Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
It was recently discovered that PHP could be made to bypass password checking if a specially crafted input was provided (CVE-2023-0567). . This flaw could possibly allow applications to accept any password as valid, contrary to expectations, potentially leading to the compromise of critical systems and sensitive information. With a low attack complexity, no user interaction required, and a high confidentiality impact, it is crucial that all impacted users apply the PHP updates issued but their distro(s) immediately to protect the privacy and confidentiality of their systems and their sensitive data. To stay on top of important updates released by the open-source programs and applications you use, be sure to register as a LinuxSecurity user , then subscribe to our Linux Advisory Watch newsletter and customize your advisories for the distro(s) you use. This will enable you to stay up-to-date on the latest, most significant issues impacting the security of your systems. Follow @LS_Advisories on Twitter for real-time updates on advisories for your distro(s) . . A significant vulnerability in PHP may allow applications to circumvent password verification, thereby endangering confidential information.. PHP Vulnerability, Bypass Security, Critical Threat. . Brittany Day
Some 250,000 diplomatic dispatches from the US State Department have accidentally been made completely public. The files include the names of informants who now must fear for their lives. It is the result of a series of blunders by WikiLeaks and its supporters.. In the end, all the efforts at confidentiality came to naught. Everyone who knows a bit about computers can now have a look into the 250,000 US diplomatic dispatches that WikiLeaks made available to select news outlets late last year. All of them. What's more, they are the unedited, unredacted versions complete with the names of US diplomats' informants -- sensitive names from Iran, China, Afghanistan, the Arab world and elsewhere. The link for this article located at Spiegel is no longer available. . In the end, all the efforts at confidentiality came to naught. Everyone who knows a bit about comput. diplomatic, dispatches, state, department, accidentally, complete. . LinuxSecurity.com Team
IT and security professionals routinely use USBs, smartphones, and tablets to move and back up confidential files, yet their organizations haven't made changes in the wake of the WikiLeaks leaks.. Maybe the massive disclosure of diplomatic memos from the U.S. State Department by WikiLeaks didn't serve as much of a cautionary tale for preventing the leak of sensitive data after all: Most IT and security professionals say they use USBs, smartphones, and tablets to move and back up confidential files, and 65 percent say they don't have a handle on what files and data leave the enterprise, a new survey says. The survey of 200 IT and security pros at the RSA Conference last month in San Francisco revealed some risky practices by users who theoretically should know better -- including 77 percent saying that they send payroll, customer data, financial, and other classified information via unsecured email monthly. "One thing we know is that people do what they need to do to be productive, and they find their own mechanisms to do this better. This is not malicious, but it puts companies at risk," says Hugh Garber, product marketing manager for Ipswitch, which conducted the survey. "If there's not a tool, they use their own stuff -- a lot are turning to USB drives, file-sharing sites, and their personal email [if corporate email restricts file-size attachments, for instance]. And that just enforces lower visibility to IT and brings more risk." The link for this article located at Dark Reading is no longer available. . Maybe the massive disclosure of diplomatic memos from the U.S. State Department by WikiLeaks didn't . security, professionals, routinely, smartphones, tablets, confi. . LinuxSecurity.com Team
As much as half of the secret documents posted by WikiLeaks may have been siphoned from peer-to-peer users who incorrectly configured their file-sharing software, according to evidence gathered by a security firm.. Tiversa, a Pennsylvania company that in 2009 uncovered confidential blueprints of the US President's Marine One helicopter being traded over P2P networks, told Bloomberg News the evidence suggests that WikiLeaks volunteers actively sought out confidential documents, despite claims by the whistle-blower website that it doesn't know who provides it with the information it gets. The link for this article located at The Register UK is no longer available. . Tiversa, a Pennsylvania company that in 2009 uncovered confidential blueprints of the US President's. secret, documents, posted, wikileaks, siphoned, peer-to-peer. . LinuxSecurity.com Team
Here's the perfect plan to solve all those pesky security problems. Confidentiality and data leakage, secure backups, individual privacy, data integrity, identity and access management - all can be dealt with in some way by encryption. So why don't we all just use it then, and be done?. Of course encryption is out there, embedded in various technologies The link for this article located at The Register UK is no longer available. . Of course encryption is out there, embedded in various technologies The link for this article locate. here's, perfect, solve, those, pesky, security, problems, confidentiality, leakage. . LinuxSecurity.com Team
At this week's annual meeting of the Optical Society of America in Rochester, N.Y., Bernard Wu and Evgenii Narimanov of Princeton University will present a method for transmitting secret messages over existing public fiber-optic networks, such as those operated by Internet service providers. This technique could immediately allow inexpensive, widespread, and secure transmission of confidential and sensitive data by governments and businesses. Wu and Narimanov's technique is not the usual form of encryption, in which computer software scrambles a message. Instead, it's a more hardware-oriented form of encryption--it uses the real-world properties of an optical-fiber network to cloak a message. . The sender transmits an optical signal that is so faint that it is very hard to detect, let alone decode. The method takes advantage of the fact that real-world fiber-optics systems inevitably have low levels of "noise," random jitters in the light waves that transmit information through the network. The new technique hides the secret message in this optical noise. The link for this article located at PhyOrg is no longer available. . Discover the innovative optical signaling approach that enables confidential data transfer across open fiber optic networks.. Secure Data Transmission,Fiber Network Security,Confidential Message Transmission,Optical Encryption Techniques. . LinuxSecurity.com Team
Digital signatures were designed to allow secure, confidential communication between two parties. As Wikipedia describes it: "A user may digitally sign messages using his private key, and another user can check that signature (using the public key contained in that user's certificate issued by a certificate authority). This enables two (or more) communicating parties to establish confidentiality, message integrity and user authentication without having to exchange any secret information in advance." . Are digital signatures legally binding? Usually. Check your local statutes. Are they foolproof? Not usually. For years, Prof. Ferenc Leitold of the University of Veszprem has been explaining the dangers of digital signatures to the world at large. This week, he's doing it again at the 15th EICAR Annual Conference in Hamburg, Germany. The link for this article located at Email Battles is no longer available. . Are digital signatures legally binding? Usually. Check your local statutes. Are they foolproof? Not . digital, signatures, designed, allow, secure, confidential, communication, between, parties. . LinuxSecurity.com Team
Along with the benefits of networked systems – easy information sharing and the ability to work wherever and whenever – comes responsibility. Professionals in all industries have the responsibility to protect their customers’ (and their own) confidentiality. When professionals access their office networks and exchange information with other organisations, confidentiality is paramount, though not always easy to achieve. . The link for this article located at Net-Security.org - Logerror is no longer available. . Delve into the vital role of confidentiality in networked systems, emphasizing data security and professional accountability.. Network Confidentiality, Data Protection, Information Security. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.