Microsoft explains how the ANI bug got baked into Vista

In a postmortem of last month’s Windows animated (.ANI) cursor vulnerability, one of Microsoft’s security development gurus Friday spelled out how the bug sneaked into Vista. Michael Howard, an authority on Microsoft’s Security Development Lifecycle (SDL) — a multipart initiative that aims to get developers to design more secure code — posted an extensive entry on the brand-new SDL blog that outlined lessons learned from the ANI vulnerability. “SDL is not perfect, nor will it ever be perfect,” Howard acknowledged Thursday. “We still have work to do, and this bug shows that.”
Tag:aim, array, bill subject, caller id data, caller id spoofing, committee head, crack, crimes, financial fraud, harassment, lawmakers, presidents, senate floor, senate judiciary committee, spoof, violators voice vote

Read more…


Leave a Reply

You must be logged in to post a comment.