Well, folks, it looks like CyanogenMod, Inc. is starting to shape up to look like a real legit company. The company has already made big deals with phone manufacturers and successfully raised a good deal of money to help in their endeavors, and now they are making some changes to the way they present themselves.
A lot of Websites are still covering the last couple of Linux security breaches and today Steven J. Vaughan-Nichols said, "It's not Linux's fault!" It rarely is. A lot of talk is heard lately about those last XP users and what they will use next, but yesterday ComputerWorld.com said ATMs will likely be migrated to Linux as well. That's a whole demographic we forgot to count. Jack Wallen says Google is "single-handedly" responsible for propelling Linux to the top. And Michael Larabel reports that Ubuntu 14.04 runs very well on MacBooks.
There have been a lot of media reports about Linux security problems recently. ZDNet has taken a stand and pointed out that the problem isn't with Linux, the problem is with certain Linux users and administrators. I'd also argue that the problem is also with certain media outlets who jump on the "linux security stinks!" bandwagon at the earliest opportunity.
Security boffins at ESET, in collaboration with CERT-Bund, the Swedish National Infrastructure for Computing as well as other agencies, have found a cybercriminal campaign that has taken control of over 25,000 Unix servers worldwide.
Dubbed "Operation Windigo" it has resulted in infected servers sending out millions of spam emails which are designed to hijack servers, infect the computers that visit them, and steal information.
While working on Replicant, a fully free/libre version of Android, we discovered that the proprietary program running on the applications processor in charge of handling the communication protocol with the modem actually implements a back-door that lets the modem perform remote file I/O operations on the file system.
News headlines screaming that yet another Microsoft Windows vulnerability has been discovered, is in the wild or has just been patched are two a penny. Such has it ever been. News headlines declaring that a 'major security problem' has been found with Linux are a different kettle of fish. So when reports of an attack that could circumvent verification of X.509 security certificates, and by so doing bypass both secure sockets layer (SSL) and Transport Layer Security (TLS) website protection, people sat up and took notice. Warnings have appeared that recount how the vulnerability can impact upon Debian, Red Hat and Ubuntu distributions. Red Hat itself issued an advisory warning that "GnuTLS did not correctly handle certain errors that could occur during the verification of an X.509 certificate, causing it to incorrectly report a successful verification... An attacker could use this flaw to create a specially crafted certificate that could be accepted by GnuTLS as valid." In all, at least 200 operating systems actually use GnuTLS when it comes to implementing SSL and TLS and the knock-on effect could mean that web applications and email alike are vulnerable to attack. And it's all Linux's fault. Or is it?
The only shocking thing is the amount of press coverage this received. PGP/GPG, OpenSSH, OpenSSL etc. were previously named here for flaws that had been found (in the context of Red Hat and the NSA [1, 2, 3]). These are not so uncommon. One just needs to keep up to date (patched) — one that which Apple’s customers cannot do. They can’t even write their own patches.
Originally reported by Ars Technica, the fix was available by the time the general public was made aware of it. It’s actually fairly similar to a certain security hole that lived for a year and could have allowed for exploits to be used in the wild.
It would be heartening to see James Whitehurst, the head of Red Hat Linux, the biggest commercial Linux outfit, and one that has seen billing go above the billion-dollar mark, deliver a speech at some official forum that underlined the fact that his company's product - and that of other commercial Linux companies - provides a guarantee against the insertion of backdoors.
The instant messenger is still in the early planning stages, but Tor's developers seem to be preparing to turn it around quickly. The messenger will be built on Instantbird, an existing open-source messenger, and development will largely involve adding in Off-the-Record Messaging encryption, making it send its messages over Tor, and stripping it of some automated logging and reporting features. Tor hopes to have its first step of work on the messaging app completed by the end of March, but it doesn't draw a timeline for the project out from there.
Does 'open' mean 'lack of security'?
According to Google, no. Instead, an open platform is the best path to take in order to make a platform as impermeable to threats as possible.
On Thursday, FrAndroid reported that Google's head of the Android division, Sundar Pichai, responded in a very candid way when asked about the operating system's security at Mobile World Congress in Barcelona, Spain.
Black is based on a proprietary security architecture that Boeing calls "PureSecure." Like Samsung’s Knox platform, it has a “trusted boot” mode that can detect and thwart any attempt to root the device—or disable it if it can’t. In addition to onboard media encryption for internal storage, the phone can be configured to inhibit certain functions based on location or the network it is connected to in order to prevent data loss. It might also be used to disable the device’s camera in secure facilities.
If you've ever used Linux, you've most likely used OpenPGP without even realizing it. The open-source implementation of OpenPGP is called GnuPG (stands for "GNU Privacy Guard"), and nearly all distributions rely on GnuPG for package integrity verification. Next time you run "yum install" or "yum update", each package will be verified against its cryptographic signature before it is allowed to be installed on your system. This assures that the software has not been altered between the time it was cryptographically signed by distribution developers on the master server, and the time it was downloaded to your system.
However, far fewer people have actually used GnuPG for what it was originally designed for -- secure exchange of information in an untrusted medium (such as the internet), and even fewer have a good understanding of how the trust relationships are supposed to work.
In this mini series of articles, we'll take a look at what the web of trust is and how to use it to set up a secure and trusted communication.
The cross-platform HEUR:Backdoor.Java.Agent.a, as reported in a blog post published Tuesday by Kaspersky Lab, takes hold of computers by exploiting CVE-2013-2465, a critical Java vulnerability that Oracle patched in June. The security bug is present on Java 7 u21 and earlier. Once the bot has infected a computer, it copies itself to the autostart directory of its respective platform to ensure it runs whenever the machine is turned on. Compromised computers then report to an Internet relay chat channel that acts as a command and control server.
A basic tenant of open-source software security has long been the idea that since the code is open, anyone can look inside to see if there is something that shouldn't be there.
At this stage, despite deceiving marketing, IBM needs GNU/Linux and Free software more than GNU/Linux and FOSS need IBM. Recently, the President of the Open Source Initiative (OSI) called IBM a patent troll. IBM can carry on openwashing its business with OpenStack [11,12], Hadoop  and so on (even OpenOffice.org), but until it stops serving the NSA, the software patents agenda and various other conflicting interests (causes that harm software freedom and GNU/Linux) we are better off nurturing “true” (as in completely) Free software companies.
Earlier this week, Microsoft revealed that it had been going into users computers and removing outdated Tor clients. At first glance, this might seem like a crazed, misplaced attack on the Tor network, not unlike a campaign by a certain Irish politician, but the issue runs deeper than first thought.
Never run Red Hat’s “Enterprise Linux”, which cannot be trusted because of NSA involvement; Amazon, which pays Microsoft for RHEL and works with the CIA, should never be used for hosting
CESG (UK Government): GNU/Linux the Most Secure Operating System; New Backdoors Released for WindowsSubmitted by Roy Schestowitz on Thursday 16th of January 2014 01:01:01 PM Filed under
Revelations about how insecure our communications are have been a daily fixture of the news cycle recently, and it's in this climate that a pair of companies are combining to launch a new smartphone focused on privacy. The Blackphone will run a "security-oriented" version of Android named PrivatOS, which the companies say will allow users to securely place and receive phone calls, text messages, video chat, transfer and store files, and "anonymize your activity" through a VPN.