Explore top 10 tips to secure your open-source projects now. Read More

×
Alerts This Week
Warning Icon 1 598
Alerts This Week
Warning Icon 1 598

Stay Ahead With Linux Security News

Filter%20icon Refine news
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":0,"type":"x","order":4,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security news

We found 57 articles for you...
78

openSUSE: Deepin Desktop Removal - Security Risks and Protocols

Alright—it’s not just about pulling a desktop environment from the repositories; it’s about what happens behind the curtain, things you might not notice until they impact your systems. If you’re managing openSUSE machines, this isn’t the kind of news you can shrug off or file away for later. The Deepin Desktop Environment (DDE) wasn’t removed because of some technical quirks or compatibility issues. No, this goes deeper than that. It’s about how security policies were sidestepped—how something sensitive found its way around the system’s safeguards. . That alone should make any Linux admin sit up straight. Now, think about what that means for you—not just for the security of your systems but for the precedent this sets. A desktop environment that seemed perfectly fine on the surface had a problematic backstory. We trust these review processes because they’re supposed to keep risky or harmful code out of the systems we rely on. When that trust is broken, even unintentionally, it forces every admin to ask hard questions about what else might be slipping through the cracks. This isn’t just about Deepin. It’s a reminder to dig deeper, check dependencies, and always keep security at the forefront before hitting “install.” Let’s break this down. The Security Policy Violation Recently, openSUSE made headlines when it decided to remove Deepin Desktop Environment (DDE) from its repositories following security policy violations through workarounds that bypass mandatory reviews of sensitive system components. The root cause of the Deepin removal stems from the deliberate circumvention of security protocols. The Deepin packager introduced a "license agreement" dialog within the deepin-feature-enable package, which allowed users to install components that should have undergone stringent security reviews. This included critical system configurations like D-Bus system services and Polkit policies , which play a vital role in the system's secure operation. TheDeepin developers exposed openSUSE systems to potential vulnerabilities by bypassing the established security review processes. These components could interact with core system functionalities, making their unchecked operation particularly risky. The decision to remove Deepin was necessary to uphold openSUSE's commitment to maintaining a secure and reliable Linux distribution. Addressing Historical Concerns The issues leading to this decisive action weren't isolated incidents. openSUSE developers have long grappled with several challenges related to the stability and security of the Deepin desktop environment. Recurring vulnerabilities were reported in Deepin's core components, and the responses from Deepin’s upstream developers were often slow and inadequate. Communications with the Deepin team proved challenging, largely due to language barriers and possible resource constraints. This consistent lack of responsiveness and the persistence of unresolved security flaws further diminished confidence in the Deepin environment's reliability. As such, retaining Deepin in the openSUSE repositories would have continued to pose unacceptable risks. Understanding the Impact on openSUSE Users Removing Deepin from repositories like Tumbleweed and Leap 16.0 has immediate and long-term implications for openSUSE users. The primary benefit of this decision is enhanced security. OpenSUSE will now experience better compliance with its stringent security protocols by eliminating a potentially unsafe desktop environment. This reduces the likelihood of exploitation through vulnerabilities that stem from skipping necessary safety checks. However, this change might be disconcerting for users who had grown accustomed to Deepin's interface and features. Transitioning away from Deepin may require some adjustment, but it’s a necessary step for maintaining a secure operating environment. Deepin users now need to explore alternative desktop environments fully supported and rigorously reviewed by the openSUSEsecurity team. Navigating the Risks Safely As system administrators pivot away from Deepin, it's essential to consider more secure alternatives available within the openSUSE ecosystem. Desktop environments like KDE Plasma, GNOME, and XFCE offer robust functionality while adhering to openSUSE’s security standards. These options offer comparable, if not superior, user experiences without compromising system integrity. First and foremost, it’s wise to avoid using Deepin unless necessary. This means refraining from manually adding Deepin’s development project repositories, which could expose systems to the same unreviewed vulnerabilities that prompted this change. If circumstances make using Deepin necessary, administrators should establish strict monitoring protocols to oversee updates and configurations carefully. Making sure that packages' origins and integrity are verified is crucial. Regular security monitoring is even more imperative in these scenarios. Conducting routine scans to identify any vulnerabilities or misconfigurations can help preempt potential security breaches. For environments where Deepin is temporarily necessary, network isolation techniques can prevent potential threats from spreading beyond a confined system. Another vital step is communicating these changes to end-users. Users must understand why the removal has taken place and its security benefits. Encouraging users to migrate to more secure desktop environments will help maintain a protected operational environment. Providing guidance and support during this transition can alleviate concerns and support a smoother shift away from Deepin. Looking Ahead as an openSUSE User The decision to remove Deepin underscores openSUSE’s commitment to stringent security measures. It also highlights the importance of maintaining transparent and responsive communication channels with upstream developers. For Deepin, rebuilding trust will require addressing these historical security issues and improving collaborationwith downstream distributions like openSUSE. This incident reminds administrators and users of security protocols' critical role in safeguarding Linux environments. Trust in the software components that power an operating system is paramount, and compliance with established security measures is non-negotiable. OpenSUSE has affirmed its dedication to providing a reliable and safe user experience by fostering an environment where security takes precedence. Removing Deepin from openSUSE repositories may have caused some initial disruption, but it is a strategic move towards a more secure future. As openSUSE continues to evolve, its firm stance on security reassures users and administrators that their digital safety remains a top priority. . The removal of Deepin from openSUSE emphasizes valid security measures and the importance of stringent compliance protocols.. about, alright—it’s, pulling, desktop, environment, repositories. . Brittany Day

Calendar%202 May 12, 2025 User Avatar Brittany Day Vendors/Products
82

Australia's Encryption Bill: No Backdoors for Encrypted Products

A little over a week since the window closed for public submissions on the government's draft Assistance and Access Bill, Minister for Home Affairs Peter Dutton on Thursday introduced the Bill into the House of Representatives.. "The legislation will not weaken encryption or mandate backdoors into encryption. The Bill specifically provides that companies cannot be required to create systemic weaknesses in their encrypted products, or be required to build a decryption capability," Dutton said in a second reading speech. The link for this article located at ZDNet is no longer available. . 'The legislation will not weaken encryption or mandate backdoors into encryption. The Bill specifica. little, since, window, closed, public, submissions, government's, draft, assist. . Brittany Day

Calendar%202 Sep 20, 2018 User Avatar Brittany Day Government
79

OpenSSL Yearly Review: Evolving Vulnerability Management Strategies

Over the last 10 years, OpenSSL has published advisories on over 100 vulnerabilities. Many more were likely silently fixed in the early days, but in the past year our goal has been to establish a clear public record. In September 2014, the team adopted a security policy that defines how we handle vulnerability reports. One year later, I. Our policy divides vulnerabilities into three categories, and defines actions for each category: we use the severity ranking to balance the need to get the fix out fast with the burden release upgrades put on our consumers. The link for this article located at OpenSSL Team is no longer available. . Our policy divides vulnerabilities into three categories, and defines actions for each category: we . years, openssl, published, advisories, vulnerabilities. . LinuxSecurity.com Team

Calendar%202 Sep 03, 2015 User Avatar LinuxSecurity.com Team Security Projects
67

IAB Advocates Universal Data Encryption Despite Security Sector Pushback

The Internet Architecture Board (IAB) has issued a sweeping directive . The statement also leaves unaddressed what will be inevitable howls of protest from the law enforcement and national security sectors, whose surveillance activities have long motivated those pushing for ubiquitous encryption.. The Internet Standards Committee advocates for robust encryption practices, even in light of possible opposition from security forces.. Data Privacy, Encryption Standard, Internet Architecture, Security Policy. . LinuxSecurity.com Team

Calendar%202 Nov 18, 2014 User Avatar LinuxSecurity.com Team Cryptography
82

NSA Nominee Michael Rogers Addresses Zero-Day Issues and Exploits

In response to a series of questions posed before his confirmation hearing in front of the Senate Armed Services Committee, National Security Agency director nominee Vice Admiral Michael Rogers said that the NSA is working with the White House to create a process to determine what to do with zero-day vulnerabilities that the agency uncovers. . In his response to the questions, posted on the Armed Services Committee. During a recent confirmation hearing, the National Security Agency's nominated leader answered Senators' questions about the agency's position on zero-day vulnerabilities and policies. NSA Policies, Threat Management, Zero-Day Exploits, Security Response. . Alex

Calendar%202 Mar 14, 2014 User Avatar Alex Government
79

Google's Zero-Day Disclosure Policy Change: Mixed Reactions from Experts

Google's dramatic shift to a seven-day grace period before disclosing actively exploited zero-day vulnerabilities in software has drawn both praise and derision from security experts.. Security engineers Chris Evans and Drew Hintz said on Wednesday in the Google Online Security Blog that the company was dropping the previous 60-day window. The link for this article located at CSO Online is no longer available. . Security engineers Chris Evans and Drew Hintz said on Wednesday in the Google Online Security Blog t. google's, dramatic, shift, seven-day, grace, period, disclosing, actively, exploited, zero-day. . LinuxSecurity.com Team

Calendar%202 Jun 03, 2013 User Avatar LinuxSecurity.com Team Security Projects
74

Rethinking Security Strategies for IPv6 Networks and Open Access

The switch from IPv4 to IPv6 will force many organizations to rethink the way their networks are defended. The result will be a shift away from the "guilty until proven innocent" attitude to incoming network traffic, toward one of "paranoid openness.". That's the view of Eric Vyncke, a Distinguished Engineer at Cisco Systems. Talking at the RSA Conference in London last month, he said that it is only when organizations become more open to incoming traffic that they will get the full benefits of IPv6. Many companies have delayed thinking about a move to the next generation IPv6 Internet protocol because there is little benefit in being a "first mover," but sometime in the next few years the remaining free IPv4 IP addresses will be used up. When that happens the world will be forced over time to move to IPv6, which offers 128 bit addresses (instead of IPv4's 32 bit addresses), resulting in a staggering 2 ^ 128 different possible IP addresses . That's more than enough to assign a unique IP address to every atom on the surface of the earth, let alone every network connected server, desktop computer, laptop, smartphone, Web camera, and any other device that will ever be manufactured and connected to a corporate network. The benefits for many organizations of this end-to-end IPv6 connectivity could be very significant indeed. The link for this article located at Enterprise Networking Planet is no longer available. . The transition to IPv6 requires a thorough evaluation of security protocols due to its distinct features compared to IPv4, enhancing risk management and defense. IPv6 Security,Cybersecurity Strategies,Network Defense Policies. . Anthony Pell

Calendar%202 Nov 23, 2010 User Avatar Anthony Pell Network Security
76

Insights From Gartner on Security Policies and Business Risks

Understanding the business risk posed due to security threats is crucial for IT managers and security officers, two analysts have claimed. Addressing a media roundtable in Sydney at the Gartner Symposium, Andrew Walls and Rob McMillan said CIOs and CSOs must be abreast of their organisations. The link for this article located at Network World is no longer available. . The link for this article located at Network World is no longer available.. understanding, business, posed, security, threats, crucial, managers, securit. . Anthony Pell

Calendar%202 Nov 19, 2010 User Avatar Anthony Pell Organizations/Events
News Add Esm H340

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":0,"type":"x","order":4,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200