Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 507
Alerts This Week
Warning Icon 1 507

Stay Ahead With Linux Security News

Filter%20icon Refine news
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security news

We found 9 articles for you...
78

Mozilla Firefox 83 Launch: Enhanced HTTPS-Only Mode for Secure Browsing

The Mozilla Firefox 83 web browser is now available for download on Linux, macOS, and Windows systems, and offers a new security feature called HTTPS-Only Mode, which provides a secure and encrypted connection between your web browser and the websites you visit - even if they don’t use HTTPS. . The biggest new change in the Mozilla Firefox 83 release appears to be a new security feature called HTTPS-Only Mode, which is implemented in Preferences, under the Privacy & Security section. It provides a secure and encrypted connection between your web browser and the websites you visit, even if they don’t use HTTPS. By default it’s disabled, but when enabled, the HTTPS-Only Mode will upgrade all your website connections to use Secure HTTP (HTTPS). The good news is that it can be used in all windows or only on private windows. Another interesting change is support for the WebRender feature to work on Intel laptops with older drivers, as well as on systems with Intel Gen12 GPUs, thus making Firefox more snappier on these hardware. The link for this article located at 9 to 5 Linux is no longer available. . A major update in Google Chrome 88 introduces a built-in VPN service, offering enhanced privacy for users browsing the web.. Mozilla Firefox, Secure Browser, HTTPS-Only, Web Security. . LinuxSecurity.com Team

Calendar%202 Nov 19, 2020 User Avatar LinuxSecurity.com Team Vendors/Products
81

WireGuard Offers Faster And More Secure VPN Solutions For Linux

VPNs, or virtual private networks, are an important part of any security and privacy toolbox. . VPNsare essentially encrypted connections between two or more devices that enable you to route data through a secure "tunnel." Companies use them to allow employees to access corporate networks from outside the office. Commercial VPN services try to protect your internet traffic from eavesdroppers by routing it through remote servers. In theory, that means that a hacker eavesdropping on public Wi-Fi or your home broadband provider can’t see what you're doing online. Routing your traffic through a remote server can also make it look like you’re in another place, allowing people in countries like China and Russia to access sites that are blocked domestically. But VPN connections are only as secure as the software that underpins them. Security researcher Thomas Ptacek says his industry is generally distrustful of VPN software. "There's always a gnawing feeling in the back of our skulls” of an unknown security weakness in VPN software, he says. One reason for that is that most VPN software is incredibly complicated. The more complex a piece of software, the harder it is to audit for security issues. The link for this article located at Wired is no longer available. . VPNs function as secure tunnels that encrypt data transmissions, offering enhanced confidentiality for online interactions and resource access.. secure VPN, WireGuard, network encryption, privacy tool, virtual networks. . LinuxSecurity.com Team

Calendar%202 Mar 02, 2020 User Avatar LinuxSecurity.com Team Privacy
81

Create Your Own VPN/TOR Router With Raspberry Pi For Privacy

Surf the Internet securely with your very own portable WiFi VPN/TOR router. You can configure a Raspberry Pi with Linux and some extra software to connect to a VPN server of your choice. The VPN connection encrypts your internet traffic so that hackers and spies can. The router is small and portable, so you can plug it in anywhere, adding secure internet browsing to any occasion, from your room to the caf The link for this article located at Make is no longer available. . The router is small and portable, so you can plug it in anywhere, adding secure internet browsing to. internet, securely, portable, vpn/tor, router, configure. . LinuxSecurity.com Team

Calendar%202 Jan 30, 2015 User Avatar LinuxSecurity.com Team Privacy
79

OpenSSH Security Update: Critical Fixes For Port Forwarding And GSSAPI

The first fix prevents "GatewayPorts" from being "incorrectly activated for dynamic ('-D') port forwardings when no listen address was explicitly specified," according to the changelog. The update also prevents GSSAPI credentials being "delegated to users who log in with methods other than GSSAPI authentication (e.g. public key) when the client requests it." The update also includes a host of bug fixes, improvements and added features according to the announcement. . Server shell (SSH) technology is used to encrypt network traffic that otherwise is relatively open to eavesdropping and attack. OpenSSH is one of the open source alternatives to proprietary secure shell software. The link for this article located at Techtonic is no longer available. . Server shell (SSH) technology is used to encrypt network traffic that otherwise is relatively open t. first, prevents, 'gatewayports', being, 'incorrectly, activated, dynamic, ('-d'). . LinuxSecurity.com Team

Calendar%202 Sep 05, 2005 User Avatar LinuxSecurity.com Team Security Projects
74

Securing Open Wireless Networks: Risks And Effective Protection Strategies

Business owners don't walk away from their buildings at night and leave the doors wide open. But quite a few are doing something that could become nearly as dangerous: Leaving wireless networks wide open to anyone passing by with a portable . . . . Business owners don't walk away from their buildings at night and leave the doors wide open. But quite a few are doing something that could become nearly as dangerous: Leaving wireless networks wide open to anyone passing by with a portable computer and less than $100 worth of hardware needed to connect to the system. "We do our war driving and we still come across access points that are not encrypted," says Keith D'Sousa, a senior manager of risk and advisory services at consulting firm KPMG LLP in Toronto. War driving involves touring cities with equipment that can sniff out a company's unprotected wireless network access points. It's a hobby of security consultants and, more frightening, computer hackers and people looking for free Internet access. The fact that it still turns up lots of open doors into corporate networks shows many businesses still aren't paying enough attention to wireless local-area network (LAN) security. The link for this article located at The Globe is no longer available. . Ensure your Wi-Fi networks are secure: understand potential threats and discover ways to safeguard your enterprise successfully.. Wireless Security, Network Encryption, Business Safety, Risk Management. . Anthony Pell

Calendar%202 Nov 06, 2003 User Avatar Anthony Pell Network Security
74

WEP Encryption Challenges in D-Link 802.11g Access Points Setup

Once more I sat at the control console and went through the D-Link wireless access point's forms to enable WEP (Wired Equivalent Privacy) encryption. I knew it wasn't exactly the best encryption on the planet, but it was better than nothing . . . . Once more I sat at the control console and went through the D-Link wireless access point's forms to enable WEP (Wired Equivalent Privacy) encryption. I knew it wasn't exactly the best encryption on the planet, but it was better than nothing at all, and the network I was working with didn't handle much sensitive information anyway. I entered the key in hex and clicked the submit button. Next, I went to a laptop computer that already had 802.11g built in. Until I'd enabled encryption on the access point, everything had been (in technical terms) hunky-dory. Now, of course, the access point couldn't be reached. So I went through the configuration for the 802.11g hardware (designed for the laptop by Hewlett-Packard), entered the same hex key as I'd entered into the access point, and confirmed that the rest of the settings were correct. The link for this article located at Infoworld is no longer available. . Delving into WEP encryption configuration for D-Link routers, along with the hurdles encountered in maintaining a secure wireless environment.. Wireless Security, WEP Encryption, 802.11g Security, Network Protection, D-Link Access Points. . Anthony Pell

Calendar%202 Aug 04, 2003 User Avatar Anthony Pell Network Security
74

Enhance Wireless Security: Upgrade 802.11 Networks To WPA

IT managers fed up with the security flaws in the wired equivalent privacy standard are wondering when to begin upgrading their enterprise 802.11 wireless LANs with Wi-Fi Protected Access. However, although there is much to be gained by moving to the . . . . IT managers fed up with the security flaws in the wired equivalent privacy standard are wondering when to begin upgrading their enterprise 802.11 wireless LANs with Wi-Fi Protected Access. However, although there is much to be gained by moving to the latest security standard from the Wi-Fi Alliance, there are many things to consider before making the jump. Ratified last year by the Wi-Fi Alliance, WPA addresses the security vulnerabilities found in WEP-enabled 802.11 WLANs. For example, WPA-compliant products will include dynamic key generation, as well as an improved RC4 data encryption scheme that uses TKIP (Temporal Key Integrity Protocol) and mandatory 802.1x authentication. WPA provides a much-enhanced RC4 encryption implementation through TKIP. TKIP makes the data packets more secure and is backward-compatible with WEP, although it also creates performance overhead. WPA also uses a new cryptographic checksum method called Michael that verifies the validity of an 8-byte message integrity code placed within the 802.11 frame to protect against forgery attacks. The link for this article located at eWeek is no longer available. . The debate between WEP and WPA for wireless networks is crucial for IT managers, with WPA offering essential security enhancements to protect sensitive data.. WPA, Wireless Security, 802.11 Standards, Enhanced Security. . Anthony Pell

Calendar%202 May 28, 2003 User Avatar Anthony Pell Network Security
67

Ingrian Networks: Enhancing Data Security With Network Attached Encryption

Application security specialist Ingrian Networks has developed a technology to offload encryption functions from application or database servers onto appliances with the aim of providing more robust security for data in storage. . .. Application security specialist Ingrian Networks has developed a technology to offload encryption functions from application or database servers onto appliances with the aim of providing more robust security for data in storage . Ingrian, which made its name marketing hardware platforms to speed up the processing of SSL, secure caching, and secure switching (securing data in transit - a market that has become commoditised), has developed software service engines to secure data in storage as well. It calls this technology Network Attached Encryption. In trying to lock-down data in storage from prying eyes, hackers, and malicious attack, companies have turned to encryption technologies to secure their applications and data. But traditional encryption technologies require some re-writing of applications, and place a heavy load on servers. There's also the issues of keys residing on the same server where applications are running, which Ingrian argues poses a security risk. . Application security specialist Ingrian Networks has developed a technology to offload encryption fu. application, security, specialist, ingrian, networks, developed, technology, offload, encryption. . LinuxSecurity.com Team

Calendar%202 Oct 31, 2002 User Avatar LinuxSecurity.com Team Cryptography
News Add Esm H340

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200