Profiel van NathanNathan's Daily GrindFoto'sWeblogLijsten Extra Help
    03 december

    Security response, a blogger's tale

    I happened to stumble across a little oddity today with the MSN Spaces site that raised some alarm bells in my mind.  In fact, it was one of those "holy crap - what do I do now" moments.  My immediate thought was that the MSN Spaces team needed to know about this PDQ, and I for SURE wasn't going to post my suspicions about a hole on one of their blogs for all to see [which is why I'm not giving details here either].

    So how do I get in touch with the team in a private way when I don't know their email addresses?  Answer: Scobleizer.  Robert Scoble (MS blogger and Channel 9 host/ interviewer/ camera man) as made it a point to put his cell number on his blog's homepage, something I always thought was dumb but he defends; and claims it's not abused.  He completely proved his point today ... I called him and laid out my concerns.  He immediately offered to relay the message on to Mike Torres on the Spaces team were I to send RS a summary of what I had found.  He also said to give Mike a call (gave me a number to find him at) and suggested the secure@microsoft.com email address for vulnerability submissions.  I left Mike a message and fired off an email with a screen shot of what I had found to Robert and the Secure alias.

    20 minutes later I had an email from Robert letting me know he got the note and copying Mike and MC.  A little over an hour after my initial calls and email I got a tracking number from the Secure team.  5 minutes later I got an actual reply from the Spaces guys saying they were aware of the problem, and detailed that it wasn't really as bad as it looked (which it's not).  We've had some more email threads throughout the day keeping me posted as to their progress on the issue, etc.  4+ hours later I haven't heard anything back yet from the Secure team.

    Now I'm not going to say the Secure team is slow ... from what I've seen of them they're very thorough and respond personally to each issue (there was a Channel 9 series on this team a while back - but I'm not going to find it right now).  But this is another great point of what a blog can do for your company - CUSTOMER SERVICE! 

    Blogging is not just about marketing and getting your message across, it creates a community of people who are passionate (one way or the other) about your product.  It allows customers to feel like that have an "inside source" with your organization that they know and are familiar with ... even though they've never actually met them, emailed, or spoken on the phone.  And you give your product team, who in the IT space is usually holed up in cubeland isolated from the customers, an outlet to reach out and communicate with the people they're really working for.  Bring these two together and the synergy is amazing - a "closed" issue before the tradition mechanisms of handling the problem have really begun to churn.

    More and more every day I'm getting hooked by this blogging thing; it really is the next "killer app" on the net.  Now we just have to find a way to squeeze 36 hours into a day so we have plenty of time to read all those feeds!

     

    Special thanks to Robert Scoble, Mike Torres and Michael Connolly.

    (6) reacties

    Een ogenblik geduld...
    De reactie die je hebt ingevoerd is te lang. Maak hem iets korter.
    Je hebt niets ingevoerd. Probeer het opnieuw.
    We kunnen je reactie nu niet toevoegen. Probeer het later opnieuw.
    Je hebt toestemming van je ouders nodig om een reactie toe te voegen Toestemming vragen
    Je kunt geen reacties geven omdat je ouders dit hebben uitgeschakeld.
    We kunnen je reactie nu niet verwijderen. Probeer het later opnieuw.
    Je hebt het maximale aantal reacties overschreden dat je elke dag kunt versturen. Probeer het over 24 uur nog eens.
    De mogelijkheid om reacties te geven is uitgeschakeld voor je account omdat onze systemen aangeven dat je spam naar andere gebruikers verzendt. Als je van mening bent dat je account ten onrechte is uitgeschakeld, kun je contact opnemen met de klantondersteuning van Windows Live.
    Voer de beveiligingscontrole hieronder uit om een reactie achter te laten.
    De tekens die je typt moeten overeenkomen met die in de afbeelding of het audiofragment.

    Meld je aan bij Windows Live ID om een reactie toe te voegen (als je Hotmail, Messenger of Xbox LIVE gebruikt, heb je al een Windows Live ID). Aanmelden


    Heb je geen Windows Live ID? Maak er nu een aan

    12 Nov.
    Afbeelding van Anoniem
    tmarshbu zegt:
    It turns out I can't. I had not tried to alter anyone's blog, but after making changes and attemptiong a deletion, they seem to not go all the way through and instead generate a basic "space/site not available" error message. Thanks for the clarification...I was a little worried. The result was much like you and Mike had mentioned, there was just not any detail to know if that was the issue you were discussing. Thanks

    Todd
    15 Dec.
    Afbeelding van Anoniem
    NathanNovak zegt:
    Todd - B I N G O
    Supposedly while you can get into the other Space and edit things you can't actually save those changes. Have you been able to actually save a change?
    14 Dec.
    Afbeelding van Anoniem
    tmarshbu zegt:
    Nathan, was this around the statistics issue? I thought I noticed something that was a little disconcerning, but haven't heard back from MSN Tech Support. I seem to be able to link right into a visitors Blog page and make edits to their blog. I was gong to try and ping Mike Torres as well to get feedback if this is the same issue.

    Todd
    14 Dec.
    Afbeelding van Anoniem
    WeyerMatthew_MVP zegt:
    Ugh, I knew I was forgetting something.

    I did a quick search <http://beta.search.msn.com/results.aspx?q=channel9.msdn.com+secure@microsoft.com+secure+team&FORM=QBHP> and believe I found the Channel9 stuff you were talking about <http://channel9.msdn.com/ShowPost.aspx?PostID=19449>.

    @Matthew
    4 Dec.
    Afbeelding van Anoniem
    WeyerMatthew_MVP zegt:
    Hey Nathan,

    I'm glad the issue didn't become a big deal, but it's great that end users are developing a connection to devs in this way. Your words about blogging are terrific and really hit the mark.

    @Matthew
    4 Dec.
    *