Alerts This Week
Warning Icon 1 659
Alerts This Week
Warning Icon 1 659

Stay Ahead With Linux Security News

Filter Icon Refine news
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security news

We found 23 articles for you...
82

Exploring NSA Encryption Insights and Strategies for Collaboration

Does business really have anything to learn from government? I pondered this notion, listening to Margaret Salter, one of the top encryption policy experts at the National Security Agency, on IE Radio this week.. This normally secretive agency within the Department of Defense is flirting with more openness and a higher public profile. More than once I heard, "We don't generally do a lot of things like this" from NSA personnel while trying to arrange a time for Salter to appear on IE Radio. Salter is technical director of the vulnerability analysis and operations group within the NSA's Information Assurance Directorate. But since she also spoke at the RSA conference in San Francisco a few months ago, it's clear that agency personnel are getting out more, and that's good news because they have an interesting story to tell. And while not overly generous on details for obvious national security reasons, what they do choose to share may help government and industry learn from each other, as Salter stated this week. For instance, take the NSA insistence on two types of encryption on any communication, an article of faith in Agency orthodoxy. In a series of crypto-interoperability trials that Salter oversees, one uses Transport Layer Security (TLS) on both the client and browser, along with digital certificates; another uses a WPA2 client, using Extensible Authentication Protocol (EAP) TLS, passing X.509 certificates, with client devices running IPSec. The link for this article located at Internet Evolution is no longer available. . This normally secretive agency within the Department of Defense is flirting with more openness and a. business, really, anything, learn, government, pondered, notion, listening. . Alex

Calendar 2 May 21, 2010 User Avatar Alex Government
77

Cyber Security KTN Roadmap: Product Inception Security Strategy

The government-backed Cyber Security Knowledge Transfer Network (KTN) launched a new roadmap today intended to kick-start an international effort to engineer security into products from their inception. Building in Information Security, Privacy and Assurance (PDF) aims to overcome the siloed approach to security taken by many countries, according to Cyber Security KTN director Nigel Jones. Security at the core is extremely important. Trying to "bolt on" security, as so many distributions do, often leads to something less than really secure. Do you agree?. "We are trying to get international co-operation on building security in from the start, because the problem still remains and it is still unclear what the best way to do it is," he said. The roadmap covers how industry, governments and consumers can improve security and privacy, and includes a number of principal recommendations. The link for this article located at vnunet is no longer available. . Join a worldwide initiative to weave security into the foundational stages, promoting stronger privacy and trust.. Product Security, Information Assurance, Privacy Management, Security Initiative. . LinuxSecurity.com Team

Calendar 2 Apr 30, 2009 User Avatar LinuxSecurity.com Team Server Security
82

DOD Directive 8570.1: Training Standards For Contractors' Compliance

Contractors who are serious about getting Defense Department contracts should make sure now that their employees who have information assurance roles meet the standards set by DOD Directive 8570.1, according to panelists who spoke this morning at an Information Technology Association of America event. "There's not a downside to contractors being certified," said Phyllis Scott, president of training firm TTSC. Contracts will require it, and contractors who are already certified will have an immediate advantage, she said. . DOD approved the directive The link for this article located at Federal Computer Week is no longer available. . The Department of Defense's (DOD) security training requirements for contractors are critical for maintaining compliance and expanding business prospects.. DOD Security Training, Contractor Compliance, Information Assurance. . Brittany Day

Calendar 2 Nov 17, 2006 User Avatar Brittany Day Government
82

Essential Cyber Security Practices for Government Effectiveness

Ronald Reagan once famously said: "The nine most terrifying words in the English language are, 'I'm from the government and I'm here to help.'" Inside the government itself, the most terrifying words in the English language may be: "The information security office is here to facilitate your office's goals and objectives." . So says a new book, Larstan's The Black Book on Government Security (publication date October 2006), intended to introduce managers and IS professionals to the key cyber security challenges faced by all levels of government. The book notes that while awareness of the importance of cyber security is growing at all levels of government, awareness is one thing; action another. One of government's biggest challenges is to transition from a general awareness of cyber security to concrete implementation of good cyber security practices. Ensuring cyber security issues are championed by leadership, embraced by business managers, implemented by users and understood by all is like herding cats, it says, especially when cyber threats are very difficult to understand. . Larstan's "The Black Book on Government Security" delves into cyber security challenges for government entities, stressing adaptable risk management and proactive strategies.. Cyber Security Awareness, Government Strategies, Information Security Management, Risk Mitigation. . Brittany Day

Calendar 2 Aug 29, 2006 User Avatar Brittany Day Government
82

Federal Cybersecurity Coordination Recommendations on R&D

The Bush administration has drafted a federal plan to improve cybersecurity research and development. Yesterday, the National Science and Technology Council, a Cabinet-level body that coordinates governmentwide science and technology policies, issued a preprint release of the “Federal Plan for Cyber Security and Information Assurance Research and Development.. In addressing gaps in the country’s current cybersecurity activities, the 121-page report recommends setting R&D priorities and strengthening coordination between agencies and the private sector. The plan also calls for implementing emerging technologies, road maps and metrics. It does not address specific funding levels or budgets. Industry officials and lawmakers had been urging the administration to improve federal cybersecurity and information assurance R&D. Officials are billing this plan as the first step toward developing a federal agenda. Members of more than 20 government organizations prepared the document as part of the Interagency Working Group on Cyber Security and Information Assurance. The link for this article located at Federal Computer Week is no longer available. . In addressing gaps in the country’s current cybersecurity activities, the 121-page report recommen. administration, drafted, federal, improve, cybersecurity, research, development. . Brittany Day

Calendar 2 Apr 25, 2006 User Avatar Brittany Day Government
82

Government Initiatives in Secure Open Source for Remote Work

The Cabinet Office's Central Sponsor for Information Assurance, which co-ordinates information security projects across government, is investigating applications based around a highly secure open source operating system. The proof-of-concept systems being developed by the CSIA will use security enhanced Linux to support remote working and web services. Ministers were prompted to disclose details of the work following parliamentary questions tabled by Lord Harris of Haringey about the CSIA's activities in evaluating the security of open source software. . Responding on behalf of the Government, Lord Bassam said the unit was also sponsoring work at CESG, the Government's information assurance facility at GCHQ. "Among a range of IA capabilities being investigated is the future 'trusted computing platform'," he added The link for this article located at eGov Monitor is no longer available. . Responding on behalf of the Government, Lord Bassam said the unit was also sponsoring work at CESG, . information, cabinet, office's, central, sponsor, assurance, which, co-ordinates, secur. . Benjamin D. Thomas

Calendar 2 Jun 24, 2005 User Avatar Benjamin D. Thomas Government
72

Key Firewall Security Insights for Effective Network Protection

A DMZ (Demilitarized Zone) is a combination of firewalls -- a perimeter network segment logically between internal and external networks. Also called a "screened subnet," its purpose is to enforce the internal network's IA policy for external information exchange and to provide external, untrusted sources with restricted access to releasable information while shielding internal networks from outside attacks. . . .. n the limited space available here, I cannot possibly address how to secure a firewall. Instead, I'll note the considerations that go into doing so and point you to some useful resources. CNSS Instruction No. 4009, revised May 2003, National Information Assurance (IA) Glossary defines a firewall as a "system designed to defend against unauthorized access to or from a private network." I prefer CERT's definition: "A combination of hardware and software used to implement a security policy governing the network traffic between two or more networks, some of which may be under your administrative control (e.g., your organization's networks) and some of which may be out of your control (e.g., the Internet)." A DMZ (Demilitarized Zone) is a combination of firewalls -- a perimeter network segment logically between internal and external networks. Also called a "screened subnet," its purpose is to enforce the internal network's IA policy for external information exchange and to provide external, untrusted sources with restricted access to releasable information while shielding internal networks from outside attacks. In some circles the DMZ is considered a part of the firewall, while other circles consider the DMZ the land of the sacrificial hosts. One way to think of a DMZ is as a group of hosts that are guided by a unique security policy. This policy balances some of the strictest controls against public access and availability requirements. The link for this article located at TechTarget.com is no longer available. . Robust firewall measures are crucial for cybersecurity, acting as barriers betweentrusted and untrusted networks while monitoring traffic with security rules. firewall security, DMZ, network protection, external threats. . Anthony Pell

Calendar 2 Oct 28, 2004 User Avatar Anthony Pell Firewalls
67

Exploring Email Encryption: Risks Of Trust And Impersonation

Gadi Evron, an information security researcher based in Israel, generally signs his posts to the list with his PGP signature, due to the fact that his email address is constantly used by spammers. Anyone who wants to verify an signed email is actually from the person claiming to send it, can do so. . . .. The trust that encryption generates can be deceptive, one researcher, a regular poster to the full-disclosure vulnerability mailing list, has discovered. Gadi Evron, an information security researcher based in Israel, generally signs his posts to the list with his PGP signature, due to the fact that his email address is constantly used by spammers. Anyone who wants to verify an signed email is actually from the person claiming to send it, can do so. What he did not reckon was that someone would try to use his PGP signature inside a spam email to impersonate him. . The trust that encryption generates can be deceptive, one researcher, a regular poster to the full-d. evron, information, security, researcher, based, israel, generally, signs, posts. . LinuxSecurity.com Team

Calendar 2 Jun 01, 2004 User Avatar LinuxSecurity.com Team Cryptography
News Add Esm H340

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here