Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 506
Alerts This Week
Warning Icon 1 506

Stay Ahead With Linux Security News

Filter%20icon Refine news
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security news

We found 2 articles for you...
78

Google WebM License: Analyzing Open Source Concerns and Impacts

As Apple and Adobe sparred over the inclusion of Flash in the iPhone OS, supporters of the emerging HTML5 standard -- including Apple, Google, and Microsoft -- touted the H.264 video codec specified in HTML5 as a reason that Flash is unnecessary. But H.264 is proprietary technology that requires a license for use and redistribution, which effectively means Mozilla can't adopt it for the open source Firefox browser. . So Google has come up with WebM, an open and royalty-free media format based on the VP8 video codec. Problem solved? Not exactly. After examining the software license, open source pundits have questioned whether WebM should be classified as open source software. But the larger question is why Google allowed this debate to occur in the first place and what it means for your organization when evaluating an "open source" product. The link for this article located at InfoWorld is no longer available. . Microsoft unveils a new API, prompting discussions around its compatibility issues and potential impacts on enterprise software deployment.. WebM Format, Open Source Debate, VP8 Codec, Software Licensing, Media Technology. . LinuxSecurity.com Team

Calendar%202 Jun 01, 2010 User Avatar LinuxSecurity.com Team Vendors/Products
78

Fortinet UK GPL Settlement: Compliance Issues Resolved for Open Source

The UK subsidiary of security software firm Fortinet has settled an action brought against it because it was allegedly not complying with the terms of the General Public Licence (GPL), which underpins the distribution of most open source software. Harald Welte, founder of the gpl-violations.org project, announced earlier this month that a German District Court had granted a preliminary injunction against Fortinet UK Ltd after the project sued, alleging that the security software firm had used GPL software in certain products and then used encryption technologies to hide the software. . The GPL is a licence commonly used for many free software projects, including the Linux operating system kernel. The GPL licenses software free of cost but requires any re-distributor to provide the full source code and a copy of the full licence text. "This violation by Fortinet is especially egregious since the vendor not only violated the GPL, but actively tried to hide that violation," said Welte. "We are not in any way opposed to the commercial use of Free and Open Source Software and there is no legal risk of using GPL licensed software in commercial products. But vendors have to comply with the licence terms, just like they would have to with any other software licence agreement," he added. In terms of the settlement agreement, Fortinet UK Ltd will modify its End User Licensing Agreement (EULA), include the GPL licensing terms with all shipments, and make available the full corresponding source code of all GPL licensed software upon request. The link for this article located at Out-law.com is no longer available. . Fortinet's branch in the UK resolves GPL litigation, committing to adhere to open source licensing guidelines and make source code available.. Fortinet GPL Settlement, Open Source Compliance, Security Software Lawsuit. . LinuxSecurity.com Team

Calendar%202 Apr 29, 2005 User Avatar LinuxSecurity.com Team Vendors/Products
82

Linux Programmer Wins GPL Enforcement Case Against Fortinet

A Linux programmer reported a new victory in a German court Thursday in enforcing the General Public License, which governs countless projects in the free and open-source software realms. A Munich district court on Tuesday issued a preliminary injunction barring Fortinet, a maker of multipurpose security devices, from distributing products that include a Linux component called "initrd" that Harald Welte helped write. . In addition to being a Linux programmer, Welte runs an operation called the GPL Violations project that attempts to encourage companies shipping products incorporating GPL software to abide by the license terms. The license lets anyone use GPL software in products without paying a fee, but it requires that they provide the underlying source code for the GPL components when they ship such a product. The case highlights the ease with which open-source software can spread across the computing industry--but also the growing pains that companies face as they adjust to new legal concepts underlying the collaborative programming approach. Fortinet, based in Sunnyvale, Calif., said in a statement it's addressing the issue but is surprised that Welte resorted to legal action.. A recent court ruling in favor of an open-source developer highlights the critical role of GPL upholding in software licensing agreements.. GPL Enforcement, Open Source Software, Software Licensing. . Brittany Day

Calendar%202 Apr 14, 2005 User Avatar Brittany Day Government
82

Homeland Security Software Licensing: Consolidation Initiatives Revealed

Speaking at a Spy Museum breakfast today, Secret Service assistant director Steve Colo said the new Homeland Security Department will consolidate all its component agencies' software licenses "for the greater good," looking first at large contracts with vendors such as Microsoft Corp. and Oracle. . .. Speaking at a Spy Museum breakfast today, Secret Service assistant director Steve Colo said the new Homeland Security Department will consolidate all its component agencies' software licenses "for the greater good," looking first at large contracts with vendors such as Microsoft Corp. and Oracle Corp. Colo said HSD "must quickly stand up an enterprise architecture," and the components' CIOs "know where they want to go." He predicted HSD agencies will see a lot more of the kind of total IT outsourcing pioneered by Transportation Security Administration systems chief Patrick Schambach. But Colo said it will take time--probably three to five years--before there is much consolidation of the very different systems. He also predicted that physical security and IT security issues will merge. In the communications area, Colo said, HSD needs a priority wireless system for emergencies and interoperable wireless equipment for law enforcement agencies. "The government's selling off spectrum, and that could affect us," he said. "It's a finite item, a major issue." The link for this article located at GCN is no longer available. . Speaking at a Spy Museum breakfast today, Secret Service assistant director Steve Colo said the new . speaking, museum, breakfast, today, secret, service, assistant, director, steve. . Anthony Pell

Calendar%202 Dec 12, 2002 User Avatar Anthony Pell Government
81

The Role of DRM Technology in Safety And Mission Critical Systems

Digital Rights Management Passport (DRMP) technology (TCPA from Intel and Palladium from Microsoft and similar) is intended to make it hard to copy downloaded music or pirated software. Preventing teenagers from making copies of Eminem songs may seem harmless, but Internet . . . . Digital Rights Management Passport (DRMP) technology (TCPA from Intel and Palladium from Microsoft and similar) is intended to make it hard to copy downloaded music or pirated software. Preventing teenagers from making copies of Eminem songs may seem harmless, but Internet Age technology is all about convergence. When a technology gets pervasively embedded in microprocessors, computer boards, and software, it will alter the performance of power turbines, jet engines, medical instruments, cell phones and missile guidance systems. Unfortunately, DRMP technology is incompatible with security and with the kinds of reliability needed in safety critical or mission critical applications. Ross Anderson has written an excellent comprehensive analysis of DRMP. Here I want to look at some concrete consequences that are important in defense and manufacturing. Despite marketing, DRMP is a licensing technology, not a security technology (see note 1). The combination of hardware and software being championed and fought over by the entertainment companies , Microsoft, and Intel, enforces something like an identity card or passport system on software. The idea is that DRM agents will be incorporated into software, processors (see note 2), and other computer hardware and the DRM agents will examine files containing programs and data (such as digitized music) to make sure the file is attached to a valid digital passport. The passports prove that the file is being used within its license terms. Before you can play a movie on your PC, the DRM agent in the processor will demand the passport on the video player and the video player software will demand the passport of the video file. Before you run a word processor, some DRM agent will make sure you have avalid license and have not violated any of the fine print of the shrink-wrap license and that the file you are opening is something you have a license to read. Programs that do not incorporate certified DRM agents will not be able to get passports, so there will be a world-wide web of DRM agents working together. The link for this article located at LinuxDevices is no longer available. . This analysis explores the impact of Digital Rights Management Passport technology on protecting critical infrastructures, highlighting both its benefits and vulnerabilities.. Digital Rights Management, Safety Systems, Mission Critical Applications. . LinuxSecurity.com Team

Calendar%202 Oct 11, 2002 User Avatar LinuxSecurity.com Team Privacy
76

OpenBSD License Change Affects Firewall Module Integrity

Maintaining the openness of OpenBSD got a little more complicated recently when the project leader of what may be one of the most popular modules in OpenBSD decided to re-word his home-grown license to specifically disallow modifications to the source code . . . . Maintaining the openness of OpenBSD got a little more complicated recently when the project leader of what may be one of the most popular modules in OpenBSD decided to re-word his home-grown license to specifically disallow modifications to the source code without his permission. OpenBSD wants to stay true to its name. The project's published goal when it comes to licensing is simply to strive "to maintain the spirit of the original Berkeley Unix copyrights." The OpenBSD team works to maintain complete openness of the source code, even allowing casual users to look at the source tree and CVS changes via the Web. As a result, recent licensing changes to a key firewall module integrated with OpenBSD have forced its removal from the Unix-derived operating system. The link for this article located at Newsforge is no longer available. . The transparency of FreeBSD has encountered increased difficulties as the head developer of an essential component altered its licensing terms.. OpenBSD, Firewall Module, Software Integrity, Licensing Issues. . Anthony Pell

Calendar%202 Jun 07, 2001 User Avatar Anthony Pell Organizations/Events
79

Understanding Copyleft And Its Legal Challenges In Software

Software that is placed under "copyleft" -- as opposed to copyright -- may be in a legal limbo and is still reliant on the concept of copyright, an Irish legal expert says. Stallman said the GPL and copyleft helps guarantee . . . . Software that is placed under "copyleft" -- as opposed to copyright -- may be in a legal limbo and is still reliant on the concept of copyright, an Irish legal expert says. Stallman said the GPL and copyleft helps guarantee that "freedom, principle and ethics" are part of the software developer and user community. "We have to think of the social consequences of our work," he said. However, Paul Lambert, a lawyer with LK Shields Solicitors in Dublin, argued that even with copyleft "as a fundamental concept, copyright remains, because copyleft can't work without copyright." If a creative work was of sufficient quality and uniqueness, "copyright manifests automatically," he said. "It's created by statute -- you can't get away from that." The link for this article located at Wired is no longer available. . Explore the complex interplay of copyleft and copyright within the realm of software licenses, analyzing both legal perspectives and the ethical ramifications.. Copyleft Licensing, Software Legalities, GPL Implications, Open Source Ethics, Software Rights. . LinuxSecurity.com Team

Calendar%202 Feb 07, 2001 User Avatar LinuxSecurity.com Team Security Projects
News Add Esm H340

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200