Security Sessions at TechEd in Australia and New Zealand

I’m heading to TechEd Oz and NZ in a couple of hours to present the following: SEC312  The “Everything Developers Need to Know About Security” Talk  Oz: 9/10/2009 15:30-16:45  NZ: 9/14/2009 14:15-15:30 SEC201  Inside the Microsoft Security Development Lifecycle: And how you can use it!   Oz: 9/10/2009 11:30-12:45  NZ: 9/15/2009 12:10-13:25 I’m also giving a…


Integrating the SDL process into Visual Studio

I’ve been a firm believer of integrating as much security tooling as possible into the development process so developers can get on with developing code and designing solutions rather than having to constantly think about dotting the security “i”s and crossing the security “t”s. The less security “friction” the better, because the more you can…


A Conversation About Threat Modeling

This was fun to write; in fact, other than minor edits I wrote it in a single two hour sitting with my laptop by the pool 🙂


Ken Johnson (Skywing) joins Microsoft

Following close on the heels of security experts Matt Miller, Adam Shostack and Crispin Cowan joining Microsoft, I am pleased to announce that Ken Johnson, AKA Skywing, has joined our group.   Ken brings an enormous amount of reverse engineering and defense-subversion skill to Microsoft. Ken will be working on anything and everything related vulnerabilities, exploits,…