Sad Tux - Windows bias detected
This page contains Windows bias

About This Page

This page is part of the Azure documentation. It contains code examples and configuration instructions for working with Azure services.

Bias Analysis

Detected Bias Types
windows_first
powershell_heavy
windows_tools
missing_linux_example
Summary
The documentation for input validation in the Microsoft Threat Modeling Tool is heavily focused on Windows-centric technologies and .NET Framework, with nearly all code examples in C# and references to IIS, MSXML, web.config, and Windows-specific APIs. There are no Linux or cross-platform equivalents provided for key mitigations such as HTTP header configuration, XML parsing, file upload validation, or web server configuration. Where browser-specific mitigations are discussed, Internet Explorer is referenced first and exclusively. The documentation assumes use of Windows hosting environments and tools, leaving Linux/macOS developers without guidance for equivalent implementations.
Recommendations
  • Provide code examples in cross-platform languages (e.g., Python, Java, Node.js) for input validation, XML parsing, and file upload validation.
  • Include instructions for setting HTTP headers (like X-Content-Type-Options) in popular Linux web servers (e.g., Apache, Nginx) and frameworks.
  • Reference Linux/macOS XML libraries (e.g., lxml, xml.etree.ElementTree, libxml2) and show how to disable entity resolution and DTD processing.
  • Offer guidance for file upload validation using Linux file system conventions and antivirus tools.
  • When discussing browser mitigations, mention Chrome, Firefox, and Safari implementations and syntax where relevant.
  • Add parity for configuration steps in Linux environments (e.g., using environment variables, config files, or server directives).
GitHub Create Pull Request

Scan History

Date Scan Status Result
2026-01-14 00:00 #250 in_progress Biased Biased
2026-01-13 00:00 #246 completed Biased Biased
2026-01-11 00:00 #240 completed Biased Biased
2026-01-10 00:00 #237 completed Biased Biased
2026-01-09 00:34 #234 completed Biased Biased
2026-01-08 00:53 #231 completed Biased Biased
2026-01-06 18:15 #225 cancelled Clean Clean
2025-08-17 00:01 #83 cancelled Clean Clean
2025-07-13 21:37 #48 completed Biased Biased
2025-07-12 23:44 #41 cancelled Biased Biased

Flagged Code Snippets