Most Linux distros are currently coming up short from offering adequate security around full disk encryption and authenticated boot. Prominent Linux developer Lennart Poettering even argues that your data is "probably more secure if stored on current ChromeOS, Android, Windows or macOS devices." . Lead systemd developer Lennart Poettering wrote a lengthy blog post today around the state of authenticated boot and disk encryption on Linux. While many Linux distributions offer full-disk encryption, offer UEFI SecureBoot, and begun embracing TPMs, many of the technologies aren't being used to their best potential yet especially now by default / out-of-the-box. Lennart's short summary of the situation is: Linux has been supporting Full Disk Encryption (FDE) and technologies such as UEFI SecureBoot and TPMs for a long time. However, the way they are set up by most distributions is not as secure as they should be, and in some ways quite frankly weird. In fact, right now, your data is probably more secure if stored on current ChromeOS, Android, Windows or MacOS devices, than it is on typical Linux distributions. The link for this article located at Phoronix is no longer available. . Lennart Poettering brings attention to vulnerabilities in Linux disk encryption and secure boot processes, urging for improvements.. Linux Disk Encryption, Authenticated Boot, Security Shortcomings, Data Protection, Lennart Poettering. . Brittany Day
A government scheme to increase consumer confidence in buying online launched Tuesday has been overshadowed by stiff criticism from a former partner on the project.. . .. A government scheme to increase consumer confidence in buying online launched Tuesday has been overshadowed by stiff criticism from a former partner on the project. The initiative -- TrustUK -- is backed by Consumer Association body, Which? and the Department of Trade and Industry (DTI). It provides certification for e-commerce sites deemed safe for customers to use. But independent e-commerce certification organisation Clicksure -- involved with the scheme until recently -- claims that TrustUK is inadequate. The link for this article located at ZDNet UK is no longer available. . The new government effort to boost online consumer trust has faced heavy criticism for its flaws in managing security certifications, raising calls for better regulation. E-commerce Security, TrustUK Initiative, Consumer Confidence. . Anthony Pell
Get the latest Linux and open source security news straight to your inbox.