Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
You don't have to be a sysadmin to keep your Linux desktop distribution safe from cybersecurity threats. But you do have to follow a few best practices. . It is no secret that Linux is a far more secure option than Windows . From the ground up, Linux was designed to be highly secure. Since I started using Linux (back in '97), I've only had one cybersecurity threat arise, which was a rootkit on a server I inherited. Sadly, that server was so badly compromised that I had to re-install the OS and start from scratch. That was the only instance, in decades, of having to suffer the consequence of a security breach. Otherwise, it's been smooth sailing. You, too, can enjoy the heightened security that comes with the Linux OS. However, you shouldn't just assume that you can install Linux and never worry about security again. My take on security is if a device is connected to a network, it's vulnerable. To that end, I thought I'd share some advice that even those who are brand new to Linux can easily follow. Don't worry, I'm not going to have you editing init scripts, issuing complicated iptables commands, or installing software like fail2ban. Instead, this is all about what new users can do to help prevent malware, ransomware, or other attacks. . Explore basic techniques to bolster your Linux desktop defenses, ensuring protection against a range of online dangers.. Linux Security Best Practices, Desktop Security Tips, Cyber Hygiene for Users. . Brittany Day
In a bid to help U.S. federal agencies protect sensitive, but unclassified information, the National Institute of Standards and Technology (NIST) has updated guidelines for selecting and implementing cryptographic methods. Originally published in 1999, Guideline for Implementing Cryptography in the Federal Government (NIST Special Publication 800-21-1) is intended primarily for federal employees who design computer systems and procure, install and operate security products to meet specific needs. . The link for this article located at SCMagazine is no longer available. . NIST revises its cryptographic standards to bolster data security for government bodies and refine protective strategies.. NIST Cryptography, Federal Data Protection, Security Standards. . LinuxSecurity.com Team
Several U.S. government agencies have teamed with an international Internet security organization to support a set of benchmarks aimed at guaranteeing a minimum security standard for computers. The National Security Agency, the Defense Information Systems Agency and the National Institute of. . .. Several U.S. government agencies have teamed with an international Internet security organization to support a set of benchmarks aimed at guaranteeing a minimum security standard for computers. The National Security Agency, the Defense Information Systems Agency and the National Institute of Standards are among the 170 members of the Center for Internet Security (CIS) that will announce their support Wednesday for a single benchmark to measure the security of Windows 2000 workstations. "This is the single most important development in security this year," said Alan Paller, research director for the System Administration, Networking and Security (SANS) Institute, a founding partner in the CIS. "I think a lot of people will expect (contractors) to step up to the plate and provide computers that meet the benchmark." The security benchmarks act as a good housekeeping seal of approval, testing whether a computer meets its patch and configuration requirements. The Level 1 series for Windows 2000 workstations has more than 500 tests that aim to ensure a minimum level of security. As reported earlier, the CIS has focused on producing benchmarks for several operating systems. The center has benchmarks for Cisco IOS operating system for routers, Windows 2000 and NY, Sun Microsystems' Solaris, Linux and HP-UX, but the government has still not settled on whether the center's specs meet their requirements. The link for this article located at ZDNet is no longer available. . Several U.S. government agencies have teamed with an international Internet security organization to. government, agencies, teamed, international, internet, security, organization. . Anthony Pell
Get the latest Linux and open source security news straight to your inbox.