Language Selection

English French German Italian Portuguese Spanish

Security

Mozilla Start Drafting Plans To Deprecate Insecure HTTP

Filed under
Moz/FF
Security

Barnes is hoping for more people to move to HTTPS by limiting new browser features from becoming available over insecure HTTP, in the name of security. He wrote in a mailing list post, "In order to encourage web developers to move from HTTP to HTTPS, I would like to propose establishing a deprecation plan for HTTP without security. Broadly speaking, this plan would entail limiting new features to secure contexts, followed by gradually removing legacy features from insecure contexts. Having an overall program for HTTP deprecation makes a clear statement to the web community that the time for plaintext is over -- it tells the world that the new web uses HTTPS, so if you want to use new things, you need to provide security."

Read more

Encryption Support For EXT4

Filed under
Linux
Google
Security

Ted published the twenty-two patches earlier this month for implementing encryption support into EXT4, complete with file-name and symlink encryption. The patches were developed by Ted Ts'o and Michael Halcrow.

Read more

Manjaro Devs Fix Embarrassing Expired SSL Certificate Problem

Filed under
Linux
Security

The Manjaro developers have finally fixed the embarrassing problem they had with an expired SSL certificate that made accessing their forums and wiki much harder.

Read more

Don’t judge the risk by the logo

Filed under
Red Hat
Security

It’s been almost a year since the OpenSSL Heartbleed vulnerability, a flaw which started a trend of the branded vulnerability, changing the way security vulnerabilities affecting open-source software are being reported and perceived. Vulnerabilities are found and fixed all the time, and just because a vulnerability gets a name and a fancy logo doesn’t mean it is of real risk to users.

Read more

Mozilla Working to Provide Tracking Protection in Firefox, How to Enable It

Filed under
Moz/FF
Security

Mozilla is working on a new feature called Tracking Protection that is helping users identify and block websites that collect personal data despite the fact that the browser has the "Do Not Track" policy enabled.

Read more

Tor 0.2.6.7 Fixes Security Issues That Could Be Used by Attackers to Crash Hidden Services and Clients

Filed under
Security

A new version of the popular Tor software that enables anonymous communication between computers around the world was released today, April 7, in order to fix two security issues discovered in the previous versions.

Read more

How Linux Australia Handled Its Recent Data Breach

Filed under
GNU
Linux
Security

In an email, Linux Australia revealed that its servers where compromised during the morning of 22 March. Over the course of a few hours, the organisation believes its databases containing conference information were dumped to an external source. A “currently unknown vulnerability” caused a buffer overflow that allowed the hacker to acquire root access.

Read more

Linux Australia server hacked, personal information may have been stolen

Filed under
Linux
Security

A public server belonging to Linux Australia, the umbrella group for Linux user groups in the country, were breached on March 22, and the personal information of members may have been stolen.

Read more

Lots of GnuPG Vulnerabilities Have Been Closed in All Ubuntu OSes

Filed under
Security
Ubuntu

Canonical has published details in a security notice about a number of GnuPG vulnerabilities that have been found and fixed in Ubuntu 14.10, Ubuntu 14.04 LTS, Ubuntu 12.04 LTS, and Ubuntu 10.04 LTS operating systems.

Read more

Threat Modeling Tool Created by Mozilla Winter of Security Team

Filed under
Moz/FF
Security

A web-based threat modeling tool was developed by undergraduate students at St. Mary’s University in Nova Scotia, Canada, as part of Mozilla’s Winter of Security project in 2014.

Read more

Syndicate content

More in Tux Machines

Ubuntu Touch to Get Improved Desktop Mode with Next Update

Canonical is preparing a major new update for Ubuntu Touch, but it will take a while until it's going to be ready. From the looks of it, the devs are preparing some interesting improvements and updates. Read more

Parsix GNU/Linux 7.0 Will Reach End of Life on June 14 to Make Room for Parsix 8.0

The Parsix Project has recently announced that their Parsix GNU/Linux 7.0 (Nestor) distribution will reach the end of its life support in the coming weeks, urging users to upgrade to Parsix GNU/Linux 7.5 (Rinaldo) as soon as possible. Read more

Leftovers: Software

  • 3 Open Source Python Shells
    Python is a high-level, general-purpose, structured, powerful, open source programming language that is used for a wide variety of programming tasks. It features a fully dynamic type system and automatic memory management, similar to that of Scheme, Ruby, Perl, and Tcl, avoiding many of the complexities and overheads of compiled languages. The language was created by Guido van Rossum in 1991, and continues to grow in popularity.
  • Google Chrome 44 (Dev) Brings Interesting New Features
  • CodeWeavers CrossOver 14.1.3 has been released
    I am delighted to announce that CodeWeavers has just released CrossOver 14.1.3 for both Mac OS X and Linux. CrossOver 14.1.3 has important bug fixes for both Mac and Linux users.

today's leftovers

  • Consumers Continue to Buy Chromebooks as Secondary PCs, Enterprise Still Uninterested
  • Video: LXD containers vs. KVM
    Since I'm such a big container fan (been using them on Linux since 2005) and I recently blogged about Docker, LXC, and OpenVZ... how could I pass up posting this? Some Canonical guys gave a presentation at the recent OpenStack Summit on "LXD vs. KVM". What is LXD? It is basically a management service for LXC that supposedly adds a lot of the features LXC was missing... and is much easier to use. For a couple of years now Canonical has shown an interest in LXC and has supposedly be doing a lot of development work around them. I wonder what specifically? They almost seem like the only company who is interested in LXC.. or at least they are putting forth a publicly noticeable effort around them.
  • Ubuntu's LXD vs. KVM For The Linux Cloud
    LXD is usable with Ubuntu 15.04 albeit not many have yet fully experimented with this new technology from Canonical given its early state. The LXD Linux container hypervisor allows for rapid provisioning, very fast performance, a REST API, and other functionality. If you're wishing to learn more about LXD, this week at the OpenStack Summit in Vancouver was a talk about LXD vs. KVM for Linux hypervisors.
  • Cloud Driving HP's Server Business Forward
    HP announced is second quarter fiscal 2015 earnings on May 21, with company executives enthusiastic about the company's upcoming split, and continued prospects in the cloud.
  • The Latest Linux Kernel Git Code Fixes The EXT4 RAID0 Corruption Problem
    An EXT4 file-system corruption problem was uncovered with Linux 4.0 that turned out to be an MD RAID0 issue with the Linux kernel in the latest stable series. This RAID corruption issue has now been fixed in the latest kernel Git code.
  • Interview with Mary Winkler
    LOVE the blending tools. I’m used to those of Paint Tool SAI, and finding a program whose brushes are far more customizable and can do more is digital art heaven. Especially an open source one!
  • Reminder: Evolving KDE survey milestone on May 31st
    Evolution is a powerful concept and tool. When harnessed properly, humans have been able to tailor and adapt crops and domesticate animals. We’ve been able to grow the Dutch unnecessarily tall and create beautiful and consequence-free theme parks as shown in the Jurassic Park documentary series on the BBC. However, when not monitored closely or left to nature’s own devices, the result is the terrifying land based sharks that have caused such recent devastation across most of Australia.
  • GNOME Shell It is!!
    It’s been a while since my last post, I was busy with my university exams and didn’t get much time to work on my GSoC project. But during whatever time I got I tried to get myself familiar with GNOME Shell coding style and get a hang of the way it works, since GNOME Shell is the main module I will be working with in this project. But things weren’t as simple as I initially thought them to be. It has been a struggle trying to find out some structured documentation for GNOME Shell code-base mainly the JavaScript part.
  • Attention Fedora 22 prerelease users
  • Fedora 21 chrooted on an aarch64 Nexus 9
    A while back I bought a Nexus 9, mainly because it has a weird processor that emulates a 64 bit ARM (aarch64). Google seem to have abandoned this platform entirely, just 6 months after I got it, so fuck you too Google. Anyway …
  • Meet SparkyLinux, a Debian-based Linux distribution
    SparkyLinux features customized lightweight desktops (like E19, LXDE and Openbox), multimedia plugins, selected sets of apps and own custom tools to ease different tasks.
  • Is Canonical going to have an IPO?
  • Mozilla shifts gears: $25 phones out, Android apps in
  • Linksys NSLU2 adventures into the NetBSD land passed through JTAG highlands - part 1
  • GCC 6 Gets Support For The IBM z13 Mainframe Server
    The latest GNU Compiler Collection code now has proper optimization targeting/tuning support for the IBM z13.
  • News for open source virtual reality, popular Linux game distros, and more