Categories
Uncategorized

Microsoft Account Gets More Secure with Two Factor Authorization

ICYMI, your Microsoft Account will get more secure as the team rolls out a new upgrade which includes two-step verification, as noted on the Bing newswire. This will improve the security of the devices and services currently used by more than 700 million people worldwide, including Windows PCs, Phones, Xboxes, and services like Outlook.com, SkyDrive and Skype.

Microsoft has increasingly focused on delivering connected devices and services that are currently used by more than 700 million people around the world. A Microsoft account is the key that unlocks your experience across these products—from your Windows PC to your Windows Phone, from Xbox to Outlook.com, from SkyDrive and Skype to Office and much more.

Given this critical role for Microsoft account, we remain vigilant in working hard to protect your account, which is why we’re adding an option so you can enable two-step verification to further protect yourself. You should see this option show up in your account in the next few days. You can enable this capability at https://account.live.com/proofs/Manage.

Two-step verification is when we ask you for two pieces of information anytime you access your account — for example, your password plus a code sent to a phone or email on file as security info.

More than a year ago, we began bringing two-step verification for certain critical activities, like editing credit cards and subscriptions at commerce.microsoft.com and xbox.com, or accessing files on another one of your computers through SkyDrive.com. For these scenarios, two-step verification is required 100 percent of the time for everyone, given the sensitive nature of these tasks.

Read more from Eric at the link above.

Categories
Uncategorized

If you can’t trust Google’s app store, how can you trust them for anything?

When you buy an Android app from the Google app store, they give the app maker your full name, email address and the neighborhood where you live. This occurs without clear warning every single time you buy an app.

If you can’t trust Google’s app store, how can you trust them for anything?

See the original post at http://bit.ly/XO17F7

Categories
Uncategorized

ICANN, the GAC, SSAC and gTLDs: Challenges with Dotless Domains and Closed Generics

Last year, Craig Mundie posted about ICANN’s gTLD Reveal Day calling it “another step in the Internet’s evolution.”

Let’s hope we won’t see “one step up and two steps back.”

ICYMI, ICANN (the Internet Corporation for Assigned Names and Numbers organization) approved plans for new generic Top Level Domains (“gTLDs”) to add to the common domains you see today, like .com, .net, and .org among and others. It was impressive to see the level of interest in these new domains, with close to 2,000 applications for new unique domains from around the world. As Craig noted, Microsoft focused on eleven new top-level domain names that correspond to our well-known products, services and brands: .microsoft, .windows, .xbox, .office, .docs, .bing, .skype, .live, .skydrive, .hotmail and .azure…

“Our goal for our new TLDs is to promote responsible utilization of the Web and ultimately better experiences for consumers. Although we’re not yet talking about specific plans for the TLDs for which we’ve applied, we believe that – properly used – this expansion of domains can help deliver new services and capabilities to consumers and the Internet community as a whole. Appropriately utilized, the new TLDs can also protect the rights of trademark holders and brand owners, while promoting a safer and more secure computing experience.

“With so many new gTLD applications, there are bound to be cases where multiple players have applied for the same top-level domain, and ICANN has processes in place to help resolve those cases. We are just now reviewing all of the applications by other companies and organizations. We will work closely with ICANN and others to ensure competition and innovation are preserved for the industry, while also helping protect the rights and expectations of other stakeholders.”

Late last summer, ICANN’s own Security and Stability Advisory Committee (SSAC) published a report to address the issue of dotless gTLDs. This was partly in response to questions on whether or not new gTLD name registry operators would be able to use their gTLD as a valid Internet domain (e.g. http://microsoft instead of the common http://www.microsoft.com). The SSAC strongly recommended against the use of dotless domains, and opened a comment period on this issue, to get feedback from the community (you can read more here)…

“…the combined effect of these potential ambiguities makes it very difficult in practice to predict how a dotless domain name will be resolved in different situations. The result could be anything from fully expected behavior to a security incident in which the user of a domain name (or URL with the domain name embedded) communicates unknowingly with a party other than intended; or, as in the email example in Section 3.4 above, a failure of the system to provide any service at all. Additionally, this ambiguous behavior could be used to develop methodologies to compromise the session and allow for malicious activities with, for example, DNS redirection.

“The SSAC is aware that there currently exist TLDs that attempt to resolve dotless domain names. Our initial examination reveals that resolution of these names is not consistent or universal, and in particular, applications behave differently when presented with “dotless” responses. These behaviors occur for reasons illustrated in this paper. Recommendation: Dotless domains will not be universally reachable and the SSAC recommends strongly against their use. As a result, the SSAC also recommends that the use of DNS resource records such as A, AAAA, and MX in the apex of a Top-Level Domain (TLD) be contractually prohibited where appropriate and strongly discouraged in all cases.”

As we summarized in our comments, Microsoft supports and endorses the report’s recommendations against use of dotless domains. There are significant security considerations around the use of dotless domains with new gTLDs, generally a bad idea that would create significant security risks for people using the Internet. Dotless domain names are often resolved by operating systems, browsers and other products to addresses on the local network / intranet. Our recommendation is to use Fully Qualified Domain Names (FQDNs) – sometimes referred to an absolute domain name – to ensure that people get where they are expecting when they type in an address on the Internet URL.

Last week, following broad coverage (as briefly noted on TechCrunch) on proposed dotless domains and how new gTLDs might be operated, I had a discussion with the folks over at TheDomains.com on the topic.

As we saw in the Governmental Advisory Committee (GAC) recommendation to ICANN last week, we believe it’s contrary to the free and open ideals of the Internet for a private commercial entity to act as gatekeeper to domains that consist of generic industry terms, like .search, .cloud or .app. ICANN should follow the GAC’s clear recommendation that any non-open domains that consist of generic industry terms be required to establish that they serve a public interest goal.

Allowing dominant market leaders to control such generic domains is like trusting a fox to guard the henhouse. We urge ICANN to abide by the GAC’s advice and to follow the SSAC’s conclusions in order to preserve the freedom and openness of the Internet, protect the billions of Internet users, and foster healthy competition.

Also available via https://aka.ms/dotless

Categories
Uncategorized

What I read: Designing for Dependability in the Cloud

Last week I read David Bills’ (our chief reliability strategist) post Data Center Knowledge. David is responsible for the broad evangelism of the company’s online service reliability programs. His latest item is a follow on to his posts articles “Designing
for Dependability in the Cloud
” and Microsoft’s Journey: Solving Cloud Reliability With Software.

“In part three, I discuss the cultural shift and evolving engineering principles Microsoft is using to help improve the dependability of the services we offer and help customers realize the full potential of the cloud.”

David highlights the importance of identifying as many potential failure conditions as possible in advance in the service design phase, so we can map out how the service should react when the unexpected occurs. (So really, it’s expected, if you’ve mapped out the different potential issues far enough.)

“Many services teams employ fault modeling (FMA) and root cause analysis (RCA) to help them improve the reliability of their services and to help prevent faults from recurring. It’s my opinion that these are necessary but insufficient. Instead, the design team should adopt failure mode and effects analysis (FMEA) to help ensure a more effective outcome.

FMA refers to a repeatable design process that is intended to identify and mitigate faults in the service design. RCA consists of identifying the factors that resulted in the nature, magnitude, location, and timing of harmful outcomes. The primary benefits of FMEA, a holistic, end-to-end methodology, include the comprehensive mapping of failure points and failure modes, which results in a prioritized list of engineering investments to mitigate known failures.”

Akin to our work in scenario focused engineering, groups should look at the entire infrastructure, from the hardware and software we use to run our datacenters, along with the infrastructure and wetware we use to power them, to components in out cloud offerings.

Worth a quick read.

Categories
Uncategorized

RSS feed reader blues? Get your feed in Microsoft Outlook and Office 365

ICYMI, Google Reader, Google Voice App for Blackberry, Google Cloud Connect, and Snapseed Desktop are shutting down. Hilarity ensued on the Internet with the melt down on social media over the change. As Danny Sullivan noted here, “Google should have done better by Google Reader & Google users than to bury its closure in a “spring cleaning” post.”

All the talk about RSS Readers reminded me of how important it is to listen and respond (this from 2011 via TechCrunch).

But I digress.

If you’re impacted by this announcement, have no fear: there are options, many great options.

First off, Good advice from Sara Hevans (@prsarahevans) on how to backup your Google Reader account http://aol.it/Wq3UkJ

Once you’ve backed up, you’ll need a new reader.

With all these options, you may already have an option on your desktop: you can also use Outlook in Microsoft Office to subscribe to an RSS feed as noted here.

So if you’re looking for RSS subscription and management? our own Office 365 Home Premium has that: http://help.outlook.com/en-us/140/cc511379.aspx

Quick links:

Tags: Microsoft, RSS, Outlook

Bookmark this on Delicious Bookmark and Share

Also available via https://aka.ms/RSSfeeds