Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 524
Alerts This Week
Warning Icon 1 524

Stay Ahead With Linux Security News

Filter%20icon Refine news
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security news

We found 1 articles for you...
78

Maximizing Disk Protection With BitLocker and TPM Security

BitLocker uses the AES encryption algorithm in cyber-block chaining (CBC) mode with a 128-bit key, combined with the Elephant diffuser for additional disk-encryption-specific security not provided by AES. . The application works by encrypting a disk partition; that partition can be located on the system or on a removable device. If you are using BitLocker to secure your system's hard drive, for example, it will create a system partition (which contains the files needed to start your computer) and an operating system partition, which contains your applications, data and Windows. The operating system partition will be encrypted and the system partition will remain unencrypted so your computer can start. BitLocker reaches its full potential on computers equipped with TPM. BitLocker can use either transparent operation mode (where the TPM automates key entry) or a user authentication mode (where the user must manually input a password). The TPM hardware detects any unauthorized changes to the pre-boot environment, including to the BIOS and master boot record (MBR). If any unauthorised changes are detected, BitLocker requests a recovery key on a USB device or a recovery password entered by hand. Either of these cryptographic secrets will decrypt the Volume Master Key (VMK) and allow the bootup process to continue. BitLocker offers additional protection in the form of BitLocker To Go, an encryption option that can be used with removable media. The link for this article located at Tech World is no longer available. . Drive encryption is implemented by BitLocker utilizing AES with CBC mode, while also enhancing protection via Trusted Platform Module (TPM) technology.. BitLocker Encryption,AES Disk Security,TPM Integration,Encryption Algorithms,Disk Protection. . LinuxSecurity.com Team

Calendar%202 Feb 10, 2010 User Avatar LinuxSecurity.com Team Vendors/Products
83

Addressing iPod Security Risks In Corporate Environments

The recent buzz about security threats posed by iPods to corporations has reinforced the need for IT managers to treat these devices like any other removable media that employees with malicious intent can use to extract sensitive data. Following the suggestion recently made by a security company that iPods be banned from the workplace until proper protection is in place, and the emergence of a proof-of-concept iPod virus, it would seem that iPods pose a particularly high risk to corporations that let employees wander into work with these devices strung to their ears. Those same devices that entertain workers during their commute can be used to copy personal or financial data, intellectual property and other sensitive information from corporate PCs, often without a trace. The idea of stealing corporate data with an iPod has gained so much attention lately that it. The link for this article located at Network World is no longer available. . Smartphones can create vulnerabilities in business data safety, underscoring the importance of implementing safeguards against gadget risks.. iPod Security Threats,Cybersecurity Strategies,Corporate Data Protection. . LinuxSecurity.com Team

Calendar%202 Apr 10, 2007 User Avatar LinuxSecurity.com Team Hacks/Cracks
83

Analyzing Modern Malware Attacks on USB Devices and Security Impacts

Researchers at the Internet Storm Center say at least a few hackers have gone old school. Kevin Liston, a handler at the Internet Storm Center, wrote in an online diary Friday that there are a handful of viruses roaming around the Internet targeting USB removable media -- think thumb drives and other storage devices. Win32.Agent.WJ and VBS.Solow.E are just two of them. . "This harkens back to the old days of floppy-disk boot-sector viruses," he writes. Johannes Ullrich, chief research officer at the SANS Institute and chief technology officer for the Internet Storm Center, says the viruses are somewhat common malware but their gimmick is that they are focused on rather unsuspecting targets. If a user's computer is infected with one of them, the malware automatically will look for a device plugged into the USB port. If there's a thumb drive there, for example, it will download itself onto it and wait for the user to click on it and start the active infection. The link for this article located at Yahoo! News is no longer available. . 'This harkens back to the old days of floppy-disk boot-sector viruses,' he writes. Johannes Ullrich,. researchers, internet, storm, center, least, hackers, school, kevin. . LinuxSecurity.com Team

Calendar%202 Mar 05, 2007 User Avatar LinuxSecurity.com Team Hacks/Cracks
83

USB Malware Threats: Old School Techniques Pose New Risks

Researchers at the Internet Storm Center say at least a few hackers have gone old school. Kevin Liston, a handler at the Internet Storm Center, wrote in an online diary Friday that there are a handful of viruses roaming around the Internet targeting USB removable media think thumb drives and other storage devices. Win32.Agent.WJ and VBS.Solow.E are just two of them. . "This harkens back to the old days of floppy-disk boot-sector viruses," he writes. Johannes Ullrich, chief research officer at the SANS Institute and chief technology officer for the Internet Storm Center, says the viruses are somewhat common malware but their gimmick is that they are focused on rather unsuspecting targets. If a user's computer is infected with one of them, the malware automatically will look for a device plugged into the USB port. If there's a thumb drive there, for example, it will download itself onto it and wait for the user to click on it and start the active infection. The link for this article located at DarkReading is no longer available. . 'This harkens back to the old days of floppy-disk boot-sector viruses,' he writes. Johannes Ullrich,. researchers, internet, storm, center, least, hackers, school, kevin. . LinuxSecurity.com Team

Calendar%202 Mar 02, 2007 User Avatar LinuxSecurity.com Team Hacks/Cracks
82

Energy Department Halts Operations: Media Protection Issues Identified

LS: Would it be inappropriate to look at this as a perfect example of the dangers inherent in the lack of risk-based security analysis? If Sandy Berger visited the DoE, they'd probably have to shut down for a year. This overreaction (hard disks with classified info cannot be used?) is an invitation to DoS the DoE by simply 'misplacing' something. It is also dangerous: a positive incentive for employees to not report theft of classified information. Simply put, if the data is that valuble, it should be encrypted and impossible to read without passing some strong authentication, including some sort of challenge-response. If it -is- that encrypted, the thief might as well format the Zip disks and use them for data storage for all the good it would do. This response demonstrates eloquently that the DoE's take on data security is, at best, reactive. . . .. Energy Secretary Spencer Abraham ordered today all Energy Department operations to halt using controlled removable electronic media (CREM) to improve media protection procedures. Abraham's directive follows an announcement earlier this month that Los Alamos National Laboratory employees had lost two Zip discs containing classified material. Lab workers are searching for the discs amid more than 2,000 safes and vaults. The lab's director has halted all operations at Los Alamos, and Abraham has directed that classified operations will not resume until Energy's deputy secretary, Kyle McSlarrow, and the National Nuclear Security Administration's administrator, Linton Brooks, confirm that newly implemented corrective actions improve CREM management. "While we have no evidence that the problems currently being investigated are present elsewhere, we have a responsibility to take all necessary action to prevent such problems from occurring at all," Abraham said in a statement. CREM includes all types of classified hard drives or computer discs. The link for this article located at fcw.com is no longer available. . Energy Secretary Spencer Abraham orderedtoday all Energy Department operations to halt using contro. would, inappropriate, perfect, example, dangers, inherent. . Anthony Pell

Calendar%202 Jul 27, 2004 User Avatar Anthony Pell Government
67

IBM Proposes Data Security Standard For Removable Media Enhancement

IBM is backing a standards proposal that would allow generic functions to be programmed into removable media such as DVDs, flash memory and Zip drives that, among other things, could limit what a user copies to or from his computer. IBM . . . . IBM is backing a standards proposal that would allow generic functions to be programmed into removable media such as DVDs, flash memory and Zip drives that, among other things, could limit what a user copies to or from his computer. IBM had previously proposed the controversial Copy Protection for Recordable Media (CPRM) standard to the T13 committee of the Washington-based National Committee for Information Technology Standards, which oversees Advanced Technology Attachment (ATA) interfaces. Such interfaces are used by a computer's motherboard to communicate with its disk storage devices. But IBM said it pulled its backing of CPRM in favor of a "generic functionality" proposal submitted by Curtis Stevens, a technical editor at Phoenix Technologies Ltd. in San Jose, at the T13 group's meeting late last month. The link for this article located at ComputerWorld is no longer available. . IBM is backing a standards proposal that would allow generic functions to be programmed into removab. backing, standards, proposal, would, allow, generic, functions, programmed, removab. . LinuxSecurity.com Team

Calendar%202 Mar 20, 2001 User Avatar LinuxSecurity.com Team Cryptography
News Add Esm H340

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200