Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 515
Alerts This Week
Warning Icon 1 515

Stay Ahead With Linux Security News

Filter%20icon Refine news
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security news

We found 4 articles for you...
79

openSUSE Trusted Computing: Enhance Security with TPM Technology

A team of researchers has implemented support for 'trusted computing' in a commercially available version of the open source operating system Linux, breaking new ground in the global drive toward more secure computing environments.. The latest release of openSUSE, a Linux version sponsored by software maker Novell, comes packaged with software that allows users to set up a trusted computing (TC) environment on their computer, enhancing security beyond the antivirus programs and firewalls that frequently prove inadequate at keeping bugs, viruses and spyware at bay. Promoted and developed by major chipmakers and software companies in the international Trusted Computing Group, trusted computing uses both hardware and software to create a trusted and secure environment, whether on a home PC, a web server, in a data centre or over a corporate network. At the core of the technology is the trusted platform module (TPM), which is a chip that, among other security-boosting features, generates and manages cryptographic keys, verifies the identity of the computer on a network and protects software and data from malicious changes. The link for this article located at Physorg is no longer available. . The latest release of openSUSE, a Linux version sponsored by software maker Novell, comes packaged w. researchers, implemented, support, 'trusted, computing', commercially. . LinuxSecurity.com Team

Calendar%202 Nov 23, 2009 User Avatar LinuxSecurity.com Team Security Projects
77

Exploring Trusted Computing Standard: Strengthening Storage Security

Trusted Computing chips are already built into most new business PCs. At this week’s RSA Security show, the Trusted Computing Group unveiled a draft specification that will add a simplified version of the chip to storage devices, too. Intended mainly for hard disks and USB flash drives, it can be used for both and portable and networked storage. Seagate Technology last year launched a laptop drive that automatically encrypted all data at wire speed. At the show, the company announced that this was based on the draft specification, which allows encryption keys to be transferred between drives and the Trusted Platform Module (TPM) chips in PCs. . The link for this article located at Information Week is no longer available. . Discover the forthcoming Secure Data Protocol aimed at improving storage safety and fortifying encryption functionalities.. Trusted Computing, Data Encryption, Storage Security. . LinuxSecurity.com Team

Calendar%202 Feb 17, 2006 User Avatar LinuxSecurity.com Team Server Security
77

Examining Trusted Computing's Role in Software Market Monopoly Effects

Technologies touted as providing a more secure computing experience are actually more likely to reinforce monopolies and lock customers in, security and free software experts have warned.The "Trusted Computing" technologies promoted by major IT companies such as Microsoft and IBM could have negative consequences for customers and rival software makers, according to security experts. . Alan Cox, a lead Linux kernel developer and security architect, said that trusting computing has often been used to lock customers into buying a particular software and to prevent rival software makers from competing on that platform. The link for this article located at ZDNet.co.uk is no longer available. . Specialists caution that Trusted Computing innovations bolster monopolistic practices and impede fair competition within the software industry.. Trusted Computing, Software Monopolies, Security Technology, Free Software, Linux Kernel. . LinuxSecurity.com Team

Calendar%202 Feb 01, 2006 User Avatar LinuxSecurity.com Team Server Security
76

Discover Trusted Computing Security Applications at Boston Conference

Embedded systems designers attending next week's Embedded Systems Conference, Boston, can see Trusted Computing components and applications in action and learn how to design in security based on Trusted Computing specifications. . . .. Embedded systems designers attending next week's Embedded Systems Conference, Boston, can see Trusted Computing components and applications in action and learn how to design in security based on Trusted Computing specifications. TCG's specifications have been developed to help vendors build products that let users protect critical data and information in a variety of computing systems. More than 5 million computing systems with hardware to protect passwords, digital keys and certificates have been shipped, and many applications for using this hardware are available. As embedded devices, smart sensors and other intelligent controllers become pervasive on wired and wireless networks, security is increasingly critical. The link for this article located at BUSINESS WIRE is no longer available. . Engineers specializing in embedded systems can find reliable computing solutions at the Embedded Systems Symposium happening in Boston during the upcoming week.. Embedded Systems, Trusted Computing, Security Solutions, Conference Boston, Data Protection. . Anthony Pell

Calendar%202 Sep 08, 2004 User Avatar Anthony Pell Organizations/Events
74

Developing Trusted Network Connect: Enhancing Wireless Security Compliance

The Trusted Computing Group said Monday that it is working on a specification to ensure that wireless clients connecting to a network won't serve as a back door to worms and crackers. Officials within the TCG, based in Portland, Ore., said the industry standards body is developing a "Trusted Network Connect" specification, designed to audit wireless-enabled PCs when they first make contact with an enterprise's wireless network. . . .. The Trusted Computing Group said Monday that it is working on a specification to ensure that wireless clients connecting to a network won't serve as a back door to worms and crackers. Officials within the TCG, based in Portland, Ore., said the industry standards body is developing a "Trusted Network Connect" specification, designed to audit wireless-enabled PCs when they first make contact with an enterprise's wireless network. The specification will be finalized later this year, said officials from the group, which comprises computer and device manufacturers, software vendors and others. Although a client or customer connecting to an enterprise network may not overtly be seeking to do harm, the laptop may in fact hide an unpatched system that could serve as an unexpected back door into an otherwise secure system. Likewise, a network administrator cannot be sure whether a laptop hides a worm that might otherwise have been blocked by a wired firewall. When completed, the specification will serve as a means by which network security and network infrastructure vendors can ensure a level of compliance with the best practices of network security, executives said. The link for this article located at eweek.com is no longer available. . The Cybersecurity Alliance is creating 'Secure Internet Link' to bolster compliance for wired network defenses.. Wireless Security, Trusted Computing, Network Auditing, Security Compliance. . Anthony Pell

Calendar%202 May 13, 2004 User Avatar Anthony Pell Network Security
81

EFF Raises Alarm About the Implications of Trusted Computing Features

A high-profile digital civil liberties group is criticizing a component of the "trusted computing" technology promoted by Microsoft, IBM and other technology companies, calling the feature a threat to computer users.. . .. A high-profile digital civil liberties group is criticizing a component of the "trusted computing" technology promoted by Microsoft, IBM and other technology companies, calling the feature a threat to computer users. The paper, which was set to be released late Wednesday by the Electronic Frontier Foundation, analyzes the promised features of several different trusted computing initiatives. The efforts aim to develop next-generation hardware and software that can better protect data from attackers, viruses and digital pirates. Applauded in the paper are three features of the best-known trusted computing technology, Microsoft's Next-Generation Secure Computing Base, that may be positive ways of securing consumers' computers. However, the EFF criticized a fourth feature--known as remote attestation--as a threat that could lock people into certain applications, force unwanted software changes on them and prevent reverse engineering. Remote attestation allows other organizations that "own" content on a person's computer to ascertain whether the data or software has been modified. Such technology could easily be at odds with a computer owner's interests, said Seth Schoen, staff technologist for the EFF and the primary author of the paper. The link for this article located at CNET is no longer available. . A digital advocacy organization has voiced strong objections to the 'secure hardware' initiatives, citing significant risks to individual privacy and autonomy over personal data.. Trusted Computing Risks, EFF Critique, User Privacy Issues, Digital Rights Advocacy. . LinuxSecurity.com Team

Calendar%202 Oct 07, 2003 User Avatar LinuxSecurity.com Team Privacy
81

Evaluating Trust In Tech Giants For User Privacy And Security

Trust must be earned. This hard lesson is being learned by the five tech giants behind "trusted-computing" initiatives aimed at securing user privacy. Depending on whom you believe, the companies developing trusted-computing technology are either Santa or Satan. . .. Trust must be earned. This hard lesson is being learned by the five tech giants behind "trusted-computing" initiatives aimed at securing user privacy. Depending on whom you believe, the companies developing trusted-computing technology are either Santa or Satan . Trusted computing is a nebulous hardware/software concept being trumpeted as the solution to safeguarding information privacy and computer security. Critics counter that the initiative is simply a front to fatten the coffers of Hollywood studios and record labels by enforcing digital-rights management (DRM), and that it could quash innovation in the software industry. And users worry that the technologies could bar them from material stored on their own computers if they haven't met licensing requirements. The link for this article located at news.com is no longer available. . Faith is a privilege. This tough insight is currently being grasped from major players in the realm of 'secure tech'. . trusted Computing, user Privacy, digital Rights, security Technology, tech Giants. . LinuxSecurity.com Team

Calendar%202 May 19, 2003 User Avatar LinuxSecurity.com Team Privacy
81

Evaluating Trusted Computing Risks In Microsoft's Rights Management System

Recent reports available with news sites and also published in the Economic Times of India suggest that Microsoft [hereinafter referred to as MSFT] will be pushing through the Windows Rights Management Architecture & Services [WRMA & WRMS] by the 1st week of March, 2003. In the light of such an event, this article proposes to establish the fallacy of the Trusted Computing paradigm as made available in public document(s) from TCPA [] . . .. Recent reports available with news sites and also published in the Economic Times of India suggest that Microsoft [hereinafter referred to as MSFT] will be pushing through the Windows Rights Management Architecture & Services [WRMA & WRMS] by the 1st week of March, 2003. In the light of such an event, this article proposes to establish the fallacy of the Trusted Computing paradigm as made available in public document(s) from TCPA [] The link for this article located at ILUG-CAL is no longer available. . The Trusted Computing model, aimed at enhancing digital security, faces scrutiny as Microsoft's Rights Management raises concerns over user control and genuine safety.. Trusted Computing, Digital Rights Management, Microsoft Security, Rights Management Architecture. . LinuxSecurity.com Team

Calendar%202 Feb 26, 2003 User Avatar LinuxSecurity.com Team Privacy
News Add Esm H340

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200