<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://port25.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Port 25: The Open Source Community at Microsoft : Security, Dev Center</title><link>http://port25.technet.com/archive/tags/Security/Dev+Center/default.aspx</link><description>Tags: Security, Dev Center</description><dc:language>en</dc:language><generator>CommunityServer 2007.1 (Build: 40109.1145)</generator><item><title>Web Sandbox Source Now Available Under Apache License 2.0</title><link>http://port25.technet.com/archive/2009/01/26/web-sandbox-source-now-available-under-apache-license-2-0.aspx</link><pubDate>Tue, 27 Jan 2009 02:48:00 GMT</pubDate><guid isPermaLink="false">af7480c4-26b7-468d-87b0-2acebabb473d:23512</guid><dc:creator>Peter Galli</dc:creator><slash:comments>5</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://port25.technet.com/rsscomments.aspx?PostID=23512</wfw:commentRss><comments>http://port25.technet.com/archive/2009/01/26/web-sandbox-source-now-available-under-apache-license-2-0.aspx#comments</comments><description>&lt;P mce_keep="true"&gt;Microsoft has released more source code under an OSI-approved license: this time it has made the source code for the &lt;A href="http://websandbox.livelabs.com/"&gt;Web Sandbox&lt;/A&gt; runtime available&amp;nbsp;under the &lt;A href="http://www.apache.org/licenses/LICENSE-2.0"&gt;Apache 2.0&lt;/A&gt; &amp;nbsp;open source license.&lt;/P&gt;
&lt;P mce_keep="true"&gt;The Web Sandbox project explores how to advance the web platform to improve security, isolation, quality of service and extensibility capabilities&amp;nbsp;for web developers and website users.&lt;/P&gt;
&lt;P&gt;More information on the licensing details, as well as comprehensive documentation for experimenting and integrating with the Web Sandbox, can be found &lt;A class="" href="http://websandbox.livelabs.com/" target=_blank mce_href="http://websandbox.livelabs.com/"&gt;here&lt;/A&gt;. &amp;nbsp;&lt;/P&gt;
&lt;P&gt;But, while developers are being encouraged to help define and refine the Web Sandbox, it is not recommended for those developers creating production sites as it is still under development.&lt;/P&gt;
&lt;P&gt;The Web Sandbox was created in response to limitations found in the current web platform, and is designed to explore &lt;A class="" href="http://websandbox.livelabs.com/documentation/overview_how.aspx" target=_blank mce_href="http://websandbox.livelabs.com/documentation/overview_how.aspx"&gt;potential solutions&lt;/A&gt;. Having a more secure and robust architecture as a foundational building block will help drive the next wave of Web innovation.&lt;/P&gt;
&lt;P&gt;The Sandbox is a framework that works on most modern browsers that support the&lt;A class="" href="http://www.ecma-international.org/publications/standards/Ecma-262.htm" target=_blank mce_href="http://www.ecma-international.org/publications/standards/Ecma-262.htm"&gt;"ECMA-262, 3&lt;SUP&gt;rd&lt;/SUP&gt; Edition"&lt;/A&gt; (JavaScript) standard, and provides the same features in all modern web browsers. &amp;nbsp;No browser add-ons or changes are required to leverage this technology. Beyond security, the Web Sandbox normalizes the different browsers and provides consistent &lt;A class="" href="http://www.w3.org/DOM/" target=_blank mce_href="http://www.w3.org/DOM/"&gt;W3C DOM&lt;/A&gt; support.&lt;/P&gt;
&lt;P&gt;Since the initial release of Web Sandbox at PDC 2008, the team has received a lot of useful feedback from the web security community, and has also been collaborating with a number of customers, partners and the standards communities, all of whom want to adopt the &amp;nbsp;technology when it is ready.&amp;nbsp; &lt;S&gt;&lt;/S&gt;&lt;/P&gt;
&lt;P&gt;The goal? An open and interoperable standard that will help foster interoperability with complementary technologies like script frameworks and drive widespread adoption of the Web Sandbox.&lt;/P&gt;
&lt;P&gt;This move is good news for Microsoft and the open source communities. But, it is important to note that while an Apache license is being used, the Web Sandbox project is not an Apache Software Foundation project and is not sponsored or endorsed by the ASF.&lt;/P&gt;
&lt;P&gt;Microsoft does, however, already have an active relationship with the ASF. In fact, last year the company announced it had become a &lt;A class="" href="http://port25.technet.com/archive/2008/07/25/oscon2008.aspx" target=_blank mce_href="http://port25.technet.com/archive/2008/07/25/oscon2008.aspx"&gt;sponsor of the ASF&lt;/A&gt;&amp;nbsp;so as to help enable the Foundation pay administrators and other support staff so that its developers can focus on writing great software.&lt;/P&gt;
&lt;P&gt;Sam Ramji, the senior Director of Platform Strategy at Microsoft, also delivered a &lt;A class="" href="http://port25.technet.com/archive/2008/11/06/apachecon-keynote.aspx" target=_blank mce_href="http://port25.technet.com/archive/2008/11/06/apachecon-keynote.aspx"&gt;keynote address at ApacheCon&lt;/A&gt; in New Orleans last November.&lt;/P&gt;
&lt;P&gt;Microsoft's Interoperability Technical Strategy Team already participates as a code contributor to the &lt;A class="" href="http://port25.technet.com/archive/2009/01/19/update-stonehenge-incubation-project.aspx" target=_blank mce_href="http://port25.technet.com/archive/2009/01/19/update-stonehenge-incubation-project.aspx"&gt;Apache Stonehenge incubator project&lt;/A&gt;; the company has also contributed&amp;nbsp;a patch to &lt;A href="http://adodb.sourceforge.net/" mce_href="http://adodb.sourceforge.net/"&gt;ADOdb&lt;/A&gt;, a popular data access layer for PHP used by many applications and which is licensed under the LGPL and BSD; while Microsoft's &lt;A class="" href="http://port25.technet.com/archive/2008/10/14/microsoft-s-powerset-team-resumes-hbase-contributions.aspx" target=_blank mce_href="http://port25.technet.com/archive/2008/10/14/microsoft-s-powerset-team-resumes-hbase-contributions.aspx"&gt;Powerset team&lt;/A&gt;&amp;nbsp;contributes&amp;nbsp;to &lt;A href="http://hadoop.apache.org/hbase/" mce_href="http://hadoop.apache.org/hbase/"&gt;HBase&lt;/A&gt;, an open-source, column-oriented, distributed database written in Java.&lt;/P&gt;&lt;img src="http://port25.technet.com/aggbug.aspx?PostID=23512" width="1" height="1"&gt;</description><category domain="http://port25.technet.com/archive/tags/Interop/default.aspx">Interop</category><category domain="http://port25.technet.com/archive/tags/Security/default.aspx">Security</category><category domain="http://port25.technet.com/archive/tags/Standards/default.aspx">Standards</category><category domain="http://port25.technet.com/archive/tags/Java/default.aspx">Java</category><category domain="http://port25.technet.com/archive/tags/Community/default.aspx">Community</category><category domain="http://port25.technet.com/archive/tags/Open+Source/default.aspx">Open Source</category><category domain="http://port25.technet.com/archive/tags/Dev+Center/default.aspx">Dev Center</category><category domain="http://port25.technet.com/archive/tags/Web/default.aspx">Web</category><category domain="http://port25.technet.com/archive/tags/_7E00_FeaturedPost/default.aspx">~FeaturedPost</category><category domain="http://port25.technet.com/archive/tags/Peter+Galli/default.aspx">Peter Galli</category></item><item><title>Black Hat US 2006: Networking &amp; Heap Manager Updates with the Core Windows Team</title><link>http://port25.technet.com/archive/2006/08/02/Black-Hat-Security-Conference-2006_3A00_-.aspx</link><pubDate>Wed, 02 Aug 2006 14:38:00 GMT</pubDate><guid isPermaLink="false">af7480c4-26b7-468d-87b0-2acebabb473d:2876</guid><dc:creator>jcannon</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://port25.technet.com/rsscomments.aspx?PostID=2876</wfw:commentRss><comments>http://port25.technet.com/archive/2006/08/02/Black-Hat-Security-Conference-2006_3A00_-.aspx#comments</comments><description>&lt;p&gt;At this year&amp;#39;s &lt;a href="http://www.blackhat.com/main.html"&gt;Black Hat Security Conference&lt;/a&gt;,&amp;nbsp;several engineers on the Windows Networking &amp;amp; Security teams will be presenting &amp;lt;for the first time, ever&amp;gt;&amp;nbsp;on a number of technical topics, ranging from the new improvements made to the reliability &amp;amp; performance of the OS &lt;a href="http://www.blackhat.com/html/bh-usa-06/bh-usa-06-speakers.html#Marinescu"&gt;Heap Manager&lt;/a&gt;, to the &lt;a href="http://www.blackhat.com/html/bh-usa-06/bh-usa-06-speakers.html#Gbadegesin"&gt;NetIO stack&lt;/a&gt;&amp;mdash;a re-architected and re-written TCP/IP stack. Our discussion on this podcast has three distinguished engineers discussing their work with Sam, including:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;strong&gt;Noel Anderson&lt;/strong&gt; - Group Manager on the Windows Wireless Team (IP Stack for Bluetooth &amp;amp; Wi-Fi)&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Adrian Marinescu&lt;/strong&gt;&amp;nbsp;- former member of the Windows Kernel team, LPC, Object Manager &amp;amp; Heap Manager. This past year, Adrian has focused his work on Vista&amp;#39;s Heap Manager. &lt;/li&gt;&lt;li&gt;&lt;strong&gt;Aboldate Gbadegesin&lt;/strong&gt;&amp;nbsp;- Architect on Core Networking on Windows (TCP/IP &amp;amp; related protocols, tools &amp;amp; components)&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;We&amp;#39;ll cover their respective areas of work &amp;amp; discuss the topics being presented at Black Hat for those that cannot attend. &lt;/p&gt;&lt;p&gt;&lt;strong&gt;Related Links:&lt;/strong&gt;&lt;br /&gt;- &lt;a href="http://port25.technet.com/videos/podcasts/P25ShowSeven.mp3"&gt;Direct Link to MP3&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Podcast Related Links:&lt;br /&gt;&lt;/strong&gt;- &lt;a href="http://feeds.feedburner.com/Port25Podcast/"&gt;Subscribe in the Port 25 Podcast Feed&lt;/a&gt;&lt;br /&gt;- &lt;a href="http://phobos.apple.com/WebObjects/MZStore.woa/wa/viewPodcast?id=164687160"&gt;&lt;font color="#112e58"&gt;Subscribe to Port 25 Podcasts&amp;nbsp;in iTunes&lt;/font&gt;&lt;br /&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;img src="http://port25.technet.com/aggbug.aspx?PostID=2876" width="1" height="1"&gt;</description><enclosure url="http://port25.technet.com/videos/podcasts/P25ShowSeven.mp3" length="38531541" type="audio/mpeg" /><category domain="http://port25.technet.com/archive/tags/Media/default.aspx">Media</category><category domain="http://port25.technet.com/archive/tags/Industry+Conferences/default.aspx">Industry Conferences</category><category domain="http://port25.technet.com/archive/tags/Security/default.aspx">Security</category><category domain="http://port25.technet.com/archive/tags/Podcast/default.aspx">Podcast</category><category domain="http://port25.technet.com/archive/tags/Dev+Center/default.aspx">Dev Center</category><category domain="http://port25.technet.com/archive/tags/App/default.aspx">App</category></item><item><title>Do many eyes make a bug shallow? </title><link>http://port25.technet.com/archive/2006/06/30/Do-many-eyes-make-a-bug-shallow_3F00_-.aspx</link><pubDate>Fri, 30 Jun 2006 18:43:00 GMT</pubDate><guid isPermaLink="false">af7480c4-26b7-468d-87b0-2acebabb473d:2693</guid><dc:creator>jcannon</dc:creator><slash:comments>4</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://port25.technet.com/rsscomments.aspx?PostID=2693</wfw:commentRss><comments>http://port25.technet.com/archive/2006/06/30/Do-many-eyes-make-a-bug-shallow_3F00_-.aspx#comments</comments><description>&lt;p&gt;Sam interviews Mike Howard,&amp;nbsp;Senior Security PM at Microsoft around security in the operating system and how we think about &amp;amp; engineer security defenses into an operating system. What are the myths around security - do many eyes make a bug shallow? How do you protect and engineer against attack types that haven&amp;#39;t been invented yet?&lt;/p&gt;&lt;p&gt;&lt;center&gt;&lt;embed src="http://images.video.msn.com/flash/soapbox1_1.swf" quality="high" width="432" height="364" base="http://images.video.msn.com" type="application/x-shockwave-flash" allowFullScreen="true" pluginspage="http://macromedia.com/go/getflashplayer" flashvars="c=v&amp;v=fffee18d-4c7c-4f81-85d8-fb9dee9bb982&amp;ifs=true&amp;fr=msnvideo&amp;mkt=en-US&amp;brand="&gt;&lt;/embed&gt;&lt;br /&gt;&lt;a href="http://video.msn.com/video.aspx?vid=fffee18d-4c7c-4f81-85d8-fb9dee9bb982" target="_new" title="Do many eyes make a bug shallow?"&gt;Video: Do many eyes make a bug shallow?&lt;/a&gt;&lt;/center&gt;&lt;/p&gt;&lt;p&gt;Also worth checking out: Mike just published a book - &lt;a href="http://www.amazon.com/gp/product/0735622140/ref=ase_bookstorenow600-20/002-8411594-2144835?s=books&amp;amp;v=glance&amp;amp;n=283155&amp;amp;tagActionCode=bookstorenow600-20"&gt;Security Development Lifecycle &lt;/a&gt;- that explains what&amp;nbsp;the SDL looks like, how it is applied through the engineering process at Microsoft and how others can adopt &amp;amp; enhance their own development processes.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Related Links:&lt;/strong&gt;&lt;br /&gt;- Learn more at the upcoming &lt;a href="http://www.blackhat.com/html/bh-usa-06/bh-usa-06-schedule.html"&gt;Black Hat Conference &lt;/a&gt;on security processes - a couple folks will from MS will be presenting.&lt;br /&gt;- Check our &lt;a href="http://blogs.msdn.com/michael_howard/default.aspx"&gt;Mike&amp;#39;s security blog&lt;/a&gt;.&lt;br /&gt;- Check out the new &lt;a href="http://www.amazon.com/gp/product/0735622140/ref=ase_bookstorenow600-20/002-8411594-2144835?s=books&amp;amp;v=glance&amp;amp;n=283155&amp;amp;tagActionCode=bookstorenow600-20"&gt;Security Development Lifecycle &lt;/a&gt;book (Amazon)&lt;br /&gt;- &lt;a href="http://www.microsoft.com/technet/Security/default.mspx"&gt;TechNet Security Center&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Alternative Video Format:&lt;/strong&gt;&lt;br /&gt;- &lt;a href="http://port25.technet.com/videos/mhoward1.mp4"&gt;Download in MPEG4&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;img src="http://port25.technet.com/aggbug.aspx?PostID=2693" width="1" height="1"&gt;</description><category domain="http://port25.technet.com/archive/tags/Media/default.aspx">Media</category><category domain="http://port25.technet.com/archive/tags/Security/default.aspx">Security</category><category domain="http://port25.technet.com/archive/tags/Podcast/default.aspx">Podcast</category><category domain="http://port25.technet.com/archive/tags/Dev+Center/default.aspx">Dev Center</category><category domain="http://port25.technet.com/archive/tags/App/default.aspx">App</category><category domain="http://port25.technet.com/archive/tags/Video/default.aspx">Video</category></item></channel></rss>