Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
The Kali Linux distribution is going to switch to a new security model by defaulting to a non-root user starting with the upcoming 2020.1 release. Learn more: . This change will come with the release of the 2020.1 version scheduled for late January 2020, but users can already test it via the daily builds . They will also be able to test it by downloading and running theweekly images released until Kali 2020.1 will be officially available. The link for this article located at Bleeping Computer is no longer available. . In the 2020.1 release, Kali Linux adopts a safety-first approach by defaulting to non-administrative user accounts, significantly improving user security.. Kali Linux Release, User Privilege Changes, Default Non-Root User, Linux Security Model. . LinuxSecurity.com Team
We love Docker and containers. But, the more we use containers the more we worry exactly what it is we're running when we spin them up. So, Linux giant and cloud power Red Hat and Black Duck, a leader in automating securing and managing open-source software, are working together on establishing a secure and trusted model for containerized application delivery. . We love containers because they enable consistent operating environments for development, testing, and deployment. That's the good news. The bad news is that container security has lagged behind its advantages. . Red Hat and Black Duck's partnership enhances container security, ensuring applications deliver trust through integration of open source management and robust container tools. Docker Security, Open Source Management, Trusted Containers, Application Security, Container Ecosystem. . LinuxSecurity.com Team
Despite the numerous advantages presented by cloud computing, security is still the biggest factor holding back more widespread adoption by businesses. A recent survey by AlienVault found that an overwhelming 90 percent of organisations are still concerned about cloud security. . But many people don't realise that the cloud also presents a great opportunity for security. The automation and scale provided by the cloud gives us a platform that we can secure far better than any in the past. The cloud is not an inherently insecure environment. . But many people don't realise that the cloud also presents a great opportunity for security. The aut. despite, numerous, advantages, presented, cloud, computing, security, still, biggest, factor. . Anthony Pell
The National Security Agency has submitted its new, label-based data store software to the Apache Software Foundation, in hopes that others will further develop it for use in secure systems. . Called Accumulo, the software uses "expressive, fine-grained" labels that can tag each cell in a data store. Security policies can then be applied to the individual labels to, for example, allow an external server to access some cells but not others. Based on Google's Big Table design, Accumulo is a simple key/value data store, where providing the system with the key will return any data associated with that key. Featuring a distributed design, Accumulo can be run across multiple servers, making it a good candidate for managing big data systems, the NSA said. The link for this article located at Network World is no longer available. . Called Accumulo, the software uses 'expressive, fine-grained' labels that can tag each cell in a dat. national, security, agency, submitted, label-based, store, software, apache. . Alex
A new week, a new rash of attacks against security vendors, email marketers and banks. It would be easy to point fingers and laugh at the irony, especially in the case of security vendors, but that would be both petty and shortsighted.. The stark reality is that security breaches can, will and do happen to everyone. For every security control and process we put in place, somewhere else there's a vulnerability, a weakness, an untrained employee or a path of least resistance for an attack. All the point solutions in the world are not going to make us any more secure. What we desperately need is a new model for integrating security solutions across vendors, across devices, across operating systems and across the globe. Companies today are faced with a fundamental security conundrum. Their networks, applications and end-user devices are made up of a patchwork of dozens if not hundreds of vendor solutions. Each vendor may offer security features in their apps, security appliances, or even an entire range of security solutions. None of them really interoperate with any of the other vendors' security solutions (not unless you consider LDAP and syslog to be interoperability). None of them work on other vendor network devices. The link for this article located at Network World is no longer available. . Cyber threats are an ongoing challenge for all suppliers. It's essential to implement protective measures across systems seamlessly.. Security Integration, Cyber Attacks, Vendor Security Solutions, Network Protection. . LinuxSecurity.com Team
The so-called Zero Trust model for security proposed by Forrester Research earlier this month has revived debate about the way organizations secure their networks.. Zero Trust means end users are no more trusted than outsiders, and that organizations must inspect all traffic, from the outside and on the inside as well. While this concept has stirred Big Brother worries among skeptics, it also resonates with some experts in light of the end user application-borne attacks as well as malicious or careless insiders. But does this user threat trend merit a whole new security model? Most security experts agree that you can't trust your internal network and have to assume you've been compromised, so it's a matter of detecting and stopping breaches before any information is stolen or damage is done. It's just that inspecting all internal traffic can be a tall order -- and maybe overkill. The link for this article located at Dark Reading is no longer available. . The concept of Zero Trust dictates that every user is scrutinized in the same way as external entities, emphasizing rigorous examination of all data flows.. Zero Trust Security, Network Inspection, End User Threats, Security Models. . Anthony Pell
After removing Google's Android driver code from the Linux kernel, Novell Fellow and Linux developer Greg Kroah-Hartman has argued that the mobile OS is incompatible with the project's main tree. Kroah-Hartman deleted the Android drivers on December 11 - Android code is no more as of version 2.6.33 of the kernel release - and yesterday, with a post to his personal blog, he explained the move in detail.. "No one cared about the code, so it was removed," writes Kroah-Hartman. "As I've stated before, code in the staging tree needs to be worked on to be merged to the main kernel tree, or it will be deleted." But the larger problem, he continues, is that Android uses a new lock type, new hooks for its "sometimes bizarre" security model, and a revamped framebuffer driver infrastructure. All this, he says, prevents "a large chunk" of Android drivers and platform code from merging into the main kernel tree. Google, he ultimately argues, has forked its mobile OS. Google did not immediately respond to our request for comment. But in a pair of posts to LWN.net, Mountain View open source guru Chris DiBona says that Android isn't in the main tree because the main tree doesn't want it. The link for this article located at The Register is no longer available. . 'No one cared about the code, so it was removed,' writes Kroah-Hartman. 'As I've stated before, code. linux, removing, google's, android, driver, kernel, novell, fellow, developer. . LinuxSecurity.com Team
When you add the responsibility for information and security in an organisation that ranges across Europe, life becomes even more complex. You also need to accommodate differences in mindset about legislative severity, and differences in national character. Within countries, many of the challenges remain the same for CIOs, wherever they are based. They must try to operate a security model that has changed from a "fortress" - where everything was kept out - to an "airport" style security. Now everyone is rushing around in different directions aiming for different destinations, and their credentials to "fly" or interact with the company need to be checked. . Organisations need to welcome everyone in from partners to customers and hope they are friends, not foes. The key word is now "deperimeterisation". But opening up the perimeter means organisations require knowledge of identities through trust and confidence. The link for this article located at ComputerWeekly.co.uk is no longer available. . Entities need to evolve alongside fresh security paradigms, welcoming deperimeterisation and placing trust in identities.. Information Management, Security Frameworks, Digital Identity, Trust Relationships. . Benjamin D. Thomas
Get the latest Linux and open source security news straight to your inbox.