Language Selection

English French German Italian Portuguese Spanish

Security

More Security News

Filed under
Security
  • FreeBSD devs ponder changes to security processes

    The developers of FreeBSD have announced they'll change the way they go about their business, after users queried why known vulnerabilities weren't being communicated to users.

    This story starts with an anonymous GitHub post detailing some vulnerabilities in the OS, specifically in freebsd-update, libarchive, bspatch and portsnap. Some of the problems in that post were verified and the FreeBSD devs started working on repairs.

  • Your Linux Distro Can Be Hacked In 60 Seconds Due To Serious TCP Flaw: Research [Ed: This headline is nonsense and shows that the author lacks technical understanding of it.]
  • Virtual Machine Introspection: A Security Innovation With New Commercial Applications

    A few weeks ago, Citrix and Bitdefender launched XenServer 7 and Bitdefender Hypervisor Introspection, which together compose the first commercial application of the Xen Project Hypervisor’s Virtual Machine Introspection (VMI) infrastructure. In this article, we will cover why this technology is revolutionary and how members of the Xen Project Community and open source projects that were early adopters of VMI (most notably LibVMI and DRAKVUF) collaborated to enable this technology.

  • 10 IoT Security Best Practices For IT Pros

    IT professionals have to treat internet of things (IoT) vulnerabilities as they would vulnerabilities in databases or web applications. Any flaw can bring unwelcome attention, for those making affected products and those using them. Any flaw may prove useful to compromise other systems on the network. When everything is connected, security is only as strong as the weakest node on the network.

  • Like The Rest Of The Internet Of Things, Most 'Smart' Locks Are Easily Hacked

    Smart refrigerators that leak your e-mail credentials. Smart TVs that collect but then fail to secure your living room conversations. Smart thermostats that can be loaded with ransomware. Smart vehicles that can be hacked and potentially kill you. This is the end result of "Internet of Things" evangelists and companies that for the last half-decade put hype and profit (the cart) well ahead of consumer privacy and security (the horse), in the process exposing us all to thousands of new attack vectors in homes and businesses around the world.

Security News

Filed under
Security

Security Leftovers

Filed under
Security
  • Security advisories for Wednesday
  • Google: QuadRooter Threat Blocked On Most Android Devices
  • Linux Distributions Vulnerable to Cyber-Attacks: Report
  • Windows 10 Attack Surface Grows with Linux Support in Anniversary Update [Ed: Does Kaspersky not know CrowdStrike is a Microsoft-connected firm that spreads Linux FUD?]
  • Web pages, Word docs, PDF files, fonts – behold your latest keys to infecting Windows PCs

    Microsoft has fixed 38 CVE-listed security vulnerabilities in Edge, Internet Explorer, and Office, as well as high-profile flaws that have allowed researchers to circumvent Windows boot protections.

    None of the programming blunders were publicly disclosed or actively exploited in the wild prior to today's patch release.

  • If census site was taken down after DDoS attack it wasn't prepared: expert

    The attack against the census website that resulted in it being taken down last night appears, at face value, to have been nothing more than the standard attack perpetrated against countless sites every day by everyone from children to malcontents with an axe to grind, an expert says.

    That the site was attacked is not in the least bit surprising, security adviser Troy Hunt told Fairfax Media, but it was unexpected that an attack of this kind would result in the site going down.

  • Census 2016: ABS needs to provide proof of DDoS

    Technical people like him are what we need to cut through all the bulldust. One person who is an expert in this art is Craig Sanders, a systems administrator of many decades, and one who can speak plainly. Many years ago, following a major distributed denial of service of attack on the Internet's root name servers, he was one who educated me on the phenomenon. This time was no different with Sanders; he calmly and clearly pointed me in the direction of the evidence that was needed.

    If the census website crashed due to foreign intervention — either through a denial of service or a distributed denial of service — how is it that none of the major security companies around the world did not notice it? You would need an attack of some magnitude to take down the ABS census site.

  • Researchers crack Microsoft feature, say encryption backdoors similarly crackable [Ed: by design]

    Researchers who uncovered a security key that protects Windows devices as they boot up say their discovery is proof that encryption backdoors do not work.

    The pair of researchers, credited by their hacker nicknames MY123 and Slipstream, found the cryptographic key protecting a feature called Secure Boot.

    They believe the discovery highlights a problem with requests law enforcement officials have made for technology companies to provide police with some form of access to otherwise virtually unbreakable encryption that might be used by criminals.

    “Microsoft implemented a ‘secure golden key’ system. And the golden keys got released from [Microsoft's] own stupidity,” wrote the researchers in their report, in a section addressed by name to the FBI.

    “Now, what happens if you tell everyone to make a ‘secure golden key’ system? Hopefully you can add 2+2.”

    Secure Boot is a built into the firmware of computer — software unique to different types of hardware that exists outside the operating system and is used to boot the OS.

Security News

Filed under
Security
  • Containerized Security: The Next Evolution of Virtualization?

    We in the security industry have gotten into a bad habit of focusing the majority of our attention and marketing dollars on raising awareness of the latest emerging threats and new technologies being developed to detect them. One just has to look at the headlines or spend fifteen minutes walking the show floor at a major security conference to see this trend. However, while we are focusing on what all the bad guys are doing, we’ve taken the eye off the ball of where our infrastructure business is going.

  • SDN Security Researchers State Their Case at Black Hat

    So say two of his grad students, Seungsoo Lee and Changhoon Yoon (left and right, respectively, in the photo above). But along with Shin, who’s now an assistant professor at the Korea Advanced Institute of Science and Technology (Kaist) and a research associate at the Open Networking Foundation (ONF), they’re hoping the industry is ready to start looking at the vulnerabilities that SDN introduces.

  • Widespread Linux Flaw Allows TCP Session Hijacking, Termination
  • Bungling Microsoft singlehandedly proves that golden backdoor keys are a terrible idea [Ed: Microsoft and backdoor should become synonymous. At every level, online and offline, Microsoft products booby-trapped with backdoors.]

    Microsoft leaked the golden keys that unlock Windows-powered tablets, phones and other devices sealed by Secure Boot – and is now scrambling to undo the blunder.

    These skeleton keys can be used to install non-Redmond operating systems on locked-down computers. In other words, on devices that do not allow you to disable Secure Boot even if you have administrator rights – such as ARM-based Windows RT tablets – it is now possible to sidestep this block and run, say, GNU/Linux or Android.

    What's more, it is believed it will be impossible for Microsoft to fully revoke the leaked keys.

    And perhaps most importantly: it is a reminder that demands by politicians and crimefighters for special keys, which can be used by investigators to unlock devices in criminal cases, will inevitably jeopardize the security of everyone.

    Microsoft's misstep was uncovered by two researchers, MY123 and Slipstream, who documented their findings here in a demoscene-themed writeup published on Tuesday. Slip believes Microsoft will find it impossible to undo its leak.

  • Microsoft Creates Backdoor In Windows, Accidentally Leaks UEFI Secure Boot Keys

    Two researchers reported that Microsoft accidentally compromised the golden keys to its UEFI Secure boot feature.

  • Can Copperhead OS fix Android's security problems?

Canonical Patches Multiple Kernel Vulnerabilities in All Supported Ubuntu OSes

Filed under
Security
Ubuntu

Today, August 10, 2016, Canonical published several security notices to inform Ubuntu Linux users about new kernel updates for their distributions, patching several vulnerabilities discovered recently.

Read more

Internet of Insecurity

Filed under
Security
  • Linux TCP flaw enables remote attacks

    Researchers at the University of California, Riverside, say they have found a weakness in the transmission control protocol (TCP) used by Linux since late 2012 which allows the remote hijacking of Internet communications.

  • Serious security threat to many Internet users highlighted
  • Your 'Smart' Thermostat Is Now Vulnerable To Ransomware

    We've noted time and time again how the much ballyhooed "internet of things" is a privacy and security dumpster fire, and the check is about to come due. Countless companies and "IoT" evangelists jumped head first into the profit party, few bothering to cast even a worried look over at the reality that basic security and privacy standards hadn't come along for the ride. The result has been an endless parade of not-so-smart devices and appliances that are busy either leaking your personal details or potentially putting your life at risk.

    Of course, the Internet of Things hype machine began with smart thermostats and the sexy, Apple-esque advertising of Nest. The fun and games didn't last however, especially after several botched firmware updates resulted in people being unable to heat or cool their homes (relatively essential for a thermostat).

Security News

Filed under
Security
  • No, 900 million Android devices are not at risk from the 'Quadrooter' monster

    Guys, gals, aardvarks, fishes: I'm running out of ways to say this. Your Android device is not in any immediate danger of being taken over a super-scary malware monster.

    It's a silly thing to say, I realize, but we go through this same song and dance every few months: Some company comes out with a sensational headline about how millions upon millions of Android users are in danger (DANGER!) of being infected (HOLY HELL!) by a Big, Bad Virus™ (A WHAT?!) any second now. Countless media outlets (cough, cough) pick up the story and run with it, latching onto that same sensational language without actually understanding a lick about Android security or the context that surrounds it.

    To wit: As you've no doubt seen by now, our latest Android malware scare du jour is something an antivirus software company called Check Point has smartly dubbed "Quadrooter" (a name worthy of Batman villain status if I've ever heard one). The company is shouting from the rooftops that 900 million (MILLION!) users are at risk of data loss, privacy loss, and presumably also loss of all bladder control -- all because of this hell-raising "Quadrooter" demon and its presence on Qualcomm's mobile processors.

  • 900 Million Androids Could Be Easy Prey for QuadRooter Exploits
  • Annoying "Open PDF in Edge" Default Option Puts Windows 10 Users at Risk

    Microsoft released today its monthly security patch, and one of the five security bulletins labeled as critical was a remote code execution (RCE) flaw in its standard PDF rendering library that could be exploited when opening PDF files.

Syndicate content

More in Tux Machines

Red Hat and Fedora

  • Red Hat, Logicalis in digital transformation partnership in Latin America
    PromonLogicalis, a provider of information technology and communication solutions and services in Latin America, and Red Hat, Inc. (NYSE: RHT), the world's leading provider of open source solutions, announced a collaboration that aim to help organizations navigate the digital transformation of their infrastructures to pave the way for cloud and the software-defined technologies, and to advance open source technology awareness in the region. Open source is delivering significant advancements in many areas of technology through community-powered innovation, including cloud computing, mobile, big data, and more. And, as companies embrace modern technology as a competitive advantage via digital transformation efforts, many are turning to open source because of the flexibility and agility it can enable.
  • Red Hat Inc. (RHT) Downgraded by Zacks Investment Research to “Hold”
  • An Easy Way To Try Intel & RADV Vulkan Drivers On Fedora 24
    Fedora 25 should have good support for the open-source Vulkan Linux drivers (particularly if it lands the next Mesa release) while Fedora 24 users can now more easily play with the latest Mesa Git RADV and Intel ANV Vulkan drivers via a new repository. A Phoronix reader has setup a Fedora Copr repository that is building Intel's Vulkan driver from Mesa Git plus the RADV Radeon Vulkan driver re-based from its source (David Airlie's semi-interesting GitHub branch). Fedora COPR, for the uninformed, is the distribution's equivalent to Ubuntu PPA repositories.
  • Meeting users, lots of users
    Every year, I introduce Fedora to new students at Brno Technical University. There are approx. 500 of them and a sizable amount of them then installs Fedora. We also organize a sort of installfest one week after the presentation where anyone who has had any difficulties with Fedora can come and ask for help. It’s a great opportunity to observe what things new users struggle with the most. Especially when you have such a high number of new users. What are my observations this year?

Linux Devices

  • 96Boards SBCs host Intel Joule and Curie IoT modules
    Gumstix announced two SBCs this week, based on Intel Joule and Curie IoT modules and built to 96Boards CE and IE form-factor specifications, respectively. At Linaro Connect Las Vegas 2016, where earlier this week Linaro’s 96Boards.org announced a new 96Boards IoT Edition (IE) spec, Gumstix announced support for 96Boards.org’s open SBC standards with two new single-board computers. Both SBCs will be available for purchase in October.
  • ORWL — First Open Source And Physically Secure PC, Runs Linux And Windows
    ORWL is the first open source, physically secure computer. Using a secure microcontroller (MCU) and an ‘active clamshell mesh’, the device makes sure that nobody breaks the security of the system. Its maker, Design Shift, has also launched a crowdfunding campaign on Crowd Supply.
  • Purism Is Still Hoping To Build A GNU/Linux Free Software Librem Smartphone
    Purism, the startup behind the Librem laptops with a focus on free software and user privacy/freedom, still has their minds set on coming up with a GNU/Linux smartphone. Purism continues selling their high-priced laptops and their Librem 11 is forthcoming as an Intel-based tablet/convertible device with stocking station. Next on their horizon they want to produce "the ideal no-carrier, Free Software phone running a bona fide GNU+Linux stack."

Leftovers: OSS

  • Asterisk 14 Improves Open-Source VoIP
    Digium, the lead commercial sponsor behind the Asterisk open source PBX project announced the release Asterisk 14 this week, continuing to evolve the decade old effort, making it easier to use and deploy.
  • Yahoo open-sources a deep learning model for classifying pornographic images
    Yahoo today announced its latest open-source release: a model that can figure out if images are specifically pornographic in nature. The system uses a type of artificial intelligence called deep learning, which involves training artificial neural networks on lots of data (like dirty images) and getting them to make inferences about new data. The model that’s now available on GitHub under a BSD 2-Clause license comes pre-trained, so users only have to fine-tune it if they so choose. The model works with the widely used Caffe open source deep learning framework. The team trained the model using its now open source CaffeOnSpark system. The new model could be interesting to look at for developers maintaining applications like Instagram and Pinterest that are keen to minimize smut. Search engine operators like Google and Microsoft might also want to check out what’s under the hood here. “To the best of our knowledge, there is no open source model or algorithm for identifying NSFW images,” Yahoo research engineer Jay Mahadeokar and senior director of product management Gerry Pesavento wrote in a blog post.
  • Cloudera, Hortonworks, and Uber to Keynote at Apache Big Data and ApacheCon Europe
  • Vendors Pile on Big Data News at Strata
    Cloudera, Pentaho and Alation are among vendors making Big Data announcements at this week's Strata event. Vendors big and small are making news at this week's Strata + Hadoop event as they try to expand their portion of the Big Data market. Cloudera highlighted a trio of Apache Software Foundation (ASF) projects to which it contributes. Among them is Spark 2.0, which benefits from a new Dataset API that offers the promise of better usability and performance as well as new machine learning libraries.
  • New alliances focus on open-source, data science empowerment
    How can data science make a true market impact? Partnerships, particularly amongst open source communities. As IBM solidifies its enterprise strategies around data demands, two new partnerships emerge: one with Continuum Analytics, Inc., advancing open-source analytics for the enterprise; and another with Galvanize, initiating a Data Science for Executives program. Continuum Analytics, the creator and driving force behind Anaconda — a leading open data science platform powered by Python — has allied with IBM to advance open-source analytics for the enterprise. Data scientists and data engineers in open-source communities can now embrace Python and R to develop analytic and machine learning models in the Spark environment through its integration with IBM’s DataWorks Project. The new agreement between IBM and Galvanize, which provides a dynamic learning community for technology, will offer an assessment, analysis and training element for Galvanize’s Data Science for Executives program. This program empowers corporations to better understand, use and maximize the value of their data. The program will support IBM’s DataFirst Method, a methodology that IBM says provides the strategy, expertise and game plan to help ensure enterprise customers’ succeed on their journey to become a data-driven business.
  • Apache Spot: open source big data analytics for cyber
  • Chinese open source blockchain startup Antshares raises $4.5M through crowdsourcing [Ed: Microsoft-connected]
  • August and September 2016: photos from Pittsburgh and Fresno
  • Libre Learn Lab: a summit on freely licensed resources for education
    Libre Learn Lab is a two-day summit for people who create, use and implement freely licensed resources for K-12 education, bringing together educators, policy experts, software developers, hardware hackers, and activists to share best practices and address the challenges of widespread adoption of these resources in education. The 2nd biennial conference is Saturday, October 8th, and Sunday, October 9th, at the MIT Tang Center. The keynote addresses will be delivered by the FSF’s own Richard M. Stallman, former Chief Open Education Advisor Andrew Marcinek and founder of HacKIDemia Stefania Druga. At the event, there will be a special tribute to Dr. Seymour Papert (the father of educational computing) by Dr. Cynthia Solomon.

Security Leftovers

  • Friday's security advisories
  • ICANN grinds forward on crucial DNS root zone signing key update
    The Internet Corporation for Assigned Names and Numbers is moving -- carefully -- to upgrade the DNS root zone key by which all domains can be authenticated under the DNS Security Extensions protocol. ICANN is the organization responsible for managing the Domain Name System, and DNS Security Extensions (DNSSEC) authenticates DNS responses, preventing man-in-the-middle attacks in which the attacker hijacks legitimate domain resolution requests and replaces them with fraudulent domain addresses. DNSSEC still relies on the original DNS root zone key generated in 2010. That 1024-bit RSA key is scheduled to be replaced with a 2048-bit RSA key next October. Although experts are split over the effectiveness of DNSSEC, the update of the current root zone key signing key (KSK) is long overdue.
  • Cybersecurity isn't an IT problem, it's a business problem
    The emergence of the CISO is a relatively recent phenomenon at many companies. Their success often relies upon educating the business from the ground up. In the process, companies become a lot better about how to handle security and certainly learn how not to handle it. As a CIO, knowing the pulse of security is critical. I oversee a monthly technology steering committee that all the executives attend. The CISO reports during this meeting on the state of the security program. He also does an excellent job of putting risk metrics out there, color coded by red, yellow, and green. This kind of color grading allows us to focus attention on where we are and what we’re doing about it.