Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 477
Alerts This Week
Warning Icon 1 477

Stay Ahead With Linux Security News

Filter%20icon Refine news
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":1,"type":"x","order":2,"pct":50,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":50,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security news

We found -2 articles for you...
77

Confidentiality And Integrity In Storage Management Strategies

In the first part of our Storage Security Basics series, we looked at authentication, authorization, accountability and access control. In this installment, we examine confidentiality and integrity. If you manage a storage network, one of your primary goals is to ensure that the data is secure. As the administrator, the confidentiality and integrity of information is your responsibility. (Data confidentiality refers to the process of encrypting information to prevent it from being read by users who weren't intended to have access to it. Data integrity means that information has not been changed or modified during transit.) . When it comes to designing a data security strategy, you need to consider where the data is located. For example, is it on the LAN/WAN, SAN or even located on the tape backup set? The location of data will often determine the type of processes and measures you use to secure that information. In this Storage Basics article, we'll explore how the concepts of confidentiality and integrity are applied in each of these areas. The link for this article located at Enterprise Storage Forum is no longer available. . Creating a robust data protection plan necessitates recognizing where data resides while safeguarding its privacy and accuracy.. Storage Management, Data Security, Confidentiality Strategies. . LinuxSecurity.com Team

Calendar%202 Aug 15, 2005 User Avatar LinuxSecurity.com Team Server Security
67

Data Encryption For Transit And Storage Confidentiality

You're exposing yourself to significant risk as long as the data on your network (data in transit) and in your storage (data at rest) is not encrypted. That's what a paranoid security specialist will tell you. . .. You're exposing yourself to significant risk as long as the data on your network (data in transit) and in your storage (data at rest) is not encrypted. That's what a paranoid security specialist will tell you . Is it true? That depends on the sensitivity of your data and on any government regulations that require the data to be encrypted--in the healthcare industry, for example. But the number of people out there who want to steal, tamper with, or destroy your data is going up, not down. And the chances are growing that you'll be targeted for such an attack either randomly or because the attacker has a political vendetta against the nation in which you're located. I'm fairly convinced that the day will come when all data--in transit and at rest--will be encrypted. It's just a question of clearing some hurdles. The link for this article located at ZDNet is no longer available. . You're exposing yourself to significant risk as long as the data on your network (data in transit) a. you're, exposing, yourself, significant, network, (data, transit). . LinuxSecurity.com Team

Calendar%202 Jul 10, 2002 User Avatar LinuxSecurity.com Team Cryptography
74

Kerberos Authentication For Secure Network Identity Verification

Kerberos is an authentication protocol that lets clients and servers reliably verify each other's identity before establishing a network connection. Developed at MIT in the late 1980s, Kerberos takes its name from the three-headed hound in Greek mythology that guards the entrance to Hades. But instead of guarding the underworld, today's Kerberos brings a measure of security to a distributed computer environment, where one computer can access the resources of any other machine on a network.. . .. Kerberos is an authentication protocol that lets clients and servers reliably verify each other's identity before establishing a network connection. Developed at MIT in the late 1980s, Kerberos takes its name from the three-headed hound in Greek mythology that guards the entrance to Hades. But instead of guarding the underworld, today's Kerberos brings a measure of security to a distributed computer environment, where one computer can access the resources of any other machine on a network. Paul Hill, information systems senior programmer at MIT and a member of the Kerberos development team since 1992, outlines the benefits of the Kerberos system. First, it has been subjected to public review for over a decade. Second, version 5 of the protocol-the most current version-was developed within the IETF standards process. Finally, Kerberos provides for secure authentication and message integrity, as well as data confidentiality and mutual authentication between a client and a server. The link for this article located at Network Magazine is no longer available. . Kerberos is an authentication protocol that lets clients and servers reliably verify each other's id. kerberos, authentication, protocol, clients, servers, reliably, verify, other's. . Anthony Pell

Calendar%202 Jul 05, 2001 User Avatar Anthony Pell Network Security
News Add Esm H340

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":1,"type":"x","order":2,"pct":50,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":50,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200