Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Security experts and lawmakers say that creating a “backdoor” to unlock devices and messages would make those products vulnerable to hackers. What are your thoughts on this? Duringa speech at a cybersecurity conferenceon Tuesday, Attorney General William Barr spoke out against the tech industry’s practice of using encryption tools that can only be unlocked by the end user, arguing that it endangers lives and makes it more difficult for law enforcement to do their jobs. Barr said that encryption can be a valuable tool when it comes to protecting information from cybercriminals. He objected, however, to tech companies’ refusal to create ways for law enforcement to access locked or encrypted devices when they are issued search warrants. . The link for this article located at Security Today is no longer available. . Cybersecurity specialists analyze the Attorney General's position regarding encrypted communications and the accessibility challenges for law enforcement.. Encryption Debate,Cybersecurity Tools,Law Enforcement Access. . Brittany Day
Encryption is hot. Perhaps that's because its been around so long it's no longer seen as a black art. Or perhaps security issues have grown so prevalent, everyone wants some sort of encryption as a truly secure way of stopping the pain of those problems. . Indeed whatever the reason, encryption technologies seem to be behind a series of important security happenings of late. Here's a look at some of the more interesting happenings shaping encryption today: The backdoor question: The Obama administration wants e-mail service providers using encryption technology to leave in a backdoor so that the government can peer in if it needs to. According to a New York Times article this week, the Obama administration plans to submit to lawmakers next year that requires e-mail transmitters like BlackBerry, social networking Web sites like Facebook and direct "peer to peer" messaging like Skype The link for this article located at Network World is no longer available. . Data protection mechanisms are crucial in today’s safety concerns as debates surrounding vulnerabilities intensify.. Encryption Methods, Data Security Trends, Information Protection. . LinuxSecurity.com Team
" Standing at the center of this debate on how much security is enough are agency chief information security officers, who report to chief information officers. " Join the debate. Do you think if the government use Linux machines and tools more it would help their security problems? I might come down to ease of use vs security. . Security measures are restrictive by definition and Federal Agencies can only implement so many of them before the backlash sets in. Many times, after being over-regulated, employees will simply find a route around the security precautions, eliminating the measures' function and even making data theft or loss easier. . Security measures are restrictive by definition and Federal Agencies can only implement so many of t. 'standing, center, debate, security, enough, agency, chief, information. . Bill Locke
I've been reading Bruce Schneier's Book on cryptography for the last couple of days, and one of the main concepts in the text struck me as interesting. One of the points of discussion when looking at the security of a given algorithm is its exposure to scrutiny. Bruce explicitly states that no one should ever trust a proprietary algorithm. He states that with few exceptions, the only relatively secure algorithms are those that have stood the test of time while being poured over by thousands of cryptanalysts. . . .. I've been reading Bruce Schneier's Book on cryptography for the last couple of days, and one of the main concepts in the text struck me as interesting. One of the points of discussion when looking at the security of a given algorithm is its exposure to scrutiny. Bruce explicitly states that no one should ever trust a proprietary algorithm. He states that with few exceptions, the only relatively secure algorithms are those that have stood the test of time while being poured over by thousands of cryptanalysts. Similar Situations What struck me is the similarity between this mode of thought and that of the open source community on the topic of security. In that debate there is much disagreement about which is better - open or closed -, while in the crypto world it's considered common knowledge that open is better. According to the crypto paradigm, having any measure of an algorithm's security based on the fact that it's a secret is generally a bad thing. There, keys are what makes the system secure - not the algorithm being a secret. I realize there are some differences in these two models, but they are small enough, in my opinion, to say that those participating in the open/closed source debate could learn something by tapping into the body of knowledge held by this related field. The link for this article located at osviews.com is no longer available. . Bruce Schneier highlights the importance of scrutinizing cryptographic algorithms to strengthen defenses, advocating for transparency inopen-source development for trust and resilience. Open Source Algorithms, Security Scrutiny, Cryptography Insights, Community Discussion. . LinuxSecurity.com Team
The Initiative for Software Choice, a software industry trade group whose members include Microsoft, Intel and Cisco, has advised the U.S. Department of Defense not to adhere to a policy that promotes open source software at the expense of proprietary software. . . . . The Initiative for Software Choice, a software industry trade group whose members include Microsoft, Intel and Cisco, has advised the U.S. Department of Defense not to adhere to a policy that promotes open source software at the expense of proprietary software. The group has issued a report arguing that the DoD's evaluation of software purchases should not be influenced by "a preconception that open source software is somehow inherently more secure." "ISC is against government policy that restricts procurement to any kind of software," ISC executive director Bob Kramer told NewsFactor. He noted that the group has no prejudice against any software, but that government procurement policies "should focus on obtaining the best software to solve the problem." The ISC Mission The Washington, D.C.-based ISC was founded in May. The group states it is "dedicated to the principle that governments should procure their software products on their merits rather than categorical preferences." Therefore, its goal is to "educate policymakers about the need to remain neutral about the governmental purchase of software." Toward that goal, the ISC recently issued a report that countered another report written by defense contractor MITRE. The MITRE report noted that open source software "plays a more critical role in the [DoD] than has generally been recognized," and that the DoD has 115 open source applications with 251 identified uses. It then concluded that open source products are a viable alternative to proprietary products made by Microsoft and others, and recommended that they be used more widely. The ISC Response The ISC strongly contested MITRE's conclusions, stating that MITRE's preference for open source stymies software innovation. Thebest way to promote innovation, according to the ISC, is to "ensure that customers -- both public and private -- have a broad range of choices in their software purchasing decisions." In particular, the ISC disagreed with the MITRE report's findings that open source products allow "early and rapid closure of security holes ... [which is] generally impractical in closed source products." In arguing against this finding, the ISC stated that "no single development mode inherently produces safer, more secure software." GPL Issues The ISC report also found fault with MITRE's conclusions about the General Public License (GPL). The GPL , which is used by some programmers in the open source community, requires developers to make their source code publicly available if they modify a program already licensed under the GPL. The ISC noted that, if there were a government policy requiring all software purchases to be licensed under the GPL, it would entail significant loss for commercial software developers. These developers "expend significant resources walling off their proprietary intellectual property," the report said. ISC pointed to MITRE's findings that more than 50 percent of the DoD's open source products are GPL-based, and that if proprietary developers were required to use the GPL, it would "foreclose proprietary companies ... from further developing and commercializing the results." . The Initiative for Software Choice advises the DoD to balance proprietary and open source software rather than favoring one.. Open Source Software, Proprietary Software, Government Policy, Software Innovation, DoD Procurement. . LinuxSecurity.com Team
There is a growing debate in the cryptography community over whether the cryptographic keys used in dozens of applications should be considered compromised in light of a recent paper detailing a more efficient way of factoring large numbers. . . .. There is a growing debate in the cryptography community over whether the cryptographic keys used in dozens of applications should be considered compromised in light of a recent paper detailing a more efficient way of factoring large numbers. On one side are security and cryptography enthusiasts--professionals and amateurs alike--who believe that the technique, described in a paper published last fall by a University of Illinois-Chicago mathematician, could enable someone with enough time and money to build a machine capable of factoring keys as large as 1024 bits derived from the RSA algorithm in a relatively short amount of time. Such a breakthrough theoretically would jeopardize the security of common protocols and applications such as Pretty Good Privacy (PGP), IPSec, SSH and others, all of which are typically deployed with keys smaller than 1024 bits, these people contend. The link for this article located at ExtremeTech is no longer available. . There is a growing debate in the cryptography community over whether the cryptographic keys used in . there, growing, debate, cryptography, community, whether, cryptographic. . LinuxSecurity.com Team
Jeremy Allison goes against a Microsoft security specialist in this open source vs proprietary debate. "I believe that the open source development model does create software with significantly fewer exploitable holes than proprietary software. ... I know that programmers of proprietary . . . . Jeremy Allison goes against a Microsoft security specialist in this open source vs proprietary debate. "I believe that the open source development model does create software with significantly fewer exploitable holes than proprietary software. ... I know that programmers of proprietary software leave holes and take more liberties than open source programmers. The reasons are simple: Their management and marketing departments are screaming for the code to ship, doing it right is harder than doing it quickly and, after all, they think, who is going to know? I've been in this situation myself. On the other hand, most open source software is written by people for whom programming is not a chore. It's a craft, and they take great pride in doing their work properly. Away from the demands of marketing and management, they are able to create the code that they want to write, not the code that will make the most money. The difference in the quality of the code produced by the two methods is staggering." The Microsoft side counters with "Commercial software tends to be more secure than open source software, for simple economic reasons. Simply put, you get what you pay for. Commercial development organizations have a powerful motivation to get security right: Their livelihoods depend on it. That's why commercial software firms use advanced tools and follow processes that leverage knowledge of known security flaws to drive "lessons learned" into new code. Commercial software firms not only employ people who are dedicated and passionate about security, they also pay them to do the hard, tedious work - including testing - that's not especially interesting to most open source volunteers." The link forthis article located at Interactive Week is no longer available. . Delving into the ongoing security discourse surrounding open source versus proprietary software, featuring perspectives from industry specialists.. Open Source Security, Proprietary Software, Security Perspectives, Exploitable Holes, Software Development. . LinuxSecurity.com Team
System administrators worldwide recently reported signs that another self-spreading program, or worm, had started to infect Linux systems. The worm's existence has given rise to two schools of thought. One, which feels that the worm will help in securing the system . . . . System administrators worldwide recently reported signs that another self-spreading program, or worm, had started to infect Linux systems. The worm's existence has given rise to two schools of thought. One, which feels that the worm will help in securing the system while the other is of the opinion that a worm is a worm after all and has to be eradicated. In this article we bring you the arguments put forth by the `cool about Cheese' school. The Cheese worm appears to be different. Dubbed the Cheese worm, the program is basically a self-spreading patch. It enters servers that have already been compromised by a previous bit of malicious code--the 3-month-old 1i0n worm--and closes the back door behind it, adding security to the system. Taken individually, the Cheese Worm is not a good thing. The last thing we need is another invasion by some nameless hacker using up our network resources. . System administrators worldwide recently reported signs that another self-spreading program, or worm. system, administrators, worldwide, recently, reported, signs, another, self-spreading, program. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.