<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://ts2blogs.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Ronaldg&amp;#39;s Ramblings</title><link>http://ts2blogs.com/blogs/ronaldg/default.aspx</link><description>Ronaldg&amp;#39;s Ramblings is a blog geared for the Microsoft partner audience.  It will generally contain posts around some aspect of Microsoft and its products and technologies that are pertinent to a Partner/influencer audience.  I hope you find this blog useful.</description><dc:language>en</dc:language><generator>CommunityServer 2007.1 (Build: 20917.1142)</generator><item><title>Which Server is Right for SOHO or Micro-biz customers?</title><link>http://ts2blogs.com/blogs/ronaldg/archive/2010/02/26/579628.aspx</link><pubDate>Fri, 26 Feb 2010 07:06:08 GMT</pubDate><guid isPermaLink="false">560f371f-757e-49b8-87a1-da047d47be11:579628</guid><dc:creator>ronaldg</dc:creator><slash:comments>0</slash:comments><description>&lt;p&gt;As most of you know, I seldom do the standard “cut-paste” thing for this blog and like to at least put my own spin around things, but this is something I ran across (the Q&amp;amp;A section below) that I think may be valuable, or at least interesting, to you even without my inimitable input or masterful massaging (a little alliterative humor there)…and I apologize for losing the source of this info, I would be more than happy to give credit for the Q&amp;amp;A if only I hadn’t lost the link to the source where I found it.&amp;#160; I ran across this Q&amp;amp;A while I was preparing a recent SMB (small and medium business) server platform and products presentation.&lt;/p&gt;  &lt;p&gt;Here’s a great link for info on &lt;a href="http://www.microsoft.com/smallbusiness/products/businessserver.aspx?CR_CC=100253861&amp;amp;WT.srch=1&amp;amp;CR_SCC=100253861&amp;amp;WT.srch=1"&gt;WHICH WINDOWS SERVER SOLUTION WORKS FOR YOU?&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;Also, I’d like to &lt;strong&gt;give a shout out to David Overton’s great blog around this same topic&lt;/strong&gt;: &lt;a title="http://davidoverton.com/blogs/doverton/archive/2009/08/20/server-line-up-for-small-businesses-and-home-is-increasing-in-options-or-complexity-for-some.aspx" href="http://davidoverton.com/blogs/doverton/archive/2009/08/20/server-line-up-for-small-businesses-and-home-is-increasing-in-options-or-complexity-for-some.aspx"&gt;http://davidoverton.com/blogs/doverton/archive/2009/08/20/server-line-up-for-small-businesses-and-home-is-increasing-in-options-or-complexity-for-some.aspx&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&lt;b&gt;Now for the Q&amp;amp;A…&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;&lt;b&gt;Q: What about Windows Server Foundation, does that replace SBS?&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;A: No. Windows Server Foundation is fulfilling the need for a cost-effective, general purpose server designed for organizations with less than 15 users. Windows SBS provides small businesses with an end to end solution beyond the server OS for small businesses with up to 75 users. The availability of both products is another great example of Microsoft’s commitment to the SMB segments offering greater choice and value over any other company.&lt;/p&gt;  &lt;p&gt;Here’s a link to the &lt;a href="http://www.microsoft.com/windowsserver2008/en/us/foundation.aspx"&gt;Windows Server 2008 R2 Foundation&lt;/a&gt; home page&lt;/p&gt;  &lt;p&gt;&lt;b&gt;Q: How is Windows Home Server different from Foundation Server?&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;A: Windows Server Foundation 2008 R2 is an entry level general purpose operating system designed specifically for business use (running business applications and securely sharing information and resources) and usually requires an experienced IT professional to set up and manage. Windows Home Server is designed for general consumer use and therefore does not require an experienced IT professional to install or support. Because of its simplicity, price point and key features, Windows Home Server is a great alternative for both home based businesses or small offices with up to 10 users who need an easy way to back up their PCs, centralize files, and access their files remotely.&lt;/p&gt;  &lt;p&gt;&lt;b&gt;Q: What is the recommended first server for small businesses?&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;A: Not all small businesses are the same; therefore Microsoft offers a portfolio of servers to choose from. As an example: Windows Home Server, while a great server for the home is also a great option for home-based businesses or small offices because of its ease of use and simple client back-up. Windows Server 2008 R2 Foundation is a great cost-effective entry level server operating system for businesses that need to run line of business applications, centralize their information and protect their data. Windows Small Business Server is a great first server for businesses who want an end to end solution that gives them secure remote access to support remote working, more control of employee access to business information, as well as a more effective and professional way to communicate internally and with their customers. SBS 2008 is also an ideal platform to run line of business applications because the premium edition includes a database.&lt;/p&gt;  &lt;p&gt;&lt;b&gt;Q: What is the portfolio of servers for SMB? &lt;/b&gt;&lt;/p&gt;  &lt;p&gt;A: Whether your business technology needs are on-prem&lt;i&gt;ise, virtual&lt;/i&gt;ized, in the cloud or hosted, there is a &lt;i&gt;‘just right’&lt;/i&gt; Windows Server offering for every customer need, size and geography.&lt;/p&gt;  &lt;p&gt;   &lt;table cellspacing="0" cellpadding="0"&gt;       &lt;tr&gt;         &lt;td&gt;           &lt;p&gt;&lt;b&gt;Pro&lt;/b&gt;&lt;b&gt;duct SKU &lt;/b&gt;&lt;/p&gt;         &lt;/td&gt;          &lt;td&gt;           &lt;p&gt;&lt;b&gt;Product Description &lt;/b&gt;&lt;b&gt;&amp;amp; # Users Supported&lt;i&gt; &lt;/i&gt;&lt;/b&gt;&lt;i&gt;&lt;/i&gt;&lt;/p&gt;         &lt;/td&gt;       &lt;/tr&gt;        &lt;tr&gt;         &lt;td&gt;           &lt;p&gt;&lt;i&gt;Windows H&lt;/i&gt;ome Server&lt;/p&gt;         &lt;/td&gt;          &lt;td&gt;           &lt;p&gt;Entry level server for home-ba&lt;i&gt;sed and smal&lt;/i&gt;l offices who need an easy way to back up their PCs, centralize files, and access their files remotely. &lt;/p&gt;            &lt;p&gt;&lt;b&gt;Up to 10 Users&lt;/b&gt;&lt;/p&gt;         &lt;/td&gt;       &lt;/tr&gt;        &lt;tr&gt;         &lt;td&gt;           &lt;p&gt;Windows Server 2008 R2 Foundation&lt;b&gt; &lt;/b&gt;&lt;/p&gt;         &lt;/td&gt;          &lt;td&gt;           &lt;p&gt;Entry level server operating system for running business applications and securely sharing information and resources.&lt;/p&gt;            &lt;p&gt;&lt;b&gt;Up to 15 Users &amp;amp; 1Proc System &lt;/b&gt;&lt;/p&gt;         &lt;/td&gt;       &lt;/tr&gt;        &lt;tr&gt;         &lt;td&gt;           &lt;p&gt;Windows Server 2008 R2 Standard&lt;b&gt; &lt;/b&gt;&lt;/p&gt;         &lt;/td&gt;          &lt;td&gt;           &lt;p&gt;Advanced server operating system with built in virtualization capabilities for increased reliability &amp;amp; security. &lt;/p&gt;            &lt;p&gt;&lt;b&gt;Unlimited Users &lt;/b&gt;&lt;/p&gt;         &lt;/td&gt;       &lt;/tr&gt;        &lt;tr&gt;         &lt;td&gt;           &lt;p&gt;Windows Small Business Server 2008&lt;b&gt; &lt;/b&gt;&lt;/p&gt;         &lt;/td&gt;          &lt;td&gt;           &lt;p&gt;Designed and Priced for Small Business&lt;/p&gt;            &lt;p&gt;All in one server suite for enhanced productivity and a more professional business image.&lt;/p&gt;            &lt;p&gt;&lt;b&gt;Up to 75 Users&lt;/b&gt;&lt;/p&gt;         &lt;/td&gt;       &lt;/tr&gt;        &lt;tr&gt;         &lt;td&gt;           &lt;p&gt;Windows Essential Business Server 2008&lt;b&gt; &lt;/b&gt;&lt;/p&gt;         &lt;/td&gt;          &lt;td&gt;           &lt;p&gt;Designed &amp;amp; Priced for Midsize Business&lt;/p&gt;            &lt;p&gt;Enterprise class server suite for enhanced manageability and security.&lt;/p&gt;            &lt;p&gt;&lt;b&gt;Up to 300 Users &lt;/b&gt;&lt;/p&gt;         &lt;/td&gt;       &lt;/tr&gt;        &lt;tr&gt;         &lt;td&gt;           &lt;p&gt;Windows Server 2008 R2 EE&lt;b&gt; &lt;/b&gt;&lt;/p&gt;         &lt;/td&gt;          &lt;td&gt;           &lt;p&gt;Advanced server operating system with built in virtualization capabilities and high availability for increased business agility. &lt;/p&gt;            &lt;p&gt;&lt;b&gt;Unlimited Users&lt;/b&gt;&lt;/p&gt;         &lt;/td&gt;       &lt;/tr&gt;     &lt;/table&gt; &lt;/p&gt;  &lt;p&gt;&lt;b&gt;Q: How does Windows Server 2008 Foundation compare to Window Server 2008 Standard.&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;A: Both Windows Server 2008 R2 Foundation and Windows Server Standard 2008 R2 are general purpose operating systems. Windows Server 2008 R2 Foundation is targeted at small businesses with less than 15 users, who buy low end hardware and want basic capabilities such as file/print share, offered by a product such as Windows Server Foundation. Windows Server 2008 R2 Standard provides businesses with more advanced capabilities such as built-in virtualization (compared to Foundation) and has no user restrictions. Windows Server Standard supports server hardware with up to 4 Physical processors.&lt;/p&gt;&lt;img src="http://ts2blogs.com/aggbug.aspx?PostID=579628" width="1" height="1"&gt;</description></item><item><title>ronaldg’s ramblings (on this blog site) going away</title><link>http://ts2blogs.com/blogs/ronaldg/archive/2010/02/26/579624.aspx</link><pubDate>Fri, 26 Feb 2010 07:01:35 GMT</pubDate><guid isPermaLink="false">560f371f-757e-49b8-87a1-da047d47be11:579624</guid><dc:creator>ronaldg</dc:creator><slash:comments>0</slash:comments><description>&lt;p&gt;As I’m sure you’ve figured out from some of my colleagues blogs excerpts on the TS2 blog home page, we’re moving off of this site/server and over to the TechNet Blog site.&amp;#160; This should happen around the end of March, so stay tuned here for at least the next 30 days or so as I’ll have some more posts on here before the move.&lt;/p&gt;  &lt;p&gt;We are also moving to a team blog scenario and I don’t know exactly how that will look yet, but hopefully it’ll be more convenient for those of you who follow several or all of the other TS2 team blogs.&amp;#160; Of course, it should reduce the number of redundant blogs, but I actually try not to blog about things that I know others are also blogging about, still I think it’s a good thing, and you will have access to an expanded array of topics and styles.&lt;/p&gt;  &lt;p&gt;You should be able to find the new site at &lt;a href="http://blogs.technet.com/uspartner_TS2Team"&gt;http://blogs.technet.com/uspartner_TS2Team&lt;/a&gt; and I see that some of my compadres have already started the ball rolling on our new site.&amp;#160; You will notice that the author is identified in small print at the bottom of each post in the following format:&lt;/p&gt;  &lt;p&gt;Posted by &lt;a href="http://blogs.technet.com/user/Profile.aspx?UserID=124444"&gt;MSFTTS2&lt;/a&gt; | &lt;a href="http://blogs.technet.com/uspartner_ts2team/archive/2010/02/20/live-meeting-audio.aspx#comments"&gt;0 Comments&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;Filed under: &lt;a href="http://blogs.technet.com/uspartner_ts2team/archive/tags/BPOS++Software+Plus+Services/default.aspx"&gt;BPOS Software Plus Services&lt;/a&gt;, &lt;a href="http://blogs.technet.com/uspartner_ts2team/archive/tags/Steve+Deming/default.aspx"&gt;Steve Deming&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;and each post will have a tag, so you use those to follow your favorite poster or topics via the RSS feed options provided.&amp;#160; In fact, you will likely want to use the Browse by tags (example below, and author is a tag) functionality to help you filter the results you want from what I suspect will be a prolific site.&amp;#160; And hopefully you’ll see me on there shortly.&amp;#160; I’m planning to put my first post up by end of next week.&amp;#160;&amp;#160; Thanks, see you in the new location shortly.&lt;/p&gt;  &lt;h4&gt;Browse by Tags&lt;/h4&gt; &lt;a href="http://blogs.technet.com/uspartner_ts2team/archive/tags/default.aspx"&gt;All Tags&lt;/a&gt; » &lt;a href="http://blogs.technet.com/uspartner_ts2team/archive/tags/Steve+Deming/default.aspx"&gt;Steve Deming&lt;/a&gt; &lt;a href="http://blogs.technet.com/uspartner_ts2team/rss.aspx?Tags=Steve+Deming&amp;amp;AndTags=1"&gt;(RSS)&lt;/a&gt;  &lt;ul&gt;   &lt;li&gt;&lt;a href="http://blogs.technet.com/uspartner_ts2team/archive/tags/Steve+Deming/BPOS++Software+Plus+Services/default.aspx"&gt;BPOS Software Plus Services&lt;/a&gt;&lt;/li&gt;    &lt;li&gt;&lt;a href="http://blogs.technet.com/uspartner_ts2team/archive/tags/Steve+Deming/Desktop+Platform/default.aspx"&gt;Desktop Platform&lt;/a&gt;&lt;/li&gt;    &lt;li&gt;&lt;a href="http://blogs.technet.com/uspartner_ts2team/archive/tags/Steve+Deming/Unified+Communications/default.aspx"&gt;Unified Communications&lt;/a&gt;&lt;/li&gt;    &lt;li&gt;&lt;a href="http://blogs.technet.com/uspartner_ts2team/archive/tags/Steve+Deming/Virtualization/default.aspx"&gt;Virtualization&lt;/a&gt;&lt;/li&gt; &lt;/ul&gt;&lt;img src="http://ts2blogs.com/aggbug.aspx?PostID=579624" width="1" height="1"&gt;</description></item><item><title>WooHoo!</title><link>http://ts2blogs.com/blogs/ronaldg/archive/2010/02/02/560595.aspx</link><pubDate>Wed, 03 Feb 2010 00:42:56 GMT</pubDate><guid isPermaLink="false">560f371f-757e-49b8-87a1-da047d47be11:560595</guid><dc:creator>ronaldg</dc:creator><slash:comments>0</slash:comments><description>&lt;p&gt;&lt;a title="http://www.bloomberg.com/apps/news?pid=newsarchive&amp;amp;sid=aajIjMcEp.E4" href="http://www.bloomberg.com/apps/news?pid=newsarchive&amp;amp;sid=aajIjMcEp.E4"&gt;Microsoft Outpaces Apple in Customer Satisfaction&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;Yep, that’s right.&amp;#160; Just couldn’t pass up the chance to blog about this.&amp;#160; If you’re interested, I’m sure you’ll read the entire article, so I’ll do &lt;em&gt;some&lt;/em&gt; summarizing here but not do any wholesale cut-paste.&amp;#160; My main reason for doing this post isn’t so much to brag about the obvious inference of the title (you believe that, don’t you?), or to add to the already great buzz around Windows 7 (hereafter referred to as Win7), but rather to point you to some (more) 3rd-party evidence that you can also show to your customers to help them overcome some of their Vista stigma or, in many cases, help them be more confident in rolling out what they likely perceive as “new technology” (but we both know that Win7 is leveraging all the reliability and security of the Vista platform while hopefully overcoming some of the negatives).&lt;/p&gt;  &lt;p&gt;As you’ll see, this article is from Bloomberg.com and it centers around a “Chart of the Day” which in this case is a chart showing the results of satisfaction surveys done by a London-based research firm YouGov for both Microsoft and Apple around satisfaction with their most recent OS upgrades (Windows 7 and Snow Leopard [SL] respectively).&amp;#160; The chart is essentially an overlay of the two surveys which purports to show, by percentage of positive “grades”, the relative customer satisfaction levels with the 2 products.&amp;#160; The basis of the article headline is that, since shortly after it’s release in Nov, Win7 has achieved higher percentages of positive grades than it’s rival (indeed, at the end of CY2009, according to the chart, Win7 was trending up and was at almost 75% satisfaction while SL remained consistently below 70%).&lt;/p&gt;  &lt;p&gt;Some of the things that I noticed (from the chart) that I thought I’d point out are:   &lt;br /&gt;- after it’s release, SL briefly spiked up to just over 70% but then plunged to well below 60% (Win7 has never gone below 60%), then did another peak (to only around 65%) before diving again back under 60% until gaining back to launch time levels of mid-to-upper 60%.    &lt;br /&gt;- Win7 launched at about the same mid-60% range as SL but has not had any plunges like SL, it did dip a couple of percentage points but not even as much as the second plunge of SL which was smaller than its first.&amp;#160; &lt;br /&gt;- I’ll be honest, I’m not doing research into why the dips happen (to find the “rest of the story” like I usually do), I just find it interesting that SL has only had better percentages for a few brief spikes all along the 7-month continuum, even when Win7 was still in pre-release.&lt;/p&gt;  &lt;p&gt;Of course, you can draw your own conclusions from the chart, and I’m not going to try and push this as some be-all-end-all proof of anything, but what I do want to point out is that I think, with all the halo-effect and general positive perception that Apple seems to enjoy, and with the lack of halo-effect and some of the (unfounded) negative perception, which you know I’ve commented on in this blog over time, that most folks (meaning your customers) would be very surprised to find out that Win7 enjoys a level of satisfaction that’s, in fact, comparable to (yea, even perhaps beats) Mac’s latest OS.&amp;#160; Man, I wish we could come up a commercial around this.&lt;/p&gt;  &lt;p&gt;You know I dislike anecdotal evidence being put forth as some sort of “leading indicator”, but in this case the quote was from an analyst for Directions on Microsoft and those folks are the real deal, so when they say something I generally find it &lt;em&gt;much&lt;/em&gt; more credible that than average supposed expert comment that I typically see.&amp;#160; And, his quote that “People who were thinking about buying a new PC are more likely to do so now. You’ll see slightly better sales.” is supported by what I see and hear all over the press.&amp;#160; So, again, back to my back premise here – hopefully you can use articles like this one to show your customers that now is the time get off that legacy stuff and get onto the current generation OS technology, and hopefully they will feel comfortable with Win7 knowing that it actually does enjoy a high satisfaction level amongst those who have actually used it.&amp;#160; That’s what I’m talking here.&amp;#160; You know as well as I do that when many of them take the step up they’ll be glad they did (on several levels) and hopefully you’ll reap the benefits as their Microsoft partner and trusted advisor.&lt;/p&gt;  &lt;p&gt;Interestingly, Apple declined to comment, go figure.&amp;#160; &lt;/p&gt;&lt;img src="http://ts2blogs.com/aggbug.aspx?PostID=560595" width="1" height="1"&gt;</description></item><item><title>Second shot at Second shot</title><link>http://ts2blogs.com/blogs/ronaldg/archive/2010/01/31/559901.aspx</link><pubDate>Sun, 31 Jan 2010 21:34:46 GMT</pubDate><guid isPermaLink="false">560f371f-757e-49b8-87a1-da047d47be11:559901</guid><dc:creator>ronaldg</dc:creator><slash:comments>0</slash:comments><description>&lt;p&gt;For those of you who are Microsoft technology certified already, or for those who are thinking about the value of adding technology certifications to your portfolio of industry acumen, there WILL be exams (to use a variation on the movie title phrase that’s really popular these days).&amp;#160; [Those already certified may well be refreshing or updating those certs for the Windows 7/Server 2008 wave of technology.]&amp;#160; For those that have done these kinds of exams, you know that sometimes they can be tricky.&amp;#160; Perhaps some of you even joined myself and Beatrice for some of our “Certification Prep Series” webcasts we did a couple of years back.&amp;#160; And, you may also remember the “Second Shot” testing promotion that has been very well received.&amp;#160; Well, I have really good news – the Second Shot program is back!&lt;/p&gt;  &lt;p&gt;Microsoft Learning (MSL) is bringing back Second Shot as part of its new Career Initiative, which is designed to help you (partner) and perhaps in some cases even some customers/clients to get trained and certified on Microsoft technologies. &lt;/p&gt;  &lt;p&gt;Those of you already certified certainly understand the value of having a Microsoft certification, whether it be for meeting the requirements of the higher levels of the Microsoft Partner Program (now Microsoft Partner Network) or just differentiating yourself from the crowd for other job or business purposes.&amp;#160; &lt;/p&gt;  &lt;p&gt;Well, since these exams are not free, a “bad day” in the test room has some potential financial impact.&amp;#160; For instance, I know some of you have employers who will reimburse for these exams, but even if you get reimbursed, they don’t necessarily reimburse for failed exams.&amp;#160; But with Second Shot you can now register for a &lt;strong&gt;free retake&lt;/strong&gt; (should you need it), and then take the first exam with less anxiety and fear of not passing. Second Shot is not available to everyone for any exam, but most of my partners who read this blog should qualify. &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;A couple of key things to note:&lt;/strong&gt;&lt;/p&gt;  &lt;li&gt;You must purchase a qualifying exam to be eligible for this offer (in case this wasn’t obvious &amp;lt;smile&amp;gt;)&lt;/li&gt;  &lt;li&gt;This current promotion is valid from &lt;strong&gt;January 13, 2009 – June 30, 2010.&lt;/strong&gt; (meaning you must sit for both the first and (if necessary) second retake exams before June 30, 2010. &lt;/li&gt;  &lt;li&gt;&lt;strong&gt;Eligible Exams:&lt;/strong&gt; All 070 and 083 exams.&lt;/li&gt;  &lt;p&gt;Second Shot is available worldwide (except India and China) and &lt;strong&gt;only at Prometric Testing Centers&lt;/strong&gt;.&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Here’s the link to get more info on the Second Shot offer:      &lt;br /&gt;&lt;a href="http://www.microsoft.com/learning/en/us/offers/Career.aspx#certification"&gt;Special Offers on Training and Certifications from Microsoft&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;&lt;a href="http://www.microsoft.com/learning/en/us/offers/career.aspx"&gt;&lt;img style="border-bottom:0px;border-left:0px;display:inline;border-top:0px;border-right:0px;" title="clip_image002" border="0" alt="clip_image002" src="http://ts2blogs.com/blogs/ronaldg/clip_image002_01382750.jpg" width="297" height="103" /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;And while I’m on the subject of certification, here’s a link to a new MSL site that lists job roles, learning paths and other resources for getting certified in the Microsoft technology area of your choice:&lt;strong&gt; &lt;/strong&gt;&lt;a href="http://www.microsoft.com/learning/en/us/start/start-career.aspx"&gt;&lt;strong&gt;Microsoft Professional Career Portal&lt;/strong&gt;&lt;/a&gt;&lt;strong&gt;.&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;On a side note, one of the things I’ll be doing now that I’m back in TS2 is being the “Champ” if you will for Microsoft Learning and our Learning Solution (CPLS) competency and our CPLS partners. So expect to see more posts from me around certifications in the future.&lt;/p&gt;&lt;img src="http://ts2blogs.com/aggbug.aspx?PostID=559901" width="1" height="1"&gt;</description></item><item><title>Great new opportunity to connect with other partners and Microsoft!</title><link>http://ts2blogs.com/blogs/ronaldg/archive/2010/01/20/556904.aspx</link><pubDate>Wed, 20 Jan 2010 23:21:54 GMT</pubDate><guid isPermaLink="false">560f371f-757e-49b8-87a1-da047d47be11:556904</guid><dc:creator>ronaldg</dc:creator><slash:comments>0</slash:comments><description>&lt;p&gt;&lt;b&gt;&lt;/b&gt;One of the key “benefits” of the TS2 style public events that our team did (and many of you likely attended), and something we always got good feedback on, was that those events were opportunities for our mainstream partners, especially our core Registered Partner base, to meet and mix, aka network, with other partners who were also invested in the Microsoft technologies and partner “ecosystem”.&amp;#160; Well, since we’ve stopped doing those events, some of our partners have had to look for other vehicles to leverage for networking.&amp;#160; And, if you’re not familiar with them, I’d like to take this opportunity to introduce and put a “shout out” to the &lt;a href="http://www.iamcp.org/pages/about.aspx"&gt;IAMCP&lt;/a&gt; (International Association of Microsoft Certified Partners) organization – they’re a great org for any Microsoft partner to invest in, especially if you’re interested in the personal/business networking aspect.&amp;#160; But this post really isn’t about IAMCP, it’s about another &lt;strong&gt;brand new opportunity for you to join the Microsoft Partner Network (MPN) &lt;a href="http://www.microsoftpartnernetwork.com/"&gt;Community&lt;/a&gt;.&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;The MPN &lt;a href="http://www.microsoftpartnernetwork.com/"&gt;Community&lt;/a&gt; is a place, hosted right on the Partner Portal, where you can connect and collaborate with other partners and with Microsoft as well.&amp;#160; In fact, the MPN Community was &lt;strong&gt;designed specifically to facilitate real-time networking opportunities between people, like yourselves, who are selling or building Microsoft solutions and Microsoft&lt;/strong&gt;. This is way better than the TS2 events because now you’re not just networking with a small group of local partners, but engaged with a much larger sphere of influence and opportunity.&amp;#160; &lt;/p&gt;  &lt;p&gt;So, by way of introducing you to the new MPN Community, let me suggest some ways for you to engage with your peers and Microsoft globally or directly within your region. Among other things, you can:&lt;/p&gt;  &lt;p&gt;1. See what’s happening in your local community and region, as well as attend partner events and engage in social media with people in your community.&lt;/p&gt;  &lt;p&gt;2. Get involved in Microsoft communities focused on student talent for hire, public policy affecting the technology industry, technology training and education and much more.&lt;/p&gt;  &lt;p&gt;3. Join the conversation with Microsoft and other partners through online social media like Twitter, Facebook and Microsoft and partner blogs.&lt;/p&gt;  &lt;p&gt;4. Keep up to date with the latest partner relevant news, webcasts, and videos, and find product specific information and training within the broader Microsoft partner network.&lt;/p&gt;  &lt;p&gt;And, finally, I’d like to direct you to a few partner network community resources that may be of interest to you and help you start the conversation with other partners and Microsoft. &lt;/p&gt;  &lt;p&gt;· &lt;a href="http://www.microsoftpartnernetwork.com/Social"&gt;Join the community Twitter feed and the partner network Facebook page&lt;/a&gt; (and the home page even has a link to a &lt;a href="http://mpncommunity.blob.core.windows.net/downloads/Partner_Community_FAQ.doc"&gt;FAQ&lt;/a&gt; to learn more about “social media” in case you’re a slacker like me who hasn’t really gotten immersed in all that stuff as yet.)&lt;/p&gt;  &lt;p&gt;· Watch short video series on &lt;a href="http://www.microsoftpartnernetwork.com"&gt;SMB, Windows 7, and Azure.&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;· Take a sneak peek at what is being planned for the &lt;a href="http://digitalwpc.com/"&gt;2010 Worldwide Partner Conference &lt;/a&gt;&lt;/p&gt;  &lt;p&gt;Hopefully, I got you at least curious enough to check it out now, and even more so, I hope you’ll find it to be a useful tool to engage with other Microsoft partners, as well as Microsoft, to help you get even more out of your investment in being a part of our partner.&lt;/p&gt;&lt;img src="http://ts2blogs.com/aggbug.aspx?PostID=556904" width="1" height="1"&gt;</description></item><item><title>Logical thinking, a lost art?</title><link>http://ts2blogs.com/blogs/ronaldg/archive/2009/12/31/550990.aspx</link><pubDate>Fri, 01 Jan 2010 00:47:37 GMT</pubDate><guid isPermaLink="false">560f371f-757e-49b8-87a1-da047d47be11:550990</guid><dc:creator>ronaldg</dc:creator><slash:comments>0</slash:comments><description>&lt;p&gt;Well, if you’ve read the last couple of posts you are aware that I’ve cast some aspersions on many folks who comment on blog posts and articles.&amp;#160; It seems to me a huge majority of them are seriously un-, under-, or mis-informed about the topics and issues they nonetheless take the liberty to comment on.&amp;#160; Of course, everyone has an opinion about Microsoft (MS), and as an MS employee for the last 12+ years, I would say that one could consider it “logical” to conclude that I would know more about MS than the vast majority of the folks who offer their opinions on our products and business practices in online venues.&amp;#160; In fact, I’m betting that my tenure at MS, and the presumed credibility it entails, is perhaps a primary reason why you bother to read this blog.&amp;#160; Of course, I’m constantly piqued, or some would say “tweaked”, by the wildly inaccurate stuff I see posted, especially in comments.&amp;#160; You likely remember in my last post (same song, second verse…), that I called out one particular comment (on XP being more secure than Vista) that was an amazing example of the type of un- or misinformed commentary that seems all too prevalent today – especially around the topic of Microsoft.&amp;#160; And you might also recall, I called out his poor logic but chose not to address it in that post.&amp;#160; As another interesting coincidence, I ran across this post from Robert Strohmeyer, of PC World, around the sad state of “logic” as it is used (or rather, more commonly, &lt;em&gt;abused&lt;/em&gt;) in the internet “echo chamber”.&amp;#160; As we close out 2009 and look forward to the new decade of 201x’s, I thought I would take this opportunity to do a post on a “generic” topic – I hope you find this interesting, if not informative.&amp;#160; I also hope that you’ve not found these logic fallacies to be characteristic of my posts and opinions.&amp;#160; I try to be objective (as I can be &amp;lt;grin&amp;gt;) and factual, and when I call out other opinions and posts that I disagree with I typically try to put out a well-supported and credible rationale as a counterpoint, not just flame the writer (for being so ignorant &amp;lt;smile&amp;gt;…just joking) as so many others do.&amp;#160; &lt;/p&gt;  &lt;p&gt;So here’s the link to the post:&amp;#160; &lt;a href="http://www.pcworld.com/article/184426/the_webs_most_illogical_arguments.html"&gt;The Web&amp;#39;s Most Illogical Arguments&lt;/a&gt;.&amp;#160; The title is self-explanatory, although he only points out 10 of the many logical fallacies that occur.&amp;#160; To that end, I’ve included some links below for you to get more comprehensive info around logic fallacies, if you choose.&amp;#160; I like his opening: &lt;/p&gt;  &lt;p&gt;“The Internet is teeming with crazies, jerks, and blowhards; and in online forums, debaters are full of passionate intensity. Peruse the comments area on any popular blog, and you&amp;#39;ll find more irrational rhetoric than you can shake an encyclopedia at.&amp;#160; What separates rational thought from bogus blather is logic. Unfortunately, sound logical thinking is a learned skill that&amp;#39;s rarer than we might hope, and it&amp;#39;s not the same as so-called common sense.”&lt;/p&gt;  &lt;p&gt;[Assuming you just read the post&amp;#39;] Did you see any (or a lot of) logic fallacies that you recognize from recent readings?&amp;#160; I’d be really surprised if you didn’t.&lt;/p&gt;  &lt;p&gt;In his paragraph on “What’s a Fallacy”, as he explains what fallacy is, he makes the following observation that I think is reasonably astute: “&lt;em&gt;Using or falling for fallacious reasoning is by no means a sign of stupidity&lt;/em&gt;.[emphasis mine] Lots of smart people inadvertently use or get taken in by irrational arguments from time to time--through lack of attention, lack of understanding about how logic works, or the simple fact that human psychology is riddled with weird idiosyncrasies that make us susceptible to misunderstanding.”&amp;#160; Again, using TJ (from yesterday’s post) as an example, his erroneous conclusion isn’t based so much on the fact that he doesn’t know anything (stupidity) so much as he doesn’t know enough about the subject he’s commenting on which leads him into logic errors – which is what I find to be the most common problem out there.&amp;#160; Folks know a lot about one thing, and think they know a lot about other stuff as well, but I find, at least in the majority of external commentary on Microsoft, that this presumed knowledge is seldom founded on actual facts but rather perceptions (usually erroneous), or purely anecdotal evidence, or outdated information (based on unfortunate generalizations of past events).&amp;#160; And sadly, many, if not most, are content to spew their opinions based on this lack of, or faulty, information.&amp;#160; Case in point – TJ makes bases his conclusion that XP is more secure than Vista on the following premise: “outside security analyst have been scouring Windows XP for almost a decade, while Windows 7 has a lot of new code [which is not being scoured]”.&amp;#160; Well, one of the &lt;strong&gt;rules of logic&lt;/strong&gt; is that if you start with a false premise you &lt;em&gt;will&lt;/em&gt; end up with a false conclusion.&amp;#160; TJ makes two errors right out of the box: one is the (false) assumption that security analysts scouring a codebase for some extended length of time is somehow an objective measure of fundamental security of that codebase; and two, the also false assumption that the Vista codebase (although newer) was not scrutinized to the any great extent.&amp;#160; On this second point, he is woefully uninformed about the SDL as well as apparently any or all of the data out there that shows how much more secure Vista is than XP – I sure hope he read CW’s response.&amp;#160; On a related note, I saw another comment on another blog that basically tried to make the case the Firefox was more secure and stable the IE because that person hadn’t had a Firefox error in months (a hasty generalization or proof by example fallacy at best or possibly a confirmation bias – you make the call, or identify a fallacy that’s even more relevant).&amp;#160; Again, with that kind of anecdotal evidence and logic, I could have made the case that since I hadn’t a problem with IE in a year, that would logically make IE 2-3x more robust and secure than FF.&amp;#160; Of course we would both be wrong.&amp;#160; I just wish more folks would be more responsible in their commentary.&lt;/p&gt;  &lt;p&gt;But the real point of this is “be careful out there”.&amp;#160; I would suggest not just a “grain of salt” but rather a healthy dose of skepticism when reading online content and comments.&amp;#160; Know your logic fallacies and remember, even what appears to be decent logic is completely negated when the premise, or basis, is false.&amp;#160; &lt;/p&gt;  &lt;p&gt;And, btw, if I’ve piqued your interest with this post, here’s some more links to info on logic fallacies.&lt;/p&gt;  &lt;p&gt;&lt;a href="http://www.logicalfallacies.info/"&gt;Logical Fallacies&lt;/a&gt;, &lt;a title="http://en.wikipedia.org/wiki/List_of_fallacies" href="http://en.wikipedia.org/wiki/List_of_fallacies"&gt;List of fallacies (wikipedia)&lt;/a&gt;, &lt;a title="http://www.skepdic.com/refuge/ctlessons/lesson5.html" href="http://www.skepdic.com/refuge/ctlessons/lesson5.html"&gt;Critical Thinking mini-lesson 5 (Skeptic.com)&lt;/a&gt;, &lt;a title="http://leo.stcloudstate.edu/acadwrite/logic.html" href="http://leo.stcloudstate.edu/acadwrite/logic.html"&gt;Logical Fallacies (LEO: Literary Education Online)&lt;/a&gt;, these are the ones I would recommend.&amp;#160; But it you’re in for a logic challenge, try this one (&lt;a href="http://www.badarguments.org/ba/Home.aspx"&gt;Bad Arguments&lt;/a&gt;) where you can test your logic skills (don’t want to brag, but I got all of the practice ones correct &amp;lt;grin&amp;gt;), hopefully you will too.&amp;#160;&amp;#160; Cheers.&amp;#160; Hope you have a great 2010.&lt;/p&gt;&lt;img src="http://ts2blogs.com/aggbug.aspx?PostID=550990" width="1" height="1"&gt;</description></item><item><title>Same song, second verse…answering the question: “Does Microsoft Look for Vulnerabilities in Their Own Products?”</title><link>http://ts2blogs.com/blogs/ronaldg/archive/2009/12/30/550675.aspx</link><pubDate>Wed, 30 Dec 2009 23:21:49 GMT</pubDate><guid isPermaLink="false">560f371f-757e-49b8-87a1-da047d47be11:550675</guid><dc:creator>ronaldg</dc:creator><slash:comments>0</slash:comments><description>&lt;p&gt;Wow, just when I thought I had hit the security theme pretty well and could kick back for the rest of the holidays, I see this on the PC Magazine Security Watch blogs.&lt;/p&gt;  &lt;p&gt;&lt;a title="http://blogs.pcmag.com/securitywatch/2009/12/does_microsoft_look_for_vulner.php#more" href="http://blogs.pcmag.com/securitywatch/2009/12/does_microsoft_look_for_vulner.php#more"&gt;Does Microsoft Look For Vulnerabilities in Their Own Products?&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;Well, if you even entertained the initial thought that the answer could be no, I sentence you to go back and read every security-related blog post I’ve written &amp;lt;grin&amp;gt;.&amp;#160; This post came about because of a Twitter whine by researcher Alex Sotirov who complained that vendors weren&amp;#39;t paying those (presumably like himself) who found the bugs in their products, and that this was somehow unjust.&amp;#160; I actually recommend you read this post by Larry Seltzer, although at the end he seems to reach the conclusion that he agrees with Sotirov.&amp;#160; I disagree with his conclusion on several bases but let me cover the post in general, and then address what I feel are the flaws in his conclusion later.&lt;/p&gt;  &lt;p&gt;Right up front Seltzer points out that “Most of the bug-finding for major products comes from researchers paid by someone for their work.”&amp;#160; For sure, most vendors like Microsoft, leverage the findings of external researchers in this regard, but I would like to see some proof of the assertion that “most” of the bug-finding is done by these folks, but this is just another example of how easy it is make an unsubstantiated declarative comment that many folks accept at face value but with no real vetting or substantiation to back it up.&amp;#160; I can’t say that I still know this for a fact (full disclosure on my part), but back when I was a security-focused Technology Specialist for Microsoft, in the early days of SDL (and the associated SWI, Secure Windows Initiative), I know that we not only did our own internal code sweeps (reviews), but also contracted with several external agencies to supplement that effort.&amp;#160; Seltzer subsequently notes that some folks were “credited” for their bug-finds, but then notes that other vulnerabilities were not credited, acknowledging that some were “privately reported”.&amp;#160; So this brought Seltzer to pose the title question to a “famous researcher”, Dino Dai Zovi, who basically said (or rather implied) &lt;em&gt;no&lt;/em&gt;, citing that Apple was “the only vendor &lt;em&gt;he knew of &lt;/em&gt;that patches internally found vulnerabilities” – I guess I’ll take his word for it that Dino is famous and credible and knows all the vendors methodologies well enough to make his statement.&amp;#160; Of course, for Seltzer “this rang true” since he looked and found out that Microsoft had not credited any internal research sources in vulnerability disclosures in 2009 (which btw begs the question of whether or not crediting internal research is, or should be, the standard to go by, which I’ll be getting to in a moment).&amp;#160;&amp;#160; So he asked Microsoft about it directly – nice work Larry (finally a little journalism by someone).&amp;#160;&amp;#160; As you should know, &lt;strong&gt;Microsoft confirmed that YES, of course they look for and find vulnerabilities internally&lt;/strong&gt; (after all that’s the whole point of SDL which is mentioned in Larry’s quote from an unnamed Microsoft person).&amp;#160; But curiously, although he acknowledges the fact that MS does internal vulnerability research, he finishes the sentence with “but not so much”, which I can only infer he says because Microsoft doesn’t report (or credit) it in the same way as other vendors (e.g. Apple) who, if you read my last post, may &lt;em&gt;not&lt;/em&gt; be the vendor(s) I would&lt;em&gt; &lt;/em&gt;be looking at as an example in this area.&amp;#160; One key piece of the vulnerability equation that seems to be ignored here is a discussion on whether or not all vulnerabilities &lt;em&gt;need&lt;/em&gt; to be proactively patched, and then whether acknowledging internal vulnerability research is a “best practice” which seems to be at the heart of his “but not so much” comment as well as his ultimate conclusion.&amp;#160; As you should know, a vulnerability, in and of itself, is not really a problem -- it only becomes a problem when someone develops an “exploit” against it presumably with malicious intent.&amp;#160; So I would ask, if I know that my program has a certain vulnerability but you do not, is it really a best practice for me to &lt;em&gt;proactively&lt;/em&gt; patch that vulnerability and thereby make a de facto announcement of it (when I release the patch) that could be used to develop an exploit against unpatched systems?&amp;#160; Well, apparently Larry and Alex and Apple think so, and if you have the small market share, and thus largely untargeted platform (the security by obscurity situation that I’ve blogged about before), that Apple has, you can do this; but to foist that paradigm on everyone is not my idea of a best practice.&amp;#160; Now Larry notes in his next to final paragraph that MS08-037 leveraged Microsoft’s “own work in finding the [bug]…”, but then states in his bottom line that “[they] don’t do proactive vulnerability research on their own shipping products”.&amp;#160; Which conclusion, btw, he arrives at by mentioning that “&lt;strong&gt;Microsoft spends a lot of time and money and effort on the security of their products&lt;/strong&gt;, but they&amp;#39;re almost entirely forward-looking about it.&amp;quot;, which he then characterizes in a negative light as “neglect” of current products.&amp;#160; I don’t know about you, but this is pretty convoluted in my opinion to say the we “do” a lot of something, but then spin that as neglect because apparently we &lt;em&gt;may&lt;/em&gt; not buy into the (proactive) patching paradigm he assumes as a standard.&amp;#160; I would also suggest that his conclusion which infers that we need to be paying outside folks more to find and report stuff that, btw, wouldn’t be a problem if they didn’t find it (with the intent of publishing it) is also suspect in my opinion, but you can make the call on that – at least you’ll have a counterpoint to consider now.&lt;/p&gt;  &lt;p&gt;In my final thoughts, I would urge you to read the quote in the article from the (unidentified) Microsoft person.&amp;#160; The main reason, I would suggest, that most external vulnerability finds are “credited” is because those folks desire the recognition as it adds to their resume (or street cred).&amp;#160; Also, most of them intend to “publish” the vulnerability which means that Microsoft must proactively patch it.&amp;#160; On the other hand, internally found vulnerabilities are generally not going to be published (and become the basis for future exploits) and thus there’s no reason to spend cycles proactively patching them, at least that’s how I believe we look at it.&amp;#160; And, as the anonymous quote points out, these are all part of the ongoing SDL process.&amp;#160; Also, I’ll bet that most internal Microsoft security researchers are not “in it’ for the external recognition, so to spin that anonymity as evidence that supposedly only “other people are finding bugs in their products” and need to be paid more, well, I’m afraid I have a problem with that conclusion per above.&amp;#160; As Larry says at the end “something’s not right with this”, but I would say that what’s not right is less about how Microsoft approaches vulnerability research and reporting but more about how Larry reports on it.&amp;#160; As always, “you make the call”, but I hope this serves to point out how careful (and critical) you need to be when reading anything online these days (even me &amp;lt;grin again&amp;gt;).&lt;/p&gt;  &lt;p&gt;Oh, btw, remember what I said in the past post about the usual uninformed comments – here’s the very first comment on Larry’s post: “Another reason why Windows XP is actually more secure than Windows 7 - outside security analyst have been scouring Windows XP for almost a decade, while Windows 7 has a lot of new code for-which Microsoft basically admits in this article that it&amp;#39;s not researching. Now that&amp;#39;s security you can trust...NOT![commented by TJ]”&amp;#160; Wow, this would be funny if it wasn’t just so wrong on several levels.&amp;#160; Unfortunately there’s probably more than one “TJ” out there who actually believes that XP is more secure than Win7, (and I won’t even comment on his flawed logic).&amp;#160; I couldn’t have come up with a better example of uninformed commentary if I had tried.&amp;#160; Moreover, I’m not sure which article he read to make the statement “Microsoft basically admits in this article that it&amp;#39;s not researching…” but the incongruity doesn’t seem to phase TJ.&amp;#160; On the other hand, &lt;strong&gt;do read&lt;/strong&gt; the follow-on comment by CW (in response to TJ) – among other things he points out &lt;strong&gt;this article which I would rate as a must read&lt;/strong&gt;, &lt;a title="http://www.eweek.com/c/a/Security/Behind-the-Scenes-at-Microsofts-Secure-Windows-Initiative/" href="http://www.eweek.com/c/a/Security/Behind-the-Scenes-at-Microsofts-Secure-Windows-Initiative/"&gt;Behind the Scenes at Microsoft`s Secure Windows Initiative&lt;/a&gt;, especially if you still have any doubts or interest as to how we deal with reported vulnerabilities.&amp;#160;&amp;#160; OK, so now hopefully on with my holiday – see you next year.&lt;/p&gt;&lt;img src="http://ts2blogs.com/aggbug.aspx?PostID=550675" width="1" height="1"&gt;</description></item><item><title>Here’s some food for thought the next time someone complains about “buggy” Microsoft software, also please check out the recommended reads listed toward the end</title><link>http://ts2blogs.com/blogs/ronaldg/archive/2009/12/28/549964.aspx</link><pubDate>Mon, 28 Dec 2009 17:45:12 GMT</pubDate><guid isPermaLink="false">560f371f-757e-49b8-87a1-da047d47be11:549964</guid><dc:creator>ronaldg</dc:creator><slash:comments>0</slash:comments><description>&lt;p&gt;Most of you already know that in this age of the Secure Computing Initiative (aka Secure Development Lifecycle) at Microsoft that we actually have made tremendous strides in providing not only more secure software but more robust software as well.&amp;#160; Of course, whenever you make a platform change, as we did with Vista, you’re going to run into driver and application platform issues that give the OS the appearance of “bugginess”, but most of you are technical enough to appreciate that driver issues are not a sign of inherent OS problems but rather an indicator of OEM/ISV development weaknesses on one level or another (funny, you seldom hear about driver issues with OSS, but they’re not immune).&amp;#160; In fact, as I’ve toured the country doing live presentations to partners audiences for TS2 over the last 3 years (since Vista), I’ve routinely found that the vast majority of partners were happy with Vista – of course, some had customers with legacy hardware or software issues, but outside of those issues, there was was overwhelming support for Vista from a partner perspective.&amp;#160; The trade press, however, fostered a negative perception about Vista that’s all too well known at this point, usually relying on anecdotal and unsupported evidence, which of course has been the subject of many blogs on my part over the last few years.&amp;#160; But &lt;strong&gt;what’s really interesting to me&lt;/strong&gt; is how little the trade press seems to focus on other software vendors who continue to put out vulnerable software that’s developed using the same old dev paradigms that they’ve used since the previous millenium -- no SDL for them, and the results are not at all surprising, other than, as I said, the lack of attention around this they seem to enjoy (especially our fruit-branded friends).&amp;#160; If you’ve read my posts for some time now you’ll know that the headline “Vista hacked” from a past PWN2OWN contest was actually the result of an Adobe software exploit.&amp;#160; And you also know that the Apple platform, and browser, only gives the appearance of security (by obscurity, or lack of value due to small market share), and is always the easiest to hack and first to fall in these hacking contests.&amp;#160; Yet, have you ever heard the trade press take Apple or Adobe (as major examples) to task for not doing something like Microsoft’s SDL to improve their dev practices?&amp;#160; So it’s interesting to me, and worthy of a post, when I come across an article like this one that at least highlights the situation.&amp;#160; &lt;strong&gt;I recommend this article on ZDNet&lt;/strong&gt;,&amp;#160;&amp;#160; &lt;a href="http://news.zdnet.com/2346-9595_22-376428.html?tag=nl.e539"&gt;10 Most Vulnerable Software Apps of 2009 [ZDNet]&lt;/a&gt;.&amp;#160; Interestingly, this is one of the few times I actually found some of the comments worth a read as well.&amp;#160; (Usually the comments are a complete waste of time IMHO, since the vast majority of them seem to be done by uninformed, but highly opinionated, “fanboys” of one ilk or another – and this one has those, but it also includes some that are actually worthwhile.)&amp;#160; One comment (#30 “Where have you been lately?”), does a good summary of the promise of the SDL without naming it specifically.&amp;#160; Of course, the response to him (#31) was the typical uninformed fanboy type.&amp;#160; The main reason I’m recommending this is to highlight that the vendors I called out above are still leading the pack in producing software that’s not as robust as it could be – no, it’s not to point out that there’s no Microsoft app in the list &amp;lt;smile&amp;gt;, but I’m guessing you’ll notice that anyway.&amp;#160; Of course, no software will likely ever be bug-free, so my point here isn’t to cast aspersions on them because of a few vulnerabilities, but rather to point out that where Microsoft has changed their dev paradigm and is actually on an obvious course to more robust software out-of-the-box, the other vendors, for whatever their reasons, are not seeming to feel the need to modernize their dev efforts, thus, my point is, that I’ve made many times before, is that you should be talking to your customers about the strategic implications of this in helping them plan their IT strategies and deployments.&amp;#160; Actually I did some research on this article and discovered something called the &lt;a href="http://www-935.ibm.com/services/us/iss/xforce/trendreports/"&gt;X-Force Threat Reports&lt;/a&gt; that I wanted to point out in case you weren’t aware either.&amp;#160; One of the commenters referenced the X-Force 2008 Annual Trend and Risk report, which is a little dated now, but I may check back for their 2009 version in the near future.&amp;#160; And, in that vein, don’t forget that Microsoft publishes their &lt;a title="http://www.microsoft.com/downloads/details.aspx?FamilyID=037f3771-330e-4457-a52c-5b085dc0a4cd&amp;amp;displaylang=en" href="http://www.microsoft.com/downloads/details.aspx?FamilyID=037f3771-330e-4457-a52c-5b085dc0a4cd&amp;amp;displaylang=en"&gt;Microsoft Security Intelligence Report&lt;/a&gt; semi-annually (the last one was published in Nov for the Jan-Jun 2009 time frame) – &lt;strong&gt;I highly recommend you download and read the Findings Summary &lt;/strong&gt;(if you don’t want to wade thru the entire report).&amp;#160; For instance, it really shows how much less vulnerable Vista is than XP (this period was prior to Win7 launch), and that Trojans are now the primary threat in the US.&amp;#160; And you should also &lt;strong&gt;check out the Exploit Trends - Browser-Based Exploits section&lt;/strong&gt; (pages 9-11) for a very interesting look at how moving to Vista significantly reduces browser vulnerability – check out this excerpt: “Microsoft software accounted for 6 of the top 10 browser-based vulnerabilities attacked on computers running Windows XP in 1H09, compared to only 1 on computers running Windows Vista. The vulnerabilities are referenced below by the relevant CVSS bulletin number or by Microsoft Security Bulletin number as appropriate.”&amp;#160; Armed with that knowledge, I’m hoping you can make a strong case for the security benefits of Vista/Win7 over XP in those customer IT conversations I referenced above.&lt;/p&gt;  &lt;p&gt;Bottom line, which comes as no surprise to my readers, is that, thanks to SDL, the Microsoft platform (and software) while certainly not perfect is nonetheless on a trend toward safer and more robust computing than any of the other platform or major software vendor and this is a message I hope you’re already sharing with your customers.&amp;#160; As this becomes more well-known and obvious, I’m hoping that many of you will be able to help your customers overcome some of the legacy attitudes (don’t do “dot zero” or “always wait for SP1”) that are keeping them from adopting “modern” technology that will in fact work better and will produce ROI for their IT investment.&amp;#160; Not to mention, help you help them with more advanced remote and management capabilities and just plain more robust software.&lt;/p&gt;&lt;img src="http://ts2blogs.com/aggbug.aspx?PostID=549964" width="1" height="1"&gt;</description></item><item><title>Another “you make the call”, is Windows 7 really less secure than Vista?</title><link>http://ts2blogs.com/blogs/ronaldg/archive/2009/12/26/549462.aspx</link><pubDate>Sat, 26 Dec 2009 20:06:21 GMT</pubDate><guid isPermaLink="false">560f371f-757e-49b8-87a1-da047d47be11:549462</guid><dc:creator>ronaldg</dc:creator><slash:comments>0</slash:comments><description>&lt;p&gt;&lt;font size="2"&gt;As you know, I “hate when they do this”.&amp;#160; Here’s another example of a headline designed to foster a negative perception – this time around Windows 7 interestingly enough (which has generally gotten great press for the most part).&amp;#160; At any rate the title of the post is “&lt;strong&gt;Out of the box, Win 7 less secure than Vista&lt;/strong&gt;” (posted by Adrian Kingsley-Hughes, Dec 10th, on ZDNet blogs).&amp;#160; I’m not even going to link to it, because it’s not really even worth a read.&amp;#160; Essentially, AK-H makes this post on the strength of one quote from Trend Micro CEO Raimund Genes who has the following observation: &lt;/font&gt;“I’m not saying Windows 7 is insecure, but out of the box Vista is better…Windows 7 may be an improvement in terms of usability but in terms of security it’s a mistake, though one that isn’t that surprising. When Microsoft’s developers choose between usability and security, they will always choose usability.”&lt;/p&gt;  &lt;p&gt;&lt;font size="2"&gt;&lt;font size="2"&gt;I guess what gets me the most is the final sentence of Genes’ comment above about MSFT “&lt;em&gt;always”&lt;/em&gt; choosing usability over security.&amp;#160; &lt;/font&gt;Really??&amp;#160; Would you agree that Vista UAC was a “choice” for usability (over security)?&amp;#160; Wow, for the last 8+ years (the Secure Computing Initiative era) MSFT actually has been routinely choosing security over usability (here’s another example: when was the last time you had to confirm the download pictures or had to deal with other content that was blocked by default?).&amp;#160; Yet, AK-H basically throws Genes’ blanket statement out there for everyone to accept on its face value, which gives the statement an aura of credibility – and t&lt;/font&gt;&lt;font size="2"&gt;he fact that he makes this blanket statement in the aftermath of the overwhelming negative usability reaction to UAC in Vista, as I pointed out above, is almost ludicrous, or it would be if folks like AK-H didn’t give it the appearance of credibility by not only publishing it, but, in fact, basing a whole post on it, with the specious title I’ve already called out above. &lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size="2"&gt;Bottom line, UAC is still at work in Win7, it’s just the level of notification that’s been changed, so I would maintain that, notwithstanding any of the other improvements made to security in Windows 7, on the basis of just this, it’s not fair to cast the perception that Windows 7 “in terms of security, [is] a mistake”.&amp;#160; His underlying premise that more notification (which is what upping the UAC settings does) = better security is subjective at best and potentially erroneous.&amp;#160; But as is my normal point with these “you make the call” posts, the lack of factual basis, and the reliance on purely anecdotal evidence (in this case a single quote) that’s not adequately vetted, or substantiated is a real disservice to the general readership.&amp;#160; Yet it continues to happen, and when enough of it is out there in the “echo chamber” (as Ed Bott likes to call it), it leads to or adds to many of the negative perceptions that you have to overcome or that keep your customers from making the best technology choices based on objective factors.&amp;#160; OK, so that’s my post.&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size="2"&gt;Windows 7 less secure than Vista?&amp;#160; You make the call.&amp;#160; But, as they say in the current vernacular, I don’t think so. &lt;/font&gt;&lt;/p&gt;&lt;img src="http://ts2blogs.com/aggbug.aspx?PostID=549462" width="1" height="1"&gt;</description></item><item><title>I’ll bet you’ve heard this, but did you know…</title><link>http://ts2blogs.com/blogs/ronaldg/archive/2009/12/08/537651.aspx</link><pubDate>Tue, 08 Dec 2009 06:46:44 GMT</pubDate><guid isPermaLink="false">560f371f-757e-49b8-87a1-da047d47be11:537651</guid><dc:creator>ronaldg</dc:creator><slash:comments>0</slash:comments><description>&lt;p&gt;By now I’m betting most of my readers have heard of the “black screen of death”, but did you know that there really is/was no such thing?&amp;#160; And yet, now, it’s likely indelibly etched in your mind thanks to some specious activity by a small and somewhat obscure security company compounded by the sensationalist, and in my opinion irresponsible (meaning no facts), journalistic tendencies of so many of our blogosphere participants, including, sadly, many who should know and do better.&amp;#160; So here we have an extraordinary case of more negative perception, not only undue, but in this case founded on error and untruth.&amp;#160; I think Ed sums it up nicely: “It’s a near-perfect case study in how Internet-driven tech journalism rewards sloppy reporting and how the &lt;a href="http://blogs.zdnet.com/Bott/?p=1181"&gt;echo chamber&lt;/a&gt; devalues getting the story right.”&lt;/p&gt;  &lt;p&gt;So why did I say there was no such thing when you’re probably saying, of course there is, I’ve been hearing about it for over a week now; well stay with me, I’ll explain why I say that in the next paragraph.&amp;#160;&amp;#160; As most of you should know, I’ve been doing counterpoint posts for some time now on articles and press (including blogs) that continually paint Microsoft in an unfair (IMHO) light, especially around security, and many times with no facts to provide even the most basic support for the quotes and assertions that are reported, and unfortunately, taken by many as factual purely because they show up under a presumably credible tagline or authorship.&amp;#160; Well, this current one, the supposed black screen of death really takes the cake and so I couldn’t let it go unchallenged.&amp;#160; Probably, the most definitive response that I’ve seen comes from Ed Bott, who you should also know I think is one of the best and most objective bloggers out there – I’ve referenced him many times in the past, and I suspect many of you probably have already seen his post on this.&amp;#160; If not, PLEASE, see his post, &lt;a title="http://blogs.zdnet.com/Bott/?p=1575&amp;amp;tag=col1;post-1575" href="http://blogs.zdnet.com/Bott/?p=1575&amp;amp;tag=col1;post-1575"&gt;What the &amp;quot;Black screen of death&amp;quot; story says about tech journalism&lt;/a&gt;, for an excellent, and factual, account of how this story came about.&amp;#160; But my post isn’t just about piggy-backing (or piling) on Ed’s comments, I wanted to point out something that I want you consider beyond just the unfactual(?) coverage of this issue that Ed highlighted so well.&amp;#160; &lt;/p&gt;  &lt;p&gt;Again, I’ll assume you’ve read Ed’s blog post, so I won’t be going into the same details he did.&amp;#160; But I did want to point out something that is central to the aspect of this that I find so unfortunate, if not downright dangerous from the perspective of readers who tend to put some level of trust in what they read in print.&amp;#160; Notice, as Ed points out, that the original headline was “Black Screen woes could affect millions…”, now notice that when the IDG news service&amp;#160; picks up on it and publishes their headline it becomes “Latest Microsoft patches cause black screen of death”.&amp;#160; Did you notice that the original headline only characterized the issue as a “black screen”, and in fact, that’s precisely what it turned out to be, just a black screen.&amp;#160; But now the IDG&amp;#160; person decides that it can characterize the black screen issue with the additional verbiage “… of death” which we all know connotes a system crash (hard stop).&amp;#160; And, of course, from there most everyone just went with this and the rest, as they say, is history.&amp;#160; Of course, it was not a registry corruption, as was originally proposed, and it turned out not be a system crash in any form, so there you have my tale of why I maintain there never was a true “black screen of death”, yet I’ll wager that you’ve never heard of this issue referred to as anything but the “KSoD” (k standing for black to differentiate from B for blue in BSoD).&amp;#160; And that, my friends is how perception can work – as Ed points out:&amp;#160; within a couple of days “More than 500 separate posts on mainstream tech sites and in blogs have amplified the original story, most of them simply repeating the accusations from the Prevx blog post with no original reporting or fact-checking. The story has now taken on a life of its own.”&lt;/p&gt;  &lt;p&gt;I guess the good news is that this one got exposed big-time, and may well have reflected more poorly on its progenitors than on Microsoft but still I hope this can be used as example to why your customers should be wary of the stuff they might see online.&amp;#160; &lt;/p&gt;  &lt;p&gt;…&lt;/p&gt;  &lt;p&gt;WOW, as usual I wait a day (after I write a post) before I actually post anything that’s not time-sensitive, and in this case, it turned out to be fortuitous, or perhaps uncanny.&amp;#160; I just saw this follow-up from Ed Bott around the topic above, &lt;a title="http://blogs.zdnet.com/Bott/?p=1583&amp;amp;tag=col1;post-1583" href="http://blogs.zdnet.com/Bott/?p=1583&amp;amp;tag=col1;post-1583"&gt;The &amp;#39;black screen of death&amp;#39;: fact, fiction, or FUD?&lt;/a&gt;&amp;#160; As you might expect, I highly recommend this post as an additional read.&amp;#160; Here’s his very first line: “Here’s what you need to know about the so-called Black Screen of Death: &lt;em&gt;There’s no such thing.&lt;/em&gt;”&amp;#160; His thrust is more on the technical side of what constitutes a “BSoD”, whereas my point was more around the issue of how negative perception, but I was still pretty floored when I saw his opening.&amp;#160; One interesting tidbit that came out of his post is that “black screen of death” was likely coined almost 20 years ago and that the “The black screen of death has been present in all versions of OS/2” (from Wikipedia), and even Apple appears to have “black screen” issues as Ed points out.&amp;#160; But I’ll bet if you ask anyone today, they’ll most likely say it’s a uniquely Microsoft issue, and that’s my point about the unfortunate, and undeserved, perceptions that you and I deal with as we try to help folks understand the quality and value of Microsoft’s post-SDL technology.&lt;/p&gt;&lt;img src="http://ts2blogs.com/aggbug.aspx?PostID=537651" width="1" height="1"&gt;</description></item><item><title>OK, had to blog this (PC/Win7 vs Mac)</title><link>http://ts2blogs.com/blogs/ronaldg/archive/2009/10/16/452644.aspx</link><pubDate>Fri, 16 Oct 2009 15:47:08 GMT</pubDate><guid isPermaLink="false">560f371f-757e-49b8-87a1-da047d47be11:452644</guid><dc:creator>ronaldg</dc:creator><slash:comments>0</slash:comments><description>&lt;p&gt;Well, I just ran across this and couldn’t resist a post on it.&amp;#160;&amp;#160; There’s plenty of good press around Windows 7, so this isn’t about highlighting some good press, but this article did take the Win7 goodness to the next level IMHO, and there were a couple of interesting notes that I wanted to highlight that are further evidence of some of the things I’ve blogged about in the past.&amp;#160; First, read this article by Sam Burke from ChannelWeb if you haven’t already…&lt;/p&gt;  &lt;p&gt;&lt;a href="http://www.crn.com/software/220600984;jsessionid=Q51RPD4IWB12XQE1GHRSKH4ATMY32JVN"&gt;Apple Will Feel the Pain From Windows 7 Launch&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;So here’s the first item of note (excerpt from article): &lt;/p&gt;  &lt;p&gt;&lt;i&gt;“BusinessWeek&lt;/i&gt; says that Apple will likely make the case that PCs are more susceptible to viruses. A flat-out false claim. There are a bunch of &lt;a href="http://www.crn.com/software/220100937;jsessionid=F0TMHEMVS0WZ3QE1GHPCKH4ATMY32JVN?pgno=1"&gt;Mac myths&lt;/a&gt;. And better security than Windows is the biggest one. Security experts say that if Mac users are less susceptible to attack, it&amp;#39;s simply due to the fact that there are fewer viruses written for Macs than for Windows.”&lt;/p&gt;  &lt;p&gt;WOW, does that sound familiar, couldn’t have said it better myself (“flat-out false claim) – if you’ve followed my blog at all over the past years &amp;amp; months you know that this has been a recurring theme of mine, dispelling the myth of Apple presumed invulnerability, the “security by obscurity” syndrome aided by the fact that their entire platform is very proprietary and thus they have much more control (but less choice) over their apps and peripherals (drivers).&amp;#160; But you already know that.&lt;/p&gt;  &lt;p&gt;So here’s the real reason I was compelled to make this post.&amp;#160;&amp;#160; As you may have just noticed, there is a link in the excerpt above called Mac myths.&amp;#160;&amp;#160; If you didn’t click on it before, I really encourage to do so, or use the (same) link below.&lt;/p&gt;  &lt;p&gt;&lt;a href="http://www.crn.com/software/220100937;jsessionid=F0TMHEMVS0WZ3QE1GHPCKH4ATMY32JVN?pgno=1"&gt;Mac myths&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&lt;font color="#ff0000"&gt;This is without a doubt one of the best overall articles on the myths of the security of the MAC platform that I have run across,&lt;/font&gt; I really hope you take the time to read it (it’s not long).&amp;#160; But, if you just want the Cliff Notes version (for those of us old enough to know what Cliff’s Notes and/or Readers’ Digest versions are) here’s some of the highlights (not doing all of them and only using excerpts from the ones I am using):&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;&lt;b&gt;Myth 1: Macs Are Safer Than PCs – …&lt;/b&gt;Security experts say that if Mac users are less susceptible to attack, it&amp;#39;s simply due to the fact that there are fewer viruses written for Macs than for Windows. &lt;em&gt; (notice “security experts say”)&lt;/em&gt;&lt;/li&gt;    &lt;li&gt;&lt;b&gt;Myth 2: Macs Have Fewer Vulnerabilities Than Windows&lt;/b&gt;      &lt;br /&gt;Not true. In fact, studies have shown that Macs actually have MORE vulnerabilities than their Windows counterparts, experts say. &lt;em&gt; (notice again, the “experts say”, this is not just the writer’s opinion, and emphasis was his, not mine)&lt;/em&gt;&lt;/li&gt;    &lt;li&gt;&lt;b&gt;Myth 3: Mac OS X Users Don&amp;#39;t Need A Separate Antivirus Solution&lt;/b&gt;      &lt;br /&gt;Not so. Not even Apple says that anymore, even if it has downplayed the fact that users also should equip themselves with third-party antivirus software.&lt;/li&gt;    &lt;li&gt;&lt;b&gt;Myth 6: Apple Is Just Like Microsoft And Has An Army Of Security Henchmen&lt;/b&gt;      &lt;br /&gt;Er, no. In fact, the company&amp;#39;s historic lack of emphasis on security issues has left Apple vastly underprepared to deal with the barrage of anticipated Mac malware coming down the pike. Experts contend that Apple lacks the necessary manpower to create and test patches on a monthly basis…&amp;#160; &lt;em&gt;(and this is another of the key points I’ve made in other articles – since the advent of our Secure Computing Initiative and the Secure Development Lifecycle early in this decade, MS has made security a top priority and now has a world-class security infrastructure and product updating/protection mechanism to make our products more secure against the malware of today’s environment. On the other hand, Apple hasn’t evolved their security to any great extent and, in fact, has consistently shown that they can’t even get patches out in a timely and efficient manner as witnessed by this excerpt from the #7 myth which I’ve not included here: “Meanwhile, Apple scrambled to repair a six-month-old critical Java vulnerability this spring after -- but only after -- researcher Landon Fuller published a proof of concept exploit exposing the flaw six months after it was first detected.”)&lt;/em&gt;&lt;/li&gt;    &lt;li&gt;and finally -- &lt;b&gt;Myth 9: There Is Only A Handful Of Mac Malware, And It&amp;#39;s Pretty Benign&lt;/b&gt;      &lt;br /&gt;…Earlier this year, Mac users were pummeled with two variants of a Mac-only iServices Trojan…[which] later developed into a full-fledged global botnet that infected more than 40,000 Macs. And experts say that Mac users can expect to see more drive-by and browser attacks. &lt;em&gt;(enough said)&lt;/em&gt;&lt;/li&gt; &lt;/ul&gt;  &lt;p&gt;Again, the above was just a selection of some of the Mac myths, and none of it should come as a surprise to anyone who has followed this blog.&amp;#160; And, as usual, my only real impetus to add it here is give you additional 3rd-party commentary for the things I have already brought to light (and that you already know), so that you will have more objective evidence to use if you should need to have the Mac conversation with a customer or someone you know.&lt;/p&gt;  &lt;p&gt;Now back to the original article.&amp;#160; I wanted to highlight one more cogent point that was made in the original article – again, it’s based on another pull quote from BusinessWeek…&lt;/p&gt;  &lt;p&gt;&lt;i&gt;“BusinessWeek&lt;/i&gt; also claims Apple will make fun of Microsoft for making Windows XP owners go through what is by all accounts a cumbersome process to upgrade from Windows XP to Windows 7. Talk about a canard. That duck just don&amp;#39;t fly…Windows 7 is a cause celebre to look at buying a new system. It is not a reason to look at upgrading a well-running Windows XP system. You wouldn&amp;#39;t upgrade a well-running Mac system either. Get a life.”&lt;/p&gt;  &lt;p&gt;Canard – wow, I’m impressed haven’t heard that word in a while, in fact, as a former pilot, I’m more familiar with the term canard used in the aeronautic sense, but here it means “a false or baseless, usually derogatory story, report, or rumor”, so I’ve saved most of you the trip to dictionary.com.&amp;#160; I love it when writers talk like that and I’m going to have to remember that word, since it describes a LOT of the stuff I saw written about Vista (as you know from my “you make the call series of posts).&amp;#160; but I digress…&lt;/p&gt;  &lt;p&gt;Now I’m not 100% in agreement with the don’t bother upgrading from XP premise, BUT for those who have chosen to stay on XP all this time and are effectively skipping a generation of the OS, I would make the case that they should expect that that upgrade process would not be as easy and smooth as moving up from Vista.&amp;#160; The fact that there will be a migration path, with some pretty solid tools, is a plus IMHO.&amp;#160; And, for sure, with the cost of PCs/laptops at current levels, if you’re still running a computer that was originally manufactured in the XP timeframe, this would be a very opportune time to consider a hardware refresh (which should make a partner happy, on several levels).&lt;/p&gt;  &lt;p&gt;So, as always, I hope this has been a worthwhile read for you.&amp;#160; Although I won’t be updating the blog as frequently as I did back in my TS2 days, as you see I will continue to post when I run across something I think is worthy of your time and attention.&amp;#160; Thanks for staying with me.&lt;/p&gt;&lt;img src="http://ts2blogs.com/aggbug.aspx?PostID=452644" width="1" height="1"&gt;</description></item><item><title>Microsoft just launched Microsoft Security Essentials</title><link>http://ts2blogs.com/blogs/ronaldg/archive/2009/10/02/412257.aspx</link><pubDate>Fri, 02 Oct 2009 13:16:03 GMT</pubDate><guid isPermaLink="false">560f371f-757e-49b8-87a1-da047d47be11:412257</guid><dc:creator>ronaldg</dc:creator><slash:comments>0</slash:comments><description>&lt;p&gt;I just published a post that I had started a while back when MSE was just coming out in beta.&amp;#160; Hopefully, you’ve just read that or will go back and give it a look.&amp;#160;&amp;#160; As of this last Tuesday (9/29/09), Microsoft has released MSE.&amp;#160; It’s basically an anti-malware offering that provides &lt;em&gt;real-time protection for your home PC, &lt;/em&gt;meaning that it guards against viruses, spyware, and other malicious software.&amp;#160; It’s free to all genuine Windows users (Windows XP SP2 or later), there are no subscription fees, and thus no registration (beyond the standard download registration) or other personal information required for billing.&lt;/p&gt;  &lt;p&gt;Microsoft Security Essentials is simple to install, easy to use, and always kept up to date (quietly, I might add) so you can be assured your PC is protected by the latest technology. It’s easy to tell if your PC is secure — when you’re green, you’re good. It’s that simple. I think many folks are going to like the simplicity. In my former life as a military pilot, we had a phrase for self-guided missiles called “launch and leave”, this is pretty what your experience should be with MSE.&amp;#160; MSE is lightweight compared to many of the other offerings out there (of course I’m speaking from a system impact perspective, certainly not from a protection perspective) – and it runs quietly and efficiently in the background. As I’ve alluded to in past posts, MSE leverages all the security and anti-malware ecosystem that Microsoft brings to the table for our corporate level Forefront product – you should also take a look at the MMPC blog post linked below for more details on that.&amp;#160;&amp;#160; &lt;/p&gt;  &lt;p&gt;Of course, you can download and get lots of other information from the official site here: &lt;a href="http://www.microsoft.com/security_essentials"&gt;http://www.microsoft.com/security_essentials&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;MMPC blog post: &lt;a href="http://blogs.technet.com/mmpc/archive/2009/09/29/introducing-microsoft-security-essentials.aspx"&gt;http://blogs.technet.com/mmpc/archive/2009/09/29/introducing-microsoft-security-essentials.aspx&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;I saw some competitor blogs about MSE, as you might expect they had almost nothing constructive, or accurate, to say.&amp;#160; What i did find interesting, however, was the overwhelming backlash in the comments to those posts.&amp;#160; The folks that did get to do the beta, including me, generally had very good experiences with it, and as I alluded in the post right before this, the results of actual anti-malware tests by independent orgs are showing that MSE is providing excellent protection.&amp;#160; In fact, one of the testing orgs gave it very good marks for handling rootkits.&amp;#160; But that’s pretty much what I’ve been trying to get across for some time now in my blog – Microsoft really does get security, and a bet on Microsoft technology for security going forward is actually a very good bet.&amp;#160; &lt;/p&gt;  &lt;p&gt;I know the MSE beta was not widely available, so I’m encouraging you to take a look at it now.&amp;#160; You know, it even works in Windows 7 XP mode – which, btw, I’m using it for.&amp;#160; I’m also loading it up for all my friends and family, which I know I’ll have to support, so in effect I’m definitely making the bet myself (or I wouldn’t ask you to do it). &lt;/p&gt;&lt;img src="http://ts2blogs.com/aggbug.aspx?PostID=412257" width="1" height="1"&gt;</description></item><item><title>Regardless of dated perceptions, Microsoft really gets security</title><link>http://ts2blogs.com/blogs/ronaldg/archive/2009/10/02/412129.aspx</link><pubDate>Fri, 02 Oct 2009 12:23:21 GMT</pubDate><guid isPermaLink="false">560f371f-757e-49b8-87a1-da047d47be11:412129</guid><dc:creator>ronaldg</dc:creator><slash:comments>0</slash:comments><description>&lt;p&gt;[This was started a while back, article is from June 2009, but now that we’ve just launched Microsoft Security Essentials I thought this might be good to finally post]&lt;/p&gt;  &lt;p&gt;Well, in light of my last post on the IE 8 security, and, in light of my “between the lines” thoughts, I thought this might be a good time to “dust off&amp;#39;” this article on our beta release of the future free AV offering (codename Morro) that I had actually intended to blog about earlier.&amp;#160;&amp;#160; For those of you who follow this blog, my title statement will come as no surprise at all.&amp;#160;&amp;#160; I would highly recommend that article, but I’m actually going to include an excerpt below that pretty much captures the main points, to save some of your valuable time.&lt;/p&gt;  &lt;p&gt;&lt;a href="http://www.computerworld.com/s/article/9134753/Antivirus_testing_outfit_Microsoft_Security_Essentials_makes_the_grade"&gt;Computerworld article: Antivirus testing outfit: Microsoft Security Essentials makes the grade&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;Article excerpt from Computerworld (emphasis mine to highlight key points) -    &lt;br /&gt;“&lt;strong&gt;Microsoft&amp;#39;s free security software passed a preliminary antivirus exam with flying colors&lt;/strong&gt;, an independent testing company said today.&amp;#160; &lt;a&gt;AV-Test GmbH&lt;/a&gt; tested Microsoft Security Essentials (MSE), the free software Microsoft launched yesterday in beta, on Windows XP, Vista and Windows 7, putting it up against nearly 3,200 common viruses, bot Trojans and worms, said Andreas Marx, one of the firm&amp;#39;s two managers. The malware was culled from the most recent WildList, a list of threats actually actively attacking computers.&amp;#160; &amp;quot;&lt;strong&gt;All files were properly detected and treated by the product,&amp;quot; said Marx in an e-mail. &amp;quot;That&amp;#39;s good&lt;/strong&gt;, as several other [antivirus] scanners are still not able to detect and kill all of these critters yet.&amp;quot;&amp;#160; &lt;strong&gt;AV-Test also measured Security Essentials against a set of in-house false positives to see whether the software mistakenly fingers legitimate files&lt;/strong&gt;, a &lt;a&gt;nightmare for users&lt;/a&gt;, who can be left with a crippled computer, and a disaster to the reputation of a security company.&amp;#160; &amp;quot;None of the clean files were flagged as being malicious,&amp;quot; noted Marx. &amp;quot;Very good.&amp;quot;&amp;#160; &lt;strong&gt;AV-Test also examined the program&amp;#39;s anti-rootkit skills and its ability to scrub a system of malware&lt;/strong&gt; it finds with a limited number of samples and &amp;quot;found no reasons to complain,&amp;quot; Marx said. &amp;quot;[Security Essentials] is able to remove found malware very well, but further tests against larger sets of samples are required before we can come to a final conclusion.&amp;quot;”&lt;/p&gt;  &lt;p&gt;On an side note, it was interesting to see some of the initial negative buzz, most of it by security competitors, and ALL of it opinion based and unsupported by any facts or data.&amp;#160;&amp;#160; This article gave an example of that in the following excerpt: “AV-Test&amp;#39;s results will disappoint some rivals in the security market, who yesterday knocked Microsoft&amp;#39;s effort. &amp;quot;It just doesn&amp;#39;t give you the protection that you need,&amp;quot; argued J.R. Smith, the CEO of AVG Technologies”.&amp;#160; The fact that articles on our technology always seem to include gratuitous negative comments that are seldom more than unsupported opinions, such as this one, is a big part of why we continue to battle the perception issue (of course that’s my opinion).&lt;/p&gt;  &lt;p&gt;So back to the reason for this post.&amp;#160; First, I wanted you to be aware of this test, and to highlight the “passed…with flying colors”.&amp;#160; Unlike the opinions, actual test data is tending to validate the Morro product, and remember this is just the beta.&amp;#160; I believe I did some posts in the (distant) past about Microsoft’s world-class Security Response System and accompanying infrastructure, but suffice it to say, that we have a highly sophisticated, global security monitoring and response operation that is really second to none – most folks are not aware of that and never hear about it.&amp;#160; Our Forefront security products have been protecting not only desktops but servers, and not only at Microsoft, but for many large customers around the world for some time now.&amp;#160; I’ve always thought it was pretty compelling, considering that we are a primary hacker target, that we “eat our own dogfood”, which means we are protected from malware threats by our very own technology.&amp;#160; Second, I wanted to call out that, even though it’s listed as an AV product, as you see from above it protects against other threats such as rootkits.&amp;#160; And, in fact, it’s the successor to our Defender product as well, so don’t be concerned that it turns off Defender when it installs.&amp;#160; Third, I wanted to add that other articles seem to indicate that it appears to be good at avoiding false positives.&amp;#160;&amp;#160; And, lastly, this article didn’t mention it, in other reports I’ve seen comments about how “quiet” it is and that it has less of an impact on your system than many other AV products.&amp;#160; Bottom line, as I’ve tried to highlight in my blog over time, a bet on Microsoft security should be a good one these days( post-SDL), even though I still see competitors (and sometimes folks online and in print) making statements that continue to try to rely on dated perceptions.&amp;#160; &lt;/p&gt;  &lt;p&gt;Some other food for thought.&amp;#160; Microsoft leverages all the security infrastructure I alluded to above for the support of all their security products, so the same technologies and supporting mechanisms that have been, and are, protecting large corporations, including Microsoft itself, are also used in our consumer products like MSE.&amp;#160; So it should be no surprise, to the person who &lt;em&gt;really&lt;/em&gt; understands Microsoft’s security commitment and products, that this product appears to be solid right out of the gate.&amp;#160; And, btw, did I mention that MSE is going to be &lt;strong&gt;free&lt;/strong&gt; when it launches (at least for consumers).&lt;/p&gt;  &lt;p&gt;&lt;a href="http://blogs.zdnet.com/microsoft/?p=3120"&gt;&amp;#160;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://ts2blogs.com/aggbug.aspx?PostID=412129" width="1" height="1"&gt;</description></item><item><title>Here’s where you can get more information on Microsoft security platform</title><link>http://ts2blogs.com/blogs/ronaldg/archive/2009/09/04/355748.aspx</link><pubDate>Fri, 04 Sep 2009 20:28:57 GMT</pubDate><guid isPermaLink="false">560f371f-757e-49b8-87a1-da047d47be11:355748</guid><dc:creator>ronaldg</dc:creator><slash:comments>0</slash:comments><description>&lt;p&gt;&lt;a name=""&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;For some time now, I’ve been extolling the advantages of Microsoft on the security front.&amp;#160; I’ve specifically mentioned the SDL as well as our threat modeling and security response capabilities in previous posts.&amp;#160; Some of you may still be skeptical and that’s OK, but I ran across this on the Partner Portal the other day and thought it would great to share with you in case you hadn’t run across it yourself.&amp;#160; As you’ll notice from the subtitle below, this is Customer Ready stuff, so please feel free to share this with them as they make strategic platform choices in the days ahead.&amp;#160; I hope, if you’re still one of the skeptics, or even if you’re not, that you’ll read some of these yourself (if necessary) to refresh on what all Microsoft is doing and has done on the security front to make sure that our platform not only delivers the security you need and deserve.&amp;#160; And, I’m hoping you also see and understand why I’ve been saying that we’re also a great, if not the best, security bet going forward for you and your customers.&amp;#160; &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Partner Sales Resources&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;Microsoft Security Development Lifecycle To-Customer White Papers&lt;/p&gt;  &lt;p&gt;Get insight into the Security Development Lifecycle that has made Microsoft products more secure. Reassure your customers by giving them an inside peek into how we make sure their software isn’t vulnerable to attack. &lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;     &lt;p&gt;&lt;a href="https://partner.microsoft.com/40100672"&gt;Investigating the Security Development Lifecycle at Microsoft&lt;/a&gt;&lt;/p&gt;   &lt;/li&gt;    &lt;li&gt;     &lt;p&gt;&lt;a href="https://partner.microsoft.com/40100671"&gt;Security Education at Microsoft&lt;/a&gt;&lt;/p&gt;   &lt;/li&gt;    &lt;li&gt;     &lt;p&gt;&lt;a href="https://partner.microsoft.com/40100670"&gt;The Microsoft Security Organization Chart&lt;/a&gt;&lt;/p&gt;   &lt;/li&gt;    &lt;li&gt;     &lt;p&gt;&lt;a href="https://partner.microsoft.com/40100669"&gt;Threat Modeling at Microsoft&lt;/a&gt;&lt;/p&gt;   &lt;/li&gt;    &lt;li&gt;     &lt;p&gt;&lt;a href="https://partner.microsoft.com/40100663"&gt;Microsoft&amp;#39;s Security Response&lt;/a&gt;&lt;/p&gt;   &lt;/li&gt;    &lt;li&gt;     &lt;p&gt;&lt;a href="https://partner.microsoft.com/40100660"&gt;Microsoft&amp;#39;s Security Toolbox&lt;/a&gt;&lt;/p&gt;   &lt;/li&gt; &lt;/ul&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;Before I close this, as a Partner Learning Advisor for security (my new role), I want to give you a head’s-up about some key changes in Microsoft’s security marketing strategy.&amp;#160; You should have already seen or heard some “buzz” around what we’re calling “Business Ready Security”; if not, might I suggest you Bing that phrase (or just take this link if you want to do it now: &lt;a href="http://www.microsoft.com/forefront/en/us/business-ready-security.aspx"&gt;Microsoft&amp;#39;s Business Ready Security strategy&lt;/a&gt;).&amp;#160; What you’ll notice is that we’re trying to take the whole notion of “security” to the next level – it’s not just about firewalls and/or malware protection any more, but about a much more holistic approach that encompasses identity management and access control in addition to the malware and networking stuff.&amp;#160; On this page you’ll also find updated info on “Stirling” and Geneva” (no, I’m not going to tell you what they are, I’m going to encourage you to go the site and see for yourself &amp;lt;smile&amp;gt;), as well as other new stuff such as Forefront Identity Manager.&amp;#160; As you likely know, Microsoft if the ONLY provider that can give you highly integrated,compatible, business-ready protection across the entire security spectrum, from anti-malware on the client, to “identity lifecycle management” in the datacenter.&amp;#160; Please take some time to educate yourself on the Microsoft security story.&lt;/p&gt;&lt;img src="http://ts2blogs.com/aggbug.aspx?PostID=355748" width="1" height="1"&gt;</description></item><item><title>Microsoft Wave, it’s not what you think, but I think you’ll be interested</title><link>http://ts2blogs.com/blogs/ronaldg/archive/2009/09/04/355726.aspx</link><pubDate>Fri, 04 Sep 2009 19:57:56 GMT</pubDate><guid isPermaLink="false">560f371f-757e-49b8-87a1-da047d47be11:355726</guid><dc:creator>ronaldg</dc:creator><slash:comments>0</slash:comments><description>&lt;p&gt;&lt;a href="http://www.microsoft.com/uk/wave/home.aspx"&gt;Microsoft Wave&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&lt;a href="http://ts2blogs.com/blogs/ronaldg/image_43677B5E.png"&gt;&lt;img style="border-right-width:0px;display:inline;border-top-width:0px;border-bottom-width:0px;border-left-width:0px;" title="image" border="0" alt="image" src="http://ts2blogs.com/blogs/ronaldg/image_thumb_69C95EA9.png" width="320" height="79" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;In case you hadn’t heard about this, our friends in the UK have put up a new online site to show off the &amp;quot;cool&amp;quot; software and hardware Microsoft develops; including &lt;a href="https://www.mesh.com/welcome/default.aspx"&gt;Live Mesh&lt;/a&gt;, &lt;a href="http://photosynth.net/Default.aspx"&gt;Photosynth&lt;/a&gt;, &lt;a href="http://www.officelabs.com/projects/pptPlex/Pages/default.aspx"&gt;pptPlex&lt;/a&gt;, &lt;a href="http://www.youtube.com/watch?v=k8GIwFkIuP8"&gt;Songsmith&lt;/a&gt;, &lt;a href="http://www.worldwidetelescope.org/Home.aspx"&gt;WorldWide Telescope&lt;/a&gt;, &lt;a href="http://research.microsoft.com/en-us/um/cambridge/projects/autocollage/"&gt;AutoCollage&lt;/a&gt;, &lt;a href="http://www.microsoft.com/downloads/details.aspx?familyid=457b17b7-52bf-4bda-87a3-fa8a4673f8bf&amp;amp;displaylang=en"&gt;DeepZoom&lt;/a&gt;, &lt;a href="https://www.microsoft.com/tag/"&gt;Tag&lt;/a&gt;, &lt;a href="http://www.microsoft.com/surface/"&gt;Surface&lt;/a&gt;, &lt;a href="http://blog.seattlepi.com/microsoft/archives/170052.asp"&gt;Xbox Project Natal&lt;/a&gt; and some Xbox games.&amp;#160; Of course, one of my favs is the Arc mouse (in the hardware tab), if you haven’t seen or tried this little beauty, I would encourage you to do so.&amp;#160; I started using one of these a while back and liked it so much, I talked the powers that be into getting them for give-aways at the OEM/SB events I did last year.&amp;#160; I have given away plenty of these and have never found anyone yet who didn’t like the Arc mouse.&amp;#160; Live Mesh is cool if you regularly need to synch multiple computing devices.&amp;#160; Perhaps you’ll find something else on this site that will become your favorite “recommend”.&amp;#160; Enjoy!!&lt;/p&gt;&lt;img src="http://ts2blogs.com/aggbug.aspx?PostID=355726" width="1" height="1"&gt;</description></item></channel></rss>