Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Though encryption is a strong way to safeguard passwords, personal information, and other sensitive data, it can be confusing due to the acronyms and technobabble that surround the topic. Many encryption utilities--such as the BitLocker feature in Windows 7 Ultimate, or the Rohos Mini Drive utility for protecting info on a thumb drive--are available. . But my favorite tool covers all the bases: It's free, it's easy, it's effective, and it works on all major operating systems. TrueCrypt lets you create virtual encrypted drives. Versions are available for Windows, Mac OS X, and Linux; if you install it on several machines running different OSs, you can open your encrypted files from a network share, thumb drive, or other shared storage device. The tool has plenty of advanced options, but the simplest approach--and the one I use--is to create an encrypted file protected by a strong password. When you open your TrueCrypt file, it acts as an additional hard drive with its own drive letter. You can interact with that virtual drive the same way that you might with any storage device: You open, save, drag, and drop files to and from the data store. TrueCrypt handles all the encryption and decryption in the background. When you close the encrypted file, the data is protected until you give the password to open it up once more. The link for this article located at Network World is no longer available. . Uncover a powerful and cost-free encryption solution that protects your confidential information on all primary platforms.. Reliable Encryption, Data Protection, TrueCrypt, Cross-platform Security, Sensitive Data Management. . LinuxSecurity.com Team
A new open-source operating system will come with the option of creating one-time, disposable virtual machines on the fly as a way to protect against malicious files.. Invisible Things Lab is creating these lightweight, throwaway VMs that work with traditional virtual machines in Qubes, the open-source, Xen-based OS it plans to release in beta later this summer. Qubes was architected to minimize the attack surface in the VM environment. Disposable VMs don't provide persistent storage and are launched on a per-document basis to open a PDF, PowerPoint, or music or video file, for instance, according to Joanna Rutkowska, founder and CEO of Invisible Things Lab. They provide a safe sandbox for opening a file or attachment: If a file opened by a disposable VM is infected, the only thing it can hurt is the throwaway VM itself, not any other applications or files. The disposable VM is clean, and its only purpose is for viewing the file, for instance; then it gets tossed away. "You still run your email client in a 'work' AppVM -- which is not disposable [because] you need to store your email client configuration, archived emails, your documents, etc. -- but you open attachments in disposable VMs," Rutkowska says. The link for this article located at Dark Reading is no longer available. . Phantom Tech unveils a groundbreaking operating system featuring ephemeral virtual machines, prioritizing secure document management and minimizing malware threats.. disposable virtual machines, open source os, file security, malware protection, isolation techniques. . LinuxSecurity.com Team
One of the best ways to protect sensitive computer data like credit card numbers and social security information is to use encryption software. Encryption software executes an algorithm that is designed to encrypt data in such a way that it cannot be recovered (decrypted) without access to the key. It is a main component of all aspects of file protection and computer communication. Files on hard drives and other removable media, email messages, and packets sent over computer networks can be made secure by encryption software.. For those of you who are interested, here's a list of well-known free and open source encryption software for Linux: TrueCrypt TrueCrypt is one of the most popular disk encryption tools around. It can encrypt and decrypt files on-the-fly (real-time) as needed without user intervention beyond entering the passphrase. TrueCrypt is capable of creating a virtual encrypted disk within a file or a device-hosted encrypted volume on either an individual partition or an entire storage device. It currently uses the XTS mode of operation but is backward compatible with older volumes. The link for this article located at Tech Source from Bohoi is no longer available. . Examine well-known free and open-source encryption solutions available for Linux to protect your confidential information securely.. Open Source Encryption, Linux Data Security, Disk Protection Tools. . LinuxSecurity.com Team
Deleting a file or reformatting a disk does not destroy your sensitive data. The data can easily be undeleted. That. The link for this article located at Ubuntugeek is no longer available. . The link for this article located at Ubuntugeek is no longer available.. deleting, reformatting, destroy, sensitive, easily. . LinuxSecurity.com Team
The pam_mount project lets you unlock an encrypted filesystem automatically when you log in. The same password used to log in is used as the key to unlock the encrypted filesystem, so you only need to type it once. Using this method, you can easily share a laptop and have only a single user's home directory unlocked and mounted when he logs in. And pam_mount can mount any filesystem, not just encrypted filesystems, so you can use it, for example, with an NFS share that you are interested in but which you might not like to leave mounted when you are not logged in. Did you ever wanted to know how to mount an encrypted filesystem automatically? This article will show you how.. The link for this article located at Linux.com is no longer available. . The link for this article located at Linux.com is no longer available.. pam_mount, project, unlock, encrypted, filesystem, automatically. . LinuxSecurity.com Team
Did you ever live with the fear that somebody may break into your system one day and steal your files? Well, those days are over, because you can now have an entire encrypted operating system. This was the first time I thought about taking the time to encrypt my whole operating system. Is encrypting the entire operating system worth the time? I feel encrypting persional information like phone numbers or bank information is important but most of what is on my operating system is things I don;t care that others see. However there is a way to encrypt the whole operating system with a Live CD to protect everything on a Linux users computer. . Did you ever live with the fear that somebody may break into your system one day and steal your files? Well, those days are over, because you can now have an entire encrypted operating system. For this setup, we used a freshly installed Ubuntu 7.04 with up-to-date software, nothing else installed. But the following guide is supposed to work with your actual Ubuntu 7.04 installation (no reinstall needed). Beware though: if you don't have the partitions setup like it The link for this article located at Softpedia News is no longer available. . Did you ever live with the fear that somebody may break into your system one day and steal your file. somebody, break, system, steal. . LinuxSecurity.com Team
File and mail security is easy to achieve with the right tools. PGP has proven itself the leader, and GnuPG is the tool of choice in the Linux world. Anyone who has read this column a while knows I'm a bit obsessive about crypto. With the speed of modern or even old processors, there's no reason that there should be any cleartext transmissions on the Internet at all. . . .. File and mail security is easy to achieve with the right tools. PGP has proven itself the leader, and GnuPG is the tool of choice in the Linux world. Anyone who has read this column a while knows I'm a bit obsessive about crypto. With the speed of modern or even old processors, there's no reason that there should be any cleartext transmissions on the Internet at all. Over the next few articles, I'll cover PGP (Pretty Good Privacy) and the GnuPG (GNU Privacy Guard) implementation of it. The link for this article located at WebProNews - Brian Hatch is no longer available. . Data protection and communication safety are enhanced with S/MIME and OpenPGP, which are prominent utilities in the Unix landscape for encrypted messaging.. File Security, Email Encryption, GnuPG Tools, PGP Implementation. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.