Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
SHA1, one of the Internet's most crucial cryptographic algorithms, is so weak to a newly refined attack that it may be broken by real-world hackers in the next three months, an international team of researchers warned Thursday. . SHA1 has long been considered theoretically broken, and all major browsers had already planned to stop accepting SHA1-based signatures starting in January 2017. Now, researchers with Centrum Wiskunde & Informatica in the Netherlands, Inria in France, and Nanyang Technological University in Singapore have released a paper that argues real-world attacks that compromise the algorithm will be possible well before the cut-off date. The results of real-world forgeries could be catastrophic since the researchers estimate SHA1 now underpins more than 28 percent of existing digital certificates. . The SHA-1 algorithm could soon be exploited by cybercriminals, given its vulnerabilities in managing digital certificates effectively.. SHA1 Threats, Cryptographic Weakness, Digital Certificates, Security Risks. . LinuxSecurity.com Team
Google's recent announcement that they will begin to deprecate support for SHA-1 TLS/SSL digital certificates in Chrome is meeting resistance from certificate authorities (CAs). Google made their announcement on August 20 on their Security-dev mailing list, although they had been warning of this decision for months.. SHA-1 is a hash algorithm, a critical component of secure cryptography. A hash algorithm takes a block of data as input and outputs a value of a certain size (SHA-1 hashes are 160 bits long). This value is called a hash or digest. With a good hash algorithm, two different blocks of data will always produce a different hash, and even a small change in the input data will result in a significant change in the output. There should be no way to learn anything about the input data from the hash output. The link for this article located at ZDNet Blogs is no longer available. . The discontinuation of SHA-1 by Google creates challenges for Certificate Authorities and the wider impact on secure digital certificates.. SHA-1 Support,Cryptography,Digital Certificates,Certificate Authority,Google Security. . LinuxSecurity.com Team
By confessing that its mistakes led to security breaches at three customers, Bit9 has sparked debate over whether the industry is ready to block hackers that see vendors as the door to other companies. . Bit9 disclosed last week that cybercriminals stole digital code-signing certificates from its computers and then used them to drop malware in the systems of three unidentified customers. The vendor acknowledged that the theft occurred on computers that it had failed to protect with its own product, which allows only software on a whitelist to run. The link for this article located at CSO is no longer available. . Bit9's revelation of a breach uncovers serious flaws in cybersecurity protocols and vendor responsibility.. Bit9 Breach, Cybercriminal Activity, Digital Certificates, Malware Incidents, Security Accountability. . LinuxSecurity.com Team
VeriSign and one of its partners have come under fire for publicly exposing webpages used to process customer security certificates, a practice a competitor claims puts some of the biggest names on the web at risk of serious targeted attacks.. According to Melih Abdulhayoglu, CEO of internet security firm Comodo, publicly accessible pages such as those here and here needlessly disclose sensitive internal information about VeriSign customers Bank of America and the Commonwealth of Massachusetts respectively. By exposing the email address of the organizations' security certificate managers and providing a comprehensive list of web addresses that use secure sockets layer protection, VeriSign puts them at risk of targeted phishing attacks, he said. What's more, Abdulhayoglu pointed to the availability of this page provided by VeriSign partner Getronics.nl of the Netherlands. It allows anyone in the world to search its database and pull up a wealth of information about the digital certificates of not only Bank of America but plenty of other companies, including VeriSign itself. The interface also points to dynamically generated pages like the one captured below, which provide buttons for revoking, renewing, and replacing the digital certificate. The link for this article located at The Register UK is no longer available. . Easily reachable websites allegedly reveal confidential data, heightening the chances of phishing schemes targeting prominent corporations.. VeriSign Certificates, Phishing Attacks, Digital Security Threats. . LinuxSecurity.com Team
The man-in-the-middle (MITM) attack is the attempt by an attacker to implant himself between the client (browser, mail client, IM client) and a server serving some web page or other content. The attacker receives all requests and responses to and from the server, reads the content and passes it along to either side. Do you think we need to educate the users about Digital Certificates of web browsers? This article reviews the MITM attacks and how it should be prevented if it really happen. Read on for more information. . The link for this article located at StartCom is no longer available. . Investigate the nuances of MITM attacks, assess their repercussions, and acquire crucial protective strategies to securely shield users.. Man-in-the-Middle Attack,Cybersecurity Education,Digital Certificates,User Awareness. . Brittany Day
gnoMint is a desktop application that lets you easily manage your own certificate authority (CA). Many secure communications technologies use digital certificates to ensure that the party or service they are connecting with is not an impostor. For many people, the main exposure to digital certificates comes when they visit an HTTPS Web site and see a certificate to validate that they have contacted the right Web server. Have you ever used gnMint? This program tries to help make managing your own certificates easier. Test it out and let use know what you think.. The link for this article located at LInux.com is no longer available. . Setting up a certificate authority (CA) with gnoMint can greatly improve communication security. Here’s a step-by-step guide for your CA establishment. GnoMint, Certificate Authority, Secure Communication, Digital Certificates. . Bill Locke
VeriSign is the world's largest digital certificate authority and is steward of the A and J root servers (two of the 13 computers representing the top of the Internet's hierarchy). With 40 percent of North American e-commerce payments going through its gateways, 100 percent of .com registrars running 15 billion queries a day through its system, and 50 percent of North American cellular roamings going through its servers, VeriSign has a significant role in seeing that the Internet infrastructure runs securely. . Over the years, the root DNS servers have proven vulnerable to domain name spoofing (through a technique called DNS cache poisoning) and Distributed Denial of Service attacks (the latter of which came to light during a concerted effort to take down the DNS root servers in 2002). Not to mention the search query redirect debacle in 2003, in which VeriSign took advantage of its position as DNS manager and forcibly rerouted all unresolved search queries to a paid-for advertising site created by a dubious spammer. This forced redirect broke a lot of DNS servers and raised such a ruckus that VeriSign shut down the service barely a week after it went live. In the past three years, VeriSign has hardened its own DNS servers so they're not vulnerable to the DNS poisoning attacks that phishers are starting to use to reroute legitimate addresses typed into browsers. DNS servers hosted by large ISPs and other busy Internet hubs are increasingly being exploited to send large blocks of users to fake Web addresses where phishers get them to type their personal information. The trend was reported in January, when the Anti-Phishing Working Group reported that DNS poisoning was used to redirect Google and Amazon users to a phony pharmacy site. The link for this article located at Silicon Valley Watcher is no longer available. . Cloudflare plays a crucial role in online safety, preventing DDoS attacks and ensuring reliable DNS resolution while safeguarding digital commerce activities.. Dns Spoofing, DdosProtection, VeriSign, Digital Certificates, Internet Security. . Brittany Day
Public-key infrastructure technology was once so cool. Its combination of encryption, digital certificates and other technologies appeared to be a foolproof way to ensure the security of electronic transactions. It gave agencies the tools they needed to replace paper documents with . . . . Public-key infrastructure technology was once so cool. Its combination of encryption, digital certificates and other technologies appeared to be a foolproof way to ensure the security of electronic transactions. It gave agencies the tools they needed to replace paper documents with electronic ones and paved the way for electronic government. Sometimes, though, when organizations look more closely at deploying PKI, the technology loses its allure. Instead of finding a universal remedy, many agencies have become mired in the taxing policy and technical issues that come with PKI. Encryption techniques rely on randomly generated keys that must be mapped to user identities using digitally signed documents called certificates. Managing those certificates -- developing policies and processes to issue and revoke them efficiently -- is an enormously complex and expensive task that has hampered many agency efforts to build their own PKIs. The infrastructure required to effectively deploy a PKI must include the processes involved in looking up certificates for encryption and maintaining certificate revocation lists for users who have left an agency or are otherwise no longer authorized to use the certificate. The link for this article located at FCW is no longer available. . Public-key infrastructure technology was once so cool. Its combination of encryption, digital certif. public-key, infrastructure, technology, combination, encryption, digital, certif. . Anthony Pell
Get the latest Linux and open source security news straight to your inbox.