Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
A team of researchers has implemented support for 'trusted computing' in a commercially available version of the open source operating system Linux, breaking new ground in the global drive toward more secure computing environments.. The latest release of openSUSE, a Linux version sponsored by software maker Novell, comes packaged with software that allows users to set up a trusted computing (TC) environment on their computer, enhancing security beyond the antivirus programs and firewalls that frequently prove inadequate at keeping bugs, viruses and spyware at bay. Promoted and developed by major chipmakers and software companies in the international Trusted Computing Group, trusted computing uses both hardware and software to create a trusted and secure environment, whether on a home PC, a web server, in a data centre or over a corporate network. At the core of the technology is the trusted platform module (TPM), which is a chip that, among other security-boosting features, generates and manages cryptographic keys, verifies the identity of the computer on a network and protects software and data from malicious changes. The link for this article located at Physorg is no longer available. . The latest release of openSUSE, a Linux version sponsored by software maker Novell, comes packaged w. researchers, implemented, support, 'trusted, computing', commercially. . LinuxSecurity.com Team
Trusted Computing chips are already built into most new business PCs. At this week’s RSA Security show, the Trusted Computing Group unveiled a draft specification that will add a simplified version of the chip to storage devices, too. Intended mainly for hard disks and USB flash drives, it can be used for both and portable and networked storage. Seagate Technology last year launched a laptop drive that automatically encrypted all data at wire speed. At the show, the company announced that this was based on the draft specification, which allows encryption keys to be transferred between drives and the Trusted Platform Module (TPM) chips in PCs. . The link for this article located at Information Week is no longer available. . Discover the forthcoming Secure Data Protocol aimed at improving storage safety and fortifying encryption functionalities.. Trusted Computing, Data Encryption, Storage Security. . LinuxSecurity.com Team
Technologies touted as providing a more secure computing experience are actually more likely to reinforce monopolies and lock customers in, security and free software experts have warned.The "Trusted Computing" technologies promoted by major IT companies such as Microsoft and IBM could have negative consequences for customers and rival software makers, according to security experts. . Alan Cox, a lead Linux kernel developer and security architect, said that trusting computing has often been used to lock customers into buying a particular software and to prevent rival software makers from competing on that platform. The link for this article located at ZDNet.co.uk is no longer available. . Specialists caution that Trusted Computing innovations bolster monopolistic practices and impede fair competition within the software industry.. Trusted Computing, Software Monopolies, Security Technology, Free Software, Linux Kernel. . LinuxSecurity.com Team
Embedded systems designers attending next week's Embedded Systems Conference, Boston, can see Trusted Computing components and applications in action and learn how to design in security based on Trusted Computing specifications. . . .. Embedded systems designers attending next week's Embedded Systems Conference, Boston, can see Trusted Computing components and applications in action and learn how to design in security based on Trusted Computing specifications. TCG's specifications have been developed to help vendors build products that let users protect critical data and information in a variety of computing systems. More than 5 million computing systems with hardware to protect passwords, digital keys and certificates have been shipped, and many applications for using this hardware are available. As embedded devices, smart sensors and other intelligent controllers become pervasive on wired and wireless networks, security is increasingly critical. The link for this article located at BUSINESS WIRE is no longer available. . Engineers specializing in embedded systems can find reliable computing solutions at the Embedded Systems Symposium happening in Boston during the upcoming week.. Embedded Systems, Trusted Computing, Security Solutions, Conference Boston, Data Protection. . Anthony Pell
The Trusted Computing Group said Monday that it is working on a specification to ensure that wireless clients connecting to a network won't serve as a back door to worms and crackers. Officials within the TCG, based in Portland, Ore., said the industry standards body is developing a "Trusted Network Connect" specification, designed to audit wireless-enabled PCs when they first make contact with an enterprise's wireless network. . . .. The Trusted Computing Group said Monday that it is working on a specification to ensure that wireless clients connecting to a network won't serve as a back door to worms and crackers. Officials within the TCG, based in Portland, Ore., said the industry standards body is developing a "Trusted Network Connect" specification, designed to audit wireless-enabled PCs when they first make contact with an enterprise's wireless network. The specification will be finalized later this year, said officials from the group, which comprises computer and device manufacturers, software vendors and others. Although a client or customer connecting to an enterprise network may not overtly be seeking to do harm, the laptop may in fact hide an unpatched system that could serve as an unexpected back door into an otherwise secure system. Likewise, a network administrator cannot be sure whether a laptop hides a worm that might otherwise have been blocked by a wired firewall. When completed, the specification will serve as a means by which network security and network infrastructure vendors can ensure a level of compliance with the best practices of network security, executives said. The link for this article located at eweek.com is no longer available. . The Cybersecurity Alliance is creating 'Secure Internet Link' to bolster compliance for wired network defenses.. Wireless Security, Trusted Computing, Network Auditing, Security Compliance. . Anthony Pell
A high-profile digital civil liberties group is criticizing a component of the "trusted computing" technology promoted by Microsoft, IBM and other technology companies, calling the feature a threat to computer users.. . .. A high-profile digital civil liberties group is criticizing a component of the "trusted computing" technology promoted by Microsoft, IBM and other technology companies, calling the feature a threat to computer users. The paper, which was set to be released late Wednesday by the Electronic Frontier Foundation, analyzes the promised features of several different trusted computing initiatives. The efforts aim to develop next-generation hardware and software that can better protect data from attackers, viruses and digital pirates. Applauded in the paper are three features of the best-known trusted computing technology, Microsoft's Next-Generation Secure Computing Base, that may be positive ways of securing consumers' computers. However, the EFF criticized a fourth feature--known as remote attestation--as a threat that could lock people into certain applications, force unwanted software changes on them and prevent reverse engineering. Remote attestation allows other organizations that "own" content on a person's computer to ascertain whether the data or software has been modified. Such technology could easily be at odds with a computer owner's interests, said Seth Schoen, staff technologist for the EFF and the primary author of the paper. The link for this article located at CNET is no longer available. . A digital advocacy organization has voiced strong objections to the 'secure hardware' initiatives, citing significant risks to individual privacy and autonomy over personal data.. Trusted Computing Risks, EFF Critique, User Privacy Issues, Digital Rights Advocacy. . LinuxSecurity.com Team
Trust must be earned. This hard lesson is being learned by the five tech giants behind "trusted-computing" initiatives aimed at securing user privacy. Depending on whom you believe, the companies developing trusted-computing technology are either Santa or Satan. . .. Trust must be earned. This hard lesson is being learned by the five tech giants behind "trusted-computing" initiatives aimed at securing user privacy. Depending on whom you believe, the companies developing trusted-computing technology are either Santa or Satan . Trusted computing is a nebulous hardware/software concept being trumpeted as the solution to safeguarding information privacy and computer security. Critics counter that the initiative is simply a front to fatten the coffers of Hollywood studios and record labels by enforcing digital-rights management (DRM), and that it could quash innovation in the software industry. And users worry that the technologies could bar them from material stored on their own computers if they haven't met licensing requirements. The link for this article located at news.com is no longer available. . Faith is a privilege. This tough insight is currently being grasped from major players in the realm of 'secure tech'. . trusted Computing, user Privacy, digital Rights, security Technology, tech Giants. . LinuxSecurity.com Team
Recent reports available with news sites and also published in the Economic Times of India suggest that Microsoft [hereinafter referred to as MSFT] will be pushing through the Windows Rights Management Architecture & Services [WRMA & WRMS] by the 1st week of March, 2003. In the light of such an event, this article proposes to establish the fallacy of the Trusted Computing paradigm as made available in public document(s) from TCPA [] . . .. Recent reports available with news sites and also published in the Economic Times of India suggest that Microsoft [hereinafter referred to as MSFT] will be pushing through the Windows Rights Management Architecture & Services [WRMA & WRMS] by the 1st week of March, 2003. In the light of such an event, this article proposes to establish the fallacy of the Trusted Computing paradigm as made available in public document(s) from TCPA [] The link for this article located at ILUG-CAL is no longer available. . The Trusted Computing model, aimed at enhancing digital security, faces scrutiny as Microsoft's Rights Management raises concerns over user control and genuine safety.. Trusted Computing, Digital Rights Management, Microsoft Security, Rights Management Architecture. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.