Linux security professionals spend most of their time on concrete problems. Hardening SSH. Configuring SELinux or AppArmor. Building secure CI/CD pipelines. Managing patches across server fleets. The work is technical, hands-on, and measurable.
...
A global summit focusing on cyberterrorism and the targets of critical infrastructures has been announced for next month. The event, Sector 5, will be co-produced by Gardner and Flight Event Work, and held in Washington, D.C., between August 21 and 23. . .
I spent three days at H2K2 hoping someone would say something worth mentioning in The Register. Finally, on Sunday, a couple of speakers did just that (on which more tomorrow). Best of all was Gweeds' savage synopsis of a thing which. . .
Just eight hours after the East Coast's largest hacking conference opened its doors Friday, H2K2 had already taken on the feel of summer camp for enthusiastic engineers. While most are here to hack around the clock for a few days and. . .
Some of the world's best-known hackers unveiled a plan this weekend to offer free software to promote anonymous Web surfing in countries where the Internet is censored, especially China and Middle Eastern nations. An international hacker group calling itself Hactivismo released a program on Saturday called Camera/Shy that allows Internet users to conceal messages inside photos posted on the Web, bypassing most known police monitoring methods.. . .
How businesses should deal with law enforcement was a topic of discussion at INT Media Group's recent E-Security Conference and Expo in Vienna, Va. In separate sessions, attendees heard from David Green, principal deputy chief of the Department of Justice Computer . . .
The departure of these and other information security veterans from Fortune 500 companies reflects the beginning of turbulent times for chief security officers (CSO). Since Sept. 11, CSOs have faced new pressures to prove the value and effectiveness of their security measures, even as they struggle politically for legitimacy within their corporations and for support from the technology and business units they're trying to protect, say analysts.. . .
At a recent publicity event here, two security companies and accounting giant PricewaterhouseCoopers showed off their latest tool for selling software: a calculator that lets clients estimate how much money they can save by using the companies' offerings.. . .
Talk may be cheap, but the infosec price tag is not. It shouldn't come as a surprise that the infamous TCO (total cost of ownership) and ROI (return on investment) justifications have descended upon the unsuspecting troopers in the infosec trenches. Apparently, it's time for us security geeks to learn some new tricks.. . .
A group of 18 organizations from all sectors of the economy has teamed with Carnegie Mellon University in Pittsburgh to form a technology consortium dedicated to improving the reliability and security of commercial software. Armed with $30 million in seed . . .
Anti-spammers are in disarray as a former employee is accusing Mail Abuse Prevention System LLC of "slimy" legal tactics. Nick Nicholas, former executive director at MAPS, posted comments online last week contending that MAPS executives had filed lawsuit affidavits that "are full of factual errors and material misrepresentations.". . .
Despite the current emphasis on security in the IT industry, CIOs and IT managers are still not paying enough attention to the problems facing their organizations, a panel of security experts said Wednesday. "Security is still very much an afterthought," said . . .
The University of Texas at Dallas has joined forces with businesses and law-enforcement officials to create a center for cybercrime education and research. The Digital Forensics and Security Institute includes the collaborative efforts of the Greater Dallas Crime Commission, the . . .
The 10th anniversary of what has become the largest hacker convention on the planet! DEF CON 10 will be August 2nd to the 4th at the Alexis Park Hotel and Resort in Las Vegas, Nevada, USA.. . .
The first hacker to gain access to a server run by Korea Digital Works and leave their name on the site's front page this week will find it an enriching experience A Korean company is offering $100,000 (£70,000) in a 48-hour hacking competition, to be run this week. . . .
Most security strategies are primarily defensive. The plan is to stop attacks at the front (firewall), back (server) and/or bedroom (desktop) doors. This plan has zero tolerance for failure because it has no component for dealing with and diagnosing successful attacks. So when the inevitable breach occurs, so do the 2 a.m. phone calls, 24-hour work details and extensive system scrubbing and reconstruction.. . .
The Alliance for Electronic Business (AEB) is hoping to overcome distrust of e-business with a new set of web security guidelines. The move follows evidence that trust and confidence are still a major barriers to adoption of Internet trading by UK businesses.. . .
Security holes exist in just about every application, but preventing an attack can be remarkably simple, says an expert hacker "It's simple," says Rain Forest Puppy. "Don't feel you have to...take it from Microsoft, just figure out what services lead to security risks and turn them off.". . .
The New Zealand Defence Force is to use an international conference to put a product created by Auckland company Esphion against distributed denial of service attacks through its paces. The event, known as the Joint Warrior Interoperability Demonstration (Jwid), will involve . . .
Microsoft and other software makers met with several computer-security companies Thursday to hash out the last details of a group that will set guidelines for reporting software flaws that affect Internet security. Currently named the Organization for Internet Safety, the group . . .
Last weekend's CodeCon conference in San Francisco saw the launch of Tinfoil Hat Linux, a self-proclaimed "exercise in over engineering" and security. What started out as a secure, single floppy, bootable Linux distribution for storing PGP keys, and encrypting, signing and . . .