Every year at this time, we bring you our now-famous security issue. We recognize the vast importance of writing and deploying secure code—it affects so many areas of concern—which is why we devote an entire issue each year to the topic. This 2005 security issue marks the fourth year that we have gathered the most relevant coverage of current best security practices for programmers who want to keep their code safe.
Of course, we don't save up all this security information for a single month's issue. That wouldn't be fair. All throughout the year, every year, we publish articles and columns on security to make sure that you have the best information possible to make your code more impervious to attack and your systems safer from hackers, accidents, and all sorts of harm. In fact, security is such a big deal to us that we've gone beyond mere print and produced a special companion security CD. In it we've gathered the best, most relevant security coverage we've published over the past five years of MSDN Magazine (see our Web site for more info).
We've covered quite a lot of ground on the topic of security, but it's never too much. It's important to remember how broad a topic this really is. The stuff that most programmers hear about—firewalls, virus checkers, and sneaky Web attacks—is really only scratching the surface. We know you also worry about the next level down: how do you fortify your code to minimize the possibility that a malicious attacker will use your program as the springboard into your machine, your network, or your company's confidential data?
This month's articles will put you on the right path in that respect. We present tips on code access security in the .NET Framework 2.0. We discuss best practices that should be followed when building secure Web applications with ASP.NET 2.0 and IIS, and we look at how the provider model and new Membership API can be used to port your existing authentication code to ASP.NET 2.0. We show you the latest sandboxing techniques to help you improve security when hosting untrusted add-ins. And we make many other useful security suggestions that you'll want to read now and refer to later as well.
Security is not just a matter of making code safer either; the physical security of your data is equally important. As a programmer, do you have backups of your code in an alternate location? If you're a photographer, do you have all your best images stored on a second machine far away from your home? Of course, as you know, all the programming tips in the world won't protect your assets if you're not prepared for the worst possible occurrences, but following some of the best security practices in your own environment is a good way to start.
On that note, it goes without saying that we are all saddened by the destruction and devastation caused by Hurricane Katrina. Our hearts go out to the thousands who have suffered, and our gratitude to the thousands who gave up their personal comfort and safety to offer their help. We all have friends, family, or acquaintances who were affected by this tragedy. Although we may not know you all personally, we have many readers in the Gulf Coast region, some of whom surely have suffered great losses. We will keep you all in our thoughts.
Many inspiring stories of help and heroism have followed this disaster. We send out our thanks to people like John Morello (who writes for our sister publication, TechNet Magazine) who went to New Orleans to help set up basic IT services and networks at shelters throughout the area. A small comfort maybe, but these services enabled people who were unable to get back to their homes to begin to initiate contact with their missing friends and relatives. It never ceases to amaze us how generous people can be at times like this. Thanks, and take care.
Thanks to the following Microsoft technical experts for their help with this issue: Kawarjit Bedi, Eric Bidstrup, Arjun Bijanki, Eugene Bobukh, Brandon Bray, Simon Calvert, Lakshan Fernando, Mark Fussell, Matthew Gibbs, Jim Hogg, Tomasz Janczuk, Charlie Kaufman, Ronald Laeremans, Martyn Lovell, Ulzii Luvsanbat, Shahrokh Mortazavi, Matt Powell, Stefan Schackow, Sidd Shenoy, Payam Shodjai, Richard Turner, Scott Woodgate, and Ting-Hao Yang.