<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:trackback="http://madskills.com/public/xml/rss/module/trackback/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:copyright="http://blogs.law.harvard.edu/tech/rss" xmlns:image="http://purl.org/rss/1.0/modules/image/" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0">
    <channel>
        <title>Sergey Simakov blog</title>
        <link>http://geekswithblogs.net/ssimakov/Default.aspx</link>
        <description>Information security world</description>
        <language>en-US</language>
        <copyright>Sergey Simakov</copyright>
        <managingEditor>sim@yandex.ru</managingEditor>
        <generator>Subtext Version 0.0.0.0</generator>
        <image>
            <title>Sergey Simakov blog</title>
            <url>http://geekswithblogs.net/images/RSS2Image.gif</url>
            <link>http://geekswithblogs.net/ssimakov/Default.aspx</link>
            <width>77</width>
            <height>60</height>
        </image>
        <atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/rss+xml" href="http://feeds.feedburner.com/sergesim" /><feedburner:info uri="sergesim" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com" /><feedburner:browserFriendly>This is an XML content feed. It is intended to be viewed in a newsreader or syndicated to another site, subject to copyright and fair use.</feedburner:browserFriendly><item>
            <title>CISSP exam and new home for blog</title>
            <category>Personal</category>
            <link>http://feedproxy.google.com/~r/sergesim/~3/O6_uAVYJ7gk/101426.aspx</link>
            <description>&lt;P&gt;Sorry for lack of posts last month. I was really busy at work with different projects (PKI, SC, security&amp;nbsp;reviews)&amp;nbsp;and tried to learn new CBK domains at home, so I basically didn't have a time to blog at all. Again, sorry.&lt;/P&gt;
&lt;P&gt;Today I had an &lt;A href="https://www.isc2.org/cgi-bin/content.cgi?category=538"&gt;CISSP&lt;/A&gt; exam&amp;nbsp;(you know -&amp;nbsp;6 hours is hard ;-)&amp;nbsp;after&amp;nbsp;week of&amp;nbsp;&lt;A href="https://www.isc2.org/cgi-bin/content.cgi?category=711"&gt;CBK review&amp;nbsp;seminars&lt;/A&gt; (by Dennis Griffin)&amp;nbsp;with some of Microsoft EMEA guys and other attendees at &lt;A href="http://maps.live.com/default.aspx?v=2&amp;amp;cp=50.986099~9.760666&amp;amp;style=r&amp;amp;lvl=12&amp;amp;tilt=-90&amp;amp;dir=0&amp;amp;alt=-1000"&gt;Rotenburg a.d. Fulda&lt;/A&gt; (and you know - it was a good choice after all, because&amp;nbsp;this hotel is so far away from town&amp;nbsp;and&amp;nbsp;there're even no any&amp;nbsp;people at reception or on my floor right now, so I could concentrate on learning). I hope that I passed it&amp;nbsp;- because sometimes it looked like a very complicated exam in English language ;-)&lt;/P&gt;
&lt;P&gt;Well, it seems that Vista is ready now and will be available to customers in near feature, so it's time to check &lt;A href="http://www.microsoft.com/downloads/details.aspx?familyid=a3d1bbed-7f35-4e72-bfb5-b84a526c1565&amp;amp;displaylang=en"&gt;Windows Vista Security Guide&lt;/A&gt; and other Vista's &lt;A href="http://www.infoworld.com/article/06/12/08/50OPsecadvise_1.html?source=NLC-STOADV2006-12-11"&gt;security features&lt;/A&gt;. I'm living with it for 5 months now and it's really good (especially from security point of view&amp;nbsp;- ASLR, BitLocker, etc)&lt;/P&gt;
&lt;P&gt;Some news on&amp;nbsp;blog changes - in near feature (begining next year) I'm going to post at &lt;A href="http://blogs.technet.com/ssimakov"&gt;http://blogs.technet.com/ssimakov&lt;/A&gt; - mostly in Russian and for russian ITSec community. But I'll keep this blog as personal and continue to cross-post here in English.&lt;/P&gt;
&lt;P&gt;And now it's time to prepare for flight back to Moscow and following&amp;nbsp;vacations&amp;nbsp;in &lt;A href="http://maps.live.com/default.aspx?v=2&amp;amp;cp=10.879162~107.977753&amp;amp;style=r&amp;amp;lvl=9&amp;amp;tilt=-90&amp;amp;dir=0&amp;amp;alt=-1000"&gt;Phan Thiet,Vietnam&lt;/A&gt;. &lt;/P&gt;
&lt;P&gt;Merry Christmas and Happy New Year!&lt;/P&gt;&lt;p&gt;&lt;a href="http://www.pheedo.com/click.phdo?x=6cda6ad746d942b9a1110d0715a4fa12&amp;u=101426"&gt;&lt;img src="http://www.pheedo.com/img.phdo?x=6cda6ad746d942b9a1110d0715a4fa12&amp;u=101426" border="0"/&gt;&lt;/a&gt;&lt;/p&gt;&lt;iframe src="http://ads.geekswithblogs.net/a.aspx?ZoneID=5&amp;amp;Task=Get&amp;amp;PageID=31016&amp;amp;SiteID=1" width=1 height=1 Marginwidth=0 Marginheight=0 Hspace=0 Vspace=0 Frameborder=0 Scrolling=No&gt;
&lt;script language='javascript1.1' src="http://ads.geekswithblogs.net/a.aspx?ZoneID=5&amp;amp;Task=Get&amp;amp;Browser=NETSCAPE4&amp;amp;NoCache=True&amp;PageID=31016&amp;amp;SiteID=1"&gt;&lt;/script&gt;
&lt;noscript&gt;&lt;a href="http://ads.geekswithblogs.net/a.aspx?ZoneID=5&amp;amp;Task=Click&amp;amp;Mode=HTML&amp;amp;SiteID=1&amp;amp;PageID=31016" target="_blank"&gt;
&lt;img src="http://ads.geekswithblogs.net/a.aspx?ZoneID=5&amp;amp;Task=Get&amp;amp;Mode=HTML&amp;amp;SiteID=1&amp;amp;PageID=31016" width="1" height="1" border="0"  alt=""&gt;&lt;/a&gt;
&lt;/noscript&gt;
&lt;/iframe&gt;
&lt;img src="http://geekswithblogs.net/ssimakov/aggbug/101426.aspx" width="1" height="1" /&gt;</description>
            <dc:creator>Sergey Simakov</dc:creator>
            <guid isPermaLink="false">http://geekswithblogs.net/ssimakov/archive/2006/12/18/101426.aspx</guid>
            <pubDate>Mon, 18 Dec 2006 07:08:00 GMT</pubDate>
            <comments>http://geekswithblogs.net/ssimakov/archive/2006/12/18/101426.aspx#feedback</comments>
            <slash:comments>1</slash:comments>
            <wfw:commentRss>http://geekswithblogs.net/ssimakov/comments/commentRss/101426.aspx</wfw:commentRss>
        <feedburner:origLink>http://geekswithblogs.net/ssimakov/archive/2006/12/18/101426.aspx</feedburner:origLink></item>
        <item>
            <title>Great blog on smartcards deployment</title>
            <category>Development</category>
            <category>Security</category>
            <link>http://feedproxy.google.com/~r/sergesim/~3/ffIQ7CpaO2A/97647.aspx</link>
            <description>I just found that I've missed a great blog by Steve Patrick (from Critical Problem Resolution&amp;nbsp;team)&amp;nbsp;with invaluable information on SmartCard deployment, so begin with this post - &lt;A href="http://blogs.msdn.com/spatdsg/archive/2006/09/05/739565.aspx"&gt;So, you want to use smart cards?&lt;/A&gt;. Thanks for sharing this information, Steve! [&lt;A href="http://blogs.msdn.com/spatdsg/rss.xml"&gt;subscribed&lt;/A&gt;]&lt;p&gt;&lt;a href="http://www.pheedo.com/click.phdo?x=6cda6ad746d942b9a1110d0715a4fa12&amp;u=97647"&gt;&lt;img src="http://www.pheedo.com/img.phdo?x=6cda6ad746d942b9a1110d0715a4fa12&amp;u=97647" border="0"/&gt;&lt;/a&gt;&lt;/p&gt;&lt;iframe src="http://ads.geekswithblogs.net/a.aspx?ZoneID=5&amp;amp;Task=Get&amp;amp;PageID=31016&amp;amp;SiteID=1" width=1 height=1 Marginwidth=0 Marginheight=0 Hspace=0 Vspace=0 Frameborder=0 Scrolling=No&gt;
&lt;script language='javascript1.1' src="http://ads.geekswithblogs.net/a.aspx?ZoneID=5&amp;amp;Task=Get&amp;amp;Browser=NETSCAPE4&amp;amp;NoCache=True&amp;PageID=31016&amp;amp;SiteID=1"&gt;&lt;/script&gt;
&lt;noscript&gt;&lt;a href="http://ads.geekswithblogs.net/a.aspx?ZoneID=5&amp;amp;Task=Click&amp;amp;Mode=HTML&amp;amp;SiteID=1&amp;amp;PageID=31016" target="_blank"&gt;
&lt;img src="http://ads.geekswithblogs.net/a.aspx?ZoneID=5&amp;amp;Task=Get&amp;amp;Mode=HTML&amp;amp;SiteID=1&amp;amp;PageID=31016" width="1" height="1" border="0"  alt=""&gt;&lt;/a&gt;
&lt;/noscript&gt;
&lt;/iframe&gt;
&lt;img src="http://geekswithblogs.net/ssimakov/aggbug/97647.aspx" width="1" height="1" /&gt;</description>
            <dc:creator>Sergey Simakov</dc:creator>
            <guid isPermaLink="false">http://geekswithblogs.net/ssimakov/archive/2006/11/20/97647.aspx</guid>
            <pubDate>Tue, 21 Nov 2006 04:13:00 GMT</pubDate>
            <comments>http://geekswithblogs.net/ssimakov/archive/2006/11/20/97647.aspx#feedback</comments>
            <wfw:commentRss>http://geekswithblogs.net/ssimakov/comments/commentRss/97647.aspx</wfw:commentRss>
        <feedburner:origLink>http://geekswithblogs.net/ssimakov/archive/2006/11/20/97647.aspx</feedburner:origLink></item>
        <item>
            <title>Consolidation of Managed Security Services market</title>
            <category>Security</category>
            <link>http://feedproxy.google.com/~r/sergesim/~3/B_4m4KHt4RA/95078.aspx</link>
            <description>Well, it didn't&amp;nbsp;take long time after SecureWorks/LURHQ&amp;nbsp;and IBM/ISS deals: &lt;A href="http://www.schneier.com/blog/archives/2006/10/bt_acquires_cou.html"&gt;British Telecom acquires Counterpane&lt;/A&gt;.&lt;p&gt;&lt;a href="http://www.pheedo.com/click.phdo?x=6cda6ad746d942b9a1110d0715a4fa12&amp;u=95078"&gt;&lt;img src="http://www.pheedo.com/img.phdo?x=6cda6ad746d942b9a1110d0715a4fa12&amp;u=95078" border="0"/&gt;&lt;/a&gt;&lt;/p&gt;&lt;iframe src="http://ads.geekswithblogs.net/a.aspx?ZoneID=5&amp;amp;Task=Get&amp;amp;PageID=31016&amp;amp;SiteID=1" width=1 height=1 Marginwidth=0 Marginheight=0 Hspace=0 Vspace=0 Frameborder=0 Scrolling=No&gt;
&lt;script language='javascript1.1' src="http://ads.geekswithblogs.net/a.aspx?ZoneID=5&amp;amp;Task=Get&amp;amp;Browser=NETSCAPE4&amp;amp;NoCache=True&amp;PageID=31016&amp;amp;SiteID=1"&gt;&lt;/script&gt;
&lt;noscript&gt;&lt;a href="http://ads.geekswithblogs.net/a.aspx?ZoneID=5&amp;amp;Task=Click&amp;amp;Mode=HTML&amp;amp;SiteID=1&amp;amp;PageID=31016" target="_blank"&gt;
&lt;img src="http://ads.geekswithblogs.net/a.aspx?ZoneID=5&amp;amp;Task=Get&amp;amp;Mode=HTML&amp;amp;SiteID=1&amp;amp;PageID=31016" width="1" height="1" border="0"  alt=""&gt;&lt;/a&gt;
&lt;/noscript&gt;
&lt;/iframe&gt;
&lt;img src="http://geekswithblogs.net/ssimakov/aggbug/95078.aspx" width="1" height="1" /&gt;</description>
            <dc:creator>Sergey Simakov</dc:creator>
            <guid isPermaLink="false">http://geekswithblogs.net/ssimakov/archive/2006/10/25/95078.aspx</guid>
            <pubDate>Thu, 26 Oct 2006 03:09:00 GMT</pubDate>
            <comments>http://geekswithblogs.net/ssimakov/archive/2006/10/25/95078.aspx#feedback</comments>
            <slash:comments>1</slash:comments>
            <wfw:commentRss>http://geekswithblogs.net/ssimakov/comments/commentRss/95078.aspx</wfw:commentRss>
        <feedburner:origLink>http://geekswithblogs.net/ssimakov/archive/2006/10/25/95078.aspx</feedburner:origLink></item>
        <item>
            <title>Active Directory Certificate Server Enhancements in Windows Server Longhorn RTW</title>
            <category>Security</category>
            <link>http://feedproxy.google.com/~r/sergesim/~3/BYqALKHeMvE/94984.aspx</link>
            <description>&lt;P&gt;&lt;A href="http://www.microsoft.com/downloads/details.aspx?familyid=9bf17231-d832-4ff9-8fb8-0539ba21ab95&amp;amp;displaylang=en"&gt;Active Directory Certificate Server Enhancements (aka Windows PKI)&amp;nbsp;in Windows Server "Longhorn"&lt;/A&gt; guide by Carsten Kinder with help of PKI PMs was finally released to web. This comprehensive document contains information about new PKI features in Windows Server "Longhorn" such as:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Cryptography API: Next Generation&amp;nbsp;(aka CNG) support in CAs&amp;nbsp;to provide crypto agility&lt;/LI&gt;
&lt;LI&gt;Unattended and integrated&amp;nbsp;interactive setup options&amp;nbsp;(without need to disable AIA in root CA cert)&lt;/LI&gt;
&lt;LI&gt;Certificate templates v3&lt;/LI&gt;
&lt;LI&gt;Restricted Enrollment Agent and Restricted Certificate Managers support (very&amp;nbsp;needed in enterprise scenarios)&lt;/LI&gt;
&lt;LI&gt;many other new features and OCSP standard support&lt;/LI&gt;&lt;/UL&gt;
&lt;P&gt;So it's very recommended&amp;nbsp;to study.&lt;/P&gt;&lt;p&gt;&lt;a href="http://www.pheedo.com/click.phdo?x=6cda6ad746d942b9a1110d0715a4fa12&amp;u=94984"&gt;&lt;img src="http://www.pheedo.com/img.phdo?x=6cda6ad746d942b9a1110d0715a4fa12&amp;u=94984" border="0"/&gt;&lt;/a&gt;&lt;/p&gt;&lt;iframe src="http://ads.geekswithblogs.net/a.aspx?ZoneID=5&amp;amp;Task=Get&amp;amp;PageID=31016&amp;amp;SiteID=1" width=1 height=1 Marginwidth=0 Marginheight=0 Hspace=0 Vspace=0 Frameborder=0 Scrolling=No&gt;
&lt;script language='javascript1.1' src="http://ads.geekswithblogs.net/a.aspx?ZoneID=5&amp;amp;Task=Get&amp;amp;Browser=NETSCAPE4&amp;amp;NoCache=True&amp;PageID=31016&amp;amp;SiteID=1"&gt;&lt;/script&gt;
&lt;noscript&gt;&lt;a href="http://ads.geekswithblogs.net/a.aspx?ZoneID=5&amp;amp;Task=Click&amp;amp;Mode=HTML&amp;amp;SiteID=1&amp;amp;PageID=31016" target="_blank"&gt;
&lt;img src="http://ads.geekswithblogs.net/a.aspx?ZoneID=5&amp;amp;Task=Get&amp;amp;Mode=HTML&amp;amp;SiteID=1&amp;amp;PageID=31016" width="1" height="1" border="0"  alt=""&gt;&lt;/a&gt;
&lt;/noscript&gt;
&lt;/iframe&gt;
&lt;img src="http://geekswithblogs.net/ssimakov/aggbug/94984.aspx" width="1" height="1" /&gt;</description>
            <dc:creator>Sergey Simakov</dc:creator>
            <guid isPermaLink="false">http://geekswithblogs.net/ssimakov/archive/2006/10/24/94984.aspx</guid>
            <pubDate>Wed, 25 Oct 2006 04:24:00 GMT</pubDate>
            <comments>http://geekswithblogs.net/ssimakov/archive/2006/10/24/94984.aspx#feedback</comments>
            <wfw:commentRss>http://geekswithblogs.net/ssimakov/comments/commentRss/94984.aspx</wfw:commentRss>
        <feedburner:origLink>http://geekswithblogs.net/ssimakov/archive/2006/10/24/94984.aspx</feedburner:origLink></item>
        <item>
            <title>BitLocker cryptographic algorithm</title>
            <category>Security</category>
            <link>http://feedproxy.google.com/~r/sergesim/~3/bdCb1UxzYbg/91460.aspx</link>
            <description>FYI - &lt;A href="http://en.wikipedia.org/wiki/Niels_Ferguson"&gt;Niels Ferguson&lt;/A&gt;&amp;nbsp;&lt;A href="http://blogs.msdn.com/si_team/archive/2006/09/15/756622.aspx"&gt;posted&lt;/A&gt;&amp;nbsp;a link&amp;nbsp;to&amp;nbsp;a document with&amp;nbsp;details&amp;nbsp;about &lt;A href="http://download.microsoft.com/download/0/2/3/0238acaf-d3bf-4a6d-b3d6-0a0be4bbb36e/BitLockerCipher200608.pdf"&gt;cryptographic algorithm that is used in BitLocker &lt;/A&gt;(AES-CBC with a specialized diffuser that improves the security against manipulation attacks)&amp;nbsp;at&amp;nbsp;&lt;A href="http://blogs.msdn.com/si_team"&gt;System Integrity team&lt;/A&gt; blog.&lt;p&gt;&lt;a href="http://www.pheedo.com/click.phdo?x=6cda6ad746d942b9a1110d0715a4fa12&amp;u=91460"&gt;&lt;img src="http://www.pheedo.com/img.phdo?x=6cda6ad746d942b9a1110d0715a4fa12&amp;u=91460" border="0"/&gt;&lt;/a&gt;&lt;/p&gt;&lt;iframe src="http://ads.geekswithblogs.net/a.aspx?ZoneID=5&amp;amp;Task=Get&amp;amp;PageID=31016&amp;amp;SiteID=1" width=1 height=1 Marginwidth=0 Marginheight=0 Hspace=0 Vspace=0 Frameborder=0 Scrolling=No&gt;
&lt;script language='javascript1.1' src="http://ads.geekswithblogs.net/a.aspx?ZoneID=5&amp;amp;Task=Get&amp;amp;Browser=NETSCAPE4&amp;amp;NoCache=True&amp;PageID=31016&amp;amp;SiteID=1"&gt;&lt;/script&gt;
&lt;noscript&gt;&lt;a href="http://ads.geekswithblogs.net/a.aspx?ZoneID=5&amp;amp;Task=Click&amp;amp;Mode=HTML&amp;amp;SiteID=1&amp;amp;PageID=31016" target="_blank"&gt;
&lt;img src="http://ads.geekswithblogs.net/a.aspx?ZoneID=5&amp;amp;Task=Get&amp;amp;Mode=HTML&amp;amp;SiteID=1&amp;amp;PageID=31016" width="1" height="1" border="0"  alt=""&gt;&lt;/a&gt;
&lt;/noscript&gt;
&lt;/iframe&gt;
&lt;img src="http://geekswithblogs.net/ssimakov/aggbug/91460.aspx" width="1" height="1" /&gt;</description>
            <dc:creator>Sergey Simakov</dc:creator>
            <guid isPermaLink="false">http://geekswithblogs.net/ssimakov/archive/2006/09/18/91460.aspx</guid>
            <pubDate>Mon, 18 Sep 2006 12:59:00 GMT</pubDate>
            <comments>http://geekswithblogs.net/ssimakov/archive/2006/09/18/91460.aspx#feedback</comments>
            <wfw:commentRss>http://geekswithblogs.net/ssimakov/comments/commentRss/91460.aspx</wfw:commentRss>
        <feedburner:origLink>http://geekswithblogs.net/ssimakov/archive/2006/09/18/91460.aspx</feedburner:origLink></item>
        <item>
            <title>Attack on RSA signature implementation</title>
            <category>Security</category>
            <link>http://feedproxy.google.com/~r/sergesim/~3/cOi-VOZY4dw/90664.aspx</link>
            <description>Good description of &lt;A href="http://www.bell-labs.com/user/bleichen/bib.html"&gt;Daniel Bleichenbacher&lt;/A&gt;'s attack on RSA signature implementations that may, under some common circumstances, break SSL/TLS in &lt;A href="http://www.matasano.com/log/469/many-rsa-signatures-may-be-forgeable-in-openssl-and-elsewhere/"&gt;Matasano blog&lt;/A&gt;.&lt;p&gt;&lt;a href="http://www.pheedo.com/click.phdo?x=6cda6ad746d942b9a1110d0715a4fa12&amp;u=90664"&gt;&lt;img src="http://www.pheedo.com/img.phdo?x=6cda6ad746d942b9a1110d0715a4fa12&amp;u=90664" border="0"/&gt;&lt;/a&gt;&lt;/p&gt;&lt;iframe src="http://ads.geekswithblogs.net/a.aspx?ZoneID=5&amp;amp;Task=Get&amp;amp;PageID=31016&amp;amp;SiteID=1" width=1 height=1 Marginwidth=0 Marginheight=0 Hspace=0 Vspace=0 Frameborder=0 Scrolling=No&gt;
&lt;script language='javascript1.1' src="http://ads.geekswithblogs.net/a.aspx?ZoneID=5&amp;amp;Task=Get&amp;amp;Browser=NETSCAPE4&amp;amp;NoCache=True&amp;PageID=31016&amp;amp;SiteID=1"&gt;&lt;/script&gt;
&lt;noscript&gt;&lt;a href="http://ads.geekswithblogs.net/a.aspx?ZoneID=5&amp;amp;Task=Click&amp;amp;Mode=HTML&amp;amp;SiteID=1&amp;amp;PageID=31016" target="_blank"&gt;
&lt;img src="http://ads.geekswithblogs.net/a.aspx?ZoneID=5&amp;amp;Task=Get&amp;amp;Mode=HTML&amp;amp;SiteID=1&amp;amp;PageID=31016" width="1" height="1" border="0"  alt=""&gt;&lt;/a&gt;
&lt;/noscript&gt;
&lt;/iframe&gt;
&lt;img src="http://geekswithblogs.net/ssimakov/aggbug/90664.aspx" width="1" height="1" /&gt;</description>
            <dc:creator>Sergey Simakov</dc:creator>
            <guid isPermaLink="false">http://geekswithblogs.net/ssimakov/archive/2006/09/08/90664.aspx</guid>
            <pubDate>Sat, 09 Sep 2006 02:03:00 GMT</pubDate>
            <comments>http://geekswithblogs.net/ssimakov/archive/2006/09/08/90664.aspx#feedback</comments>
            <wfw:commentRss>http://geekswithblogs.net/ssimakov/comments/commentRss/90664.aspx</wfw:commentRss>
        <feedburner:origLink>http://geekswithblogs.net/ssimakov/archive/2006/09/08/90664.aspx</feedburner:origLink></item>
        <item>
            <title>Joint architecture for NAP/NAC interoperability announcement</title>
            <category>Security</category>
            <link>http://feedproxy.google.com/~r/sergesim/~3/3_j4YsYIZNw/90477.aspx</link>
            <description>Joint architecture for Microsoft Network Access Protection (NAP) and Cisco Network Admission Control (NAC) interoperability is &lt;A href="http://blogs.msdn.com/windowsvistasecurity/archive/2006/09/06/742775.aspx"&gt;officially announced&lt;/A&gt; at &lt;A href="http://www.thesecuritystandard.net/"&gt;Security Standard&lt;/A&gt; conference in Boston. More information is available in &lt;A href="http://download.microsoft.com/download/d/0/8/d08df717-d752-4fa2-a77a-ab29f0b29266/NAC-NAP_Whitepaper.pdf"&gt;Cisco Network Admission Control and Microsoft Network Access Protection Interoperability Architecture&lt;/A&gt; whitepaper and &lt;A href="http://blogs.technet.com/nap/default.aspx"&gt;NAP team&lt;/A&gt; blog.&lt;p&gt;&lt;a href="http://www.pheedo.com/click.phdo?x=6cda6ad746d942b9a1110d0715a4fa12&amp;u=90477"&gt;&lt;img src="http://www.pheedo.com/img.phdo?x=6cda6ad746d942b9a1110d0715a4fa12&amp;u=90477" border="0"/&gt;&lt;/a&gt;&lt;/p&gt;&lt;iframe src="http://ads.geekswithblogs.net/a.aspx?ZoneID=5&amp;amp;Task=Get&amp;amp;PageID=31016&amp;amp;SiteID=1" width=1 height=1 Marginwidth=0 Marginheight=0 Hspace=0 Vspace=0 Frameborder=0 Scrolling=No&gt;
&lt;script language='javascript1.1' src="http://ads.geekswithblogs.net/a.aspx?ZoneID=5&amp;amp;Task=Get&amp;amp;Browser=NETSCAPE4&amp;amp;NoCache=True&amp;PageID=31016&amp;amp;SiteID=1"&gt;&lt;/script&gt;
&lt;noscript&gt;&lt;a href="http://ads.geekswithblogs.net/a.aspx?ZoneID=5&amp;amp;Task=Click&amp;amp;Mode=HTML&amp;amp;SiteID=1&amp;amp;PageID=31016" target="_blank"&gt;
&lt;img src="http://ads.geekswithblogs.net/a.aspx?ZoneID=5&amp;amp;Task=Get&amp;amp;Mode=HTML&amp;amp;SiteID=1&amp;amp;PageID=31016" width="1" height="1" border="0"  alt=""&gt;&lt;/a&gt;
&lt;/noscript&gt;
&lt;/iframe&gt;
&lt;img src="http://geekswithblogs.net/ssimakov/aggbug/90477.aspx" width="1" height="1" /&gt;</description>
            <dc:creator>Sergey Simakov</dc:creator>
            <guid isPermaLink="false">http://geekswithblogs.net/ssimakov/archive/2006/09/07/90477.aspx</guid>
            <pubDate>Thu, 07 Sep 2006 10:18:00 GMT</pubDate>
            <comments>http://geekswithblogs.net/ssimakov/archive/2006/09/07/90477.aspx#feedback</comments>
            <wfw:commentRss>http://geekswithblogs.net/ssimakov/comments/commentRss/90477.aspx</wfw:commentRss>
        <feedburner:origLink>http://geekswithblogs.net/ssimakov/archive/2006/09/07/90477.aspx</feedburner:origLink></item>
        <item>
            <title>Social engineering threats</title>
            <link>http://feedproxy.google.com/~r/sergesim/~3/DIti5zERnrE/89109.aspx</link>
            <description>&lt;p&gt;It's a known fact that one of the weakest links in current security systems&amp;nbsp;are people, and last week very interesting paper was released as part of Midsize Business Security Guidance - &lt;a href="http://www.microsoft.com/downloads/details.aspx?FamilyID=05033e55-aa96-4d49-8f57-c47664107938&amp;amp;DisplayLang=en"&gt;How to Protect Insiders from Social Engineering Threats&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;a href="http://www.pheedo.com/click.phdo?x=6cda6ad746d942b9a1110d0715a4fa12&amp;u=89109"&gt;&lt;img src="http://www.pheedo.com/img.phdo?x=6cda6ad746d942b9a1110d0715a4fa12&amp;u=89109" border="0"/&gt;&lt;/a&gt;&lt;/p&gt;&lt;iframe src="http://ads.geekswithblogs.net/a.aspx?ZoneID=5&amp;amp;Task=Get&amp;amp;PageID=31016&amp;amp;SiteID=1" width=1 height=1 Marginwidth=0 Marginheight=0 Hspace=0 Vspace=0 Frameborder=0 Scrolling=No&gt;
&lt;script language='javascript1.1' src="http://ads.geekswithblogs.net/a.aspx?ZoneID=5&amp;amp;Task=Get&amp;amp;Browser=NETSCAPE4&amp;amp;NoCache=True&amp;PageID=31016&amp;amp;SiteID=1"&gt;&lt;/script&gt;
&lt;noscript&gt;&lt;a href="http://ads.geekswithblogs.net/a.aspx?ZoneID=5&amp;amp;Task=Click&amp;amp;Mode=HTML&amp;amp;SiteID=1&amp;amp;PageID=31016" target="_blank"&gt;
&lt;img src="http://ads.geekswithblogs.net/a.aspx?ZoneID=5&amp;amp;Task=Get&amp;amp;Mode=HTML&amp;amp;SiteID=1&amp;amp;PageID=31016" width="1" height="1" border="0"  alt=""&gt;&lt;/a&gt;
&lt;/noscript&gt;
&lt;/iframe&gt;
&lt;img src="http://geekswithblogs.net/ssimakov/aggbug/89109.aspx" width="1" height="1" /&gt;</description>
            <dc:creator>Sergey Simakov</dc:creator>
            <guid isPermaLink="false">http://geekswithblogs.net/ssimakov/archive/2006/08/24/89109.aspx</guid>
            <pubDate>Thu, 24 Aug 2006 21:19:00 GMT</pubDate>
            <comments>http://geekswithblogs.net/ssimakov/archive/2006/08/24/89109.aspx#feedback</comments>
            <wfw:commentRss>http://geekswithblogs.net/ssimakov/comments/commentRss/89109.aspx</wfw:commentRss>
        <feedburner:origLink>http://geekswithblogs.net/ssimakov/archive/2006/08/24/89109.aspx</feedburner:origLink></item>
        <item>
            <title>Interesting blog</title>
            <category>Security</category>
            <link>http://feedproxy.google.com/~r/sergesim/~3/o5Lq2mqJO7Y/88289.aspx</link>
            <description>&lt;p&gt;I've missed the fact that &lt;a href="http://blogs.msdn.com/kevinlam"&gt;Kevin Lam&lt;/a&gt; from &lt;a href="http://blogs.msdn.com/ace_team"&gt;ACE&lt;/a&gt; (Application&amp;nbsp;Consulting &amp;amp; Engineering)&amp;nbsp;Team (author of very interesting &lt;a href="http://www.amazon.com/gp/product/0735620334/"&gt;Accessing Network Security&lt;/a&gt; book about penetration testing) is now blogging&amp;nbsp;- &lt;a href="http://blogs.msdn.com/kevinlam/rss.xml"&gt;subscribed&lt;/a&gt;.&lt;/p&gt;&lt;p&gt;&lt;a href="http://www.pheedo.com/click.phdo?x=6cda6ad746d942b9a1110d0715a4fa12&amp;u=88289"&gt;&lt;img src="http://www.pheedo.com/img.phdo?x=6cda6ad746d942b9a1110d0715a4fa12&amp;u=88289" border="0"/&gt;&lt;/a&gt;&lt;/p&gt;&lt;iframe src="http://ads.geekswithblogs.net/a.aspx?ZoneID=5&amp;amp;Task=Get&amp;amp;PageID=31016&amp;amp;SiteID=1" width=1 height=1 Marginwidth=0 Marginheight=0 Hspace=0 Vspace=0 Frameborder=0 Scrolling=No&gt;
&lt;script language='javascript1.1' src="http://ads.geekswithblogs.net/a.aspx?ZoneID=5&amp;amp;Task=Get&amp;amp;Browser=NETSCAPE4&amp;amp;NoCache=True&amp;PageID=31016&amp;amp;SiteID=1"&gt;&lt;/script&gt;
&lt;noscript&gt;&lt;a href="http://ads.geekswithblogs.net/a.aspx?ZoneID=5&amp;amp;Task=Click&amp;amp;Mode=HTML&amp;amp;SiteID=1&amp;amp;PageID=31016" target="_blank"&gt;
&lt;img src="http://ads.geekswithblogs.net/a.aspx?ZoneID=5&amp;amp;Task=Get&amp;amp;Mode=HTML&amp;amp;SiteID=1&amp;amp;PageID=31016" width="1" height="1" border="0"  alt=""&gt;&lt;/a&gt;
&lt;/noscript&gt;
&lt;/iframe&gt;
&lt;img src="http://geekswithblogs.net/ssimakov/aggbug/88289.aspx" width="1" height="1" /&gt;</description>
            <dc:creator>Sergey Simakov</dc:creator>
            <guid isPermaLink="false">http://geekswithblogs.net/ssimakov/archive/2006/08/17/88289.aspx</guid>
            <pubDate>Fri, 18 Aug 2006 00:22:00 GMT</pubDate>
            <comments>http://geekswithblogs.net/ssimakov/archive/2006/08/17/88289.aspx#feedback</comments>
            <wfw:commentRss>http://geekswithblogs.net/ssimakov/comments/commentRss/88289.aspx</wfw:commentRss>
        <feedburner:origLink>http://geekswithblogs.net/ssimakov/archive/2006/08/17/88289.aspx</feedburner:origLink></item>
        <item>
            <title>Microsoft acquires Sysinternals and Wininternals</title>
            <category>Development</category>
            <link>http://feedproxy.google.com/~r/sergesim/~3/9hfm1yuzv94/85552.aspx</link>
            <description>&lt;P&gt;According to Mark's &lt;A href="http://www.sysinternals.com/blog/2006/07/on-my-way-to-microsoft.html"&gt;blog post&lt;/A&gt;&amp;nbsp;-&amp;nbsp;Microsoft &lt;A href="http://www.winternals.com/Company/PressRelease92.aspx"&gt;has acquired Wininternals&lt;/A&gt; and Sysinternals: developers of&amp;nbsp;great&amp;nbsp;troubleshooting and management tools such as Recovery Manager, Protection Manager and ERD Commander (part of Administrator Pack), free &lt;A href="http://www.sysinternals.com/Utilities/Autologon.html"&gt;Autoruns&lt;/A&gt;/Process Explorer/&lt;A href="http://www.sysinternals.com/Utilities/RootkitRevealer.html"&gt;Rootkit Revealer&lt;/A&gt;, and many others that are included in my must-have utilities&amp;nbsp;list.&lt;/P&gt;
&lt;P&gt;Congratulations to Mark and Bruce!&lt;/P&gt;&lt;p&gt;&lt;a href="http://www.pheedo.com/click.phdo?x=6cda6ad746d942b9a1110d0715a4fa12&amp;u=85552"&gt;&lt;img src="http://www.pheedo.com/img.phdo?x=6cda6ad746d942b9a1110d0715a4fa12&amp;u=85552" border="0"/&gt;&lt;/a&gt;&lt;/p&gt;&lt;iframe src="http://ads.geekswithblogs.net/a.aspx?ZoneID=5&amp;amp;Task=Get&amp;amp;PageID=31016&amp;amp;SiteID=1" width=1 height=1 Marginwidth=0 Marginheight=0 Hspace=0 Vspace=0 Frameborder=0 Scrolling=No&gt;
&lt;script language='javascript1.1' src="http://ads.geekswithblogs.net/a.aspx?ZoneID=5&amp;amp;Task=Get&amp;amp;Browser=NETSCAPE4&amp;amp;NoCache=True&amp;PageID=31016&amp;amp;SiteID=1"&gt;&lt;/script&gt;
&lt;noscript&gt;&lt;a href="http://ads.geekswithblogs.net/a.aspx?ZoneID=5&amp;amp;Task=Click&amp;amp;Mode=HTML&amp;amp;SiteID=1&amp;amp;PageID=31016" target="_blank"&gt;
&lt;img src="http://ads.geekswithblogs.net/a.aspx?ZoneID=5&amp;amp;Task=Get&amp;amp;Mode=HTML&amp;amp;SiteID=1&amp;amp;PageID=31016" width="1" height="1" border="0"  alt=""&gt;&lt;/a&gt;
&lt;/noscript&gt;
&lt;/iframe&gt;
&lt;img src="http://geekswithblogs.net/ssimakov/aggbug/85552.aspx" width="1" height="1" /&gt;</description>
            <dc:creator>Sergey Simakov</dc:creator>
            <guid isPermaLink="false">http://geekswithblogs.net/ssimakov/archive/2006/07/18/85552.aspx</guid>
            <pubDate>Tue, 18 Jul 2006 22:44:00 GMT</pubDate>
            <comments>http://geekswithblogs.net/ssimakov/archive/2006/07/18/85552.aspx#feedback</comments>
            <wfw:commentRss>http://geekswithblogs.net/ssimakov/comments/commentRss/85552.aspx</wfw:commentRss>
        <feedburner:origLink>http://geekswithblogs.net/ssimakov/archive/2006/07/18/85552.aspx</feedburner:origLink></item>
        <item>
            <title>Crypto classes</title>
            <category>Development</category>
            <category>Security</category>
            <link>http://feedproxy.google.com/~r/sergesim/~3/jpwHLOR6ZKU/79344.aspx</link>
            <description>&lt;P&gt;Michael Howard &lt;A href="http://blogs.msdn.com/michael_howard/archive/2006/05/22/604076.aspx"&gt;posted&lt;/A&gt; a link to the &lt;A href="http://www.cs.washington.edu/education/courses/csep590/06wi/lectures/"&gt;lecture materials&lt;/A&gt; from University of Washington's cryptography class.&lt;/P&gt;
&lt;P&gt;And you should pay attention to the lecturers list:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Brian LaMacchia (ex-security architect for the .NET Framework and Common Language Runtime)&lt;/LI&gt;
&lt;LI&gt;Josh Benaloh (senior cryptographer in Microsoft Research)&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;John Manferdelli (Distinguished Engineer, worked on the TPM stuff at Microsoft.)&lt;/LI&gt;&lt;/UL&gt;
&lt;P&gt;BTW, does anyone mentions that v1.1 of KMDF was &lt;A href="http://www.microsoft.com/whdc/driver/wdf/KMDF_pkg.mspx"&gt;released&lt;/A&gt;? It supports Windows 2000 now, so driver developers&amp;nbsp;position&amp;nbsp;helped =)&amp;nbsp;&lt;/P&gt;&lt;p&gt;&lt;a href="http://www.pheedo.com/click.phdo?x=6cda6ad746d942b9a1110d0715a4fa12&amp;u=79344"&gt;&lt;img src="http://www.pheedo.com/img.phdo?x=6cda6ad746d942b9a1110d0715a4fa12&amp;u=79344" border="0"/&gt;&lt;/a&gt;&lt;/p&gt;&lt;iframe src="http://ads.geekswithblogs.net/a.aspx?ZoneID=5&amp;amp;Task=Get&amp;amp;PageID=31016&amp;amp;SiteID=1" width=1 height=1 Marginwidth=0 Marginheight=0 Hspace=0 Vspace=0 Frameborder=0 Scrolling=No&gt;
&lt;script language='javascript1.1' src="http://ads.geekswithblogs.net/a.aspx?ZoneID=5&amp;amp;Task=Get&amp;amp;Browser=NETSCAPE4&amp;amp;NoCache=True&amp;PageID=31016&amp;amp;SiteID=1"&gt;&lt;/script&gt;
&lt;noscript&gt;&lt;a href="http://ads.geekswithblogs.net/a.aspx?ZoneID=5&amp;amp;Task=Click&amp;amp;Mode=HTML&amp;amp;SiteID=1&amp;amp;PageID=31016" target="_blank"&gt;
&lt;img src="http://ads.geekswithblogs.net/a.aspx?ZoneID=5&amp;amp;Task=Get&amp;amp;Mode=HTML&amp;amp;SiteID=1&amp;amp;PageID=31016" width="1" height="1" border="0"  alt=""&gt;&lt;/a&gt;
&lt;/noscript&gt;
&lt;/iframe&gt;
&lt;img src="http://geekswithblogs.net/ssimakov/aggbug/79344.aspx" width="1" height="1" /&gt;</description>
            <dc:creator>Sergey Simakov</dc:creator>
            <guid isPermaLink="false">http://geekswithblogs.net/ssimakov/archive/2006/05/23/79344.aspx</guid>
            <pubDate>Tue, 23 May 2006 23:41:00 GMT</pubDate>
            <comments>http://geekswithblogs.net/ssimakov/archive/2006/05/23/79344.aspx#feedback</comments>
            <wfw:commentRss>http://geekswithblogs.net/ssimakov/comments/commentRss/79344.aspx</wfw:commentRss>
        <feedburner:origLink>http://geekswithblogs.net/ssimakov/archive/2006/05/23/79344.aspx</feedburner:origLink></item>
        <item>
            <title>Red pill</title>
            <category>Personal</category>
            <link>http://feedproxy.google.com/~r/sergesim/~3/BLguS7xteWc/73396.aspx</link>
            <description>&lt;P&gt;Well, it's time to announce some changes in my professional life:&lt;/P&gt;
&lt;BLOCKQUOTE dir=ltr style="MARGIN-RIGHT: 0px"&gt;
&lt;P&gt;&lt;EM&gt;Ch-ch-Changes&lt;BR&gt;Just gonna have to be a different man&lt;BR&gt;Time may change me&lt;BR&gt;But I can't trace time [by &lt;/EM&gt;&lt;A href="http://www.amazon.com/gp/product/B00006JYI7"&gt;&lt;EM&gt;David Bowie&lt;/EM&gt;&lt;/A&gt;&lt;EM&gt;]&lt;/EM&gt;&lt;/P&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;So, I've taken a red pill (it's just our way of saying "we've taken a job at Microsoft." ;-) and now&amp;nbsp;I'm working with great people in &lt;A href="http://www.microsoft.com/rus/business/Services/Consulting/Default.mspx"&gt;Microsoft Consulting Services Russia&lt;/A&gt; team and I'm very excited about new opportunities.&lt;/P&gt;&lt;p&gt;&lt;a href="http://www.pheedo.com/click.phdo?x=6cda6ad746d942b9a1110d0715a4fa12&amp;u=73396"&gt;&lt;img src="http://www.pheedo.com/img.phdo?x=6cda6ad746d942b9a1110d0715a4fa12&amp;u=73396" border="0"/&gt;&lt;/a&gt;&lt;/p&gt;&lt;iframe src="http://ads.geekswithblogs.net/a.aspx?ZoneID=5&amp;amp;Task=Get&amp;amp;PageID=31016&amp;amp;SiteID=1" width=1 height=1 Marginwidth=0 Marginheight=0 Hspace=0 Vspace=0 Frameborder=0 Scrolling=No&gt;
&lt;script language='javascript1.1' src="http://ads.geekswithblogs.net/a.aspx?ZoneID=5&amp;amp;Task=Get&amp;amp;Browser=NETSCAPE4&amp;amp;NoCache=True&amp;PageID=31016&amp;amp;SiteID=1"&gt;&lt;/script&gt;
&lt;noscript&gt;&lt;a href="http://ads.geekswithblogs.net/a.aspx?ZoneID=5&amp;amp;Task=Click&amp;amp;Mode=HTML&amp;amp;SiteID=1&amp;amp;PageID=31016" target="_blank"&gt;
&lt;img src="http://ads.geekswithblogs.net/a.aspx?ZoneID=5&amp;amp;Task=Get&amp;amp;Mode=HTML&amp;amp;SiteID=1&amp;amp;PageID=31016" width="1" height="1" border="0"  alt=""&gt;&lt;/a&gt;
&lt;/noscript&gt;
&lt;/iframe&gt;
&lt;img src="http://geekswithblogs.net/ssimakov/aggbug/73396.aspx" width="1" height="1" /&gt;</description>
            <dc:creator>Sergey Simakov</dc:creator>
            <guid isPermaLink="false">http://geekswithblogs.net/ssimakov/archive/2006/03/26/73396.aspx</guid>
            <pubDate>Mon, 27 Mar 2006 02:16:00 GMT</pubDate>
            <comments>http://geekswithblogs.net/ssimakov/archive/2006/03/26/73396.aspx#feedback</comments>
            <slash:comments>2</slash:comments>
            <wfw:commentRss>http://geekswithblogs.net/ssimakov/comments/commentRss/73396.aspx</wfw:commentRss>
        <feedburner:origLink>http://geekswithblogs.net/ssimakov/archive/2006/03/26/73396.aspx</feedburner:origLink></item>
        <item>
            <title>Identity management seminar in Moscow</title>
            <category>Security</category>
            <link>http://feedproxy.google.com/~r/sergesim/~3/4wsgNYRPwtM/73394.aspx</link>
            <description>&lt;P&gt;Last month Rafal Lukawiecki (&lt;A href="http://www.projectbotticelli.co.uk/"&gt;Project Botticelli&lt;/A&gt; Ltd) made a very good presentation about 'Identification and access management in heterogeneous enterprise networks' in Moscow Microsoft office (program in russian is available &lt;A href="http://www.microsoft.com/rus/Events/RafalSecurityTour/Default.mspx"&gt;here&lt;/A&gt;).&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Overview and comparison of Microsoft&amp;nbsp;identity management&amp;nbsp;technologies (MIIS, ADFS) was the&amp;nbsp;most interesting part of this presentation (especially assuming that&amp;nbsp;&lt;A href="http://www.microsoft.com/presspass/features/2006/feb06/02-14InfoCards.mspx"&gt;InfoCard&lt;/A&gt; and other plans for future developments in this area from Microsoft&amp;nbsp;was announced at &lt;A href="https://2006.rsaconference.com/us/conference/webcasts.aspx"&gt;RSA conference&lt;/A&gt; at the same day). &lt;/P&gt;
&lt;P&gt;Unfortunately presentation is not available for download right now, but I think it'll be available for download from TechNet &lt;A href="http://www.microsoft.com/emea/itsshowtime/result_search.aspx?speaker=16&amp;amp;x=24&amp;amp;y=10"&gt;IT's Showtime&lt;/A&gt; section.&lt;/P&gt;&lt;p&gt;&lt;a href="http://www.pheedo.com/click.phdo?x=6cda6ad746d942b9a1110d0715a4fa12&amp;u=73394"&gt;&lt;img src="http://www.pheedo.com/img.phdo?x=6cda6ad746d942b9a1110d0715a4fa12&amp;u=73394" border="0"/&gt;&lt;/a&gt;&lt;/p&gt;&lt;iframe src="http://ads.geekswithblogs.net/a.aspx?ZoneID=5&amp;amp;Task=Get&amp;amp;PageID=31016&amp;amp;SiteID=1" width=1 height=1 Marginwidth=0 Marginheight=0 Hspace=0 Vspace=0 Frameborder=0 Scrolling=No&gt;
&lt;script language='javascript1.1' src="http://ads.geekswithblogs.net/a.aspx?ZoneID=5&amp;amp;Task=Get&amp;amp;Browser=NETSCAPE4&amp;amp;NoCache=True&amp;PageID=31016&amp;amp;SiteID=1"&gt;&lt;/script&gt;
&lt;noscript&gt;&lt;a href="http://ads.geekswithblogs.net/a.aspx?ZoneID=5&amp;amp;Task=Click&amp;amp;Mode=HTML&amp;amp;SiteID=1&amp;amp;PageID=31016" target="_blank"&gt;
&lt;img src="http://ads.geekswithblogs.net/a.aspx?ZoneID=5&amp;amp;Task=Get&amp;amp;Mode=HTML&amp;amp;SiteID=1&amp;amp;PageID=31016" width="1" height="1" border="0"  alt=""&gt;&lt;/a&gt;
&lt;/noscript&gt;
&lt;/iframe&gt;
&lt;img src="http://geekswithblogs.net/ssimakov/aggbug/73394.aspx" width="1" height="1" /&gt;</description>
            <dc:creator>Sergey Simakov</dc:creator>
            <guid isPermaLink="false">http://geekswithblogs.net/ssimakov/archive/2006/03/26/73394.aspx</guid>
            <pubDate>Mon, 27 Mar 2006 01:29:00 GMT</pubDate>
            <comments>http://geekswithblogs.net/ssimakov/archive/2006/03/26/73394.aspx#feedback</comments>
            <wfw:commentRss>http://geekswithblogs.net/ssimakov/comments/commentRss/73394.aspx</wfw:commentRss>
        <feedburner:origLink>http://geekswithblogs.net/ssimakov/archive/2006/03/26/73394.aspx</feedburner:origLink></item>
        <item>
            <title>Two approaches to check functions parameters</title>
            <category>Personal</category>
            <category>Development</category>
            <link>http://feedproxy.google.com/~r/sergesim/~3/7WipL1lcks8/5066.aspx</link>
            <description>&lt;P&gt;Larry Osterman posted interesting discussion about checking parameters in components - &lt;A href="http://blogs.msdn.com/larryosterman/archive/2004/05/18/134471.aspx"&gt;Should I check the parameters to my function?&lt;/A&gt;. Currently I'm using school one approach (always check incoming data with IsBadXXXPtr), but:&lt;/P&gt;
&lt;BLOCKQUOTE dir=ltr style="MARGIN-RIGHT: 0px"&gt;
&lt;P&gt;&lt;FONT face="Trebuchet MS" size=2&gt;The way you check for bad pointers on Win32 is by calling the &lt;/FONT&gt;&lt;A href="http://msdn.microsoft.com/library/default.asp?url=/library/en-us/memory/base/isbadreadptr.asp"&gt;&lt;FONT face="Trebuchet MS" color=#355ea0 size=2&gt;IsBadReadPtr&lt;/FONT&gt;&lt;/A&gt;&lt;FONT face="Trebuchet MS" size=2&gt; and &lt;/FONT&gt;&lt;A href="http://msdn.microsoft.com/library/default.asp?url=/library/en-us/memory/base/isbadreadptr.asp"&gt;&lt;FONT face="Trebuchet MS" color=#355ea0 size=2&gt;IsBadWritePtr&lt;/FONT&gt;&lt;/A&gt;&lt;FONT face="Trebuchet MS" size=2&gt; API.  &lt;/FONT&gt;&lt;A href="http://weblogs.asp.net/michael_howard"&gt;&lt;FONT face="Trebuchet MS" color=#355ea0 size=2&gt;Michael Howard&lt;/FONT&gt;&lt;/A&gt;&lt;FONT face="Trebuchet MS" size=2&gt; calls these APIs &amp;#8220;CrashMyApplication&amp;#8221; and &amp;#8220;CorruptMemoryAndCrashMySystem&amp;#8221; respectively.  The problem with IsBadReadPtr/IsBadWritePtr is that they do exactly what they&amp;#8217;re advertised as doing:  They read and/or write to the memory location specified, with an exception handler wrapped around the read/write.  If an exception is thrown, they fail, if not, they succeed.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Trebuchet MS'"&gt;There are two problems with this.  The only thing that IsBadReadPtr/IsBadWritePtr verifies is that at the instant that the API is called, there was valid memory at that location.  There&amp;#8217;s nothing to prevent another thread in the application from unmapping the virtual address passed into IsBadReadPtr immediately after the call is made.  Which means that any error checks you made based on the results of this API aren&amp;#8217;t valid (this is called out in the documentation for IsBadWritePtr/IsBadReadPtr).&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Trebuchet MS'"&gt;The other one is worse.  What happens if the memory address passed into IsBadReadPtr is a stack guard page (a guard page is a page kept at the bottom of the stack &amp;#8211; when the system top level exception handler sees a fault on a guard page, it will grow the threads stack (up to the threads stack limit))?  Well, the IsBadReadPtr will catch the guard page exception and will handle it (because IsBadReadPtr handles all exceptions).  So the system exception handler doesn&amp;#8217;t see the exception.  Which means that when that thread later runs, its stack won&amp;#8217;t grow past the current limit.  By calling IsBadReadPtr in your API, you&amp;#8217;ve turned an easily identifiable application bug into a really subtle stack overflow bug that may not be encountered for many minutes (or hours) later. [via &lt;FONT face="Times New Roman" size=3&gt;&lt;A href="http://blogs.msdn.com/larryosterman/archive/2004/05/18/134471.aspx"&gt;Larry Osterman&lt;/A&gt;]&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BLOCKQUOTE&gt;
&lt;P dir=ltr&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Trebuchet MS'"&gt;&lt;FONT face="Times New Roman" size=3&gt;Hmm, it seems that I need to move IsBadXXXPtr only to debug asserts in my projects.&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;p&gt;&lt;a href="http://www.pheedo.com/click.phdo?x=6cda6ad746d942b9a1110d0715a4fa12&amp;u=5066"&gt;&lt;img src="http://www.pheedo.com/img.phdo?x=6cda6ad746d942b9a1110d0715a4fa12&amp;u=5066" border="0"/&gt;&lt;/a&gt;&lt;/p&gt;&lt;iframe src="http://ads.geekswithblogs.net/a.aspx?ZoneID=5&amp;amp;Task=Get&amp;amp;PageID=31016&amp;amp;SiteID=1" width=1 height=1 Marginwidth=0 Marginheight=0 Hspace=0 Vspace=0 Frameborder=0 Scrolling=No&gt;
&lt;script language='javascript1.1' src="http://ads.geekswithblogs.net/a.aspx?ZoneID=5&amp;amp;Task=Get&amp;amp;Browser=NETSCAPE4&amp;amp;NoCache=True&amp;PageID=31016&amp;amp;SiteID=1"&gt;&lt;/script&gt;
&lt;noscript&gt;&lt;a href="http://ads.geekswithblogs.net/a.aspx?ZoneID=5&amp;amp;Task=Click&amp;amp;Mode=HTML&amp;amp;SiteID=1&amp;amp;PageID=31016" target="_blank"&gt;
&lt;img src="http://ads.geekswithblogs.net/a.aspx?ZoneID=5&amp;amp;Task=Get&amp;amp;Mode=HTML&amp;amp;SiteID=1&amp;amp;PageID=31016" width="1" height="1" border="0"  alt=""&gt;&lt;/a&gt;
&lt;/noscript&gt;
&lt;/iframe&gt;
&lt;img src="http://geekswithblogs.net/ssimakov/aggbug/5066.aspx" width="1" height="1" /&gt;</description>
            <dc:creator>Sergey Simakov</dc:creator>
            <guid isPermaLink="false">http://geekswithblogs.net/ssimakov/archive/2004/05/19/5066.aspx</guid>
            <pubDate>Wed, 19 May 2004 11:56:00 GMT</pubDate>
            <comments>http://geekswithblogs.net/ssimakov/archive/2004/05/19/5066.aspx#feedback</comments>
            <slash:comments>2</slash:comments>
            <wfw:commentRss>http://geekswithblogs.net/ssimakov/comments/commentRss/5066.aspx</wfw:commentRss>
        <feedburner:origLink>http://geekswithblogs.net/ssimakov/archive/2004/05/19/5066.aspx</feedburner:origLink></item>
        <item>
            <title>New Year in Sri Lanka</title>
            <category>Personal</category>
            <link>http://feedproxy.google.com/~r/sergesim/~3/yf3aMygeS7o/70970.aspx</link>
            <description>&lt;P&gt;Better late than never.&lt;/P&gt;
&lt;P&gt;I spent this New Year and russian Orhodox Christmas&amp;nbsp;at beautiful Sri Lanka (Ceylon) island. Some photos from this travel are &lt;A href="http://www.flickr.com/photos/sergesim/tags/srilanka/"&gt;posted&lt;/A&gt;&amp;nbsp;on my &lt;A href="http://www.flickr.com/photos/sergesim/tags/srilanka/"&gt;Flickr account&lt;/A&gt;.&amp;nbsp;Weather was really great (but unsually rainy for this time of year on the south-west side of island) -&amp;nbsp;especially if&amp;nbsp;you&amp;nbsp;compare it with Moscow weather in January (60 degrees difference ;-).&lt;/P&gt;
&lt;P&gt;This time we visit nearly every part of this wonderful country - from &lt;A href="http://www.flickr.com/photos/sergesim/tags/nuwareeliya/"&gt;Nuware Eliya&lt;/A&gt; to ex-capital&amp;nbsp;&lt;A href="http://www.flickr.com/photos/sergesim/tags/kandi/"&gt;Kandy&lt;/A&gt;, to Dambula, to&amp;nbsp;the &lt;A href="http://en.wikipedia.org/wiki/Sigiriya"&gt;8th&amp;nbsp;wonder&lt;/A&gt; of the World in &lt;A href="http://www.flickr.com/photos/sergesim/tags/sigiriya/"&gt;Sigiriya&lt;/A&gt;&amp;nbsp;(btw the famous &lt;A href="http://www.imdb.com/title/tt0050212/"&gt;The Bridge on The River Kwai&lt;/A&gt; that &lt;A href="http://sundaybytes.com/travel/thailand2006/kanchanaburi/"&gt;Anton Antich&lt;/A&gt; visited this year is actually was filmed&amp;nbsp;at &lt;A href="http://www.flickr.com/photos/sergesim/105934528/"&gt;this place&lt;/A&gt; ;-).&lt;/P&gt;
&lt;P align=center&gt;&lt;IMG src="http://static.flickr.com/50/105929438_647789ab0a_m.jpg"&gt;&lt;/P&gt;
&lt;P&gt;But the real&amp;nbsp;motive for this post is the difference that&amp;nbsp;free education and medical help have&amp;nbsp;for ordinary people. May be you didn't know, but &lt;A href="http://en.wikipedia.org/wiki/Sri_lanka"&gt;Sri Lanka&lt;/A&gt; is Democratic &lt;EM&gt;Socialist&lt;/EM&gt; Republic and for this matter they have free of charge education (inc. &amp;nbsp;and medical help for all people. And it works&amp;nbsp;- I'm comparing impressions&amp;nbsp;with our travel to &lt;A href="http://en.wikipedia.org/wiki/Goa"&gt;Goa&lt;/A&gt; (the richest state in India after all) and from &lt;EM&gt;my&lt;/EM&gt; point of view ordinary people are much happier, there're no such obvious diversity and economic growth&amp;nbsp;is visible. And even after&amp;nbsp;terrible &lt;A href="http://tsunamihelp.blogspot.com/"&gt;tsunami&lt;/A&gt; that happened last year (down &lt;A href="http://www.flickr.com/photos/sergesim/105931317/"&gt;this railroad&lt;/A&gt;)&amp;nbsp;they didn't give up and&amp;nbsp;are building their small&amp;nbsp;businesses - and I wish them good luck.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;p&gt;&lt;a href="http://www.pheedo.com/click.phdo?x=6cda6ad746d942b9a1110d0715a4fa12&amp;u=70970"&gt;&lt;img src="http://www.pheedo.com/img.phdo?x=6cda6ad746d942b9a1110d0715a4fa12&amp;u=70970" border="0"/&gt;&lt;/a&gt;&lt;/p&gt;&lt;iframe src="http://ads.geekswithblogs.net/a.aspx?ZoneID=5&amp;amp;Task=Get&amp;amp;PageID=31016&amp;amp;SiteID=1" width=1 height=1 Marginwidth=0 Marginheight=0 Hspace=0 Vspace=0 Frameborder=0 Scrolling=No&gt;
&lt;script language='javascript1.1' src="http://ads.geekswithblogs.net/a.aspx?ZoneID=5&amp;amp;Task=Get&amp;amp;Browser=NETSCAPE4&amp;amp;NoCache=True&amp;PageID=31016&amp;amp;SiteID=1"&gt;&lt;/script&gt;
&lt;noscript&gt;&lt;a href="http://ads.geekswithblogs.net/a.aspx?ZoneID=5&amp;amp;Task=Click&amp;amp;Mode=HTML&amp;amp;SiteID=1&amp;amp;PageID=31016" target="_blank"&gt;
&lt;img src="http://ads.geekswithblogs.net/a.aspx?ZoneID=5&amp;amp;Task=Get&amp;amp;Mode=HTML&amp;amp;SiteID=1&amp;amp;PageID=31016" width="1" height="1" border="0"  alt=""&gt;&lt;/a&gt;
&lt;/noscript&gt;
&lt;/iframe&gt;
&lt;img src="http://geekswithblogs.net/ssimakov/aggbug/70970.aspx" width="1" height="1" /&gt;</description>
            <dc:creator>Sergey Simakov</dc:creator>
            <guid isPermaLink="false">http://geekswithblogs.net/ssimakov/archive/2006/02/28/70970.aspx</guid>
            <pubDate>Wed, 01 Mar 2006 02:37:00 GMT</pubDate>
            <comments>http://geekswithblogs.net/ssimakov/archive/2006/02/28/70970.aspx#feedback</comments>
            <slash:comments>1</slash:comments>
            <wfw:commentRss>http://geekswithblogs.net/ssimakov/comments/commentRss/70970.aspx</wfw:commentRss>
        <feedburner:origLink>http://geekswithblogs.net/ssimakov/archive/2006/02/28/70970.aspx</feedburner:origLink></item>
        <item>
            <title>SmartCard Base CSP and Windows PKI resources</title>
            <category>Security</category>
            <link>http://feedproxy.google.com/~r/sergesim/~3/tVkdj1BXTNI/63145.aspx</link>
            <description>&lt;P&gt;Yeap, I knew that I forget someting - &lt;/P&gt;
&lt;P&gt;David Cross &lt;A href="http://groups.google.com/group/microsoft.public.security.crypto/browse_thread/thread/c44cdaaf9966003b/"&gt;announced on public.security.crypto newsgroup&lt;/A&gt; release of the Smart Card Base Cryptographic Service Provider as &lt;A href="http://www.microsoft.com/downloads/details.aspx?FamilyID=e8095fd5-c7e5-4bee-9577-2ea6b45b41c6&amp;amp;DisplayLang=en"&gt;free download&lt;/A&gt; (also available via&amp;nbsp;Windows Update):&lt;/P&gt;
&lt;BLOCKQUOTE dir=ltr style="MARGIN-RIGHT: 0px"&gt;
&lt;P&gt;&lt;EM&gt;Writing a Smart Card CSP has not been trivial.&amp;nbsp; This has been addressed by splitting the CSP architecture to a Base CSP and Card Module architecture. The Base CSP is provided by Microsoft as a part of the platform (with this &lt;BR&gt;Base CSP release).&amp;nbsp;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Card Module is a interface supported by Microsoft for card vendors to write their implementations for the same to their card. This is analogous to writing a printer driver for a printer.&lt;BR&gt;It is this new Card Module architecture that will also be available as a&amp;nbsp;part of Windows Vista.&amp;nbsp; With this release, one of the goals that we want to accomplish is that the same card module works on older platforms and also Vista.&lt;/EM&gt;&lt;/P&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;More information available in &lt;A href="http://blogs.msdn.com/shivaram/archive/2005/11/30/498134.aspx"&gt;Shivaram Mysore blog&lt;/A&gt; (he is &lt;A href="http://www.geocities.com/shivarammysore/"&gt;active participant&lt;/A&gt; of XML Encryption and XKMS and ex-Sun software architect). &lt;/P&gt;
&lt;P&gt;There are also &lt;STRONG&gt;great&lt;/STRONG&gt; collection of Windows PKI and cryptography &lt;A href="http://blogs.msdn.com/shivaram/archive/2005/08/15/References_and_Links.aspx"&gt;references and links&lt;/A&gt;&amp;nbsp;[&lt;A href="http://blogs.msdn.com/shivaram/rss.aspx"&gt;subscribed&lt;/A&gt;].&lt;/P&gt;&lt;p&gt;&lt;a href="http://www.pheedo.com/click.phdo?x=6cda6ad746d942b9a1110d0715a4fa12&amp;u=63145"&gt;&lt;img src="http://www.pheedo.com/img.phdo?x=6cda6ad746d942b9a1110d0715a4fa12&amp;u=63145" border="0"/&gt;&lt;/a&gt;&lt;/p&gt;&lt;iframe src="http://ads.geekswithblogs.net/a.aspx?ZoneID=5&amp;amp;Task=Get&amp;amp;PageID=31016&amp;amp;SiteID=1" width=1 height=1 Marginwidth=0 Marginheight=0 Hspace=0 Vspace=0 Frameborder=0 Scrolling=No&gt;
&lt;script language='javascript1.1' src="http://ads.geekswithblogs.net/a.aspx?ZoneID=5&amp;amp;Task=Get&amp;amp;Browser=NETSCAPE4&amp;amp;NoCache=True&amp;PageID=31016&amp;amp;SiteID=1"&gt;&lt;/script&gt;
&lt;noscript&gt;&lt;a href="http://ads.geekswithblogs.net/a.aspx?ZoneID=5&amp;amp;Task=Click&amp;amp;Mode=HTML&amp;amp;SiteID=1&amp;amp;PageID=31016" target="_blank"&gt;
&lt;img src="http://ads.geekswithblogs.net/a.aspx?ZoneID=5&amp;amp;Task=Get&amp;amp;Mode=HTML&amp;amp;SiteID=1&amp;amp;PageID=31016" width="1" height="1" border="0"  alt=""&gt;&lt;/a&gt;
&lt;/noscript&gt;
&lt;/iframe&gt;
&lt;img src="http://geekswithblogs.net/ssimakov/aggbug/63145.aspx" width="1" height="1" /&gt;</description>
            <dc:creator>Sergey Simakov</dc:creator>
            <guid isPermaLink="false">http://geekswithblogs.net/ssimakov/archive/2005/12/14/63145.aspx</guid>
            <pubDate>Thu, 15 Dec 2005 04:22:00 GMT</pubDate>
            <comments>http://geekswithblogs.net/ssimakov/archive/2005/12/14/63145.aspx#feedback</comments>
            <wfw:commentRss>http://geekswithblogs.net/ssimakov/comments/commentRss/63145.aspx</wfw:commentRss>
        <feedburner:origLink>http://geekswithblogs.net/ssimakov/archive/2005/12/14/63145.aspx</feedburner:origLink></item>
        <item>
            <title>news for last three months </title>
            <category>Development</category>
            <category>Security</category>
            <link>http://feedproxy.google.com/~r/sergesim/~3/ytv-A6poGsw/63144.aspx</link>
            <description>&lt;P&gt;Well,&amp;nbsp;period of silence on this blog ended. Unfortunately I couldn't post for last three months for many reasons&amp;nbsp;and I'm sorry for it :(( &lt;/P&gt;
&lt;P&gt;In this post I'll try to summarize what interesting&amp;nbsp;things&amp;nbsp;happened in security from my point of view (actually Valery already mentioned most of them in his &lt;A href="http://www.harper.no/valery/"&gt;blog&lt;/A&gt;):&lt;/P&gt;
&lt;P&gt;Peter Gutmann updated his &amp;#8220;&lt;A href="http://www.cs.auckland.ac.nz/~pgut001/tutorial/index.html"&gt;Godzilla crypto and security&lt;/A&gt;&amp;#8220; tutorial&amp;nbsp;with excellent quote on current state of laws in Russia: &amp;#8220;The severity of Russian law is compensated for by it&amp;#8217;s non-mandatoryness.&amp;#8221;&lt;/P&gt;
&lt;P&gt;NSA announced &lt;A href="http://www.nsa.gov/ia/industry/crypto_suite_b.cfm"&gt;Suite B Cryptography&lt;/A&gt; at RSA 2005 consisting of AES, Elliptic Curve Digital Signature and Key Exchange and SHA-256/384.&lt;/P&gt;
&lt;P&gt;
&lt;HR id=null&gt;
&lt;/P&gt;
&lt;P&gt;For this reason I try to&amp;nbsp;describe &lt;STRONG&gt;unofficial&lt;/STRONG&gt; Russian &amp;#8220;Suite B&amp;#8220;:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;GOST 28147-89 for encryption&lt;/LI&gt;
&lt;LI&gt;GOST R 34.10-2001 (Elliptic Curve Digital Signature) for DS and Key Exchange (it supersedes GOST R 34.10-94 that should be withdrawn&amp;nbsp;before&amp;nbsp;1.01.2008)&lt;/LI&gt;
&lt;LI&gt;GOST R 34.11-94 for hash function&lt;/LI&gt;&lt;/UL&gt;
&lt;P&gt;More information about using these algorithms with X.509 certificate and CRL profile is&amp;nbsp;currently&amp;nbsp;available as &lt;A href="http://www.ietf.org/internet-drafts/draft-ietf-pkix-gost-cppk-03.txt"&gt;draft &lt;/A&gt;(and will be accepted as informational RFC in the&amp;nbsp;&lt;A href="http://article.gmane.org/gmane.ietf.x509/22808/match=draft+ietf+pkix+gost+cppk+03"&gt;nearest time&lt;/A&gt;). Basic implementation for OpenSSL 0.9.8 could be downloaded at &lt;A href="http://www.cryptocom.ru/OpenSource/OpenSSL_eng.html"&gt;CryptoCom open-source&amp;nbsp;site&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;
&lt;HR id=null&gt;
&lt;/P&gt;
&lt;P&gt;Bruce Schneier posted his impressions from&amp;nbsp;&lt;A href="http://www.csrc.nist.gov/pki/HashWorkshop/index.html"&gt;&lt;FONT color=#0000eb&gt;Cryptographic Hash Workshop&lt;/FONT&gt;&lt;/A&gt; hosted by NIST: &lt;A href="http://www.schneier.com/blog/archives/2005/10/nist_hash_works_1.html"&gt;1&lt;/A&gt;, &lt;A href="http://www.schneier.com/blog/archives/2005/10/nist_hash_works_2.html"&gt;2&lt;/A&gt;, &lt;A href="http://www.schneier.com/blog/archives/2005/10/nist_hash_works_3.html"&gt;3&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;This autumn was a bad time for many IPSec ISAKMP/IKE implementations: &lt;A href="http://www.ee.oulu.fi/research/ouspg/protos/testing/c09/isakmp/"&gt;Protos test suite&lt;/A&gt; from Oulu University Secure Programming Group found multiple vendor &lt;A href="http://www.kb.cert.org/vuls/id/226364"&gt;implementation vulnerabilities&lt;/A&gt;. And this is an exact sample of using &lt;A href="http://doi.ieeecomputersociety.org/10.1109/MSP.2005.55"&gt;fuzzing technique&lt;/A&gt; to find security flaws.&lt;/P&gt;
&lt;P&gt;Sun Microsystem released Solaris 10 source code as &lt;A href="http://www.opensolaris.org/os/community/security/"&gt;OpenSolaris&lt;/A&gt; including &lt;A href="http://cvs.opensolaris.org/source/xref/usr/src/uts/common/crypto"&gt;Kernel Crypto Framework/Drivers&lt;/A&gt;, &lt;A href="http://cvs.opensolaris.org/source/xref/usr/src/lib/pkcs11"&gt;&lt;FONT color=#002c99&gt;User Crypto Framework (PKCS#11)&lt;/FONT&gt;&lt;/A&gt; and &lt;A href="http://cvs.opensolaris.org/source/xref/usr/src/common/crypto"&gt;&lt;FONT color=#002c99&gt;Crypto Algorithms&lt;/FONT&gt;&lt;/A&gt; (more information is available at &lt;A href="http://blogs.sun.com/roller/page/darren"&gt;Darren J. Moffat blog&lt;/A&gt;)&lt;/P&gt;
&lt;P&gt;
&lt;HR id=null&gt;
&lt;/P&gt;
&lt;P&gt;BTW, it is interesting to compare design of future Microsoft&amp;nbsp;CryptoAPI NG from &lt;A href="http://geekswithblogs.net/ssimakov/archive/2005/09/15/53963.aspx"&gt;previous post&lt;/A&gt; and &lt;A href="http://www.opensolaris.org/os/community/security/projects/ef/"&gt;The (Open)Solaris Cryptographic Framework&lt;/A&gt;. They are build of the same cryptoproviders separation as distinct&amp;nbsp;digest, signature, etc providers and both moving to support kernel (right now it's impossible to use CryptoAPI in ipsec driver for example).&lt;/P&gt;
&lt;P&gt;
&lt;HR id=null&gt;
&lt;/P&gt;
&lt;P&gt;And&amp;nbsp;developer part&amp;nbsp;of news: two most successful Microsoft Shared Source projects released as &lt;A href="http://wix.sourceforge.net/latestrelease.html"&gt;WiX 2.0&lt;/A&gt; and &lt;A href="http://wtl.sourceforge.net/"&gt;WTL 7.5&lt;/A&gt;&amp;nbsp;- and MSFT could be really proud of them (we use them extensively in our projects). &lt;/P&gt;
&lt;P&gt;Windows kernel developers also received new development framework - &lt;A href="http://www.microsoft.com/whdc/driver/wdf/KMDF_pkg.mspx"&gt;Kernel Mode Driver Framework 1.0&lt;/A&gt; (unfortunately it didn't support Windows 2000 in version 1.0, but I hope it will due to &lt;A href="http://www.osronline.com/article.cfm?article=429"&gt;feedback from developers community&lt;/A&gt;) and &amp;nbsp;updated &lt;A href="http://www.microsoft.com/whdc/driver/wdf/KMDF_pkg.mspx"&gt;Driver Install Framework Tools 2.01&lt;/A&gt;. And best of all - WDF contains Windows Server 2003 SP1 DDK with Static Driver Verifier for free ;-) If you're interested in Windows Kernel development - watch for OSR &lt;A href="http://www.osronline.com/rss/ntdev.xml"&gt;NTDEV&lt;/A&gt; and &lt;A href="http://kernelmustard.com/"&gt;Steve Dispensa&amp;nbsp;blog&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;Well, it's enough for today - thank you&amp;nbsp;for reading&amp;nbsp;=)&lt;/P&gt;&lt;p&gt;&lt;a href="http://www.pheedo.com/click.phdo?x=6cda6ad746d942b9a1110d0715a4fa12&amp;u=63144"&gt;&lt;img src="http://www.pheedo.com/img.phdo?x=6cda6ad746d942b9a1110d0715a4fa12&amp;u=63144" border="0"/&gt;&lt;/a&gt;&lt;/p&gt;&lt;iframe src="http://ads.geekswithblogs.net/a.aspx?ZoneID=5&amp;amp;Task=Get&amp;amp;PageID=31016&amp;amp;SiteID=1" width=1 height=1 Marginwidth=0 Marginheight=0 Hspace=0 Vspace=0 Frameborder=0 Scrolling=No&gt;
&lt;script language='javascript1.1' src="http://ads.geekswithblogs.net/a.aspx?ZoneID=5&amp;amp;Task=Get&amp;amp;Browser=NETSCAPE4&amp;amp;NoCache=True&amp;PageID=31016&amp;amp;SiteID=1"&gt;&lt;/script&gt;
&lt;noscript&gt;&lt;a href="http://ads.geekswithblogs.net/a.aspx?ZoneID=5&amp;amp;Task=Click&amp;amp;Mode=HTML&amp;amp;SiteID=1&amp;amp;PageID=31016" target="_blank"&gt;
&lt;img src="http://ads.geekswithblogs.net/a.aspx?ZoneID=5&amp;amp;Task=Get&amp;amp;Mode=HTML&amp;amp;SiteID=1&amp;amp;PageID=31016" width="1" height="1" border="0"  alt=""&gt;&lt;/a&gt;
&lt;/noscript&gt;
&lt;/iframe&gt;
&lt;img src="http://geekswithblogs.net/ssimakov/aggbug/63144.aspx" width="1" height="1" /&gt;</description>
            <dc:creator>Sergey Simakov</dc:creator>
            <guid isPermaLink="false">http://geekswithblogs.net/ssimakov/archive/2005/12/14/63144.aspx</guid>
            <pubDate>Thu, 15 Dec 2005 04:03:00 GMT</pubDate>
            <comments>http://geekswithblogs.net/ssimakov/archive/2005/12/14/63144.aspx#feedback</comments>
            <wfw:commentRss>http://geekswithblogs.net/ssimakov/comments/commentRss/63144.aspx</wfw:commentRss>
        <feedburner:origLink>http://geekswithblogs.net/ssimakov/archive/2005/12/14/63144.aspx</feedburner:origLink></item>
        <item>
            <title>Security slide decks at PDC2005</title>
            <category>Development</category>
            <category>Security</category>
            <link>http://feedproxy.google.com/~r/sergesim/~3/RcdU0DlMSuQ/53963.aspx</link>
            <description>&lt;P&gt;For poor souls like me (who could not attent PDC this year&amp;nbsp;;-) - at least we can check&amp;nbsp;PDC2005&amp;nbsp;&lt;A href="http://commnet.microsoftpdc.com/content/downloads.aspx"&gt;slide decks&lt;/A&gt; [via &lt;A href="http://samgentile.com/blog/archive/2005/09/15/31946.aspx"&gt;Sam Gentile&lt;/A&gt;].&lt;/P&gt;
&lt;P&gt;I'm&amp;nbsp;interested in&amp;nbsp;&amp;#8220;&lt;A href="http://216.55.183.63/pdc2005/slides/TLNL06_Guerrera.ppt"&gt;Scrubbing Source Code for Common Coding Mistakes (FxCop and PreFast)&lt;/A&gt;&amp;#8220;,&amp;nbsp;&amp;nbsp;&amp;#8220;&lt;A href="http://216.55.183.63/pdc2005/slides/COM304_Talwar.ppt"&gt;Building IPv6, Firewall, and IPsec Aware Applications&lt;/A&gt;&amp;#8220; and especially &amp;#8220;&lt;A href="http://216.55.183.63/pdc2005/slides/FUN210_Ben-Menahem_Tucker.ppt"&gt;Understanding, Enhancing, and Extending Security End-to-End&lt;/A&gt;&amp;#8220; (because it mentions CryptoAPI NG)&lt;/P&gt;
&lt;P&gt;[Updated 2005/12/07 to include direct links to presentations and btw CNG is _must read_ for any CSP developer!]&lt;BR&gt;&lt;/P&gt;&lt;p&gt;&lt;a href="http://www.pheedo.com/click.phdo?x=6cda6ad746d942b9a1110d0715a4fa12&amp;u=53963"&gt;&lt;img src="http://www.pheedo.com/img.phdo?x=6cda6ad746d942b9a1110d0715a4fa12&amp;u=53963" border="0"/&gt;&lt;/a&gt;&lt;/p&gt;&lt;iframe src="http://ads.geekswithblogs.net/a.aspx?ZoneID=5&amp;amp;Task=Get&amp;amp;PageID=31016&amp;amp;SiteID=1" width=1 height=1 Marginwidth=0 Marginheight=0 Hspace=0 Vspace=0 Frameborder=0 Scrolling=No&gt;
&lt;script language='javascript1.1' src="http://ads.geekswithblogs.net/a.aspx?ZoneID=5&amp;amp;Task=Get&amp;amp;Browser=NETSCAPE4&amp;amp;NoCache=True&amp;PageID=31016&amp;amp;SiteID=1"&gt;&lt;/script&gt;
&lt;noscript&gt;&lt;a href="http://ads.geekswithblogs.net/a.aspx?ZoneID=5&amp;amp;Task=Click&amp;amp;Mode=HTML&amp;amp;SiteID=1&amp;amp;PageID=31016" target="_blank"&gt;
&lt;img src="http://ads.geekswithblogs.net/a.aspx?ZoneID=5&amp;amp;Task=Get&amp;amp;Mode=HTML&amp;amp;SiteID=1&amp;amp;PageID=31016" width="1" height="1" border="0"  alt=""&gt;&lt;/a&gt;
&lt;/noscript&gt;
&lt;/iframe&gt;
&lt;img src="http://geekswithblogs.net/ssimakov/aggbug/53963.aspx" width="1" height="1" /&gt;</description>
            <dc:creator>Sergey Simakov</dc:creator>
            <guid isPermaLink="false">http://geekswithblogs.net/ssimakov/archive/2005/09/15/53963.aspx</guid>
            <pubDate>Fri, 16 Sep 2005 01:23:00 GMT</pubDate>
            <comments>http://geekswithblogs.net/ssimakov/archive/2005/09/15/53963.aspx#feedback</comments>
            <wfw:commentRss>http://geekswithblogs.net/ssimakov/comments/commentRss/53963.aspx</wfw:commentRss>
        <feedburner:origLink>http://geekswithblogs.net/ssimakov/archive/2005/09/15/53963.aspx</feedburner:origLink></item>
        <item>
            <title>Humans</title>
            <category>Personal</category>
            <link>http://feedproxy.google.com/~r/sergesim/~3/HIPwgv05jYA/49976.aspx</link>
            <description>&lt;P&gt;&lt;A href="http://www.harper.no/valery/PermaLink,guid,d8f0f29d-ff7e-47a2-8189-fb35bd3f4217.aspx"&gt;Valery shared&lt;/A&gt; that wonderful quote from &lt;A href="http://www.amazon.com/exec/obidos/tg/detail/-/0130614661"&gt;Network Security: Private Communication in a Public World&lt;/A&gt; last week:&lt;/P&gt;
&lt;BLOCKQUOTE dir=ltr style="MARGIN-RIGHT: 0px"&gt;
&lt;P&gt;&lt;EM&gt;Humans are incapable of securely storing high-quality cryptographic keys, and they have unacceptable speed and accuracy when performing cryptographic operations. (They are also large, expensive to maintain, difficult to manage, and they pollute environment. It is astonishing that these devices continue to be manufactured and deployed. But they are sufficiently pervasive that we must design our protocols around their limitations.)&lt;/EM&gt;&lt;/P&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;And today this &lt;A href="http://www.dilbert.com/comics/dilbert/archive/dilbert-20050812.html"&gt;comic&amp;nbsp;by Scott Adams&lt;/A&gt;&amp;nbsp;=):&lt;/P&gt;
&lt;P&gt;&lt;IMG src="http://www.dilbert.com/comics/dilbert/archive/images/dilbert2005018313812.gif" border=0&gt;&lt;/P&gt;&lt;p&gt;&lt;a href="http://www.pheedo.com/click.phdo?x=6cda6ad746d942b9a1110d0715a4fa12&amp;u=49976"&gt;&lt;img src="http://www.pheedo.com/img.phdo?x=6cda6ad746d942b9a1110d0715a4fa12&amp;u=49976" border="0"/&gt;&lt;/a&gt;&lt;/p&gt;&lt;iframe src="http://ads.geekswithblogs.net/a.aspx?ZoneID=5&amp;amp;Task=Get&amp;amp;PageID=31016&amp;amp;SiteID=1" width=1 height=1 Marginwidth=0 Marginheight=0 Hspace=0 Vspace=0 Frameborder=0 Scrolling=No&gt;
&lt;script language='javascript1.1' src="http://ads.geekswithblogs.net/a.aspx?ZoneID=5&amp;amp;Task=Get&amp;amp;Browser=NETSCAPE4&amp;amp;NoCache=True&amp;PageID=31016&amp;amp;SiteID=1"&gt;&lt;/script&gt;
&lt;noscript&gt;&lt;a href="http://ads.geekswithblogs.net/a.aspx?ZoneID=5&amp;amp;Task=Click&amp;amp;Mode=HTML&amp;amp;SiteID=1&amp;amp;PageID=31016" target="_blank"&gt;
&lt;img src="http://ads.geekswithblogs.net/a.aspx?ZoneID=5&amp;amp;Task=Get&amp;amp;Mode=HTML&amp;amp;SiteID=1&amp;amp;PageID=31016" width="1" height="1" border="0"  alt=""&gt;&lt;/a&gt;
&lt;/noscript&gt;
&lt;/iframe&gt;
&lt;img src="http://geekswithblogs.net/ssimakov/aggbug/49976.aspx" width="1" height="1" /&gt;</description>
            <dc:creator>Sergey Simakov</dc:creator>
            <guid isPermaLink="false">http://geekswithblogs.net/ssimakov/archive/2005/08/12/49976.aspx</guid>
            <pubDate>Fri, 12 Aug 2005 17:14:00 GMT</pubDate>
            <comments>http://geekswithblogs.net/ssimakov/archive/2005/08/12/49976.aspx#feedback</comments>
            <wfw:commentRss>http://geekswithblogs.net/ssimakov/comments/commentRss/49976.aspx</wfw:commentRss>
        <feedburner:origLink>http://geekswithblogs.net/ssimakov/archive/2005/08/12/49976.aspx</feedburner:origLink></item>
        <item>
            <title>New security books from Microsoft security team</title>
            <category>Development</category>
            <category>Security</category>
            <link>http://feedproxy.google.com/~r/sergesim/~3/dxtsU5XL4HE/33330.aspx</link>
            <description>&lt;P&gt;As I &lt;A href="http://geekswithblogs.net/ssimakov/archive/2005/01/14/20008.aspx"&gt;posted&lt;/A&gt; recently &lt;A href="http://www.awprofessional.com/title/0321336437"&gt;&lt;FONT color=#ff9900&gt;Protect Your Windows Network&lt;/FONT&gt;&lt;/A&gt; book by &lt;A href="http://blogs.msdn.com/steriley/archive/2005/03/21/399990.aspx"&gt;&lt;FONT color=#ff9900&gt;Steve Riley&lt;/FONT&gt;&lt;/A&gt; and Jesper M. Johansson&amp;nbsp;is available for pre-ordering. Both &lt;A href="http://blogs.msdn.com/michael_howard/archive/2005/04/12/407641.aspx"&gt;Michael Howard&lt;/A&gt; and &lt;A href="http://blogs.technet.com/steriley/archive/2005/04/12/403642.aspx"&gt;Steve Riley&lt;/A&gt; posted&amp;nbsp;updated information about&amp;nbsp;preorder (with promo code ;-)&lt;/P&gt;
&lt;P&gt;Also yesterday I accidentially found new book by Michael, David LeBlank AND &lt;A href="http://www.viega.org"&gt;John Viega&lt;/A&gt; - &lt;A href="http://books.mcgraw-hill.com/getbook.php?isbn=0072260858"&gt;19 Deadly Sins of Software Security&lt;/A&gt; due to August 2005. It should be interesting book from authors of Writing of Secure Code and &lt;A href="http://www.secureprogramming.com/"&gt;Secure Programming Cookbook&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;[Update] This monday Michael Howard &lt;A href="http://blogs.msdn.com/michael_howard/archive/2005/07/11/437875.aspx"&gt;officially announced&lt;/A&gt; this book on his blog.&lt;/P&gt;&lt;p&gt;&lt;a href="http://www.pheedo.com/click.phdo?x=6cda6ad746d942b9a1110d0715a4fa12&amp;u=33330"&gt;&lt;img src="http://www.pheedo.com/img.phdo?x=6cda6ad746d942b9a1110d0715a4fa12&amp;u=33330" border="0"/&gt;&lt;/a&gt;&lt;/p&gt;&lt;iframe src="http://ads.geekswithblogs.net/a.aspx?ZoneID=5&amp;amp;Task=Get&amp;amp;PageID=31016&amp;amp;SiteID=1" width=1 height=1 Marginwidth=0 Marginheight=0 Hspace=0 Vspace=0 Frameborder=0 Scrolling=No&gt;
&lt;script language='javascript1.1' src="http://ads.geekswithblogs.net/a.aspx?ZoneID=5&amp;amp;Task=Get&amp;amp;Browser=NETSCAPE4&amp;amp;NoCache=True&amp;PageID=31016&amp;amp;SiteID=1"&gt;&lt;/script&gt;
&lt;noscript&gt;&lt;a href="http://ads.geekswithblogs.net/a.aspx?ZoneID=5&amp;amp;Task=Click&amp;amp;Mode=HTML&amp;amp;SiteID=1&amp;amp;PageID=31016" target="_blank"&gt;
&lt;img src="http://ads.geekswithblogs.net/a.aspx?ZoneID=5&amp;amp;Task=Get&amp;amp;Mode=HTML&amp;amp;SiteID=1&amp;amp;PageID=31016" width="1" height="1" border="0"  alt=""&gt;&lt;/a&gt;
&lt;/noscript&gt;
&lt;/iframe&gt;
&lt;img src="http://geekswithblogs.net/ssimakov/aggbug/33330.aspx" width="1" height="1" /&gt;</description>
            <dc:creator>Sergey Simakov</dc:creator>
            <guid isPermaLink="false">http://geekswithblogs.net/ssimakov/archive/2005/04/13/33330.aspx</guid>
            <pubDate>Wed, 13 Apr 2005 16:03:00 GMT</pubDate>
            <comments>http://geekswithblogs.net/ssimakov/archive/2005/04/13/33330.aspx#feedback</comments>
            <wfw:commentRss>http://geekswithblogs.net/ssimakov/comments/commentRss/33330.aspx</wfw:commentRss>
        <feedburner:origLink>http://geekswithblogs.net/ssimakov/archive/2005/04/13/33330.aspx</feedburner:origLink></item>
    </channel>
</rss>
