<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://port25.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Port 25: The Open Source Community at Microsoft : Security, Interop</title><link>http://port25.technet.com/archive/tags/Security/Interop/default.aspx</link><description>Tags: Security, Interop</description><dc:language>en</dc:language><generator>CommunityServer 2007.1 (Build: 40109.1145)</generator><item><title>Project Quant</title><link>http://port25.technet.com/archive/2009/04/15/project-quant.aspx</link><pubDate>Wed, 15 Apr 2009 22:54:00 GMT</pubDate><guid isPermaLink="false">af7480c4-26b7-468d-87b0-2acebabb473d:25303</guid><dc:creator>Peter Galli</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://port25.technet.com/rsscomments.aspx?PostID=25303</wfw:commentRss><comments>http://port25.technet.com/archive/2009/04/15/project-quant.aspx#comments</comments><description>&lt;P mce_keep="true"&gt;I noticed today that my colleague Jeff Jones in the security group is launching a metric project that appears to be leveraging some of the good bits of open techniques.&amp;nbsp; &lt;/P&gt;
&lt;P&gt;I touched base with him briefly and he gave me a little more information about &lt;A class="" href="http://securosis.com/projectquant" target=_blank mce_href="http://securosis.com/projectquant"&gt;Project Quant&lt;/A&gt;, which is being undertaken along with &lt;A class="" href="http://securosis.com/" target=_blank mce_href="http://securosis.com/"&gt;Securosis&lt;/A&gt;, an independent security research firm.&lt;/P&gt;
&lt;P&gt;Project Quant will be working on the metrics of patch management and is as much an experiment of a new research process as it is one of security metrics, said Securosis founder Rich Mogull in a &lt;A class="" href="http://securosis.com/projectquant" target=_blank mce_href="http://securosis.com/projectquant"&gt;blog post&lt;/A&gt;.&lt;/P&gt;
&lt;P mce_keep="true"&gt;"For this project Jeff wanted to be involved, but also asked for an open, unbiased model that will be useful to community-at-large (in other words, he didn't ask for a sales tool). Rather than us developing something back at the metrics lab, Jeff asked us to lead an open community project with as much involvement from the different corners of the industry as possible," Mogull said.&lt;/P&gt;
&lt;P mce_keep="true"&gt;While he also acknowledged that it is risky for Securosis&amp;nbsp;to allow direct involvement of the sponsor, the company is hoping that the process works the way it thinks it will and which also happens to match Microsoft's project goals.&lt;/P&gt;
&lt;P&gt;So, this is what's expected to happen: a project landing site has been set up at Securosis that will contain all material and research as it is developed; every piece of research will be posted for public comment and no comments will be filtered unless they are spam, totally off topic, or personal insults. &lt;/P&gt;
&lt;P mce_keep="true"&gt;All significant contributors will also be acknowledged in the final report, although there will be no financial compensation for contributors and the project itself will retain ownership rights. All material will also be released under a &lt;A class="" href="http://port25.technet.com/archive/2009/03/11/microsoft-makes-more-source-code-available.aspx" target=_blank mce_href="http://port25.technet.com/archive/2009/03/11/microsoft-makes-more-source-code-available.aspx"&gt;Creative Commons&lt;/A&gt; license, with spreadsheets released in both Excel and open formats. &lt;/P&gt;
&lt;P mce_keep="true"&gt;"In short, we are developing all research out in the open, soliciting community involvement at every stage, making all the materials public, acknowledging contributors, and eventually releasing the final results for free and public use. The end goal of the project is to deliver a metrics model for patch management response to help organizations assess their costs, optimize their process, and achieve their business goals. Let us know what you think, even if you think we're just full of it," Mogull said. &lt;/P&gt;
&lt;P mce_keep="true"&gt;For his part, Jones told me that while he has been zealous in past reports about using repeatable methodologies, pointing to his source of public data, and outlining his assumptions step-by-step, he would like to take transparency one step further by developing models and methodologies first, in an open and transparent manner, so that everyone can agree on the pros and cons before the methodologies are applied.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;"I think being completely open and transparent will help credibility since, similar to open source, everyone can scrutinize every step of the analysis ... creating open models and potentially getting community involvement just seems to be the right process," he says.&lt;/P&gt;
&lt;P&gt;I plan to interview him at greater length in the next few weeks, so look for a follow-up blog then.&lt;/P&gt;&lt;img src="http://port25.technet.com/aggbug.aspx?PostID=25303" width="1" height="1"&gt;</description><category domain="http://port25.technet.com/archive/tags/Partnerships/default.aspx">Partnerships</category><category domain="http://port25.technet.com/archive/tags/Interop/default.aspx">Interop</category><category domain="http://port25.technet.com/archive/tags/Security/default.aspx">Security</category><category domain="http://port25.technet.com/archive/tags/Management/default.aspx">Management</category><category domain="http://port25.technet.com/archive/tags/Community/default.aspx">Community</category><category domain="http://port25.technet.com/archive/tags/_7E00_FeaturedPost/default.aspx">~FeaturedPost</category></item><item><title>Web Sandbox Source Now Available Under Apache License 2.0</title><link>http://port25.technet.com/archive/2009/01/26/web-sandbox-source-now-available-under-apache-license-2-0.aspx</link><pubDate>Tue, 27 Jan 2009 02:48:00 GMT</pubDate><guid isPermaLink="false">af7480c4-26b7-468d-87b0-2acebabb473d:23512</guid><dc:creator>Peter Galli</dc:creator><slash:comments>5</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://port25.technet.com/rsscomments.aspx?PostID=23512</wfw:commentRss><comments>http://port25.technet.com/archive/2009/01/26/web-sandbox-source-now-available-under-apache-license-2-0.aspx#comments</comments><description>&lt;P mce_keep="true"&gt;Microsoft has released more source code under an OSI-approved license: this time it has made the source code for the &lt;A href="http://websandbox.livelabs.com/"&gt;Web Sandbox&lt;/A&gt; runtime available&amp;nbsp;under the &lt;A href="http://www.apache.org/licenses/LICENSE-2.0"&gt;Apache 2.0&lt;/A&gt; &amp;nbsp;open source license.&lt;/P&gt;
&lt;P mce_keep="true"&gt;The Web Sandbox project explores how to advance the web platform to improve security, isolation, quality of service and extensibility capabilities&amp;nbsp;for web developers and website users.&lt;/P&gt;
&lt;P&gt;More information on the licensing details, as well as comprehensive documentation for experimenting and integrating with the Web Sandbox, can be found &lt;A class="" href="http://websandbox.livelabs.com/" target=_blank mce_href="http://websandbox.livelabs.com/"&gt;here&lt;/A&gt;. &amp;nbsp;&lt;/P&gt;
&lt;P&gt;But, while developers are being encouraged to help define and refine the Web Sandbox, it is not recommended for those developers creating production sites as it is still under development.&lt;/P&gt;
&lt;P&gt;The Web Sandbox was created in response to limitations found in the current web platform, and is designed to explore &lt;A class="" href="http://websandbox.livelabs.com/documentation/overview_how.aspx" target=_blank mce_href="http://websandbox.livelabs.com/documentation/overview_how.aspx"&gt;potential solutions&lt;/A&gt;. Having a more secure and robust architecture as a foundational building block will help drive the next wave of Web innovation.&lt;/P&gt;
&lt;P&gt;The Sandbox is a framework that works on most modern browsers that support the&lt;A class="" href="http://www.ecma-international.org/publications/standards/Ecma-262.htm" target=_blank mce_href="http://www.ecma-international.org/publications/standards/Ecma-262.htm"&gt;"ECMA-262, 3&lt;SUP&gt;rd&lt;/SUP&gt; Edition"&lt;/A&gt; (JavaScript) standard, and provides the same features in all modern web browsers. &amp;nbsp;No browser add-ons or changes are required to leverage this technology. Beyond security, the Web Sandbox normalizes the different browsers and provides consistent &lt;A class="" href="http://www.w3.org/DOM/" target=_blank mce_href="http://www.w3.org/DOM/"&gt;W3C DOM&lt;/A&gt; support.&lt;/P&gt;
&lt;P&gt;Since the initial release of Web Sandbox at PDC 2008, the team has received a lot of useful feedback from the web security community, and has also been collaborating with a number of customers, partners and the standards communities, all of whom want to adopt the &amp;nbsp;technology when it is ready.&amp;nbsp; &lt;S&gt;&lt;/S&gt;&lt;/P&gt;
&lt;P&gt;The goal? An open and interoperable standard that will help foster interoperability with complementary technologies like script frameworks and drive widespread adoption of the Web Sandbox.&lt;/P&gt;
&lt;P&gt;This move is good news for Microsoft and the open source communities. But, it is important to note that while an Apache license is being used, the Web Sandbox project is not an Apache Software Foundation project and is not sponsored or endorsed by the ASF.&lt;/P&gt;
&lt;P&gt;Microsoft does, however, already have an active relationship with the ASF. In fact, last year the company announced it had become a &lt;A class="" href="http://port25.technet.com/archive/2008/07/25/oscon2008.aspx" target=_blank mce_href="http://port25.technet.com/archive/2008/07/25/oscon2008.aspx"&gt;sponsor of the ASF&lt;/A&gt;&amp;nbsp;so as to help enable the Foundation pay administrators and other support staff so that its developers can focus on writing great software.&lt;/P&gt;
&lt;P&gt;Sam Ramji, the senior Director of Platform Strategy at Microsoft, also delivered a &lt;A class="" href="http://port25.technet.com/archive/2008/11/06/apachecon-keynote.aspx" target=_blank mce_href="http://port25.technet.com/archive/2008/11/06/apachecon-keynote.aspx"&gt;keynote address at ApacheCon&lt;/A&gt; in New Orleans last November.&lt;/P&gt;
&lt;P&gt;Microsoft's Interoperability Technical Strategy Team already participates as a code contributor to the &lt;A class="" href="http://port25.technet.com/archive/2009/01/19/update-stonehenge-incubation-project.aspx" target=_blank mce_href="http://port25.technet.com/archive/2009/01/19/update-stonehenge-incubation-project.aspx"&gt;Apache Stonehenge incubator project&lt;/A&gt;; the company has also contributed&amp;nbsp;a patch to &lt;A href="http://adodb.sourceforge.net/" mce_href="http://adodb.sourceforge.net/"&gt;ADOdb&lt;/A&gt;, a popular data access layer for PHP used by many applications and which is licensed under the LGPL and BSD; while Microsoft's &lt;A class="" href="http://port25.technet.com/archive/2008/10/14/microsoft-s-powerset-team-resumes-hbase-contributions.aspx" target=_blank mce_href="http://port25.technet.com/archive/2008/10/14/microsoft-s-powerset-team-resumes-hbase-contributions.aspx"&gt;Powerset team&lt;/A&gt;&amp;nbsp;contributes&amp;nbsp;to &lt;A href="http://hadoop.apache.org/hbase/" mce_href="http://hadoop.apache.org/hbase/"&gt;HBase&lt;/A&gt;, an open-source, column-oriented, distributed database written in Java.&lt;/P&gt;&lt;img src="http://port25.technet.com/aggbug.aspx?PostID=23512" width="1" height="1"&gt;</description><category domain="http://port25.technet.com/archive/tags/Interop/default.aspx">Interop</category><category domain="http://port25.technet.com/archive/tags/Security/default.aspx">Security</category><category domain="http://port25.technet.com/archive/tags/Standards/default.aspx">Standards</category><category domain="http://port25.technet.com/archive/tags/Java/default.aspx">Java</category><category domain="http://port25.technet.com/archive/tags/Community/default.aspx">Community</category><category domain="http://port25.technet.com/archive/tags/Open+Source/default.aspx">Open Source</category><category domain="http://port25.technet.com/archive/tags/Dev+Center/default.aspx">Dev Center</category><category domain="http://port25.technet.com/archive/tags/Web/default.aspx">Web</category><category domain="http://port25.technet.com/archive/tags/_7E00_FeaturedPost/default.aspx">~FeaturedPost</category><category domain="http://port25.technet.com/archive/tags/Peter+Galli/default.aspx">Peter Galli</category></item><item><title>Technical Analysis: OpenSSH on Linux using Windows/Kerberos for Authentication</title><link>http://port25.technet.com/archive/2008/06/06/technical-analysis-openssh-on-linux-using-windows-kerberos-for-authentication.aspx</link><pubDate>Fri, 06 Jun 2008 14:35:00 GMT</pubDate><guid isPermaLink="false">af7480c4-26b7-468d-87b0-2acebabb473d:19278</guid><dc:creator>jcannon</dc:creator><slash:comments>1</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://port25.technet.com/rsscomments.aspx?PostID=19278</wfw:commentRss><comments>http://port25.technet.com/archive/2008/06/06/technical-analysis-openssh-on-linux-using-windows-kerberos-for-authentication.aspx#comments</comments><description>&lt;P mce_keep="true"&gt;&lt;STRONG&gt;Abstract:&lt;/STRONG&gt; Secure remote access to UNIX and Linux systems is generally accomplished through SSH. The most frequent implementation of that protocol is OpenSSH, originally written for the OpenBSD project but now ported to a wide variety of platforms. This paper will show how to use OpenSSH with the Kerberos portion of Active Directory to automate authentication.&lt;/P&gt;
&lt;P mce_keep="true"&gt;Download &lt;A class="" href="http://port25.technet.com/Videos/research/OpenSSH%20on%20Linux%20using%20Windows.pdf" mce_href="http://port25.technet.com/Videos/research/OpenSSH%20on%20Linux%20using%20Windows.pdf"&gt;OpenSSH on Linux using Windows/Kerberos for Authentication&lt;/A&gt;&lt;/P&gt;
&lt;P mce_keep="true"&gt;&lt;STRONG&gt;Note: &lt;/STRONG&gt;This paper represents testing and documentation in a lab environment. User Account Control (UAC) is an essential security component to Windows and Microsoft does not recommend turning off UAC in production environments.&lt;/P&gt;&lt;img src="http://port25.technet.com/aggbug.aspx?PostID=19278" width="1" height="1"&gt;</description><enclosure url="http://port25.technet.com/Videos/research/OpenSSH%20on%20Linux%20using%20Windows.pdf" length="141231" type="application/pdf" /><category domain="http://port25.technet.com/archive/tags/Active+Directory/default.aspx">Active Directory</category><category domain="http://port25.technet.com/archive/tags/Interop/default.aspx">Interop</category><category domain="http://port25.technet.com/archive/tags/Security/default.aspx">Security</category><category domain="http://port25.technet.com/archive/tags/Windows+Server/default.aspx">Windows Server</category><category domain="http://port25.technet.com/archive/tags/Linux/default.aspx">Linux</category><category domain="http://port25.technet.com/archive/tags/Open+Source/default.aspx">Open Source</category><category domain="http://port25.technet.com/archive/tags/Server+Center/default.aspx">Server Center</category><category domain="http://port25.technet.com/archive/tags/jcannon/default.aspx">jcannon</category><category domain="http://port25.technet.com/archive/tags/_7E00_FeaturedPost/default.aspx">~FeaturedPost</category></item></channel></rss>