Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 428
Alerts This Week
Warning Icon 1 428

Stay Ahead With Linux Security News

Filter%20icon Refine news
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security news

We found 7 articles for you...
81

Choose Safe Passwords to Enhance Your Cybersecurity Measures

Classic article on choosing a secure password from Bruce Schneier on Wired. It's great reading, even for those of us who have been around a while. Ever since I wrote about the 34,000 MySpace passwords I analyzed, people have been asking how to choose secure passwords. My piece aside, there's been a lot written on this topic over the years -- both serious and humorous -- but most of it seems to be based on anecdotal suggestions rather than actual analytic evidence. What follows is some serious advice. . The attack I'm evaluating against is an offline password-guessing attack. This attack assumes that the attacker either has a copy of your encrypted document, or a server's encrypted password file, and can try passwords as fast as he can. There are instances where this attack doesn't make sense. ATM cards, for example, are secure even though they only have a four-digit PIN, because you can't do offline password guessing. And the police are more likely to get a warrant for your Hotmail account than to bother trying to crack your e-mail password. Your encryption program's key-escrow system is almost certainly more vulnerable than your password, as is any "secret question" you've set up in case you forget your password. The link for this article located at Wired is no longer available. . Create a robust, unique password of at least 12 characters, mixing letters, numbers, and symbols. Use a memorable passphrase and update regularly.. Secure Passwords, Cybersecurity Tips, Authenticator Recommendations. . LinuxSecurity.com Team

Calendar%202 Aug 10, 2009 User Avatar LinuxSecurity.com Team Privacy
76

Crucial Tips for Safely Navigating DefCon 2023 Experience

Now that DefCon is upon all of us in an age where laptops flow free like wine, one still has to wonder - why would anyone jump on the "free public WiFi" offered at the event? It doesn't take a mastermind to sum up that 1. I'm at a hacker's conference, 2. I'm at a hacker's conference just teeming with BlackHats and 3. oh look, what's this "Wall of Sheep" I'm looking at? And why is my name on it??? Anyone wishing to attend the conference might want to take a quick review of this article just to make sure you won't be walking in with a huge bullseye over your forehead. If you do go, be sure to come back here and let us know of the best (and worst!) of DefCon by posting here! . The link for this article located at The Register is no longer available. . Experiencing DefCon is thrilling for tech and cybersecurity fans. Prioritize your security with these key precautions for a smooth visit at the event. defcon 2023, cyber security tips, hacker conference safety. . Brittany Day

Calendar%202 Aug 02, 2007 User Avatar Brittany Day Organizations/Events
83

Mastering Phishing Detection Techniques For Enhanced Cyber Safety

Phishers launched a record number of attacks in January 2006, as reported by the Anti-Phishing Working Group. These attacks often take the form of an email that purports to be from a trusted entity, such as eBay or PayPal. . The email states that the user needs to provide information, such as credit card numbers, identity information, or login credentials, often to correct some alleged problem supposedly found with an account. Some number of users fall for these attacks by providing the requested information, which can lead to fraudulent charges against credit cards, withdrawals from bank accounts, or other undesirable effects. The link for this article located at It-Observer.com is no longer available. . Become adept at spotting fraudulent emails and safeguard your data against cyber threats lurking in your mailbox.. Phishing Alerts, Email Security Tips, Cyber Safety Practices, Identity Protection, Data Safety Measures. . LinuxSecurity.com Team

Calendar%202 Jul 28, 2006 User Avatar LinuxSecurity.com Team Hacks/Cracks
81

Identity Protection: Government Data Threats to Personal Information

If you are worried about a thief stealing your identity, it's not your wallet that needs guarding - it's your state and local governments. That's the alarm Betty "BJ" Ostergren, the self-proclaimed Virginia Watchdog, has been sounding for the past four years from her rural Virginia home. . Sitting at her computer, she shows us with just a click of the mouse she can find Social Security numbers, birthdates, bank loans and even digitized signatures that a clever thief could easily manipulate onto official-looking documents. Everything anyone would need to steal your identity is right online, put there by local and state government agencies. The link for this article located at CNN is no longer available. . Uncover the ways digital data might be exposed to identity fraud due to mishandling of governmental records.. Data Security, Identity Protection, Online Threats, Privacy Concerns, Cyber Safety. . LinuxSecurity.com Team

Calendar%202 Jun 14, 2006 User Avatar LinuxSecurity.com Team Privacy
81

9.9 Million Identity Theft Victims in America: $48 Billion Impact

A staggering 27.3 million Americans have been victims of identity theft in the last five years, according to Federal Trade Commission survey out this week. In the last year alone, 9.9 million people have had their identity purloined. Identity theft . . . . A staggering 27.3 million Americans have been victims of identity theft in the last five years, according to Federal Trade Commission survey out this week. In the last year alone, 9.9 million people have had their identity purloined. Identity theft cost businesses and financial institutions nearly $48 billion and consumer victims reported $5 billion in out-of-pocket expenses last year, according to the FTC. "Identity theft is affecting millions of consumers and costing billions of dollars," said Howard Beales, Director of the FTC's Bureau of Consumer Protection. "This information can serve to galvanize federal, state, and local law enforcers, the business community, and consumers to work together to combat this menace." The survey was released in the wake of the formation of an industry coalition to fight online identity theft (involving leading financial services, IT and e-commerce companies) earlier this week. Microsoft Corp, eBay, Amazon.com and Visa are among founder members of the Coalition on Online Identity Theft. . Over the last half-decade, approximately 30.2 million individuals in the U.S. experienced compromises of their personal data, significantly impacting the nation.. Identity Theft, Consumer Protection, Cyber Safety, Fraud Issues, Online Security. . LinuxSecurity.com Team

Calendar%202 Sep 09, 2003 User Avatar LinuxSecurity.com Team Privacy
82

Overview of Homeland Security's Network Initiative for Cyber Safety

The White House and the new Department of Homeland Security have begun in earnest the process of implementing the plan to secure the nation's critical networks--starting with extensive changes in the federal security infrastructure. . . .. The White House and the new Department of Homeland Security have begun in earnest the process of implementing the plan to secure the nation's critical networks--starting with extensive changes in the federal security infrastructure. The most significant move is the development of a private, compartmentalized network that will be used by federal agencies and private-sector experts to share information during large-scale security events, government officials said at the National Information Assurance Leadership conference here last week. The system is part of the newly created Cyber Warning Information Network, a group of organizations including the National Infrastructure Protection Center, the Critical Infrastructure Assurance Office and others that have some responsibility for the security of federal systems. The private-sector Information Sharing and Analysis Centers will also be included. The link for this article located at eWeek is no longer available. . The White House and the new Department of Homeland Security have begun in earnest the process of imp. white, house, department, homeland, security, begun, earnest, process. . Anthony Pell

Calendar%202 Mar 11, 2003 User Avatar Anthony Pell Government
74

Reorganizing Senate Homeland Security: Cyber Safety Reform Implications

The overwhelming vote by the Senate late Tuesday approving a Homeland Security Department clears the way for massive reorganization of the federal government that will have a dramatic impact on computer and network security. . .. The overwhelming vote by the Senate late Tuesday approving a Homeland Security Department clears the way for massive reorganization of the federal government that will have a dramatic impact on computer and network security . The bill, which sets the stage for the largest federal reorganization since the Defense Department was formed in 1947, does more than reshuffle government agencies. It gives the government a major role in securing operating systems, hardware and the Internet, including allowing for more police surveillance of the Net; punishing malicious computer hackers with up to life in prison; establishing a national clearinghouse for computer and network security work; and spending at least half a billion dollars a year for homeland security research. President Bush is expected to sign the bill by the end of the month. "The United States Congress has taken a historic and bold step forward to protect the American people by passing legislation to create the Department of Homeland Security," Bush said after the vote. "This landmark legislation, the most extensive reorganization of the federal government since the 1940s, will help our nation meet the emerging threats of terrorism in the 21st century." Attorney General John Ashcroft heralded the Senate's 90-9 vote for the massive new bureaucracy, which combines about 170,000 employees from 22 existing agencies, as beginning "a new era of cooperation and coordination in the nation's homeland defense." Earlier on Tuesday, the Senate voted 52-47, largely along party lines, to reject Democratic amendments to the bill. The final bill prohibits the Justice Department's proposed citizen-informant program called TIPS (Terrorist Information and Prevention System) and rejects "the development of a national identification system orcard." But privacy advocates and civil libertarians remain worried about the negative consequences of such a sweeping reorganization of law enforcement functions with little oversight. In a statement calling for more supervision of law enforcement practices, the Center for Democracy and Technology said the plan "raises serious concerns about the privacy of Americans" by granting the government "substantial--and potentially invasive--authorities to compile, analyze and mine the personal information of millions of Americans." Technology companies, on the other hand, praised the plan, which promises to be a cash cow for businesses that develop security products. AeA, a trade group representing technology companies, in particular applauded a provision that would require the government to focus on small businesses. "Some of the most cutting-edge technologies are being developed in smaller firms, but we are frequently lost in the shadow of the big guys," Michele Wong, CEO of Synergex and an AeA board member, said in a statement. Meanwhile, Microsoft is one of many large technology companies looking to further expand its government contracts into the homeland security arena. The company has named a new internal federal director of homeland security to work with the government on information technology issues. After the federal reorganization is complete, the new department will mash together five agencies that currently divvy up responsibility for "critical infrastructure protection." Those are the FBI's National Infrastructure Protection Center, the Defense Department's National Communications System, the Commerce Department's Critical Infrastructure Assurance Office, an Energy Department analysis center, and the Federal Computer Incident Response Center. Policing the Net A last-minute addition to the bill last week, before the House approved it by a 299-121 vote, is the 16-page Cyber Security Enhancement Act. It stiffens prison terms for hackers, expands the ability of police to conduct Internetor telephone eavesdropping without first obtaining a court order, and grants Internet providers more latitude to disclose information about subscribers to police. Another addition, which was opposed by open-government activists and journalist groups, says that information businesses give the department that's related to "critical infrastructure" will not be subject to the Freedom of Information Act. That could include details on virus research, security holes in applications, or operating system vulnerabilities. Included in the bill is a Homeland Security Advanced Research Projects Agency (HSARPA), modeled after the Defense Advanced Research Projects Agency, which will receive at least $500 million a year to fund the development of new technologies. According to the bill, HSARPA will "promote revolutionary changes in technologies that would promote homeland security, advance the development (of technologies), and accelerate the prototyping and deployment of technologies that would address homeland vulnerabilities." The final version of the mammoth, 484-page bill also does the following: * Establishes an office that is designed to become "the national focal point for work on law enforcement technology." Categories include computer forensics, tools for investigating computer crime, firearms that recognize their owner, and DNA identification technologies. The office also is charged with funding the development of tools to help state and local law enforcement agencies thwart computer crime. * Creates a Directorate for Information Analysis and Infrastructure Protection that is charged with analyzing vulnerabilities in systems including the Internet, telephone networks, and other critical infrastructures. * Orders the creation of "a comprehensive national plan for securing the key resources and critical infrastructure of the United States" including information technology, financial networks and satellites. * Requires all federal agencies, including the CIA, the Defense Department, and NationalSecurity Agency, to provide the new department with any "information concerning the vulnerability of the infrastructure of the United States." * Punishes any department employee with one year in prison for disclosing details that are "not customarily in the public domain" about critical infrastructures. * Creates a privacy representative and a civil liberties officer to ensure that the department follows reasonable "privacy protections relating to the use, collection and disclosure of personal information." * Orders the department to provide technical assistance and confidential warnings of potential vulnerabilities to companies that operate "critical information systems." * Allows the department to create a national corps of volunteers to "assist local communities to respond and recover from attacks on information systems and communications networks." * Creates a Homeland Security Institute to perform systems analysis, risk analysis, and simulation and modeling to determine the vulnerabilities of critical infrastructures, including the Internet. The nine senators who voted against the bill were Democrats Robert Byrd of West Virginia, Paul Sarbanes of Maryland, Daniel Akaka and Daniel Inouye of Hawaii, Edward Kennedy of Massachusetts, Russ Feingold of Wisconsin, Fritz Hollings of South Carolina, and Carl Levin of Michigan. Democratic-leaning independent James Jeffords of Vermont also opposed the bill. The link for this article located at News.com is no longer available. . The overwhelming vote by the Senate late Tuesday approving a Homeland Security Department clears the. overwhelming, senate, tuesday, approving, homeland, security, department, clears. . Anthony Pell

Calendar%202 Nov 20, 2002 User Avatar Anthony Pell Network Security
74

Exploring Password Management And Secure Online Identities

In order to access computer networks, online bank or e-mail accounts, we need a wide range of usernames and passwords. Constant attention is required to track what our name is in each virtual environment, and what password is needed at that moment to access personal information. . . .. In order to access computer networks, online bank or e-mail accounts, we need a wide range of usernames and passwords. Constant attention is required to track what our name is in each virtual environment, and what password is needed at that moment to access personal information. This means that using the internet requires us to constantly create and manage multiple identities. The complaint that the internet enables people all too freely to impersonate alternate identities often overlooks a fundamental point: online, we are all required to assume multiple personae. The link for this article located at BBC News is no longer available. . Comprehending the protection of digital profiles necessitates the effective handling of various identifiers and passphrases.. Password Management, Identity Protection, Online Security, Authentication Solutions, Cyber Safety. . Anthony Pell

Calendar%202 May 10, 2002 User Avatar Anthony Pell Network Security
News Add Esm H340

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200