Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Security conferences are a great place to learn about the latest hacking tricks, tools and exploits, but they also remind us of important stuff that was shown to be hackable in previous years yet never really got fixed. Perhaps the best example of this at last week. Nearly four years ago, researchers at the Chaos Communication Congress (CCC), a security conference in Berlin, released a paper (PDF) demonstrating a serious vulnerability in smart cards made by Austin, Texas-based HID Global, by far the largest manufacturer of these devices. The CCC researchers showed that the card reader device that HID sells to validate the data stored on its then-new line of iClass proximity cards includes the master encryption key needed to read data on those cards. The link for this article located at Krebs on Security is no longer available. . Concerns over vulnerabilities in HID Global's smart card tech highlight severe risks in access control systems, impacting sectors like finance and healthcare. HID Smart Cards, Encryption Issues, Data Security, Security Conference. . LinuxSecurity.com Team
The Department of Homeland Security is three years behind schedule on a project to develop a standard smart-card identification method for federal employees and contractors, according to a DHS report. The project -- officially called Homeland Security Presidential Directive 12 (HSPD-12): Policy for a Common Identification Standard for Federal Employees and Contractors -- requires that DHS develop a government-wide way to identify employees by issuing smart cards. The cards contain information about which IT applications and networks and facilities each employee is permitted access to. . The original completion for the issuance and use of identity cards was Oct. 27, 2008, according to the report, issued by inspector general Richard L. Skinner. However, as of Sept. 22, 2009, only 15,567 of the approximately 250,000 department employees and contractors have been issued identity credentials. The program's target date for completion has now been pushed to Sept. 30, 2011, the end of the 2011 fiscal year. Specifically, DHS plans to issue smart cards to 135,000 federal employees and contractors by the end of fiscal year 2010, and to the remaining 105,000 employees and contractors by the end of fiscal year 2011. The report blames poor program management, including insufficient funding and resources, as well as a change in implementation strategy for issuing cards in June 2009, for falling behind schedule. There are significant IT problems hindering completion of the directive, too, according to the report. The link for this article located at InfoWorld is no longer available. . The original completion for the issuance and use of identity cards was Oct. 27, 2008, according to t. department, homeland, security, three, years, behind, schedule, project, develop, standar. . Anthony Pell
A group of smart card and smart chip vendors are launching a campaign to talk up the security and privacy features of their products, even as researchers raise questions about their use in passports. . Smart card makers Gemalto NV and Oberthur Card Systems, as well as chip makers Infineon Technologies AG, Philips Semiconductors and Texas Instruments Inc., on Wednesday launched the Secure ID Coalition to promote the use of secure smart card standards as a way to protect privacy. The link for this article located at InfoWorld is no longer available. . Smart card makers Gemalto NV and Oberthur Card Systems, as well as chip makers Infineon Technologies. smart, group, vendors, launching, campaign, security. . LinuxSecurity.com Team
Defense Department officials selected two companies to provide digital certificate validation for the department's public-key infrastructure (PKI), a decision that some officials feel could spur a faster move to paperless e-government. After a yearlong, worldwide pilot test, military officials chose Tumbleweed Communications and CoreStreet as the two certificate validation providers for its Identity Protection and Management Program, which includes the Common Access Card smart card program. . DOD requires that all e-mail messages be digitally signed, which means PKI users must download a Certificate Revocation List (CRL) that is currently a 30M file. With names constantly being added to the list, users would have to download that file at least daily to make sure the digital signatures on e-mail messages were allowed. That might be feasible for land-based sites, said John Hines, director of Tumbleweed's validation authority product development, but it's practically impossible for ships at sea, where users share relatively low-bandwidth pipes. Tumbleweed and CoreStreet get around the download requirement by setting up a middleman, which forwards a request for a signature validation posted by the PKI user to a CRL, collects the response and prompts the desktop application to accept or reject the e-mail. This all takes place in a fraction of a second, and the request and response files are typically only 1K in size. The link for this article located at fcw.com is no longer available. . DOD requires that all e-mail messages be digitally signed, which means PKI users must download a Cer. defense, department, officials, selected, companies, provide, digital, certificate, validation. . LinuxSecurity.com Team
Biometrics authentication technology should be a promising means to confirm a cardholder's authenticity. With a Linux-based radio frequency (RF) personalizer that reads and writes in memory, the administrator can set various parameters of the smart security controller, such as real-time clock, personal identification number (PIN) option, alarm options and reader delays. Biometric security Relevant Products/Services from Verisign -- Free E-Commerce Start-up Kit with fingerprint matching involves protecting results -- a user's template, fingerprint images, a fingerprint's features, and a user's finger. The simplest design solution for a client considering finger-print matching is to embed all functions and data in tamper-resistant smart cards. . However, smart cards with a fingerprint scanner and high-powered processor for feature extraction and image processing may not be practical because of the cost of distributing the card to each user. Biometrics authentication technology should be a promising means to confirm a cardholder's authenticity. With a Linux-based radio frequency (RF) personalizer that reads and writes in memory, the administrator can set various parameters of the smart security controller, such as real-time clock, personal identification number (PIN) option, alarm options and reader delays. This protocol can upload card transaction data saved in the reader memory. It can also access key sets and other operational data to the reader. A biometric Latest News about biometric template is an encrypted hash of the actual biometric itself. You can effectively combine smart cards and biometrics for personal authentication over the open-source network. The combination is a two-step authentication in which you authenticate the smart card based on a public key infrastructure Relevant Products/Services from Sybase ASE Linux Express Edition – FREE (PKI). Cardholder authentication occurs by using the template stored in the smart card based on the biometrics verification. Execution of theverification must occur in the card for security purposes. The RF smart card and card reader/writer handle payment transactions for public transportation systems. Security features of these contactless cards include encrypted RF transmission, mutual authentication, and security keys. The card has up to 16 separate sectors, which you can configure as purses or for general data storage Relevant Products/Services from IBM eServer xSeries Systems. You typically use the first sector as a directory for the rest of the card, leaving 15 segments available for data or purses. You can store up to 15 different applications on an RF smart card, and when you use unique keys for each sector, applications are separate and secure from one another. The link for this article located at linuxinsider.com is no longer available. . Explore the potential of biometric devices to enhance the security of smart cards and verify individual identities leveraging Linux-based solutions.. Biometric Authentication, Smart Card Solutions, RF Technology, Data Encryption. . LinuxSecurity.com Team
A Canadian man was sentenced to seven years in a U.S. prison this week after admitting he led a sophisticated satellite TV piracy ring that produced and sold thousands of hacked smart cards in the U.S. and Canada. . Martin Mullen, 50, was also ordered to pay DirecTV and its smart card provider NDS Ltd. $24 million in restitution. Mullen pled guilty in a federal court in Tampa, Florida last September to conspiracy to violate anti-piracy laws, and to entering the U.S. illegally after being deported on an unrelated matter years earlier. According to court records, Mullen was an expert at cracking security on the smart cards DirecTV issues to subscribers to authorize access to television programming. In normal operation, a subscriber inserts the card into a slot in the DirectTV set top box, and a satellite signal from the company tells the receiver which channels, if any, the subscriber is allowed to watch, based on the unique identification number coded into each card. The link for this article located at Kevin Poulsen is no longer available. . A US citizen has been sentenced to eight years in prison for leading a counterfeit passport operation and is required to pay $30 million in damages.. satellite piracy, smart card fraud, cyber crime, U.S. prison, DirecTV restitution. . Joe Shakespeare
Researchers at the University of Pennsylvania have developed smart credit cards with embedded microchips. What's new about is a technique which lets ordinary card users program in their own spending parameters.. . .. Researchers at the University of Pennsylvania have developed smart credit cards with embedded microchips. What's new about is a technique which lets ordinary card users program in their own spending parameters. Just imagine: employers could better manage spending on corporate cards, while parents could create emergency credit cards for their children, to be used only at certain locations such as hotels or pay phones. Banks and other card issuers have long been able to set general parameters in chip cards, such as credit limits. So far, there has been little interest in setting finer limits because the procedure is awkward and expensive to manage. But not anymore, according to Penn scientist Carl Gunter, who presented this work at the recent conference on Object-Oriented Programming in Darmstadt, Germany. . Unveil cutting-edge digital financial tools crafted by innovators, offering tailored budgeting limits for enhanced money management.. Smart Cards, Embedded Technology, Spending Management. . LinuxSecurity.com Team
The technology exists to create a governmentwide smart card program, but cultural issues and a lack of top-level management support stand in the way of implementation, experts testified today. A single government smart card is possible, but managerial and policy . . . . The technology exists to create a governmentwide smart card program, but cultural issues and a lack of top-level management support stand in the way of implementation, experts testified today. A single government smart card is possible, but managerial and policy differences create difficulties, said Joel Willemssen, managing director of information technology issues at the General Accounting Office. "It would probably be very difficult to standardize it from a management and policy perspective," Willemssen testified today at a hearing of the House Government Reform subcommittee on technology, information policy, intergovernmental relations and the census. Agencies have different security clearances and access controls. GAO identified 62 smart card initiatives in varying stages at 18 agencies, Willemssen said. One of the next steps, he said, is establishing a governmentwide employee credentialing policy to streamline employee clearances. The link for this article located at FCW is no longer available. . The rollout of a thorough smart card program within government entities encounters challenges due to cultural resistance and lack of leadership support, hindering progress.. Government Smart Card, Management Support, Security Issues, Credentialing Policy, Cultural Barriers. . Anthony Pell
Get the latest Linux and open source security news straight to your inbox.