Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Leading security expert Bruce Schneier was in London this week on a whirlwind lecture tour. ZDNet UK caught up with the ex-NSA man, who is now BT's chief security technology officer, at lectures in parliament and at University College London.. Schneier talked to ZDNet UK about his views on behavioural advertising, the efforts of various governments to tackle unlawful file-sharing, cyber-warfare and vendor lock-in. Q: The UK government is currently trying to pass the Digital Economy Bill, which includes provisions to penalise unlawful file-sharing. Is this technically feasible? A: The problem with a lot of these measures is that they only affect the average user. Professionals, hackers, clever people can get around them. No, I don't think this is technically feasible. The ones they don't care about, the average user, are the ones they are going to stop, and the detection mechanisms are sloppy. There are so many examples of the industry getting it wrong. The link for this article located at ZDNet UK is no longer available. . Schneier talked to ZDNet UK about his views on behavioural advertising, the efforts of various gover. leading, security, expert, bruce, schneier, london, whirlwind, lecture, zdnet. . LinuxSecurity.com Team
Our esteemed leaders in the U.S. Congress are vowing to enact new laws targeting data thieves, backup-tape burglars and other information-age miscreants. We should be worried. . Any reasonable person, of course, should agree that such thefts must be punished and data warehouses should let us know if our information falls into the hands of criminals. But a bill announced last week by Sens. Arlen Specter, R-Penn., and Patrick Leahy, D-Vt., goes far beyond reasonable data security precautions. It amounts to a crackdown on individuals, bloggers and legitimate e-mail list moderators. Anyone who runs a Web site with registered users and receives income from it (Blogads and Google Ads count) should be concerned. The Specter-Leahy bill says that if that site's list of user IDs or e-mail addresses is compromised, each registered user must be notified via U.S. mail or telephone. Refusal to do so can be punished with $55,000-a-day fines and prison time of up to five years. That's remarkable but not as extreme as the second requirement: The Web master or mailing list operator might have to "cover the cost" of 12 monthly credit reports of each person whose e-mail addresses was lost or purloined. For a popular site with 10,000 registered users, that would be a princely sum. If monthly credit reports cost $15 a person, that's $1.8 million over a year.. Proposed data protection laws raise concerns for webmasters, including heavy fines and user notification requirements.. data protection, webmasters concerns, user notification. . Brittany Day
Recently the press and the public policy makers have begun to speak of "Identity Theft" as though it was a novel concept requiring severe new legislation. These laws are likely to put significant new burdens on business. While most identity theft problems originate via plain old "snail mail", the discussion these days is all about the Internet. The sponsors of the legislation point to exponential growth in the problem as justification for these laws. . . .. Recently the press and the public policy makers have begun to speak of "Identity Theft" as though it was a novel concept requiring severe new legislation. These laws are likely to put significant new burdens on business. While most identity theft problems originate via plain old "snail mail", the discussion these days is all about the Internet. The sponsors of the legislation point to exponential growth in the problem as justification for these laws. This paper suggests that the "growth" actually comes from redefining traditional fraud, not from the growth of the internet. It begins with as discussion of the concept of identity and ends with recommendations for individuals, fiduciaries and merchants to safeguard themselves. The link for this article located at ebcvg.com is no longer available. . Recently the press and the public policy makers have begun to speak of 'Identity Theft' as though it. recently, press, public, policy, makers, begun, speak, 'identity, theft', though. . Anthony Pell
Instead of prohibiting bad code, a better solution is to prohibit bad behavior. That could mean, for example, a general rule against fraud instead of trusting tech-impaired politicos to draw up a list of every type of possible code that could perform fraudulent acts. . . .. A congressional hearing on Internet porn last week illustrates what happens when politicians try to ban technology they don't like or understand. The topic of Thursday's meeting of the House of Representatives' consumer protection subcommittee was a bill intended to require that programs like Kazaa and Grokster obtain parental consent before installation. Peer-to-peer software is starting "to lure our children from the perceived safety of the family living room out into the dangers of the Internet wilderness," subcommittee chairman Cliff Stearns, R-Fla., warned. The only problem: The bill that Stearns and his colleagues suggest as a solution is so broadly worded that it regulates far more than just peer-to-peer applications. Anyone distributing instant-messaging programs, File Transfer Protocol software or Internet Relay Chat clients would have to follow a complicated set of regulations to be published by the Federal Trade Commission, which might as well be renamed the Federal Software Regulatory Commission. Software distribution sites like those of SourceForge and the Comprehensive Perl Archive Network would be outlawed, if they did not follow these byzantine legal rules, which include obtaining "verifiable parental consent," if the downloader is a minor, ensuring that the software can be readily uninstalled, keeping "records of its compliance" and so on. Anyone running such a Web site outside the United States would be required to hire a "resident agent" and file reports with the FTC--hardly a boon to the burgeoning global open-source movement. . A congressional hearing on Internet porn last week illustrates what happens when politicians try to . instead, prohibiting, better, solution, prohibit, behavior. . LinuxSecurity.com Team
The government's preferred method of dealing with the challenges posed by technology by simply passing new legislation is now spilling over into the debate over Internet privacy.. . .. The government's preferred method of dealing with the challenges posed by technology by simply passing new legislation is now spilling over into the debate over Internet privacy. Even though legislation on this issue is not likely to be passed this year, the outcome of the ongoing conversation will have a significant impact. A lot of attention has focused on Senate Commerce chairman Fritz Hollings' "Online Privacy Protection Act." His bill legislates what a Web site's privacy policy should be, depending on two distinct types of information collected: "sensitive personally identifiable information" and "nonsensitive personally identifiable information." The link for this article located at ZDNet is no longer available. . The government's preferred method of dealing with the challenges posed by technology by simply passi. government's, preferred, method, dealing, challenges, posed, technology, simply, passi. . LinuxSecurity.com Team
Basically, the SSSCA seeks to enforce rigorous rights controls on all digital devices and their software -- to make it "unlawful to manufacture, import, offer to the public, provide or otherwise traffic in any interactive digital device that does not include" security systems earning Hollywood's approval. To really see this in the proper light, here's a quote from the draft legislation. . .. Basically, the SSSCA seeks to enforce rigorous rights controls on all digital devices and their software -- to make it "unlawful to manufacture, import, offer to the public, provide or otherwise traffic in any interactive digital device that does not include" security systems earning Hollywood's approval. To really see this in the proper light, here's a quote from the draft legislation : The term "interactive digital device" means any machine, device, product, software, or technology, whether or not included with or as part of some other machine, device, product, software, or technology, that is designed, marketed or used for the primary purpose of, and that is capable of, storing, retrieving, processing, performing, transmitting, receiving, or copying information in digital form. Well, that covers everything from my PC to the clock radio on my desk. It also applies to every piece of a computer system and its software, along with any digital office equipment and maybe a few household appliances -- desktops, servers, hard disks, RAM, and anything that even comes into contact with digital information is subject to the SSSCA. To call this description all-encompassing would be the understatement of the century. But more important, what could it mean for business? The link for this article located at Earthweb is no longer available. . Basically, the SSSCA seeks to enforce rigorous rights controls on all digital devices and their soft. basically, sssca, seeks, enforce, rigorous, rights, controls, digital, devices, their. . Anthony Pell
It has been almost a year since former President Bill Clinton signed into law the Electronic Signatures in Global and National Commerce (E-SIGN) Act. That was the legislation that cleared the way for digital signatures, a move many thought would be . . . . It has been almost a year since former President Bill Clinton signed into law the Electronic Signatures in Global and National Commerce (E-SIGN) Act. That was the legislation that cleared the way for digital signatures, a move many thought would be pivotal in catapulting electronic commerce into this millennium. Suddenly, everything from auto loans to home mortgages could be signed, sealed and delivered without so much as a Bic pen or a sheet of paper. The link for this article located at E-Commerce Times is no longer available. . Twelve months have elapsed since the implementation of the E-SIGN Act, revolutionizing the landscape of digital transactions.. E-Signature Legislation, Digital Commerce Trends, Online Signing Solutions. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.