<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: sp1]]></title>
    <link>http://securityratty.com/tag/sp1</link>
    <description></description>
    <pubDate>Tue, 08 Apr 2008 09:21:49 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Internet Explorer security levels compared]]></title>
      <link>http://securityratty.com/article/cce1e6c584435126c5c4900522285f44</link>
      <guid>http://securityratty.com/article/cce1e6c584435126c5c4900522285f44</guid>
      <description><![CDATA[A pretty good question came across the newsgroups the other day. Someone was asking what are the differences between IE's &quot;medium&quot; and &quot;medium-high&quot; security settings. I did some digging, and found...]]></description>
      <content:encoded><![CDATA[<p>A pretty good question came across the newsgroups the other day. Someone was asking what are the differences between IE's &quot;medium&quot; and &quot;medium-high&quot; security settings. I did some digging, and found only this on MSDN: <a href="http://msdn.microsoft.com/en-us/library/ms537186(VS.85).aspx" target="_blank">About URL security zone templates</a>. No wonder it's difficult to find -- the terminology is different, and the table is organized by URL actions, not by the text in the dialog.</p>  <p>Someone on the IE security team forwarded me a document that had additional details. So here, for your enjoyment, is a chart listing the default settings for each security level. To answer the newsgroup poster, &quot;medium&quot; and &quot;medium-high&quot; aren't the same.</p>  <p>About the formatting: to get it to fit within the width of the blog's text section, I've made some abbreviations.</p>  <table cellspacing="0" cellpadding="0" width="290" border="0"><tbody>     <tr>       <td valign="top" width="145"><strong><u>Column headings</u></strong></td>        <td valign="top" width="145"><strong><u>Entries</u></strong></td>     </tr>   </tbody></table>  <table cellspacing="0" cellpadding="0" width="290" border="0"><tbody>     <tr>       <td valign="top" width="25">H</td>        <td valign="top" width="120">High</td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="120">Disable</td>     </tr>      <tr>       <td valign="top" width="25">MH</td>        <td valign="top" width="120">Medium-high</td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="120">Enable</td>     </tr>      <tr>       <td valign="top" width="25">M</td>        <td valign="top" width="120">Medium</td>        <td valign="top" width="25"><strong><font color="#0000ff">P</font></strong></td>        <td valign="top" width="120">Prompt</td>     </tr>      <tr>       <td valign="top" width="25">ML</td>        <td valign="top" width="120">Medium-low</td>        <td valign="top" width="25">&#160;</td>        <td valign="top" width="120">&#160;</td>     </tr>      <tr>       <td valign="top" width="25">L</td>        <td valign="top" width="120">Low</td>        <td valign="top" width="25">&#160;</td>        <td valign="top" width="120">&#160;</td>     </tr>   </tbody></table>  <p>In a few cases, the table shows a number rather than D or E or P; below the table is a description of each such entry.</p>  <p>At the very bottom of this post I've included the settings from the privacy tab, too.</p>  <p>Note: these settings reflect those for Internet Explorer 7 on Vista SP1. Please see the MDSN link above for differences between IE 6 and IE 7.</p>  <p>&#160;</p>  <p><strong>.NET Framework</strong></p>  <table cellspacing="0" cellpadding="0" width="550" border="1"><tbody>     <tr>       <td valign="top" width="325">&#160;</td>        <td valign="top" width="25">H</td>        <td valign="top" width="25">MH</td>        <td valign="top" width="25">M</td>        <td valign="top" width="25">ML</td>        <td valign="top" width="25">L</td>     </tr>      <tr>       <td valign="top" width="325">Loose XAML</td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>     </tr>      <tr>       <td valign="top" width="325">XAML browser applications</td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>     </tr>      <tr>       <td valign="top" width="325">XPS documents</td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>     </tr>   </tbody></table>  <p><strong>.NET Framework-reliant components</strong></p>  <table cellspacing="0" cellpadding="0" width="550" border="1"><tbody>     <tr>       <td valign="top" width="325">&#160;</td>        <td valign="top" width="25">H</td>        <td valign="top" width="25">MH</td>        <td valign="top" width="25">M</td>        <td valign="top" width="25">ML</td>        <td valign="top" width="25">L</td>     </tr>      <tr>       <td valign="top" width="325">Permissions for components with manifests</td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25">1</td>        <td valign="top" width="25">1</td>        <td valign="top" width="25">1</td>        <td valign="top" width="25">1</td>     </tr>      <tr>       <td valign="top" width="325">Run components not signed with Authenticode</td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>     </tr>      <tr>       <td valign="top" width="325">Run components signed with Authenticode</td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>     </tr>   </tbody></table>  <p>&#160;&#160;&#160;&#160; 1 = High safety</p>  <p><strong>ActiveX controls and plug-ins</strong></p>  <table cellspacing="0" cellpadding="0" width="550" border="1"><tbody>     <tr>       <td valign="top" width="325">&#160;</td>        <td valign="top" width="25">H</td>        <td valign="top" width="25">MH</td>        <td valign="top" width="25">M</td>        <td valign="top" width="25">ML</td>        <td valign="top" width="25">L</td>     </tr>      <tr>       <td valign="top" width="325">Allow previously unused ActiveX controls to run without prompt</td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>     </tr>      <tr>       <td valign="top" width="325">Allow scriptlets</td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>     </tr>      <tr>       <td valign="top" width="325">Automatic prompting for ActiveX controls</td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>     </tr>      <tr>       <td valign="top" width="325">Binary and script behaviors</td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>     </tr>      <tr>       <td valign="top" width="325">Display video and animation on a Web page that doesn't use an external media player</td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>     </tr>      <tr>       <td valign="top" width="325">Download signed ActiveX controls</td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><strong><font color="#0000ff">P</font></strong></td>        <td valign="top" width="25"><strong><font color="#0000ff">P</font></strong></td>        <td valign="top" width="25"><strong><font color="#0000ff">P</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>     </tr>      <tr>       <td valign="top" width="325">Download unsigned ActiveX controls</td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><strong><font color="#0000ff">P</font></strong></td>     </tr>      <tr>       <td valign="top" width="325">Initialize and script ActiveX controls not marked as safe for scripting</td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><strong><font color="#0000ff">P</font></strong></td>     </tr>      <tr>       <td valign="top" width="325">Run ActiveX controls and plug-ins</td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>     </tr>      <tr>       <td valign="top" width="325">Script ActiveX controls marked as safe for scripting</td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>     </tr>   </tbody></table>  <p><strong>Downloads</strong></p>  <table cellspacing="0" cellpadding="0" width="550" border="1"><tbody>     <tr>       <td valign="top" width="325">&#160;</td>        <td valign="top" width="25">H</td>        <td valign="top" width="25">MH</td>        <td valign="top" width="25">M</td>        <td valign="top" width="25">ML</td>        <td valign="top" width="25">L</td>     </tr>      <tr>       <td valign="top" width="325">Automatic prompting for file downloads</td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>     </tr>      <tr>       <td valign="top" width="325">File download</td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>     </tr>      <tr>       <td valign="top" width="325">Font download</td>        <td valign="top" width="25"><strong><font color="#0000ff">P</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>     </tr>   </tbody></table>  <p><strong>Enable .NET Framework setup</strong></p>  <table cellspacing="0" cellpadding="0" width="550" border="1"><tbody>     <tr>       <td valign="top" width="325">&#160;</td>        <td valign="top" width="25">H</td>        <td valign="top" width="25">MH</td>        <td valign="top" width="25">M</td>        <td valign="top" width="25">ML</td>        <td valign="top" width="25">L</td>     </tr>      <tr>       <td valign="top" width="325">Enable .NET Framework setup</td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong><font color="#ff0000"></font></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>     </tr>   </tbody></table>  <p><strong>Miscellaneous</strong></p>  <table cellspacing="0" cellpadding="0" width="550" border="1"><tbody>     <tr>       <td valign="top" width="325">&#160;</td>        <td valign="top" width="25">H</td>        <td valign="top" width="25">MH</td>        <td valign="top" width="25">M</td>        <td valign="top" width="25">ML</td>        <td valign="top" width="25">L</td>     </tr>      <tr>       <td valign="top" width="325">Access data sources across domains</td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25">P</td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong><font color="#ff0000"></font></td>     </tr>      <tr>       <td valign="top" width="325">Allow META REFRESH</td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong><font color="#ff0000"></font></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>     </tr>      <tr>       <td valign="top" width="325">Allow scripting of Internet Explorer Web browser control</td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong><font color="#ff0000"><strong></strong></font></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>     </tr>      <tr>       <td valign="top" width="325">Allow script-initiated windows without size or position constraints</td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>     </tr>      <tr>       <td valign="top" width="325">Allow web pages to use restricted protocols for active content</td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><strong><font color="#0000ff">P</font></strong></td>        <td valign="top" width="25"><strong><font color="#0000ff">P</font></strong></td>        <td valign="top" width="25"><strong><font color="#0000ff">P</font></strong></td>        <td valign="top" width="25"><strong><font color="#0000ff">P</font></strong></td>     </tr>      <tr>       <td valign="top" width="325">Allow web sites to open windows without address or status bars</td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>     </tr>      <tr>       <td valign="top" width="325">Display mixed content</td>        <td valign="top" width="25"><strong><font color="#0000ff">P</font></strong></td>        <td valign="top" width="25"><strong><font color="#0000ff">P</font></strong></td>        <td valign="top" width="25"><strong><font color="#0000ff">P</font></strong></td>        <td valign="top" width="25"><strong><font color="#0000ff">P</font></strong></td>        <td valign="top" width="25"><strong><font color="#0000ff">P</font></strong></td>     </tr>      <tr>       <td valign="top" width="325">Don't prompt for client certificate selection when no certificates or only one certificate exists</td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>     </tr>      <tr>       <td valign="top" width="325">Drag and drop or copy and paste files</td>        <td valign="top" width="25"><strong><font color="#0000ff">P</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>     </tr>      <tr>       <td valign="top" width="325">Include local directory path when uploading files to a server</td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>     </tr>      <tr>       <td valign="top" width="325">Installation of desktop items</td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><strong><font color="#0000ff">P</font></strong></td>        <td valign="top" width="25"><strong><font color="#0000ff">P</font></strong></td>        <td valign="top" width="25"><strong><font color="#0000ff">P</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>     </tr>      <tr>       <td valign="top" width="325">Launching applications and unsafe files</td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><strong><font color="#0000ff">P</font></strong></td>        <td valign="top" width="25"><strong><font color="#0000ff">P</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>     </tr>      <tr>       <td valign="top" width="325">Launching programs and files in an IFRAME</td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><strong><font color="#0000ff">P</font></strong></td>        <td valign="top" width="25"><strong><font color="#0000ff">P</font></strong></td>        <td valign="top" width="25"><strong><font color="#0000ff">P</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>     </tr>      <tr>       <td valign="top" width="325">Navigate sub-frames across different domains</td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>     </tr>      <tr>       <td valign="top" width="325">Open files based on content, not file extension</td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>     </tr>      <tr>       <td valign="top" width="325">Software channel permissions</td>        <td valign="top" width="25">1</td>        <td valign="top" width="25">2</td>        <td valign="top" width="25">2</td>        <td valign="top" width="25">2</td>        <td valign="top" width="25">3</td>     </tr>      <tr>       <td valign="top" width="325">Submit non-encrypted form data</td>        <td valign="top" width="25"><strong><font color="#0000ff">P</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>     </tr>      <tr>       <td valign="top" width="325">Use phishing filter</td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>     </tr>      <tr>       <td valign="top" width="325">Use pop-up blocker</td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>     </tr>      <tr>       <td valign="top" width="325">Userdata persistence</td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>     </tr>      <tr>       <td valign="top" width="325">Web sites in less privileged content zone can navigate into this zone</td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#0000ff">P</font></strong></td>     </tr>   </tbody></table>  <p>&#160;&#160;&#160;&#160; 1 = Prohibit downloads from software update channels    <br />&#160;&#160;&#160;&#160; 2 = Cache content downloaded from software update channels     <br />&#160;&#160;&#160;&#160; 3 = Automatically install software updates</p>  <p><strong>Scripting</strong></p>  <table cellspacing="0" cellpadding="0" width="550" border="1"><tbody>     <tr>       <td valign="top" width="325">&#160;</td>        <td valign="top" width="25">H</td>        <td valign="top" width="25">MH</td>        <td valign="top" width="25">M</td>        <td valign="top" width="25">ML</td>        <td valign="top" width="25">L</td>     </tr>      <tr>       <td valign="top" width="325">Active scripting</td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong><font color="#ff0000"></font></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>     </tr>      <tr>       <td valign="top" width="325">Allow programmatic clipboard access</td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><strong><font color="#0000ff">P</font></strong></td>        <td valign="top" width="25"><strong><font color="#0000ff">P</font></strong></td>        <td valign="top" width="25"><strong><font color="#0000ff">P</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>     </tr>      <tr>       <td valign="top" width="325">Allow status bar updates via script</td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>     </tr>      <tr>       <td valign="top" width="325">Allow Web sites to prompt for information using scripted windows</td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>     </tr>      <tr>       <td valign="top" width="325">Scripting of Java applets</td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>     </tr>   </tbody></table>  <p><strong>User authentication</strong></p>  <table cellspacing="0" cellpadding="0" width="550" border="1"><tbody>     <tr>       <td valign="top" width="325">&#160;</td>        <td valign="top" width="25">H</td>        <td valign="top" width="25">MH</td>        <td valign="top" width="25">M</td>        <td valign="top" width="25">ML</td>        <td valign="top" width="25">L</td>     </tr>      <tr>       <td valign="top" width="325">Logon</td>        <td valign="top" width="25">1</td>        <td valign="top" width="25">2</td>        <td valign="top" width="25">2</td>        <td valign="top" width="25">2</td>        <td valign="top" width="25">3</td>     </tr>   </tbody></table>  <p>&#160;&#160;&#160;&#160; 1 = Prompt the user for name and password    <br />&#160;&#160;&#160;&#160; 2 = Automatic logon only in intranet zone     <br />&#160;&#160;&#160;&#160; 3 = Automatic logon with current user name and password</p>  <p>&#160;</p>  <p><strong>Privacy settings (on the &quot;Privacy&quot; tab)</strong></p>  <table cellspacing="0" cellpadding="0" width="550" border="1"><tbody>     <tr>       <td valign="top" width="325">&#160;</td>        <td valign="top" width="25">H</td>        <td valign="top" width="25">MH</td>        <td valign="top" width="25">M</td>        <td valign="top" width="25">ML</td>        <td valign="top" width="25">L</td>     </tr>      <tr>       <td valign="top" width="325">Allow persistent cookies</td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>     </tr>      <tr>       <td valign="top" width="325">Allow per-session cookies</td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>     </tr>      <tr>       <td valign="top" width="325">Allow third-party persistent cookies</td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><strong><font color="#0000ff">P</font></strong></td>        <td valign="top" width="25"><strong><font color="#0000ff">P</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>     </tr>      <tr>       <td valign="top" width="325">Allow third-party session cookies</td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>     </tr>   </tbody></table><img src="http://blogs.technet.com/aggbug.aspx?PostID=3124973" width="1" height="1">]]></content:encoded>
      <pubDate>Tue, 16 Sep 2008 20:19:36 +0000</pubDate>
      <category domain="http://securityratty.com/tag/script behaviors">script behaviors</category>
      <category domain="http://securityratty.com/tag/script">script</category>
      <category domain="http://securityratty.com/tag/script activex controls">script activex controls</category>
      <category domain="http://securityratty.com/tag/activex controls">activex controls</category>
      <category domain="http://securityratty.com/tag/net framework">net framework</category>
      <category domain="http://securityratty.com/tag/net">net</category>
      <category domain="http://securityratty.com/tag/zone">zone</category>
      <category domain="http://securityratty.com/tag/content zone">content zone</category>
      <category domain="http://securityratty.com/tag/content">content</category>
      <source url="http://blogs.technet.com/steriley/archive/2008/09/16/internet-explorer-security-levels-compared.aspx">Internet Explorer security levels compared</source>
    </item>
    <item>
      <title><![CDATA[Black Hat : Got2 Luv the H8ers]]></title>
      <link>http://securityratty.com/article/d5f40fbddbb173969933598d3796b520</link>
      <guid>http://securityratty.com/article/d5f40fbddbb173969933598d3796b520</guid>
      <description><![CDATA[So, this afternoon, I'm in the Microsoft booth at Black Hat when this guy comes up (badge hidden of course) and starts talking to some of my colleagues. Right away, it was pretty obvious that he was...]]></description>
      <content:encoded><![CDATA[<p><img style="border-top-width: 0px; border-left-width: 0px; border-bottom-width: 0px; border-right-width: 0px" height="124" alt="bh2008news" src="http://blogs.technet.com/blogfiles/security/WindowsLiveWriter/BlackHatGot2LuvtheH8ers_F8AC/bh2008news_5.png" width="180" align="left" border="0"> So, this afternoon, I'm in the Microsoft booth at Black Hat when this guy comes up (badge hidden of course) and starts talking to some of my colleagues.&nbsp; Right away, it was pretty obvious that he was antagonistic.&nbsp; I will refer to him as "h8er" from here on out.&nbsp; Though I am paraphrasing a bit, this is based upon a true story.&nbsp; It gave me a chuckle, so I thought I'd share.</p> <p></p> <p><em><strong>h8er:</strong>&nbsp; So, how does it feel to work for a company that has made so many bad security decisions.</em></p> <p><em><strong>MSFT guy:</strong>&nbsp; Well, I feel lucky to be in a position to try and influence good security decisions going forward - are there any specifics you want to give me feedback on?</em></p> <p><em><strong>h8er:</strong>&nbsp; All those prompts irritating people, for example.</em></p> <p><em><strong>MSFT guy:</strong>&nbsp; Oh, so you don't like that aspect of UAC.&nbsp; We've gotten a lot of feedback on that, but the UAC security changes in Windows Vista encompass a pretty wide range of options designed to make it easier for most users to run as non-admin.&nbsp; Plus, we've incorporated some of the feedback into SP1 and I think it is a lot better.&nbsp; Have you tried SP1?</em></p> <p><em><strong>h8er:</strong>&nbsp; &lt;crickets chirping in the silence&gt;</em></p> <p><em><strong>MSFT guy:</strong> (still trying) Let me ask it a different way.&nbsp; A lot of folks have said that after the first few weeks, the UAC prompts tapered off, have you not found that to be the case?</em></p> <p><em><strong>h8er:</strong>&nbsp; &lt;crickets chirping in the silence&gt;</em></p> <p><em><strong>MSFT guy:</strong> What about some of the other changes in Windows Vista - I think the addition of ASLR, for example, was a good decision and raises the bars for attackers developing exploits.</em></p> <p><em><strong>non-MSFT guys standing nearby:</strong>&nbsp; He has probably never even tried Vista - I bet you run Linux and just heard the prompt stuff second hand.<img style="border-top-width: 0px; border-left-width: 0px; border-bottom-width: 0px; border-right-width: 0px" height="86" alt="cultofmac" src="http://blogs.technet.com/blogfiles/security/WindowsLiveWriter/BlackHatGot2LuvtheH8ers_F8AC/cultofmac_3.jpg" width="69" align="right" border="0"></em></p> <p><em><strong>h8er:</strong>&nbsp; I don't run Linux ... I run a Mac! </em></p> <p>(NOTE: This seemed to rattle him, so he went on the offensive.)</p> <p><em><strong>h8er:</strong>&nbsp; Don't you feel embarrassed working for Microsoft knowing that 40% of your customers are infected with Malware?</em></p> <p><em><strong>MSFT guy:</strong>&nbsp; Actually, based upon research in the latest <a href="http://www.microsoft.com/sir" target="_blank">Security Intelligence Report</a>, less than 1% of machines have malware and need corrective action - plus, recent research in the same report has shown that most of that is on older platforms and Windows Vista has an even lower incidence.&nbsp; 4</em><em>0% is a pretty high number, what source did you hear that from?</em></p> <p><em><strong>h8er:</strong>&nbsp; &lt;crickets chirping in the silence&gt;</em></p> <p>(NOTE:&nbsp; Need a new tack, better try something different.)</p> <p><em><strong>h8er:</strong>&nbsp; Well, I feel a lot safer running my Mac and knowing the malware writers aren't targeting me.</em></p> <p><em><strong>MSFT guy:</strong>&nbsp; Oh, threat landscape is a different topic than the security of the software, but I can't really agree anyway.&nbsp; Many of the folks I talk to are more concerned about spearphishing or targeted attacks specifically against their valuable data.&nbsp; Recent data shows that Mac OS X has quite a higher incidence of security vulnerabilities that other comparable systems.&nbsp; That means that if an attacker did target them, he'd have a lot more options to choose from.&nbsp; In that case, I feel much more comfortable using or recommending Windows Vista than I would using your Mac.</em></p> <p>He left shortly after that, but not before giving the Microsoft guy an invite to his company's party - I won't tell you which company it was, but it makes the story even funnier.&nbsp; To cap it, a few minutes later, one of the bystanders came by and said "so, did the Mac fanboy get tired of harrassing you and leave?"</p> <p>Having lots of fun at Black Hat 2008 ~ Jeff</p><img src="http://blogs.technet.com/aggbug.aspx?PostID=3101931" width="1" height="1">]]></content:encoded>
      <pubDate>Thu, 07 Aug 2008 01:07:02 +0000</pubDate>
      <category domain="http://securityratty.com/tag/guy">guy</category>
      <category domain="http://securityratty.com/tag/msft guy">msft guy</category>
      <category domain="http://securityratty.com/tag/windows vista encompass">windows vista encompass</category>
      <category domain="http://securityratty.com/tag/windows vista">windows vista</category>
      <category domain="http://securityratty.com/tag/report">report</category>
      <category domain="http://securityratty.com/tag/uac">uac</category>
      <category domain="http://securityratty.com/tag/uac security">uac security</category>
      <category domain="http://securityratty.com/tag/security intelligence report">security intelligence report</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <source url="http://blogs.technet.com/security/archive/2008/08/07/black-hat-got2-luv-the-h8ers.aspx">Black Hat : Got2 Luv the H8ers</source>
    </item>
    <item>
      <title><![CDATA[Symantec tool cleans up XP SP3 registry corruption]]></title>
      <link>http://securityratty.com/article/4b8d3de1c1eb64168ca42208045e3277</link>
      <guid>http://securityratty.com/article/4b8d3de1c1eb64168ca42208045e3277</guid>
      <description><![CDATA[Symantec has released a free tool that clears spurious Windows' registry entries that had crippled some PCs running the company's security software after they were upgraded to Windows XP Service Pack...]]></description>
      <content:encoded><![CDATA[Symantec has released a free tool that clears spurious Windows' registry entries that had crippled some PCs running the company's security software after they were upgraded to Windows XP Service Pack 3 or Vista SP1.
<p><a href="http://feeds.computerworld.com/~a/Computerworld/Security/News?a=MSqDPB"><img src="http://feeds.computerworld.com/~a/Computerworld/Security/News?i=MSqDPB" border="0"></img></a></p><img src="http://feeds.computerworld.com/~r/Computerworld/Security/News/~4/306244215" height="1" width="1"/>]]></content:encoded>
      <pubDate>Fri, 06 Jun 2008 09:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/windows">windows</category>
      <category domain="http://securityratty.com/tag/clears spurious windows">clears spurious windows</category>
      <category domain="http://securityratty.com/tag/symantec">symantec</category>
      <category domain="http://securityratty.com/tag/security software">security software</category>
      <category domain="http://securityratty.com/tag/registry entries">registry entries</category>
      <category domain="http://securityratty.com/tag/free tool">free tool</category>
      <category domain="http://securityratty.com/tag/service pack">service pack</category>
      <category domain="http://securityratty.com/tag/vista sp1">vista sp1</category>
      <category domain="http://securityratty.com/tag/pcs">pcs</category>
      <source url="http://feeds.computerworld.com/~r/Computerworld/Security/News/~3/306244215/article.do">Symantec tool cleans up XP SP3 registry corruption</source>
    </item>
    <item>
      <title><![CDATA[June Patch Tuesday Advance Notification]]></title>
      <link>http://securityratty.com/article/555c8728a66a50c3b81fac49a35ddad9</link>
      <guid>http://securityratty.com/article/555c8728a66a50c3b81fac49a35ddad9</guid>
      <description><![CDATA[On Tuesday, June 10, Microsoft will release 7 security bulletins, 3 of them critical, and security updates to address them. Microsoft's new advance notification bulletin format adds a very readable...]]></description>
      <content:encoded><![CDATA[On Tuesday, June 10, Microsoft will release 7 security bulletins, 3 of them critical, and security updates to address them.

<a href="http://www.microsoft.com/technet/security/bulletin/ms08-jun.mspx">Microsoft's new advance notification bulletin format</a> adds a very readable new view in the Affected Software section. For each operating system version you can see which bulletins are relevant and what the severity is. The bulletins now have English titles too:

The three critical bulletins:
<ul>
	<li>The Bluetooth Bulletin: Affects XP SP2 and SP3, Vista and Vista SP1</li>
	<li>The Internet Explorer Bulletin: Affects all Windows versions. Critical on IE6 and IE7 on Windows 2000, XP and Vista; Moderate on Windows Server 2003 and 2008., </li>
	<li>The DirectX Bulletin: Critical on all versions of Windows and DirectX.</li>
</ul>

The other bulletins are entitled WINS, Active Directory, PGM (all ranked Important) and Kill Bit, ranked Moderate.<br style="clear: both;"/>
  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=e08d9e772790cd852c900f652dab0eb4" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=e08d9e772790cd852c900f652dab0eb4" style="display: none;" border="0" height="1" width="1" alt=""/><img src="http://feeds.ziffdavisenterprise.com/~r/RSS/cheap_hack/~4/305549057" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 05 Jun 2008 11:49:31 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security bulletins">security bulletins</category>
      <category domain="http://securityratty.com/tag/bulletins">bulletins</category>
      <category domain="http://securityratty.com/tag/critical bulletins">critical bulletins</category>
      <category domain="http://securityratty.com/tag/windows versions">windows versions</category>
      <category domain="http://securityratty.com/tag/versions">versions</category>
      <category domain="http://securityratty.com/tag/windows">windows</category>
      <category domain="http://securityratty.com/tag/critical">critical</category>
      <category domain="http://securityratty.com/tag/vista sp1">vista sp1</category>
      <category domain="http://securityratty.com/tag/windows server">windows server</category>
      <source url="http://feeds.ziffdavisenterprise.com/~r/RSS/cheap_hack/~3/305549057/june_patch_tuesday_advance_notification.html">June Patch Tuesday Advance Notification</source>
    </item>
    <item>
      <title><![CDATA[June Patch Tuesday Advance Notification]]></title>
      <link>http://securityratty.com/article/b73bb209c12910b096a7a6b1cff88750</link>
      <guid>http://securityratty.com/article/b73bb209c12910b096a7a6b1cff88750</guid>
      <description><![CDATA[On Tuesday, June 10, Microsoft will release seven security bulletins, three of them critical, and security updates to address them. Microsoft's new advance notification bulletin format adds a very...]]></description>
      <content:encoded><![CDATA[On Tuesday, June 10, Microsoft will release seven security bulletins, three of them critical, and security updates to address them.

<a href="http://www.microsoft.com/technet/security/bulletin/ms08-jun.mspx" target="_blank">Microsoft's new advance notification bulletin format</a> adds a very readable new view in the Affected Software section. For each operating system version you can see which bulletins are relevant and what the severity is. The bulletins now have English titles too:

The three critical bulletins:
<ul><li>The Bluetooth Bulletin: Affects XP SP2 and SP3, Vista and Vista SP1</li>
	<li>The Internet Explorer Bulletin: Affects all Windows versions. Critical on IE 6 and IE 7 on Windows 2000, XP and Vista; Moderate on Windows Server 2003 and 2008</li>
	<li>The DirectX Bulletin: Critical on all versions of Windows and DirectX</li>
</ul>

The other bulletins are for WINS, Active Directory and PGM (all ranked Important) and Kill Bit, ranked Moderate.<br style="clear: both;"/>
  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=bbca11af77f12f3757d0d85640d39569" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=bbca11af77f12f3757d0d85640d39569" style="display: none;" border="0" height="1" width="1" alt=""/><img src="http://feeds.ziffdavisenterprise.com/~r/RSS/cheap_hack/~4/338277695" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 05 Jun 2008 11:49:31 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security bulletins">security bulletins</category>
      <category domain="http://securityratty.com/tag/bulletins">bulletins</category>
      <category domain="http://securityratty.com/tag/critical bulletins">critical bulletins</category>
      <category domain="http://securityratty.com/tag/windows versions">windows versions</category>
      <category domain="http://securityratty.com/tag/versions">versions</category>
      <category domain="http://securityratty.com/tag/windows">windows</category>
      <category domain="http://securityratty.com/tag/critical">critical</category>
      <category domain="http://securityratty.com/tag/vista sp1">vista sp1</category>
      <category domain="http://securityratty.com/tag/windows server">windows server</category>
      <source url="http://feeds.ziffdavisenterprise.com/~r/RSS/cheap_hack/~3/338277695/june_patch_tuesday_advance_notification.html">June Patch Tuesday Advance Notification</source>
    </item>
    <item>
      <title><![CDATA[Security Briefing: May 27th]]></title>
      <link>http://securityratty.com/article/5db823fcf7ed033552cee3af3fd12fae</link>
      <guid>http://securityratty.com/article/5db823fcf7ed033552cee3af3fd12fae</guid>
      <description><![CDATA[Sorry for the lack of content yesterday. Due to a PBCAK failure to pay attention I neglected to publish write yesterdays article. So, theyll trickle out over the next couple days Ill try to do better...]]></description>
      <content:encoded><![CDATA[<p><center><img src='http://www.liquidmatrix.org/blog/wp-content/uploads/2007/09/newspapera.jpg' alt='newspapera.jpg' /></center></p>
<p>Sorry for the lack of content yesterday. Due to a <strike>PBCAK</strike> <i>failure to pay attention</i> I neglected to <strike>publish</strike> <i>write</i> yesterday&#8217;s article. So, <strike>they&#8217;ll trickle out over the next couple days</strike> <i>I&#8217;ll try to do better while Dave takes some time off to work on a personal project.</i> Thanks to all of our new subscribers that joined us yesterday. Welcome! </p>
<p>Click here to <a href="http://feeds.feedburner.com/Liquidmatrix">subscribe to Liquidmatrix Security Digest!</a></p>
<p>And now, the news&#8230;</p>
<ol>
<li><a href="http://www.tsa.gov/blog/2008/05/science-behind-3-1-1.html">The Science behind 3-1-1</a> <i>Mental Note - When flying this weekend, do not play the part of a vain astronaut.</i></li>
<li><a href="http://www.turre.com/blog/?p=156">DeCSS is now illegal in Finland</a> <i>Quick - jam the inflatable boat back into the travel pouch &#8212; Hurry!</i></li>
<li><a href="http://www.microsoft.com/downloads/details.aspx?familyid=37d0c614-9c06-4b61-bb2e-6ab9953a14ab&#038;displaylang=en&#038;tm">Microsoft Whitepaper: Comparing Features - Windows XP SP3 and Vista SP1</a> <i>smell the slow burn of a sweaty Ballmer</i></li>
<li><a href="http://blog.wired.com/27bstroke6/2008/05/computer-progra.html">CFP (Computers Freedom and Privacy) Conference Roundup from Wired&#8217;s 27B/6</a> <i>MmmmMmmmm&#8230; Cyberdyne me baby</i></li>
<li><a href="http://infotech.indiatimes.com/RIM_not_to_give_keys_of_BlackBerry_/articleshow/3075964.cms">RIM will not give Blackberry Keys to India</a> <i>Ahhh yes, but to which national governments (besides the  Mennonites) have the boyz in Waterloo given the keys?</i></li>
<li><a href="http://lifehacker.com/391261/elevator-quickly-disables-uac-for-specific-programs">Elevator disables UAC on a per-application basis</a> <i>Do you want to Allow or Cancel?</i></li>
<li><a href="http://education.guardian.co.uk/higher/news/story/0,,2282045,00.html">Nottingham University Student Detained</a>  <i>DWB (Downloading While Brown) from the US Gov&#8217;t - Go Directly to Secret Detention</i></li>
<li><a href="http://www.medicalnewstoday.com/articles/108399.php">President Bush Signs Landmark Genetic Nondiscrimination Information Act Into Law</a> <i>Gattaca&#8230; Gattaca&#8230; Gattaca&#8230;</i></li>
</ol>
<p>More as I process it all (seriously, where the hell does Dave find the time for this every.single.day?)</p>
<p> Tags: <a href="http://technorati.com/tag/News" rel="tag">News</a>, <a href="http://technorati.com/tag/Daily+Links" rel="tag"> Daily Links</a>, <a href="http://technorati.com/tag/Security+Blog" rel="tag"> Security Blog</a>, <a href="http://technorati.com/tag/Information+Security" rel="tag"> Information Security</a>, <a href="http://technorati.com/tag/Security+News" rel="tag"> Security News</a></p>

<p><a href="http://feeds.feedburner.com/~a/Liquidmatrix?a=K9vbdc"><img src="http://feeds.feedburner.com/~a/Liquidmatrix?i=K9vbdc" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=JIiHXH"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=JIiHXH" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=BXtljh"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=BXtljh" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=56BOth"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=56BOth" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=bpNnfh"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=bpNnfh" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=GSQF6h"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=GSQF6h" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/Liquidmatrix/~4/299094807" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 27 May 2008 09:30:44 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security news">security news</category>
      <category domain="http://securityratty.com/tag/news">news</category>
      <category domain="http://securityratty.com/tag/blackberry keys">blackberry keys</category>
      <category domain="http://securityratty.com/tag/nottingham university student">nottingham university student</category>
      <category domain="http://securityratty.com/tag/dave">dave</category>
      <category domain="http://securityratty.com/tag/content yesterday">content yesterday</category>
      <category domain="http://securityratty.com/tag/yesterday">yesterday</category>
      <category domain="http://securityratty.com/tag/travel pouch hurry">travel pouch hurry</category>
      <category domain="http://securityratty.com/tag/keys">keys</category>
      <source url="http://feeds.feedburner.com/~r/Liquidmatrix/~3/299094807/">Security Briefing: May 27th</source>
    </item>
    <item>
      <title><![CDATA[Microsoft backpedals on Windows updates]]></title>
      <link>http://securityratty.com/article/f771d508ca099617a2187fc62f981bfc</link>
      <guid>http://securityratty.com/article/f771d508ca099617a2187fc62f981bfc</guid>
      <description><![CDATA[Earlier this week, Microsoft announced that it was delaying the release of Windows XP Service Pack 3 due to incompatibilities with its Microsoft Dynamics Retail Management software. Now comes word...]]></description>
      <content:encoded><![CDATA[Earlier this week, Microsoft announced that it was delaying the release of Windows XP Service Pack 3 due to incompatibilities with its Microsoft Dynamics Retail Management software. Now comes word that Windows Vista Service Pack 1 has also been withdrawn from automatic distribution. According to Microsoft representatives, changes introduced in Vista SP1 affect how Microsoft's SQL Server database behaves in certain situations, potentially resulting in data loss or corruption.]]></content:encoded>
      <pubDate>Wed, 30 Apr 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/microsoft">microsoft</category>
      <category domain="http://securityratty.com/tag/microsoft representatives">microsoft representatives</category>
      <category domain="http://securityratty.com/tag/vista sp1 affect">vista sp1 affect</category>
      <category domain="http://securityratty.com/tag/data loss">data loss</category>
      <category domain="http://securityratty.com/tag/automatic distribution">automatic distribution</category>
      <category domain="http://securityratty.com/tag/windows">windows</category>
      <category domain="http://securityratty.com/tag/service pack">service pack</category>
      <category domain="http://securityratty.com/tag/corruption">corruption</category>
      <category domain="http://securityratty.com/tag/withdrawn">withdrawn</category>
      <source url="http://www.networkworld.com/news/2008/050108-microsoft-backpedals-on-windows.html?fsrc=rss-security">Microsoft backpedals on Windows updates</source>
    </item>
    <item>
      <title><![CDATA[Researcher finds new flaw in QuickTime for Windows]]></title>
      <link>http://securityratty.com/article/a30733e1f20189015c9cac8e468c3593</link>
      <guid>http://securityratty.com/article/a30733e1f20189015c9cac8e468c3593</guid>
      <description><![CDATA[A rather tricky vulnerability in QuickTime could be exploited remotely to attack Windows PCs running Vista SP1 or XP...]]></description>
      <content:encoded><![CDATA[A rather tricky vulnerability in QuickTime could be exploited remotely to attack Windows PCs running Vista SP1 or XP SP2.
<p><a href="http://feeds.computerworld.com/~a/Computerworld/Security/News?a=IVUwTJ"><img src="http://feeds.computerworld.com/~a/Computerworld/Security/News?i=IVUwTJ" border="0"></img></a></p><img src="http://feeds.computerworld.com/~r/Computerworld/Security/News/~4/279367866" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 28 Apr 2008 09:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/attack windows pcs">attack windows pcs</category>
      <category domain="http://securityratty.com/tag/quicktime">quicktime</category>
      <category domain="http://securityratty.com/tag/tricky vulnerability">tricky vulnerability</category>
      <category domain="http://securityratty.com/tag/vista sp1">vista sp1</category>
      <category domain="http://securityratty.com/tag/remotely">remotely</category>
      <category domain="http://securityratty.com/tag/sp2">sp2</category>
      <source url="http://feeds.computerworld.com/~r/Computerworld/Security/News/~3/279367866/article.do">Researcher finds new flaw in QuickTime for Windows</source>
    </item>
    <item>
      <title><![CDATA[Microsoft releases remaining Vista SP1 language packs]]></title>
      <link>http://securityratty.com/article/6d216b6a29af795ffdf360cb1dc77490</link>
      <guid>http://securityratty.com/article/6d216b6a29af795ffdf360cb1dc77490</guid>
      <description><![CDATA[Microsoft Tuesday released the remaining 31 language editions of Windows Vista Service Pack 1 (SP1) to Windows...]]></description>
      <content:encoded><![CDATA[Microsoft Tuesday released the remaining 31 language editions of Windows Vista Service Pack 1 (SP1) to Windows Update.]]></content:encoded>
      <pubDate>Tue, 15 Apr 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/sp1">sp1</category>
      <category domain="http://securityratty.com/tag/microsoft tuesday">microsoft tuesday</category>
      <category domain="http://securityratty.com/tag/language editions">language editions</category>
      <category domain="http://securityratty.com/tag/windows">windows</category>
      <source url="http://www.networkworld.com/news/2008/041608-microsoft-releases-remaining-vista-sp1.html?fsrc=rss-security">Microsoft releases remaining Vista SP1 language packs</source>
    </item>
    <item>
      <title><![CDATA[Microsoft fixes SP1 'repeating reboot' bug ]]></title>
      <link>http://securityratty.com/article/9ff629610f6e396db7c099801d5e248b</link>
      <guid>http://securityratty.com/article/9ff629610f6e396db7c099801d5e248b</guid>
      <description><![CDATA[Microsoft is resuming automatic distribution of a Vista Service Pack 1 prerequisite update that previously sent some users of the operating system into an endless reboot cycle during...]]></description>
      <content:encoded><![CDATA[Microsoft is resuming automatic distribution of a Vista Service Pack 1 prerequisite update that previously sent some users of the operating system into an endless reboot cycle during installation.]]></content:encoded>
      <pubDate>Tue, 08 Apr 2008 09:21:49 +0000</pubDate>
      <category domain="http://securityratty.com/tag/vista service pack">vista service pack</category>
      <category domain="http://securityratty.com/tag/endless reboot cycle">endless reboot cycle</category>
      <category domain="http://securityratty.com/tag/automatic distribution">automatic distribution</category>
      <category domain="http://securityratty.com/tag/microsoft">microsoft</category>
      <category domain="http://securityratty.com/tag/system">system</category>
      <category domain="http://securityratty.com/tag/users">users</category>
      <category domain="http://securityratty.com/tag/installation">installation</category>
      <category domain="http://securityratty.com/tag/previously">previously</category>
      <category domain="http://securityratty.com/tag/prerequisite">prerequisite</category>
      <source url="http://www.enn.ie/article/10124179.html">Microsoft fixes SP1 'repeating reboot' bug </source>
    </item>
  </channel>
</rss>
