Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Is your home router leaving your network vulnerable to attack? New research suggests that this worrisome scenario is more likely than you may have thought. A Fraunhofer Institute for Communication (FKIE) report reveals that the firmware used in a large number of popular home routers is susceptible to malware and other serious exploits in cybersecurity. . We explored the importance of prioritizing data and network security in a recent LinuxSecurity.com feature article: Top Tips for Securing Your Linux System in 2020 and thought it was important to dive deeper into the topic given these critical new findings. In this article, we will review a recent study, popular flaws in router systems, and how to mitigate such network security threats prior to any breach. Study Regarding Router Security Vulnerabilities After examining 127 home routers from seven leading brands (Netgear, Linksys, D-Link, ASUS, AVM, TP-Link, and Zyxel), FKIE security researchers discovered that, on average, these routers contained 53 critical cyber security vulnerabilities, and none of the routers were fully protected. Many of these routers never received a firmware update, making them susceptible to various network security issues. To make matters worse, certain vendors have been shipping firmware updates without fixing known security bugs. Fifty of the routers examined in the study used hard-coded credentials, where known credentials were encoded into the router by default, emitting at least five keys per firmware image. FKIE took these observations into account when stating, “The updated policy of router vendors is far behind the standards as we know it from desktop or server operating systems. However, routers are exposed to the Internet 24 hours a day, leading to an even higher risk of malware infection.” The organization emphasizes the need for industry-wide improvements in router data and network security. Ninety percent of the routers involved in FKIE’s recent study were powered by Linux. If router manufacturerswere staying on top of software updates and applying the latest security patching and fixes, this could become a huge victory in the security realm. Unfortunately, the researchers found that the majority of manufacturers were falling down on the job, leaving the devices they sold vulnerable to a multitude of exploits in cyber security. Because of the transparency of its source code, Linux has the potential to be a highly secure OS, more so than proprietary alternatives like Windows or MacOS; however, misconfigurations and poor administration often leave cyber security vulnerabilities within Linux systems likely to face an attack. In this case, Linux and the attentive, conscientious global community behind it have made the job of router vendors much easier. Johannes vom Dorp, a member of FKIE's Cyber Analysis & Defense department, explains: "Linux works continuously to close security vulnerabilities in its operating system and to develop new functionalities. Really, all the manufacturers would have to do is install the latest software, but they do not integrate it to the extent that they could and should." Vom Dorp elaborates on this widespread negligence: “Most of the devices are powered by Linux, and security patches for the Linux kernel and other open-source software are released several times a year. This means the vendors could distribute security patches to their devices far more often, but they do not." FKIE’s research proves there are various network security issues at risk due to poorly configured router security. The widespread cyber security vulnerabilities present in home routers are leaving systems worldwide susceptible to compromise. Therefore, companies must work to be more aware of the threats they face and how to take care of them to ensure data and network security. Key Router Attack Vectors There are many methods that cybercriminals will utilize in order to instigate an attack on your business. Here are some of the more frequent and common cyber security vulnerabilities thatthreat actors exploit in the process of a router security issue: Firmware weaknesses : When preparing a device for release, a company may not perform sufficient testing to make sure no security patching is needed to protect the software from any risks. This could be the result of human error, and threat actors will take advantage of such oversights to break into a system. Credential hacking : If your business is managing more than one account but still using the same login information among all of the platforms, whether they are default or easy-to-remember passwords, hackers can initiate brute-force attacks in order to access the router and its configurations. Device misconfigurations : Your company should try to avoid utilizing the automatic router configurations and features, as those tend to make it easier for malicious actors to breach and reach secure information. This can sometimes be the fault of the router manufacturer, who leaves the end user in charge of setting up the security system. Outdated technology : Certain firmware may not be updated automatically, resulting in old libraries, weak security checks, and other faulty architectural features. Hackers can abuse such issues in order to break into a system. Your company may ignore these cyber security vulnerabilities because of the price you must pay for upgrades, but it is worth it in the long run to keep your business safe. Insider threats : Users within a company who have access to privileged information could weaken the security of the router and the business overall should they abuse their reach. If such employees have malicious intent, a company can face significant risk just by providing the worker access in the first place, leaving the system susceptible to all kinds of cybersecurity vulnerabilities. How Can I Improve Router Security? When it comes to remedying this industry-wide fiasco, the majority of the responsibility lies in the hands of router manufacturers and vendors. Here are some tips andrecommendations for users looking to improve the security posture of their home router in the process of dealing with this rising network security threat: Update firmware frequently: Staying on top of firmware updates is crucial in preventing attacks that exploit firmware cyber security vulnerabilities that could compromise your system and company overall. Change router passwords: A known password comes encoded into your router by default. Replacing this password is imperative in protecting your privacy and maintaining a secure system. Do your research before purchasing a router: While none of the routers that FKIE studied were without flaws, some brands fared far better than others in terms of security. FKIE concludes: “AVM does a better job than the other vendors regarding most aspects. ASUS and Netgear do better in some aspects than D-Link, Linksys, TP-Link, and Zyxel.” Replacing the Linux firmware in your home router is also an excellent option for mitigating the risk that network security issues in your router pose to your entire system. Final Thoughts on Protecting Your Linux System Awareness of the risks you face with unsafe routers is the first step in protecting your company's security. As we have seen, there are various real-life examples of businesses facing severe network security threats and issues due to flawed router configurations. All companies should be aware of any cyber security vulnerabilities they face within their day-to-day operations so that they can do what is needed to reinstate proper safety measures and improve security posture. . An analysis uncovers vulnerabilities in home router software that could jeopardize your online safety. Discover how to safeguard your equipment.. Router Security, Firmware Update, Home Network, Cyber Threats. . Brittany Day
Sending sensitive data through email has become a frequent practice among online workers. However, not all sources you send can be trusted entirely, as someone could be hacked or want to use your information for malicious intent. GnuPG , an easy-to-use encryption service, can help you ensure data and network security so only those who need access can see the information being sent. . GnuPG, or the GNU Privacy Guard, is a free drop-in replacement for PGP, Pretty Good Privacy. PGP is a standard file encryption and security service that utilizes public key cryptography cyber security to protect the communication between two parties. GnuPG implements the OpenPGP standard as outlined in RFC 2440. Pine is a popular mail and news client that can prioritize using GnuPG to improve security posture within a company. This article will discuss how GnuPG and Pine can work as a secure email system, ensuring data and network security. As we continue the article, GnuPG and Pine will be discussed, assuming both are installed on your device. If not, consider downloading them to follow along as you read. If you use an RPM-based system, the EnGarde 1.0.1 system already includes “pinegpgp.” To install it, implement "rpm -Uvh ." Throughout this article, all key examples are fictitious, nonexistent, and invalid. The pinepgpg examples use a valid code (0xD3292967), which can be found on the keyservers. What is GnuPG Encryption? How Is It Different from PGP? GnuPG encryption is a free network security toolkit that can be implemented quickly for beginning email security clients. This software encrypts messages and files sent between two parties, which involves scrambling the data to prevent outsiders from accessing what is written. Regarding differences, GnuPG is open-source material available to the public, while PGP is not. Though developed over twenty years ago, GnuPG is still a very helpful and secure software company that can rely on to guarantee data and network security. Can I Use GnuPG on a Remote System? Avoid doing this at all costs, as you will never have physical control over a secret key ring. Local computers should be utilized in all steps of the encryption process to avoid opportunities for cybersecurity vulnerabilities to be exploited. If you use a connected server, have a strong password that will protect your key, and make sure to have a trusted system administrator. If you must use a remote system, consider generating the keypair on a desktop and copying the keyring to the machine to ensure protection and safety. How Can I Encrypt and Sign Messages with GnuPG Commands? Here are the steps you need to take to generate keys to join everyone else with these cyber security trends that will promise your company protection. You will first need to execute the command “gpg” to set up your ~/.gnupg directory: [ryan@mastermind ryan]$ gpg gpg: Warning: using insecure memory! gpg: /home/ryan/.gnupg: directory created gpg: /home/ryan/.gnupg/options: new options file created gpg: you have to start GnuPG again so that it can read the new options file You are now set up for key generation. Start with the command “gpg --gen-key” [ryan@mastermind ryan]$ gpg --gen-key gpg (GnuPG) 1.0.4; Copyright (C) 2000 Free Software Foundation, Inc. This program comes with ABSOLUTELY NO WARRANTY. This is free software, and you can redistribute it under certain conditions. See the file COPYING for details. gpg: Warning: using insecure memory! gpg: /home/ryan/.gnupg/secring.gpg: keyring created gpg: /home/ryan/.gnupg/pubring.gpg: keyring created Step 1: Select Key Type The first step in GnuPG key generation is choosing exactly what type of key you want. You will see the screen below, where you will be asked to select that key. Please select what kind of key you want: (1) DSA and ElGamal (default) (2) DSA (sign only) (4) ElGamal (sign and encrypt) Yourselection? 1 A Digital Signature Algorithm (DSA) generates digital signatures. An ElGamal (ELG-E) does both digital signatures and encryption. If you are mainly focused on identity verifications, then DSA keys are best. If you also want to send encrypted emails with sensitive information, then using EIGamal is a good idea. As a result, most people prefer to use the default option since you can perform all of the actions whenever needed. In the following steps, we will assume the user selected option 1. Step 2: Select Keypair Size You will need to determine the ELG-E keypair size in the next step. DSA keypair will have 1024 bits. About to generate a new ELG-E keypair. (1) minimum keysize is768 bits (2) default keysize is 1024 bits Highest suggested keysize is 2048 bits What keysize do you want? (1024) 1024 The default size, 1024, is the best choice, as more is unnecessary. You will then receive a confirmation on screen. Requested keysize is 1024 bits Step 3: Select Key Lifetime Choose how long the key will be valid. Typically, you will want it to be forever, and the default assumes you want a key that does not expire. If you wish to an end date, this screen is where you can make adjustments: Please specify how long the key should be valid. 0 = key does not expire = key expires in n days w = key expires in n weeks m = key expires in n months y = key expires in n years Key is valid for? (0) 0 You will then be presented with a confirmation: Key does not expire at all Is this correct (y/n)? y Step 4: Create User ID GnuPG will generate a User ID for you that is unique to the key and derives from your name, email address, and any comments you make: You need a User-ID to identify your key; the software constructs the user id from Real Name, Comment and Email Address in this form: "Heinrich Heine (Der Dichter) ;" Real name: Ryan W. Maple Email address: ryan@guardiandigital.com Comment: Guardian Digital, Inc. You will then need to confirm the information. You selected this USER-ID: "Ryan W. Maple (Guardian Digital, Inc.) ;" Change (N)ame, (C)omment, (E)mail or (O)kay/(Q)uit? O Step 5: Select Passphrase When signing or encrypting something, you will need a passphrase to unlock your secret key. A good passphrase requires a long combination of lowercase and uppercase letters, numbers, and punctuation. When entering your passphrase, this is what your screen will look like: You need a Passphrase to protect your secret key. Enter passphrase: Repeat passphrase: Finally, GnuPG attempts to generate many random bytes to encrypt your private key. This will be your screen: We need to generate a lot of random bytes. It is a good idea to perform some other action (type on the keyboard, move the mouse, utilize the disks) during the prime generation; this gives the random number generator a better chance to gain enough entropy. Start doing the “other action” recommended to help the GnuPG generate the random numbers needed for your key. Then you will see a success message: public and secret key created and signed. What is a Revocation Certificate? You will need a revocation certificate if you forget your passphrase or the key is compromised. The GnuPG manual explains that should this take place, you must immediately notify others of the cloud security breach or network security issues. You can still verify past documents with the signature, but you should not generate more encryptions with that passphrase. To create a revocation certificate, execute the command “gpg --gen-revoke user@host”: [ryan@mastermind ryan]$ gpg --gen-revoke --output revocation.asc ryan@guardiandigital.com gpg: Warning: using insecure memory! sec1024D/60DDF66A 2001-01-03Ryan W. Maple (Guardian Digital, Inc.) ; Create a revocation certificate for this key? y Afterward, you will need to provide the reason for revocation. Option 1 is most common, but options 2 and 3 result from choosing a shorter time span on your key pair: Please select the reason for the revocation: 1 = Key has been compromised 2 = Key is superseded 3 = Key is no longer used 0 = Cancel Your decision? 1 Enter an optional description; end it with an empty line: > Reason for revocation: Key has been compromised (No description given) Is this okay? Y You need a passphrase to unlock the secret key for user: "Ryan W. Maple (Guardian Digital, Inc.) ;" 1024-bit DSA key, ID 60DDF66A, created 2001-01-03 Enter passphrase: Following this, your revocation certificate will be stored, and you will receive a warning: ASCII armored output forced. Revocation certificate created. Please move it to a medium you can hide away; if Mallory gets access to this certificate, he can use it to make your key unusable. Printing this certificate and storing it in case your media becomes unreadable is smart. But be cautious: Your machine's print system might store the data and make it available to others! Keep this certificate in a safe place: [ryan@mastermind ryan]$ cat revocation.asc -----BEGIN PGP PUBLIC KEY BLOCK-----Version: GnuPG v1.0.4 (GNU/Linux) Comment: For info see https://www.gnupg.org Comment: A revocation certificate should follow iEkEIBECAAkFAjpbhzACHQIACgkQZi8S3ZLqN2GZHgCgsWbCMQBiExcvoGDZJQfniHbGOuYAoJndfnpvYloGReJZ1nTDwKGgWoN+=aXah -----END PGP PUBLIC KEY BLOCK----- Final Details for Revocation Certificate Keep the keypair and revocation certificate in a safeplace, such as storing it on a read-only media, in a tarball, or a safe deposit box by executing the following command (as long as your file is a “revocation.asc”): [ryan@mastermind ryan]$ tar -cvf gnupg-BACKUP-2001-01.tar .gnupg revocation.asc If your key gets compromised, you can issue your certificate to make your keys null and void, protecting yourself and your company. Also, consider exporting a copy of your public key to keyservers so others can retrieve it if needed. Keyservers share public key information in a distributed fashion so that other servers can reach it quickly should any network security issues arise. To export a copy of your public key to stdout, execute the command: [ryan@mastermind ryan]$ gpg --export --armor
Get the latest Linux and open source security news straight to your inbox.