Language Selection

English French German Italian Portuguese Spanish

Security

IPFire 2.15 Core 80 Is a Powerful and Free Linux Firewall OS

Filed under
GNU
Linux
Security

Michael Tremer, a developer for the ipfire.org team, has announced that IPFire 2.13 Core 80, a new stable build of the popular Linux-based firewall distribution, has been released and is now available for download.

Read more

Mozilla's Developer Network Site Has Leaks

Filed under
Moz/FF
Security

Mozilla's website dedicated to developers has suffered from a database error that has exposed email addresses and encrypted passwords of registered users for about a month, the company announced.
About 76,000 Mozilla Development Network (MDN) users had their email addresses exposed, along with around 4,000 encrypted passwords, said Stormy Peters, director of development relations, and Joe Stevensen, operations security manager. Many of those affected have already been notified.

Read more

Answering questions regarding the Fedora Security Team

Filed under
Red Hat
Security

Wow, I had no idea that people would care about the start of this project. There seems to be a few questions out there that I’d like to address here to clarify what we are doing and why.

Read more

Mitro Releases a New Free & Open Source Password Manager

Filed under
OSS
Security

Today, Twitter acquired a password manager startup called Mitro. As part of the deal, Mitro will be releasing the source to its client and server code under the GPL.

Read more

DHS Wants To Help Developers Secure Open-Source Software

Filed under
OSS
Security

The Department of Homeland Security is funding a project aimed at protecting the nation's critical infrastructure and networks by providing tools that test for defects in open source and commercial software.

Read more

Tor anonymity service says unknown attackers compromised its network

Filed under
Moz/FF
OSS
Security

The Tor encryption service is a high-profile bastion of computer security, but the project appears to have been compromised earlier this year. Today, the Tor Project blog announced that an unknown party likely managed to gather information about people who were looking up hidden services — websites that users can operate and visit anonymously, like Silk Road — and could theoretically have compromised other parts of the network.

Read more

The security flaws in Tails Linux are not its only problem

Filed under
Security
Debian

If you want to use Tor, then Tails is your best friend. Tails is a version of Linux that sends data through the Tor network.

All Internet traffic to/from Tails goes through Tor, making it resistant to end user mistakes. Tails is not normally installed on a computer, instead it's run from a bootable DVD, USB flash drive or flash memory card. Compared to the Tor Browser Bundle, Tails is unquestionably the way to go. Ed Snowden uses it.

Read more

Also related:

Homeland Security gets into software security

Filed under
OSS
Security

Personally, while I still think the DHS is an unlikely sponsor for this project — the National Security Agency (NSA) or NIST seem like its more natural home — I think the SWAMP sounds like a very useful one-stop for anyone wanting to double-check their pre-production code for errors before release.

Read more

The world's most secure OS may have a serious problem

Filed under
GNU
Linux
Security
Debian

The Tails operating system is one of the most trusted platforms in cryptography, favored by Edward Snowden and booted up more than 11,000 times per day in May. But according to the security firm Exodus Intelligence, the program may not be as secure as many thought. The company says they've discovered an undisclosed vulnerability that will let attackers deanonymize Tails computers and even execute code remotely, potentially exposing users to malware attacks. Exodus is currently working with Tails to patch the bug, and expects to hand over a full report on the exploit next week.

Read more

Docker security with SELinux

Filed under
GNU
Linux
Server
Security

This article is based on a talk I gave at DockerCon this year. It will discuss Docker container security, where we are currently, and where we are headed.

Read more

Syndicate content

More in Tux Machines

Munich Switching to Windows from Linux Is Proof That Microsoft Is Still an Evil Company

Reports about the city of Munich authorities that are considering the replacement of Linux with Microsoft products mostly comes from one man, the Deputy Mayor of Munich, who is also a long-term self-declared Windows fan. Munich is the poster child for the adoption of a Linux distribution and the replacement of the old Windows OS. It provided a powerful incentive for other cities to do the same, and it's been a thorn in Microsoft's side for a very long time. The adoption of open source software in Munich started back in 2004 and it took the local authorities over 10 years to finish the process. It's a big infrastructure, but in the end they managed to do it. As you can imagine, Microsoft was not happy about it. Even the CEO of Microsoft, Steve Ballmer, tried to stop the switch to Linux, but he was too late to the party. Read more

Dangling the Linux Carrot

Sometimes the direct sell method isn’t the best way to close the deal. How do you think the whole “play hard to get” thing got traction throughout the years? That method is successful in any number of applications. And really, I wasn’t wearing my Linux Advocacy hat that evening…I was just a guy relaxing after a day’s work. Read more

Red Hat Sets New 12-Month High at $61.97 (RHT)

They now have a $70.00 price target on the stock, up previously from $57.00. Three equities research analysts have rated the stock with a hold rating and eighteen have issued a buy rating to the company’s stock. Red Hat has an average rating of “Buy” and an average price target of $63.50. Read more

Systemd 216 Piles On More Features, Aims For New User-Space VT

Lennart Poettering announced the systemd 216 release on Tuesday and among its changes is a more complete systemd-resolved that has nearly complete caching DNS and LLMNR stub resolver, a new systemd terminal library, and a number of new commands. The systemd 216 release also has improvements to various systemd sub-commands, an nss-mymachines NSS module was added, a new networkctl client tool, KDBUS updates against Linux 3.17's memfd, networkd improvements, a new systemd-terminal library for implementing full TTY stream parsing and rendering, a new systemd-journal-upload utility, an LZ4 compressor for journald, a new systemd-escape tool, a new systemd-firstboot component, and much more. Read more