Explore top 10 tips to secure your open-source projects now. Read More

×
Alerts This Week
Warning Icon 1 483
Alerts This Week
Warning Icon 1 483

Stay Ahead With Linux Security News

Filter%20icon Refine news
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":0,"type":"x","order":4,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security news

We found 8 articles for you...
81

U.S. Court Ruling: NSA Can't Retain Phone Records Over Five Years

The secret Foreign Intelligence Surveillance Court has ruled against a U.S. government request that it be allowed to hold telephone metadata beyond the current five-year limit as it may be required as evidence in civil lawsuits that question the data collection.. The American Civil Liberties Union, U.S. Senator Rand Paul and the First Unitarian Church of Los Angeles are among those who have filed lawsuits challenging the phone records program, which came to light in June last year, after former National Security Agency contractor, Edward Snowden, revealed that the agency was collecting bulk phone records of Verizon customers in the U.S. The link for this article located at IT World is no longer available. . A hidden tribunal rejected the FBI's plea to retain email logs beyond three years, influencing surveillance strategies.. Phone Records Retention, NSA Surveillance Impact, Civil Liberties Concerns. . LinuxSecurity.com Team

Calendar%202 Mar 10, 2014 User Avatar LinuxSecurity.com Team Privacy
81

House Republicans Propose Mandatory User Data Tracking By ISPs

The House Republicans' first major technology initiative is about to be unveiled: a push to force Internet companies to keep track of what their users are doing.. A House panel chaired by Rep. F. James Sensenbrenner of Wisconsin is scheduled to hold a hearing tomorrow morning to discuss forcing Internet providers, and perhaps Web companies as well, to store records of their users' activities for later review by police. One focus will be on reviving a dormant proposal for data retention that would require companies to store Internet Protocol (IP) addresses for two years, CNET has learned. The link for this article located at CNET is no longer available. . House Republicans seek to mandate user data tracking by internet service providers, raising fears over privacy and potential security risks.. User Data Privacy, ISP Regulations, Data Retention Policy. . LinuxSecurity.com Team

Calendar%202 Jan 25, 2011 User Avatar LinuxSecurity.com Team Privacy
81

Investigating ISP Data Retention Policies And user Privacy Issues

Last Friday, 27B asked 10 of the nation's largest ISPs to clarify their data retention and sharing policies, in the wake of a report that ISPs were selling 'anonimized' user internet history logs to data firms and an ongoing drive by the Justice Department and some in Congress to require ISPs to hold that data for long periods of time. 'Anonymized' clickstreams can easily be used to rebuild a person's online life, especially given that search engine urls usually include the contents of a search. . The link for this article located at Wired.com is no longer available. . The sale of user data by ISPs highlights major privacy concerns as consumer awareness grows, pushing for stronger data protection regulations and transparency.. ISP Data Policies, User Data Privacy, Anonymized Internet History. . LinuxSecurity.com Team

Calendar%202 Mar 22, 2007 User Avatar LinuxSecurity.com Team Privacy
81

Privacy Insights and Data Management Strategies from Industry Leaders

During a recent panel discussion, Jennifer Mardosz, Qwest's (Q) chief privacy officer and corporate counsel, told the audience she was skeptical of congressional mandates laying out requirements for data retention. She argued that there was no need for legislative interference because "companies were already doing the right thing." Google (GOOG) CEO Eric Schmidt also addressed the privacy issue at another conference this month, noting that he was more afraid of government (U.S. or other) trying to get access to Google's data than an accidental release of confidential customer information. When asked why Google doesn't purge their search information, Schmidt replied that they didn't need to because security protections would make it difficult, if not impossible, to steal customer data. . Several other major companies have said something similar whenever the subject of confidential data comes up. The "right thing" that most of them are doing to protect our privacy is to trust their own security while retaining their options The link for this article located at Business Week is no longer available. . Businesses prioritize confidentiality by safeguarding their handling of sensitive information. Delve into perspectives from sector specialists.. Data Management, Privacy Concerns, Security Strategy. . LinuxSecurity.com Team

Calendar%202 Sep 07, 2006 User Avatar LinuxSecurity.com Team Privacy
82

Exploring How Access Logs Affect Privacy and Security Issues Today

When you use the Internet, a certain record of your activities is invariably created and - at least for a short time - retained by your Internet Service Provider. For example, when you establish an account with your ISP - whether it is AOL, Comcast, Verizon, Time-Warner, or any of thousands of ISPs you generally provide the ISP with your name, address, telephone number, and if it is a paid service, some form of payment - credit card, bank account, etc. The ISP will typically retain this account information, and will also keep records that associate this account information with any accounts that you create. Thus, while you think you are so clever creating the online persona "cyber-stud" the ISP knows that you are really a twenty nine year old permanent undergraduate engineering student living at home in your mother's basement. . This "real world" account information - associating a cyber persona with a real identity - is a gold mine for marketers, law enforcement agencies and the intelligence community, as they want to know who their customers or the users of online services really are. This information can be used for good or for evil. If there is an online pedophile or terrorist, one certainly wants the police to have the ability to, in close-to-real-time when necessary, be able to learn who these people are, and physically where they are as well. One would think that the police would need a subpoena or court order for this information, right? Well, not exactly. The link for this article located at is no longer available. . Digital footprints can expose personal data, merging online behaviors with real-life identities; this raises significant issues for privacy and safety in internet usage.. Access Logs, Data Retention, Internet Privacy. . Brittany Day

Calendar%202 Jun 12, 2006 User Avatar Brittany Day Government
81

Compliance Risks in Email Archiving Strategies: Insights from Experts

Mark Diamond, consultant with Contoural Inc., said a survey of clients showed 29% found email archiving for the long term less risky, in terms of compliance, than attempting to reduce data, while 21% thought deleting data on a regular basis was less risky. Forty-two percent answered that they are not sure. A convincing case for long-term retention, however, was found when Diamond offered insight into the inner workings of a lawyers mind in a presentation to Chicago's storage networking user group Wednesday morning. . One slide in the presentation contained a quote from an unnamed lawyer saying that his/her primary litigation strategy is first to send a letter to the lowest ranking member of a company's legal department announcing intentions to file suit. "We know it'll take at least a month for that letter to bubble up," the anonymous source said. "After 120 days, we actually file the suit and our first item of discovery is email dating from the time our initial letter was sent." By then, according to Diamond's source, most companies have moved data off primary systems and rotated backup tapes. The link for this article located at Search Security is no longer available. . The document emphasizes the importance of systematic email storage methods and outlines potential compliance challenges related to prolonged data preservation.. Email Management, Data Compliance, Legal Strategy. . LinuxSecurity.com Team

Calendar%202 May 24, 2006 User Avatar LinuxSecurity.com Team Privacy
81

Congress Considers Mandatory ISP Data Retention for User Privacy

It didn't take long for the idea of forcing Internet providers to retain records of their users' activities to gain traction in the U.S. Congress. Last week, Attorney General Alberto Gonzales, a Republican, gave a speech saying that data retention by Internet service providers is an "issue that must be addressed." Child pornography investigations have been "hampered" because data may be routinely deleted, Gonzales warned. Now, in a demonstration of bipartisan unity, a Democratic member of the Congressional Internet Caucus is preparing to introduce an amendment--perhaps during a U.S. House of Representatives floor vote next week--that would make such data deletion illegal. . . The legislature is considering compulsory data preservation for internet service providers, addressing the demands of authorities for access to user behavior information.. Data Retention, ISP Regulations, Internet Privacy. . LinuxSecurity.com Team

Calendar%202 May 01, 2006 User Avatar LinuxSecurity.com Team Privacy
74

Key Compliance Hurdles: Best Log Management Strategies for Sarbanes-Oxley

Companies are now finding that log management is a cornerstone best practice in their compliance efforts. Sarbanes-Oxley 404 Internal IT Control requirements infer rigorous end-to-end Log Management and Archival. Net Report helps companies face this issue. . What is the most challenging Sarbanes-Oxley issue facing Enterprises today? Nerys GRIVOLAS, Regulatory Consultant at Net Report SAS How to ensure end-to-end log lifecycle management to ensure secure audit trails… Montpellier, France, October 5, 2005, Net Report SAS. Companies are now finding that log management is a cornerstone best practice in their compliance efforts. Sarbanes-Oxley 404 Internal IT Control requirements infer rigorous end-to-end Log Management and Archival. Driven by compliance, security and risk mitigation, enterprises of all kinds are standardizing and automating their log management processes – from storage and reporting to proactive alerting on security and other issues. The automation, search and analysis of all this data can be characterized as ‘log intelligence’ for executives, and provides compliance conformance and risk mitigation for an enterprise. A combination of compliance and risk mitigation needs are driving these industries away from disparate, homegrown log management, or niche security event management. The new challenge is about capturing all logs, from any device, and then systematically storing, analysing, reporting and alerting about them in seconds. The market's move towards industry standard log data management, storage and reporting, and the global adoption of these technologies to address compliance and risk mitigation is an enormous opportunity for Net Report and a keystone to meeting the challenge facing companies seeking Sarbanes-Oxley compliance. Net Report’s Solution to meeting the challenge for Compliance, Risk Mitigation & Business Continuity A veritable Business Solution, Net Report's solutions meet every angle of your log exploitation issues. Net Report comprehensivelycovers the entirety of a business's needs in the following realms: Reporting. Providing a Dynamic Security and Activity Dashboard. Archiving your Information Security data. Centralizing Logs. Correlating events and sending real-time alerts. International Regulatory Conformity. Net Report Monitoring Center Version 4.0 Net Report has recently announced the coming release of Net Report Monitoring Center Version 4.0 scheduled for early October 2005. Click the link below for more information: . This new version delivers high-performance data log capture, long-term storage, dashboard reporting and alerts. A unique real-time log data collection and analysis solution. Net Report captures all log data from almost any security device or application, archives it (for over seven years and more), ensuring that companies have all the information needed for an audit or investigation. Net Report’s Solution provides a simple, automated solution for secure, long-term log data retention - automating compliance requirements. Net Report is easy-to-install, standards-based, and fully scalable, enabling companies to deploy immediate log analysis capabilities across a globally distributed network. Net Report’s Regulatory Consulting Net Report helps companies meet the requirements in the Sarbanes-Oxley Act sections 302, 401, 404, 409, 802, 1102. Net Report is mapped from an IT Internal Control Compliance optic with the following standards frameworks PCAOB (Auditing Standards II), SEC 1934, the Turnbull Report published by the Institute of Chartered Accountants in England & Wales, COSO, COBIT, ISO 17799. Net Report offers Regulatory Consultancy to help companies become aware of the regulatory environment surrounding Sarbanes-Oxley along with the issues for those European Companies seeking compliance with other regulations such as Basel II and the Loi de Sécurité Financière (LSF). Click the link below for more information: About Net Report Net Report, a log intelligence leader,provides enterprise-class log lifecycle management platform for high-performance log data archival, aggregation, analysis, reporting and alerting. With this highly-scalable and easy-to-install platform, Net Report addresses the compliance, risk mitigation, security, and business continuity needs of the most demanding enterprises. For more information, please visit Contact Mrs Nerys Grivolas Regulatory Consultant, Net Report SAS e-mail This email address is being protected from spambots. You need JavaScript enabled to view it. Tel: +33 (0)46 784 4800 Fax: +33 (0)46 784 4811 The link for this article located at Nerys Grivolas is no longer available. . The Sarbanes-Oxley Act enforces strict rules on public companies to assure transparency in financial reporting, facing challenges like data documentation and integrity. log Management Solutions, Sarbanes-Oxley Compliance, Log Data Retention, Risk Mitigation, IT Control Practices. . Brittany Day

Calendar%202 Oct 07, 2005 User Avatar Brittany Day Network Security
News Add Esm H340

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":0,"type":"x","order":4,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200