Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
If you're physically transporting data you don't want other people to see, you should be doing it on secure media. And what better than something that hides easily within a pocket? Secure flash drives that are only about the size of a small cigarette lighter feature robust hardware security to make them super secure. You'll pay a premium for the integrated security, but you can't put a price on the peace of mind you get by knowing that your data is locked down.. To get the skinny on the state-of-the-art in secure flash drives, we took five hardware-encrypted drives for test spins. The results? As far as security is concerned, it's all systems go. Three of the units--the Kingston DataTraveler 4000 Managed, the Kanguru Defender 2000, and the CMS CE-Secure Vault FIPS--are certified to Level 2 of the government's FIPS 140-2 security standard. The Imation Defender F200 ratchets that up to Level 3. The Apricorn Aegis Secure Key is being processed for Level 3 certification, though it is not yet certified. The link for this article located at PC World is no longer available. . To get the skinny on the state-of-the-art in secure flash drives, we took five hardware-encrypted dr. you're, physically, transporting, don't, other, people, should, doing. . LinuxSecurity.com Team
Sturdy and secure USB flash memory storage solution is rapidly deployable with a SAAS-based configuration and management tool. IronKey has built its Enterprise D200 and S200 USB flash drives to withstand just about anything thrown at it. And I made it my goal to find out how much of a beating it could actually take.. The USB flash drives are rugged, waterproof to MIL-STD-810F specifications and meet Security Level 3 of FIPS 140-2. A tamper-resistant and tamper-evident design houses flash memory storage and a crypto chip, which provides AES 256-bit encryption in CBC mode. For those who are price sensitive, the D200 series uses MLC flash memory, while the S200 series uses SLC flash memory to provide faster performance and longer data life. Both series share the same physical characteristics. The S200 is priced at $79 for a 1GB model, $199 for 8GBs and $299 for 16GB. The D200 is priced at $99 for a 4GB model, $129 for 8GB and $299 for 32GB. The management service costs $24 per user per year. The IronKey drives are extraordinarily solidly constructed of flash memory embedded in military-grade epoxy wrapped in a single piece aluminum casing. To put it concisely, I beat the hell out of these things. I blame IronKey for encouraging me by sending me seven test units. I felt like I should just keep finding new ways to torture them. The link for this article located at eWeek is no longer available. . Durable, water-resistant USB memory sticks comply with MIL-STD-810G and FIPS 140-3 to ensure safe data preservation and archival.. Rugged USB Flash Drives, Secure Data Storage Solutions, IronKey Technology. . LinuxSecurity.com Team
Like many Internet addicts, I have way too many user name/password accounts to remember: accounts on social-networking sites, rarely used logins at work, on-line banking and so on. One solution to this problem is to use the same user name and password everywhere, but that's clearly not safe; if people get a hold of your account information in one place, they own all your other accounts too. I wanted a relatively safe, flexible and easy way to store passwords and other useful confidential information. I also wanted it to be easily accessible, which meant that I'd like to get at it over a text-only SSH connection. And, I wanted it to be something that could move around from machine to machine without too much trouble. This article looks at ways of storing passwords securely. With all those password we have to remember it's a good securely practice to store them encrypted.. . Explore reliable and adaptable options for safeguarding credentials using GPG and SSH access techniques.. Password Management Solutions,GPG Encryption,Secure Passwords,SSH Access. . LinuxSecurity.com Team
This article is a step-by-step guide to using two passwords with EncFS. The primary password is required and may be used to secure all data; the secondary password is optional and may be stored on USB stick or other removable media and used to secure more sensitive data. EncFS can also be combined with block device encryption for maximum security . 1. Protection relative to the sensitivity of the data. John Doe uses EncFS to store some important personal information on his laptop. He uses a secondary password to store corporate information when working from home. Both set of files are stored in the same encrypted directory. Usually personal passwords are easy to guess if you have information about the person. If personal password (e.g his dog The link for this article located at RedHatMagazine is no longer available. . Enhance your data security with dual password encryption in EncFS. This guide covers installation, configuration, and best practices for protecting files.. Dual Passwords, EncFS Encryption, Secure Data Storage. . LinuxSecurity.com Team
The Kanguru Bio Slider II is a USB 2.0 secure flash drive made complete with the most up-to-date biometric fingerprint technology. The drive offers a low maintenance, effortless approach to protecting and storing your data. . The link for this article located at Help Net Security is no longer available. . Discover the innovative Kanguru Bio Slider II USB drive, equipped with cutting-edge biometric features for enhanced data protection.. Biometric Flash Drive, USB Data Protection, Secure USB Device. . LinuxSecurity.com Team
If you are developing a password-protected web site, you have to make a decision about how to store user password information securely. What is "secure," anyway? Realize that the data in your database is not safe. What if the password to the database is compromised? Then your entire user password database will be compromised as well. Even if you are quite certain of the security of your database, your users' passwords are still accessible to all administrators who work at the Web hosting company where your database is hosted. Scrambling the passwords using some home-brewed algorithm may add some obscurity but not true "security." Another approach would be to encrypt all passwords in your database using some industry-standard cipher, such as the Message-Digest Algorithm 5 (MD5). . MD5 encryption is a one-way hashing algorithm. Two important properties of the MD5 algorithm are that it is impossible to revert back an encrypted output to the initial, plain-text input, and that any given input always maps to the same encrypted value. This ensures that the passwords stored on the server cannot be deciphered by anyone. This way, even if an attacker gains reading permission to the user table, it will do him no good. The link for this article located at Web Cheat Sheet is no longer available. . MD5 encryption is a one-way hashing algorithm. Two important properties of the MD5 algorithm are tha. developing, password-protected, decision, about, store. . LinuxSecurity.com Team
"My company, an IT and business consulting firm of around 150 people, is looking for a Password Vault/Manager/Database solution to manage the numerous passwords we've developed in the course of a major internal network and server upgrade. Our must haves are multiple privilege levels (I don't need to see network passwords, and the network guys don't need to see database passwords, and so on) and it would be nice if we could view when people last retrieved each password. Does anyone manage passwords in this fashion at their work/home? A lot of the free password managers are one user, full access, which is a little less secure than we need. How do other companies (small or large) manage the hundreds of server, network, database, and application passwords that must crop up?" . The link for this article located at Slashdot is no longer available. . The link for this article located at Slashdot is no longer available.. company, business, consulting, around, people, looking, password. . LinuxSecurity.com Team
The US National Security Agency (NSA) and Treasure Department have expressed interest in a secure storage device that hard drive manufacturer Seagate is developing. Seagate spokesperson Michael Hall told vnunet.com that the company has met with the two US government agencies over its Momentus 5400 FDE technology. He said that the agencies are investigating the device's implications on their ability to fight organised crime, but stressed that so far they are only gathering information. . The link for this article located at VNUNet is no longer available. . The link for this article located at VNUNet is no longer available. . national, security, agency, (nsa), treasure, department, expressed, interest, secure. . Benjamin D. Thomas
Get the latest Linux and open source security news straight to your inbox.