Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
Monday a group of cryptographers and security experts released a major paper outlining the risks of government-mandated back-doors in encryption products: Keys Under Doormats: Mandating insecurity by requiring government access to all data and communications, by Hal Abelson, Ross Anderson, Steve Bellovin, Josh Behaloh, Matt Blaze, Whitfield Diffie, John Gilmore, Matthew Green, Susan Landau, Peter Neumann, Ron Rivest, Jeff Schiller, Bruce Schneier, Michael Specter, and Danny Weitzner.. Abstract: Twenty years ago, law enforcement organizations lobbied to require data and communication services to engineer their products to guarantee law enforcement access to all data. After lengthy debate and vigorous predictions of enforcement channels going dark, these attempts to regulate the emerging Internet were abandoned. In the intervening years, innovation on the Internet flourished, and law enforcement agencies found new and more effective means of accessing vastly larger quantities of data. The link for this article located at Schneier on Security is no longer available. . Government-mandated back doors in encryption jeopardize data security and privacy, increasing risks of exploitation by malicious actors and eroding trust.. encryption risks,data security,backdoor access,cryptography concerns,security measures. . LinuxSecurity.com Team
What if everyone one day took everything that "could" be used "maliciously" and with "evil intent" (even though there are many benefits to these things) and just deemed them illegal right off the bat? A hacksaw could be used to cause bodily harm (in horror movies mostly), yet it's a valuable tool for carpenters - why should there be an evaluation on its intent? In the following article, see how the government may be deeming "dual use" security tools illegal before they are even used - authors of these tools may be prosecuted if they intended the tool to be used illegally. . They revised their proposals a bit The link for this article located at Light Blue Touchpaper is no longer available. . They revised their proposals a bit The link for this article located at Light Blue Touchpaper is no . everyone, everything, 'could', 'maliciously', 'evil, intent'. . Brittany Day
This is the third part of a four-part series looking at U.S. information security laws and the way those laws affect security professionals. This installment begins the discussion of information security in the public sector. Government's involvement with information security takes . . . . This is the third part of a four-part series looking at U.S. information security laws and the way those laws affect security professionals. This installment begins the discussion of information security in the public sector. Government's involvement with information security takes place in two unique contexts: criminal justice and national defense. (Of course, government agencies also have information security concerns that are analogous to those of private industry, which were considered in the first two articles in this series.) In this installment, we will look at the basics of the criminal information security law. As we discussed in the first article in this series, the Computer Fraud and Abuse Act, 18 U.S.C.§ 1030 (the "CFAA") is the primary computer crime statute in the United States. The CFAA imposes criminal liability [1] for: The link for this article located at SecurityFocus is no longer available. . U.S. information security laws have transformed operations for public sector and criminal justice professionals, focusing on data confidentiality amid increasing cyber threats. Information Security, U.S. Laws, Public Sector Security, Criminal Justice Oversight. . Anthony Pell
The Senate easily passed a measure Thursday expanding a powerful surveillance law, used in spy and terrorism investigations, to allow U.S. agents to wiretap lone foreigners who can't be linked to a terror organization or government. Currently, U.S. law enforcement . . . . The Senate easily passed a measure Thursday expanding a powerful surveillance law, used in spy and terrorism investigations, to allow U.S. agents to wiretap lone foreigners who can't be linked to a terror organization or government. Currently, U.S. law enforcement officers can get warrants authorizing intelligence-gathering wiretaps from a secret court, but only if they can establish a reasonable belief the target is an "agent of a foreign power" or group. The bill, which passed 90 to 4, would amend the 1978 Foreign Intelligence Surveillance Act to remove that requirement. As used in the act, the term "agent of a foreign power" includes those controlled by governments, political organizations or terrorist groups. But lawmakers feared that this requirement could hinder the FBI when its investigators can't make such a link to a known terror organization or a foreign government. The link for this article located at SecurityFocus is no longer available. . The House expanded a critical privacy measure, simplifying monitoring protocols for overseas individuals lacking ties to terrorism.. wiretap authority, Foreign Intelligence Surveillance Act, surveillance legislation. . Anthony Pell
Created in response to last week's bloody attacks, the draft "Mobilization Against Terrorism Act" (MATA) rewrites laws dealing with wiretapping, eavesdropping and immigration. The draft, intended to increase prosecutors' courtroom authority, also unleashes the government's Echelon and Carnivore spy systems. President . . . . Created in response to last week's bloody attacks, the draft "Mobilization Against Terrorism Act" (MATA) rewrites laws dealing with wiretapping, eavesdropping and immigration. The draft, intended to increase prosecutors' courtroom authority, also unleashes the government's Echelon and Carnivore spy systems. President Bush sent his anti-terrorism bill to Congress late Wednesday, launching an emotional debate that will force U.S. politicians to choose between continued freedom for Americans or greater security. The link for this article located at Wired is no longer available. . Created in response to last week's bloody attacks, the draft 'Mobilization Against Terrorism Act' (M. created, response, week's, bloody, attacks, draft, 'mobilization, against, terrorism. . LinuxSecurity.com Team
The House of Representatives quietly approved legislation designed to bolster computer security at civilian federal agencies. By voice vote, the House passed the Computer Security Enhancement Act, which was introduced in 1999 by House Science Committee Chairman James Sensenbrenner, R-Wis., in . . . . The House of Representatives quietly approved legislation designed to bolster computer security at civilian federal agencies. By voice vote, the House passed the Computer Security Enhancement Act, which was introduced in 1999 by House Science Committee Chairman James Sensenbrenner, R-Wis., in response to growing concerns about hacker attacks on federal agencies. Among other things, H.R. 2413 would require the National Institute of Science and Technology to serve as a computer security consultant for other federal civilian agencies. In that role, NIST would advise agencies on what "off-the-shelf" computer security products met with the government's approval. The link for this article located at Computer User is no longer available. . Congress approved a bill aimed at enhancing cybersecurity across government departments, strengthening safeguards against digital attacks.. Federal Regulation, Computer Security Act, Cybersecurity Initiative, Federal Agencies. . Anthony Pell
Oscar S. Cisneros writes: "A new government-approved standard for telecommunications equipment violates the Fourth Amendment's prohibition against unreasonable searches and seizures, critics say. The standard, released in updated form last week by the Telecommunication Industry Association, instructs telecommunications hardware manufacturers on . . . . Oscar S. Cisneros writes: "A new government-approved standard for telecommunications equipment violates the Fourth Amendment's prohibition against unreasonable searches and seizures, critics say. The standard, released in updated form last week by the Telecommunication Industry Association, instructs telecommunications hardware manufacturers on how to build their equipment so that it complies with a federal wiretap law passed by Congress in 1994." In today's day and age where we are all prone to our traffic being sniffed an issue like this should be important to all of us. The link for this article located at Wired News is no longer available. . Oscar S. Cisneros writes: 'A new government-approved standard for telecommunications equipment viola. oscar, cisneros, writes, government-approved, standard, telecommunications, equipment, viola. . Anthony Pell
Get the latest Linux and open source security news straight to your inbox.