Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 461
Alerts This Week
Warning Icon 1 461

Stay Ahead With Linux Security News

Filter%20icon Refine news
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security news

We found 17 articles for you...
81

13 Key Strategies To Improve Security And Privacy On Ubuntu

Learn 13 Linux security best practices you can follow to avoid privacy risks and data leaks. . Everybody should be concerned about their privacy and security in this day and age. It is a common misconception that if you are running Linux you do not need to concern yourselves with privacy and security issues. Every operating system has risks and vulnerabilities that can be exploited and leave you exposed. . Uncover vital Ubuntu Linux privacy and security configurations to safeguard your information and maintain confidentiality effectively.. Ubuntu Security, Linux Privacy, Security Best Practices. . LinuxSecurity.com Team

Calendar%202 Jun 28, 2021 User Avatar LinuxSecurity.com Team Privacy
79

Exploring Yescrypt: Innovative KDF For Enhanced Password Security

yescrypt is a password-based key derivation function (KDF) and password hashing scheme. It builds upon Colin Percival's scrypt and includes classic scrypt, a minor extension of scrypt known as YESCRYPT_WORM (named that for "write once, read [potentially] many [times]", which is how scrypt works), and the full native yescrypt also known as YESCRYPT_RW (for "read-write"). . Like it or not, password authentication remains relevant (including as one of several authentication factors), password hash database leaks happen, the leaks are not always detected and fully dealt with right away, and even once they are many users' same or similar passwords reused elsewhere remain exposed. To mitigate these risks (as well as those present in other scenarios where password-based key derivation or password hashing is relevant), computationally expensive (bcrypt, PBKDF2, etc.) and more recently also memory-hard (scrypt, Argon2, etc.) password hashing schemes have been introduced.. Password security continues to be crucial, as yescrypt's key derivation function and hashing approach help reduce vulnerabilities from password breaches.. Yescrypt, Password-Based, Key Derivation, Hashing Solutions. . LinuxSecurity.com Team

Calendar%202 Mar 16, 2018 User Avatar LinuxSecurity.com Team Security Projects
79

Startup Security Risks and Best Practices for Data Protection

For startups, user growth, product growth, virality, marketing usually goes on the top of their priority list. As part of product planning cycles, embedding information security into their product/service is the last concern for most startups.. Which is deeply ignored here? Information and data security. Often you see devops engineers, systems engineers, infrastructure engineers or system administrators wear the security hat in these startups and performs some of the small security fixes or patches. Even though they can perform research on the procedures to apply patches, harden databases, or implement remediation as a result of the industry breaches, they might not take every decision or option from security perspective. The link for this article located at TechWorld is no longer available. . Emerging businesses frequently overlook essential information and cybersecurity protocols while scaling operations and developing their product strategies.. Startup Security, Data Protection, Security Practices, Growth Phases, Risk Management. . LinuxSecurity.com Team

Calendar%202 Nov 11, 2014 User Avatar LinuxSecurity.com Team Security Projects
77

Exploring Red Hat's Approach To Linux Security Management

How does Red Hat go about building and developing a secure Linux operating system? That question was asked and answered at the Red Hat Summit this week by Josh Bressers, who heads the Red Hat Product Security Team.. Bressers explained that the security process involves both manual and automated activities for quality assurance. Linux is further reinforced with what Dan Walsh, senior principal software engineer at Red Hat called a "silver bullet" for Linux security -- SELinux. The link for this article located at eSecurity Planet is no longer available. . Bressers explained that the security process involves both manual and automated activities for quali. about, building, developing, secure, linux, operating, system, question. . LinuxSecurity.com Team

Calendar%202 Jun 17, 2013 User Avatar LinuxSecurity.com Team Server Security
72

Questioning Firewalls' Place in Modern Network Security

Once, firewalls were useful for certain types of attacks. Now they're more trouble than they're worth -- and create a false sense of security into the bargain . Firewalls need to go away. I'm just saying what we all already know. Firewalls have always been problematic, and today there is almost no reason to have one. Computer firewalls have been with us since the 1980s. Even early on it was pretty clear that they didn't really work; if they did, we would have defeated malicious hackers and malware a long time ago. But at least back in the day there was a decent reason to need them. The link for this article located at InfoWorld is no longer available. . Firewalls need to go away. I'm just saying what we all already know. Firewalls have always been prob. they're, firewalls, useful, certain, types, attacks, trouble. . Dave Wreski

Calendar%202 May 15, 2012 User Avatar Dave Wreski Firewalls
79

Call For Security By Default Policies In Major Companies

In this op-ed, a cybersecurity researcher argues that major companies are leaving customers at risk by not enforcing security by default. The opinions expressed here do not necessarily represent the opinions of Ars Technica. . Major social networks, e-mail providers, and communications companies offer products with insecure default settings, needlessly exposing their customers to hacking, identity theft, and government surveillance. Some firms offer security options that can be used to protect against common attacks; however, they are frequently so hidden in obscure configuration menus as to be invisible to the average user. Consequently, most consumers don't know about these options, and so they neither seek them out nor enable them. The article located at arsTechnica is no longer available. . Leading corporations jeopardize user protection by utilizing vulnerable initial settings, necessitating a transition to inherent security protocols.. Security By Default, Cybersecurity Strategies, Privacy Issues. . LinuxSecurity.com Team

Calendar%202 Aug 18, 2011 User Avatar LinuxSecurity.com Team Security Projects
77

Essential Strategies for Data Protection on World Backup Day

Hello, world! Today it's your Backup Day. World Backup Day is a new idea promoted by a small team of Redditors, and it's a good idea. You can never be too careful when it comes to backing up.. By the way, this is about your data, and not calling your buddies over for help in a hostile situation, which is not really my area of expertise. So let's talk backups! Basically it means putting your data in multiple places so that if something happens to one place (let's say you forget your laptop on the top of your car and subsequently back over it), that important PowerPoint presentation you've been working on isn't lost. The link for this article located at CNET is no longer available. . By the way, this is about your data, and not calling your buddies over for help in a hostile situati. world, backup, hello, today, promoted, small. . LinuxSecurity.com Team

Calendar%202 Apr 01, 2011 User Avatar LinuxSecurity.com Team Server Security
67

Understanding AES Encryption's Role in Security Practices

Nearly nine years after the publication of FIPS 197, AES encryption remains the de facto standard today for symmetric encryption, and brute-force attacks remain infeasible, at least for the foreseeable future. To date, most attacks methods have focused on weaknesses or characteristics in specific implementations, called "side-channel attacks," not on the algorithm itself.. Threats to computer and network security Planning for the next peak season? Ensure your website is fast, secure and available 24/7. Click here to learn how. increase with each passing day and come from a growing number of sources. No computer or network is immune from attack. A recent concern is the susceptibility of the power grid and other national infrastructure to a systematic, organized attack on the United States from other nations or terrorist organizations. Encryption, or the ability to store and transmit information in a form that is unreadable to anyone other than intended persons, is a critical element of our defense to these attacks. Indeed, man has spent thousands of years in the quest for strong encryption algorithms. The link for this article located at Tech News World is no longer available. . Threats to computer and network security Planning for the next peak season? Ensure your website is f. nearly, years, publication, encryption, remains, facto, standard. . LinuxSecurity.com Team

Calendar%202 Jul 19, 2010 User Avatar LinuxSecurity.com Team Cryptography
News Add Esm H340

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200