Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Researchers have decomposed a 768-bit number with 232 decimal places into its two prime factors and published a paper with their results. The number is the string released as "RSA-768" under the now defunct RSA Challenge. As a result, RSA encryptions with 768-bit keys must, from now on, be considered cracked. . It took the team of researchers from Switzerland, Japan, Germany, France, the US and the Netherlands about two and a half years to perform the factorisation. The first step of the calculation, polynomial selection, required half a year on a cluster consisting of 80 PCs, while the second and considerably more labour-intensive sieving step took about two years on a cluster of several hundred computers. According to the researchers, a single Opteron processor with 2 Gbytes of RAM would have needed about 1,500 years to complete the sieving step. The link for this article located at H Security is no longer available. . It took the team of researchers from Switzerland, Japan, Germany, France, the US and the Netherlands. researchers, decomposed, 768-bit, number, decimal, places, prime, factors. . LinuxSecurity.com Team
Security researchers have developed a new approach to breaking the RSA algorithm that creates new problems for the development of effective rights management software. Cryptoanalysts already known the time taken to make different calculations using the same encryption key might, in theory at least, give attackers code-breaking clues in much the same way electro-magnetic leakage or power fluctuations can be used in so-called "side-channel" attacks on secure systems. The new so-called Branch Prediction Analysis (BPA) attack is a refinement on this approach that makes code breaking feasible on commodity PCs instead of expensive high-performance kit. . The link for this article located at TheRegister.co.uk is no longer available. . The link for this article located at TheRegister.co.uk is no longer available.. security, researchers, developed, approach, breaking, algorithm, creates. . LinuxSecurity.com Team
The omnipresent SSL (Secure Socket Layer) which is supposed to offer a secure channel to transmit sensitive data across the Internet, may actually be opening up a gaping hole in your network security. This was the surprising bit of information was . . . . The omnipresent SSL (Secure Socket Layer) which is supposed to offer a secure channel to transmit sensitive data across the Internet, may actually be opening up a gaping hole in your network security. This was the surprising bit of information was delivered to the attending bankers on the second day of bank.net event here in Mumbai by Udi Segall, Marketing Product Manager Radwell. According to Segall, SSL does two things - one it authenticates the identity of the server, and optionally the client as well. And second, it creates a secure tunnel between the client and the server. The problem here is that once a secure link is created, it is assumed that the client connecting to the server is genuine (because he has been able to successfully login). Since the SSL traffic is encrypted, it cannot be analyzed by IDS and IPS (Intrusion Detection Systems and Intrusion Prevention System) system. The link for this article located at CXO Today is no longer available. . TLS may not offer the protection it once did, possibly revealing weaknesses in digital communications. Stay informed about the dangers!. SSL Security Risks, Network Encryption, Intrusion Detection. . Anthony Pell
Security managers need to be aware of the inherent weaknesses in wireless technology, which although similar to those in wired networking, add a few more headaches. According to security professionals, the IEEE wireless protocol 802.11 not only shares unlicensed frequencies with . . . . Security managers need to be aware of the inherent weaknesses in wireless technology, which although similar to those in wired networking, add a few more headaches. According to security professionals, the IEEE wireless protocol 802.11 not only shares unlicensed frequencies with other devices, including consumer-based Bluetooth devices, cordless phones, and baby monitors - which can, and do, interfere with each other - it also has weaknesses in its encryption structure. The link for this article located at VNUNET.com is no longer available. . Network administrators should acknowledge the fundamental vulnerabilities of mobile systems to safeguard against cyber intrusions successfully.. Wireless Security, Threat Mitigation, Encryption Solutions, Network Management. . Anthony Pell
The Czech group which recently found vulnerabilities in OpenPGP has released two documents outlining the attack. . .. The Czech group which recently found vulnerabilities in OpenPGP has released two documents outlining the attack : A PowerPoint presentation A PDF outlining the vulnerablity and the attack Both are a good read. I highly recommend them. . The Czech group which recently found vulnerabilities in OpenPGP has released two documents outlining. czech, group, which, recently, found, vulnerabilities, openpgp, released, documents, outlining. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.