Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
The EU is poised to pass a sweeping new regulation, eIDAS 2.0. Buried deep in the text is Article 45, which returns us to the dark ages of 2011, when certificate authorities (CAs) could collaborate with governments to spy on encrypted traffic—and get away with it. Article 45 forbids browsers from enforcing modern security requirements on certain CAs without the approval of an EU member government. Which CAs? . Specifically, the CAs that were appointed by the government, which in some cases will be owned or operated by that selfsame government. That means cryptographic keys under one government’s control could be used to intercept HTTPS communication throughout the EU and beyond. This is a catastrophe for the privacy of everyone who uses the internet, but particularly for those who use the internet in the EU. Browser makers have not announced their plans yet, but it seems inevitable that they will have to create two versions of their software: one for the EU, with security checks removed, and another for the rest of the world, with security checks intact. We’ve been down this road before when export controls on cryptography meant browsers were released in two versions: strong cryptography for US users and weak cryptography for everyone else. It was a fundamentally inequitable situation, and the knock-on effects set back web security by decades. Read what LinuxSecurity.com Founder and Linux Security expert Dave Wreski has to say about the implications of this proposed regulation in a new LinkedIn update. . Investigating the impact of Article 45 on digital safety and personal data protection for online users within the European Union framework.. Web Security Regulations, Certificate Authorities EU, Privacy Encryption Laws, Internet Governance Compliance. . Brittany Day
Sigstore that is backed by Google, Red Hat, GitHub, and other prominent organizations with an aim to secure the open-source software supply chain has reached general availability and issued the "v1.0" releases for their key software components. . This week Sigstore celebrated its general availability milestone and releasing the v1.0 software of their Rekor transparency log and Fulcio certificate authority software. Sigstore now considers itself to be production-grade for software artifact signing and verification. Sigstore provides the means of easily and cryptographically-backed means of signing code, verifying signatures using a transparency log, and monitoring of activity for safely vetting the software supply chain. The link for this article located at Phoronix is no longer available. . Recently, Sigstore marked a significant achievement with the announcement of its general availability and the launch of version 1.0 of its essential software tools.. Sigstore, Software Supply Chain, Code Signing, Open Source Security, Fulcio. . LinuxSecurity.com Team
The most popular free certificate signing authority Let's Encrypt is going to revoke more than 3 million TLS certificates within the next 24 hours that may have been issued wrongfully due to a bug in its Certificate Authority software. . The bug, which Let's Encrypt confirmed on February 29 and was fixed two hours after discovery, impacted the way it checked the domain name ownership before issuing new TLS certificates. As a result, the bug opened up a scenario where a certificate could be issued even without adequately validating the holder's control of a domain name. The link for this article located at The Hacker News is no longer available. . A flaw in Let's Encrypt's system was acknowledged, resulting in the inappropriate granting of TLS certificates, which have since been rescinded to ensure security.. TLS Certificate Revocation, Let's Encrypt Bug, Certificate Authority Issues. . LinuxSecurity.com Team
. . Explore how Let's Encrypt launched its first free digital certificate, enhancing web security for sites.. Lets Encrypt, Free Digital Certificate, Open Source Security, Web Encryption. . LinuxSecurity.com Team
Miffed certificate authorities are calling on Google to give websites more time to upgrade the security used in browser-to-server communications before displaying warnings in Chrome.. The CAs are upset over Google's roughly six-month timetable for ratcheting up the notices that begin this month for Chrome users visiting sites that do not upgrade from SHA-1 to SHA-2. The link for this article located at CSO Online is no longer available. . The schedule set by Mozilla for browser certificate renewals raises alarms among regulators impacting online safety.. Certificate Security, Browser Communication, SHA-1 Upgrade. . LinuxSecurity.com Team
When Firefox 32 shipped this week, Mozilla also officially ended its support of 1024-bit certificate authority certificates in its trusted store.. While it still takes a considerable amount of resources to factor and crack a 1024-bit RSA key, important organizations such as NIST have been advising organizations to move to 2048-bit keys or higher going as far back as 2011. Microsoft announced a change to its certificate key length requirements shortly thereafter, yet others including Google, have been slow to follow suit. The link for this article located at ThreatPost is no longer available. . Google's decision to phase out SHA-1 certificates affects more than 85,000 domains, enhancing security standards.. 1024-bit Certificates, Browser Security, Key Management, Encryption Protocols. . LinuxSecurity.com Team
Google's recent announcement that they will begin to deprecate support for SHA-1 TLS/SSL digital certificates in Chrome is meeting resistance from certificate authorities (CAs). Google made their announcement on August 20 on their Security-dev mailing list, although they had been warning of this decision for months.. SHA-1 is a hash algorithm, a critical component of secure cryptography. A hash algorithm takes a block of data as input and outputs a value of a certain size (SHA-1 hashes are 160 bits long). This value is called a hash or digest. With a good hash algorithm, two different blocks of data will always produce a different hash, and even a small change in the input data will result in a significant change in the output. There should be no way to learn anything about the input data from the hash output. The link for this article located at ZDNet Blogs is no longer available. . The discontinuation of SHA-1 by Google creates challenges for Certificate Authorities and the wider impact on secure digital certificates.. SHA-1 Support,Cryptography,Digital Certificates,Certificate Authority,Google Security. . LinuxSecurity.com Team
Google has identified and blocked unauthorized digital certificates for a number of its domains issued by the National Informatics Centre (NIC) of India, a unit of India. National Informatics Center (NIC) holds several intermediate Certification Authority (CA) certs trusted by the Indian government The link for this article located at The Hacker News is no longer available. . National Informatics Center (NIC) holds several intermediate Certification Authority (CA) certs trus. google, identified, blocked, unauthorized, digital, certificates, number, domains. . Alex
Get the latest Linux and open source security news straight to your inbox.