Larry Osterman's WebLogConfessions of an Old FogeyCool Schwag :)- May 15, 2008 Not surprisingly, I'm the security contact for my small part of the Windows organization (it's called the Devices&Media group, which is within the WEX division). As such, I'm responsible for providing security guidance and reviewing the threat models for our group (I've done a lot of them over the past few months :)). Earlier this morning, one of the PMs for one of the teams in D&M stopped by my office with a thank you gift for the work I've done with his team. He had...http://blogs.msdn.com/larryosterman/archive/2008/05/15/cool-schwag.aspx More proof that crypto should be left to the experts- May 13, 2008 Apparently two years ago, someone ran a static analysis tool named "Valgrind" against the source code to OpenSSL in the Debian Linux distribution. The Valgrind tool reported an issue with the OpenSSL package distributed by Debian, so the Debian team decided that they needed to fix this "security bug". Unfortunately, the solution they chose to implement apparently removed all entropy from the OpenSSL random number generator. As the OpenSSL team comments "Had Debian contributed.http://blogs.msdn.com/larryosterman/archive/2008/05/13/more-proof-that-crypto-should-be-le... Resilience is NOT necessarily a good thing- May 1, 2008 I just ran into this post by Eric Brechner who is the director of Microsoft's Engineering Excellence center. What really caught my eye was his opening paragraph: I heard a remark the other day that seemed stupid on the surface, but when I really thought about it I realized it was completely idiotic and irresponsible. The remark was that it's better to crash and let Watson report the error than it is to catch the exception and try to correct it. Wow. I'm not going to mince words: What a...http://blogs.msdn.com/larryosterman/archive/2008/05/01/resilience-is-not-necessarily-a-goo... |