Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 492
Alerts This Week
Warning Icon 1 492

Stay Ahead With Linux Security News

Filter%20icon Refine news
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security news

We found 26 articles for you...
82

Article 45: Assessing Risks to EU Web Security and User Privacy Concerns

The EU is poised to pass a sweeping new regulation, eIDAS 2.0. Buried deep in the text is Article 45, which returns us to the dark ages of 2011, when certificate authorities (CAs) could collaborate with governments to spy on encrypted traffic—and get away with it. Article 45 forbids browsers from enforcing modern security requirements on certain CAs without the approval of an EU member government. Which CAs? . Specifically, the CAs that were appointed by the government, which in some cases will be owned or operated by that selfsame government. That means cryptographic keys under one government’s control could be used to intercept HTTPS communication throughout the EU and beyond. This is a catastrophe for the privacy of everyone who uses the internet, but particularly for those who use the internet in the EU. Browser makers have not announced their plans yet, but it seems inevitable that they will have to create two versions of their software: one for the EU, with security checks removed, and another for the rest of the world, with security checks intact. We’ve been down this road before when export controls on cryptography meant browsers were released in two versions: strong cryptography for US users and weak cryptography for everyone else. It was a fundamentally inequitable situation, and the knock-on effects set back web security by decades. Read what LinuxSecurity.com Founder and Linux Security expert Dave Wreski has to say about the implications of this proposed regulation in a new LinkedIn update. . Investigating the impact of Article 45 on digital safety and personal data protection for online users within the European Union framework.. Web Security Regulations, Certificate Authorities EU, Privacy Encryption Laws, Internet Governance Compliance. . Brittany Day

Calendar%202 Nov 08, 2023 User Avatar Brittany Day Government
79

Sigstore v1.0 Launch for Open-Source Software Supply Chain Security

Sigstore that is backed by Google, Red Hat, GitHub, and other prominent organizations with an aim to secure the open-source software supply chain has reached general availability and issued the "v1.0" releases for their key software components. . This week Sigstore celebrated its general availability milestone and releasing the v1.0 software of their Rekor transparency log and Fulcio certificate authority software. Sigstore now considers itself to be production-grade for software artifact signing and verification. Sigstore provides the means of easily and cryptographically-backed means of signing code, verifying signatures using a transparency log, and monitoring of activity for safely vetting the software supply chain. The link for this article located at Phoronix is no longer available. . Recently, Sigstore marked a significant achievement with the announcement of its general availability and the launch of version 1.0 of its essential software tools.. Sigstore, Software Supply Chain, Code Signing, Open Source Security, Fulcio. . LinuxSecurity.com Team

Calendar%202 Oct 30, 2022 User Avatar LinuxSecurity.com Team Security Projects
67

Let's Encrypt Issues Advisory For 3 Million TLS Certificates Revocation

The most popular free certificate signing authority Let's Encrypt is going to revoke more than 3 million TLS certificates within the next 24 hours that may have been issued wrongfully due to a bug in its Certificate Authority software. . The bug, which Let's Encrypt confirmed on February 29 and was fixed two hours after discovery, impacted the way it checked the domain name ownership before issuing new TLS certificates. As a result, the bug opened up a scenario where a certificate could be issued even without adequately validating the holder's control of a domain name. The link for this article located at The Hacker News is no longer available. . A flaw in Let's Encrypt's system was acknowledged, resulting in the inappropriate granting of TLS certificates, which have since been rescinded to ensure security.. TLS Certificate Revocation, Let's Encrypt Bug, Certificate Authority Issues. . LinuxSecurity.com Team

Calendar%202 Mar 04, 2020 User Avatar LinuxSecurity.com Team Cryptography
81

Let's Encrypt: Free Digital Certificate Introduces Enhanced Web Security

. . Explore how Let's Encrypt launched its first free digital certificate, enhancing web security for sites.. Lets Encrypt, Free Digital Certificate, Open Source Security, Web Encryption. . LinuxSecurity.com Team

Calendar%202 Sep 16, 2015 User Avatar LinuxSecurity.com Team Privacy
67

Google's CA Updates Schedule: A Key to Elevating Web Security Standards

Miffed certificate authorities are calling on Google to give websites more time to upgrade the security used in browser-to-server communications before displaying warnings in Chrome.. The CAs are upset over Google's roughly six-month timetable for ratcheting up the notices that begin this month for Chrome users visiting sites that do not upgrade from SHA-1 to SHA-2. The link for this article located at CSO Online is no longer available. . The schedule set by Mozilla for browser certificate renewals raises alarms among regulators impacting online safety.. Certificate Security, Browser Communication, SHA-1 Upgrade. . LinuxSecurity.com Team

Calendar%202 Sep 11, 2014 User Avatar LinuxSecurity.com Team Cryptography
78

Mozilla Firefox 32: Critical Change In 1024-Bit Certificate Support

When Firefox 32 shipped this week, Mozilla also officially ended its support of 1024-bit certificate authority certificates in its trusted store.. While it still takes a considerable amount of resources to factor and crack a 1024-bit RSA key, important organizations such as NIST have been advising organizations to move to 2048-bit keys or higher going as far back as 2011. Microsoft announced a change to its certificate key length requirements shortly thereafter, yet others including Google, have been slow to follow suit. The link for this article located at ThreatPost is no longer available. . Google's decision to phase out SHA-1 certificates affects more than 85,000 domains, enhancing security standards.. 1024-bit Certificates, Browser Security, Key Management, Encryption Protocols. . LinuxSecurity.com Team

Calendar%202 Sep 08, 2014 User Avatar LinuxSecurity.com Team Vendors/Products
67

Google's SHA-1 Support Withdrawal: Effects on Certificate Authorities

Google's recent announcement that they will begin to deprecate support for SHA-1 TLS/SSL digital certificates in Chrome is meeting resistance from certificate authorities (CAs). Google made their announcement on August 20 on their Security-dev mailing list, although they had been warning of this decision for months.. SHA-1 is a hash algorithm, a critical component of secure cryptography. A hash algorithm takes a block of data as input and outputs a value of a certain size (SHA-1 hashes are 160 bits long). This value is called a hash or digest. With a good hash algorithm, two different blocks of data will always produce a different hash, and even a small change in the input data will result in a significant change in the output. There should be no way to learn anything about the input data from the hash output. The link for this article located at ZDNet Blogs is no longer available. . The discontinuation of SHA-1 by Google creates challenges for Certificate Authorities and the wider impact on secure digital certificates.. SHA-1 Support,Cryptography,Digital Certificates,Certificate Authority,Google Security. . LinuxSecurity.com Team

Calendar%202 Sep 03, 2014 User Avatar LinuxSecurity.com Team Cryptography
82

Google Identifies Unapproved Digital Certificates by Indian NIC

Google has identified and blocked unauthorized digital certificates for a number of its domains issued by the National Informatics Centre (NIC) of India, a unit of India. National Informatics Center (NIC) holds several intermediate Certification Authority (CA) certs trusted by the Indian government The link for this article located at The Hacker News is no longer available. . National Informatics Center (NIC) holds several intermediate Certification Authority (CA) certs trus. google, identified, blocked, unauthorized, digital, certificates, number, domains. . Alex

Calendar%202 Jul 10, 2014 User Avatar Alex Government
News Add Esm H340

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200