Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Let’s dive into the latest leap for Linux security: hardware-wrapped inline encryption keys. You might have heard about this feature making its way into the mainline Linux kernel with version 6.16. It's a fascinating piece of technology, particularly...
Why ``snake oil''? The term is used in many fields to denote something sold without consideration of its quality or its ability to fulfill its vendor's claims. This term originally applied to elixirs sold in traveling medicine shows. The salesmen . . .
SSH Secure Shell is the de facto standard for remote logins, with an estimated three million users in 80 countries. It solves the most important security problem on the Internet: hackers stealing passwords. Typical applications include remote system administration, file . . .
For years now, the IT industry has anxiously anticipated the arrival of the public-key infrastructure (PKI), a magical technology that would, in one fell swoop, solve the problems of authentication, confidentiality and single sign-on for the corporate world. Businesses continue . . .
Congress this year is expected to approve normal trade relations with China and make electronic signatures legal, lawmakers told information-technology executives Tuesday. An extension of the moratorium on Internet taxes and an increase in the number of foreign-guest high-tech . . .
William Reinsch, the Commerce Department's undersecretary for export administration, told technology executives on Tuesday that while the administration's new encryption export regulations appeared to be a huge improvement over prior iterations of the policy, a few cracks are starting to . . .
This edition of "Couch Sessions" talks about building an online shopping cart. "Need to build an online shopping cart in a hurry? This article takes a look at session management, an important component of transaction-based Web sites, and explains the . . .
Researchers are reporting encouraging progress in experiments to develop an unbreakable computer code that harnesses the unpredictable realm of quantum physics. . . .
Zero Knowledge Systems, a Montreal-based company specializing in anonymous secure Web surfing, has launched an ad campaign in Newsweek, Forbes, Fast Company and Business 2.0 magazines, featuring an encrypted message buried in photos of tattooed bar codes. . . .
The National Science Foundation will begin testing electronic signature technology next month that could remove the last impediment to its paperless proposal process. . . .
Here's an excellent (as always) article by Bruce Schneier on the process of thinking about security. "Security is a process, not a product. Products provide some protection, but the only way to effectively do business in an insecure world . . .
Lance Spitzner tells us all about Digital Certificates & Encryption how they work and apply to Internet Commerce. "On the Internet, information you send from one computer to another passes through numerous systems before it reaches its destination. Normally, . . .
"mod_ssl combines the flexibility of Apache with the security of OpenSSL." This module provides strong cryptography for the Apache 1.3 webserver via the Secure Sockets Layer (SSL v2/v3) and Transport Layer Security (TLS v1) protocols by the help of the . . .
Think that encryption will secure corporate data? Not according to virus specialist Ncipher (https://www.entrust.com/products/hsm). The company says it’s found viruses that hunt through a computer’s memory for the key used to decrypt data. First proposed in 1999 by Dr. Adi . . .
Before Jim Bell went to prison, he suspected that most government officials were corrupt. Three years behind bars later, the self-proclaimed Internet anarchist is sure of it. After Bell, a cypherpunk who the United States government dubbed a techno-terrorist, . . .
The CRYPTOCard PalmToken is a software-based token system that provides challenge-response authentication. "An attacker can determine the private PIN number of a users token within a matter of minutes and clone the challenge/response scheme of the legitimate user." . . .
An encryption method widely expected to secure next-generation wireless phones and other devices succumbed to a brute-force collaborative effort to break it, a French research agency announced Thursday. An international team of researchers — led by crypto researcher Robert . . .
Here's a link to an OpenBSD page that describes what crypto features are capable with it. Specifically, as pointed out on slashdot, http://www.openbsd.org/crypto.html#hardware is a link to new support for hardware crypto devices using OpenBSD. We'd be happy to post this kind of information in the future -- just send it along.
At a recent Computers, Freedom and Privacy Conference, developers and lawyers battled it out on issues of crypto and freedom. "... the unique annual meeting that brings together an unlikely combination of programmers, activists and government officials -- two . . .
While the Clinton administration has relaxed the international export of encryption technologies, there are still some other "draconian proposals" in the pipeline, according to the Electronic Privacy Information Center's (EPIC) third annual report on the state of encryption policies. The . . .
A U.S. Appeals Court judge has ruled that encryption source code is constitutionally protected and not subject to restrictions imposed by the U.S. government. The U.S. government had previously limited its distribution until January of this year, but the latest . . .