217;t be surprised if some of the more savvy forensics investigators haven&#8217;t been carrying USB Switchblades around for a couple of years.</p>
<p>This is twice in a week that I know of computer crime stories got blown out of proportion.  Is it a trend or just a blip in the statistics?  All I know is it feels weird to <span style="text-decoration: underline; font-style: italic;">not</span> be on the side being called paranoid.</p>

<span class="slashdigglicious">
<a href="http://slashdot.org/bookmark.pl?url=http%3A%2F%2Fwww.mckeay.net%2F2008%2F04%2F30%2Fmicrosoft-giving-police-tools-they-can-get-for-themselves%2F&amp;title=Microsoft+giving+police+tools+they+can+get+for+themselves" title="Slashdot It!"><img src="http://slashdot.org/favicon.ico" height="16" width="16" alt="[Slashdot]" /></a>
<a href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fwww.mckeay.net%2F2008%2F04%2F30%2Fmicrosoft-giving-police-tools-they-can-get-for-themselves%2F&amp;title=Microsoft+giving+police+tools+they+can+get+for+themselves" title="Digg This Story"><img src="http://digg.com/favicon.ico" width="16" height="16" alt="[Digg]" /></a>
<a href="http://reddit.com/submit?url=http%3A%2F%2Fwww.mckeay.net%2F2008%2F04%2F30%2Fmicrosoft-giving-police-tools-they-can-get-for-themselves%2F&amp;title=Microsoft+giving+police+tools+they+can+get+for+themselves" title="Reddit"><img src="http://reddit.com/favicon.ico" width="16" height="16" alt="[Reddit]" /></a>
<a href="http://del.icio.us/post?url=http%3A%2F%2Fwww.mckeay.net%2F2008%2F04%2F30%2Fmicrosoft-giving-police-tools-they-can-get-for-themselves%2F&amp;title=Microsoft+giving+police+tools+they+can+get+for+themselves" title="Save to del.icio.us" onclick="window.open('http://del.icio.us/post?v=4&amp;noui&amp;jump=close&amp;url=http%3A%2F%2Fwww.mckeay.net%2F2008%2F04%2F30%2Fmicrosoft-giving-police-tools-they-can-get-for-themselves%2F&amp;title=Microsoft+giving+police+tools+they+can+get+for+themselves', 'delicious', 'toolbar=no,width=700,height=400'); return false;"><img src="http://images.del.icio.us/static/img/delicious.small.gif" width="16" height="16" alt="[del.icio.us]" /></a>
<a href="http://www.facebook.com/share.php?u=http%3A%2F%2Fwww.mckeay.net%2F2008%2F04%2F30%2Fmicrosoft-giving-police-tools-they-can-get-for-themselves%2F" title="Share on Facebook"><img src="http://www.facebook.com/favicon.ico" width="16" height="16" alt="[Facebook]" /></a>
<a href="http://technorati.com/faves?add=http%3A%2F%2Fwww.mckeay.net%2F2008%2F04%2F30%2Fmicrosoft-giving-police-tools-they-can-get-for-themselves%2F" title="Add to my Technorati Favorites"><img src="http://technorati.com/favicon.ico" width="16" height="16" alt="[Technorati]" /></a>
<a href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http%3A%2F%2Fwww.mckeay.net%2F2008%2F04%2F30%2Fmicrosoft-giving-police-tools-they-can-get-for-themselves%2F&amp;title=Microsoft+giving+police+tools+they+can+get+for+themselves" title="Save to Google Bookmarks"><img src="http://www.google.com/favicon.ico" width="16" height="16" alt="[Google]" /></a>
<a href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fwww.mckeay.net%2F2008%2F04%2F30%2Fmicrosoft-giving-police-tools-they-can-get-for-themselves%2F&amp;title=Microsoft+giving+police+tools+they+can+get+for+themselves" title="Stumble it!"><img src="http://www.stumbleupon.com/favicon.ico" width="16" height="16" alt="[StumbleUpon]" /></a>
</span>]]></content:encoded>
			<wfw:commentRss>http://www.mckeay.net/2008/04/30/microsoft-giving-police-tools-they-can-get-for-themselves/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Windows Error at the Airport</title>
		<link>http://www.mckeay.net/2008/04/19/windows-error-at-the-airport/</link>
		<comments>http://www.mckeay.net/2008/04/19/windows-error-at-the-airport/#comments</comments>
		<pubDate>Sat, 19 Apr 2008 22:00:25 +0000</pubDate>
		<dc:creator>Martin</dc:creator>
				<category><![CDATA[Microsoft]]></category>

		<guid isPermaLink="false">http://www.mckeay.net/2008/04/19/windows-error-at-the-airport/</guid>
		<description><![CDATA[I&#8217;m starting a collection of Windows error messages I see in odd screens around the country. I thought it was funny to see a windows third party DLL error message on a screen talking about airport security. I hope the airport&#8217;s physical security is better than it&#8217;s patching and updating practices are. Is there a [...]]]></description>
			<content:encoded><![CDATA[<p>I&#8217;m starting a collection of Windows error messages I see in odd screens around the country.  I thought it was funny to see a windows third party DLL error message on a screen talking about airport security.  I hope the airport&#8217;s physical security is better than it&#8217;s patching and updating practices are.  Is there a site out there that already tracks these things?</p>
<div style="text-align: center;"><a href="http://www.flickr.com/photos/mmckeay/2425619027/"><img style="max-width: 800px;" src="http://farm3.static.flickr.com/2019/2425619027_be6e8a3ec7.jpg?v=0" /></a></div>

<span class="slashdigglicious">
<a href="http://slashdot.org/bookmark.pl?url=http%3A%2F%2Fwww.mckeay.net%2F2008%2F04%2F19%2Fwindows-error-at-the-airport%2F&amp;title=Windows+Error+at+the+Airport" title="Slashdot It!"><img src="http://slashdot.org/favicon.ico" height="16" width="16" alt="[Slashdot]" /></a>
<a href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fwww.mckeay.net%2F2008%2F04%2F19%2Fwindows-error-at-the-airport%2F&amp;title=Windows+Error+at+the+Airport" title="Digg This Story"><img src="http://digg.com/favicon.ico" width="16" height="16" alt="[Digg]" /></a>
<a href="http://reddit.com/submit?url=http%3A%2F%2Fwww.mckeay.net%2F2008%2F04%2F19%2Fwindows-error-at-the-airport%2F&amp;title=Windows+Error+at+the+Airport" title="Reddit"><img src="http://reddit.com/favicon.ico" width="16" height="16" alt="[Reddit]" /></a>
<a href="http://del.icio.us/post?url=http%3A%2F%2Fwww.mckeay.net%2F2008%2F04%2F19%2Fwindows-error-at-the-airport%2F&amp;title=Windows+Error+at+the+Airport" title="Save to del.icio.us" onclick="window.open('http://del.icio.us/post?v=4&amp;noui&amp;jump=close&amp;url=http%3A%2F%2Fwww.mckeay.net%2F2008%2F04%2F19%2Fwindows-error-at-the-airport%2F&amp;title=Windows+Error+at+the+Airport', 'delicious', 'toolbar=no,width=700,height=400'); return false;"><img src="http://images.del.icio.us/static/img/delicious.small.gif" width="16" height="16" alt="[del.icio.us]" /></a>
<a href="http://www.facebook.com/share.php?u=http%3A%2F%2Fwww.mckeay.net%2F2008%2F04%2F19%2Fwindows-error-at-the-airport%2F" title="Share on Facebook"><img src="http://www.facebook.com/favicon.ico" width="16" height="16" alt="[Facebook]" /></a>
<a href="http://technorati.com/faves?add=http%3A%2F%2Fwww.mckeay.net%2F2008%2F04%2F19%2Fwindows-error-at-the-airport%2F" title="Add to my Technorati Favorites"><img src="http://technorati.com/favicon.ico" width="16" height="16" alt="[Technorati]" /></a>
<a href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http%3A%2F%2Fwww.mckeay.net%2F2008%2F04%2F19%2Fwindows-error-at-the-airport%2F&amp;title=Windows+Error+at+the+Airport" title="Save to Google Bookmarks"><img src="http://www.google.com/favicon.ico" width="16" height="16" alt="[Google]" /></a>
<a href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fwww.mckeay.net%2F2008%2F04%2F19%2Fwindows-error-at-the-airport%2F&amp;title=Windows+Error+at+the+Airport" title="Stumble it!"><img src="http://www.stumbleupon.com/favicon.ico" width="16" height="16" alt="[StumbleUpon]" /></a>
</span>]]></content:encoded>
			<wfw:commentRss>http://www.mckeay.net/2008/04/19/windows-error-at-the-airport/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Vista vulnerabilities at a year</title>
		<link>http://www.mckeay.net/2008/01/23/vista-vulnerabilities-at-a-year/</link>
		<comments>http://www.mckeay.net/2008/01/23/vista-vulnerabilities-at-a-year/#comments</comments>
		<pubDate>Wed, 23 Jan 2008 21:08:31 +0000</pubDate>
		<dc:creator>Martin</dc:creator>
				<category><![CDATA[Microsoft]]></category>

		<guid isPermaLink="false">http://www.mckeay.net/2008/01/23/vista-vulnerabilities-at-a-year/</guid>
		<description><![CDATA[Jeff Jones has just released a pdf, Windows Vista One Year Vulnerability Report.&#160; I&#8217;m still digging into the report, but I like how he&#8217;s shown a side by side comparison between the number of vulnerabilities XP had at one year versus the number Vista has had at one year.&#160; A number that would be more [...]]]></description>
			<content:encoded><![CDATA[<p>Jeff Jones has just released a pdf, <a href="http://blogs.technet.com/security/archive/2008/01/23/download-windows-vista-one-year-vulnerability-report.aspx">Windows Vista One Year Vulnerability Report</a>.&nbsp; I&#8217;m still digging into the report, but I like how he&#8217;s shown a side by side comparison between the number of vulnerabilities XP had at one year versus the number Vista has had at one year.&nbsp; A number that would be more revealing, but that we&#8217;re not going to see, would be the number of open, unpatched vulnerabilities in each system today.&nbsp; That would tell us a lot more about how secure we are, which is really what we really want to know.&nbsp; I think Jeff does a very good job of comparing apples to apples in the report, but it doesn&#8217;t do much to prove that as of today, Windows Vista is the most secure OS available.&nbsp; </p>
<p>I&#8217;m still not upgrading to Vista until I can make sure the 64-bit drivers exist for all of my hardware.&nbsp; Even if Vista is as secure as Jeff asserts, it&#8217;s not enough to make the upgrade worthwhile to me.</p>

<span class="slashdigglicious">
<a href="http://slashdot.org/bookmark.pl?url=http%3A%2F%2Fwww.mckeay.net%2F2008%2F01%2F23%2Fvista-vulnerabilities-at-a-year%2F&amp;title=Vista+vulnerabilities+at+a+year" title="Slashdot It!"><img src="http://slashdot.org/favicon.ico" height="16" width="16" alt="[Slashdot]" /></a>
<a href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fwww.mckeay.net%2F2008%2F01%2F23%2Fvista-vulnerabilities-at-a-year%2F&amp;title=Vista+vulnerabilities+at+a+year" title="Digg This Story"><img src="http://digg.com/favicon.ico" width="16" height="16" alt="[Digg]" /></a>
<a href="http://reddit.com/submit?url=http%3A%2F%2Fwww.mckeay.net%2F2008%2F01%2F23%2Fvista-vulnerabilities-at-a-year%2F&amp;title=Vista+vulnerabilities+at+a+year" title="Reddit"><img src="http://reddit.com/favicon.ico" width="16" height="16" alt="[Reddit]" /></a>
<a href="http://del.icio.us/post?url=http%3A%2F%2Fwww.mckeay.net%2F2008%2F01%2F23%2Fvista-vulnerabilities-at-a-year%2F&amp;title=Vista+vulnerabilities+at+a+year" title="Save to del.icio.us" onclick="window.open('http://del.icio.us/post?v=4&amp;noui&amp;jump=close&amp;url=http%3A%2F%2Fwww.mckeay.net%2F2008%2F01%2F23%2Fvista-vulnerabilities-at-a-year%2F&amp;title=Vista+vulnerabilities+at+a+year', 'delicious', 'toolbar=no,width=700,height=400'); return false;"><img src="http://images.del.icio.us/static/img/delicious.small.gif" width="16" height="16" alt="[del.icio.us]" /></a>
<a href="http://www.facebook.com/share.php?u=http%3A%2F%2Fwww.mckeay.net%2F2008%2F01%2F23%2Fvista-vulnerabilities-at-a-year%2F" title="Share on Facebook"><img src="http://www.facebook.com/favicon.ico" width="16" height="16" alt="[Facebook]" /></a>
<a href="http://technorati.com/faves?add=http%3A%2F%2Fwww.mckeay.net%2F2008%2F01%2F23%2Fvista-vulnerabilities-at-a-year%2F" title="Add to my Technorati Favorites"><img src="http://technorati.com/favicon.ico" width="16" height="16" alt="[Technorati]" /></a>
<a href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http%3A%2F%2Fwww.mckeay.net%2F2008%2F01%2F23%2Fvista-vulnerabilities-at-a-year%2F&amp;title=Vista+vulnerabilities+at+a+year" title="Save to Google Bookmarks"><img src="http://www.google.com/favicon.ico" width="16" height="16" alt="[Google]" /></a>
<a href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fwww.mckeay.net%2F2008%2F01%2F23%2Fvista-vulnerabilities-at-a-year%2F&amp;title=Vista+vulnerabilities+at+a+year" title="Stumble it!"><img src="http://www.stumbleupon.com/favicon.ico" width="16" height="16" alt="[StumbleUpon]" /></a>
</span>]]></content:encoded>
			<wfw:commentRss>http://www.mckeay.net/2008/01/23/vista-vulnerabilities-at-a-year/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Stephen Toulouse leaving Microsoft security</title>
		<link>http://www.mckeay.net/2007/07/16/stephen-toulouse-leaving-microsoft-security/</link>
		<comments>http://www.mckeay.net/2007/07/16/stephen-toulouse-leaving-microsoft-security/#comments</comments>
		<pubDate>Tue, 17 Jul 2007 06:08:34 +0000</pubDate>
		<dc:creator>Martin</dc:creator>
				<category><![CDATA[Microsoft]]></category>

		<guid isPermaLink="false">http://www.mckeay.net/2007/07/16/stephen-toulouse-leaving-microsoft-security/</guid>
		<description><![CDATA[
]]></description>
			<content:encoded><![CDATA[<p>Stephen Toulouse has been one of the most visible security people at Microsoft since 2002.&nbsp; If you go to any major convention, there&#8217;s a good chance Stephen would be the one organizing the meetings with bloggers.&nbsp; Or at least thats how I met him.&nbsp; I was talking to Richard Bejtlich at RSA 2006, the first time I&#8217;d actually talked to Richard one on one, and he mentioned he was heading to a lunch put on by Sunbelt Software and Microsoft.&nbsp; I tagged along and Stephen immediately made me feel welcome at the lunch and a great conversation was had by all.&nbsp; Unluckily, I didn&#8217;t get a chance to meet Stephen again until RSA this year, and now it appears I won&#8217;t be seeing him at any Microsoft lunches any time in the foreseeable future.</p>
<p>Stephen is still working for Microsoft, he just won&#8217;t be with the security team any longer.&nbsp; If there&#8217;s one thing that&#8217;s geekier than being a Microsoft security  guru, it&#8217;s <a href="http://stepto.com/Lists/Posts/Post.aspx?ID=339">becoming an X-box Live guru</a>.  I&#8217;m not a console gamer, but from what I&#8217;ve read on his site, that really is Stephen&#8217;s passion.&nbsp; And if you can get a job doing your passion, I say go for it!&nbsp; I know from recent personal experience, it may not always work out as planned.&nbsp; But it&#8217;s better to have tried and failed than to live your life regretting the chances that slipped through your fingers.</p>
<p>Congratulations Stephen.&nbsp; The security teams loss is Xbox Live&#8217;s gain.&nbsp; Of course, this means you&#8217;re off the list for RSA 2008&#8242;s Security Bloggers Meetup, but there has to be a price to pay for your dream job. </p>
<p>Technorati Tags: <a class="performancingtags" href="http://technorati.com/tag/Microsoft" rel="tag">Microsoft</a>, <a class="performancingtags" href="http://technorati.com/tag/Stephen%20Toulouse" rel="tag">Stephen Toulouse</a>, <a class="performancingtags" href="http://technorati.com/tag/Xbox%20Live" rel="tag">Xbox Live</a></p>

<span class="slashdigglicious">
<a href="http://slashdot.org/bookmark.pl?url=http%3A%2F%2Fwww.mckeay.net%2F2007%2F07%2F16%2Fstephen-toulouse-leaving-microsoft-security%2F&amp;title=Stephen+Toulouse+leaving+Microsoft+security" title="Slashdot It!"><img src="http://slashdot.org/favicon.ico" height="16" width="16" alt="[Slashdot]" /></a>
<a href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fwww.mckeay.net%2F2007%2F07%2F16%2Fstephen-toulouse-leaving-microsoft-security%2F&amp;title=Stephen+Toulouse+leaving+Microsoft+security" title="Digg This Story"><img src="http://digg.com/favicon.ico" width="16" height="16" alt="[Digg]" /></a>
<a href="http://reddit.com/submit?url=http%3A%2F%2Fwww.mckeay.net%2F2007%2F07%2F16%2Fstephen-toulouse-leaving-microsoft-security%2F&amp;title=Stephen+Toulouse+leaving+Microsoft+security" title="Reddit"><img src="http://reddit.com/favicon.ico" width="16" height="16" alt="[Reddit]" /></a>
<a href="http://del.icio.us/post?url=http%3A%2F%2Fwww.mckeay.net%2F2007%2F07%2F16%2Fstephen-toulouse-leaving-microsoft-security%2F&amp;title=Stephen+Toulouse+leaving+Microsoft+security" title="Save to del.icio.us" onclick="window.open('http://del.icio.us/post?v=4&amp;noui&amp;jump=close&amp;url=http%3A%2F%2Fwww.mckeay.net%2F2007%2F07%2F16%2Fstephen-toulouse-leaving-microsoft-security%2F&amp;title=Stephen+Toulouse+leaving+Microsoft+security', 'delicious', 'toolbar=no,width=700,height=400'); return false;"><img src="http://images.del.icio.us/static/img/delicious.small.gif" width="16" height="16" alt="[del.icio.us]" /></a>
<a href="http://www.facebook.com/share.php?u=http%3A%2F%2Fwww.mckeay.net%2F2007%2F07%2F16%2Fstephen-toulouse-leaving-microsoft-security%2F" title="Share on Facebook"><img src="http://www.facebook.com/favicon.ico" width="16" height="16" alt="[Facebook]" /></a>
<a href="http://technorati.com/faves?add=http%3A%2F%2Fwww.mckeay.net%2F2007%2F07%2F16%2Fstephen-toulouse-leaving-microsoft-security%2F" title="Add to my Technorati Favorites"><img src="http://technorati.com/favicon.ico" width="16" height="16" alt="[Technorati]" /></a>
<a href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http%3A%2F%2Fwww.mckeay.net%2F2007%2F07%2F16%2Fstephen-toulouse-leaving-microsoft-security%2F&amp;title=Stephen+Toulouse+leaving+Microsoft+security" title="Save to Google Bookmarks"><img src="http://www.google.com/favicon.ico" width="16" height="16" alt="[Google]" /></a>
<a href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fwww.mckeay.net%2F2007%2F07%2F16%2Fstephen-toulouse-leaving-microsoft-security%2F&amp;title=Stephen+Toulouse+leaving+Microsoft+security" title="Stumble it!"><img src="http://www.stumbleupon.com/favicon.ico" width="16" height="16" alt="[StumbleUpon]" /></a>
</span>]]></content:encoded>
			<wfw:commentRss>http://www.mckeay.net/2007/07/16/stephen-toulouse-leaving-microsoft-security/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

