<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" version="2.0"><channel><title>Steve Riley on Security</title><link>http://blogs.technet.com/steriley/default.aspx</link><description>&lt;strong&gt;Formerly&lt;/strong&gt; of Microsoft's &lt;a href="http://www.microsoft.com/twc"&gt;Trustworthy Computing&lt;/a&gt; Group.</description><dc:language>en-US</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" href="http://feeds.feedburner.com/SteveRileyOnSecurity" type="application/rss+xml" /><feedburner:feedFlare xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" href="http://add.my.yahoo.com/rss?url=http%3A%2F%2Ffeeds.feedburner.com%2FSteveRileyOnSecurity" src="http://us.i1.yimg.com/us.yimg.com/i/us/my/addtomyyahoo4.gif">Subscribe with My Yahoo!</feedburner:feedFlare><feedburner:feedFlare xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" href="http://www.newsgator.com/ngs/subscriber/subext.aspx?url=http%3A%2F%2Ffeeds.feedburner.com%2FSteveRileyOnSecurity" src="http://www.newsgator.com/images/ngsub1.gif">Subscribe with NewsGator</feedburner:feedFlare><feedburner:feedFlare xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" href="http://feeds.my.aol.com/add.jsp?url=http%3A%2F%2Ffeeds.feedburner.com%2FSteveRileyOnSecurity" src="http://o.aolcdn.com/favorites.my.aol.com/webmaster/ffclient/webroot/locale/en-US/images/myAOLButtonSmall.gif">Subscribe with My AOL</feedburner:feedFlare><feedburner:feedFlare xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" href="http://www.bloglines.com/sub/http://feeds.feedburner.com/SteveRileyOnSecurity" src="http://www.bloglines.com/images/sub_modern11.gif">Subscribe with Bloglines</feedburner:feedFlare><feedburner:feedFlare xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" href="http://www.netvibes.com/subscribe.php?url=http%3A%2F%2Ffeeds.feedburner.com%2FSteveRileyOnSecurity" src="http://www.netvibes.com/img/add2netvibes.gif">Subscribe with Netvibes</feedburner:feedFlare><feedburner:feedFlare xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" href="http://fusion.google.com/add?feedurl=http%3A%2F%2Ffeeds.feedburner.com%2FSteveRileyOnSecurity" src="http://buttons.googlesyndication.com/fusion/add.gif">Subscribe with Google</feedburner:feedFlare><feedburner:feedFlare xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" href="http://www.pageflakes.com/subscribe.aspx?url=http%3A%2F%2Ffeeds.feedburner.com%2FSteveRileyOnSecurity" src="http://www.pageflakes.com/ImageFile.ashx?instanceId=Static_4&amp;fileName=ATP_blu_91x17.gif">Subscribe with Pageflakes</feedburner:feedFlare><feedburner:feedFlare xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" href="http://www.plusmo.com/add?url=http%3A%2F%2Ffeeds.feedburner.com%2FSteveRileyOnSecurity" src="http://plusmo.com/res/graphics/fbplusmo.gif">Subscribe with Plusmo</feedburner:feedFlare><feedburner:feedFlare xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" href="http://my.feedlounge.com/external/subscribe?url=http%3A%2F%2Ffeeds.feedburner.com%2FSteveRileyOnSecurity" src="http://static.feedlounge.com/buttons/subscribe_0.gif">Subscribe with FeedLounge</feedburner:feedFlare><feedburner:feedFlare xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" href="http://www.thefreedictionary.com/_/hp/AddRSS.aspx?http%3A%2F%2Ffeeds.feedburner.com%2FSteveRileyOnSecurity" src="http://img.tfd.com/hp/addToTheFreeDictionary.gif">Subscribe with The Free Dictionary</feedburner:feedFlare><feedburner:feedFlare xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" href="http://www.bitty.com/manual/?contenttype=rssfeed&amp;contentvalue=http%3A%2F%2Ffeeds.feedburner.com%2FSteveRileyOnSecurity" src="http://www.bitty.com/img/bittychicklet_91x17.gif">Subscribe with Bitty Browser</feedburner:feedFlare><feedburner:feedFlare xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" href="http://www.newsalloy.com/?rss=http%3A%2F%2Ffeeds.feedburner.com%2FSteveRileyOnSecurity" src="http://www.newsalloy.com/subrss3.gif">Subscribe with NewsAlloy</feedburner:feedFlare><feedburner:feedFlare xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" href="http://www.live.com/?add=http%3A%2F%2Ffeeds.feedburner.com%2FSteveRileyOnSecurity" src="http://tkfiles.storage.msn.com/x1piYkpqHC_35nIp1gLE68-wvzLZO8iXl_JMledmJQXP-XTBOLfmQv4zhj4MhcWEJh_GtoBIiAl1Mjh-ndp9k47If7hTaFno0mxW9_i3p_5qQw">Subscribe with Live.com</feedburner:feedFlare><feedburner:feedFlare xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" href="http://mix.excite.eu/add?feedurl=http%3A%2F%2Ffeeds.feedburner.com%2FSteveRileyOnSecurity" src="http://image.excite.co.uk/mix/addtomix.gif">Subscribe with Excite MIX</feedburner:feedFlare><feedburner:feedFlare xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" href="http://www.yourminis.com/subscribe.aspx?u=http%3A%2F%2Ffeeds.feedburner.com%2FSteveRileyOnSecurity" src="http://www.yourminis.com/images/addtoyourminisbadge.gif">Subscribe with Yourminis.com</feedburner:feedFlare><feedburner:feedFlare xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" href="http://download.attensa.com/app/get_attensa.html?feedurl=http%3A%2F%2Ffeeds.feedburner.com%2FSteveRileyOnSecurity" src="http://www.attensa.com/blogs/attensa/WindowsLiveWriter/BadgeredintoBadges_10C02/attensa_feed_button5.gif">Subscribe with Attensa for Outlook</feedburner:feedFlare><feedburner:feedFlare xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" href="http://www.webwag.com/wwgthis.php?url=http%3A%2F%2Ffeeds.feedburner.com%2FSteveRileyOnSecurity" src="http://www.webwag.com/images/wwgthis.gif">Subscribe with Webwag</feedburner:feedFlare><feedburner:feedFlare xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" href="http://hub.netomat.net/account/account.autoSubscribe.jspa?urls=http%3A%2F%2Ffeeds.feedburner.com%2FSteveRileyOnSecurity" src="http://www.netomat.net/blogger/images/icon_netomat_feedbutton.gif">Subscribe with netomat Hub</feedburner:feedFlare><feedburner:feedFlare xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" href="http://www.dailyrotation.com/index.php?feed=http%3A%2F%2Ffeeds.feedburner.com%2FSteveRileyOnSecurity" src="http://www.dailyrotation.com/rss-dr2.gif">Subscribe with Daily Rotation</feedburner:feedFlare><feedburner:feedFlare xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" href="http://www.podcastready.com/oneclick_bookmark.php?url=http%3A%2F%2Ffeeds.feedburner.com%2FSteveRileyOnSecurity" src="http://www.podcastready.com/images/podcastready_button.gif">Subscribe with Podcast Ready</feedburner:feedFlare><feedburner:feedFlare xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" href="http://www.flurry.com/pushRssFeed.do?r=fb&amp;url=http%3A%2F%2Ffeeds.feedburner.com%2FSteveRileyOnSecurity" src="http://www.flurry.com/images/flurry_rss_logo2.gif">Subscribe with Flurry</feedburner:feedFlare><feedburner:feedFlare xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" href="https://intouch.particls.com/download/?mode=2&amp;feed=http%3A%2F%2Ffeeds.feedburner.com%2FSteveRileyOnSecurity" src="https://intouch.particls.com/resources/buttons/it-button2.gif">Subscribe with Particls</feedburner:feedFlare><feedburner:feedFlare xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" href="http://www.addtoany.com/?linkname=Steve%20Riley%20on%20Security&amp;linkurl=http%3A%2F%2Ffeeds.feedburner.com%2FSteveRileyOnSecurity&amp;type=feed" src="http://www.addtoany.com/addfr-b.gif">Add to Any Feed Reader</feedburner:feedFlare><item><title>Good bye, and good luck</title><link>http://blogs.technet.com/steriley/archive/2009/05/06/good-bye-and-good-luck.aspx</link><pubDate>Wed, 06 May 2009 20:11:56 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3236445</guid><dc:creator>Steve Riley</dc:creator><slash:comments>131</slash:comments><comments>http://blogs.technet.com/steriley/comments/3236445.aspx</comments><wfw:commentRss>http://blogs.technet.com/steriley/commentrss.aspx?PostID=3236445</wfw:commentRss><wfw:comment>http://blogs.technet.com/steriley/rsscomments.aspx?PostID=3236445</wfw:comment><description>&lt;p&gt;&lt;a href="http://blogs.technet.com/blogfiles/steriley/WindowsLiveWriter/Goodbyeandgoodluck_B98C/ghost_light_2.jpg"&gt;&lt;img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="ghost_light" border="0" alt="ghost_light" src="http://blogs.technet.com/blogfiles/steriley/WindowsLiveWriter/Goodbyeandgoodluck_B98C/ghost_light_thumb.jpg" width="400" height="280" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;Friends, as a part of Microsoft’s second round of restructuring, my position was eliminated yesterday and my employment with Microsoft has ended. While there were many rewards that came from my job, the most satisfying element was knowing that our time spent together helped improve everyone—whether at conferences or through this blog, I’ve learned as much from you as you’ve learned from me. Sharing information, debating positions, and doing the right work for the right reasons are all very important and I’m honored and humbled to have been trusted by so many of you.&lt;/p&gt;  &lt;p&gt;I’m certainly not disappearing. While I won’t be at &lt;a href="http://www.msteched.com/teched/default.aspx" target="_blank"&gt;TechEd North America&lt;/a&gt; this year (yes, I’m truly sad about that), I’ll remain involved in the security industry. You can find me on LinkedIn at &lt;a title="http://www.linkedin.com/in/steverileysea" href="http://www.linkedin.com/in/steverileysea"&gt;http://www.linkedin.com/in/steverileysea&lt;/a&gt;. And I’ve got a new blog at &lt;a title="http://msinfluentials.com/blogs/steveriley/default.aspx" href="http://msinfluentials.com/blogs/steveriley/default.aspx"&gt;http://msinfluentials.com/blogs/steveriley/default.aspx&lt;/a&gt;, where I promise I’ll start writing more. Please check in there for updates, and I’ll be sure to let you all know where I land next.&lt;/p&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3236445" width="1" height="1"&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/SteveRileyOnSecurity?a=LFe2IugXYS4:99F7bXrmydA:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/SteveRileyOnSecurity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/SteveRileyOnSecurity?a=LFe2IugXYS4:99F7bXrmydA:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/SteveRileyOnSecurity?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/SteveRileyOnSecurity?a=LFe2IugXYS4:99F7bXrmydA:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/SteveRileyOnSecurity?i=LFe2IugXYS4:99F7bXrmydA:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/SteveRileyOnSecurity?a=LFe2IugXYS4:99F7bXrmydA:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/SteveRileyOnSecurity?i=LFe2IugXYS4:99F7bXrmydA:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><category domain="http://blogs.technet.com/steriley/archive/tags/the+future/default.aspx">the future</category><category domain="http://blogs.technet.com/steriley/archive/tags/the+end/default.aspx">the end</category></item><item><title>If you know the Conficker dude, we've got a prize for you</title><link>http://blogs.technet.com/steriley/archive/2009/02/13/if-you-know-the-conficker-dude-we-ve-got-a-prize-for-you.aspx</link><pubDate>Fri, 13 Feb 2009 17:39:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3201923</guid><dc:creator>Steve Riley</dc:creator><slash:comments>5</slash:comments><comments>http://blogs.technet.com/steriley/comments/3201923.aspx</comments><wfw:commentRss>http://blogs.technet.com/steriley/commentrss.aspx?PostID=3201923</wfw:commentRss><wfw:comment>http://blogs.technet.com/steriley/rsscomments.aspx?PostID=3201923</wfw:comment><description>&lt;P&gt;Yesterday (12 February 2009)&amp;nbsp;Microsoft announced a partnership with technology industry leaders and academia to implement a coordinated, global response to the Conficker (aka Downadup) worm. Together with security researchers, Internet Corporation for Assigned Names and Numbers (ICANN) and operators within the Domain Name System, Microsoft coordinated a response designed to disable domains targeted by Conficker. Microsoft also announced a $250,000 reward for information that results in the arrest and conviction of those responsible for illegally launching the Conficker malicious code on the Internet. &lt;/P&gt;
&lt;P&gt;“As part of Microsoft’s ongoing security efforts, we constantly look for ways to use a diverse set of tools and develop methodologies to protect our customers,” said George Stathakopoulos, general manager of the Trustworthy Computing Group at Microsoft. “By combining our expertise with that of the broader community we can expand the boundaries of defense to better protect people worldwide.”&lt;/P&gt;
&lt;P&gt;As cyberthreats have rapidly evolved, a greater level of industry coordination and new tactics for communication and threat mitigation are required. To optimize the multiple initiatives being employed across the security industry and within academia, Microsoft helped unify these broad efforts to implement a community-based defense to disrupt the spread of Conficker. &lt;/P&gt;
&lt;P&gt;Along with Microsoft, organizations involved in this collaborative effort include ICANN, NeuStar, VeriSign, CNNIC, Afilias, Public Internet Registry, Global Domains International Inc., M1D Global, AOL, Symantec, F-Secure, ISC, researchers from Georgia Tech, the Shadowserver Foundation, Arbor Networks and Support Intelligence.&lt;/P&gt;
&lt;P&gt;“The best way to defeat potential botnets like Conficker/Downadup is by the security and Domain Name System communities working together,” said Greg Rattray, chief Internet security advisor at ICANN. “ICANN represents a community that’s all about coordinating those kinds of efforts to keep the Internet globally secure and stable.” &lt;/P&gt;
&lt;P&gt;“Microsoft’s approach combines technology innovation and effective cross-sector partnerships to help protect people from cybercriminals,” Stathakopoulos said. “We hope these efforts help to contain the threat posed by Conficker, as well as hold those who illegally launch malware accountable.” &lt;/P&gt;
&lt;P&gt;More information about how to protect yourself from Conficker can be found at &lt;A href="http://www.microsoft.com/conficker"&gt;http://www.microsoft.com/conficker&lt;/A&gt;. Customers interested in learning more about staying safe online can visit &lt;A href="http://www.microsoft.com/protect"&gt;http://www.microsoft.com/protect&lt;/A&gt;. &lt;/P&gt;
&lt;P&gt;Microsoft’s reward offer stems from the company’s recognition that the Conficker worm is a criminal attack. Microsoft wants to help the authorities catch the criminals responsible for it. Residents of any country are eligible for the reward, according to the laws of that country, because Internet viruses affect the Internet community worldwide. Individuals with information about the Conficker worm should contact their international law enforcement agencies.&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3201923" width="1" height="1"&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/SteveRileyOnSecurity?a=pKpAsqPa8wI:PYneRU6867A:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/SteveRileyOnSecurity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/SteveRileyOnSecurity?a=pKpAsqPa8wI:PYneRU6867A:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/SteveRileyOnSecurity?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/SteveRileyOnSecurity?a=pKpAsqPa8wI:PYneRU6867A:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/SteveRileyOnSecurity?i=pKpAsqPa8wI:PYneRU6867A:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/SteveRileyOnSecurity?a=pKpAsqPa8wI:PYneRU6867A:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/SteveRileyOnSecurity?i=pKpAsqPa8wI:PYneRU6867A:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><category domain="http://blogs.technet.com/steriley/archive/tags/protection/default.aspx">protection</category><category domain="http://blogs.technet.com/steriley/archive/tags/patch+management/default.aspx">patch management</category><category domain="http://blogs.technet.com/steriley/archive/tags/malware/default.aspx">malware</category><category domain="http://blogs.technet.com/steriley/archive/tags/home+and+family+security/default.aspx">home and family security</category></item><item><title>Today’s spam</title><link>http://blogs.technet.com/steriley/archive/2009/01/21/today-s-spam.aspx</link><pubDate>Wed, 21 Jan 2009 18:13:31 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3188609</guid><dc:creator>Steve Riley</dc:creator><slash:comments>12</slash:comments><comments>http://blogs.technet.com/steriley/comments/3188609.aspx</comments><wfw:commentRss>http://blogs.technet.com/steriley/commentrss.aspx?PostID=3188609</wfw:commentRss><wfw:comment>http://blogs.technet.com/steriley/rsscomments.aspx?PostID=3188609</wfw:comment><description>&lt;p&gt;Here’s what’s in my junk mail folder today:&lt;/p&gt;  &lt;p&gt;&lt;img title="image" style="border-right: 0px; border-top: 0px; display: inline; border-left: 0px; border-bottom: 0px" height="476" alt="image" src="http://blogs.technet.com/blogfiles/steriley/WindowsLiveWriter/Todaysspam_8FC7/image_3.png" width="422" border="0" /&gt; &lt;/p&gt;  &lt;p&gt;What is up with all that? Apparently I sent a payment to myself, I initiated another payment to myself, I am a user of myself who’s received exclusive offers for January, and I received a payment from myself. Wow! Furthermore, an internal discussion group (IPv6) is apparently engaging in a PayPal transaction, and M &amp;amp; T Bank’s mailer needs to make doubly sure that I realize I’m receiving a new message.&lt;/p&gt;  &lt;p&gt;I don’t know where to direct my ire—at the spammers who litter the Internet with their spew or at the people who still get duped by it. Spam would wither away if everyone just ignored it. But I guess enough people are lured by cheap mortgages for their penis extensions that the spammers rake in enough money to cover their costs…so sad.&lt;/p&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3188609" width="1" height="1"&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/SteveRileyOnSecurity?a=KqyzrncmOWs:yz73ox2E8Ao:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/SteveRileyOnSecurity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/SteveRileyOnSecurity?a=KqyzrncmOWs:yz73ox2E8Ao:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/SteveRileyOnSecurity?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/SteveRileyOnSecurity?a=KqyzrncmOWs:yz73ox2E8Ao:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/SteveRileyOnSecurity?i=KqyzrncmOWs:yz73ox2E8Ao:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/SteveRileyOnSecurity?a=KqyzrncmOWs:yz73ox2E8Ao:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/SteveRileyOnSecurity?i=KqyzrncmOWs:yz73ox2E8Ao:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><category domain="http://blogs.technet.com/steriley/archive/tags/spam/default.aspx">spam</category><category domain="http://blogs.technet.com/steriley/archive/tags/email/default.aspx">email</category><category domain="http://blogs.technet.com/steriley/archive/tags/things+that+make+me+angry/default.aspx">things that make me angry</category></item><item><title>Attacks against integrity</title><link>http://blogs.technet.com/steriley/archive/2009/01/20/attacks-against-integrity.aspx</link><pubDate>Wed, 21 Jan 2009 04:28:58 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3188133</guid><dc:creator>Steve Riley</dc:creator><slash:comments>3</slash:comments><comments>http://blogs.technet.com/steriley/comments/3188133.aspx</comments><wfw:commentRss>http://blogs.technet.com/steriley/commentrss.aspx?PostID=3188133</wfw:commentRss><wfw:comment>http://blogs.technet.com/steriley/rsscomments.aspx?PostID=3188133</wfw:comment><description>&lt;p&gt;I’ve been mentioning this frequently during my talks in the last 12 months: that accidental or malicious data modification is yet something else we need to defend against. Richard Bejtlich wrote last year about &lt;a href="http://taosecurity.blogspot.com/2008/02/first-they-came-for-bandwidth.html" target="_blank"&gt;attack progressions&lt;/a&gt;, and this year &lt;a href="http://taosecurity.blogspot.com/2009/01/integrity-attacks-begin-as-mistakes.html" target="_blank"&gt;summarized&lt;/a&gt; an accidental integrity error that &lt;a href="http://www.msnbc.msn.com/id/28655104/" target="_blank"&gt;created minor havoc&lt;/a&gt; at Veteran’s Affairs health centers. Richard’s progression nicely matches our beloved friend, the infosec triad:&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;&lt;em&gt;First they came for &lt;strong&gt;bandwidth&lt;/strong&gt;... These are attacks on &lt;strong&gt;availability&lt;/strong&gt;, executed via denial of service attacks starting in the mid 1990's and monetized later via extortion.&lt;/em&gt;&lt;/li&gt;    &lt;li&gt;&lt;em&gt;Next they came for &lt;strong&gt;secrets&lt;/strong&gt;... These are attacks on &lt;strong&gt;confidentiality&lt;/strong&gt;, executed via disclosure of sensitive data starting in the late 1990's and monetized as personally identifiable information and accounts for sale in the underground.&lt;/em&gt;&lt;/li&gt;    &lt;li&gt;&lt;em&gt;Now they are coming to &lt;strong&gt;make a difference&lt;/strong&gt;... These are attacks on &lt;strong&gt;integrity&lt;/strong&gt;, executed by degrading information starting at the beginning of this decade. These attacks will manifest as changes to trusted data such that those alterations benefit the party making the change. This sort of attack undermines the trustworthiness of data.&lt;/em&gt;&lt;/li&gt; &lt;/ul&gt;  &lt;p&gt;Alas, his concluding sentence is all too true:&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;&lt;em&gt;If we think it's tough to maintain availability and confidentiality, wait until we security people are tasked with validating the integrity of data. It will happen after a celebrity dies or a group of &amp;quot;normal people&amp;quot; do, unfortunately en masse.&lt;/em&gt;&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;Get ready to start adding integrity protection to your data and incorporating integrity protection in your applications. Also: start making noise yourself, and let your vendors know this will eventually become a business requirement for you. Please, let’s not give the folks at the &lt;a href="http://www.privacyrights.org/" target="_blank"&gt;Privacy Rights Clearinghouse&lt;/a&gt; another &lt;a href="http://www.privacyrights.org/ar/ChronDataBreaches.htm" target="_blank"&gt;category to track&lt;/a&gt;!&lt;/p&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3188133" width="1" height="1"&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/SteveRileyOnSecurity?a=ITUptYyKOL0:D8I2g9tOtDg:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/SteveRileyOnSecurity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/SteveRileyOnSecurity?a=ITUptYyKOL0:D8I2g9tOtDg:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/SteveRileyOnSecurity?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/SteveRileyOnSecurity?a=ITUptYyKOL0:D8I2g9tOtDg:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/SteveRileyOnSecurity?i=ITUptYyKOL0:D8I2g9tOtDg:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/SteveRileyOnSecurity?a=ITUptYyKOL0:D8I2g9tOtDg:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/SteveRileyOnSecurity?i=ITUptYyKOL0:D8I2g9tOtDg:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><category domain="http://blogs.technet.com/steriley/archive/tags/security+policies/default.aspx">security policies</category><category domain="http://blogs.technet.com/steriley/archive/tags/protection/default.aspx">protection</category><category domain="http://blogs.technet.com/steriley/archive/tags/integrity/default.aspx">integrity</category></item><item><title>I want a Model 22 HDD Hard Drive Disintegrator</title><link>http://blogs.technet.com/steriley/archive/2009/01/20/i-want-a-model-22-hdd-hard-drive-disintegrator.aspx</link><pubDate>Tue, 20 Jan 2009 21:43:40 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3187608</guid><dc:creator>Steve Riley</dc:creator><slash:comments>10</slash:comments><comments>http://blogs.technet.com/steriley/comments/3187608.aspx</comments><wfw:commentRss>http://blogs.technet.com/steriley/commentrss.aspx?PostID=3187608</wfw:commentRss><wfw:comment>http://blogs.technet.com/steriley/rsscomments.aspx?PostID=3187608</wfw:comment><description>&lt;p&gt;Here at Microsoft we have an active internal discussion group where most security-minded folk hang out. The topic of data destruction came up recently, it’s actually a lot more difficult than most people think. CIPHER /W and SDELETE do a reasonable job, but they aren’t perfect: the paper &lt;a href="http://www.cs.harvard.edu/~malan/publications/pet06.pdf" target="_blank"&gt;One big file is not enough: a critical evaluation of the dominant free-space sanitization technique&lt;/a&gt; dives into some interesting detail. Frequently people talk about DoD (U.S. Department of Defense) compliance, but seven wipes really aren’t necessary, according to &lt;a href="http://www.heise-online.co.uk/security/Secure-deletion-a-single-overwrite-will-do-it--/news/112432" target="_blank"&gt;Secure deletion: a single overwrite will do it&lt;/a&gt;. I’ve always thought the notion that bits will somehow “soak” down into the disk and could be recovered by “shaving off” the disk’s top layer is silly—probably invented by the folks who want to sell you secure wipe utilities. If that were really true, then it would be a fairly simple operation to “wash” away encryption, no?&lt;/p&gt;  &lt;p&gt;For thorough data destruction, I’ve been a fan of shotgun washing. But for those without shotguns at the office, a company called Security Engineered Machinery has introduced the Model 22 HDD Hard Drive Disintegrator.&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;&lt;img title="Model22HDD" style="border-right: 0px; border-top: 0px; display: inline; border-left: 0px; border-bottom: 0px" height="267" alt="Model22HDD" src="http://blogs.technet.com/blogfiles/steriley/WindowsLiveWriter/IwantaModel22HDDHardDriveDisintegrator_C106/Model22HDD_3.jpg" width="400" border="0" /&gt; &lt;/p&gt;    &lt;p&gt;This system is built specifically to destroy hard disk drives. Load up to 10 drives on to the automatically indexing conveyor and in 30 minutes you'll have nothing but a pile of metal chips. The unit comes as a complete system, including sound-dampening enclosure and HEPA vacuum to remove airborne contaminants. The disintegrator's rotating knives transform the drives into unreconstructable fragments, leaving all data unrecoverable. the bin is made of aluminum, to prevent magnetic pieces from sticking to it&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;&lt;a href="http://www.semshred.com/contentmgr/showdetails.php/id/1277" target="_blank"&gt;Watch the video&lt;/a&gt;, it’s pretty cool. I love the narrator’s dead-pan delivery, but the resemblance to the Illudium Q-36 Explosive Space Modulator really made me chuckle. They should do a marketing tie-in with Marvin the Martian.&lt;/p&gt;  &lt;p&gt;&lt;img title="IlludiumQ36" style="border-right: 0px; border-top: 0px; display: inline; border-left: 0px; border-bottom: 0px" height="240" alt="IlludiumQ36" src="http://blogs.technet.com/blogfiles/steriley/WindowsLiveWriter/IwantaModel22HDDHardDriveDisintegrator_C106/IlludiumQ36_3.jpg" width="340" border="0" /&gt; &lt;/p&gt;  &lt;p&gt;“Oh, recoverable data makes me &lt;em&gt;very&lt;/em&gt; angry. Very angry indeed!” (h/t Scott Culp for the quote.)&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;Speaking of washers and aluminum, my six-year-old Frigidaire front-load clothes washer started making a loud thumping sound during the spin cycle. So I did a little bit of searching and found out that this particular unit, a popular model made by Electrolux and sold under the Frigidaire, Kenmore, and General Electric brands, was apparently designed by someone who lacked a high school understanding of chemistry. An aluminum spider arm is connected to the stainless steel inner basket, which of course gets wet during use. What happens when you apply water to the interface of aluminum and steel? Galvanic action! The aluminum disintegrates. Some owners have posted videos of their washers &lt;a href="http://www.youtube.com/watch?v=UwpKP_9_fAA&amp;amp;eurl" target="_blank"&gt;here&lt;/a&gt; and &lt;a href="http://www.youtube.com/watch?v=NoIMCVi1m9k" target="_blank"&gt;here&lt;/a&gt;.&lt;/p&gt;  &lt;p&gt;&lt;img title="spiderarm" style="border-right: 0px; border-top: 0px; display: inline; border-left: 0px; border-bottom: 0px" height="180" alt="spiderarm" src="http://blogs.technet.com/blogfiles/steriley/WindowsLiveWriter/IwantaModel22HDDHardDriveDisintegrator_C106/spiderarm_3.jpg" width="269" border="0" /&gt; &lt;/p&gt;  &lt;p&gt;I’ll attempt the $300 three-hour repair, and I’ll paint the new spider arm with some primer and anti-rust paint. Or maybe I’ll convert it into my very own Illudium Q-22 HDD Explosive Hard Drive Disintegrator.&lt;/p&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3187608" width="1" height="1"&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/SteveRileyOnSecurity?a=usYmDDlzatw:C2NPt7HR__s:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/SteveRileyOnSecurity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/SteveRileyOnSecurity?a=usYmDDlzatw:C2NPt7HR__s:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/SteveRileyOnSecurity?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/SteveRileyOnSecurity?a=usYmDDlzatw:C2NPt7HR__s:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/SteveRileyOnSecurity?i=usYmDDlzatw:C2NPt7HR__s:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/SteveRileyOnSecurity?a=usYmDDlzatw:C2NPt7HR__s:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/SteveRileyOnSecurity?i=usYmDDlzatw:C2NPt7HR__s:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><category domain="http://blogs.technet.com/steriley/archive/tags/security+myths/default.aspx">security myths</category><category domain="http://blogs.technet.com/steriley/archive/tags/physical+security/default.aspx">physical security</category><category domain="http://blogs.technet.com/steriley/archive/tags/data+destruction/default.aspx">data destruction</category></item><item><title>Questions about virtualization and security?</title><link>http://blogs.technet.com/steriley/archive/2009/01/09/questions-about-virtualization-and-security.aspx</link><pubDate>Fri, 09 Jan 2009 17:46:50 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3178984</guid><dc:creator>Steve Riley</dc:creator><slash:comments>4</slash:comments><comments>http://blogs.technet.com/steriley/comments/3178984.aspx</comments><wfw:commentRss>http://blogs.technet.com/steriley/commentrss.aspx?PostID=3178984</wfw:commentRss><wfw:comment>http://blogs.technet.com/steriley/rsscomments.aspx?PostID=3178984</wfw:comment><description>&lt;p&gt;Yesterday, Donnie Hamlett, a Microsoft core infrastructure optimization specialist, gave a webcast and played a video of my TechEd presentation on virtualization and security. Some of the viewers had questions, and I offered to Donnie that they could come to my blog to post them. I’ll extend that offer to all of my readers—if you’ve got a question about this topic, ask away, and I’ll answer here. Thanks!&lt;/p&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3178984" width="1" height="1"&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/SteveRileyOnSecurity?a=9MAZMOtNzbA:zRT3rbn_ZcQ:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/SteveRileyOnSecurity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/SteveRileyOnSecurity?a=9MAZMOtNzbA:zRT3rbn_ZcQ:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/SteveRileyOnSecurity?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/SteveRileyOnSecurity?a=9MAZMOtNzbA:zRT3rbn_ZcQ:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/SteveRileyOnSecurity?i=9MAZMOtNzbA:zRT3rbn_ZcQ:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/SteveRileyOnSecurity?a=9MAZMOtNzbA:zRT3rbn_ZcQ:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/SteveRileyOnSecurity?i=9MAZMOtNzbA:zRT3rbn_ZcQ:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><category domain="http://blogs.technet.com/steriley/archive/tags/configuration/default.aspx">configuration</category><category domain="http://blogs.technet.com/steriley/archive/tags/virtualization/default.aspx">virtualization</category></item><item><title>Poll: do you use scheduled scans for malware?</title><link>http://blogs.technet.com/steriley/archive/2009/01/05/poll-do-you-use-scheduled-scans-for-malware.aspx</link><pubDate>Mon, 05 Jan 2009 20:03:59 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3176696</guid><dc:creator>Steve Riley</dc:creator><slash:comments>18</slash:comments><comments>http://blogs.technet.com/steriley/comments/3176696.aspx</comments><wfw:commentRss>http://blogs.technet.com/steriley/commentrss.aspx?PostID=3176696</wfw:commentRss><wfw:comment>http://blogs.technet.com/steriley/rsscomments.aspx?PostID=3176696</wfw:comment><description>&lt;p&gt;An&amp;#160; interesting comment recently appeared on my &lt;a href="http://blogs.technet.com/steriley/archive/2007/09/22/antivirus-software-who-needs-it.aspx" target="_blank"&gt;older post&lt;/a&gt; about whether or not to use antimalware software. Peter van Dam wondered whether scheduled scans are really necessary, given that anti-malware products scan files as they enter (and sometimes exit) a computer.&lt;/p&gt;  &lt;p&gt;He raises a good point, and I’m curious what all of you think? Do you use scheduled scans? If so, why? If not, is it because you’ve decided the same as Peter?&lt;/p&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3176696" width="1" height="1"&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/SteveRileyOnSecurity?a=kEjOxKKJ_Sk:Q7igO_h8Qds:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/SteveRileyOnSecurity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/SteveRileyOnSecurity?a=kEjOxKKJ_Sk:Q7igO_h8Qds:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/SteveRileyOnSecurity?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/SteveRileyOnSecurity?a=kEjOxKKJ_Sk:Q7igO_h8Qds:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/SteveRileyOnSecurity?i=kEjOxKKJ_Sk:Q7igO_h8Qds:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/SteveRileyOnSecurity?a=kEjOxKKJ_Sk:Q7igO_h8Qds:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/SteveRileyOnSecurity?i=kEjOxKKJ_Sk:Q7igO_h8Qds:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><category domain="http://blogs.technet.com/steriley/archive/tags/risk+mitigation/default.aspx">risk mitigation</category><category domain="http://blogs.technet.com/steriley/archive/tags/protection/default.aspx">protection</category><category domain="http://blogs.technet.com/steriley/archive/tags/malware/default.aspx">malware</category></item><item><title>Updated Microsoft Security Assessment Tool</title><link>http://blogs.technet.com/steriley/archive/2008/12/01/updated-microsoft-security-assessment-tool.aspx</link><pubDate>Tue, 02 Dec 2008 04:13:03 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3162703</guid><dc:creator>Steve Riley</dc:creator><slash:comments>6</slash:comments><comments>http://blogs.technet.com/steriley/comments/3162703.aspx</comments><wfw:commentRss>http://blogs.technet.com/steriley/commentrss.aspx?PostID=3162703</wfw:commentRss><wfw:comment>http://blogs.technet.com/steriley/rsscomments.aspx?PostID=3162703</wfw:comment><description>&lt;p&gt;Greetings. In case you haven’t already read about it, we recently updated the Microsoft Security Assessment Tool (MSAT). Version 4.0 hit the web on 31 October. It’s been four years since the initial release, and two years since the prior version. Between then and now your security world has evolved a lot, and the tool now reflects that.&lt;/p&gt;  &lt;p&gt;Read more: &lt;a title="http://technet.microsoft.com/en-us/security/cc185712.aspx" href="http://technet.microsoft.com/en-us/security/cc185712.aspx"&gt;http://technet.microsoft.com/en-us/security/cc185712.aspx&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;Download now: &lt;a title="http://www.microsoft.com/downloads/details.aspx?FamilyId=CD057D9D-86B9-4E35-9733-7ACB0B2A3CA1&amp;amp;displaylang=en" href="http://www.microsoft.com/downloads/details.aspx?FamilyId=CD057D9D-86B9-4E35-9733-7ACB0B2A3CA1&amp;amp;displaylang=en"&gt;http://www.microsoft.com/downloads/details.aspx?FamilyId=CD057D9D-86B9-4E35-9733-7ACB0B2A3CA1&amp;amp;displaylang=en&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;Take a few moments and give yourself a security checkup. If you have any comments or feedback on the tool, feel free to leave them here on my blog—I’ll make sure the right people see it.&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Update:&lt;/strong&gt; got an email from someone with two questions:&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;When you install the tool, the UAC dialog shows “Microsoft Corporation (Internal Use Only).” This is the CA that signed the tool, and it’s an internal CA—thus the “internal use only” bit.&lt;/li&gt;    &lt;li&gt;The tool fails to run on Vista x64. This is a known issue, we’re working to fix it.&lt;/li&gt; &lt;/ul&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;From the download page:&lt;/p&gt;  &lt;p&gt;The MSAT employs a holistic approach to measuring your security posture by covering topics across people, process, and technology. Findings are coupled with prescriptive guidance and recommended mitigation efforts, including links to more information for additional industry guidance. These resources may assist you in keeping you aware of specific tools and methods that can help change the security posture of your IT environment. &lt;/p&gt;  &lt;p&gt;There are two assessments that define the Microsoft Security Assessment Tool: &lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;Business Risk Profile Assessment &lt;/li&gt;    &lt;li&gt;Defense in Depth Assessment (UPDATED) &lt;/li&gt; &lt;/ul&gt;  &lt;p&gt;The questions identified in the survey portion of the tool and the associated answers are derived from commonly accepted best practices around security, both general and specific. The questions and the recommendations that the tool offers are based on standards such as ISO 17799 and NIST-800.x, as well as recommendations and prescriptive guidance from Microsoft’s Trustworthy Computing Group and additional security resources valued in the industry.&lt;/p&gt;  &lt;p&gt;After completing an Assessment, you will gain access to a detailed report of your results. You may also compare your results with those of your peers (by industry and company size), provided that you upload your results anonymously to the secure MSAT Web server. When you upload your data the application will simultaneously retrieve the most recent data available. To be able to provide this comparative data, we need customers such as you to upload their information. All information is kept strictly confidential and no personally identifiable information whatsoever will be sent.&lt;/p&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3162703" width="1" height="1"&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/SteveRileyOnSecurity?a=65QcKpF1l3Q:h-OH9djhH4k:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/SteveRileyOnSecurity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/SteveRileyOnSecurity?a=65QcKpF1l3Q:h-OH9djhH4k:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/SteveRileyOnSecurity?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/SteveRileyOnSecurity?a=65QcKpF1l3Q:h-OH9djhH4k:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/SteveRileyOnSecurity?i=65QcKpF1l3Q:h-OH9djhH4k:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/SteveRileyOnSecurity?a=65QcKpF1l3Q:h-OH9djhH4k:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/SteveRileyOnSecurity?i=65QcKpF1l3Q:h-OH9djhH4k:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><category domain="http://blogs.technet.com/steriley/archive/tags/security+policies/default.aspx">security policies</category><category domain="http://blogs.technet.com/steriley/archive/tags/risk+mitigation/default.aspx">risk mitigation</category><category domain="http://blogs.technet.com/steriley/archive/tags/assessing+security/default.aspx">assessing security</category></item><item><title>Reading list from “How IT will change in the next 10 years”</title><link>http://blogs.technet.com/steriley/archive/2008/11/24/reading-list-from-how-it-will-change-in-the-next-10-years.aspx</link><pubDate>Mon, 24 Nov 2008 19:39:10 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3158863</guid><dc:creator>Steve Riley</dc:creator><slash:comments>4</slash:comments><comments>http://blogs.technet.com/steriley/comments/3158863.aspx</comments><wfw:commentRss>http://blogs.technet.com/steriley/commentrss.aspx?PostID=3158863</wfw:commentRss><wfw:comment>http://blogs.technet.com/steriley/rsscomments.aspx?PostID=3158863</wfw:comment><description>&lt;p&gt;At &lt;a target="_blank" href="http://www.winconnections.com/default.asp"&gt;Windows Connections&lt;/a&gt; two weeks ago, during my keynote speech “How IT will change in the next 10 years and why you should care,” I mentioned several books worth reading. Many of you have asked for the list; here it is:&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;&lt;em&gt;The Cathedral and the Bazaar&lt;/em&gt; by Eric S. Raymond&lt;/li&gt;    &lt;li&gt;&lt;em&gt;The Wisdom of Crowds&lt;/em&gt; by James Surowiecki&lt;/li&gt;    &lt;li&gt;&lt;em&gt;We Are Smarter Than Me&lt;/em&gt; by Barry Libert, Jon Spector, Don Tapscott&lt;/li&gt;    &lt;li&gt;&lt;em&gt;The World Is Flat&lt;/em&gt; by Thomas L. Friedman&lt;/li&gt;    &lt;li&gt;&lt;em&gt;The Innovator's Dilemma&lt;/em&gt; by Clayton M. Christensen&lt;/li&gt;    &lt;li&gt;&lt;em&gt;The Long Tail&lt;/em&gt; by Chris Anderson&lt;/li&gt;    &lt;li&gt;&lt;em&gt;The Speed of Trust&lt;/em&gt; by Stephen M. R. Covey&lt;/li&gt;    &lt;li&gt;&lt;em&gt;What Got You Here Won't Get You There&lt;/em&gt; by Marshall Goldsmith&lt;/li&gt;    &lt;li&gt;&lt;em&gt;Outsourced&lt;/em&gt; (the movie)&lt;/li&gt; &lt;/ul&gt;  &lt;p&gt;Also remember that I mildly panned &lt;em&gt;Digital Economy&lt;/em&gt; by Harbhajan Kehal and Varinder P. Singh; my assertion was that the next 10 years will bring about a social economy instead, one that includes the digital natives you’ll all be hiring and selling to now or very soon. They’re the ones who are building it, so you might as well adapt.&lt;/p&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3158863" width="1" height="1"&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/SteveRileyOnSecurity?a=UGwIn213eoQ:FAfA57VhQ3c:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/SteveRileyOnSecurity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/SteveRileyOnSecurity?a=UGwIn213eoQ:FAfA57VhQ3c:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/SteveRileyOnSecurity?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/SteveRileyOnSecurity?a=UGwIn213eoQ:FAfA57VhQ3c:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/SteveRileyOnSecurity?i=UGwIn213eoQ:FAfA57VhQ3c:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/SteveRileyOnSecurity?a=UGwIn213eoQ:FAfA57VhQ3c:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/SteveRileyOnSecurity?i=UGwIn213eoQ:FAfA57VhQ3c:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><category domain="http://blogs.technet.com/steriley/archive/tags/conferences+and+seminars/default.aspx">conferences and seminars</category><category domain="http://blogs.technet.com/steriley/archive/tags/public+policy/default.aspx">public policy</category><category domain="http://blogs.technet.com/steriley/archive/tags/the+future/default.aspx">the future</category></item><item><title>Comments, administrivia, and the future of the “infosec professional”</title><link>http://blogs.technet.com/steriley/archive/2008/10/15/comments-administrivia-and-the-future-of-the-infosec-professional.aspx</link><pubDate>Wed, 15 Oct 2008 22:29:13 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3136996</guid><dc:creator>Steve Riley</dc:creator><slash:comments>14</slash:comments><comments>http://blogs.technet.com/steriley/comments/3136996.aspx</comments><wfw:commentRss>http://blogs.technet.com/steriley/commentrss.aspx?PostID=3136996</wfw:commentRss><wfw:comment>http://blogs.technet.com/steriley/rsscomments.aspx?PostID=3136996</wfw:comment><description>&lt;p&gt;Back when the spam was spiraling out of control, I configured my blog to close comments after 90 days. I’ve removed the limitation now, for two reasons: the spam is under control, and I wanted to reply to a comment made to my post on IPsec/IPv6 direct connect.&lt;/p&gt;  &lt;p&gt;On &lt;a target="_blank" href="http://blogs.technet.com/steriley/archive/2008/06/25/directly-connect-to-your-corpnet-with-ipsec-and-ipv6.aspx#3104911"&gt;13 August, jcorey&lt;/a&gt; asked about how to deal with those who firmly believe that the only answer to any security problem is to inspect everything at the edge. This is an important question, and I wanted to give Joe an answer. (You might have to scroll down when you click the previous link, it seems that linking to individual comments is broken.)&lt;/p&gt;  &lt;p&gt;Today, &lt;a target="_blank" href="http://blogs.technet.com/steriley/archive/2008/06/25/directly-connect-to-your-corpnet-with-ipsec-and-ipv6.aspx#3136984"&gt;15 October, I&lt;/a&gt; wrote a little thesis as an answer to his question. I’m calling it out in a separate post because I want to make sure those of you with aggregators that don’t update when posts receive new comments still have a chance to reply with your thoughts. I’ll also repost it here:&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;jcorey-- You've nailed the biggest obstacle to deploying something like direct connect. Many security professionals have been taught that there simply is, and never will be, a process or technology that allows you to trust anything that originates from outside your corpnet. These professionals cling to this belief, and have been the cause that allowed the whole “detection” market to bloom. &lt;/p&gt;    &lt;p&gt;Let me be clear: this total lack of trustworthiness is no longer absolutely true. Of course there will be times when unknown machines will be used by known and unknown people to access your information. But what about one particular subset -- known humans, with known portable computers -- can't we do something better than treat them as toxic invaders? &lt;/p&gt;    &lt;p&gt;Indeed we can. And that's what I'm proposing with direct connect. The technology -- managed, of course, with the right processes -- exists so that you can extend the trust to known computers even though you don't trust the network they're connected to. This is because you have mechanisms that: &lt;/p&gt;    &lt;p&gt;1. Allow you to configure the machine according to your requirements (domain join, group policy) &lt;/p&gt;    &lt;p&gt;2. Dictate computer and user authentication requirements (IPsec policies, smart cards) &lt;/p&gt;    &lt;p&gt;3. Limit what the users of these machines can do (UAC, non-admin, Forefront Client Security, Windows Firewall, even software restriction policies) &lt;/p&gt;    &lt;p&gt;4. Validate the health of machines initiating incoming connections and remediate if necessary (NAP, System Center Configuration Manager) &lt;/p&gt;    &lt;p&gt;5. Limit the threat of attacks against stolen computers (domain logon, smart cards, BitLocker with TPM) &lt;/p&gt;    &lt;p&gt;With the robust authentication, validation, configuration, and control mechanisms available to you, I simply don't see that there's any need to fall back to “detection” now. Detection technologies were -- and remain -- necessary for the times when we have no clue about the health of client computers and when we had no way to gauge the intent of the users. But it is truly reflective of a head-in-the-sand mentality to assume that this is a complete description of what's capable today. &lt;/p&gt;    &lt;p&gt;You know, someone once asked me what it takes to be a security professional. I answered that there are two primary elements: &lt;strong&gt;become a networking/packet wonk&lt;/strong&gt;, and &lt;strong&gt;be willing to change your opinions&lt;/strong&gt; when the right evidence comes along. Indeed, I suspect that many security folk have forgotten the need to keep their wonikness updated, which in turn makes them resist new ideas regardless of the strength of the evidence. I'm not very proud of what I just wrote, because I loathe generalities, but I'm not sure what else to think here. Sigh.&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;Joe’s question is important and strikes at the foundation of what it means to be a security professional today. I’m eager to continue this conversation, because it’s reflective of what I sense to be a radical shift in our jobs—we are, or should be, no longer the wolf-crying propeller-head who sits in the basement and twiddles with the firewall. Instead, our job should be defined as one who’s charged with protecting the organization’s information from attack, while maximizing its utility to authorized users, according to the principles of least privilege. Your thoughts?&lt;/p&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3136996" width="1" height="1"&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/SteveRileyOnSecurity?a=gCOqUbloDZU:-_FeH9L8QuM:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/SteveRileyOnSecurity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/SteveRileyOnSecurity?a=gCOqUbloDZU:-_FeH9L8QuM:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/SteveRileyOnSecurity?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/SteveRileyOnSecurity?a=gCOqUbloDZU:-_FeH9L8QuM:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/SteveRileyOnSecurity?i=gCOqUbloDZU:-_FeH9L8QuM:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/SteveRileyOnSecurity?a=gCOqUbloDZU:-_FeH9L8QuM:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/SteveRileyOnSecurity?i=gCOqUbloDZU:-_FeH9L8QuM:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><category domain="http://blogs.technet.com/steriley/archive/tags/blogging/default.aspx">blogging</category><category domain="http://blogs.technet.com/steriley/archive/tags/infosec+as+a+profession/default.aspx">infosec as a profession</category></item><item><title>Ethernet and WiFi and Bluetooth, oh my!</title><link>http://blogs.technet.com/steriley/archive/2008/10/15/ethernet-and-wifi-and-bluetooth-oh-my.aspx</link><pubDate>Wed, 15 Oct 2008 21:16:48 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3136959</guid><dc:creator>Steve Riley</dc:creator><slash:comments>19</slash:comments><comments>http://blogs.technet.com/steriley/comments/3136959.aspx</comments><wfw:commentRss>http://blogs.technet.com/steriley/commentrss.aspx?PostID=3136959</wfw:commentRss><wfw:comment>http://blogs.technet.com/steriley/rsscomments.aspx?PostID=3136959</wfw:comment><description>&lt;p&gt;Customers have long requested a way to configure a computer to automatically disable its wireless NIC when its Ethernet is in use. Many third-party utilities can do this for you, but neither XP nor Vista have a built-in way to accomplish this, nor will Windows 7. Although having both NICs enabled first appears to cause a security issue, in reality that would be true only if both of the following were also true: &lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;The user is logged on as a local administrator&lt;/li&gt;    &lt;li&gt;The user, or some code the user runs, enables IP routing&lt;/li&gt; &lt;/ul&gt;  &lt;p&gt;By default, all forms of IP routing (including NIC bridging) are disabled. Only local administrators (or group policy) can enable them. So the risk, actually, is minimal. &lt;/p&gt;  &lt;p&gt;If you have a stroll through group policy, you'll discover this setting: &amp;quot;Prohibit installation and configuration of Network Bridge on your DNS domain network&amp;quot; (more &lt;a target="_blank" href="http://technet.microsoft.com/en-us/library/cc783558.aspx"&gt;here&lt;/a&gt;, &lt;a target="_blank" href="http://technet.microsoft.com/en-us/library/cc758455.aspx"&gt;here&lt;/a&gt;). This setting allows you turn a computer into a router that bridges two networks. The bridging works only when one of the interfaces is in the same DNS namespace it was in when the bridge setting was enabled, and it works only when the Windows firewall is &lt;em&gt;disabled&lt;/em&gt; on both interfaces (&lt;a target="_blank" href="http://blogs.technet.com/steriley/archive/2007/05/29/technet-exploring-the-windows-vista-firewall.aspx"&gt;never a good idea&lt;/a&gt;). Additionally, regardless of the group policy setting, the function doesn’t even appear as an option when the user is logged in as a non-admin. The group policy setting simply removes the option from people who are local admins of their computers. So here's a way you can remove the ability even for local admins to enable routing. &lt;/p&gt;  &lt;p&gt;However, let me admit that I wish we &lt;em&gt;did&lt;/em&gt; have a way to implement your request, but for an entirely different reason: IP address preservation. Consider what happens when I'm on my own corpnet in my office. I put my laptop in its dock, which is connected to the Ethernet. I never bother disabling my wireless (I'm lazy). So whenever I'm in my office I'm taking up two IP addresses: one on the Ethernet and one on the wireless. Such wasteful profligacy, I know! (Note this isn’t a problem for any Bluetooth adapter, which always uses &lt;a target="_blank" href="http://support.microsoft.com/kb/220874"&gt;APIPA&lt;/a&gt; in its default configuration; I can’t imagine a scenario where you’d want Bluetooth to use DHCP.)&lt;/p&gt;  &lt;p&gt;If you agree with me that this is something we should address post Windows 7, not for &amp;quot;security&amp;quot; reasons but as a good general networking practice of being conservative with address allocation, please speak up. Now's the time for your input.&lt;/p&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3136959" width="1" height="1"&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/SteveRileyOnSecurity?a=iJ0IBRl6V9Y:x6vAKjecxnA:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/SteveRileyOnSecurity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/SteveRileyOnSecurity?a=iJ0IBRl6V9Y:x6vAKjecxnA:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/SteveRileyOnSecurity?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/SteveRileyOnSecurity?a=iJ0IBRl6V9Y:x6vAKjecxnA:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/SteveRileyOnSecurity?i=iJ0IBRl6V9Y:x6vAKjecxnA:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/SteveRileyOnSecurity?a=iJ0IBRl6V9Y:x6vAKjecxnA:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/SteveRileyOnSecurity?i=iJ0IBRl6V9Y:x6vAKjecxnA:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><category domain="http://blogs.technet.com/steriley/archive/tags/wireless/default.aspx">wireless</category><category domain="http://blogs.technet.com/steriley/archive/tags/configuration/default.aspx">configuration</category><category domain="http://blogs.technet.com/steriley/archive/tags/networking/default.aspx">networking</category><category domain="http://blogs.technet.com/steriley/archive/tags/group+policy/default.aspx">group policy</category><category domain="http://blogs.technet.com/steriley/archive/tags/Windows+7/default.aspx">Windows 7</category></item><item><title>Passgen tool from my book</title><link>http://blogs.technet.com/steriley/archive/2008/09/29/passgen-tool-from-my-book.aspx</link><pubDate>Mon, 29 Sep 2008 20:42:29 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3130067</guid><dc:creator>Steve Riley</dc:creator><slash:comments>14</slash:comments><comments>http://blogs.technet.com/steriley/comments/3130067.aspx</comments><wfw:commentRss>http://blogs.technet.com/steriley/commentrss.aspx?PostID=3130067</wfw:commentRss><wfw:comment>http://blogs.technet.com/steriley/rsscomments.aspx?PostID=3130067</wfw:comment><description>&lt;p&gt;Way back in 2005, &lt;a target="_blank" href="http://msinfluentials.com/blogs/jesper/"&gt;Jesper Johannson&lt;/a&gt; and I wrote &lt;em&gt;Protect Your Windows Network&lt;/em&gt;. It’s &lt;a target="_blank" href="http://www.amazon.com/dp/0321336437"&gt;still available&lt;/a&gt;, and although its product set is now somewhat dated (Windows XP and Server 2003), much of the practical advice about security policies, social engineering, security dependencies, and how to think about security remains relevant. That’s because we strove to write something more lasting than a simple configuration guide.&lt;/p&gt;  &lt;p&gt;On the CD-ROM accompanying the book we included a tool called Passgen. In the book, we recommended that you maintain separate passwords on every local administrator and service account in your enterprise. This is, of course, almost impossible to manage without something to automate it for you. That’s what Passgen does. The tool generates unique passwords based on known input (an identifier and passphrase you define), sets those passwords remotely, and allows you to retrieve them later.&lt;/p&gt;  &lt;p&gt;For a while Jesper maintained a web site for the book, running on a server in his house. His &lt;a target="_blank" href="http://www.comcast.net/terms/subscriber/"&gt;ISP&lt;/a&gt; changed &lt;a target="_blank" href="http://www.comcast.net/terms/use/"&gt;policies&lt;/a&gt; and made it impractical to continue running the site. But because the tool is still so useful, I’ve put a copy in my &lt;a target="_blank" href="http://steveriley-ms.spaces.live.com/"&gt;SkyDrive&lt;/a&gt;—look in the “&lt;a target="_blank" href="http://cid-45497626ab321d20.skydrive.live.com/browse.aspx/Passgen"&gt;Passgen&lt;/a&gt;” folder.&lt;/p&gt;  &lt;p&gt;Also, note that I’ve put a new section in the right-side column, “Resources for you.” Here’s where I’ll keep links to bits and pieces that many of you will find relevant and interesting.&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Update.&lt;/strong&gt; A few readers have informed me that the SHA-1 hash printed in the README.DOC doesn’t match the actual hash of passgen.exe. Jesper made a few changes and recompiled the tool. The correct hash is now:&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;fa19722348e9e0603f24c0ef9fc715010403bcfa&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;I’ve updated the README file with the new hash. Also, passgen.exe has a digital signature, and you can check its details if you’d like.&lt;/p&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3130067" width="1" height="1"&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/SteveRileyOnSecurity?a=RXOPMH2nrss:42tWDvTxO-w:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/SteveRileyOnSecurity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/SteveRileyOnSecurity?a=RXOPMH2nrss:42tWDvTxO-w:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/SteveRileyOnSecurity?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/SteveRileyOnSecurity?a=RXOPMH2nrss:42tWDvTxO-w:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/SteveRileyOnSecurity?i=RXOPMH2nrss:42tWDvTxO-w:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/SteveRileyOnSecurity?a=RXOPMH2nrss:42tWDvTxO-w:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/SteveRileyOnSecurity?i=RXOPMH2nrss:42tWDvTxO-w:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><category domain="http://blogs.technet.com/steriley/archive/tags/passwords/default.aspx">passwords</category><category domain="http://blogs.technet.com/steriley/archive/tags/my+book/default.aspx">my book</category></item><item><title>Sao Paulo, here I come</title><link>http://blogs.technet.com/steriley/archive/2008/09/29/sao-paulo-here-i-come.aspx</link><pubDate>Mon, 29 Sep 2008 17:31:02 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3130019</guid><dc:creator>Steve Riley</dc:creator><slash:comments>14</slash:comments><comments>http://blogs.technet.com/steriley/comments/3130019.aspx</comments><wfw:commentRss>http://blogs.technet.com/steriley/commentrss.aspx?PostID=3130019</wfw:commentRss><wfw:comment>http://blogs.technet.com/steriley/rsscomments.aspx?PostID=3130019</wfw:comment><description>&lt;p&gt;I have a new &lt;a target="_blank" href="http://www.teched.com.br/Palestrantes.aspx"&gt;TechEd destination&lt;/a&gt; this year: Brazil. It’ll be my first time to speak at our event there; indeed, even my first time to travel to South America. I’m looking forward to it.&lt;/p&gt;  &lt;p&gt;The event runs during &lt;a target="_blank" href="http://www.teched.com.br/Default.aspx"&gt;14-16 October 2008&lt;/a&gt;. I’m delivering the same four presentations I gave at TechEd US (and have used at most other TechEds around the world, too):&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;Do these ten things now or else get 0wn3d!&lt;/li&gt;    &lt;li&gt;Virtualization and security: what does it mean for me?&lt;/li&gt;    &lt;li&gt;Privacy: the why, the what, and the how&lt;/li&gt;    &lt;li&gt;21st century networking: throw away your medieval gateways&lt;/li&gt; &lt;/ul&gt;  &lt;p&gt;That’s gonna be a crazy week, because I’ll have been in Hong Kong for TechEd there the week prior. I get home from Hong Kong on Saturday, spend the night in Seattle, then on Sunday fly down to Sao Paulo! Oh well, I still love my job :)&lt;/p&gt;  &lt;p&gt;If you’re headed to TechEd Brazil, be sure to introduce yourself to me after one of my talks. See you soon!&lt;/p&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3130019" width="1" height="1"&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/SteveRileyOnSecurity?a=2n08H4d06ks:WTWVgonqgvQ:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/SteveRileyOnSecurity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/SteveRileyOnSecurity?a=2n08H4d06ks:WTWVgonqgvQ:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/SteveRileyOnSecurity?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/SteveRileyOnSecurity?a=2n08H4d06ks:WTWVgonqgvQ:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/SteveRileyOnSecurity?i=2n08H4d06ks:WTWVgonqgvQ:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/SteveRileyOnSecurity?a=2n08H4d06ks:WTWVgonqgvQ:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/SteveRileyOnSecurity?i=2n08H4d06ks:WTWVgonqgvQ:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><category domain="http://blogs.technet.com/steriley/archive/tags/TechEd/default.aspx">TechEd</category></item><item><title>Internet Explorer security levels compared</title><link>http://blogs.technet.com/steriley/archive/2008/09/16/internet-explorer-security-levels-compared.aspx</link><pubDate>Wed, 17 Sep 2008 00:19:36 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3124973</guid><dc:creator>Steve Riley</dc:creator><slash:comments>9</slash:comments><comments>http://blogs.technet.com/steriley/comments/3124973.aspx</comments><wfw:commentRss>http://blogs.technet.com/steriley/commentrss.aspx?PostID=3124973</wfw:commentRss><wfw:comment>http://blogs.technet.com/steriley/rsscomments.aspx?PostID=3124973</wfw:comment><description>&lt;p&gt;A pretty good question came across the newsgroups the other day. Someone was asking what are the differences between IE's &amp;quot;medium&amp;quot; and &amp;quot;medium-high&amp;quot; security settings. I did some digging, and found only this on MSDN: &lt;a href="http://msdn.microsoft.com/en-us/library/ms537186(VS.85).aspx" target="_blank"&gt;About URL security zone templates&lt;/a&gt;. No wonder it's difficult to find -- the terminology is different, and the table is organized by URL actions, not by the text in the dialog.&lt;/p&gt;  &lt;p&gt;Someone on the IE security team forwarded me a document that had additional details. So here, for your enjoyment, is a chart listing the default settings for each security level. To answer the newsgroup poster, &amp;quot;medium&amp;quot; and &amp;quot;medium-high&amp;quot; aren't the same.&lt;/p&gt;  &lt;p&gt;About the formatting: to get it to fit within the width of the blog's text section, I've made some abbreviations.&lt;/p&gt;  &lt;table cellspacing="0" cellpadding="0" width="290" border="0"&gt;&lt;tbody&gt;     &lt;tr&gt;       &lt;td valign="top" width="145"&gt;&lt;strong&gt;&lt;u&gt;Column headings&lt;/u&gt;&lt;/strong&gt;&lt;/td&gt;        &lt;td valign="top" width="145"&gt;&lt;strong&gt;&lt;u&gt;Entries&lt;/u&gt;&lt;/strong&gt;&lt;/td&gt;     &lt;/tr&gt;   &lt;/tbody&gt;&lt;/table&gt;  &lt;table cellspacing="0" cellpadding="0" width="290" border="0"&gt;&lt;tbody&gt;     &lt;tr&gt;       &lt;td valign="top" width="25"&gt;H&lt;/td&gt;        &lt;td valign="top" width="120"&gt;High&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;font color="#ff0000"&gt;&lt;strong&gt;D&lt;/strong&gt;&lt;/font&gt;&lt;/td&gt;        &lt;td valign="top" width="120"&gt;Disable&lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td valign="top" width="25"&gt;MH&lt;/td&gt;        &lt;td valign="top" width="120"&gt;Medium-high&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#00ff00"&gt;E&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;        &lt;td valign="top" width="120"&gt;Enable&lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td valign="top" width="25"&gt;M&lt;/td&gt;        &lt;td valign="top" width="120"&gt;Medium&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#0000ff"&gt;P&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;        &lt;td valign="top" width="120"&gt;Prompt&lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td valign="top" width="25"&gt;ML&lt;/td&gt;        &lt;td valign="top" width="120"&gt;Medium-low&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&amp;#160;&lt;/td&gt;        &lt;td valign="top" width="120"&gt;&amp;#160;&lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td valign="top" width="25"&gt;L&lt;/td&gt;        &lt;td valign="top" width="120"&gt;Low&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&amp;#160;&lt;/td&gt;        &lt;td valign="top" width="120"&gt;&amp;#160;&lt;/td&gt;     &lt;/tr&gt;   &lt;/tbody&gt;&lt;/table&gt;  &lt;p&gt;In a few cases, the table shows a number rather than D or E or P; below the table is a description of each such entry.&lt;/p&gt;  &lt;p&gt;At the very bottom of this post I've included the settings from the privacy tab, too.&lt;/p&gt;  &lt;p&gt;Note: these settings reflect those for Internet Explorer 7 on Vista SP1. Please see the MDSN link above for differences between IE 6 and IE 7.&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;.NET Framework&lt;/strong&gt;&lt;/p&gt;  &lt;table cellspacing="0" cellpadding="0" width="550" border="1"&gt;&lt;tbody&gt;     &lt;tr&gt;       &lt;td valign="top" width="325"&gt;&amp;#160;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;H&lt;/td&gt;        &lt;td valign="top" width="25"&gt;MH&lt;/td&gt;        &lt;td valign="top" width="25"&gt;M&lt;/td&gt;        &lt;td valign="top" width="25"&gt;ML&lt;/td&gt;        &lt;td valign="top" width="25"&gt;L&lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td valign="top" width="325"&gt;Loose XAML&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;font color="#ff0000"&gt;&lt;strong&gt;D&lt;/strong&gt;&lt;/font&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#00ff00"&gt;E&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#00ff00"&gt;E&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#00ff00"&gt;E&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#00ff00"&gt;E&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td valign="top" width="325"&gt;XAML browser applications&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;font color="#ff0000"&gt;&lt;strong&gt;D&lt;/strong&gt;&lt;/font&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#00ff00"&gt;E&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#00ff00"&gt;E&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#00ff00"&gt;E&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#00ff00"&gt;E&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td valign="top" width="325"&gt;XPS documents&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;font color="#ff0000"&gt;&lt;strong&gt;D&lt;/strong&gt;&lt;/font&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#00ff00"&gt;E&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#00ff00"&gt;E&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#00ff00"&gt;E&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#00ff00"&gt;E&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;     &lt;/tr&gt;   &lt;/tbody&gt;&lt;/table&gt;  &lt;p&gt;&lt;strong&gt;.NET Framework-reliant components&lt;/strong&gt;&lt;/p&gt;  &lt;table cellspacing="0" cellpadding="0" width="550" border="1"&gt;&lt;tbody&gt;     &lt;tr&gt;       &lt;td valign="top" width="325"&gt;&amp;#160;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;H&lt;/td&gt;        &lt;td valign="top" width="25"&gt;MH&lt;/td&gt;        &lt;td valign="top" width="25"&gt;M&lt;/td&gt;        &lt;td valign="top" width="25"&gt;ML&lt;/td&gt;        &lt;td valign="top" width="25"&gt;L&lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td valign="top" width="325"&gt;Permissions for components with manifests&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;font color="#ff0000"&gt;&lt;strong&gt;D&lt;/strong&gt;&lt;/font&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;1&lt;/td&gt;        &lt;td valign="top" width="25"&gt;1&lt;/td&gt;        &lt;td valign="top" width="25"&gt;1&lt;/td&gt;        &lt;td valign="top" width="25"&gt;1&lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td valign="top" width="325"&gt;Run components not signed with Authenticode&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;font color="#ff0000"&gt;&lt;strong&gt;D&lt;/strong&gt;&lt;/font&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#00ff00"&gt;E&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#00ff00"&gt;E&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#00ff00"&gt;E&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#00ff00"&gt;E&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td valign="top" width="325"&gt;Run components signed with Authenticode&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;font color="#ff0000"&gt;&lt;strong&gt;D&lt;/strong&gt;&lt;/font&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#00ff00"&gt;E&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#00ff00"&gt;E&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#00ff00"&gt;E&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#00ff00"&gt;E&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;     &lt;/tr&gt;   &lt;/tbody&gt;&lt;/table&gt;  &lt;p&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160; 1 = High safety&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;ActiveX controls and plug-ins&lt;/strong&gt;&lt;/p&gt;  &lt;table cellspacing="0" cellpadding="0" width="550" border="1"&gt;&lt;tbody&gt;     &lt;tr&gt;       &lt;td valign="top" width="325"&gt;&amp;#160;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;H&lt;/td&gt;        &lt;td valign="top" width="25"&gt;MH&lt;/td&gt;        &lt;td valign="top" width="25"&gt;M&lt;/td&gt;        &lt;td valign="top" width="25"&gt;ML&lt;/td&gt;        &lt;td valign="top" width="25"&gt;L&lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td valign="top" width="325"&gt;Allow previously unused ActiveX controls to run without prompt&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;font color="#ff0000"&gt;&lt;strong&gt;D&lt;/strong&gt;&lt;/font&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;font color="#ff0000"&gt;&lt;strong&gt;D&lt;/strong&gt;&lt;/font&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#00ff00"&gt;E&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#00ff00"&gt;E&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#00ff00"&gt;E&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td valign="top" width="325"&gt;Allow scriptlets&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;font color="#ff0000"&gt;&lt;strong&gt;D&lt;/strong&gt;&lt;/font&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;font color="#ff0000"&gt;&lt;strong&gt;D&lt;/strong&gt;&lt;/font&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;font color="#ff0000"&gt;&lt;strong&gt;D&lt;/strong&gt;&lt;/font&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#00ff00"&gt;E&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#00ff00"&gt;E&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td valign="top" width="325"&gt;Automatic prompting for ActiveX controls&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;font color="#ff0000"&gt;&lt;strong&gt;D&lt;/strong&gt;&lt;/font&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;font color="#ff0000"&gt;&lt;strong&gt;D&lt;/strong&gt;&lt;/font&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;font color="#ff0000"&gt;&lt;strong&gt;D&lt;/strong&gt;&lt;/font&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#00ff00"&gt;E&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#00ff00"&gt;E&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td valign="top" width="325"&gt;Binary and script behaviors&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;font color="#ff0000"&gt;&lt;strong&gt;D&lt;/strong&gt;&lt;/font&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#00ff00"&gt;E&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#00ff00"&gt;E&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#00ff00"&gt;E&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#00ff00"&gt;E&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td valign="top" width="325"&gt;Display video and animation on a Web page that doesn't use an external media player&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;font color="#ff0000"&gt;&lt;strong&gt;D&lt;/strong&gt;&lt;/font&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;font color="#ff0000"&gt;&lt;strong&gt;D&lt;/strong&gt;&lt;/font&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;font color="#ff0000"&gt;&lt;strong&gt;D&lt;/strong&gt;&lt;/font&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;font color="#ff0000"&gt;&lt;strong&gt;D&lt;/strong&gt;&lt;/font&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;font color="#ff0000"&gt;&lt;strong&gt;D&lt;/strong&gt;&lt;/font&gt;&lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td valign="top" width="325"&gt;Download signed ActiveX controls&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;font color="#ff0000"&gt;&lt;strong&gt;D&lt;/strong&gt;&lt;/font&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#0000ff"&gt;P&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#0000ff"&gt;P&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#0000ff"&gt;P&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#00ff00"&gt;E&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td valign="top" width="325"&gt;Download unsigned ActiveX controls&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;font color="#ff0000"&gt;&lt;strong&gt;D&lt;/strong&gt;&lt;/font&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;font color="#ff0000"&gt;&lt;strong&gt;D&lt;/strong&gt;&lt;/font&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;font color="#ff0000"&gt;&lt;strong&gt;D&lt;/strong&gt;&lt;/font&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;font color="#ff0000"&gt;&lt;strong&gt;D&lt;/strong&gt;&lt;/font&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#0000ff"&gt;P&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td valign="top" width="325"&gt;Initialize and script ActiveX controls not marked as safe for scripting&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;font color="#ff0000"&gt;&lt;strong&gt;D&lt;/strong&gt;&lt;/font&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;font color="#ff0000"&gt;&lt;strong&gt;D&lt;/strong&gt;&lt;/font&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;font color="#ff0000"&gt;&lt;strong&gt;D&lt;/strong&gt;&lt;/font&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;font color="#ff0000"&gt;&lt;strong&gt;D&lt;/strong&gt;&lt;/font&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#0000ff"&gt;P&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td valign="top" width="325"&gt;Run ActiveX controls and plug-ins&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;font color="#ff0000"&gt;&lt;strong&gt;D&lt;/strong&gt;&lt;/font&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#00ff00"&gt;E&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#00ff00"&gt;E&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#00ff00"&gt;E&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#00ff00"&gt;E&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td valign="top" width="325"&gt;Script ActiveX controls marked as safe for scripting&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;font color="#ff0000"&gt;&lt;strong&gt;D&lt;/strong&gt;&lt;/font&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#00ff00"&gt;E&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#00ff00"&gt;E&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#00ff00"&gt;E&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#00ff00"&gt;E&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;     &lt;/tr&gt;   &lt;/tbody&gt;&lt;/table&gt;  &lt;p&gt;&lt;strong&gt;Downloads&lt;/strong&gt;&lt;/p&gt;  &lt;table cellspacing="0" cellpadding="0" width="550" border="1"&gt;&lt;tbody&gt;     &lt;tr&gt;       &lt;td valign="top" width="325"&gt;&amp;#160;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;H&lt;/td&gt;        &lt;td valign="top" width="25"&gt;MH&lt;/td&gt;        &lt;td valign="top" width="25"&gt;M&lt;/td&gt;        &lt;td valign="top" width="25"&gt;ML&lt;/td&gt;        &lt;td valign="top" width="25"&gt;L&lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td valign="top" width="325"&gt;Automatic prompting for file downloads&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;font color="#ff0000"&gt;&lt;strong&gt;D&lt;/strong&gt;&lt;/font&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#00ff00"&gt;E&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#00ff00"&gt;E&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#00ff00"&gt;E&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#00ff00"&gt;E&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td valign="top" width="325"&gt;File download&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;font color="#ff0000"&gt;&lt;strong&gt;D&lt;/strong&gt;&lt;/font&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#00ff00"&gt;E&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#00ff00"&gt;E&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#00ff00"&gt;E&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#00ff00"&gt;E&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td valign="top" width="325"&gt;Font download&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#0000ff"&gt;P&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#00ff00"&gt;E&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#00ff00"&gt;E&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#00ff00"&gt;E&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#00ff00"&gt;E&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;     &lt;/tr&gt;   &lt;/tbody&gt;&lt;/table&gt;  &lt;p&gt;&lt;strong&gt;Enable .NET Framework setup&lt;/strong&gt;&lt;/p&gt;  &lt;table cellspacing="0" cellpadding="0" width="550" border="1"&gt;&lt;tbody&gt;     &lt;tr&gt;       &lt;td valign="top" width="325"&gt;&amp;#160;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;H&lt;/td&gt;        &lt;td valign="top" width="25"&gt;MH&lt;/td&gt;        &lt;td valign="top" width="25"&gt;M&lt;/td&gt;        &lt;td valign="top" width="25"&gt;ML&lt;/td&gt;        &lt;td valign="top" width="25"&gt;L&lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td valign="top" width="325"&gt;Enable .NET Framework setup&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;font color="#ff0000"&gt;&lt;strong&gt;D&lt;/strong&gt;&lt;/font&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#00ff00"&gt;E&lt;/font&gt;&lt;/strong&gt;&lt;font color="#ff0000"&gt;&lt;/font&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#00ff00"&gt;E&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#00ff00"&gt;E&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#00ff00"&gt;E&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;     &lt;/tr&gt;   &lt;/tbody&gt;&lt;/table&gt;  &lt;p&gt;&lt;strong&gt;Miscellaneous&lt;/strong&gt;&lt;/p&gt;  &lt;table cellspacing="0" cellpadding="0" width="550" border="1"&gt;&lt;tbody&gt;     &lt;tr&gt;       &lt;td valign="top" width="325"&gt;&amp;#160;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;H&lt;/td&gt;        &lt;td valign="top" width="25"&gt;MH&lt;/td&gt;        &lt;td valign="top" width="25"&gt;M&lt;/td&gt;        &lt;td valign="top" width="25"&gt;ML&lt;/td&gt;        &lt;td valign="top" width="25"&gt;L&lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td valign="top" width="325"&gt;Access data sources across domains&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;font color="#ff0000"&gt;&lt;strong&gt;D&lt;/strong&gt;&lt;/font&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;font color="#ff0000"&gt;&lt;strong&gt;D&lt;/strong&gt;&lt;/font&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;font color="#ff0000"&gt;&lt;strong&gt;D&lt;/strong&gt;&lt;/font&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;P&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#00ff00"&gt;E&lt;/font&gt;&lt;/strong&gt;&lt;font color="#ff0000"&gt;&lt;/font&gt;&lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td valign="top" width="325"&gt;Allow META REFRESH&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;font color="#ff0000"&gt;&lt;strong&gt;D&lt;/strong&gt;&lt;/font&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#00ff00"&gt;E&lt;/font&gt;&lt;/strong&gt;&lt;font color="#ff0000"&gt;&lt;/font&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#00ff00"&gt;E&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#00ff00"&gt;E&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#00ff00"&gt;E&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td valign="top" width="325"&gt;Allow scripting of Internet Explorer Web browser control&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;font color="#ff0000"&gt;&lt;strong&gt;D&lt;/strong&gt;&lt;/font&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;font color="#ff0000"&gt;&lt;strong&gt;D&lt;/strong&gt;&lt;/font&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;font color="#ff0000"&gt;&lt;strong&gt;D&lt;/strong&gt;&lt;/font&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#00ff00"&gt;E&lt;/font&gt;&lt;/strong&gt;&lt;font color="#ff0000"&gt;&lt;strong&gt;&lt;/strong&gt;&lt;/font&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#00ff00"&gt;E&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td valign="top" width="325"&gt;Allow script-initiated windows without size or position constraints&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;font color="#ff0000"&gt;&lt;strong&gt;D&lt;/strong&gt;&lt;/font&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;font color="#ff0000"&gt;&lt;strong&gt;D&lt;/strong&gt;&lt;/font&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;font color="#ff0000"&gt;&lt;strong&gt;D&lt;/strong&gt;&lt;/font&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#00ff00"&gt;E&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#00ff00"&gt;E&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td valign="top" width="325"&gt;Allow web pages to use restricted protocols for active content&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;font color="#ff0000"&gt;&lt;strong&gt;D&lt;/strong&gt;&lt;/font&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#0000ff"&gt;P&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#0000ff"&gt;P&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#0000ff"&gt;P&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#0000ff"&gt;P&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td valign="top" width="325"&gt;Allow web sites to open windows without address or status bars&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;font color="#ff0000"&gt;&lt;strong&gt;D&lt;/strong&gt;&lt;/font&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;font color="#ff0000"&gt;&lt;strong&gt;D&lt;/strong&gt;&lt;/font&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;font color="#ff0000"&gt;&lt;strong&gt;D&lt;/strong&gt;&lt;/font&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#00ff00"&gt;E&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#00ff00"&gt;E&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td valign="top" width="325"&gt;Display mixed content&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#0000ff"&gt;P&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#0000ff"&gt;P&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#0000ff"&gt;P&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#0000ff"&gt;P&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#0000ff"&gt;P&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td valign="top" width="325"&gt;Don't prompt for client certificate selection when no certificates or only one certificate exists&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;font color="#ff0000"&gt;&lt;strong&gt;D&lt;/strong&gt;&lt;/font&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;font color="#ff0000"&gt;&lt;strong&gt;D&lt;/strong&gt;&lt;/font&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;font color="#ff0000"&gt;&lt;strong&gt;D&lt;/strong&gt;&lt;/font&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#00ff00"&gt;E&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#00ff00"&gt;E&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td valign="top" width="325"&gt;Drag and drop or copy and paste files&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#0000ff"&gt;P&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#00ff00"&gt;E&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#00ff00"&gt;E&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#00ff00"&gt;E&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#00ff00"&gt;E&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td valign="top" width="325"&gt;Include local directory path when uploading files to a server&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;font color="#ff0000"&gt;&lt;strong&gt;D&lt;/strong&gt;&lt;/font&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#00ff00"&gt;E&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#00ff00"&gt;E&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#00ff00"&gt;E&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#00ff00"&gt;E&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td valign="top" width="325"&gt;Installation of desktop items&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;font color="#ff0000"&gt;&lt;strong&gt;D&lt;/strong&gt;&lt;/font&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#0000ff"&gt;P&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#0000ff"&gt;P&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#0000ff"&gt;P&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#00ff00"&gt;E&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td valign="top" width="325"&gt;Launching applications and unsafe files&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;font color="#ff0000"&gt;&lt;strong&gt;D&lt;/strong&gt;&lt;/font&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#0000ff"&gt;P&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#0000ff"&gt;P&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#00ff00"&gt;E&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#00ff00"&gt;E&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td valign="top" width="325"&gt;Launching programs and files in an IFRAME&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;font color="#ff0000"&gt;&lt;strong&gt;D&lt;/strong&gt;&lt;/font&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#0000ff"&gt;P&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#0000ff"&gt;P&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#0000ff"&gt;P&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#00ff00"&gt;E&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td valign="top" width="325"&gt;Navigate sub-frames across different domains&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;font color="#ff0000"&gt;&lt;strong&gt;D&lt;/strong&gt;&lt;/font&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;font color="#ff0000"&gt;&lt;strong&gt;D&lt;/strong&gt;&lt;/font&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;font color="#ff0000"&gt;&lt;strong&gt;D&lt;/strong&gt;&lt;/font&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#00ff00"&gt;E&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#00ff00"&gt;E&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td valign="top" width="325"&gt;Open files based on content, not file extension&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;font color="#ff0000"&gt;&lt;strong&gt;D&lt;/strong&gt;&lt;/font&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#00ff00"&gt;E&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#00ff00"&gt;E&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#00ff00"&gt;E&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#00ff00"&gt;E&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td valign="top" width="325"&gt;Software channel permissions&lt;/td&gt;        &lt;td valign="top" width="25"&gt;1&lt;/td&gt;        &lt;td valign="top" width="25"&gt;2&lt;/td&gt;        &lt;td valign="top" width="25"&gt;2&lt;/td&gt;        &lt;td valign="top" width="25"&gt;2&lt;/td&gt;        &lt;td valign="top" width="25"&gt;3&lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td valign="top" width="325"&gt;Submit non-encrypted form data&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#0000ff"&gt;P&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#00ff00"&gt;E&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#00ff00"&gt;E&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#00ff00"&gt;E&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#00ff00"&gt;E&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td valign="top" width="325"&gt;Use phishing filter&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#00ff00"&gt;E&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#00ff00"&gt;E&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#00ff00"&gt;E&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;font color="#ff0000"&gt;&lt;strong&gt;D&lt;/strong&gt;&lt;/font&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;font color="#ff0000"&gt;&lt;strong&gt;D&lt;/strong&gt;&lt;/font&gt;&lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td valign="top" width="325"&gt;Use pop-up blocker&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#00ff00"&gt;E&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#00ff00"&gt;E&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#00ff00"&gt;E&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;font color="#ff0000"&gt;&lt;strong&gt;D&lt;/strong&gt;&lt;/font&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;font color="#ff0000"&gt;&lt;strong&gt;D&lt;/strong&gt;&lt;/font&gt;&lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td valign="top" width="325"&gt;Userdata persistence&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;font color="#ff0000"&gt;&lt;strong&gt;D&lt;/strong&gt;&lt;/font&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#00ff00"&gt;E&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#00ff00"&gt;E&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#00ff00"&gt;E&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#00ff00"&gt;E&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td valign="top" width="325"&gt;Web sites in less privileged content zone can navigate into this zone&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;font color="#ff0000"&gt;&lt;strong&gt;D&lt;/strong&gt;&lt;/font&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#00ff00"&gt;E&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#00ff00"&gt;E&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#00ff00"&gt;E&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#0000ff"&gt;P&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;     &lt;/tr&gt;   &lt;/tbody&gt;&lt;/table&gt;  &lt;p&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160; 1 = Prohibit downloads from software update channels    &lt;br /&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160; 2 = Cache content downloaded from software update channels     &lt;br /&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160; 3 = Automatically install software updates&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Scripting&lt;/strong&gt;&lt;/p&gt;  &lt;table cellspacing="0" cellpadding="0" width="550" border="1"&gt;&lt;tbody&gt;     &lt;tr&gt;       &lt;td valign="top" width="325"&gt;&amp;#160;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;H&lt;/td&gt;        &lt;td valign="top" width="25"&gt;MH&lt;/td&gt;        &lt;td valign="top" width="25"&gt;M&lt;/td&gt;        &lt;td valign="top" width="25"&gt;ML&lt;/td&gt;        &lt;td valign="top" width="25"&gt;L&lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td valign="top" width="325"&gt;Active scripting&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;font color="#ff0000"&gt;&lt;strong&gt;D&lt;/strong&gt;&lt;/font&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#00ff00"&gt;E&lt;/font&gt;&lt;/strong&gt;&lt;font color="#ff0000"&gt;&lt;/font&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#00ff00"&gt;E&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#00ff00"&gt;E&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#00ff00"&gt;E&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td valign="top" width="325"&gt;Allow programmatic clipboard access&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;font color="#ff0000"&gt;&lt;strong&gt;D&lt;/strong&gt;&lt;/font&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#0000ff"&gt;P&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#0000ff"&gt;P&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#0000ff"&gt;P&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#00ff00"&gt;E&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td valign="top" width="325"&gt;Allow status bar updates via script&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;font color="#ff0000"&gt;&lt;strong&gt;D&lt;/strong&gt;&lt;/font&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;font color="#ff0000"&gt;&lt;strong&gt;D&lt;/strong&gt;&lt;/font&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;font color="#ff0000"&gt;&lt;strong&gt;D&lt;/strong&gt;&lt;/font&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#00ff00"&gt;E&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#00ff00"&gt;E&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td valign="top" width="325"&gt;Allow Web sites to prompt for information using scripted windows&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;font color="#ff0000"&gt;&lt;strong&gt;D&lt;/strong&gt;&lt;/font&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;font color="#ff0000"&gt;&lt;strong&gt;D&lt;/strong&gt;&lt;/font&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#00ff00"&gt;E&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#00ff00"&gt;E&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#00ff00"&gt;E&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td valign="top" width="325"&gt;Scripting of Java applets&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;font color="#ff0000"&gt;&lt;strong&gt;D&lt;/strong&gt;&lt;/font&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#00ff00"&gt;E&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#00ff00"&gt;E&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#00ff00"&gt;E&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#00ff00"&gt;E&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;     &lt;/tr&gt;   &lt;/tbody&gt;&lt;/table&gt;  &lt;p&gt;&lt;strong&gt;User authentication&lt;/strong&gt;&lt;/p&gt;  &lt;table cellspacing="0" cellpadding="0" width="550" border="1"&gt;&lt;tbody&gt;     &lt;tr&gt;       &lt;td valign="top" width="325"&gt;&amp;#160;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;H&lt;/td&gt;        &lt;td valign="top" width="25"&gt;MH&lt;/td&gt;        &lt;td valign="top" width="25"&gt;M&lt;/td&gt;        &lt;td valign="top" width="25"&gt;ML&lt;/td&gt;        &lt;td valign="top" width="25"&gt;L&lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td valign="top" width="325"&gt;Logon&lt;/td&gt;        &lt;td valign="top" width="25"&gt;1&lt;/td&gt;        &lt;td valign="top" width="25"&gt;2&lt;/td&gt;        &lt;td valign="top" width="25"&gt;2&lt;/td&gt;        &lt;td valign="top" width="25"&gt;2&lt;/td&gt;        &lt;td valign="top" width="25"&gt;3&lt;/td&gt;     &lt;/tr&gt;   &lt;/tbody&gt;&lt;/table&gt;  &lt;p&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160; 1 = Prompt the user for name and password    &lt;br /&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160; 2 = Automatic logon only in intranet zone     &lt;br /&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160; 3 = Automatic logon with current user name and password&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Privacy settings (on the &amp;quot;Privacy&amp;quot; tab)&lt;/strong&gt;&lt;/p&gt;  &lt;table cellspacing="0" cellpadding="0" width="550" border="1"&gt;&lt;tbody&gt;     &lt;tr&gt;       &lt;td valign="top" width="325"&gt;&amp;#160;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;H&lt;/td&gt;        &lt;td valign="top" width="25"&gt;MH&lt;/td&gt;        &lt;td valign="top" width="25"&gt;M&lt;/td&gt;        &lt;td valign="top" width="25"&gt;ML&lt;/td&gt;        &lt;td valign="top" width="25"&gt;L&lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td valign="top" width="325"&gt;Allow persistent cookies&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;font color="#ff0000"&gt;&lt;strong&gt;D&lt;/strong&gt;&lt;/font&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#00ff00"&gt;E&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#00ff00"&gt;E&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#00ff00"&gt;E&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#00ff00"&gt;E&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td valign="top" width="325"&gt;Allow per-session cookies&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;font color="#ff0000"&gt;&lt;strong&gt;D&lt;/strong&gt;&lt;/font&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#00ff00"&gt;E&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#00ff00"&gt;E&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#00ff00"&gt;E&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#00ff00"&gt;E&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td valign="top" width="325"&gt;Allow third-party persistent cookies&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;font color="#ff0000"&gt;&lt;strong&gt;D&lt;/strong&gt;&lt;/font&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#0000ff"&gt;P&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#0000ff"&gt;P&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#00ff00"&gt;E&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#00ff00"&gt;E&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td valign="top" width="325"&gt;Allow third-party session cookies&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;font color="#ff0000"&gt;&lt;strong&gt;D&lt;/strong&gt;&lt;/font&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#00ff00"&gt;E&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#00ff00"&gt;E&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#00ff00"&gt;E&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;        &lt;td valign="top" width="25"&gt;&lt;strong&gt;&lt;font color="#00ff00"&gt;E&lt;/font&gt;&lt;/strong&gt;&lt;/td&gt;     &lt;/tr&gt;   &lt;/tbody&gt;&lt;/table&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3124973" width="1" height="1"&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/SteveRileyOnSecurity?a=mRQDZ5AB3sQ:A6d_3euTfU0:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/SteveRileyOnSecurity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/SteveRileyOnSecurity?a=mRQDZ5AB3sQ:A6d_3euTfU0:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/SteveRileyOnSecurity?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/SteveRileyOnSecurity?a=mRQDZ5AB3sQ:A6d_3euTfU0:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/SteveRileyOnSecurity?i=mRQDZ5AB3sQ:A6d_3euTfU0:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/SteveRileyOnSecurity?a=mRQDZ5AB3sQ:A6d_3euTfU0:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/SteveRileyOnSecurity?i=mRQDZ5AB3sQ:A6d_3euTfU0:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><category domain="http://blogs.technet.com/steriley/archive/tags/configuration/default.aspx">configuration</category><category domain="http://blogs.technet.com/steriley/archive/tags/Internet+Explorer/default.aspx">Internet Explorer</category></item><item><title>The opt-out from hell</title><link>http://blogs.technet.com/steriley/archive/2008/09/16/the-opt-out-from-hell.aspx</link><pubDate>Tue, 16 Sep 2008 19:22:03 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3124873</guid><dc:creator>Steve Riley</dc:creator><slash:comments>8</slash:comments><comments>http://blogs.technet.com/steriley/comments/3124873.aspx</comments><wfw:commentRss>http://blogs.technet.com/steriley/commentrss.aspx?PostID=3124873</wfw:commentRss><wfw:comment>http://blogs.technet.com/steriley/rsscomments.aspx?PostID=3124873</wfw:comment><description>&lt;p&gt;One problem with making your email address available (which I will continue to do, don't worry) is that folks with something to sell assume you're interested in their stuff. To wit, let's consider an email I received today (copied, headers and all, after my griping).&lt;/p&gt;  &lt;p&gt;Note that if I want to opt out of further communications, I have to do &lt;em&gt;two separate things&lt;/em&gt; -- which actually becomes three things.&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;First I have to click the last link to opt out of future TechTarget spam. (Yes, I deleted the actual links. But certainly none of &lt;em&gt;my&lt;/em&gt; trustworthy readers would attempt to re-subscribe me, right...? &amp;lt;g&amp;gt; &lt;/li&gt;    &lt;li&gt;But that isn't enough -- I &lt;em&gt;also&lt;/em&gt; have to separately opt out of future Avaya spam! (Why does the no-more-from-Avaya link live on a techtargetmail.com server? Whatever.) Clicking on that link eventually does land me on an avaya.com page, where I have to confirm my email address and indicate they don't have my permission to send me spam. Hmm, too difficult to embed my email in that link, when the other techtargetmail.com link &lt;em&gt;did&lt;/em&gt; embed my email? &lt;/li&gt;    &lt;li&gt;Then after submitting it, another page pops up telling me that I'll soon receive an email with &lt;em&gt;additional&lt;/em&gt; instructions! In this email there's a link -- to avaya.com with my email address embedded -- that I must click, I guess to double plus confirm that yes, I really really really do wish never to hear from you again. Clicking that link takes me to a page that promises my &amp;quot;permissions have successfully been set. Thank you.&amp;quot; &lt;/li&gt; &lt;/ul&gt;  &lt;p&gt;A pox on both your houses, TechTarget and Avaya. I never asked for your stuff. Go away.&lt;/p&gt;  &lt;p&gt;Spam, my friends, is only going to &lt;a href="http://www.washingtonpost.com/wp-dyn/content/article/2008/09/12/AR2008091201211.html?hpid=topnews" target="_blank"&gt;get&lt;/a&gt; &lt;a href="http://voices.washingtonpost.com/securityfix/2008/09/virginia_anti-spam_law_overtur.html?hpid=news-col-blogs" target="_blank"&gt;worse&lt;/a&gt;. It was so easy to &lt;a href="http://en.wikipedia.org/wiki/Junk_fax" target="_blank"&gt;ban junk faxes&lt;/a&gt; in 1991. But even those regulations were &lt;a href="http://en.wikipedia.org/wiki/Junk_Fax_Prevention_Act_of_2005" target="_blank"&gt;weakened in 2005&lt;/a&gt;. So do you really think we'll see anything even remotely logical for outlawing spam? I doubt it, unless we the citizens foment a revolt. Let's get cracking! &lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;hr /&gt;  &lt;p&gt;&lt;font face="Courier New" size="2"&gt;Received: from SVC-EXGWY-E801.partners.extranet.microsoft.com (10.251.24.242)      &lt;br /&gt;by tk5-exhub-c102.redmond.corp.microsoft.com (157.54.18.53) with Microsoft       &lt;br /&gt;SMTP Server (TLS) id 8.1.291.1; Tue, 16 Sep 2008 11:27:56 -0700       &lt;br /&gt;Received: from mail139-wa4-R.bigfish.com (216.32.181.113) by       &lt;br /&gt;mail04.microsoft.com (10.253.160.184) with Microsoft SMTP Server (TLS) id       &lt;br /&gt;8.1.291.1; Tue, 16 Sep 2008 11:27:55 -0700       &lt;br /&gt;Received: from mail139-wa4 (localhost.localdomain [127.0.0.1])&amp;#160;&amp;#160;&amp;#160; by       &lt;br /&gt;mail139-wa4-R.bigfish.com (Postfix) with ESMTP id 018C11184C2&amp;#160;&amp;#160;&amp;#160; for       &lt;br /&gt;&amp;lt;steriley@microsoft.com&amp;gt;; Tue, 16 Sep 2008 18:27:50 +0000 (UTC)       &lt;br /&gt;X-BigFish: ps16(zz18c1K1936K2b7wcak69jzzzz2af1jz2fh6bh5eh65h)       &lt;br /&gt;X-Spam-TCS-SCL: 4:0       &lt;br /&gt;Received: by mail139-wa4 (MessageSwitch) id 1221589667478982_28100; Tue, 16       &lt;br /&gt;Sep 2008 18:27:47 +0000 (UCT)       &lt;br /&gt;Received: from pp.techtargetmail.com (pp.techtargetmail.com [65.211.80.227])       &lt;br /&gt;&amp;#160;&amp;#160;&amp;#160; by mail139-wa4.bigfish.com (Postfix) with SMTP id 46566978071&amp;#160;&amp;#160;&amp;#160; for       &lt;br /&gt;&amp;lt;steriley@microsoft.com&amp;gt;; Tue, 16 Sep 2008 18:27:47 +0000 (UTC)       &lt;br /&gt;DomainKey-Signature: a=rsa-sha1; q=dns; c=nofws; s=s1024; d=pp.techtargetmail.com; b=iOmibOrM91/1Ugy2gj3QbWo74T2m3GuhmwxZCXJQpFT+nwRES8QKg+4vjt48SNp7WWJExG61Ge+DtnKD3KVI3KwqTKzkPRVrEBF0DCHhYot6VAG/EyEr5vb5RhBz+91yvNhbIqITzGnuQ+uBDJzyc6gU0FHfBl0Fa3S/phcPELM=;       &lt;br /&gt;Message-ID: &amp;lt;a818b044.724694.236c8ee748f7dd97.1.n.4.2971370188@pp.techtargetmail.com&amp;gt;       &lt;br /&gt;Date: Tue, 16 Sep 2008 14:27:47 -0400       &lt;br /&gt;thread-index: a818b044.724694.236c8ee748f7dd97.1.n.4       &lt;br /&gt;Reply-To: Avaya &amp;lt;a818b044.724694.236c8ee748f7dd97.1.n.4@pp.techtargetmail.com&amp;gt;       &lt;br /&gt;From: Avaya &amp;lt;Avaya@pp.techtargetmail.com&amp;gt;       &lt;br /&gt;To: Steve Riley &amp;lt;steriley@microsoft.com&amp;gt;       &lt;br /&gt;Subject: 7 Tips to Ensure Readiness for UC Deployment       &lt;br /&gt;MIME-Version: 1.0       &lt;br /&gt;Content-Type: text/plain       &lt;br /&gt;Content-Transfer-Encoding: 7bit       &lt;br /&gt;Content-Class: urn:content-classes:message       &lt;br /&gt;Importance: normal       &lt;br /&gt;Priority: normal       &lt;br /&gt;X-MimeOLE: Produced By Microsoft MimeOLE V6.00.3790.4133       &lt;br /&gt;Return-Path: a818b044.724694.236c8ee748f7dd97.1.n.4@pp.techtargetmail.com       &lt;br /&gt;X-MS-Exchange-Organization-PRD: pp.techtargetmail.com       &lt;br /&gt;Received-SPF: Pass (SVC-EXGWY-E801.partners.extranet.microsoft.com: domain       &lt;br /&gt;of Avaya@pp.techtargetmail.com designates 65.211.80.227 as permitted sender)       &lt;br /&gt;receiver=SVC-EXGWY-E801.partners.extranet.microsoft.com;       &lt;br /&gt;client-ip=65.211.80.227; helo=mail139-wa4-R.bigfish.com;       &lt;br /&gt;X-MS-Exchange-Organization-PCL: 2       &lt;br /&gt;X-MS-Exchange-Organization-Antispam-Report: DV:3.3.6916.600;SV:3.3.6916.813;SID:SenderIDStatus Pass;OrigIP:65.211.80.227       &lt;br /&gt;X-MS-Exchange-Organization-SCL: 2       &lt;br /&gt;X-MS-Exchange-Organization-SenderIdResult: PASS&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font face="Courier New" size="2"&gt;The following message was sent to you as a subscriber to third party offers from a TechTarget property, including our network of Search sites, Bitpipe.com, CIO Decisions Magazine, Information Security Magazine, Storage Magazine, KnowledgeStorm, TheServerSide.com and/or TheServerSide.NET. To unsubscribe, see below.      &lt;br /&gt;____________________________________________________________ &lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font face="Courier New" size="2"&gt;How should you evaluate the move to unified communications (UC)? Who within which parts of an organization will benefit? Will UC reduce the time to market? Read this E-Guide for answers to these questions and a better look at how the value of UC will, at first, be less of a financial issue and more of a productivity improvement issue that translates into financial benefits. Download this white paper now: &lt;/font&gt;&lt;a href="http://pp.techtargetmail.com/c.asp?724694&amp;amp;236c8ee748f7dd97&amp;amp;1"&gt;&lt;font face="Courier New" size="2"&gt;http://pp.techtargetmail.com/c.asp?724694&amp;amp;236c8ee748f7dd97&amp;amp;1&lt;/font&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&lt;font face="Courier New" size="2"&gt;When implementing unified communications, there are a number of important issues to think about and questions to ask. This E-Guide analyzes seven phases to ensure you reap the full benefits of UC in each. If you're ready to take the plunge but you're not sure your business or your infrastructure is - download this E-Guide now. &lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font face="Courier New" size="2"&gt;Click here to learn more: &lt;/font&gt;&lt;a href="http://pp.techtargetmail.com/c.asp?724694&amp;amp;236c8ee748f7dd97&amp;amp;1"&gt;&lt;font face="Courier New" size="2"&gt;http://pp.techtargetmail.com/c.asp?724694&amp;amp;236c8ee748f7dd97&amp;amp;1&lt;/font&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&lt;font face="Courier New" size="2"&gt;&amp;quot;If you do not wish to receive future promotions directly from Avaya please forward this e-mail to &lt;u&gt;{link removed}&lt;/u&gt; ; please note that there is a separate opt-out procedure below to be removed from the list from which this email originated.&amp;quot;       &lt;br /&gt;____________________________________________________________ &lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font face="Courier New" size="2"&gt;Please do not reply to this email.&amp;#160; To unsubscribe from all future third party offers from all TechTarget properties, simply click here: &lt;u&gt;{link removed}&lt;/u&gt;&lt;/font&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&lt;font face="Courier New" size="2"&gt;TechTarget | 117 Kendrick Street, Suite 800 | Needham, MA 02494&lt;/font&gt; &lt;/p&gt;  &lt;hr /&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3124873" width="1" height="1"&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/SteveRileyOnSecurity?a=ClgGxDKVR1E:wt7ug8KWWog:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/SteveRileyOnSecurity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/SteveRileyOnSecurity?a=ClgGxDKVR1E:wt7ug8KWWog:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/SteveRileyOnSecurity?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/SteveRileyOnSecurity?a=ClgGxDKVR1E:wt7ug8KWWog:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/SteveRileyOnSecurity?i=ClgGxDKVR1E:wt7ug8KWWog:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/SteveRileyOnSecurity?a=ClgGxDKVR1E:wt7ug8KWWog:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/SteveRileyOnSecurity?i=ClgGxDKVR1E:wt7ug8KWWog:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><category domain="http://blogs.technet.com/steriley/archive/tags/advertising/default.aspx">advertising</category><category domain="http://blogs.technet.com/steriley/archive/tags/spam/default.aspx">spam</category><category domain="http://blogs.technet.com/steriley/archive/tags/email/default.aspx">email</category><category domain="http://blogs.technet.com/steriley/archive/tags/things+that+make+me+angry/default.aspx">things that make me angry</category><category domain="http://blogs.technet.com/steriley/archive/tags/public+policy/default.aspx">public policy</category></item></channel></rss>
