SHARE
Follow this article on Twitter Facebook LinkedIn Bookmark and Share
Home >> Security >> Security Products, Practices and Infrastructure

Xbox Live exec leans on his security background

Xbox Live exec leans on his security background

By:  Rafael Ruffolo  On: 07 Oct 2008 For: ComputerWorld Canada Creator

A Microsoft executive tells the SecTor 2008 crowd how to get every business unit thinking about protecting data without shelling out big bucks on new training and services

TORONTO -- Encouraging security professionals to branch out and spread their knowledge to other business groups will increase an enterprise’s overall security without increasing the budget, according to a former program manager with Microsoft’s Security Response Center.

In a keynote address at Wednesday’s Security Conference Toronto (SecTor), Stephen Toulouse – who now works as a lead program manager for policy and enforcement at Xbox Live – credited his background in security as the primary factor to his success as a well-rounded IT professional. At Xbox Live, Toulouse and his team help ensure that customer data is protected and that the online gaming service’s privacy policy is properly enforced. Although security no longer has a direct impact on his day-to-day work anymore, he said that many of his security skills have been completely transferable to his new role.

One of the greatest skills a security researcher can bring to the table, he said, is their ability to understand the potential misuses in functionality in a new tool. “The first thing a security persona asks is ‘what’s the worse thing a person could do with this new functionality to hurt the customer,” he added.

Along with that, Toulouse said, security pros are also conditioned to think about the unintended consequences of this user functionality. When preparing to rollout a new Xbox Live feature called “friends of friends – which enabled users to view their friend’s contact lists – the development team almost failed to create an opt-out feature for users who didn’t want the added functionality.

“We started to realize that some parents would want to have their children’s friend’s list restricted from this feature,” he said. “And what if you’re friend’s with a celebrity who doesn’t want their profile to be exposed?”

The bottom line for Toulouse is that security pros often put a greater focus on the customers and always thinking about the best way to implement features or business practices that keep the end-users in mind.

“Sometimes it will lead you to actions that other people in your business see as counter intuitive,” he added. When working on the security designs for Windows Vista, Toulouse recalled, many features were killed off after rigorous penetration testing and security reviews.

“It takes a strong customer focus to look at all your hard work, time and money and simply scrap something,” he said.

But while this might work in theory, getting others to listen and trust you might be another story. Christopher Hoff, chief security architect with Unisys Corp., advised security people to be farmers, rather than lumberjacks.

“Act as an advisor rather than a dictator,” he said. Offering up suggestions and insights to your colleagues and letting them decide is often the best way to get people to trust you, Hoff added.

Toulouse agreed, saying that working with other business units is often a two way street.


Sign up for our Newsletters












Print |  Views: 1448   |   Rating:offoffoffoffoff  (0 votes)
Rate this article on a scale of
1 to 5 stars,5 being the best.




Rafael Ruffolo Rafael Ruffolo was a senior writer for ComputerWorld Canada from 2006 to 2011. He was the winner of a Kenneth R. Wilson award for business journalism in 2009.

Related Content

Half of UK financial firms not ready for compliance
Half of UK financial firms not ready for complianceMore than half (51 per cent) of all U.K. firms have not implemented the security processes to comply with legislative directives such as PCI and MiFID, says a report.
It's time for a new password
It's time for a new passwordUsers hate passwords. They don't like entering them to gain access to a system; they don't like inventing new ones every 30 or 60 or 90 days; and they really don't like having different passwords for different systems. The more active and mobile the user, the more often they must enter passwords, and so their resentment grows.
Is IT to blame for security woes?
Is IT to blame for security woes? IT professionals polled in a recent survey had an "unflattering" view of if their colleagues or managers. IT leaders don't much care about the end-user shenanigans, those polled claimed.
The trouble with InfoSecurity 2008 (and events like it)
can you imagine having a conference intended to represent the canadian it security landscape and not have symantec among the exhibitors? what about microsoft? if you’re attending infosecurity canada 2008, don’t bother looking for bell canada or rsa, either.

Comments (0)

No Comments!
Name: (required) eMail: (optional)

Your email address will not appear online and will be used only if the editor wishes to contact you personally for additional comments.