<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" media="screen" href="/styles/xslt/rss.xslt"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:trackback="http://madskills.com/public/xml/rss/module/trackback/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:media="http://search.yahoo.com/mrss/" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:c9="http://channel9.msdn.com">
<channel>
	<title>Comment Feed for Channel 9 - Michael Howard - When does threat modeling come into play?</title>
	<atom:link rel="self" type="application/rss+xml" href="http://channel9.msdn.com/Blogs/TheChannel9Team/Michael-Howard-When-does-threat-modeling-come-into-play/RSS"></atom:link>
	<image>
		<url>http://mschnlnine.vo.llnwd.net/d1/Dev/App_Themes/C9/images/feedimage.png</url>
		<title>Channel 9 - Michael Howard - When does threat modeling come into play?</title>
		<link></link>
	</image>
	<description>Michael Howard, program manager on Microsoft&#39;s security team, discusses how the Internet Explorer team used threat modeling to reduce the attack surface of its software.</description>
	<link></link>
	<language>en</language>
	<pubDate>Tue, 18 Jun 2013 23:33:22 GMT</pubDate>
	<lastBuildDate>Tue, 18 Jun 2013 23:33:22 GMT</lastBuildDate>
	<generator>Rev9</generator>
	<item>
		<title>Re: Michael Howard - When does threat modeling come into play?</title>
		<description>
			<![CDATA[Very interesting presentation.&nbsp; I really like how he presents an example of how one group works together with another, the W2K03 group, to address issues preemptively.&nbsp;
<br>
<br>
I have always worked under the assumption that you don't browse from any server, much less a DC.&nbsp; But as Michael points out, you have to throw out all those assumptions and work in a &quot;worst case scenario&quot; frame of mind in order to build better and more secure
 apps.<p>posted by cmchavez</p>]]>
		</description>
		<link>http://channel9.msdn.com/Blogs/TheChannel9Team/Michael-Howard-When-does-threat-modeling-come-into-play#c632169786500000000</link>
		<pubDate>Wed, 07 Apr 2004 23:50:50 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Blogs/TheChannel9Team/Michael-Howard-When-does-threat-modeling-come-into-play#c632169786500000000</guid>
		<dc:creator>cmchavez</dc:creator>
	</item>
	<item>
		<title>Re: Michael Howard - When does threat modeling come into play?</title>
		<description>
			<![CDATA[
<p>I agree that browsing the internet on a DC or any other server is something you just don't do. And implementing a high security default in&nbsp;IE is certainly a good way to lower the risk of it, but why not go all the way and disable&nbsp;internet access via IE (or
 any other browser) on server systems&nbsp;completely? No &quot;good admin&quot; would use it anyway and it certainly would make life easier for those companies whose admins&nbsp;do.</p>
<p>posted by Fox</p>]]>
		</description>
		<link>http://channel9.msdn.com/Blogs/TheChannel9Team/Michael-Howard-When-does-threat-modeling-come-into-play#c632170076160000000</link>
		<pubDate>Thu, 08 Apr 2004 07:53:36 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Blogs/TheChannel9Team/Michael-Howard-When-does-threat-modeling-come-into-play#c632170076160000000</guid>
		<dc:creator>Fox</dc:creator>
	</item>
	<item>
		<title>Re: Michael Howard - When does threat modeling come into play?</title>
		<description>
			<![CDATA[Fox:<br>
&nbsp;&nbsp;&nbsp;I agree in priciple w/ your comments.&nbsp; A &quot;good admin&quot; should never surf the internet.&nbsp; But the point of turning on all those settings is to mitigate any potenial security leaks while still keeping basic functionality.&nbsp; Plus adding the ability to remove the
 security if the admin so desires.&nbsp; Security is by it's very nature a battle between functionality and safety with a delicate balance being redefined continiously.<br>
<br>
I felt the presentation was a little cursory overall and stated a lot of obvious and uninteresting points.&nbsp; I wonder how much prep work goes into each of these interviews...both by the interviewer and interviewee<p>posted by danhopkins</p>]]>
		</description>
		<link>http://channel9.msdn.com/Blogs/TheChannel9Team/Michael-Howard-When-does-threat-modeling-come-into-play#c632170340390000000</link>
		<pubDate>Thu, 08 Apr 2004 15:13:59 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Blogs/TheChannel9Team/Michael-Howard-When-does-threat-modeling-come-into-play#c632170340390000000</guid>
		<dc:creator>danhopkins</dc:creator>
	</item>
	<item>
		<title>Re: Michael Howard - When does threat modeling come into play?</title>
		<description>
			<![CDATA[&quot;I felt the presentation was a little cursory overall and stated a lot of obvious and uninteresting points&quot;<br>
<br>
What would you like to know about security that is more spot on in your opinion?<br>
<br>
<br>
<br>
&quot;I wonder how much prep work goes into each of these interviews...both by the interviewer and interviewee&quot;<br>
<br>
As one of the members of Channel 9 and having conducted many interviews I can assure that the only preparation that goes into our interviews is getting the interviewee to consent to being interviewed and scheduling time to conduct the interview. That's it.<br>
<br>
Absolutely nothing is rehearsed.<br>
<br>
<br>
<br>
Thanks for taking part in Channel 9.<br>
<br>
<br>
Keep on posting,<br>
<br>
Charles<p>posted by Charles</p>]]>
		</description>
		<link>http://channel9.msdn.com/Blogs/TheChannel9Team/Michael-Howard-When-does-threat-modeling-come-into-play#c632170646700000000</link>
		<pubDate>Thu, 08 Apr 2004 23:44:30 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Blogs/TheChannel9Team/Michael-Howard-When-does-threat-modeling-come-into-play#c632170646700000000</guid>
		<dc:creator>Charles</dc:creator>
	</item>
	<item>
		<title>Re: Michael Howard - When does threat modeling come into play?</title>
		<description>
			<![CDATA[I simply can't agree with this;&nbsp; While I do believe Michael's intentions are ultimately to make things safer for the end user, &quot;turning it off&quot; doesn't help us.&nbsp; Many of us need these components to work.<br>
<br>
I would much rather see fixes for these problems rather than an &quot;ignore it and it'll go away&quot; approach.<br>
<p>posted by Benjamin</p>]]>
		</description>
		<link>http://channel9.msdn.com/Blogs/TheChannel9Team/Michael-Howard-When-does-threat-modeling-come-into-play#c632171437320000000</link>
		<pubDate>Fri, 09 Apr 2004 21:42:12 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Blogs/TheChannel9Team/Michael-Howard-When-does-threat-modeling-come-into-play#c632171437320000000</guid>
		<dc:creator>Benjamin</dc:creator>
	</item>
	<item>
		<title>Re: Michael Howard - When does threat modeling come into play?</title>
		<description>
			<![CDATA[You seriously NEED to browse the internet on a server? Or even on a DC? <br>
<br>
I agree that turning off features rather than fixing security problems in&nbsp;them is not the right way to go. But disabling unnecessary features to increase security is something I'd definitely support.
<br>
<br>
And I didn't understand this to be Microsoft's way of dealing with security issues in general but just as an example how you can&nbsp;minimize the possible area of attack. Especially as in this case (admin surfing the internet on a PDC) you don't even need a&nbsp;bug
 or a security problem&nbsp;to mess things up - the admin is doing all that on his own.<p>posted by Fox</p>]]>
		</description>
		<link>http://channel9.msdn.com/Blogs/TheChannel9Team/Michael-Howard-When-does-threat-modeling-come-into-play#c632171782400000000</link>
		<pubDate>Sat, 10 Apr 2004 07:17:20 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Blogs/TheChannel9Team/Michael-Howard-When-does-threat-modeling-come-into-play#c632171782400000000</guid>
		<dc:creator>Fox</dc:creator>
	</item>
	<item>
		<title>Re: Michael Howard - When does threat modeling come into play?</title>
		<description>
			<![CDATA[The problem is simply not limited to servers though;&nbsp; Internet explorer vulnerabilities have plauged every version of windows.&nbsp; They are possibly the single largest flaw in the windows operating system where most viruses and worms make their entree.<br>
<br>
In my opinion, not enough has been done to fix these problems, some of which have existed in Internet Explorer for quite a long time now.<br>
<br>
On a server shutting everything off is not a big deal, but on a desktop it's a really big deal, and desktops are the ones spreading many of the annoying worms we have to deal with today.<br>
<p>posted by Benjamin</p>]]>
		</description>
		<link>http://channel9.msdn.com/Blogs/TheChannel9Team/Michael-Howard-When-does-threat-modeling-come-into-play#c632172297200000000</link>
		<pubDate>Sat, 10 Apr 2004 21:35:20 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Blogs/TheChannel9Team/Michael-Howard-When-does-threat-modeling-come-into-play#c632172297200000000</guid>
		<dc:creator>Benjamin</dc:creator>
	</item>
	<item>
		<title>Re: Michael Howard - When does threat modeling come into play?</title>
		<description>
			<![CDATA[Last time I checked.. the most up-to-date and current source for patches was windowsupdate.microsoft.com.. an internet site..<br>
<br>
Don't get me wrong.. I think the security lockdown mode of IE on W2k3 server&nbsp;is a very necessary feature, but it is difficult to draw the line on what's &quot;good&quot; and &quot;bad&quot; in all possible scenarios..<br>
<br>
continuing&nbsp;your line of thinking, why not deny access from the DC to any ip which is external to the domain? not allow installs of any application on the DC since any application could pose a security risk. Don't allow remoting or terminal services to a DC
 since&nbsp;it&nbsp;could be a&nbsp;untrusted user from inside the network.. &nbsp;<br>
<br>
there are any number of&nbsp;scenarios where doing these things would just complicate matters and not make things any more secure -- maybe even less..<br>
<br>
<br>
it is still incumbent upon the admin to make sound decisions -- simply taking away IE doesn't solve much as it would just frustrate the admin and he/she would probably find a reg hack or download and install another browser..<br>
<br>
the probably best way is to keep features intact, secure by default, and have the user be the determining factor on what should or shouldn't be done...<br>
<br>
<p>posted by SMac</p>]]>
		</description>
		<link>http://channel9.msdn.com/Blogs/TheChannel9Team/Michael-Howard-When-does-threat-modeling-come-into-play#c632179563120000000</link>
		<pubDate>Mon, 19 Apr 2004 07:25:12 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Blogs/TheChannel9Team/Michael-Howard-When-does-threat-modeling-come-into-play#c632179563120000000</guid>
		<dc:creator>SMac</dc:creator>
	</item>
	<item>
		<title>Re: Michael Howard - When does threat modeling come into play?</title>
		<description>
			<![CDATA[With a simple problem comes a simple solution: If you really need to browse on the server with all the functionality enabled, then just take a remote session to a workstation or use vmware or other virtual machine. Why such sandbox solution doesn't come&nbsp;as
 default is beyond me.<p>posted by androidi</p>]]>
		</description>
		<link>http://channel9.msdn.com/Blogs/TheChannel9Team/Michael-Howard-When-does-threat-modeling-come-into-play#c632182876830000000</link>
		<pubDate>Fri, 23 Apr 2004 03:28:03 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Blogs/TheChannel9Team/Michael-Howard-When-does-threat-modeling-come-into-play#c632182876830000000</guid>
		<dc:creator>androidi</dc:creator>
	</item>
	<item>
		<title>Re: Michael Howard - When does threat modeling come into play?</title>
		<description>
			<![CDATA[Many people seem shocked that anyone would browse the web from a domain controller -- yet my wife does it every day.<br>
<br>
Being an unfunded researcher, I run my development out of my living room.&nbsp; When I needed a server, my wife graciously lent me the unused cycles on her desktop machine.&nbsp; So she surfs on the server, and I code against it -- and everything works.&nbsp; Pure programming
 (and marital) bliss.<br>
<br>
The point is not that I was able to come up with a bizzare scenerio where it happens.&nbsp; The fact is that the threat model suggested it, and an appropriate mitigation was in place.&nbsp; The threat model found an odball&nbsp;what-if that happened to be real and reasonable
 in a context that I am sure the server 2003 team never anticipated and handled it in a secure and transparent way.<br>
<br>
The fact that I chose to override the security is not the point either.&nbsp; It wouldn't be the end of the world if our three computer domain bites the dust, but it&nbsp;might be if she can't surf!&nbsp; I appriciated the reminder that surfing from a server is usually unwise.&nbsp;
 I appriciate the software allowing me to overide that recommendation in a situation when it didn't apply.<p>posted by John Melville-- MD</p>]]>
		</description>
		<link>http://channel9.msdn.com/Blogs/TheChannel9Team/Michael-Howard-When-does-threat-modeling-come-into-play#c632265856450000000</link>
		<pubDate>Wed, 28 Jul 2004 04:27:25 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Blogs/TheChannel9Team/Michael-Howard-When-does-threat-modeling-come-into-play#c632265856450000000</guid>
		<dc:creator>John Melville-- MD</dc:creator>
	</item>
	<item>
		<title>Re: Michael Howard - When does threat modeling come into play?</title>
		<description>
			<![CDATA[
<blockquote>
<div>John Melville, MD wrote:</div>
<div>The fact that I chose to override the security is not the point either.&nbsp; It wouldn't be the end of the world if our three computer domain bites the dust, but it&nbsp;might be if she can't surf!&nbsp; I appriciated the reminder that surfing from a server is usually
 unwise.&nbsp; I appriciate the software allowing me to overide that recommendation in a situation when it didn't apply.</div>
</blockquote>
<br>
<br>
<p>I can't agree more with above. I would suggest that the more that is locked down the better!!</p>
<p>The admin(s) is responsible - it's not always MS fault... if it's locked down to begin with there is much less room for mistakes, i.e. not locking down a port you didn't know was open or even aware off!</p>
<p>posted by Kryptos</p>]]>
		</description>
		<link>http://channel9.msdn.com/Blogs/TheChannel9Team/Michael-Howard-When-does-threat-modeling-come-into-play#c632266424780000000</link>
		<pubDate>Wed, 28 Jul 2004 20:14:38 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Blogs/TheChannel9Team/Michael-Howard-When-does-threat-modeling-come-into-play#c632266424780000000</guid>
		<dc:creator>Kryptos</dc:creator>
	</item>
	<item>
		<title>Re: Michael Howard - When does threat modeling come into play?</title>
		<description>
			<![CDATA[
<p>Thank youaaaa</p>
<p><a href="http://www.2fnn.com">شات</a> - <a href="http://www.2fnn.com">شات كتابي</a> -
<a href="http://www.2fnn.com/vb">منتديات</a> - <a href="http://www.up.2fnn.com">مركز تحميل</a> -
<a href="http://www.chat1.ps">شات فلسطين</a> - <a href="http://www.chat1.ps">دردشة فلسطين</a> -
<a href="http://www.2fnn.com/vb/showthread.php?t=14257">ماسنجر</a> - <a href="http://www.2fnn.com/vb/forumdisplay.php?f=47">
فيديو كليب</a> - <a href="http://www.2fnn.com/dir">دليل مواقع</a></p>
<p>posted by sad sad</p>]]>
		</description>
		<link>http://channel9.msdn.com/Blogs/TheChannel9Team/Michael-Howard-When-does-threat-modeling-come-into-play#c634167188840000000</link>
		<pubDate>Fri, 06 Aug 2010 19:14:44 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Blogs/TheChannel9Team/Michael-Howard-When-does-threat-modeling-come-into-play#c634167188840000000</guid>
		<dc:creator>sad sad</dc:creator>
	</item>
	<item>
		<title>Re: Michael Howard - When does threat modeling come into play?</title>
		<description>
			<![CDATA[There's not a problem to see the &lt;a href="http://www.genuinewriting.com"&gt;write my essay&lt;/a&gt;&nbsp; service, just because there're several of them in web. However, students should chose a distinguished service to order high quality term papers.<p>posted by IP tracer</p>]]>
		</description>
		<link>http://channel9.msdn.com/Blogs/TheChannel9Team/Michael-Howard-When-does-threat-modeling-come-into-play#c634244566200000000</link>
		<pubDate>Thu, 04 Nov 2010 08:37:00 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Blogs/TheChannel9Team/Michael-Howard-When-does-threat-modeling-come-into-play#c634244566200000000</guid>
		<dc:creator>IP tracer</dc:creator>
	</item>
</channel>
</rss>