Alerts This Week
Warning Icon 1 914
Alerts This Week
Warning Icon 1 914

Stay Ahead With Linux Security News

Filter%20icon Refine news
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":555,"type":"x","order":1,"pct":78.72,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.26,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.82,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.2,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security news

We found -4 articles for you...
79

Linux 6.9 CoCo VMs Panic on Broken RdRand RNG: Security Impact

A significant change has been merged into the x86 fixes for Linux 6.9, requiring the seeding of RNG (Random Number Generation) with RdRand for CoCo (Confidential Computing) environments. The change focuses on CoCo virtual machines , designed to be as isolated as possible, assuming the VM host is untrusted. RdRand is critical as a hardware random number generator instruction for entropy to guest VMs. Security expert and WireGuard developer Jason Donenfeld authored this change. . What Changes Have Been Made? What Are the Implications for Confidential Computing? CoCo VMs will now panic if RdRand is broken, ensuring that the VMs do not continue to boot with limited or no entropy, which previously led to incomplete random number generation. Consequently, the change asserts that without proper seeding through RdRand, most cryptography within the CoCo VM will be compromised, which challenges the entire concept of confidential computing. RdRand is crucial in confidential computing and has the potential to impact Linux environments significantly. This move to require the seeding of RNG with RdRand for CoCo environments signifies a significant shift in the approach to handling security and entropy in virtual machines. One intriguing aspect of this change is the potential consequences of not seeding the RNG with RdRand, particularly in CoCo environments. It raises questions about how this change may affect the overall security posture of the Linux 6.9 release and whether it introduces any new vulnerabilities. Furthermore, the challenges posed by the existing threat model for CoCo must be acknowledged, where the VM host is considered untrusted and potentially adversarial. This prompts further consideration of how this requirement shapes the security assumptions and threat mitigation strategies for such environments. From a long-term perspective, this change may shift how Linux administrators and security professionals approach the design and deployment of CoCo environments. It prompts admins toconsider how this requirement aligns with their current security practices and whether it necessitates any adjustments in their security protocols. The implications of this change on the broader Linux and open-source security landscape also merit attention. As Linux 6.9 progresses, monitoring any feedback, challenges, or unforeseen impacts resulting from this requirement would be valuable. This requires a collective effort from the community to assess the practical implications of the change and provide feedback for refining its implementation. This change reminds security practitioners of the dynamic nature of security technologies and the continuous evolution of best practices. It urges them to stay informed about foundational changes and adapt their security strategies to align with emerging ecosystem requirements. Our Final Thoughts on These Changes in Linux 6.9 This pivotal change reverberates across the Linux and open-source security domains. By critically examining the implications of this requirement, security practitioners are equipped to navigate the evolving landscape of confidential computing and the associated security considerations in virtualized environments. . If RdRand fails, CoCo VMs might crash, jeopardizing entropy and cryptographic functions within Linux 6.9 secure contexts.. Confidential Computing, Random Number Generation, CoCo VMs, Linux Security. . Dave Wreski

Calendar%202 Apr 08, 2024 User Avatar Dave Wreski Security Projects
News Add Esm H340

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":555,"type":"x","order":1,"pct":78.72,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.26,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.82,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.2,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here