<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Fjodor's thoughts &#187; Microsoft</title>
	<atom:link href="http://blog.molgaard.org/category/microsoft/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.molgaard.org</link>
	<description>Mostly rants about Microsoft</description>
	<lastBuildDate>Thu, 10 Sep 2009 09:37:53 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
		<item>
		<title>Microsoft getting nostalgic?</title>
		<link>http://blog.molgaard.org/2009/09/10/microsoft-getting-nostalgic/</link>
		<comments>http://blog.molgaard.org/2009/09/10/microsoft-getting-nostalgic/#comments</comments>
		<pubDate>Thu, 10 Sep 2009 09:37:53 +0000</pubDate>
		<dc:creator>Fjodor</dc:creator>
				<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://blog.molgaard.org/?p=41</guid>
		<description><![CDATA[If the reader remembers the days of Windows 95 and NT, she should also remember the teardrop attacks. It would appear that some brave MS programmer pined for those days of remote BSODs, and thus has reintroduced this beloved feature in the SMB2 protocol driver in Vista and Windows 7. Kudos!]]></description>
			<content:encoded><![CDATA[<p>If the reader remembers the days of Windows 95 and NT, she should also remember the <a href="http://en.wikipedia.org/wiki/Teardrop_attack#Teardrop_attacks">teardrop attacks</a>.</p>
<p>It would appear that some brave MS programmer pined for those days of remote BSODs, and thus has  <a href="http://seclists.org/fulldisclosure/2009/Sep/0039.html">reintroduced this beloved feature in the SMB2 protocol driver in Vista and Windows 7</a>.</p>
<p>Kudos!</p>
<img src="http://blog.molgaard.org/?ak_action=api_record_view&id=41&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://blog.molgaard.org/2009/09/10/microsoft-getting-nostalgic/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Now, where did that file go?</title>
		<link>http://blog.molgaard.org/2007/07/20/now-where-did-that-file-go/</link>
		<comments>http://blog.molgaard.org/2007/07/20/now-where-did-that-file-go/#comments</comments>
		<pubDate>Fri, 20 Jul 2007 15:14:04 +0000</pubDate>
		<dc:creator>Fjodor</dc:creator>
				<category><![CDATA[Microsoft]]></category>

		<guid isPermaLink="false">http://blog.molgaard.org/2007/07/20/now-where-did-that-file-go/</guid>
		<description><![CDATA[Hal Licino did an interesting experiment, suggesting that Hotmail loses an indecently high number of mails containing attachments. Worth noting, he did the experiment with paid for accounts, not the free ones, even though the numbers would be outrageous even if that was the case. Lost any mails in transfer lately? Using Hotmail? Go sue [...]]]></description>
			<content:encoded><![CDATA[<p>Hal Licino did <a href="http://hubpages.com/hub/Hotmail_Fails_To_Deliver_Up_To_81_Of_All_Attachment_Emails" title="An interesting experiment">an interesting experiment</a>, suggesting that Hotmail loses an indecently high number of mails containing attachments. Worth noting, he did the experiment with paid for accounts, not the free ones, even though the numbers would be outrageous even if that was the case.</p>
<p>Lost any mails in transfer lately? Using Hotmail? Go sue someone!</p>
<img src="http://blog.molgaard.org/?ak_action=api_record_view&id=20&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://blog.molgaard.org/2007/07/20/now-where-did-that-file-go/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Testing vista for 30 days -&gt; data loss and instability</title>
		<link>http://blog.molgaard.org/2007/04/05/testing-vista-for-30-days-data-loss-and-instability/</link>
		<comments>http://blog.molgaard.org/2007/04/05/testing-vista-for-30-days-data-loss-and-instability/#comments</comments>
		<pubDate>Thu, 05 Apr 2007 08:47:55 +0000</pubDate>
		<dc:creator>Fjodor</dc:creator>
				<category><![CDATA[Microsoft]]></category>

		<guid isPermaLink="false">http://blog.molgaard.org/2007/04/05/testing-vista-for-30-days-data-loss-and-instability/</guid>
		<description><![CDATA[HardOCP.com writer Brian Boyko took Vista for a spin, using it exclusively on his home machine for 30 days, resulting in 30 Days with Windows Vista. It is a lengthy piece, seems unbiased, and he even puts in a nice little disclaimer, stating that he is by no means an MS-basher. It could be hard [...]]]></description>
			<content:encoded><![CDATA[<p>HardOCP.com writer Brian Boyko took Vista for a spin, using it exclusively on his home machine for 30 days, resulting in <a href="http://enthusiast.hardocp.com/article.html?art=MTMxOCwxLCxoZW50aHVzaWFzdA==">30 Days with Windows Vista</a>.</p>
<p>It is a lengthy piece, seems unbiased, and he even puts in a nice little disclaimer, stating that he is by no means an MS-basher. It could be hard to tell, though, from what he has to say about Vista.</p>
<p>The only mildly interested readers should at least read the conclusion (reachable from the article front page).</p>
<img src="http://blog.molgaard.org/?ak_action=api_record_view&id=16&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://blog.molgaard.org/2007/04/05/testing-vista-for-30-days-data-loss-and-instability/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>When the Blue Screen of Death may be just that</title>
		<link>http://blog.molgaard.org/2007/02/26/when-the-blue-screen-of-death-may-be-just-that/</link>
		<comments>http://blog.molgaard.org/2007/02/26/when-the-blue-screen-of-death-may-be-just-that/#comments</comments>
		<pubDate>Mon, 26 Feb 2007 18:58:37 +0000</pubDate>
		<dc:creator>Fjodor</dc:creator>
				<category><![CDATA[Microsoft]]></category>

		<guid isPermaLink="false">http://blog.molgaard.org/2007/02/26/when-the-blue-screen-of-death-may-be-just-that/</guid>
		<description><![CDATA[I will probably never be heard touting the security and reliability of Windows. Never have, can&#8217;t see it happening anytime soon. It would seem however, that the UK&#8217;s Royal Navy is more easily impressed. Cue Windows 2000 for Warships&#8230; Am I the only one who remember the case of Windows 2000 and LAX not mixing [...]]]></description>
			<content:encoded><![CDATA[<p>I will probably never be heard touting the security and reliability of Windows. Never have, can&#8217;t see it happening anytime soon. It would seem however, that the UK&#8217;s Royal Navy is more easily impressed.</p>
<p>Cue <a href="http://www.theregister.co.uk/2007/02/26/windows_boxes_at_sea/">Windows 2000 for Warships</a>&#8230; Am I the only one who remember the case of Windows 2000 and LAX not <a href="http://www.techworld.com/opsys/news/index.cfm?NewsID=2275">mixing</a> <a href="http://software.silicon.com/applications/0,39024653,39124122,00.htm">well</a>?</p>
<img src="http://blog.molgaard.org/?ak_action=api_record_view&id=15&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://blog.molgaard.org/2007/02/26/when-the-blue-screen-of-death-may-be-just-that/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>UAC (still) not a security boundary</title>
		<link>http://blog.molgaard.org/2007/02/26/uac-still-not-a-security-boundary/</link>
		<comments>http://blog.molgaard.org/2007/02/26/uac-still-not-a-security-boundary/#comments</comments>
		<pubDate>Mon, 26 Feb 2007 18:13:59 +0000</pubDate>
		<dc:creator>Fjodor</dc:creator>
				<category><![CDATA[Microsoft]]></category>

		<guid isPermaLink="false">http://blog.molgaard.org/2007/02/26/uac-still-not-a-security-boundary/</guid>
		<description><![CDATA[Once again, a UAC vulnerability has been found. And once again, MS fails to see it as a problem&#8230;]]></description>
			<content:encoded><![CDATA[<p>Once again, a <a href="http://www.pcworld.com/article/id,129268/article.html">UAC vulnerability has been found. And once again, MS fails to see it as a problem&#8230;</p>
<img src="http://blog.molgaard.org/?ak_action=api_record_view&id=14&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://blog.molgaard.org/2007/02/26/uac-still-not-a-security-boundary/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Speak up or shut up</title>
		<link>http://blog.molgaard.org/2007/02/26/speak-up-or-shut-up/</link>
		<comments>http://blog.molgaard.org/2007/02/26/speak-up-or-shut-up/#comments</comments>
		<pubDate>Mon, 26 Feb 2007 13:58:10 +0000</pubDate>
		<dc:creator>Fjodor</dc:creator>
				<category><![CDATA[Microsoft]]></category>

		<guid isPermaLink="false">http://blog.molgaard.org/2007/02/26/speak-up-or-shut-up/</guid>
		<description><![CDATA[Known to most, Mr. Steve Ballmer has repeated ad nauseam his claims that Linux infringes on MS intellectual property. And contrasting his claims has been the utter reluctance to name even one case in which it is true. Sometimes someone has to call &#8220;enough&#8221;, and thus has come forward this open letter, urging MS to [...]]]></description>
			<content:encoded><![CDATA[<p>Known to most, Mr. Steve Ballmer has repeated ad nauseam his claims that Linux infringes on MS intellectual property. And contrasting his claims has been the utter reluctance to name even one case in which it is true.</p>
<p>Sometimes someone has to call &#8220;enough&#8221;, and thus has come forward <a href="http://showusthecode.com">this</a> open letter, urging MS to either identify problem areas or stop spreading unfounded FUD.</p>
<p>I call it most welcome, however the outcome may be.</p>
<img src="http://blog.molgaard.org/?ak_action=api_record_view&id=13&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://blog.molgaard.org/2007/02/26/speak-up-or-shut-up/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Microsoft &#8220;lost&#8221; evidence in Burst vs. Microsoft</title>
		<link>http://blog.molgaard.org/2007/02/17/microsoft-lost-evidence-in-burst-vs-microsoft/</link>
		<comments>http://blog.molgaard.org/2007/02/17/microsoft-lost-evidence-in-burst-vs-microsoft/#comments</comments>
		<pubDate>Sat, 17 Feb 2007 18:25:17 +0000</pubDate>
		<dc:creator>Fjodor</dc:creator>
				<category><![CDATA[Microsoft]]></category>

		<guid isPermaLink="false">http://blog.molgaard.org/2007/02/17/microsoft-lost-evidence-in-burst-vs-microsoft/</guid>
		<description><![CDATA[Remember the &#8220;Burst vs. Microsoft&#8221; case? At some point in time, Microsoft were ordered to deliver copies of email correspondence relating to Burst, but told the court it would be infeasible. The order was none the less repeated, but before said emails were delivered, the case was settled. Robert X. Cringely covered the case, and [...]]]></description>
			<content:encoded><![CDATA[<p>Remember the <a href="http://www.gendb.net/burst/investors_links.aspx?refid=t48&amp;srcid=t48&amp;sysid=1232272005022563_246_18_4-&amp;catid=burst_investors">&#8220;Burst vs. Microsoft&#8221; case</a>?</p>
<p>At some point in time, Microsoft were ordered to deliver copies of email correspondence relating to Burst, but told the court it would be infeasible. The order was none the less repeated, but before said emails were delivered, the case was settled. <a href="http://www.technologyevangelist.com/cringely.html">Robert X. Cringely</a> covered the case, and he recently <a href="http://www.technologyevangelist.com/2007/02/microsoft_dirty_tric_1.html">received an email</a> from a contractor involved in backup procedures within Microsoft.</p>
<p>The following timeline seems to cover the problem of the email correspondence:</p>
<ul>
<li>Microsoft is ordered to hand over the emails.</li>
<li>Microsoft informs the court that this would be infeasible</li>
<li><iph>None the less, Microsoft instructs their contractors to gather backups from the specified period, and store them at a given location</iph></li>
<li>The court repeats it&#8217;s orders</li>
<li><iph>The backup contractors discover that the previously gathered tapes are &#8220;mysteriously missing&#8221;, and are held responsible by Microsoft</iph></li>
<li>The case is settled out of court without Microsoft producing the emails</li>
</ul>
<p>How very convenient, and how very sad.</p>
<img src="http://blog.molgaard.org/?ak_action=api_record_view&id=12&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://blog.molgaard.org/2007/02/17/microsoft-lost-evidence-in-burst-vs-microsoft/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Microsoft fighting for open standards?</title>
		<link>http://blog.molgaard.org/2007/02/16/microsoft-fighting-for-open-standards/</link>
		<comments>http://blog.molgaard.org/2007/02/16/microsoft-fighting-for-open-standards/#comments</comments>
		<pubDate>Fri, 16 Feb 2007 19:16:34 +0000</pubDate>
		<dc:creator>Fjodor</dc:creator>
				<category><![CDATA[Microsoft]]></category>

		<guid isPermaLink="false">http://blog.molgaard.org/2007/02/16/microsoft-fighting-for-open-standards/</guid>
		<description><![CDATA[As may be known to you, proposals for open, XML-based document formats have been submitted to the ISO/IEC. Open Document Format (wikipedia article), ODF, meets the usual requirements for being an open standard, and on the outside, MS&#8217; competing format Office Open XML (wikipedia article), OOXML, appears to do so as well. ISO adoption of [...]]]></description>
			<content:encoded><![CDATA[<p>As may be known to you, proposals for open, XML-based document formats have been submitted to the ISO/IEC. Open Document Format (<a href="http://en.wikipedia.org/wiki/OpenDocument">wikipedia article</a>), ODF, meets the usual requirements for being an open standard, and on the outside, MS&#8217; competing format Office Open XML (<a href="http://en.wikipedia.org/wiki/Ooxml">wikipedia article</a>), OOXML, appears to do so as well.</p>
<p>ISO adoption of the OOXML format has been blocked by IBM, backing ODF, which has sparked <a href="http://www.microsoft.com/interop/letters/choice.mspx">this</a> open letter from MS, stating among other things that</p>
<blockquote><p> When ODF was under consideration, Microsoft made no effort to slow down the process because we recognized customers’ interest in the standardization of document formats.</p></blockquote>
<p>While it is true that MS did not hinder the standardisation process, it certainly did not forgo chances to hinder the adoption of it by interested parties: <a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;articleId=273815&amp;intsrc=news_ts_head">Inside story: How Microsoft &amp; Massachusetts played hardball over open standards</a>, Computerworld.com.</p>
<p>Furthermore, while a proposed standard may be openly presented, that certainly does not mean that it is openly implementable, as <a href="http://www.robweir.com/blog/2006/01/how-to-hire-guillaume-portes.html">this</a> article shows.</p>
<p>I will let it suffice to ask, if a standard containing the tags &#8220;lineWrapLikeWord6&#8243;, &#8220;useWord2002TableStyleRules&#8221; or &#8220;useWord97LineBreakRules&#8221; conveys a sense of openness or interoperabilty, considering that the formats for Word 6, Word 97 and Word2002 are strictly closed.</p>
<img src="http://blog.molgaard.org/?ak_action=api_record_view&id=11&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://blog.molgaard.org/2007/02/16/microsoft-fighting-for-open-standards/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>MS&#8217; answer to Rutkowska: UAC is not about security afterall</title>
		<link>http://blog.molgaard.org/2007/02/14/ms-answer-to-rutkowska-uac-is-not-about-security-afterall/</link>
		<comments>http://blog.molgaard.org/2007/02/14/ms-answer-to-rutkowska-uac-is-not-about-security-afterall/#comments</comments>
		<pubDate>Wed, 14 Feb 2007 08:58:40 +0000</pubDate>
		<dc:creator>Fjodor</dc:creator>
				<category><![CDATA[Microsoft]]></category>

		<guid isPermaLink="false">http://blog.molgaard.org/2007/02/14/ms-answer-to-rutkowska-uac-is-not-about-security-afterall/</guid>
		<description><![CDATA[Seems MS has an answer for Joanna Rutkowska (her blog entry), with regards to the situation described in my last post. Contrary to all statements leading up to the Vista relase, she quotes Mark Russinovich of MS as writing that UAC is not &#8220;a security boundary&#8221;, and thus that: Because elevations and ILs don’t define [...]]]></description>
			<content:encoded><![CDATA[<p>Seems MS has an answer for Joanna Rutkowska (<a href="http://theinvisiblethings.blogspot.com/2007/02/vista-security-model-big-joke.html">her blog entry</a>), with regards to the situation described in my last post.</p>
<p>Contrary to all statements leading up to the Vista relase, she quotes Mark Russinovich of MS as writing that UAC is not &#8220;a security boundary&#8221;, and thus that:</p>
<blockquote><p> Because elevations and ILs don’t define a security boundary, potential avenues of attack, regardless of ease or scope, are not security bugs.</p></blockquote>
<p>So, not only is the much hyped security measures not reagarded as security measures by MS, and thus their failing to provide security is a non-bug.</p>
<p>Now isn&#8217;t that lovely?</p>
<img src="http://blog.molgaard.org/?ak_action=api_record_view&id=9&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://blog.molgaard.org/2007/02/14/ms-answer-to-rutkowska-uac-is-not-about-security-afterall/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Joanna Rutkowska on Vista security</title>
		<link>http://blog.molgaard.org/2007/02/14/joanna-rutkowska-on-vista-security/</link>
		<comments>http://blog.molgaard.org/2007/02/14/joanna-rutkowska-on-vista-security/#comments</comments>
		<pubDate>Wed, 14 Feb 2007 08:35:10 +0000</pubDate>
		<dc:creator>Fjodor</dc:creator>
				<category><![CDATA[Microsoft]]></category>

		<guid isPermaLink="false">http://blog.molgaard.org/2007/02/14/joanna-rutkowska-on-vista-security/</guid>
		<description><![CDATA[Rutkowska is trying out Vista. And as always, it seems to be a different world than what MS marketing would have us believe&#8230; Quote from her blog: One thing that I found particularly annoying though, is that Vista automatically assumes that all setup programs (application installers) should be run with administrator privileges. [...] That means [...]]]></description>
			<content:encoded><![CDATA[<p>Rutkowska is trying out Vista. And as always, it seems to be a different world than what MS marketing would have us believe&#8230;</p>
<p>Quote from <a href="http://blog.molgaard.org/wp-admin/">her blog</a>:</p>
<blockquote><p> One thing that I found particularly annoying though, is that Vista automatically assumes that all setup programs (application installers) should be run with administrator privileges.<br />
[...]<br />
That means that if you downloaded some freeware Tetris game, you will have to run its installer as administrator, giving it not only full access to all your file system and registry, but also allowing e.g. to load kernel drivers!</p></blockquote>
<p>Now how about that. She describes the XP option of customised privileges, enabling the user to assign only the strictly required privileges for installing software, and still disallowing e.g. loading kernel drivers. Seems neat, but, alas, a thing of the past.</p>
<p>Next, she finds that while Vista still does go through some work to protect itself, it seems a little more careless with actual user data. In other words, even processes running at the lowest &#8220;Integrety Level&#8221; might still read data from more privileged processes. As she puts it:</p>
<blockquote><p>
So, the statistics look better and everybody is generally happier. Including the competition, who now has access to stolen data <img src='http://blog.molgaard.org/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' />
</p></blockquote>
<p>She goes on to describe her ability for an &#8220;IL&#8221; process to send keyboard and mouse events to a shell running as Administrator. How very reassuring.</p>
<p>Go Vista!</p>
<img src="http://blog.molgaard.org/?ak_action=api_record_view&id=8&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://blog.molgaard.org/2007/02/14/joanna-rutkowska-on-vista-security/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>
