August 2007 - Posts

Windows Live now supports Information Cards
Wednesday, August 29, 2007 3:14 AM
Yahoo! Microsoft is finally eating its own dogfood when it comes to identity and access control for the masses!!! You can now login to your Windows Live account using an Information Card. Notice the dropdown now has "Information Card" as an...
Writing Vista Sidebar Gadgets securely
Tuesday, August 14, 2007 10:05 PM
During today's patch release cycle from Microsoft, a new set of vulnerabilties were fixed against Vista Sidebar gadgets that could allow for remote code execution. You can read the security bulletin on this threat over on TechNet here if you would...
Is DREAD really dead?
Tuesday, August 14, 2007 3:26 AM
A couple of years ago I stated that I wasn't a fan of DREAD when threat modeling. I prefer the standard information security risk formula of " risk = Probability(chance) * Damage Potential (damage) " I was pleased to hear from a Microsoft...