Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Let’s dive into the latest leap for Linux security: hardware-wrapped inline encryption keys. You might have heard about this feature making its way into the mainline Linux kernel with version 6.16. It's a fascinating piece of technology, particularly...
The idea of the International Kernel Patch is to collect all crypto patches so that using crypto in the kernel will be easier than today. The patch includes a number of crypto patches including a crypto API including Blowfish, CAST-128, DES, . . .
As most may know, one of three existing Enigma machines was stolen a few months ago. Bletchley Park Museum had agreed to hand over a £25,000 ransom before midnight on Friday but the deadline passed with no word from the . . .
This article starts out with a nice description of cryptography then goes into how to incorporate PGP for use with Pine. "Encryption is the transformation of data into a form that is (hopefully) impossible to read without the knowledge of a . . .
NetBSD-current IPsec (from KAME) now supports rijndael algorithm for ESP encryption, thanks to the integration work of Jun-ichiro itojun Hagino. rijndael is the finalist of AES contest, and will be standardized in FIPS standard suite, to replace DES.. . .
Federal Information Processing Standard 140-1(FIPS 140-1) is entitled "Security Requirements for Cryptographic Modules". It's a standard that describes government requirements that hardware and software products should meet for Sensitive, but Unclassified (SBU) use. The standard was published by the National Institute . . .
As a result of a landmark "e-sign" law that took effect in the United States on Sunday, businesses and consumers may now close mortgages, sign life insurance and seal contracts with the click of a mouse. "This is going to revolutionize . . .
A scrambling technique scripted by two Belgians has been chosen as the proposed US government standard to protect sensitive data and help spur the digital economy, the Commerce Department said Monday. The selection of the Rijndael (pronounced "Rhine-doll") . . .
Rijndael becomes the new data encryption standard beating out Schneier, IBM, and others. This DejaNews thread talks about the announcement of the winner of the new encryption standard. The Rijndael home page also provides some interesting . . .
The National Institute of Standards and Technology (NIST), an agency of the US Commerce Department's Technology Administration, will announce its choice for the Advanced Encryption Standard (AES) at 11:00 a.m. EDT today. The announcement, which will be broadcast on the Web . . .
Electronic signatures carry full legal weight beginning Sunday, ushering in a new era for commerce over the Internet. Digital signatures carry the promise of reducing the cost of business and making it more efficient, spurring the growth of e-commerce.. . .
It appears the winner of the new encryption standard to replace DES will be announced on Monday. "The National Institute of Standards and Technology (NIST) has been working with industry and the cryptographic community to develop an Advanced Encryption Standard (AES). . . .
The Royal Mail, Britain's postal service, is to offer free digital signatures to all citizens in a bid to improve consumer acceptance of e-business. From later this year, consumers will be able to collect software on a free CD-ROM from any . . .
Mitsubishi and Hokkaido University have completed a latest round of experiments in quantum cryptography over optical fibres. The two organisations say that their quantum cryptographic system is a success, and could have important implications for optical fibre networks already in use.. . .
Cryptcat is the standard netcat enhanced with twofish encryption. Cryptcat allows you to pipe data from one host to another using encryption. "Netcat is a simple Unix utility which reads and writes data across network connections, using TCP . . .
Do we need to worry about government tracing and identity theft? A leading technology expert has warned that digital signatures, an increasingly prevalent Internet security technology, could hail a future devoid of privacy.. . .
We've already seen one of the primary uses of ssh: it allows you to open up a terminal session to a remote system. By using "ssh" instead of telnet or rsh, you get the same ability to type commands on remote . . .
A new mailing list, dedicated to all Linux Crypto topics has just opened. It is This email address is being protected from spambots. You need JavaScript enabled to view it.. Thanks go to all at nl.linux.org for allowing me to host this mailing list using their majordomo, esp. to Rik van Riel.. . .
This document is a bit dated, but a good discussion of SSL. The Secure Sockets Layer protocol provides one means for achieving these goals and is the subject of this article. This document introduces SSL by reviewing cryptographic techniques and by . . .
GnuPG is a complete and free replacement for PGP. Because it does not use the patented IDEA algorithm, it can be used without any restrictions. GnuPG is a RFC2440 (OpenPGP) compliant application. This version comes with RSA support and the new . . .
A law that would allow electronic signatures to seal legally binding documents is scheduled to take effect on Oct. 1, but don't throw away your pens just yet. Electronic signatures aren't simply digital representations of the handwritten variety. In fact, they're . . .