Linux security professionals spend most of their time on concrete problems. Hardening SSH. Configuring SELinux or AppArmor. Building secure CI/CD pipelines. Managing patches across server fleets. The work is technical, hands-on, and measurable.
...
The problem with IT security benchmarks is that the reference point is a constantly shifting target as new technologies and threats emerge. And that's an especially difficult problem to overcome, said corporate security systems managers. They are examining the fruits of . . .
With security expertise becoming an increasingly expensive but important commodity, security companies plan to focus on managed security services as a key selling point at the RSA Conference 2001 this week in San Francisco. In addition, companies are pushing systems to . . .
The RSA Conference, named for the Bedford, Mass.-based security company that puts it together, began Sunday and runs through Thursday. In another sign that security has become important business, the sponsors include Intel, Microsoft, Hewlett-Packard, IBM and Compaq. "I think the . . .
Does an alphabet soup of acronyms, which stand for certifications that you've obtained, follow your signature? Are you wondering which, if any, are really valuable? Are you contemplating a worthwhile certification challenge? Have you been working in the information system security . . .
On the surface, IT-ISAC sounds wonderful, but there's something wrong with this picture. Each of these companies might provide a general idea as to the kinds of attacks that it is receiving. But no company in its right mind will contribute . . .
The Electronic Privacy Information Center (EPIC) has teamed up with Privacy International in relaunching a Web site that aims to become the clearinghouse for all privacy-related news worldwide. The new site, EPIC – Electronic Privacy Information Center, hosts links to hundreds of news . . .
Nineteen leading tech firms have created an information-sharing conglomerate aimed at countering the growing number of electronic attacks on U.S. companies. The information technology sector on Tuesday became the third area of the economy to create its own "Information Sharing and . . .
These are portraits Marcus Ranum took at the first ever computer security summit, held at Bill Cheswick's house in the summer of 1998, I believe. Ever wonder what Dan Farmer or Wietse Venema look like? Marcus adds, "Due to unfortunate lack . . .
Although U.S. companies lose billions of dollars every year as a result of cybercrimes committed by internal and external hackers, more than 90% of CIOs polled in a recent survey said they have confidence in their company's network security. According to . . .
In its clearest signal yet that it may be bracing for a massive attack, computer network security group CERT issued an advisory today asking system administrators to prepare systems to block denial of service attacks. The advisory, titled DenialofService Vulnerabilities in . . .
A variety of denial-of-service vulnerabilities has been explored and documented by BindView's RAZOR Security Team. These vulnerabilities allow attackers to consume limited resources on victim machines. BindView's RAZOR Security Team has referred to these vulnerabilities as Naptha vulnerabilities. Denial-of-service attacks . . .
During just one month of monitoring, the Honeynet team's "honey pot," which poses as a real network to attract hackers, had been scanned by hundreds of unique IP addresses looking for two particular ports: UDP (User Datagram Protocol) port 137, used . . .
Tired of conferences not living up to your expectations? Then you haven't been to Usenix. In this month's Wizard's Guide to Security, Carole Fennelly reports that Usenix's recent security conference offered interesting and accessible talks -- and a who's who of . . .
Several security vulnerabilities have been found in the latest version of BIND. CERT has now issued an advisory outlining those vulnerabilities and how to resolve them. "The CERT Coordination Center has recently learned of two serious denial-of-service vulnerabilities in the Internet . . .
Kris Kennaway succeeds Warner Losh as FreeBSD security officer. " I am resigning as FreeBSD's Security Officer. Over the past several years I have enjoyed watching FreeBSD's security improve. The change in attitude towards security issues of FreeBSD has . . .
Security was a hot topic at Monday's first-ever federal Linux user's conference. The news that Microsoft Corp.'s network had been breached and that hackers had gained access to source code underscores the need for effective security systems to protect large institutions . . .
Now you can download some late arriving presentations from SANS Network Security 2000 last October 15 - 22 in Monterey. Just click on the title of the presentation you're interested in to access the PDF file. Brief session descriptions are provided . . .
This year's BSDCon is being held at the Monterey Hyatt, in Monterey Ca. The first tutorial was a two-day tutorial covering BSD System Security. For the most part the classes are intensive and there was a lot of ground to cover. . . .
Members of the Members of the Global Internet Liberty Campaign (GILC) will today urge the Council of Europe to reconsider a draft treaty on cybercrime. The international coalition of civil liberties and human rights organizations, which includes the Electronic Privacy Information . . .