<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://windowsteamblog.com/utility/FeedStylesheets/atom.xsl" media="screen"?><feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en"><title type="html">Windows Security Blog</title><subtitle type="html" /><id>http://windowsteamblog.com/blogs/windowssecurity/atom.aspx</id><link rel="alternate" type="text/html" href="http://windowsteamblog.com/blogs/windowssecurity/default.aspx" /><link rel="self" type="application/atom+xml" href="http://windowsteamblog.com/blogs/windowssecurity/atom.aspx" /><generator uri="http://communityserver.org" version="4.0.30619.63">Community Server</generator><updated>2008-12-15T16:20:00Z</updated><entry><title>Windows 7 Vulnerability Claims</title><link rel="alternate" type="text/html" href="/blogs/windowssecurity/archive/2009/11/06/windows-7-vulnerability-claims.aspx" /><id>/blogs/windowssecurity/archive/2009/11/06/windows-7-vulnerability-claims.aspx</id><published>2009-11-07T00:56:00Z</published><updated>2009-11-07T00:56:00Z</updated><content type="html">&lt;p&gt;Now that Windows 7 is available, a recent blog by Chester Wisnieski (who works at security vendor Sophos), entitled &lt;a href="http://www.sophos.com/blogs/chetw/g/2009/11/03/windows-7-vulnerable-8-10-viruses"&gt;Windows 7 vulnerable to 8 out of 10 viruses&lt;/a&gt;, which has stirred some interest.&lt;/p&gt;
&lt;p&gt;Here's a quick summary for those who missed Chester's blog. During a test SophosLabs conducted, they subjected Windows 7 to "10 unique [malware] samples that arrived in the SophosLabs feed." They utilized a clean install of Windows 7, using default settings (including the UAC defaults), but did not install any anti-virus software. The end result was 8 of the 10 malware samples successfully ran and the blog proclaims that "Windows 7 disappointed just like earlier versions of Windows." Chester's final conclusion? "You still need to run anti-virus on Windows 7." Well, we agree: users of any computer, on any platform, should run anti-virus software, including those running Windows 7.&lt;/p&gt;
&lt;p&gt;Clearly, the findings of this unofficial test are by no means conclusive, and several members of the press have picked apart the findings, so I don't need to do that. I'm a firm believer that if you run unknown code on your machine, bad things can happen. This test shows just that; however, most people don't knowingly have and run known malware on their system. Malware typically makes it onto a system through other avenues like the browser or email program. So while I absolutely agree that anti-virus software is essential to protecting your PC, there are other defenses as well. &lt;/p&gt;
&lt;p&gt;Let me recap some of the Windows 7 security basics. Windows 7 is built upon the security platform of Windows Vista, which included a defense-in-depth approach to help protect customers from malware. This includes features like User Account Control (UAC), Kernel Patch Protection, Windows Service Hardening, Address Space Layout Randomization (ASLR), and Data Execution Prevention (DEP) to name just a few. The result, Windows 7 retains and refines the development processes, including going through the Security Development Lifecycle, and technologies that made Windows Vista the most secure Windows operating system ever released.&lt;/p&gt;
&lt;p&gt;Beyond the core security of Windows 7, we have also done a lot of work with Windows 7 to make it harder for malware to reach a user's PCs in the first place. One of my favorite new features is the SmartScreen Filter in Internet Explorer 8. The SmartScreen Filter was built upon the phishing protection in Internet Explorer 7 and (among other new benefits) adds protection from malware. The SmartScreen Filter will notify you when you attempt to download software that is unsafe - which the SophosLabs methodology totally bypassed in doing their test.&lt;/p&gt;
&lt;p&gt;So while I'm not a fan of companies sensationalizing findings about Windows 7 in order to sell more of their own software, I nevertheless agree with them that you still need to run anti-virus software on Windows 7.&amp;nbsp; This is why we've made our &lt;a href="http://www.microsoft.com/security_essentials/"&gt;Microsoft Security Essentials&lt;/a&gt; offering available for free to customers. But it's also equally important to keep all of your software up to date through automatic updates, such as through the Windows Update service. By configuring your computers to download and install updates automatically you will help ensure that you have the highest level of protection against malware and other vulnerabilities.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://windowsteamblog.com/aggbug.aspx?PostID=527942" width="1" height="1"&gt;</content><author><name>Paul Cooke</name><uri>http://windowsteamblog.com/members/Paul-Cooke/default.aspx</uri></author><category term="Security" scheme="http://windowsteamblog.com/blogs/windowssecurity/archive/tags/Security/default.aspx" /><category term="Windows Security" scheme="http://windowsteamblog.com/blogs/windowssecurity/archive/tags/Windows+Security/default.aspx" /><category term="IT Pro" scheme="http://windowsteamblog.com/blogs/windowssecurity/archive/tags/IT+Pro/default.aspx" /><category term="Windows" scheme="http://windowsteamblog.com/blogs/windowssecurity/archive/tags/Windows/default.aspx" /><category term="Windows 7" scheme="http://windowsteamblog.com/blogs/windowssecurity/archive/tags/Windows+7/default.aspx" /><category term="Security Development Lifecycle" scheme="http://windowsteamblog.com/blogs/windowssecurity/archive/tags/Security+Development+Lifecycle/default.aspx" /><category term="Internet Explorer 8" scheme="http://windowsteamblog.com/blogs/windowssecurity/archive/tags/Internet+Explorer+8/default.aspx" /><category term="Windows Update" scheme="http://windowsteamblog.com/blogs/windowssecurity/archive/tags/Windows+Update/default.aspx" /><category term="UAC" scheme="http://windowsteamblog.com/blogs/windowssecurity/archive/tags/UAC/default.aspx" /></entry><entry><title>New Microsoft Security Intelligence Report Released</title><link rel="alternate" type="text/html" href="/blogs/windowssecurity/archive/2009/11/02/new-microsoft-security-intelligence-report-released.aspx" /><id>/blogs/windowssecurity/archive/2009/11/02/new-microsoft-security-intelligence-report-released.aspx</id><published>2009-11-02T19:00:00Z</published><updated>2009-11-02T19:00:00Z</updated><content type="html">&lt;p&gt;Volume seven of the &lt;a href="http://www.microsoft.com/sir"&gt;Microsoft Security Intelligence Report&lt;/a&gt; (SIRv7) - part of Microsoft's&amp;nbsp; commitment to providing an unparalleled level of security intelligence to help keep individuals and organizations better informed and to maximize security investments - was released today and there are a couple of tidbits in the report that caught my attention that I thought I would pass on. As a reminder, the SIR is published by Microsoft twice per year and looks at the data and trends observed in the first and second halves of each calendar year.&lt;b&gt;&lt;/b&gt;&lt;/p&gt;
&lt;p&gt;The first thing that struck me while reading through the report is that for the first time, the SIR shares some high-level security best practices from countries that have consistently exhibited low malware infection. For example, Japan, Austria and Germany's infection rates remained relatively low during the first half of this year.&lt;/p&gt;
&lt;p&gt;So how do these regions keep their customers and resources safe from cyber threats?&amp;nbsp; Japan's infection rates remain relatively low is due in large part to collaborations like the Cyber Clean Center. The Cyber Clean Center is a cooperative project between ISPs, major security vendors and Japanese government agencies aimed at educating users on how to keep their PCs infection free. Austria has implemented strict IT enforcement guidelines to lower piracy rates and this, along with strong ISP relationships and fast Internet lines, has helped ensure the ecosystem is kept up to date with security patches. Germany has also leveraged collaboration efforts with its CERT and ISP communities to help identify and raise awareness of botnet infections and, in some cases, quarantine infected computers. &lt;/p&gt;
&lt;p&gt;The other thing that stood out to me was the graph below. This graph shows the effectiveness of automatic updating and shows what happened to the trojan downloader family Win32/Renos once Microsoft released a signature update for Windows Defender via Windows Update and Microsoft Update. Within three days, enough computers had received the new signature update to reduce the error reports from 1.2 million per day to less than 100,000 per day worldwide! To me this shows how important it is for users and organizations to utilize automatic updates to help prevent the spread of malware!&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;img src="http://windowsteamblog.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/windowssecurity/SIRv7_2D00_DefenderImpact.png" /&gt;&lt;/p&gt;
&lt;p&gt;The report also underscores some of the trends that we have seen from previous versions of the report: for example, the infection rate for Windows Vista is significantly lower than that of its predecessor, Windows XP. It also tells me that the higher the service pack levels of an OS, the lower the infection rate. Once again, these items help point out that you need to keep your software up-to-date. With Windows 7 now available it might be a good time to look at upgrading your OS!&lt;/p&gt;
&lt;p&gt;Take a look at the full report at &lt;a href="http://www.microsoft.com/sir"&gt;http://www.microsoft.com/sir&lt;/a&gt; and use the information to help protect yourself, your networks, and your users.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://windowsteamblog.com/aggbug.aspx?PostID=527595" width="1" height="1"&gt;</content><author><name>Paul Cooke</name><uri>http://windowsteamblog.com/members/Paul-Cooke/default.aspx</uri></author><category term="Announcement" scheme="http://windowsteamblog.com/blogs/windowssecurity/archive/tags/Announcement/default.aspx" /><category term="Security" scheme="http://windowsteamblog.com/blogs/windowssecurity/archive/tags/Security/default.aspx" /><category term="IT Pro" scheme="http://windowsteamblog.com/blogs/windowssecurity/archive/tags/IT+Pro/default.aspx" /><category term="SIR" scheme="http://windowsteamblog.com/blogs/windowssecurity/archive/tags/SIR/default.aspx" /><category term="Trustworthy Computing" scheme="http://windowsteamblog.com/blogs/windowssecurity/archive/tags/Trustworthy+Computing/default.aspx" /></entry><entry><title>Mark Russinovich on Windows 7 UAC</title><link rel="alternate" type="text/html" href="/blogs/windowssecurity/archive/2009/06/09/mark-russinovich-on-windows-7-uac.aspx" /><id>/blogs/windowssecurity/archive/2009/06/09/mark-russinovich-on-windows-7-uac.aspx</id><published>2009-06-09T16:00:00Z</published><updated>2009-06-09T16:00:00Z</updated><content type="html">&lt;p&gt;User Account Control is one of those Windows features that evokes a number of different responses from folks. Most people appreciate the enhanced security UAC offers, but we did hear complaints about the high number of UAC prompts in Windows Vista. This led some customers to turn off UAC, which concerns us from a security perspective. So in Windows 7, we've given a great deal of thought to how we marry enhanced security with ease-of-use. We have written&amp;nbsp;extensively about&amp;nbsp;the changes in UAC&amp;nbsp;for Windows 7 on the &lt;em&gt;Engineering Windows 7&lt;/em&gt; blog (&lt;a href="http://blogs.msdn.com/e7/archive/2008/10/08/user-account-control.aspx"&gt;Post 1&lt;/a&gt;, &lt;a href="http://blogs.msdn.com/e7/archive/2009/01/15/user-account-control-uac-quick-update.aspx"&gt;Post 2&lt;/a&gt;, &lt;a href="http://blogs.msdn.com/e7/archive/2009/02/05/update-on-uac.aspx"&gt;Post 3&lt;/a&gt;, &lt;a href="http://blogs.msdn.com/e7/archive/2009/02/05/uac-feedback-and-follow-up.aspx"&gt;Post 4&lt;/a&gt;).&lt;/p&gt;
&lt;p&gt;Now,&amp;nbsp;Technical Fellow Mark Russinovich weighs in on UAC with some great insight on the technology and some of our motivations around the decisions we have made.&amp;nbsp;Check out&amp;nbsp;&lt;a href="http://technet.microsoft.com/en-us/magazine/2009.07.uac.aspx"&gt;Inside User Account&amp;nbsp;Control&lt;/a&gt; now available&amp;nbsp;online from TechNet Magazine.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://windowsteamblog.com/aggbug.aspx?PostID=516352" width="1" height="1"&gt;</content><author><name>Paul Cooke</name><uri>http://windowsteamblog.com/members/Paul-Cooke/default.aspx</uri></author><category term="Security" scheme="http://windowsteamblog.com/blogs/windowssecurity/archive/tags/Security/default.aspx" /><category term="Windows Security" scheme="http://windowsteamblog.com/blogs/windowssecurity/archive/tags/Windows+Security/default.aspx" /><category term="Windows 7" scheme="http://windowsteamblog.com/blogs/windowssecurity/archive/tags/Windows+7/default.aspx" /><category term="UAC" scheme="http://windowsteamblog.com/blogs/windowssecurity/archive/tags/UAC/default.aspx" /></entry><entry><title>Upcoming Action Center Changes for Security Vendor Software</title><link rel="alternate" type="text/html" href="/blogs/windowssecurity/archive/2009/05/06/upcoming-action-center-changes-for-security-vendor-software.aspx" /><id>/blogs/windowssecurity/archive/2009/05/06/upcoming-action-center-changes-for-security-vendor-software.aspx</id><published>2009-05-06T15:05:00Z</published><updated>2009-05-06T15:05:00Z</updated><content type="html">&lt;p&gt;We have been working in partnership with our independent software vendor (ISV) community to move the ecosystem to a set of new application programming interfaces (APIs) that many ISVs use to report status to Security Center (integrated within Action Center in Windows 7). The interfaces are used by many antivirus, antispyware, and firewall programs. Te interface changes were introduced in Windows Vista SP1. These new APIs supersede the ones originally shipped in Windows Vista.&lt;/p&gt;
&lt;p&gt;From the release of Vista SP1, we jointly established with the security ISVs an 18 month grace period where they could use both the old and the new interfaces. After the 18 month grace period expires, a security application using the older interface will cause the Windows Security Center system tray icon to indicate a warning. In addition, the Security Center control panel will display a &lt;i&gt;"&amp;lt;program name&amp;gt; is on but is reporting its status to Windows Security Center in a format that is no longer supported. Use the program's automatic updating feature, or contact the program manufacturer for an updated version"&lt;/i&gt; warning message, a sample screen shot is included below. The grace period begins at the time Vista SP1 is installed on a Windows Vista system. As a result, the grace period will begin expiring in September 2009, 18 months after Windows Vista SP1 was released on the Microsoft Download Center in March 2008.&lt;/p&gt;
&lt;p&gt;&lt;img src="http://windowsteamblog.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/windowssecurity/AV-API-Change-_2D00_-Small.png" /&gt;&lt;/p&gt;
&lt;p&gt;Through our partner outreach and the &lt;a href="http://www.microsoft.com/whdc/win7/default.mspx"&gt;Ecosystem Readiness Program&lt;/a&gt;, we have been working with the ISVs since October of 2007 to help them get ready for the final transition to this new interface. As a result, we have removed the old API from the Windows 7 RC.&amp;nbsp; Users who are running security software that does not use the newer API will see the "non-compatible" message shown below from the new Action Center, which instructs customers to contact their security software provider.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Although you may receive this "non-compatible" message from your security software, it should continue to work and help protect your system even though it is not able to report its status through the Action Center UI.&lt;/p&gt;
&lt;p&gt;If you encounter this message today on Window 7 or in the future on Windows Vista, I encourage you to check with your software vendor to see if they have an updated version of software available. Many of our partners already have products that use the new APIs and the others have committed to having compatible versions by the end of the Windows Vista grace period and for Windows 7. Having the latest, compatible software from your security vendors will help ensure that your system remains protected and that you are accurately informed when your security software is not running properly.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://windowsteamblog.com/aggbug.aspx?PostID=513959" width="1" height="1"&gt;</content><author><name>Paul Cooke</name><uri>http://windowsteamblog.com/members/Paul-Cooke/default.aspx</uri></author><category term="Windows Vista" scheme="http://windowsteamblog.com/blogs/windowssecurity/archive/tags/Windows+Vista/default.aspx" /><category term="Security" scheme="http://windowsteamblog.com/blogs/windowssecurity/archive/tags/Security/default.aspx" /><category term="Windows Security" scheme="http://windowsteamblog.com/blogs/windowssecurity/archive/tags/Windows+Security/default.aspx" /><category term="Windows 7" scheme="http://windowsteamblog.com/blogs/windowssecurity/archive/tags/Windows+7/default.aspx" /></entry><entry><title>Who Gets Windows Security Updates?</title><link rel="alternate" type="text/html" href="/blogs/windowssecurity/archive/2009/04/27/who-gets-windows-security-updates.aspx" /><id>/blogs/windowssecurity/archive/2009/04/27/who-gets-windows-security-updates.aspx</id><published>2009-04-28T03:00:00Z</published><updated>2009-04-28T03:00:00Z</updated><content type="html">&lt;p&gt;RSA was great last week - security was clearly top of mind for the attendees, and I fielded a number of different questions last week about how Microsoft protects our customers. Some are pretty straightforward around how the various Windows 7 security technologies work, but many have focused on how we actually deliver protection to customers on an ongoing basis. &lt;/p&gt;
&lt;p&gt;One question that comes up more than I would have ever expected is: Who gets security updates? &lt;/p&gt;
&lt;p&gt;There seems to be a myth that Microsoft limits security updates to genuine Windows users. &lt;/p&gt;
&lt;p&gt;&lt;b&gt;Let me be clear: &lt;span style="text-decoration: underline;"&gt;all &lt;/span&gt;security updates go to &lt;span style="text-decoration: underline;"&gt;all &lt;/span&gt;users.&lt;/b&gt;&lt;/p&gt;
&lt;p&gt;Not only do all security updates go to all users' systems, but non-genuine Windows systems are able to install service packs, update rollups, and important reliability and application compatibility updates. In addition, the users of non-genuine Windows systems can also upgrade a lot of the other software on their computer. For example Internet Explorer 8 has numerous security- oriented features and improvements, and it is available to all users.&lt;b&gt;&lt;/b&gt;&lt;/p&gt;
&lt;p&gt;This isn't to say that all updates are available to non-genuine PCs. Other value-adding updates and software may or may not be blocked, at Microsoft's discretion. On Windows Vista, available updates can be accessed through the Windows Update control panel. On Windows XP, a non-genuine Windows system can access updates through Automatic Updates, but they cannot get to any of the optional updates which are only available through the Windows Update and Microsoft Update websites. &lt;/p&gt;
&lt;p&gt;Keeping a machine up to date is one of the first steps in helping ensure that they remain reliable, compatible, and safe from threats when they are online. Some of the most famous incidents of malicious software infection have come after security updates were publicly available from Microsoft - Blaster, Zotob, Conficker and Sasser, just to name a few. &lt;/p&gt;
&lt;p&gt;I hope this clears up some confusion. Rest assured that we at Microsoft are committed to making sure that security updates are available to all of our users to help ensure a safe online experience for everyone.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://windowsteamblog.com/aggbug.aspx?PostID=513032" width="1" height="1"&gt;</content><author><name>Paul Cooke</name><uri>http://windowsteamblog.com/members/Paul-Cooke/default.aspx</uri></author><category term="Security" scheme="http://windowsteamblog.com/blogs/windowssecurity/archive/tags/Security/default.aspx" /><category term="Windows Update" scheme="http://windowsteamblog.com/blogs/windowssecurity/archive/tags/Windows+Update/default.aspx" /></entry><entry><title>Business Ready Security and Windows 7</title><link rel="alternate" type="text/html" href="/blogs/windowssecurity/archive/2009/04/24/business-ready-security-and-windows-7.aspx" /><id>/blogs/windowssecurity/archive/2009/04/24/business-ready-security-and-windows-7.aspx</id><published>2009-04-24T20:45:11Z</published><updated>2009-04-24T20:45:11Z</updated><content type="html">&lt;p&gt;Here’s the last of the security stories from the RSA show floor. To wrap things up we asked John (JG) Chirapurath (Director, Identity &amp;amp; Security Business Group) to give us a quick rundown on Microsoft Forefront for &lt;a href="http://www.microsoft.com/forefront/en/us/business-ready-security.aspx"&gt;Business Ready Security&lt;/a&gt; and how it fits in with Windows 7.&lt;/p&gt; &lt;strong&gt;&lt;/strong&gt;&lt;iframe height="326" src="http://www.microsoft.com/video/en/us/player/embed/d80282bf-85ff-4d20-b75f-45e878fe3db7" frameborder="0" width="430" allowtransparency="allowtransparency" scrolling="no"&gt;&lt;/iframe&gt;  &lt;br /&gt;&lt;a href="http://www.microsoft.com/video/en/us/details/d80282bf-85ff-4d20-b75f-45e878fe3db7?vp_evt=eref&amp;amp;vp_video=A+Look+at+Microsoft+Forefront"&gt;A Look at Microsoft Forefront&lt;/a&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://windowsteamblog.com/aggbug.aspx?PostID=512162" width="1" height="1"&gt;</content><author><name>Paul Cooke</name><uri>http://windowsteamblog.com/members/Paul-Cooke/default.aspx</uri></author><category term="Windows 7" scheme="http://windowsteamblog.com/blogs/windowssecurity/archive/tags/Windows+7/default.aspx" /><category term="RSA" scheme="http://windowsteamblog.com/blogs/windowssecurity/archive/tags/RSA/default.aspx" /><category term="Business Ready Security" scheme="http://windowsteamblog.com/blogs/windowssecurity/archive/tags/Business+Ready+Security/default.aspx" /><category term="Microsoft Forefront" scheme="http://windowsteamblog.com/blogs/windowssecurity/archive/tags/Microsoft+Forefront/default.aspx" /></entry><entry><title>Internet Explorer 8 Security</title><link rel="alternate" type="text/html" href="/blogs/windowssecurity/archive/2009/04/24/internet-explorer-8-security.aspx" /><id>/blogs/windowssecurity/archive/2009/04/24/internet-explorer-8-security.aspx</id><published>2009-04-24T20:20:41Z</published><updated>2009-04-24T20:20:41Z</updated><content type="html">&lt;p&gt;Here is another story from a Microsoft Program Manger discussing their favorite things in Windows 7. This time it is Eric Lawrence (Senior Program Manager on the Internet Explorer Team) to talk about his favorite security features in Internet Explorer 8, the browser that ships in Windows 7.&lt;/p&gt; &lt;iframe height="326" src="http://www.microsoft.com/video/en/us/player/embed/17020a8a-b7e1-43fe-9ade-8179ed4fe3bf" frameborder="0" width="430" allowtransparency="allowtransparency" scrolling="no"&gt;&lt;/iframe&gt;  &lt;br /&gt;&lt;a href="http://www.microsoft.com/video/en/us/details/17020a8a-b7e1-43fe-9ade-8179ed4fe3bf?vp_evt=eref&amp;amp;vp_video=Eric+Lawrence+Discusses+His+Favorite+Internet+Explorer+Security+Features"&gt;Eric Lawrence Discusses His Favorite Internet Explorer Security Features&lt;/a&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://windowsteamblog.com/aggbug.aspx?PostID=512160" width="1" height="1"&gt;</content><author><name>Paul Cooke</name><uri>http://windowsteamblog.com/members/Paul-Cooke/default.aspx</uri></author><category term="Security" scheme="http://windowsteamblog.com/blogs/windowssecurity/archive/tags/Security/default.aspx" /><category term="Windows 7" scheme="http://windowsteamblog.com/blogs/windowssecurity/archive/tags/Windows+7/default.aspx" /><category term="RSA" scheme="http://windowsteamblog.com/blogs/windowssecurity/archive/tags/RSA/default.aspx" /><category term="Internet Explorer 8" scheme="http://windowsteamblog.com/blogs/windowssecurity/archive/tags/Internet+Explorer+8/default.aspx" /></entry><entry><title>Steve Riley on Windows 7 Security</title><link rel="alternate" type="text/html" href="/blogs/windowssecurity/archive/2009/04/22/steve-riley-on-windows-7-security.aspx" /><id>/blogs/windowssecurity/archive/2009/04/22/steve-riley-on-windows-7-security.aspx</id><published>2009-04-23T00:22:43Z</published><updated>2009-04-23T00:22:43Z</updated><content type="html">&lt;p&gt;While walking the show floor here at RSA, I ran into Steve Riley, who’s an incredibly passionate and knowledgeable Security Evangelist (or officially “Senior Technical Evangelist”) in Microsoft’s Trustworthy Computing organization. He’s a well respected and sought out speaker on security topics. So I thought it would be great to get Steve’s take on his favorite two security features in Windows 7. Take a look at what Steve has to say about Windows 7 security!&lt;/p&gt; &lt;iframe height="326" src="http://www.microsoft.com/video/en/us/player/embed/3bce5c98-ce93-46b5-9a1a-3a2914059ad1" frameborder="0" width="430" allowtransparency="allowtransparency" scrolling="no"&gt;&lt;/iframe&gt;  &lt;br /&gt;&lt;a href="http://www.microsoft.com/video/en/us/details/3bce5c98-ce93-46b5-9a1a-3a2914059ad1?vp_evt=eref&amp;amp;vp_video=Steve+Riley+discusses+Windows+7+Security+Features+at+RSA"&gt;Steve Riley discusses Windows 7 Security Features at RSA&lt;/a&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://windowsteamblog.com/aggbug.aspx?PostID=512077" width="1" height="1"&gt;</content><author><name>Paul Cooke</name><uri>http://windowsteamblog.com/members/Paul-Cooke/default.aspx</uri></author><category term="Windows 7" scheme="http://windowsteamblog.com/blogs/windowssecurity/archive/tags/Windows+7/default.aspx" /><category term="DirectAccess" scheme="http://windowsteamblog.com/blogs/windowssecurity/archive/tags/DirectAccess/default.aspx" /><category term="RSA" scheme="http://windowsteamblog.com/blogs/windowssecurity/archive/tags/RSA/default.aspx" /><category term="BitLocker to Go" scheme="http://windowsteamblog.com/blogs/windowssecurity/archive/tags/BitLocker+to+Go/default.aspx" /><category term="Trustworthy Computing" scheme="http://windowsteamblog.com/blogs/windowssecurity/archive/tags/Trustworthy+Computing/default.aspx" /></entry><entry><title>AppLocker: Direct from RSA</title><link rel="alternate" type="text/html" href="/blogs/windowssecurity/archive/2009/04/22/applocker-direct-from-rsa.aspx" /><id>/blogs/windowssecurity/archive/2009/04/22/applocker-direct-from-rsa.aspx</id><published>2009-04-22T23:59:25Z</published><updated>2009-04-22T23:59:25Z</updated><content type="html">&lt;p&gt;The buzz at RSA around Windows 7 has been tremendous. &lt;/p&gt;  &lt;p&gt;Yesterday, in his keynote, Scott Charney (Corporate VP Trustworthy Computing) talked about AppLocker and how it helps ensure that only known, trusted software is run within an organization’s desktop environment. Shortly after the keynote, I ran into Marcelo Birnbach - a Senior Program Manager in the Windows Security Technologies organization and works on &lt;strong&gt;AppLocker&lt;/strong&gt; - on the expo floor. Since he’s an expert, we thought we would ask him for his perspective on AppLocker in Windows 7. &lt;/p&gt;  &lt;p&gt;&lt;iframe height="326" src="http://www.microsoft.com/video/en/us/player/embed/4021fe27-37e6-4717-9afb-e1bfd55f9b5f" frameborder="0" width="430" allowtransparency="allowtransparency" scrolling="no"&gt;&lt;/iframe&gt;    &lt;br /&gt;&lt;a href="http://www.microsoft.com/video/en/us/details/4021fe27-37e6-4717-9afb-e1bfd55f9b5f?vp_evt=eref&amp;amp;vp_video=Marcelo+Birnbach+talks+about+Windows+7%e2%80%99s+AppLocker+Feature"&gt;Marcelo Birnbach talks about Windows 7’s AppLocker Feature&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;And since Marcelo is originally from Argentina, we also asked him to share his thoughts in Spanish. &lt;/p&gt; &lt;iframe height="326" src="http://www.microsoft.com/video/en/us/player/embed/01fe9d1f-dba7-4ec3-9c5c-49250b29f2aa" frameborder="0" width="430" allowtransparency="allowtransparency" scrolling="no"&gt;&lt;/iframe&gt;  &lt;br /&gt;&lt;a href="http://www.microsoft.com/video/en/us/details/01fe9d1f-dba7-4ec3-9c5c-49250b29f2aa?vp_evt=eref&amp;amp;vp_video=Marcelo+Birnbach+talks+about+Windows+7%e2%80%99s+AppLocker+Feature+%5bSpanish+Version%5d"&gt;Marcelo Birnbach talks about Windows 7’s AppLocker Feature [Spanish Version]&lt;/a&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://windowsteamblog.com/aggbug.aspx?PostID=512076" width="1" height="1"&gt;</content><author><name>Paul Cooke</name><uri>http://windowsteamblog.com/members/Paul-Cooke/default.aspx</uri></author><category term="Windows Security" scheme="http://windowsteamblog.com/blogs/windowssecurity/archive/tags/Windows+Security/default.aspx" /><category term="Windows 7" scheme="http://windowsteamblog.com/blogs/windowssecurity/archive/tags/Windows+7/default.aspx" /><category term="RSA" scheme="http://windowsteamblog.com/blogs/windowssecurity/archive/tags/RSA/default.aspx" /><category term="AppLocker" scheme="http://windowsteamblog.com/blogs/windowssecurity/archive/tags/AppLocker/default.aspx" /></entry><entry><title>End to End Trust and Windows 7</title><link rel="alternate" type="text/html" href="/blogs/windowssecurity/archive/2009/04/21/end-to-end-trust-and-windows-7.aspx" /><id>/blogs/windowssecurity/archive/2009/04/21/end-to-end-trust-and-windows-7.aspx</id><published>2009-04-21T17:32:00Z</published><updated>2009-04-21T17:32:00Z</updated><content type="html">&lt;p&gt;I attended Scott Charney&amp;rsquo;s keynote this morning at RSA &amp;ndash; &lt;i&gt;Moving Towards End to End Trust: A Collaborative Effort&lt;/i&gt;. I would assume that many of the readers of this blog are not familiar with the End to End Trust story. In a nutshell, End to End trust is Microsoft&amp;rsquo;s vision for creating a safer, more trusted Internet. It&amp;rsquo;s a great vision, but it&amp;rsquo;s also a big job that requires a commitment and focus on the fundamentals&amp;mdash;fundamentals that will help deliver the most secure and privacy-enhanced versions of software and services that we have ever delivered. We&amp;rsquo;re also not going it alone. End to End Trust requires broad collaboration within the industry and Microsoft will continue to share our best practices with the IT communities of our customers.&lt;/p&gt;
&lt;p&gt;Scott talked about how hard we are working across Microsoft to deliver technology innovations that move the needle towards a trusted stack, with security rooted in hardware and an identity metasystem (a big word that means a way of trusting people are who they say they are on the Internet). Even with progress, people still need strong defense in depth security technologies and Scott talked about how Microsoft&amp;rsquo;s Identity and Security Division is delivering integrated identity and security business solutions today to our customers. But maybe the most interesting thing he touched on was how technology innovations alone are not enough. Innovation also needs to align with political, economic and IT forces to enable the change that is truly needed. &lt;/p&gt;
&lt;p&gt;End to End trust is a vision of what&amp;rsquo;s possible if we collectively work together, and it can help address real world problems that people face every day such as ID theft, online fraud and child safety. If you want to learn more about End to End Trust, visit &lt;a href="http://www.microsoft.com/endtoendtrust"&gt;http://www.microsoft.com/endtoendtrust&lt;/a&gt; to find out the entire story. &lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;a href="http://windowsteamblog.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/windowssecurity/Windows7_5F00_h_5F00_rgb_5F00_0EC4F31F.png"&gt;&lt;img height="38" width="240" src="http://windowsteamblog.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/windowssecurity/Windows7_5F00_h_5F00_rgb_5F00_thumb_5F00_5BF4ECAA.png" alt="Windows7_h_rgb" border="0" title="Windows7_h_rgb" style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" /&gt;&lt;/a&gt; &lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Now, let&amp;rsquo;s talk about Windows 7 and the progress we&amp;rsquo;re making to deliver End to End Trust in the Windows platform. In my &lt;a href="http://windowsteamblog.com/blogs/windowssecurity/archive/2009/04/20/windows-7-security-helping-enable-the-mobile-workforce.aspx"&gt;blog post yesterday&lt;/a&gt; on how Windows 7 helps enable the mobile workforce, I wrote about technologies like DirectAccess, BitLocker To Go, and AppLocker. Each of these technologies plays a part in helping us enable End to End Trust, whether it is strong machine and user authentication with DirectAccess or limiting running software on a system to known, trusted applications with AppLocker. But there are other technologies that help us as well:&lt;/p&gt;
&lt;p&gt;&lt;b&gt;Biometric Framework&lt;/b&gt; &lt;br /&gt;Fingerprint scanners are becoming more and more common in standard laptop configurations&amp;mdash;my laptop came standard with one. Windows 7 helps ensure that fingerprint readers work well and that they are easy to set up and use. This is accomplished by taking the common code that everyone needs to write and standardizing it in the platform so that biometric hardware vendors can concentrate on the code they need to write to make their device work and not have to worry about how it ties into Windows. This new framework makes logging on to Windows using a fingerprint more reliable across different hardware providers and makes fingerprint reader configurations are easy to modify. This puts the user in control of how they log on to Windows 7 and manage the fingerprint data stored on their PC.&lt;/p&gt;
&lt;p&gt;&lt;b&gt;Improved Smart Card Support&lt;/b&gt; &lt;br /&gt;Password-based authentication has well-understood security limitations; however, deploying strong authentication technologies like smart cards remains a challenge for many. Windows 7 enhances the smart card infrastructure advances made in Windows Vista through support of Plug and Play. This eases deployment of smart card infrastructures because drivers for both smart cards and smart card readers are automatically installed, without the need for administrative permissions or user interaction. I think this new behavior is going to ease the deployment of strong, two-factor authentication for many organizations.&lt;/p&gt;
&lt;p&gt;&lt;b&gt;BitLocker &lt;br /&gt;&lt;/b&gt;I&amp;rsquo;m a big fan of BitLocker, it helps prevent a thief who boots another operating system or runs a software hacking tool from breaking into my laptop if they happen to get a hold of it. This holds true for both the operating system volume (C: drive) and my data volume (D: drive). Most customers I talk to love the encryption protection that BitLocker provides, but many are not aware that BitLocker also does integrity checking of early boot components to help ensure that the system has not been tampered with and that the encrypted drive has not been swapped out to another computer. This integrity checking ties back into the &amp;ldquo;security rooted in hardware&amp;rdquo; that is a part of End to End Trust. This integrity checking utilizes a Trusted Platform Module (a smart card like chip on the system motherboard) to help protect the encryption keys utilized by BitLocker. This is true for BitLocker in Windows 7 as well as Windows Vista.&lt;/p&gt;
&lt;p&gt;We&amp;rsquo;ve also listened to feedback and made enhancements to Windows 7 BitLocker to provide a better experience for IT Pros and for end users. One of the simple enhancements we made is to right-click enable the BitLocker protection of a disk volume. Now I can go to Windows Explorer and right click any disk volume, including my removable BitLocker To Go volumes, and encrypt them right there without having to go to the Control Panel. &lt;/p&gt;
&lt;p&gt;Another big change was the addition of Data Recovery Agent (DRA) support for all protected volumes. The DRA is a certificate-based data recovery agent that can be utilized to recover the contents of any BitLocker protected volume. Since the group policy settings are separate for Operating System Drives, Fixed Data Drives, and Removable Data Drives, customers have flexibility in how they want to configure their recovery options for the different threats that each separate drive type may experience. &lt;/p&gt;
&lt;p&gt;With BitLocker and BitLocker To Go, enterprises can rest assured that their information and data is secure, no matter where their employees are working. I know I feel better knowing my laptop and all of my USB sticks are protected!&lt;/p&gt;
&lt;p&gt;&lt;b&gt;Internet Explorer 8&lt;/b&gt;&lt;/p&gt;
&lt;p&gt;I know folks are more concerned than ever about protecting themselves while online, particularly form identity theft, malware, and other potentially dangerous online threats. I feel like we have done a lot in the platform and the security technologies we have been talking about this week (Firewall, DirectAccess, BitLocker To Go and AppLocker) are a part of the protection equation. But Internet Explorer 8 is also another huge piece of the equation as users spend more time online, in their browsers. IE 8 is the most secure web browser on the market and provides another, vital layer of defense against online threats.&lt;/p&gt;
&lt;p&gt;We built upon the phishing protection in Internet Explorer 7 with the SmartScreen Filter, which now adds protection from malware &amp;ndash; a threat that is growing significantly faster than phishing.&lt;/p&gt;
&lt;p&gt;We also built in support for protecting users against type-1 (or &amp;ldquo;reflection) Cross-Site Scripting (XSS) attacks. XSS threats try to exploit vulnerabilities in the websites we visit and are quickly becoming one of the most prevalent ways web sites can be compromised. The bad news for you and I is that an XSS attack can help a bad guy steal our usernames and passwords for our online bank accounts or other confidential information. The XSS filter in IE 8 uses heuristics to detect such attacks and, when they are detected, prevent their execution. This should help you and I safe from the most common form of XSS attacks in use today.&lt;/p&gt;
&lt;p&gt;Another innovation concerns ClickJacking. While a lot or people have heard of phishing attacks, a new kind of phishing attack called ClickJacking is on the rise. ClickJacking occurs where an attacker&amp;rsquo;s web page deceives a person into clicking on content from another website without realizing it &amp;ndash; so they&amp;rsquo;re clicking on something that, for instance, buys something from the site, changes settings on their browser, or provides advertisements that these cybercriminals get paid for. ClickJacking Protection in IE is a feature that allows Web site content owners to put a tag in a page header that will help prevent ClickJacking. &lt;/p&gt;
&lt;p&gt;I think the IE team has done a great job with the security in IE 8 and love that it puts people in control of their safety and privacy and helps protect them from new online threats. For those of you who are interested, there is a lot more security goodness in IE 8 on the &lt;a href="http://blogs.msdn.com/ie/"&gt;IE blog&lt;/a&gt; and via these links:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="http://blogs.msdn.com/ie/archive/2008/04/08/ie8-security-part-I_3A00_-dep-nx-memory-protection.aspx"&gt;IE8 Security Part I: DEP/NX Memory Protection&lt;/a&gt; &lt;/li&gt;
&lt;li&gt;&lt;a href="http://blogs.msdn.com/ie/archive/2008/05/07/ie8-security-part-ii-activex-improvements.aspx"&gt;IE8 Security Part II: ActiveX Improvements&lt;/a&gt; &lt;/li&gt;
&lt;li&gt;&lt;a href="http://blogs.msdn.com/ie/archive/2008/07/02/ie8-security-part-iii-smartscreen-filter.aspx"&gt;IE8 Security Part III: SmartScreen&amp;reg; Filter&lt;/a&gt; &lt;/li&gt;
&lt;li&gt;&lt;a href="http://blogs.msdn.com/ie/archive/2008/07/02/ie8-security-part-iv-the-xss-filter.aspx"&gt;IE8 Security Part IV: The XSS Filter&lt;/a&gt; &lt;/li&gt;
&lt;li&gt;&lt;a href="http://blogs.msdn.com/ie/archive/2008/07/02/ie8-security-part-v-comprehensive-protection.aspx"&gt;IE8 Security Part V: Comprehensive Protection&lt;/a&gt; &lt;/li&gt;
&lt;li&gt;&lt;a href="http://blogs.msdn.com/ie/archive/2008/09/02/ie8-security-part-vi-beta-2-update.aspx"&gt;IE8 Security Part VI: Beta 2 Update&lt;/a&gt; &lt;/li&gt;
&lt;li&gt;&lt;a href="http://blogs.msdn.com/ie/archive/2009/01/27/ie8-security-part-vii-clickjacking-defenses.aspx"&gt;IE8 Security Part VII: ClickJacking Defenses&lt;/a&gt; &lt;/li&gt;
&lt;li&gt;&lt;a href="http://blogs.msdn.com/ie/archive/2009/02/09/ie8-security-part-viii-smartscreen-filter-release-candidate-update.aspx"&gt;IE8 Security Part VIII: SmartScreen Filter Release Candidate Update&lt;/a&gt; &lt;/li&gt;
&lt;li&gt;&lt;a href="http://blogs.msdn.com/ie/archive/2009/03/25/ie8-security-part-ix-anti-malware-protection-with-ie8-s-smartscreen-filter.aspx"&gt;IE8 Security Part IX - Anti-Malware protection with IE8&amp;rsquo;s SmartScreen Filter&lt;/a&gt; &lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Got To Run&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;I feel great about Windows 7 and the security enhancements we have been able to make. Hopefully as you learn more about the security work that we have put into it, you will reach the same conclusion that I have: Windows 7 is the most robust platform we have ever delivered, it helps support End to End trust, helps keep you and I safe, and was designed to prevent malware from getting onto our PCs to begin with.&lt;/p&gt;
&lt;p&gt;There is a lot going on here at RSA and I want to go spend some more time seeing what&amp;rsquo;s new and exciting. I&amp;rsquo;ll be back with some of my impressions of RSA in a bit.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://windowsteamblog.com/aggbug.aspx?PostID=512016" width="1" height="1"&gt;</content><author><name>Paul Cooke</name><uri>http://windowsteamblog.com/members/Paul-Cooke/default.aspx</uri></author><category term="Security" scheme="http://windowsteamblog.com/blogs/windowssecurity/archive/tags/Security/default.aspx" /><category term="RSA" scheme="http://windowsteamblog.com/blogs/windowssecurity/archive/tags/RSA/default.aspx" /><category term="Clickjacking" scheme="http://windowsteamblog.com/blogs/windowssecurity/archive/tags/Clickjacking/default.aspx" /><category term="Windows Biometric Framework" scheme="http://windowsteamblog.com/blogs/windowssecurity/archive/tags/Windows+Biometric+Framework/default.aspx" /><category term="SmartScreen" scheme="http://windowsteamblog.com/blogs/windowssecurity/archive/tags/SmartScreen/default.aspx" /><category term="Smart Card" scheme="http://windowsteamblog.com/blogs/windowssecurity/archive/tags/Smart+Card/default.aspx" /><category term="End to End Trust" scheme="http://windowsteamblog.com/blogs/windowssecurity/archive/tags/End+to+End+Trust/default.aspx" /><category term="Internet Explorer 8" scheme="http://windowsteamblog.com/blogs/windowssecurity/archive/tags/Internet+Explorer+8/default.aspx" /><category term="BitLocker" scheme="http://windowsteamblog.com/blogs/windowssecurity/archive/tags/BitLocker/default.aspx" /><category term="Biometrics" scheme="http://windowsteamblog.com/blogs/windowssecurity/archive/tags/Biometrics/default.aspx" /></entry><entry><title>Windows 7 Security: Helping Enable the Mobile Workforce</title><link rel="alternate" type="text/html" href="/blogs/windowssecurity/archive/2009/04/20/windows-7-security-helping-enable-the-mobile-workforce.aspx" /><id>/blogs/windowssecurity/archive/2009/04/20/windows-7-security-helping-enable-the-mobile-workforce.aspx</id><published>2009-04-20T19:15:24Z</published><updated>2009-04-20T19:15:24Z</updated><content type="html">&lt;p&gt;Along with 17,000+ other security- minded professionals, I’m at RSA in San Francisco this week. For those who are not familiar with the RSA Conference, it’s the premier information security conference of the year. It attracts the best and brightest security folks from around the world. In addition, it is a great place to keep up with what’s going on in the information security marketplace. I’m at RSA to not only see what’s going on in the industry, but to also talk about some of the cool new security features in Windows 7.&lt;/p&gt;  &lt;p&gt;We’re really excited about Windows 7’s new security features. This next OS is built upon the proven security technologies in Windows Vista and provides a fundamentally secure computing platform. We not only utilized enhanced Security Development Lifecycle (SDL) process during planning, development and testing but we also have worked to make the security features more discoverable, usable and manageable. These enhancements give Windows 7 the expanded security offerings to provide the necessary security controls to help mobile workers access the information they need to be productive, wherever and whenever they need it.&lt;/p&gt;  &lt;p&gt;There is a lot of new stuff in Windows 7, but let me highlight some of those things that go into helping the mobile worker…&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Multiple Active Firewall Policies&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;In Windows Vista, firewall policy is based on the “type” of network connection established—such as Home, Work, Public, or Domain (the fourth, hidden type.) This can be a security problem for IT professionals since mobile users will connect to multiple networks while on the road. For example, let’s say I get connected to the Internet through a “Public” network. As a result, the “Public” firewall policy is applied to the computer. Now, if I want to connect to the Microsoft corporate network via my VPN, the IT configured firewall settings for accessing the “Domain” corporate network cannot be applied because the first network type (and thus the firewall settings) had already been set.&lt;/p&gt;  &lt;p&gt;Windows 7 gets rid of this IT pain through support for multiple active firewall policies. This enables my PC to obtain and apply domain firewall profile information regardless of other networks that may be active on the PC. Now IT Pros can simplify connectivity and security policies by maintaining a single set of rules for both remote clients and clients that are physically connected to the corporate network and know that the rules are appropriately applied.&lt;/p&gt;  &lt;p&gt;&lt;/p&gt;  &lt;p&gt;&lt;/p&gt;  &lt;p&gt;&lt;a href="http://windowsteamblog.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/windowssecurity/image_5F00_5A3BE415.png"&gt;&lt;img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="image" border="0" alt="image" src="http://windowsteamblog.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/windowssecurity/image_5F00_thumb_5F00_3A031C6F.png" width="350" height="301" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;DirectAccess&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;When I travel or am day-extending by working from home, I tend to need a lot of access to the corporate Intranet. As you can imagine, we use SharePoint a lot and a large number of our Line of Business applications are all Web- enabled. The result: I have to use our corporate VPN a lot. Unfortunately, it’s always an interruption for me to stop what I am doing and to fire up my VPN connection.&lt;/p&gt;  &lt;p&gt;Windows 7 works in conjunction with Windows Server 2008 R2 to make working outside of the office simpler and less frustrating with DirectAccess. DirectAccess works by automatically establishing a bi-directional connection from client computers to the corporate network. As a result, as a remote user I have seamless, secure access to the corporate network anytime I am connected to the Internet, without having to manually initiate a traditional VPN connection. This helps make me more productive and allows me to focus on my work and not the remote access technology. Now whenever and wherever I travel, I can not only access my corporate email, but also open Intranet sites, shared drives, use line-of-business applications, and have full access to corporate resources that I need to do my job without having to manually create my VPN tunnel.&lt;/p&gt;  &lt;p&gt;From a security perspective, DirectAccess is built on a foundation of proven, standards-based technologies like IPv6 and IPSec. IPsec is utilized to authenticate both the computer and user. This allows IT the capability to manage the computer even before I log on. IT can also optionally require me to authenticate with a smart card. IPsec is also utilized to provide encryption for communications across the Internet with encryption algorithms such as AES.&lt;/p&gt;  &lt;p&gt;DirectAccess also has a cool benefit for IT Pros as well, since it provides an always on, secure mechanism to remotely manage and update the PCs of their mobile workforce. Whenever my laptop has Internet connectivity it is directly connected to the Microsoft corporate network. This gives IT more opportunity to distribute software updates and policies to me and other mobile workers and helps keep our machines free of malware and other unwanted software.&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;BranchCache&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;DirectAccess is great for the mobile worker, but what about the remote worker who works out in a branch office location? I’ve worked in many a branch office and the one thing they all seem to have in common is limited network bandwidth. Accessing large files in a branch office is always a slow, frustrating affair for me. I, like most users, prefer a snappy network and quick downloads. All the waiting that I have to do-- or you have to do -- is just lost productivity that, at the end of the day, can hurt the company’s bottom line.&lt;/p&gt;  &lt;p&gt;Windows 7 incorporates BranchCache, another technology that works in conjunction with Windows Server 2008 R2, which helps make network responsiveness of applications and data housed within your data center feel snappy. This gives users in remote, branch offices the experience of working as if they were on the local area network (LAN) of the server they are accessing.&lt;/p&gt;  &lt;p&gt;BranchCache also helps reduce the utilization of the wide area network (WAN). When BranchCache is enabled, a copy of any data accessed from Intranet Web sites and/or file servers is cached locally within the branch office. When another client on the same network requests the file, the client downloads it from the local cache without downloading the same content across the WAN.&lt;/p&gt;  &lt;p&gt;The key thing for me is that it makes access to static data quick and it is all done without decreasing the security of that data. Access controls are enforced on cached files in the same way they are on original files.&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;BitLocker To Go&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;While here at RSA, it is inevitable that I will need to share data with one of my trusted partners or customers. My primary method of transferring data is to use one of the half dozen or so USB sticks I carry around in my backpack. Over time, these USB sticks end up with all sorts of different data and documents on them. As a security guy, I worry about what would happen if I lost one of these USB sticks. What if I have some confidential or customer data on one of them?&lt;/p&gt;  &lt;p&gt;Windows 7 helps address the continued threat of data leakage with introduction of &lt;b&gt;BitLocker To Go&lt;/b&gt;: an extension to BitLocker in Windows Vista that allows me to encrypt the disk volume of removable storage devices with a password and/or a digital certificate stored on a smart card. &lt;/p&gt;  &lt;p&gt;BitLocker To Go was designed to facilitate the secure sharing of data on removable storage devices and was designed to work on any standard removable storage device. No special, proprietary hardware is required. So now, whether you are traveling with your laptop, sharing large files with a trusted partner, or taking work home, you can feel secure that your data is safe. Both traditional BitLocker and BitLocker To Go protected devices help ensure that only authorized users can read the data, even if the media is lost, stolen, or misused.&lt;/p&gt;  &lt;p&gt;One last thing worth mentioning -- I can use BitLocker To Go to share data with a Windows user who is running Windows Vista or Windows XP through the BitLocker To Go Reader. This application is installed by default on removable storage volumes and allows read-only access on older versions of Windows while still allowing you to help protect your USB sticks.&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;AppLocker&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;While I feel good about protecting my data with BitLocker in case it is lost or stolen, data can still be lost due to malware or other unwanted software. When I talk to customers about keeping malware off of their systems, we always end up talking about desktop lockdown and the first topic of desktop lockdown is always removing administrative access from a majority of users. This is a great first step for any organization to take; however, workers today bring software from home, download applications from the Internet (intentional and unintentional), and access new programs through email. Many of these applications don’t need system- wide, administrative access to install or run. The result is a higher incidence of malware infections, more help desk calls, and difficulty in ensuring that only approved, licensed software is installed and utilized.&lt;/p&gt;  &lt;p&gt;Windows 7 has a new application control solution in AppLocker. AppLocker gives control back to IT administrators and helps them eliminate unknown and unwanted software in their environment. AppLocker can be configured through Group Policy and can help manage those applications that run on corporate PCs, helping keep your organization’s data safe and your enterprise PCs manageable. AppLocker works by intercepting kernel calls that try to create new processes or load libraries and making sure that the code in question has been allowed to execute.&lt;/p&gt;  &lt;p&gt;&lt;a href="http://windowsteamblog.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/windowssecurity/image_5F00_3B673F41.png"&gt;&lt;img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="image" border="0" alt="image" src="http://windowsteamblog.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/windowssecurity/image_5F00_thumb_5F00_3A916A08.png" width="350" height="402" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;AppLocker just might be my favorite security feature in Windows 7, for it not only provides security protections but as an ex-IT Pro I really appreciate the operational and compliance benefits as well. Things like:&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;Keeping unlicensed, vulnerable software from running in the desktop environment, including stopping workers from running applications that needlessly use consumer network bandwidth or otherwise impact the enterprise computing environment. &lt;/li&gt;    &lt;li&gt;Easing enterprise software deployments and maintenance through effective desktop configuration management. &lt;/li&gt;    &lt;li&gt;AppLocker allows users to install and run approved applications and software updates based upon their business needs. &lt;/li&gt;    &lt;li&gt;Helping ensure a company’s desktop environment is in compliance with corporate policies and industry regulations such as PCI DSS, Sarbanes-Oxley, HIPAA, Basel II, and others. &lt;/li&gt; &lt;/ul&gt;  &lt;p&gt;&lt;strong&gt;More to Come&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;This is just a small part of what’s in Windows 7 from a security perspective, and just the tip of the iceberg for the features I’ve described. Stay tuned for more information on what’s going on at RSA and more information on the cool new security technologies in Windows.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://windowsteamblog.com/aggbug.aspx?PostID=511967" width="1" height="1"&gt;</content><author><name>Paul Cooke</name><uri>http://windowsteamblog.com/members/Paul-Cooke/default.aspx</uri></author><category term="Announcement" scheme="http://windowsteamblog.com/blogs/windowssecurity/archive/tags/Announcement/default.aspx" /><category term="Security" scheme="http://windowsteamblog.com/blogs/windowssecurity/archive/tags/Security/default.aspx" /><category term="AES" scheme="http://windowsteamblog.com/blogs/windowssecurity/archive/tags/AES/default.aspx" /><category term="DirectAccess" scheme="http://windowsteamblog.com/blogs/windowssecurity/archive/tags/DirectAccess/default.aspx" /><category term="RSA" scheme="http://windowsteamblog.com/blogs/windowssecurity/archive/tags/RSA/default.aspx" /><category term="BranchCache" scheme="http://windowsteamblog.com/blogs/windowssecurity/archive/tags/BranchCache/default.aspx" /><category term="VPN" scheme="http://windowsteamblog.com/blogs/windowssecurity/archive/tags/VPN/default.aspx" /><category term="Windows Server 2008 R2" scheme="http://windowsteamblog.com/blogs/windowssecurity/archive/tags/Windows+Server+2008+R2/default.aspx" /><category term="AppLocker" scheme="http://windowsteamblog.com/blogs/windowssecurity/archive/tags/AppLocker/default.aspx" /><category term="Security Development Lifecycle" scheme="http://windowsteamblog.com/blogs/windowssecurity/archive/tags/Security+Development+Lifecycle/default.aspx" /><category term="BitLocker to Go" scheme="http://windowsteamblog.com/blogs/windowssecurity/archive/tags/BitLocker+to+Go/default.aspx" /><category term="IPSec" scheme="http://windowsteamblog.com/blogs/windowssecurity/archive/tags/IPSec/default.aspx" /></entry><entry><title>Now Available - Microsoft Security Intelligence Report</title><link rel="alternate" type="text/html" href="/blogs/windowssecurity/archive/2009/04/08/now-available-microsoft-security-intelligence-report.aspx" /><id>/blogs/windowssecurity/archive/2009/04/08/now-available-microsoft-security-intelligence-report.aspx</id><published>2009-04-08T19:18:00Z</published><updated>2009-04-08T19:18:00Z</updated><content type="html">&lt;p&gt;I got into the office this morning and noticed that&amp;nbsp;volume six of the &lt;a target="_blank" href="http://www.microsoft.com/security/portal/sir.aspx" title="Microsoft Security Intelligence Report"&gt;Microsoft Security Intelligence Report&lt;/a&gt; (SIRv6) was released earlier today. For those of you who are not familiar with the report, the SIR is published by Microsoft twice per year. Each volume of the SIR looks at the data and trends observed in the first and second halves of each calendar year with a focus on malware data, software vulnerability disclosure data, vulnerability exploit data, and related trends.&lt;/p&gt;
&lt;p&gt;A trend that the SIR calls out right up front was around rogue security software. The second half of 2008 saw a clear rise in prevalence of rogue security software (software which poses as&amp;nbsp; anti-malware or anti-spyware protection but in reality does little or nothing, and may even be malware!). While I knew the issue was out there and even had to help a good friend clean his system after being duped, the rise was eye-opening for me. &lt;strong&gt;The take away:&amp;nbsp; be careful out there!&lt;/strong&gt; Get your software from a trusted source and keep it up-to-date with the latest Windows Updates. Be cautious not to follow advertisements for unknown software that pretends to provide protection. Access the sites of reputable vendors directly for information or subscription to their products and services.&lt;/p&gt;
&lt;p&gt;Another piece of data I that I wanted to pass along deals with the infection rates of Windows, as shown in the graph below:&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;img src="http://windowsteamblog.com/cfs-file.ashx/__key/CommunityServer.Components.PostAttachments/00.00.51.14.75/MSRT-Cleanings.bmp" /&gt;&lt;/p&gt;
&lt;p&gt;What this graph tells me is that the infection rate for Windows Vista is significantly lower than that of its predecessor, Windows XP, in all configurations. It also tells me that the higher the service pack level of an OS, the lower the infection rate. Once again, this really points out that you need to keep your software up-to-date!&lt;/p&gt;
&lt;p&gt;I encourage you to download the full report and hope that you find the data, insights, and guidance provided in the SIR useful in helping you understand today&amp;rsquo;s threat landscape and ultimately help you protect your networks and users.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://windowsteamblog.com/aggbug.aspx?PostID=511474" width="1" height="1"&gt;</content><author><name>Paul Cooke</name><uri>http://windowsteamblog.com/members/Paul-Cooke/default.aspx</uri></author><category term="Announcement" scheme="http://windowsteamblog.com/blogs/windowssecurity/archive/tags/Announcement/default.aspx" /><category term="Security" scheme="http://windowsteamblog.com/blogs/windowssecurity/archive/tags/Security/default.aspx" /><category term="IT Pro" scheme="http://windowsteamblog.com/blogs/windowssecurity/archive/tags/IT+Pro/default.aspx" /><category term="Windows" scheme="http://windowsteamblog.com/blogs/windowssecurity/archive/tags/Windows/default.aspx" /><category term="SIR" scheme="http://windowsteamblog.com/blogs/windowssecurity/archive/tags/SIR/default.aspx" /></entry><entry><title>Data Privacy Day</title><link rel="alternate" type="text/html" href="/blogs/windowssecurity/archive/2009/01/28/data-privacy-day.aspx" /><id>/blogs/windowssecurity/archive/2009/01/28/data-privacy-day.aspx</id><published>2009-01-28T20:00:00Z</published><updated>2009-01-28T20:00:00Z</updated><content type="html">&lt;p&gt;As a security guy, I get all sorts of questions from people about privacy. A lot of folks really think about online privacy as the same thing as computer security. Others see it as a pure tradeoff between one or the other. I don&amp;rsquo;t necessarily think that giving up privacy results in greater security; nor do I believe that greater security requires a loss of privacy. No matter what your thoughts are on security and privacy, I hope there is one thing we can all agree on: both are important.&lt;/p&gt;
&lt;p&gt;That&amp;rsquo;s why I&amp;rsquo;m glad to report that Microsoft, along with other key players in the safety ecosystem, is once again participating in today&amp;rsquo;s global event, Data Privacy Day. A lot of you have probably never heard of Data Privacy Day, so here&amp;rsquo;s the skinny: it is a day intended to increase awareness of privacy and data protection issues that we all face. I&amp;rsquo;m proud of Microsoft&amp;rsquo;s commitment to protecting consumer privacy, and on a personal level, I&amp;rsquo;m happy to have been involved in campaigns promoting child safety and preventing identity theft. &lt;/p&gt;
&lt;p&gt;I&amp;rsquo;m also proud of our work on Windows Vista. It&amp;rsquo;s built and tested to allow users to connect to whomever and whatever they want while providing the confidence that personal information is safe. The Windows Security Center in Windows XP SP2 and Windows Vista is one of the innovative tools that helps protects users from security risks. The program informs users if key security capabilities are turned on and updated and if a problem is detected, customers receive a notification and are given recommended actions to help protect their information. IE Protected Mode in Windows Vista also helps protect users from attack by running the Internet Explorer process with greatly restricted privileges. Protected Mode significantly reduces the ability of an attack to write, alter, or destroy data on the user&amp;#39;s machine or to install malicious code. These are just a few of the ways that Microsoft is working to keep its customers safe. We are also continuing our commitment to security in Windows 7 by building upon the strong foundation created in Windows Vista.&lt;/p&gt;
&lt;p&gt;Like me, many of us at Microsoft are passionate about helping to ensure that you have the safest, most secure computing experience possible. If you&amp;rsquo;re passionate about online safety or if you just want to learn more about the topic, check out the &lt;a href="http://www.microsoft.com/security/privacy/default.mspx"&gt;Data Privacy Day 2009 website&lt;/a&gt; to see how we&amp;rsquo;re working to raise awareness about online privacy and safety issues.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://windowsteamblog.com/aggbug.aspx?PostID=508809" width="1" height="1"&gt;</content><author><name>Paul Cooke</name><uri>http://windowsteamblog.com/members/Paul-Cooke/default.aspx</uri></author><category term="Announcement" scheme="http://windowsteamblog.com/blogs/windowssecurity/archive/tags/Announcement/default.aspx" /><category term="Security" scheme="http://windowsteamblog.com/blogs/windowssecurity/archive/tags/Security/default.aspx" /></entry><entry><title>BitLocker on TechNet Radio</title><link rel="alternate" type="text/html" href="/blogs/windowssecurity/archive/2009/01/23/bitlocker-on-technet-radio.aspx" /><id>/blogs/windowssecurity/archive/2009/01/23/bitlocker-on-technet-radio.aspx</id><published>2009-01-23T19:00:00Z</published><updated>2009-01-23T19:00:00Z</updated><content type="html">&lt;p&gt;Not sure how many of you are familiar wtih TechNet Radio, but I did a piece for them the other day that I encourage you to go check out. It&amp;#39;s a quick interview on BitLocker Drive Encryption. In it, I get asked about BitLocker not only in Windows Vista, but also around some of the changes we have made in Windows 7. Take a listen to the interview below and trust me, we will have more on the new Windows 7 security features coming shortly...&lt;/p&gt;
&lt;p&gt;TechNet Radio - BitLocker Drive Encryption&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;div style="padding-left:30px;"&gt;&lt;a href="http://download.microsoft.com/download/7/B/0/7B0F2457-C2D0-41B4-BA16-A4D648C615C2/TechNetRadio-01202009-web.wma" title="WMA Format"&gt;WMA Format&lt;/a&gt;&lt;/div&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;div style="padding-left:30px;"&gt;&lt;a href="http://download.microsoft.com/download/7/B/0/7B0F2457-C2D0-41B4-BA16-A4D648C615C2/TechNetRadio-01202009-hi-web.mp3" title="MP3 - Hi Bandwidth"&gt;MP3 - Hi Bandwidth&lt;/a&gt; &lt;/div&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;div style="padding-left:30px;"&gt;&lt;a href="http://download.microsoft.com/download/7/B/0/7B0F2457-C2D0-41B4-BA16-A4D648C615C2/TechNetRadio-01202009-lo-web.mp3" title="MP3 - Low Bandwidth"&gt;MP3 - Low Bandwidth&lt;/a&gt;&lt;/div&gt;
&lt;/li&gt;
&lt;/ul&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://windowsteamblog.com/aggbug.aspx?PostID=508369" width="1" height="1"&gt;</content><author><name>Paul Cooke</name><uri>http://windowsteamblog.com/members/Paul-Cooke/default.aspx</uri></author><category term="Windows Vista" scheme="http://windowsteamblog.com/blogs/windowssecurity/archive/tags/Windows+Vista/default.aspx" /><category term="Security" scheme="http://windowsteamblog.com/blogs/windowssecurity/archive/tags/Security/default.aspx" /><category term="Windows Security" scheme="http://windowsteamblog.com/blogs/windowssecurity/archive/tags/Windows+Security/default.aspx" /><category term="Windows" scheme="http://windowsteamblog.com/blogs/windowssecurity/archive/tags/Windows/default.aspx" /><category term="Windows 7" scheme="http://windowsteamblog.com/blogs/windowssecurity/archive/tags/Windows+7/default.aspx" /></entry><entry><title>Secure Your Windows and Office 2007 Installations</title><link rel="alternate" type="text/html" href="/blogs/windowssecurity/archive/2008/12/15/secure-your-windows-and-office-2007-installations.aspx" /><id>/blogs/windowssecurity/archive/2008/12/15/secure-your-windows-and-office-2007-installations.aspx</id><published>2008-12-15T22:20:00Z</published><updated>2008-12-15T22:20:00Z</updated><content type="html">&lt;p&gt;I noticed over the weekend that Microsoft&amp;#39;s Solution Accelerator team has just released a Beta of Project Codename Sundance. This Solution Accelerator builds on previous Microsoft security guidance and is aimed at helping you configure and deploy security settings for both Windows and Office 2007. With more than 700 security setting recommendations, the guidance and tools included should help fine-tune the security posture of your Windows and Office 2007 deployments. &lt;/p&gt;
&lt;p&gt;After deploying the security settings, you can even verify the settings and monitor policy changes by using one or more of 18 new configuration packs designed for the Desired Configuration Management (DCM) feature of Microsoft System Center Configuration Manager 2007.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;img src="http://windowsteamblog.com/cfs-file.ashx/__key/CommunityServer.Components.PostAttachments/00.00.50.43.21/Sundance.jpg" alt="" /&gt;&lt;/p&gt;
&lt;p&gt;This solution accelerator can help you in a number of ways:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;b&gt;Accelerate and secure deployments&lt;/b&gt;&lt;br /&gt;Predefined templates and automated tools enable you to greatly reduce the time required to deploy security settings and monitor security baselines.&lt;/li&gt;
&lt;li&gt;&lt;b&gt;Provide higher reliability&lt;/b&gt;&lt;br /&gt;Eliminate a number of manual steps and get faster, more reliable security results.&lt;/li&gt;
&lt;li&gt;&lt;b&gt;Comprehensive solution&lt;/b&gt;&lt;br /&gt;Includes information about hundreds of security and privacy setting options, as well as recommendations for each one based on best practices.&lt;/li&gt;
&lt;li&gt;&lt;b&gt;Manage risk&lt;/b&gt;&lt;br /&gt;Manage security setting changes in Windows operating systems and Office applications that otherwise could place the integrity of your IT systems at risk.&lt;/li&gt;
&lt;li&gt;&lt;b&gt;Right Price&lt;/b&gt;&lt;br /&gt;It&amp;#39;s free from Microsoft Connect.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;I invite you to join the Beta Program for Project Codename Sundance and take a look at how it might help you secure your Windows and Office 2007 installations.&lt;/p&gt;
&lt;p&gt;To join the Beta Program for Project Codename Sundance, please click on the following link:&lt;br /&gt;&lt;a href="https://connect.microsoft.com/InvitationUse.aspx?ProgramID=2682&amp;amp;InvitationID=SUN-698V-PYJF&amp;amp;SiteID=715"&gt;https://connect.microsoft.com/InvitationUse.aspx?ProgramID=2682&amp;amp;InvitationID=SUN-698V-PYJF&amp;amp;SiteID=715&lt;/a&gt; &lt;/p&gt;
&lt;p&gt;After you have joined the program, add the following link to your favorites&lt;br /&gt;&lt;a href="https://connect.microsoft.com/site/sitehome.aspx?SiteID=715"&gt;https://connect.microsoft.com/site/sitehome.aspx?SiteID=715&lt;/a&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;[Edited on 12/17/2008 to provide best user experience for beta program links.]&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://windowsteamblog.com/aggbug.aspx?PostID=504319" width="1" height="1"&gt;</content><author><name>Paul Cooke</name><uri>http://windowsteamblog.com/members/Paul-Cooke/default.aspx</uri></author><category term="Announcement" scheme="http://windowsteamblog.com/blogs/windowssecurity/archive/tags/Announcement/default.aspx" /><category term="Security" scheme="http://windowsteamblog.com/blogs/windowssecurity/archive/tags/Security/default.aspx" /><category term="Solution Accelerator" scheme="http://windowsteamblog.com/blogs/windowssecurity/archive/tags/Solution+Accelerator/default.aspx" /><category term="IT Pro" scheme="http://windowsteamblog.com/blogs/windowssecurity/archive/tags/IT+Pro/default.aspx" /><category term="Office" scheme="http://windowsteamblog.com/blogs/windowssecurity/archive/tags/Office/default.aspx" /><category term="Windows" scheme="http://windowsteamblog.com/blogs/windowssecurity/archive/tags/Windows/default.aspx" /></entry></feed>