Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
Google revealed that it recently discovered a bug that caused a subset of its enterprise G Suite customers to have their passwords stored in an unhashed — albeit encrypted — form for about 14 years. . “This is a G Suite issue users only — no free consumer Google accounts were affected — and we are working with enterprise administrators to ensure that their users reset their passwords,” Google said in a blog post disclosing the security lapse. The company failed to specify exactly how many customers were affected this way. However, it went on to stress that it didn’t find any evidence of improper access. The link for this article located at The Next Web is no longer available. . “This is a G Suite issue users only — no free consumer Google accounts were affected — and we . google, revealed, recently, caused, subset, enterprise, suite. . LinuxSecurity.com Team
Sony Co., in a blog post Thursday, announced that every single important record from the breached credit card database last week was encrypted. But, security experts say it was not enough to fully protect the Sony PlayStation users and that consumer data might still be used by the hackers.. On Friday, reports had been released saying the hackers may have obtained the consumer. On Friday, reports had been released saying the hackers may have obtained the consumer. thursday, announced, every, single, important, record, breached. . LinuxSecurity.com Team
A long-known but little-discussed vulnerability in the modern Internet's design was highlighted yesterday by a report that hackers traced to Iran spoofed the encryption procedures used to secure connections to Google, Yahoo, Microsoft, and other major Web sites.. This design, pioneered by Netscape in the early and mid-1990s, allows the creation of encrypted channels to Web sites, an important security feature typically identified by a closed lock icon in a browser. The system relies on third parties to issue so-called certificates that prove that a Web site is legitimate when making an "https://" connection. The problem, however, is that the list of certificate issuers has ballooned over the years to approximately 650 organizations, which may not always follow the strictest security procedures. And each one has a copy of the Web's master keys. The link for this article located at CNET is no longer available. . An investigation uncovers that cybercriminals capitalized on a longstanding vulnerability in internet security protocols, endangering numerous prominent platforms.. encryption flaws, web security issues, cyber threats. . LinuxSecurity.com Team
Flaws in the way web applications handle encrypted session cookies might leave online banking accounts open to attack. The security risk stems from a cryptographic weakness in web applications developed using Microsoft's ASP.Net framework. . ASP.Net uses the US government-approved AES encryption algorithm to secure the cookies generated by applications during online banking sessions and the like. However implementation flaws in how ASP.NET handles errors when the encrypted data in a cookie has been modified give clues to a potential attacker that would allow him to narrow down the possible range of the keys used in an online banking session. Attacks based on this weakness might allow a hacker to decrypt sniffed cookies or forge authentications tickets, among other attacks. The link for this article located at The Register UK is no longer available. . Weaknesses in ASP.Net’s management of encrypted cookies could potentially put online banking at risk of cyber threats.. AES Encryption, Online Banking Threats, Application Security, Cybersecurity Risks, Cryptographic Vulnerabilities. . LinuxSecurity.com Team
Snoopers on the Internet could decode sensitive e-mail messages simply by tricking recipients into hitting the reply button, computer security researchers warned Monday. The flaw affects software using Pretty Good Privacy, the most popular tool for scrambling. . .. Snoopers on the Internet could decode sensitive e-mail messages simply by tricking recipients into hitting the reply button, computer security researchers warned Monday. The flaw affects software using Pretty Good Privacy, the most popular tool for scrambling e-mail. Researchers at Columbia University and Counterpane Internet Security Inc. found that someone intercepting an encrypted message could descramble it by repackaging the message and passing it on to the recipient. The message would appear as gibberish, possibly prompting the recipient to request a resend. The link for this article located at DigitalMass is no longer available. . Snoopers on the Internet could decode sensitive e-mail messages simply by tricking recipients into h. snoopers, internet, decode, sensitive, e-mail, messages, simply, tricking, recipients. . LinuxSecurity.com Team
A cryptologist who discovered several gaping holes in the international standard governing the design of wireless network devices and the encryption algorithm meant to protect those networks last week detailed vulnerabilities that could be leaving corporate systems open to hackers.. . .. A cryptologist who discovered several gaping holes in the international standard governing the design of wireless network devices and the encryption algorithm meant to protect those networks last week detailed vulnerabilities that could be leaving corporate systems open to hackers. Ian Goldberg, a cryptologist at Montreal-based security and privacy software developer Zero-Knowledge Systems Inc., along with researchers at the University of California, Berkeley, uncovered flaws in the IEEE 802.11 standard. Goldberg published a paper () on the findings earlier this year and made one of his first public appearances about it at the annual Black Hat hacker conference here. The link for this article located at Computer World is no longer available. . A cryptologist who discovered several gaping holes in the international standard governing the desig. cryptologist, gaping, holes, international, standard, governing, desig. . Anthony Pell
A GERMAN RESEARCHER has discovered a major security flaw in the latest versions of the PGP free e-mail encryption software that could allow someone to read another person's encrypted e-mail if he or she was able to intercept it. . . .. A GERMAN RESEARCHER has discovered a major security flaw in the latest versions of the PGP free e-mail encryption software that could allow someone to read another person's encrypted e-mail if he or she was able to intercept it. The flaw, discovered by Ralf Senderek and reported Thursday, highlights the technical difficulties in creating key-recovery systems, said Bruce Schneier, CTO of Counterpane Internet Security and author of Applied Cryptography. Schneier, and a group of other cryptographers predicted the exact type of problem that PGP now faces in a paper they wrote in 1997, when the U.S. government was pushing for key escrow, raising the ire of civil libertarians and many software firms in the process. The link for this article located at InfoWorld is no longer available. . A significant vulnerability has been revealed in the newest PGP email encryption application, exposing users to potential threats.. PGP Encryption, Email Security, Encryption Flaw. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.