Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Despite the enormous success of SSL for securing web traffic, there has been little technical change in the way that SSL is used for secure HTTP in the ten years since SSL version 3 was introduced. Although it has been around since 1996, most browsers have continued to make connections compatible with the older SSL version 2 protocol. But now the major browser developers are aiming to drop SSL v2 completely; export-grade encryption ciphers are also to be dropped. SSL version 2 was supported by Netscape 1.0, back in 1994, and it was made obsolete by SSL version 3, published in 1996. But while SSL version 3 was soon widely supported — and over 97% of HTTPS sites also support its successor, TLS — most browsers have continued to make SSL-v2-compatible connections, in order to stay compatible. . The link for this article located at Netcraft.com is no longer available. . The link for this article located at Netcraft.com is no longer available.. despite, enormous, success, securing, traffic, there, little, technical, change. . Benjamin D. Thomas
Security developers representing four of the major browser firms have met up to discuss how to combat security threats. Techies working on Internet Explorer, Mozilla/FireFox and Opera teamed up with the folks from Konqueror to discuss how to combat security risks posed by phishing, aging encryption ciphers and inconsistent SSL Certificate practices. A surprising amount of consensus emerged through the informal meeting, hosted by Konqueror's George Staikos in Toronto last week. . All agreed to push ahead with plans to introduce stronger encryption protocols. "With the availability of bot nets and massively distributed computing, current encryption standards are showing their age," Staikos writes. "Prompted by Opera, we are moving towards the removal of SSLv2 from our browsers. IE will disable SSLv2 in version 7 and it has been completely removed in the KDE 4 source tree already." The link for this article located at SNPX is no longer available. . Web engineers collaborate to enhance security algorithms and tackle online fraud and cybersecurity risks.. Browser Security, Strong Encryption, Developer Collaboration, Phishing Defense, Cybersecurity Initiatives. . LinuxSecurity.com Team
Wi-Fi networks have, up until this point, been a bit like the Wild West: exciting, but difficult to control and keep safe. Now, a host of new management and security options are springing up as Wi-Fi penetrates corporate environments. Read on . . . . Wi-Fi networks have, up until this point, been a bit like the Wild West: exciting, but difficult to control and keep safe. Now, a host of new management and security options are springing up as Wi-Fi penetrates corporate environments. Read on to find out what's in store. As Wi-Fi hardware becomes a corporate standard, vendors are rolling out increasingly sophisticated management, security, and software development options. Some of the newer Wi-Fi products are designed to boost network management capabilities, offering features comparable to those for tried-and-true networking options like Ethernet. Vendors are offering software suites designed to hook wired networks into wireless networks seamlessly, integrating key wired functions into the Wi-Fi network and providing bandwidth-management and identity controls. Other next-generation enterprise Wi-Fi products are designed to quell ongoing security fears. Many vendors are moving away from the Wired Equivalent Privacy (WEP) standard, whose static, shared encryption keys might linger long enough to be cracked by hostile outsiders, and toward the Wi-Fi Protected Access (WPA) protocol. The link for this article located at IBM is no longer available. . Wi-Fi networks have, up until this point, been a bit like the Wild West: exciting, but difficult to . wi-fi, networks, until, point, exciting, difficult. . Anthony Pell
The Web's leading standards group proposed two recommendations for encrypting XML data and documents, a key development in the organization's push to standardize technologies crucial to Web services. . .. The Web's leading standards group proposed two recommendations for encrypting XML data and documents, a key development in the organization's push to standardize technologies crucial to Web services . The World Wide Web Consortium (W3C) released proposed recommendations for XML Encryption Syntax and Processing and Decryption Transform for XML Signature. Together, the protocols will let Web sites and services send and receive sensitive data confidentially. While methods already exist for encrypting XML documents, the W3C's proposed recommendations will make it possible to encrypt selected sections or elements of a document--for instance, a credit card number entered in an XML form. The Decryption Transform recommendation provides a way of determining what parts of a document were encrypted or decrypted at the time a party signed it. The proposed recommendation is crucial to letting different parties authenticate discrete sections of a document at different times. The link for this article located at ZDNet is no longer available. . The Web's leading standards group proposed two recommendations for encrypting XML data and documents. web's, leading, standards, group, proposed, recommendations, encrypting, documents. . LinuxSecurity.com Team
For years, voice, data, and just about all software-defined network services were called "virtual private networks" by the telephone companies. The current generation of VPNs, however, is a more advanced combination of tunneling, encryption, authentication and access control technologies and services used to carry traffic over the Internet, a managed IP network or a provider's backbone. . . .. For years, voice, data, and just about all software-defined network services were called "virtual private networks" by the telephone companies. The current generation of VPNs, however, is a more advanced combination of tunneling, encryption, authentication and access control technologies and services used to carry traffic over the Internet, a managed IP network or a provider's backbone. The traffic reaches these backbones using any combination of access technologies, including T1, frame relay, ISDN, ATM or simple dial access. VPNs use familiar networking technology and protocols. The client sends a stream of encrypted Point-to-Point Protocol (PPP) packets to a remote server or router, except instead of going across a dedicated line (as in the case of WANs), the packets go across a tunnel over a shared network. The general idea behind using this method, is that a company reduces the recurring telecommunications charges that are shouldered when connecting remote users and branch offices to resources in a corporation's headquarters. The most commonly accepted method of creating VPN tunnels is by encapsulating a network protocol (including IPX, NetBEUI, AppleTalk, and others) inside the PPP, and then encapsulating the entire package inside a tunneling protocol, which is typically IP, but could also be ATM or frame relay. This increasingly popular approach is called Layer 2 tunneling, because the passenger is a Layer-2 Tunneling Protocol (L2TP). The link for this article located at findvpn is no longer available. . Explore the ways contemporary VPNs leverage encapsulation, cryptography, and authorizationmechanisms to ensure safe data exchange.. VPN Technology, Secure Network, Encryption Protocols, Access Control, Tunneling Techniques. . Anthony Pell
Get the latest Linux and open source security news straight to your inbox.