Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 524
Alerts This Week
Warning Icon 1 524

Stay Ahead With Linux Security News

Filter%20icon Refine news
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security news

We found -2 articles for you...
67

Exploring Quantum Cryptography for Enhanced Secure Communication

Quantum cryptography goes a step further than electronic cryptography through its employment of a stream of photons, the quantum properties of which determine the key. The fun part is that if an intruder observes or intercepts the transmission, those properties get . . . . Quantum cryptography goes a step further than electronic cryptography through its employment of a stream of photons, the quantum properties of which determine the key. The fun part is that if an intruder observes or intercepts the transmission, those properties get changed -- an unavoidable principle of quantum mechanics -- meaning the sender and receiver can tell if anyone is eavesdropping. The link for this article located at LightReading is no longer available. . Quantum cryptography goes a step further than electronic cryptography through its employment of a st. cryptography, quantum, further, electronic, through, employment. . LinuxSecurity.com Team

Calendar%202 Nov 05, 2003 User Avatar LinuxSecurity.com Team Cryptography
74

IEEE 802.11i: New Wireless Security Standards and RSN Methodology

After two years of rousing debate, the body responsible for the Wi-Fi standard is finally putting the finishing touches on its new security standard, IEEE 802.11i. Although this standard's Robust Security Network feature will deliver the level of security the wireless . . . . After two years of rousing debate, the body responsible for the Wi-Fi standard is finally putting the finishing touches on its new security standard, IEEE 802.11i. Although this standard's Robust Security Network feature will deliver the level of security the wireless world is clamoring for, don't be fooled: Your wireless network won't be secure until your transition to RSN is complete. RSN defines two security methodologies--one for legacy hardware based on RC4 and one for new hardware based on AES. The standard also provides the flexibility to add new methodologies if the need arises. RSN uses the IEEE 802.1x port-authentication standard to authenticate wireless devices to the network and to provide the dynamic keys it requires. The task group does not specify any authentication method over 802.1x; it just defines the features such a method must provide. The idea here is to "future-proof" the RSN authentication process. The link for this article located at NWC is no longer available. . Investigate the recent advancements in WLAN security pertaining to the IEEE 802.11i standards and the practical application of its Robust Security Network (RSN) framework.. Wireless Security, IEEE Standards, WLAN Security, RSN Implementation, AES Methodology. . Anthony Pell

Calendar%202 Mar 06, 2003 User Avatar Anthony Pell Network Security
74

Evaluating Internet-Connected Custom Web Applications' Risks

This article is the fourth in a series that is designed to help readers to assess the risk that their Internet-connected systems are exposed to. In the first installment, we established the reasons for doing a technical risk assessment. In the . . . . This article is the fourth in a series that is designed to help readers to assess the risk that their Internet-connected systems are exposed to. In the first installment, we established the reasons for doing a technical risk assessment. In the second article, we started to discuss the methodology that we follow in performing this kind of assessment. The third part discussed methodology in more detail, focussing on visibility and vulnerability scanning. This installment will discuss a relatively unexplored aspect of Internet security, custom Web applications. Of all the possible services on the Internet DNS, e-mail and the World Wide Web are by far the most pervasive. (In fact, in July 2002, the monthly Netcraft Web site survey reported that 37,235,470 active Web servers were connected to the Internet.) Of these, Web services are the most complex and the most frequently abused. Originally a simple text-based information service, the Web has developed into a highly functional interactive application development platform that is being used for almost every possible application on both the Internet and Intranet. Major vendors have recognized the power of the Web and have made significant investments in Web development platforms. These include Sun (Java), Microsoft (Active Server Pages, Site Server and Commerce Server), the open source community (PHP) and others (ColdFusion). Such platforms make it very easy for standard administrators to develop complex applications. A simple wave of the Web development wand and suddenly everybody's a programmer, even me! Web applications are often developed by under-qualified, inexperienced developers. Unknowingly many programmers make errors that provide potential intruders with precisely the vector they need to penetrate theprivate network. As these applications are built on standard platforms, they tend to look similar, and tend to have similar security weaknesses. The link for this article located at SecurityFocus is no longer available. . This article is the fourth in a series that is designed to help readers to assess the risk that thei. article, fourth, series, designed, readers, assess. . Anthony Pell

Calendar%202 Oct 04, 2002 User Avatar Anthony Pell Network Security
News Add Esm H340

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200