Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges

Alerts This Week
Warning Icon 1 488
Alerts This Week
Warning Icon 1 488

Stay Ahead With Linux Security News

Filter%20icon Refine news
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":0,"type":"x","order":4,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security news

We found 24 articles for you...
83

Protect Your Computer From DMA Attacks: Effective Prevention Techniques

Direct Memory Access (DMA) is a controller feature that has been available at least since the original IBM PC. It can be used by hackers to compromise your otherwise very heavily protected computer. Fortunately, there are steps you can take to minimize DMA-based attacks.. Although DMA attacks have been possible for decades, they gained notoriety in 2009 when researchers discovered DMA could be used to compromise Microsoft's BitLocker Drive Encryption technology, according to a Princeton University paper. The white-hat researchers were able to recover the private keys in several popular encryption systems, including BitLocker, FileVault, dm-crypt, and TrueCrypt, using off-the-shelf components. The link for this article located at InfoWorld is no longer available. . Although DMA attacks have been possible for decades, they gained notoriety in 2009 when researchers . direct, memory, (dma), controller, feature, least, since, origin. . LinuxSecurity.com Team

Calendar%202 Jun 17, 2014 User Avatar LinuxSecurity.com Team Hacks/Cracks
67

NSA's $80 Million Quantum Computing Project: A New Encryption Threat Ahead

The U.S. National Security Agency is attempting to build a new breed of supercomputer that theoretically could make short work of cracking most keys used for encrypted communications. . The project to build "a cryptographically useful quantum computer" is part of an $80 million research project called "Penetrating Hard Targets" that is taking place at a campus in College Park, Maryland, according to The Washington Post. The newspaper quoted documents it said were provided by former NSA contractor Edward Snowden. The link for this article located at Network World is no longer available. . The endeavor to construct 'a practically applicable quantum device for encryption' is part of a $100 million research program launched by the CIA.. Quantum Computing, Encryption Security, Cybersecurity Innovations. . LinuxSecurity.com Team

Calendar%202 Jan 03, 2014 User Avatar LinuxSecurity.com Team Cryptography
67

The Evolution Of Encryption In Enterprise Security And Data Protection

Back in the mid 70s, the use of encryption in enterprises was pretty much unheard of. Soon companies started to introduce some encryption in limited instances, such as encoders on communication lines to encrypt financial transactions. . A major breakthrough in the 90s saw the rapid expansion of the use of encryption with the arrival of asymmetric key encryption. And asymmetric encryption gave birth to two technologies that are now found in every corner of the enterprise: SSH and SSL. Critical company information and communications are protected by keys and certificates, and ineffective management of keys and certificates is the single biggest reason why companies experience data security breaches. And this applies not just too symmetric keys, but to all cryptographic keys, including private keys, asymmetric keys SSH keys, and certificates. Symmetric key technology is still widely used today for the protection of data at rest, and SSH and SSL are the de-factor standards for data in motion. In the case of symmetric key encryption there are no de-facto standards with the result that most storage vendors such as IBM, HP, EMC, etc., provide proprietary solutions. The link for this article located at SecurityPark is no longer available. . The 1990s saw encryption evolve significantly, driven by digital growth and data security needs, with AES introduction enhancing protection against cyber threats. Encryption Practices, Key Management, Data Protection, Enterprise Security. . LinuxSecurity.com Team

Calendar%202 Apr 14, 2011 User Avatar LinuxSecurity.com Team Cryptography
67

Exploring Encryption Trends And The Government Backdoor Controversy

Encryption is hot. Perhaps that's because its been around so long it's no longer seen as a black art. Or perhaps security issues have grown so prevalent, everyone wants some sort of encryption as a truly secure way of stopping the pain of those problems. . Indeed whatever the reason, encryption technologies seem to be behind a series of important security happenings of late. Here's a look at some of the more interesting happenings shaping encryption today: The backdoor question: The Obama administration wants e-mail service providers using encryption technology to leave in a backdoor so that the government can peer in if it needs to. According to a New York Times article this week, the Obama administration plans to submit to lawmakers next year that requires e-mail transmitters like BlackBerry, social networking Web sites like Facebook and direct "peer to peer" messaging like Skype The link for this article located at Network World is no longer available. . Data protection mechanisms are crucial in today’s safety concerns as debates surrounding vulnerabilities intensify.. Encryption Methods, Data Security Trends, Information Protection. . LinuxSecurity.com Team

Calendar%202 Sep 29, 2010 User Avatar LinuxSecurity.com Team Cryptography
67

Symantec Acquisition of PGP and GuardianEdge Strengthens Data Protection

Symantec will acquire encryption specialist PGP and endpoint security vendor GuardianEdge Technologies for $300 million and $70 million respectively, the company said today.. Both are privately held companies. Symantec said the deals are subject to regulatory approval but are expected to close by June. Symantec said the companies' combined specialties in standards-based encryption for e-mail, file systems, removable media and smartphones will complement its security offerings, such as its gateway, endpoint security and data-loss prevention software. Encrypting information offers a higher level of security in case data is lost or stolen. Symantec said it will standardize its products on PGP's key management platform, which allows administrators to centrally manage encryption tasks. That platform will be integrated into the Symantec Protection Center, a management console for its products. The link for this article located at Computer World is no longer available. . The acquisition of PGP and GuardianEdge by Symantec bolsters their encryption capabilities and fortifies endpoint security, leading to enhanced safeguards for sensitive data.. Symantec Acquisition, Encryption Specialist, GuardianEdge Technologies, Data Security, Key Management. . LinuxSecurity.com Team

Calendar%202 Apr 29, 2010 User Avatar LinuxSecurity.com Team Cryptography
81

Enhance Your Gmail Privacy with GPG Encryption Techniques Today

Perhaps Google's announcement that Chinese cyber attackers went after human rights activists' Gmail accounts has made you skittish about just how private your own messages are on the Google e-mail service. . Well, if you want to take a significant step in keeping prying eyes away from your electronic correspondence, one good encryption technology that predates Google altogether is worth looking at. It's called public key encryption, and I'm sharing some instructions on how to get it working if you want try it. Unfortunately, better security typically goes hand in hand with increased inconvenience. But some human rights activists who used Gmail right now likely wish they'd put up with a little hardship to help keep hackers at bay. I'm not going so far as to recommend you use e-mail encryption, but I think this is a good time to take a close look at it. Specifically, I'll show here how to use a collection of free or open-source software packages: GPG, or GNU Privacy Guard, Mozilla Messaging's Thunderbird e-mail software, and its Enigmail plug-in. But first, some background about how it works. The link for this article located at CNET is no longer available. . GPG encryption acts as a powerful protector for your email, enhancing privacy and shielding against cyber threats through asymmetric encryption methods. GPG Encryption, Email Security, Mozilla Thunderbird, Enigmail Plugin, Cyber Protection. . LinuxSecurity.com Team

Calendar%202 Jan 14, 2010 User Avatar LinuxSecurity.com Team Privacy
78

ZoneAlarm Extreme Security 2010: Enhanced Data Protection with AES

Network security firm Check Point today launched a new version of its consumer security suite designed specifically to meet the increasingly sophisticated security needs of small and home business users.. ZoneAlarm Extreme Security 2010 features new 256-bit AES hard disk encryption, giving users greater peace of mind if their laptop is lost or stolen. According to the vendor, around three quarters of ID theft cases result from lost or stolen devices. ZoneAlarm. Norton Security 2021 implements advanced phishing protection to safeguard personal information for enterprises.. ZoneAlarm Extreme Security, AES Encryption, Data Protection, SMB Security. . LinuxSecurity.com Team

Calendar%202 Sep 02, 2009 User Avatar LinuxSecurity.com Team Vendors/Products
67

Seagate Momentus 5400 FDE.2 Drives Enhance Security With Biometrics

Fremont, Calif.-based ASI Computer Technologies will start selling computers equipped with Seagate's Momentus 5400 FDE.2 drive next month, Seagate said in a statement. The computers, called ASI C8015, will be sold through a number of ASI's partners, including Newegg.com, PowerNotebooks.com and ZipZoomfly.com, an ASI representative said. . In addition to an 80GB Seagate drive, the ASI machine will feature a fingerprint reader, 15.4-inch display, Intel Core 2 Duo Mobile 2.0GHz processor, Nvidia graphics with 256MB memory, 1GB RAM and a DVD rewritable drive, according to ASI. The price is expected to be about $2,150. The Seagate drives are equipped with the company's new "DriveTrust" technology, which the company promotes as a simpler way to safeguard data stored on laptops. The encryption technology is designed to make life tougher for computer thieves and to prevent embarrassing breaches. ASI is a small player among notebook makers. It ships "whitebook" computers that don't carry a name brand and are sold by resellers who sometimes put their own names on the hardware. The link for this article located at ZD Net is no longer available. . In addition to an 80GB Seagate drive, the ASI machine will feature a fingerprint reader, 15.4-inch d. fremont, calif, -based, computer, technologies, start, selling, computers, equipped, seagate's. . LinuxSecurity.com Team

Calendar%202 Mar 13, 2007 User Avatar LinuxSecurity.com Team Cryptography
News Add Esm H340

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":0,"type":"x","order":4,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200