Microsoft: March 2006 Archives

This sounds familiar. Corporations thinking that the next OS of Microsoft will cure all security woes. Donna's Security Flash had a link to this techtarget article which reports the result of a survey.

90% of respondent expect automatic patch updates and installation management functionality to be part of Vista.
66% expect IPS features.

I think they would have gotten the same numbers for "which security features have you heard of"

I'm taking another look at whether or not it is worthwhile to disable the LANMAN hash. If you don't know what that is, this is probably not the article for you.

The LANMAN hash is listed on the SANS/FBI Top 20 list. Microsoft says to disable it you dont need the backward compatibility.

Yet Jesper Johansson pretty much calls doing this security theatre. If someone were to compromise the password database, they aren't going to be cracking the passwords in his opinion, instead they will be replaying the hash. But sometimes the password is needed such as going after EFS or if the password might be used on other non-windows accounts.

I need to think about this.

I saw this over at Microsoft Monitor. The link to YouTube is dead, but I found it over on video.google.com.

Reportedly this is a self-parody. It was made inhouse to critique their design process. Either way, I was laughing through it. I just wish the quality of the video was a tough better so I could see the small print.