
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:ent="http://www.purl.org/NET/ENT/1.0/">
	<channel>
		<title>TechEd Bloggers Identity, Access, and Security</title>
		<link>http://www.msteched.com/online/blogs.aspx</link>
		<description></description>
		<managingEditor>info@indepth-tech.com</managingEditor>
		<lastBuildDate>Mon, 15 Mar 2010 17:35:50 GMT</lastBuildDate>
		<generator>Ashton RssHandler</generator>
		<!--
		<image>
			<url>http://techedbloggers.net/images/TechEd_Bloggers_small.gif</url>
			<title>TechEd Bloggers</title>
			<link>http://TechEdBloggers.net</link>
		</image>
		-->
		
					<item>
						
						<title>Eight Vulnerabilities in Windows and Office via Security Bulletin </title>
						<link>http://teched.indepthtalk.net/TechEd/Tracks/Security/28636.item</link>
						<pubDate>Tue, 09 Mar 2010 22:50:22 GMT</pubDate>
						<author>Microsoft Security Response Center</author>
						<category>Identity, Access, and Security</category>
						<guid isPermaLink="true">http://teched.indepthtalk.net/TechEd/Tracks/Security/28636.item</guid>
						<ent:cloud ent:href="http://teched.indepthtalk.net">
						
								<ent:topic ent:id='2386' ent:classification='BLOG'>Microsoft Security Response Center</ent:topic>
							
								<ent:topic ent:id='4558' ent:classification='SECT'>Security</ent:topic>
							
						</ent:cloud>

<description>	
&lt;a href='http://teched.indepthtalk.net/TechEd/Tracks/Security/28636.item'&gt;Microsoft Security Response Center&lt;/a&gt; writes,
"Today we are releasing two Important security bulletins addressing eight vulnerabilities in Windows and Microsoft Office. Both bulletins have an aggregate Exploitability Index rating of “1” so we recommend that customers deploy these updates as soon as possible...A summary of today’s security updates can be found... [here]" &lt;a href='http://teched.indepthtalk.net/TechEd/Tracks/Security/28636.item'&gt;more&lt;/a&gt;
&lt;div style="color:black;font-size:10px;font-style:italic;margin-top:2px;margin-bottom:-2px" &gt;Tue, 09 Mar 2010 22:50:22 GMT&lt;/div&gt;
&lt;hr/&gt;
&lt;small&gt;

&lt;/small&gt;
</description>
	


					</item>
				
					<item>
						
						<title>Windows 7 Does a Good Job Limiting Malware Infection</title>
						<link>http://teched.indepthtalk.net/TechEd/Tracks/Security/28628.item</link>
						<pubDate>Tue, 09 Mar 2010 19:22:07 GMT</pubDate>
						<author>Kerry Brown</author>
						<category>Identity, Access, and Security</category>
						<guid isPermaLink="true">http://teched.indepthtalk.net/TechEd/Tracks/Security/28628.item</guid>
						<ent:cloud ent:href="http://teched.indepthtalk.net">
						
								<ent:topic ent:id='4558' ent:classification='SECT'>Security</ent:topic>
							
								<ent:topic ent:id='4745' ent:classification='BLOG'>Kerry Brown</ent:topic>
							
						</ent:cloud>

<description>	
&lt;a href='http://teched.indepthtalk.net/TechEd/Tracks/Security/28628.item'&gt;Kerry Brown&lt;/a&gt; writes,
"...The latest version is extremely hard to remove from XP. If Windows is running it’s near impossible. The malware gets into the system files and doesn’t let other programs run. I have to remove the hard drive and scan it with another computer. Then I re-install the hard drive...Windows 7 with the default security settings did a great job of limiting the infection and making it easy to remove." &lt;a href='http://teched.indepthtalk.net/TechEd/Tracks/Security/28628.item'&gt;more&lt;/a&gt;
&lt;div style="color:black;font-size:10px;font-style:italic;margin-top:2px;margin-bottom:-2px" &gt;Tue, 09 Mar 2010 19:22:07 GMT&lt;/div&gt;
&lt;hr/&gt;
&lt;small&gt;

&lt;/small&gt;
</description>
	


					</item>
				
					<item>
						
						<title>Security Advisory on Vulnerability in VBScript Could Allow Remote Code Execution</title>
						<link>http://teched.indepthtalk.net/TechEd/Tracks/Security/28568.item</link>
						<pubDate>Tue, 02 Mar 2010 20:31:32 GMT</pubDate>
						<author>Microsoft Security Response Center</author>
						<category>Identity, Access, and Security</category>
						<guid isPermaLink="true">http://teched.indepthtalk.net/TechEd/Tracks/Security/28568.item</guid>
						<ent:cloud ent:href="http://teched.indepthtalk.net">
						
								<ent:topic ent:id='2386' ent:classification='BLOG'>Microsoft Security Response Center</ent:topic>
							
								<ent:topic ent:id='4558' ent:classification='SECT'>Security</ent:topic>
							
						</ent:cloud>

<description>	
&lt;a href='http://teched.indepthtalk.net/TechEd/Tracks/Security/28568.item'&gt;Microsoft Security Response Center&lt;/a&gt; writes,
"...we are not aware of any active attacks at this time and the following operating systems are not affected by this issue: Windows 7, Windows Server 2008 R2, Windows Server 2008, and Windows Vista. Our investigation is ongoing. Users on older versions of Windows should review the Security Advisory for mitigations and workarounds for this issue. Additionally, our Security Research &amp; Defense team provides a detailed analysis of..." &lt;a href='http://teched.indepthtalk.net/TechEd/Tracks/Security/28568.item'&gt;more&lt;/a&gt;
&lt;div style="color:black;font-size:10px;font-style:italic;margin-top:2px;margin-bottom:-2px" &gt;Tue, 02 Mar 2010 20:31:32 GMT&lt;/div&gt;
&lt;hr/&gt;
&lt;small&gt;

&lt;/small&gt;
</description>
	


					</item>
				
					<item>
						
						<title>Clearing up Confusion About Secure Strings</title>
						<link>http://teched.indepthtalk.net/TechEd/Tracks/Security/28495.item</link>
						<pubDate>Tue, 23 Feb 2010 23:55:28 GMT</pubDate>
						<author>Richard Siddaway</author>
						<category>Identity, Access, and Security</category>
						<guid isPermaLink="true">http://teched.indepthtalk.net/TechEd/Tracks/Security/28495.item</guid>
						<ent:cloud ent:href="http://teched.indepthtalk.net">
						
								<ent:topic ent:id='4428' ent:classification='BLOG'>Richard Siddaway</ent:topic>
							
								<ent:topic ent:id='4558' ent:classification='SECT'>Security</ent:topic>
							
						</ent:cloud>

<description>	
&lt;a href='http://teched.indepthtalk.net/TechEd/Tracks/Security/28495.item'&gt;Richard Siddaway&lt;/a&gt; writes,
"Secure Strings are a way to work with encrypted data – one of the common uses is to protect passwords used in scripts. The way to use them may not be obvious at first sight. I hope to clear some of the confusion...One draw back to secure strings is that we can’t save them in a file.  To do that..." &lt;a href='http://teched.indepthtalk.net/TechEd/Tracks/Security/28495.item'&gt;more&lt;/a&gt;
&lt;div style="color:black;font-size:10px;font-style:italic;margin-top:2px;margin-bottom:-2px" &gt;Tue, 23 Feb 2010 23:55:28 GMT&lt;/div&gt;
&lt;hr/&gt;
&lt;small&gt;

&lt;/small&gt;
</description>
	


					</item>
				
					<item>
						
						<title>Malware Blue-Screens When Patched</title>
						<link>http://teched.indepthtalk.net/TechEd/Tracks/Security/28449.item</link>
						<pubDate>Thu, 18 Feb 2010 18:51:11 GMT</pubDate>
						<author>Alun Jones</author>
						<category>Identity, Access, and Security</category>
						<guid isPermaLink="true">http://teched.indepthtalk.net/TechEd/Tracks/Security/28449.item</guid>
						<ent:cloud ent:href="http://teched.indepthtalk.net">
						
								<ent:topic ent:id='3552' ent:classification='BLOG'>Alun Jones</ent:topic>
							
								<ent:topic ent:id='4558' ent:classification='SECT'>Security</ent:topic>
							
						</ent:cloud>

<description>	
&lt;a href='http://teched.indepthtalk.net/TechEd/Tracks/Security/28449.item'&gt;Alun Jones&lt;/a&gt; writes,
"...the message here is that the operating system on a Windows computer belongs to Microsoft, and they document well those places where you are expected to modify it. Step outside those boundaries of safe patching, and you run a good risk that a patch will trigger significant adverse behaviour...If you experience problems as a result of applying a Microsoft security patch, or..." &lt;a href='http://teched.indepthtalk.net/TechEd/Tracks/Security/28449.item'&gt;more&lt;/a&gt;
&lt;div style="color:black;font-size:10px;font-style:italic;margin-top:2px;margin-bottom:-2px" &gt;Thu, 18 Feb 2010 18:51:11 GMT&lt;/div&gt;
&lt;hr/&gt;
&lt;small&gt;

&lt;/small&gt;
</description>
	


					</item>
				
					<item>
						
						<title>Top 25 Most Dangerous Security Programming Errors </title>
						<link>http://teched.indepthtalk.net/TechEd/Tracks/Security/28428.item</link>
						<pubDate>Wed, 17 Feb 2010 19:30:56 GMT</pubDate>
						<author>Roger Halbheer</author>
						<category>Identity, Access, and Security</category>
						<guid isPermaLink="true">http://teched.indepthtalk.net/TechEd/Tracks/Security/28428.item</guid>
						<ent:cloud ent:href="http://teched.indepthtalk.net">
						
								<ent:topic ent:id='4468' ent:classification='BLOG'>Roger Halbheer</ent:topic>
							
								<ent:topic ent:id='4558' ent:classification='SECT'>Security</ent:topic>
							
						</ent:cloud>

<description>	
&lt;a href='http://teched.indepthtalk.net/TechEd/Tracks/Security/28428.item'&gt;Roger Halbheer&lt;/a&gt; writes,
"...It shows as we often say that the attacks moved up the stack and a lot of challenges are based on improperly written applications. So, if you are organization is developing applications, you should start to implement a process like the Security Development Lifecycle. If you need information about this..." &lt;a href='http://teched.indepthtalk.net/TechEd/Tracks/Security/28428.item'&gt;more&lt;/a&gt;
&lt;div style="color:black;font-size:10px;font-style:italic;margin-top:2px;margin-bottom:-2px" &gt;Wed, 17 Feb 2010 19:30:56 GMT&lt;/div&gt;
&lt;hr/&gt;
&lt;small&gt;

&lt;/small&gt;
</description>
	


					</item>
				
					<item>
						
						<title>Allowing a Service Account to Manage Its Own SPN</title>
						<link>http://teched.indepthtalk.net/TechEd/Tracks/Security/28368.item</link>
						<pubDate>Thu, 11 Feb 2010 00:18:21 GMT</pubDate>
						<author>Jeff Guillet</author>
						<category>Identity, Access, and Security</category>
						<guid isPermaLink="true">http://teched.indepthtalk.net/TechEd/Tracks/Security/28368.item</guid>
						<ent:cloud ent:href="http://teched.indepthtalk.net">
						
								<ent:topic ent:id='4032' ent:classification='BLOG'>Jeff Guillet</ent:topic>
							
								<ent:topic ent:id='4558' ent:classification='SECT'>Security</ent:topic>
							
						</ent:cloud>

<description>	
&lt;a href='http://teched.indepthtalk.net/TechEd/Tracks/Security/28368.item'&gt;Jeff Guillet&lt;/a&gt; writes,
"...If you don't set the SPN properly, Kerberos Authentication will not work and that stops pass through authentication from working....A simple and easier way to fix this is by using Active Directory Users and Computers to assign the Write Public Information permission to Self on the domain account that SQL is using, as shown..." &lt;a href='http://teched.indepthtalk.net/TechEd/Tracks/Security/28368.item'&gt;more&lt;/a&gt;
&lt;div style="color:black;font-size:10px;font-style:italic;margin-top:2px;margin-bottom:-2px" &gt;Thu, 11 Feb 2010 00:18:21 GMT&lt;/div&gt;
&lt;hr/&gt;
&lt;small&gt;

&lt;/small&gt;
</description>
	


					</item>
				
					<item>
						
						<title>To Patch or Not the TLS Renegotiation Attack </title>
						<link>http://teched.indepthtalk.net/TechEd/Tracks/Security/28362.item</link>
						<pubDate>Wed, 10 Feb 2010 22:20:39 GMT</pubDate>
						<author>Alun Jones</author>
						<category>Identity, Access, and Security</category>
						<guid isPermaLink="true">http://teched.indepthtalk.net/TechEd/Tracks/Security/28362.item</guid>
						<ent:cloud ent:href="http://teched.indepthtalk.net">
						
								<ent:topic ent:id='3552' ent:classification='BLOG'>Alun Jones</ent:topic>
							
								<ent:topic ent:id='4558' ent:classification='SECT'>Security</ent:topic>
							
						</ent:cloud>

<description>	
&lt;a href='http://teched.indepthtalk.net/TechEd/Tracks/Security/28362.item'&gt;Alun Jones&lt;/a&gt; writes,
"...If your servers do not use client auth / mutual auth, you don’t need this patch. Your server simply isn’t going to accept a renegotiation request. If your servers do use client authentication / mutual authentication, you can either apply this patch, or..." &lt;a href='http://teched.indepthtalk.net/TechEd/Tracks/Security/28362.item'&gt;more&lt;/a&gt;
&lt;div style="color:black;font-size:10px;font-style:italic;margin-top:2px;margin-bottom:-2px" &gt;Wed, 10 Feb 2010 22:20:39 GMT&lt;/div&gt;
&lt;hr/&gt;
&lt;small&gt;

&lt;/small&gt;
</description>
	


					</item>
				
					<item>
						
						<title>Security Bulletin Release for February 2010</title>
						<link>http://teched.indepthtalk.net/TechEd/Tracks/Security/28343.item</link>
						<pubDate>Tue, 09 Feb 2010 20:34:03 GMT</pubDate>
						<author>Microsoft Security Response Center</author>
						<category>Identity, Access, and Security</category>
						<guid isPermaLink="true">http://teched.indepthtalk.net/TechEd/Tracks/Security/28343.item</guid>
						<ent:cloud ent:href="http://teched.indepthtalk.net">
						
								<ent:topic ent:id='2386' ent:classification='BLOG'>Microsoft Security Response Center</ent:topic>
							
								<ent:topic ent:id='4558' ent:classification='SECT'>Security</ent:topic>
							
						</ent:cloud>

<description>	
&lt;a href='http://teched.indepthtalk.net/TechEd/Tracks/Security/28343.item'&gt;Microsoft Security Response Center&lt;/a&gt; writes,
"...today we are releasing 13 bulletins addressing 26 vulnerabilities. 11 bulletins affect Windows and 2 affect older versions of Microsoft Office...Here is the mapping from the bulletin numbers in the ANS to the released bulletin ID’s:..." &lt;a href='http://teched.indepthtalk.net/TechEd/Tracks/Security/28343.item'&gt;more&lt;/a&gt;
&lt;div style="color:black;font-size:10px;font-style:italic;margin-top:2px;margin-bottom:-2px" &gt;Tue, 09 Feb 2010 20:34:03 GMT&lt;/div&gt;
&lt;hr/&gt;
&lt;small&gt;

&lt;/small&gt;
</description>
	


					</item>
				
					<item>
						
						<title>Private Cloud Security is no Security at All</title>
						<link>http://teched.indepthtalk.net/TechEd/Tracks/Security/28296.item</link>
						<pubDate>Wed, 03 Feb 2010 17:33:26 GMT</pubDate>
						<author>Sam Johnston</author>
						<category>Identity, Access, and Security</category>
						<guid isPermaLink="true">http://teched.indepthtalk.net/TechEd/Tracks/Security/28296.item</guid>
						<ent:cloud ent:href="http://teched.indepthtalk.net">
						
								<ent:topic ent:id='4524' ent:classification='BLOG'>Sam Johnston</ent:topic>
							
								<ent:topic ent:id='4558' ent:classification='SECT'>Security</ent:topic>
							
						</ent:cloud>

<description>	
&lt;a href='http://teched.indepthtalk.net/TechEd/Tracks/Security/28296.item'&gt;Sam Johnston&lt;/a&gt; writes,
"...don't take it for granted that private cloud offerings are secure, and in the unlikely event that the systems themselves are secure, don't assume you or your provider can run them in a more secure fashion than a &quot;public&quot; cloud provider could. Incidents like this go a long way towards realising one of my predictions for 2010...in that Private clouds will be discredited by year end..." &lt;a href='http://teched.indepthtalk.net/TechEd/Tracks/Security/28296.item'&gt;more&lt;/a&gt;
&lt;div style="color:black;font-size:10px;font-style:italic;margin-top:2px;margin-bottom:-2px" &gt;Wed, 03 Feb 2010 17:33:26 GMT&lt;/div&gt;
&lt;hr/&gt;
&lt;small&gt;

&lt;/small&gt;
</description>
	


					</item>
				
					<item>
						
						<title>Scenarios Using ADFS with Amazon EC2</title>
						<link>http://teched.indepthtalk.net/TechEd/Tracks/Security/28115.item</link>
						<pubDate>Thu, 14 Jan 2010 19:06:29 GMT</pubDate>
						<author>Steve Riley</author>
						<category>Identity, Access, and Security</category>
						<guid isPermaLink="true">http://teched.indepthtalk.net/TechEd/Tracks/Security/28115.item</guid>
						<ent:cloud ent:href="http://teched.indepthtalk.net">
						
								<ent:topic ent:id='3949' ent:classification='BLOG'>Steve Riley</ent:topic>
							
								<ent:topic ent:id='4558' ent:classification='SECT'>Security</ent:topic>
							
						</ent:cloud>

<description>	
&lt;a href='http://teched.indepthtalk.net/TechEd/Tracks/Security/28115.item'&gt;Steve Riley&lt;/a&gt; writes,
"...release of a whitepaper written by David Chappell that explores these federation scenarios in more detail. David begins [with] your Amazon EC2 resources are placed in an Amazon Virtual Private Cloud (VPC) and joined to your own corporate domain; here, there’s no use of ADFS. Then he illustrates the two scenarios...and shows how it would work with both ADFS 1.1 and ADFS 2.0..." &lt;a href='http://teched.indepthtalk.net/TechEd/Tracks/Security/28115.item'&gt;more&lt;/a&gt;
&lt;div style="color:black;font-size:10px;font-style:italic;margin-top:2px;margin-bottom:-2px" &gt;Thu, 14 Jan 2010 19:06:29 GMT&lt;/div&gt;
&lt;hr/&gt;
&lt;small&gt;

&lt;/small&gt;
</description>
	


					</item>
				
					<item>
						
						<title>Apply Security Update if You are Using Windows Embedded CE 6.0</title>
						<link>http://teched.indepthtalk.net/TechEd/Tracks/Security/28108.item</link>
						<pubDate>Wed, 13 Jan 2010 19:59:39 GMT</pubDate>
						<author>Don Patterson</author>
						<category>Identity, Access, and Security</category>
						<guid isPermaLink="true">http://teched.indepthtalk.net/TechEd/Tracks/Security/28108.item</guid>
						<ent:cloud ent:href="http://teched.indepthtalk.net">
						
								<ent:topic ent:id='3926' ent:classification='BLOG'>Don Patterson</ent:topic>
							
								<ent:topic ent:id='4558' ent:classification='SECT'>Security</ent:topic>
							
						</ent:cloud>

<description>	
&lt;a href='http://teched.indepthtalk.net/TechEd/Tracks/Security/28108.item'&gt;Don Patterson&lt;/a&gt; writes,
"...Rereleased this bulletin to add Windows Embedded CE 6.0 to affected software. The new update for Windows Embedded CE 6.0..." &lt;a href='http://teched.indepthtalk.net/TechEd/Tracks/Security/28108.item'&gt;more&lt;/a&gt;
&lt;div style="color:black;font-size:10px;font-style:italic;margin-top:2px;margin-bottom:-2px" &gt;Wed, 13 Jan 2010 19:59:39 GMT&lt;/div&gt;
&lt;hr/&gt;
&lt;small&gt;

&lt;/small&gt;
</description>
	


					</item>
				
					<item>
						
						<title>Windows Security Risk on Embedded OpenType Font Engine</title>
						<link>http://teched.indepthtalk.net/TechEd/Tracks/Security/28092.item</link>
						<pubDate>Tue, 12 Jan 2010 21:18:59 GMT</pubDate>
						<author>Microsoft Security Response Center</author>
						<category>Identity, Access, and Security</category>
						<guid isPermaLink="true">http://teched.indepthtalk.net/TechEd/Tracks/Security/28092.item</guid>
						<ent:cloud ent:href="http://teched.indepthtalk.net">
						
								<ent:topic ent:id='2386' ent:classification='BLOG'>Microsoft Security Response Center</ent:topic>
							
								<ent:topic ent:id='4558' ent:classification='SECT'>Security</ent:topic>
							
						</ent:cloud>

<description>	
&lt;a href='http://teched.indepthtalk.net/TechEd/Tracks/Security/28092.item'&gt;Microsoft Security Response Center&lt;/a&gt; writes,
"...Critical bulletin affecting all versions of Windows. The bulletin, MS10-001, addresses one vulnerability in the Embedded OpenType Font Engine and is Critical on Windows 2000. For all other versions of Windows...The following risk and impact slide reflects the aggregate severity and exploitability index rating for this bulletin..." &lt;a href='http://teched.indepthtalk.net/TechEd/Tracks/Security/28092.item'&gt;more&lt;/a&gt;
&lt;div style="color:black;font-size:10px;font-style:italic;margin-top:2px;margin-bottom:-2px" &gt;Tue, 12 Jan 2010 21:18:59 GMT&lt;/div&gt;
&lt;hr/&gt;
&lt;small&gt;

&lt;/small&gt;
</description>
	


					</item>
				
					<item>
						
						<title>Fix for OCS 2007, NTLM and Edge Server Login Problems</title>
						<link>http://teched.indepthtalk.net/TechEd/Tracks/Security/28083.item</link>
						<pubDate>Tue, 12 Jan 2010 06:47:01 GMT</pubDate>
						<author>Aaron Tiensivu</author>
						<category>Identity, Access, and Security</category>
						<guid isPermaLink="true">http://teched.indepthtalk.net/TechEd/Tracks/Security/28083.item</guid>
						<ent:cloud ent:href="http://teched.indepthtalk.net">
						
								<ent:topic ent:id='3229' ent:classification='BLOG'>Aaron Tiensivu</ent:topic>
							
								<ent:topic ent:id='4558' ent:classification='SECT'>Security</ent:topic>
							
						</ent:cloud>

<description>	
&lt;a href='http://teched.indepthtalk.net/TechEd/Tracks/Security/28083.item'&gt;Aaron Tiensivu&lt;/a&gt; writes,
"...If NTLM is “broken” inside the domain between domain controllers and OCS servers (front End/edge), the Office Communicator client will act as if the user entered an invalid username or password. The error message on the client computer is very misleading and everyone external will not be able to log in...verall, assuming all your software and operating systems on your network work properly with NTLMv2, I recommend..." &lt;a href='http://teched.indepthtalk.net/TechEd/Tracks/Security/28083.item'&gt;more&lt;/a&gt;
&lt;div style="color:black;font-size:10px;font-style:italic;margin-top:2px;margin-bottom:-2px" &gt;Tue, 12 Jan 2010 06:47:01 GMT&lt;/div&gt;
&lt;hr/&gt;
&lt;small&gt;

&lt;/small&gt;
</description>
	


					</item>
				
					<item>
						
						<title>Security Advisory for Adobe Reader and Acrobat - January 7, 2010</title>
						<link>http://teched.indepthtalk.net/TechEd/Tracks/Security/28063.item</link>
						<pubDate>Fri, 08 Jan 2010 00:36:01 GMT</pubDate>
						<author>Don Patterson</author>
						<category>Identity, Access, and Security</category>
						<guid isPermaLink="true">http://teched.indepthtalk.net/TechEd/Tracks/Security/28063.item</guid>
						<ent:cloud ent:href="http://teched.indepthtalk.net">
						
								<ent:topic ent:id='3926' ent:classification='BLOG'>Don Patterson</ent:topic>
							
								<ent:topic ent:id='4558' ent:classification='SECT'>Security</ent:topic>
							
						</ent:cloud>

<description>	
&lt;a href='http://teched.indepthtalk.net/TechEd/Tracks/Security/28063.item'&gt;Don Patterson&lt;/a&gt; writes,
"...Among other issues, this update will resolve a critical vulnerability in Adobe Reader and Acrobat 9.2 and earlier (CVE-2009-4324) on Windows, Macintosh and UNIX. There are reports that this issue is being actively exploited in the wild; the exploit targets" &lt;a href='http://teched.indepthtalk.net/TechEd/Tracks/Security/28063.item'&gt;more&lt;/a&gt;
&lt;div style="color:black;font-size:10px;font-style:italic;margin-top:2px;margin-bottom:-2px" &gt;Fri, 08 Jan 2010 00:36:01 GMT&lt;/div&gt;
&lt;hr/&gt;
&lt;small&gt;

&lt;/small&gt;
</description>
	


					</item>
				
					<item>
						
						<title>Client and Cloud Security whitepaper Download</title>
						<link>http://teched.indepthtalk.net/TechEd/Tracks/Security/27898.item</link>
						<pubDate>Tue, 15 Dec 2009 17:22:49 GMT</pubDate>
						<author>Georgeo Pulikkathara</author>
						<category>Identity, Access, and Security</category>
						<guid isPermaLink="true">http://teched.indepthtalk.net/TechEd/Tracks/Security/27898.item</guid>
						<ent:cloud ent:href="http://teched.indepthtalk.net">
						
								<ent:topic ent:id='1092' ent:classification='BLOG'>Georgeo Pulikkathara</ent:topic>
							
								<ent:topic ent:id='4558' ent:classification='SECT'>Security</ent:topic>
							
						</ent:cloud>

<description>	
&lt;a href='http://teched.indepthtalk.net/TechEd/Tracks/Security/27898.item'&gt;Georgeo Pulikkathara&lt;/a&gt; writes,
"...security guidance from Microsoft Trustworthy Computing on client + Cloud security...talks about client + cloud security in today’s environment,and what you need to consider before taking off for the cloud..." &lt;a href='http://teched.indepthtalk.net/TechEd/Tracks/Security/27898.item'&gt;more&lt;/a&gt;
&lt;div style="color:black;font-size:10px;font-style:italic;margin-top:2px;margin-bottom:-2px" &gt;Tue, 15 Dec 2009 17:22:49 GMT&lt;/div&gt;
&lt;hr/&gt;
&lt;small&gt;

&lt;/small&gt;
</description>
	


					</item>
				
					<item>
						
						<title>ACS Noise Filter: Translating Server Security EventIDs to Windows Server 2008</title>
						<link>http://teched.indepthtalk.net/TechEd/Tracks/Security/27873.item</link>
						<pubDate>Mon, 14 Dec 2009 13:26:30 GMT</pubDate>
						<author>Marnix Wolf</author>
						<category>Identity, Access, and Security</category>
						<guid isPermaLink="true">http://teched.indepthtalk.net/TechEd/Tracks/Security/27873.item</guid>
						<ent:cloud ent:href="http://teched.indepthtalk.net">
						
								<ent:topic ent:id='4558' ent:classification='SECT'>Security</ent:topic>
							
								<ent:topic ent:id='4807' ent:classification='BLOG'>Marnix Wolf</ent:topic>
							
						</ent:cloud>

<description>	
&lt;a href='http://teched.indepthtalk.net/TechEd/Tracks/Security/27873.item'&gt;Marnix Wolf&lt;/a&gt; writes,
"...what if you are designing an ACS solution for Windows Server 2008 servers? Yes, you can apply the filter as stated in those very same documents. But it won’t work...I ran the same ‘formula’ against the other matching EventIDs and the same number came out! Time for a test. I took a non-matched W2K03 Security EventID..." &lt;a href='http://teched.indepthtalk.net/TechEd/Tracks/Security/27873.item'&gt;more&lt;/a&gt;
&lt;div style="color:black;font-size:10px;font-style:italic;margin-top:2px;margin-bottom:-2px" &gt;Mon, 14 Dec 2009 13:26:30 GMT&lt;/div&gt;
&lt;hr/&gt;
&lt;small&gt;

&lt;/small&gt;
</description>
	


					</item>
				
					<item>
						
						<title>Securing Windows Live When Using ASP.NET MVC</title>
						<link>http://teched.indepthtalk.net/TechEd/Tracks/Security/27815.item</link>
						<pubDate>Wed, 09 Dec 2009 18:05:45 GMT</pubDate>
						<author>Angus Logan</author>
						<category>Identity, Access, and Security</category>
						<guid isPermaLink="true">http://teched.indepthtalk.net/TechEd/Tracks/Security/27815.item</guid>
						<ent:cloud ent:href="http://teched.indepthtalk.net">
						
								<ent:topic ent:id='2756' ent:classification='BLOG'>Angus Logan</ent:topic>
							
								<ent:topic ent:id='4558' ent:classification='SECT'>Security</ent:topic>
							
						</ent:cloud>

<description>	
&lt;a href='http://teched.indepthtalk.net/TechEd/Tracks/Security/27815.item'&gt;Angus Logan&lt;/a&gt; writes,
"I’ve been working with some of our centralized Windows Live security and privacy folks recently. These guys are super skilled...lessons learnt about securing Windows Live when using ASP.NET MVC...." &lt;a href='http://teched.indepthtalk.net/TechEd/Tracks/Security/27815.item'&gt;more&lt;/a&gt;
&lt;div style="color:black;font-size:10px;font-style:italic;margin-top:2px;margin-bottom:-2px" &gt;Wed, 09 Dec 2009 18:05:45 GMT&lt;/div&gt;
&lt;hr/&gt;
&lt;small&gt;

&lt;/small&gt;
</description>
	


					</item>
				
					<item>
						
						<title>4 Microsoft Security Notifications - December 8, 2009</title>
						<link>http://teched.indepthtalk.net/TechEd/Tracks/Security/27798.item</link>
						<pubDate>Tue, 08 Dec 2009 23:27:28 GMT</pubDate>
						<author>Don Patterson</author>
						<category>Identity, Access, and Security</category>
						<guid isPermaLink="true">http://teched.indepthtalk.net/TechEd/Tracks/Security/27798.item</guid>
						<ent:cloud ent:href="http://teched.indepthtalk.net">
						
								<ent:topic ent:id='3926' ent:classification='BLOG'>Don Patterson</ent:topic>
							
								<ent:topic ent:id='4558' ent:classification='SECT'>Security</ent:topic>
							
						</ent:cloud>

<description>	
&lt;a href='http://teched.indepthtalk.net/TechEd/Tracks/Security/27798.item'&gt;Don Patterson&lt;/a&gt; writes,
"...Vulnerability in Internet Explorer Could Allow Remote Code Execution...Credential Relaying Attacks on Integrated Windows Authentication...Extended Protection for Authentication...Security Enhancements for the Indeo Codec..." &lt;a href='http://teched.indepthtalk.net/TechEd/Tracks/Security/27798.item'&gt;more&lt;/a&gt;
&lt;div style="color:black;font-size:10px;font-style:italic;margin-top:2px;margin-bottom:-2px" &gt;Tue, 08 Dec 2009 23:27:28 GMT&lt;/div&gt;
&lt;hr/&gt;
&lt;small&gt;

&lt;/small&gt;
</description>
	


					</item>
				
					<item>
						
						<title>Deep Linking Your Way Out of Home Realm Discovery</title>
						<link>http://teched.indepthtalk.net/TechEd/Tracks/Security/27761.item</link>
						<pubDate>Fri, 04 Dec 2009 00:51:46 GMT</pubDate>
						<author>Vittorio Bertocci</author>
						<category>SOA and Business Processes</category>
						<guid isPermaLink="true">http://teched.indepthtalk.net/TechEd/Tracks/Security/27761.item</guid>
						<ent:cloud ent:href="http://teched.indepthtalk.net">
						
								<ent:topic ent:id='350' ent:classification='BLOG'>Vittorio Bertocci</ent:topic>
							
								<ent:topic ent:id='4546' ent:classification='SECT'>SOA and Business Processes</ent:topic>
							
								<ent:topic ent:id='4558' ent:classification='SECT'>Security</ent:topic>
							
						</ent:cloud>

<description>	
&lt;a href='http://teched.indepthtalk.net/TechEd/Tracks/Security/27761.item'&gt;Vittorio Bertocci&lt;/a&gt; writes,
"This method is not a solution to home realm discovery, rather it is a “shortcut” that piggybacks on existing home real discovery solutions which must be in place for this to work. Furthermore, this has to be arranged by every partner and relies completely on the fact that the users will access the application through the specially crafter URL as opposed to..." &lt;a href='http://teched.indepthtalk.net/TechEd/Tracks/Security/27761.item'&gt;more&lt;/a&gt;
&lt;div style="color:black;font-size:10px;font-style:italic;margin-top:2px;margin-bottom:-2px" &gt;Fri, 04 Dec 2009 00:51:46 GMT&lt;/div&gt;
&lt;hr/&gt;
&lt;small&gt;

&lt;/small&gt;
</description>
	


					</item>
				
	</channel>
</rss>