Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 499
Alerts This Week
Warning Icon 1 499

Stay Ahead With Linux Security News

Filter%20icon Refine news
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security news

We found 28 articles for you...
82

Article 45: Assessing Risks to EU Web Security and User Privacy Concerns

The EU is poised to pass a sweeping new regulation, eIDAS 2.0. Buried deep in the text is Article 45, which returns us to the dark ages of 2011, when certificate authorities (CAs) could collaborate with governments to spy on encrypted traffic—and get away with it. Article 45 forbids browsers from enforcing modern security requirements on certain CAs without the approval of an EU member government. Which CAs? . Specifically, the CAs that were appointed by the government, which in some cases will be owned or operated by that selfsame government. That means cryptographic keys under one government’s control could be used to intercept HTTPS communication throughout the EU and beyond. This is a catastrophe for the privacy of everyone who uses the internet, but particularly for those who use the internet in the EU. Browser makers have not announced their plans yet, but it seems inevitable that they will have to create two versions of their software: one for the EU, with security checks removed, and another for the rest of the world, with security checks intact. We’ve been down this road before when export controls on cryptography meant browsers were released in two versions: strong cryptography for US users and weak cryptography for everyone else. It was a fundamentally inequitable situation, and the knock-on effects set back web security by decades. Read what LinuxSecurity.com Founder and Linux Security expert Dave Wreski has to say about the implications of this proposed regulation in a new LinkedIn update. . Investigating the impact of Article 45 on digital safety and personal data protection for online users within the European Union framework.. Web Security Regulations, Certificate Authorities EU, Privacy Encryption Laws, Internet Governance Compliance. . Brittany Day

Calendar%202 Nov 08, 2023 User Avatar Brittany Day Government
81

Tails 5.0 Advisory Alerts Users to Privacy Risks with Tor Browser

Tails developers have warned users to stop using the portable Debian-based Linux distro until the next release if they're entering or accessing sensitive information using the bundled Tor Browser application. . Tails (short for The Amnesic Incognito Live System) is a Linux distro focused on protecting the users' anonymity (e.g., activists and journalists) and helping them circumvent censorship by forcing all connections to and from the Internet through the Tor network. "We recommend that you stop using Tails until the release of 5.1 (May 31) if you use Tor Browser for sensitive information (passwords, private messages, personal information, etc.)," the Tails developers warned. . Tails developers warn users to avoid employing the OS for critical operations, emphasizing potential privacy vulnerabilities when browsing with Tor.. Tails Linux, Tor Browser security, Debian-based privacy. . LinuxSecurity.com Team

Calendar%202 May 26, 2022 User Avatar LinuxSecurity.com Team Privacy
81

Police Officer Safety Threatened By Ring Doorbell Surveillance Risks

You're probably aware of the privacy concerns associated with Ring doorbells, but have you considered the risks that this popular IoT device poses to police officers? . Leaked documents have revealed the concerns of law enforcement in how Internet of Things (IoT) technology can pose a risk to the safety of police officers. Smart doorbell vendors including Ring have created product lines that have transformed traditional bells and door chimes into intelligent technological solutions that provide location monitoring, real-time camera feeds, audio and visual recordings, and the ability to communicate with visitors remotely. . Confidential reports indicate police concerns over the risks posed by IoT devices, especially doorbell cameras, and their impact on officer safety in different scenarios. IoT Security, Surveillance Technology, Police Safety, Smart Devices, Privacy Concerns. . LinuxSecurity.com Team

Calendar%202 Sep 01, 2020 User Avatar LinuxSecurity.com Team Privacy
81

Smartwatch Security Risks Endanger Millions Of Children Worldwide

New findings by security firm Pen Test Partners reveal that 47 million devices worldwide could be exposed and tracked thanks to a strikingly insecure cloud platform. Learn more about the privacy risks associated with these smartwatches: . Throughout 2019, security researchers have discovered striking flaws about child-tracking smartwatches that could be manipulated by hackers. But new findings reported by TechCrunch show that the smartwatches had a larger problem on their hands: a very insecure common cloud platform lacking basic cybersecurity protections. Researchers found that the cloud platform, made by Chinese electronics company and location-tracking giant Thinkrace, puts at least 47 million devices at risk of being hacked. Because each device interacts with the cloud platform either directly or through a web domain set up by a reseller, cybersecurity firm Pen Test Partners was able to all commands for the devices back to the faulty cloud platform. The link for this article located at Security Today is no longer available. . Recent investigations unveil significant vulnerabilities in children’s GPS-enabled watches, putting countless users at risk of cyberattacks.. Child Tracking, Smartwatch Security, Cloud Vulnerabilities, Cybersecurity Research. . LinuxSecurity.com Team

Calendar%202 Dec 20, 2019 User Avatar LinuxSecurity.com Team Privacy
82

EFF Report: Exposed License Plate Readers Raise Security Concerns

Law enforcement agencies around the country have been all too eager to adopt mass surveillance technologies, but sometimes they have put little effort into ensuring the systems are secure and the sensitive data they collect on everyday people is protected. . Case in point: automated license plate recognition (ALPR) systems. Earlier this year, EFF learned that more than a hundred ALPR cameras were exposed online, often with totally open Web pages accessible by anyone with a browser. In five cases, we were able to track the cameras to their sources: St. Tammany Parish Sheriff . Uncover the alarming truth as more than 150 surveillance cameras are publicly accessible online, raising significant concerns regarding personal privacy and security threats.. License Plate Exposure, ALPR Vulnerabilities, Surveillance Security. . Anthony Pell

Calendar%202 Mar 14, 2017 User Avatar Anthony Pell Government
81

Techniques by MIT Researchers Unmask Tor Anonymity Risks

MIT researchers have developed digital attacks which can unmask Tor services in the Deep Web with a high degree of accuracy.. As reported by Net Security, a team from the Massachusetts Institute of Technology (MIT) have developed attacks which can be used to identify an anonymous hidden service, clients and potentially servers. The link for this article located at ZDNet Security is no longer available. . A team from MIT has created methods capable of exposing Tor hidden services, jeopardizing the privacy of users on the Deep Web.. Tor Service Attacks, MIT Research, Deep Web Anonymity, Digital Security Risks. . LinuxSecurity.com Team

Calendar%202 Jul 31, 2015 User Avatar LinuxSecurity.com Team Privacy
83

Hola VPN Exposed: Assessing Privacy Threats and DDoS Issues Ahead

Hola is a VPN provider that purports to offer its users freedom from censorship, a way to access geoblocked content, and anonymous browsing. The service claims that more than 47 million people are part of its peer-to-peer network. But according to a group of researchers (calling themselves Adios), it's dangerously insecure: the client software has flaws that allow for remote code execution and features of the client enabled tracking. . On top of that, critically, Hola sells access to its peer-to-peer network with little oversight, enabling it to be used maliciously. The nature and scale of problems with Hola has researchers now saying users should bid adieu to the software.. Hola VPN faces allegations of compromising user privacy by selling access to its network, raising concerns over security and facilitating DDoS attacks.. Hola VPN, Privacy Risks, DDoS Concerns, User Tracking. . LinuxSecurity.com Team

Calendar%202 Jun 02, 2015 User Avatar LinuxSecurity.com Team Hacks/Cracks
81

Michael Chertoff Discusses Privacy Risks of Google Glass

Interesting op-ed by former DHS head Michael Chertoff on the privacy risks of Google Glass. Now imagine that millions of Americans walk around each day wearing the equivalent of a drone on their head: a device capable of capturing video and audio recordings of everything that happens around them. . It's not unusual for government officials -- the very people we disagree with regarding civil liberties issues -- to agree with us on consumer privacy issues. But don't forget that this person advocated for full-body scanners at airports while on the payroll of a scanner company. The link for this article located at Schneier on Security is no longer available. . It's not unusual for government officials -- the very people we disagree with regarding civil libert. interesting, op-ed, former, michael, chertoff, privacy, risks, google, glass. . LinuxSecurity.com Team

Calendar%202 May 06, 2013 User Avatar LinuxSecurity.com Team Privacy
News Add Esm H340

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200