Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
OpenSSF was launched in August of 2020 as “a cross-industry collaboration that brings together leaders to improve the security of open source software (OSS)”. This article provides an overview of OpenSSF's mission, what it’s accomplished in its first six months and its plans for the future. . The Open Source Software Foundation (OpenSSF) officially launched on August 3, 2020 . In this article, we’ll look at why the OpenSSF was formed, what it’s accomplished in its first six months, and its plans for the future. The world depends on open source software (OSS), so OSS security is vital. Various efforts have been created to help improve OSS security. These efforts include the Core Infrastructure Initiative (CII) in the Linux Foundation, the Open Source Security Coalition (OSSC) founded by the GitHub Security Lab, and the Joint Open Source Software Initiative (JOSSI) founded by Google and others. It became apparent that progress would be easier if these efforts merged into a single effort. The OpenSSF was created in 2020 as a merging of these three groups into “a cross-industry collaboration that brings together leaders to improve the security of open source software (OSS).” . The Collaborative Development Initiative (CDI) was formally established on September 15, 2021. This write-up outlines its objectives.. OpenSSF, Open Source Security Foundation, OSS Collaboration, Software Security Initiative. . Brittany Day
The Linux Foundation's Open Source Security Foundation (OpenSSF) looks to jointly mitigate risks inherent to the open-source style of development, and the foundation just announced that a total of 16 new contributors have joined OpenSSF including Canonical, Facebook, Samsung, Huawei Technologies, and more. . Security has always been of utmost importance to the entire open source ecosystem. Eric S. Raymond, one of the luminaries of the open source movement, in his famous essay, Cathedral and the Bazaar, wrote “given enough eyeballs, all bugs are shallow.” While still true, the complexity of software, and the increasing number of collaborators, puts an increasing onus on the eyeballs hunting for vulnerabilities. In addition to well-defined security policies at a project level, virtually all of the top organisations that contribute to open source software have security initiatives of their own. . Protection is crucial within the open-source community, with emerging programs bolstering efforts to address weaknesses.. Open Source Security, Software Risk Management, Vulnerability Mitigation. . Brittany Day
At Black Hat USA, the network operations center (NOC) and security operations center (SOC) are one in the same — reasonable for a network that exists to serve a huge gathering of security professionals. While the network that exists for a high-intensity week is unique in many ways, in others it is a concentrated example of what is possible when professionals with different areas of expertise — and different vendors — work together.. Neil Wyler, known to most as "Grifter," made sure that working together is what happened in the NOC. He described the scope of the Black Hat network operation, explaining that the team used the physical cable provided by the facility (in this case, the Mandalay Bay Convention Center) but brought in everything else. From demarc to access points, everything was deployed in less than a week, then was expected to operate without flaw for another week before it disappeared. The link for this article located at DarkReading is no longer available. . Elena Morin facilitates seamless communication within the SOC during DEF CON, exemplifying cooperation in cybersecurity responses.. Black Hat USA, Network Operations Center, Cybersecurity Strategies, Security Collaboration, Event Security. . Brittany Day
Rackspace is leading an effort to create a new group of top-tier cloud companies that it hopes will share information about security in close to real time. Rackspace chief security officer Brian Kelly today told The Reg at a Sydney event that he feels cloud companies have to take a lead to address security challenges. . Rackspace, he said, operates a skunkworks in which it is considering approaches such as asking CPU-makers to add security functions to silicon in order to make dedicated security appliances less relevant. That effort, he said, has seen Rackspace hire two of three leaders of the US military's online operations squads because Rackspace wants that kind of expertise and experience on staff. The link for this article located at The Register UK is no longer available. . Rackspace, he said, operates a skunkworks in which it is considering approaches such as asking CPU-m. rackspace, leading, effort, create, group, top-tier, cloud, companies, hopes. . Dave Wreski
Google is finalizing an agreement with the National Security Agency to help the search giant ward off cyberattacks, according to the Washington Post. The electronic surveillance organization is expected to help analyze a cyberattack on Google that the company said originated in China, so that the company can better defend itself against future attacks, the newspaper reported Wednesday. . The arrangement is reportedly being designed to allow the two groups to share information without violating Google's privacy policies or laws governing online communications. Google declined to comment on the report, and the NSA did not immediately respond to a request for comment. Google disclosed in January that e-mail accounts belonging to human rights activists in China had been compromised and said the attacks originated in China. The company said it discovered the attacks in mid-December. And while it did not specifically implicate the Chinese government, Google said it may withdraw from doing business in China. China's government responded by reiterating that companies doing business in that country must respect and adhere to its laws and later issued statements denying any state involvement in the cyberattacks, as well as defending its Internet censorship. China also warned of strained U.S.-China relations after U.S. Secretary of State Hillary Rodham Clinton formally denounced Internet censorship in a speech. The link for this article located at CNET is no longer available. . Microsoft and FBI establish a partnership to enhance surveillance protocols aimed at countering threats from Russia.. Google NSA Partnership, Cyber Defense, Information Sharing, Security Strategies, Cyberattacks. . Anthony Pell
Cisco, NetApp and VMware announced a project to improve the security of virtualization deployments, with a focus on isolating applications that use the same physical network, server and storage resources in multi-tenant systems.. Cisco, NetApp and VMware Tuesday announced a project to improve the security of virtualization deployments, with a focus on isolating applications that use the same physical network, server and storage resources in multi-tenant systems. Virtualization security remains a work in progress The companies are providing clients a The link for this article located at ComputerWorld is no longer available. . Dell, EMC, and Red Hat announce a collaboration aimed at enhancing safety in cloud environments, focusing on data protection strategies.. Virtualization Security, Cisco Collaboration, Network Isolation. . LinuxSecurity.com Team
" The security chiefs of several large infrastructure and software vendors said they are doing all they can do to embed security into their products, but they agreed that more work must be done to improve security between their platforms. " How well does the open source community spread security issues? Does Redhat and Novel work together to improve security? One of the best ways to improve security is to have all players share their patches to fix vulnerabilities fast. . Secure software code is a priority at Oracle, said Oracle CSO, Mary Ann Davidson. She suggested more collaboration between vendors on security issues and called on the US National Institute of Standards and Technology (NIST) to encourage the development of a secure software auditing standard. Davidson said such a standard could force better collaboration and ultimately reduce flaws in software code. The link for this article located at ComputerWeekly.com is no longer available. . At Oracle, safeguarding software code is paramount, highlighting partnerships with vendors to improve security protocols and methodologies.. Secure Software, Collaboration In Security, Vendor Cooperation, Code Auditing Standards. . LinuxSecurity.com Team
It might not seem as if a building security guard and a network administrator have much in common. But they do--and the distinction between the two is blurring more every day. It's true that the people who control building access from security desks and those securing computer networks both watch traffic and walk perimeters to safeguard an organization's assets. But now, technology, tighter security controls, federal regulations and potential cost benefits are bringing the two traditionally separate worlds together--and the convergence is driving industry alliances that may have seemed unusual in the past. . Oracle, for example, has partnered with Honeywell and Lenel to make its identity and access-manager software work with the physical access systems sold by those companies. A similar announcement from Novell and Honeywell is expected in coming weeks. "It used to be the guns, gates and guards versus the bit chasers and the hacker trackers," said Howard Schmidt, president of the Information Systems Security Association, an international group of IT security professionals. "Technology has fundamentally changed the way all those groups do business. We're much more united today than in the past." Unifying technologies include network-connected surveillance cameras and mechanisms to control building access that tie into the same systems used to grant network access, said Schmidt, a security consultant who has served as cybersecurity adviser to the White House and ksecurity executive at Microsoft and eBay. "We're seeing the technologies that used to be restricted to physical space--the cameras, the alarm systems, the card readers--all of which were unique to a hard-wired analog environment, moving into an IP-based digital system," Schmidt said. The Internet Protocol, or IP, is used to connect computers on modern networks. Software can catch what the human eye might not, such as somebody sneaking into a building behind another person who just swiped a security badge. Also, a single system forcredentials can replace multiple access systems and passwords. One badge, or smart card, could be used to enter buildings, log on to networks and buy lunch in the campus cafeteria. Removing security silos "It is all about removing the silos around security," said Wynn White, vice president of security and management products at Oracle. Many software applications already let users sign on with a single password--the integration of physical and logical security takes that several steps further, he said. Through integration, organizations will get a better view of their overall security, said Geoffrey Turner, an analyst at Forrester Research. "You now are able to follow through in securing both tangible and intangible assets," he said. Ultimately, this should provide more security for employees, as well. The link for this article located at ZD Net is no longer available. . Oracle, for example, has partnered with Honeywell and Lenel to make its identity and access-manager . might, building, security, guard, network, administrator, common. . Brittany Day
Get the latest Linux and open source security news straight to your inbox.