Categories
Uncategorized

A bit about BitLocker today on the Windows Team Blog

Picture of BitLockerIf there is data on your PC that you need to protect, BitLocker encryption can help to protect your files with encryption. (As noted on the Windows 7 site, BitLocker "helps keep everything from documents to passwords safer by encrypting the entire drive that Windows and your data reside on. Once BitLocker is turned on, any file you save on that drive is encrypted automatically.")

Last week I read several articles in the news – like this one on arstechnica – about commercial tools that claim to crack BitLocker and take advantage of weaknesses. Of interest today is Paul Cooke’s post over on the Windows Team Blog on Windows BitLocker Claims and that to say these tools break BitLocker "is a bit of a misnomer"…

"Windows 7 is seeing success in the marketplace which I am very happy about from a security perspective. The Microsoft Security Intelligence Report has shown us again and again that the more up-to-date a PC is, the less likely it is to be infected by malware and other potentially dangerous software. So Windows 7 making strides is helpful to the ecosystem overall from a security standpoint. Success comes at a price though, through greater scrutiny and misinterpretation of some of the technologies. One of those technologies is BitLocker.

"Our customers are confronted with a wide spectrum of data security threats that are specific to their environment and we work hard to provide capabilities and information to help the customer achieve the right balance of security, manageability, and ease-of-use for their specific circumstances. BitLocker is an effective solution to help safeguard personal and private data on mobile PCs and provides a number of protection options that meet different end-user needs.  Like most full volume encryption products on the market, BitLocker uses a key-in memory when the system is running in order to encrypt/decrypt data on the fly for the drives in use.  Also like other encryption products, a determined adversary has significant advantages when they have physical access to a computer.

"We recognize users want advice with regards to BitLocker and have published best practice guidance in The Data Encryption Toolkit for Mobile PCs. In the toolkit, we discuss the balance of security and usability and detail that the most secure method to use BitLocker in hibernate mode and a TPM+PIN configuration. Using this method, a machine that is powered off or hibernated will protect users from the ability to extract a physical memory image of the computer.

"Windows 7 BitLocker continues to be a foundational component adding to any defense in depth strategy for securing systems, and specifically laptops.  Even with the great enhancements made in Windows 7 such as BitLocker To Go, it still remains that BitLocker alone is not a complete security solution.  IT professionals as well as users must be diligent when protecting IT resources and the best protection against these sorts of targeted attacks requires more than just technology: it requires end user education and physical security also play important roles."

As Ars pointed out in an updated post…

"… this isn’t exactly a "crack" for BitLocker. Like most similar digital forensics analysis software, Passware Kit Forensic requires access to a physical memory image file of the target computer before it can extract all the encryption keys for a BitLocker disk. If a forensics analyst or thief has physical access to a running system, it is possible to take advantage of the fact that the contents are in the computer’s memory. Other drive encryption programs have similar issues."

Learn more about BitLocker…

 

Tags: Windows Vista, Security, what I read, twitter, Microsoft, Windows 7, BitLocker.

Clubhouse Tags: Clubhouse, how-to, Windows 7, Security, BitLocker.

Delicious Bookmark this on Delicious Bookmark and Share

Also available via

Categories
Uncategorized

Black is not the new Blue this season: more on “Black Screen” issues and the Microsoft November Security Updates

Well, Black really isn’t the new Blue this season, as some may have you believe.

Over at the Microsoft Security Response Center (MSRC) blog, Christopher posted a note on the reports of so-called “Black Screen” issues that some customers might have experienced with their systems as a result of issues with the November Security Updates

We’ve investigated these reports and found that our November Security Updates are not making changes to the system that these reports say are responsible for these issues.

While these reports weren’t brought to us directly, from our research into them, it appears they’re saying that our security updates are making permission changes in the registry to the value for the HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell key.

We’ve conducted a comprehensive review of the November Security Updates, the Windows Malicious Software Removal Tool, and the non-security updates we released through Windows Update in November. That investigation has shown that none of these updates make any changes to the permissions in the registry. Thus, we don’t believe the updates are related to the “black screen” behavior described in these reports.

We’ve also checked with our worldwide Customer Service and Support organization, and they’ve told us they’re not seeing “black screen” behavior as a broad customer issue. Because these reports were not brought to us directly, it’s impossible to know conclusively what might be causing a “black screen” in those limited instances where customers have seen it. However, we do know that “black screen” behavior is associated with some malware families such as Daonol.

If you think that you’ve been affected by this type of an issue, contact our Customer Service and Support group and any time you think that you’ve been impacted by malware. As he further notes, Christopher reminds us that "this enables us to determine what might be happening and take steps to help customers by documenting new malware families in our MMPC malware encyclopedia or documenting known issues in our security bulletins and the supporting Knowledge Base articles."

To avoid malware and other bad things as I wrote here, you should only download software from a trusted source – for example, via Microsoft for our products and service – and avoid peer to peer to save yourself an additional security risk.

Additional information and guidance:

Tags: Windows Vista, Security, what I read, twitter, Microsoft, Windows 7, Microsoft Security Essentials.

Clubhouse Tags: Clubhouse, how-to, Security, download, Microsoft Security Essentials.

Delicious Bookmark this on Delicious Bookmark and Share

Also available via http://bit.ly/4HFBlB

Categories
Uncategorized

Announcement: Hotfix for Microsoft Windows OS releases available for Fiji 2009/2010 Daylight Saving Time

Going to Fiji anytime soon? Or scheduling LiveMeetings with a thriving supplier in the region? Then you’ll want to know about the latest changes to their changes to daylight saving time (aka DST).

As found over on the Microsoft Daylight Saving Time & Time Zone Blog, there is a link to the Hotfix for Windows OS releases available for Fiji 2009/2010 Daylight Saving Time

Fiji government has approved the re-introduction of daylight saving time in Fiji, from Sunday, November 29th 2009 at 2.00 am to Sunday, April 25th 2010 at 3.00 am.  This hotfix updates the start and end of Daylight Savings Time (DST) for Fiji in 2009.

Microsoft has produced a hotfix to implement this change.  If interested in downloading this hotfix, please refer to KB 977748 titled: “A hotfix is available to update the Daylight Saving Time for the Fiji Standard Time time zone for the year 2009 for Windows XP-based, Windows Server 2003-based, Windows Vista-based, Windows Server 2008-based, Windows 7-based and Windows Server 2008 R2-based computers”.

Hotfix download is available
Hotfix Download Available
View and request hotfix downloads

 

Tags: Windows, Microsoft, Daylight Saving Time, Daylight Savings Time, RSS, DST; 18,000,000; 20,400,000 (up >3M)

Delicious Bookmark this on Delicious Bookmark and Share

Also available via http://bit.ly/836fYb

Categories
Uncategorized

Announcement: Microsoft Windows December 2009 Updates to Daylight Saving Time and Time Zones

New over at the Microsoft Daylight Saving Time & Time Zone Blog, details on the Microsoft Windows Daylight Saving Time and Time Zone update now available (December 2009) 


The most recent cumulative update to daylight saving time (DST) and world time zones (TZ) is now available for supported versions of the Windows Operating System via Microsoft Download Center and Windows Update.


 


Microsoft product teams follow a semi-annual DST and TZ update schedule, which follows the Windows regular schedule for publishing newly legislated DST rules and time zone updates. These annual Windows “Cumulative Daylight Saving Time and Time Zone Updates” are released in December for each calendar year; a semi-annual update will be released in August, as needed.  Microsoft products that are affected may also schedule updates to accommodate some of these changes.


 


For more information about this cumulative DST and TZ update, visit the following Microsoft Web site: http://support.microsoft.com/kb/976098


 


Tags: Windows, Microsoft, Daylight Saving Time, Daylight Savings Time, RSS, DST; 18,000,000; 20,400,000 (up >3M)


Delicious Bookmark this on Delicious Bookmark and Share


Also available via http://bit.ly/717zJI

Categories
Uncategorized

How to make an impact at Thanksgiving, even if you’re not Bill Gates

It’s Thanksgiving, and again I am fortunate enough to spend my holiday with my friends and family. In a past post, I noted my posts on being thankful, in particular this one on being thankful, where I noted the Seattle P-I newspaper’s slide show on “Words of Thanks.”



“What are you most thankful for? P-I photographer Meryl Schenker profiles six local residents who have different reasons for giving thanks on this holiday.”


At home, we’re thankful for many things, primarily for good health, family, and our community. The philanthropist W. Clement Stone said that “If you are really thankful, what do you do? You share.”


Today I received a mail with a link to an article from last year on Bill Gates and how Microsoft’s founder and his wife, Melinda, are aiming to change charity…



“For the past 10 years, the Gateses have opted for the latter: “How can we do the most good for the greatest number with the resources we have?” Bill asked a sea of Harvard University graduates at their commencement ceremony last year.


“The answer? If you’re Bill Gates — with $37.5 billion in your foundation’s coffers and as much as $100 billion to contribute over the course of your lifetime — you do it very, very carefully, say philanthropy leaders.”


OK, you don’t have Bill & Melinda Gates’ resources. What can you do?


Plenty. And you don’t need billions to make a difference.


In an article today from Patrick May of the San Jose Mercury News writes about the local impact of the recession at the holiday to some of those in Silicon Valley, and provides a list of places to give for the holidays in San Jose and surrounding areas.


In Amy Goodman’s article about thanksgiving, she notes “Billion for a Billion” campaign launched by the WFP, “urging the 1 billion people who use the Internet to help the billion who are hungry. But if you think that hunger is far from our shores, here is some food for thought … and action: The U.S. Department of Agriculture released a report Monday stating that in 2008 one in six households in the U.S. was “food insecure,” the highest number since the figures were first gathered in 1995.


And Jerry Large writes today about good people giving back with thanks, about “someone who traveled to a foreign land and made a fresh start despite hardships and with the help of new friends.”


So I’ve included this link on how to help over the holidays from my previous hometown paper, and from our new home town, The Seattle Times Fund For The Needy


This in closing from the article on Gates noted above



“Gates — who dropped out of Harvard to create Microsoft — returned to the university last year to accept an honorary degree and to deliver the 2007 commencement speech to graduates. It was, Gates-watchers agreed, probably one of his finest speeches ever, an eloquent reminder that success doesn’t always mean following the rules. Among other things, Gates told Harvard students that technological achievement is critical in the years ahead, but that “humanity’s greatest advances are not in is discoveries but in how those discoveries are applied to reduce inequity … reducing human inequity is the highest human achievement.”


How will you pay it forward?


Whatever you do, for those in the States and wherever you are, have a happy Thanksgiving.


 


Tags: shopping, Microsoft, articles, blogs, what I read, Thanksgiving.


Clubhouse Tags: Clubhouse, Windows Vista, Windows 7, computers, Thanksgiving, how-to


Delicious Bookmark this on Delicious Bookmark and Share


Also available via http://bit.ly/8wn8wA