Category Archives: Uncategorized

Bug in 2.0 Jitter?!

Just found this (scroll down to “.NET Framework 2.0 Security Hole”) via Marc’s Blog. Not sure if this is true – but it sounds scary…this brings me back to an old point – don’t run untrusted apps off the Internet – and be … Continue reading

Posted in Uncategorized | Leave a comment

"Manage Private Key" on Vista

A while ago I wrote how to set ACLs on a private key container. Today I spotted a new context menu item in the “Certificates” MMC snap-in on Vista. Right-click a certificate and select “All Actions->Manage Private Key” to get … Continue reading

Posted in Uncategorized | Leave a comment

TVP Slides

Thanks to everyone who attended the Connected Systems Roadshow this week in Reading! We had great fun. You can find the slides and the architecture sample I wrote during the talk here. Mike – who did a great talk on hosting … Continue reading

Posted in Uncategorized | Leave a comment

HttpSysCfg

A (kind of) polished version of my HTTP.SYS ACL/SSL helper tool can be found on the thinktecture tools page.  

Posted in Uncategorized | Leave a comment

AntiXss 1.5

Finally…the new version of the AntiXss library is now available for download. Go get it! New features include: support for partial trust :) more encoding functions tutorials Happy encoding!  

Posted in Uncategorized | Leave a comment

AzManBulkImport Update

Joe sent me a new version of his AzMan bulk importer – in the .zip is a changes document. enjoy! AzManBulkImport123.zip (6.25 KB)  

Posted in Uncategorized | Leave a comment

SecureString Redux

Read more over at Shawn’s http://blogs.msdn.com/shawnfa/archive/2006/11/01/securestring-redux.aspx  

Posted in Uncategorized | Leave a comment

CAS und ClickOnce Webcast

Ich habe total vergessen die versprochenen Samples für den CAS & ClickOnce Webcast hochzuladen (danke Andreas für die Erinnerung). ClickOnce und NoTouch.zip (873.58 KB)  

Posted in Uncategorized | Leave a comment

Interview mit Mike Downen

Mike Downen ist der Security Program Manager der CLR – dieses Interview habe ich im Sommer für das Reach Magazine geführt, und ist jetzt online auf MSDN. http://www.microsoft.com/germany/msdn/security/interview27102006.mspx

Posted in Uncategorized | Leave a comment

So much for SecureString

Every once in a while questions come up regarding the usefulness of SecureString. StaceyW posted this link today…:O Interestingly, Ian told me that the latest build of WPF also removed the SecureString functionality from the PasswordBox and replaced it with an … Continue reading

Posted in Uncategorized | Leave a comment