Language Selection

English French German Italian Portuguese Spanish

Security

Cyber criminals capture 25,000 Unix servers

Filed under
Server
Security

Security boffins at ESET, in collaboration with CERT-Bund, the Swedish National Infrastructure for Computing as well as other agencies, have found a cybercriminal campaign that has taken control of over 25,000 Unix servers worldwide.

Dubbed "Operation Windigo" it has resulted in infected servers sending out millions of spam emails which are designed to hijack servers, infect the computers that visit them, and steal information.

Read more ►

Replicant developers find and close Samsung Galaxy back-door

Filed under
Android
Security

While working on Replicant, a fully free/libre version of Android, we discovered that the proprietary program running on the applications processor in charge of handling the communication protocol with the modem actually implements a back-door that lets the modem perform remote file I/O operations on the file system.

Read more ►

Red Hat Risk Reflex (The Linux Security Flaw That Isn't)

Filed under
Red Hat
Security

News headlines screaming that yet another Microsoft Windows vulnerability has been discovered, is in the wild or has just been patched are two a penny. Such has it ever been. News headlines declaring that a 'major security problem' has been found with Linux are a different kettle of fish. So when reports of an attack that could circumvent verification of X.509 security certificates, and by so doing bypass both secure sockets layer (SSL) and Transport Layer Security (TLS) website protection, people sat up and took notice. Warnings have appeared that recount how the vulnerability can impact upon Debian, Red Hat and Ubuntu distributions. Red Hat itself issued an advisory warning that "GnuTLS did not correctly handle certain errors that could occur during the verification of an X.509 certificate, causing it to incorrectly report a successful verification... An attacker could use this flaw to create a specially crafted certificate that could be accepted by GnuTLS as valid." In all, at least 200 operating systems actually use GnuTLS when it comes to implementing SSL and TLS and the knock-on effect could mean that web applications and email alike are vulnerable to attack. And it's all Linux's fault. Or is it?

Read more ►

Panic Over Transport Layer Security (TLS) Flaw Which is Already Patched

Filed under
GNU
Security

The only shocking thing is the amount of press coverage this received. PGP/GPG, OpenSSH, OpenSSL etc. were previously named here for flaws that had been found (in the context of Red Hat and the NSA [1, 2, 3]). These are not so uncommon. One just needs to keep up to date (patched) — one that which Apple’s customers cannot do. They can’t even write their own patches.

Read more ►

Yes there was a security hole in Linux, but Red Hat already fixed it

Filed under
GNU
Linux
Red Hat
Security

Originally reported by Ars Technica, the fix was available by the time the general public was made aware of it. It’s actually fairly similar to a certain security hole that lived for a year and could have allowed for exploits to be used in the wild.

Read more ►

Linux companies never miss an opportunity to miss an opportunity

Filed under
Linux
Security

It would be heartening to see James Whitehurst, the head of Red Hat Linux, the biggest commercial Linux outfit, and one that has seen billing go above the billion-dollar mark, deliver a speech at some official forum that underlined the fact that his company's product - and that of other commercial Linux companies - provides a guarantee against the insertion of backdoors.

Read more ►

Tor developing anonymous instant messenger

Filed under
OSS
Security

The instant messenger is still in the early planning stages, but Tor's developers seem to be preparing to turn it around quickly. The messenger will be built on Instantbird, an existing open-source messenger, and development will largely involve adding in Off-the-Record Messaging encryption, making it send its messages over Tor, and stripping it of some automated logging and reporting features. Tor hopes to have its first step of work on the messaging app completed by the end of March, but it doesn't draw a timeline for the project out from there.

Read more ►

Google Android chief: Android may be open, but it is not less secure

Filed under
Android
Google
Security

Does 'open' mean 'lack of security'?

According to Google, no. Instead, an open platform is the best path to take in order to make a platform as impermeable to threats as possible.

On Thursday, FrAndroid reported that Google's head of the Android division, Sundar Pichai, responded in a very candid way when asked about the operating system's security at Mobile World Congress in Barcelona, Spain.

Read more ►

Deep Black: More details on Boeing’s new secure Android smartphone

Filed under
Android
Linux
Security

Black is based on a proprietary security architecture that Boeing calls "PureSecure." Like Samsung’s Knox platform, it has a “trusted boot” mode that can detect and thwart any attempt to root the device—or disable it if it can’t. In addition to onboard media encryption for internal storage, the phone can be configured to inhibit certain functions based on location or the network it is connected to in order to prevent data loss. It might also be used to disable the device’s camera in secure facilities.

Read more ►

PGP Web of Trust: Core Concepts Behind Trusted Communication

Filed under
Security

If you've ever used Linux, you've most likely used OpenPGP without even realizing it. The open-source implementation of OpenPGP is called GnuPG (stands for "GNU Privacy Guard"), and nearly all distributions rely on GnuPG for package integrity verification. Next time you run "yum install" or "yum update", each package will be verified against its cryptographic signature before it is allowed to be installed on your system. This assures that the software has not been altered between the time it was cryptographically signed by distribution developers on the master server, and the time it was downloaded to your system.

However, far fewer people have actually used GnuPG for what it was originally designed for -- secure exchange of information in an untrusted medium (such as the internet), and even fewer have a good understanding of how the trust relationships are supposed to work.

In this mini series of articles, we'll take a look at what the web of trust is and how to use it to set up a secure and trusted communication.

Read more

Syndicate content

More in Tux Machines

Canonical Publishes Impressive Roadmap for All of Their Ubuntu Products

Canonical is working on multiple projects at the same time, and it's often difficult to understand their plans, but Director of Product Strategy Engineering Olli Ries has shed some light on how their inner workings are structured and how things are evolving, from the inside out. Read more

Making the Case for Koha: Why Libraries Should Consider an Open Source ILS

When Engard educates people on what open source is, what it means to use open source software, what types of software are available, which companies use it, and who trusts it, they see that their fears are unfounded, she says. To back up her discussions with facts, she maintains bibliographies on open source and open source security. She also has a set of bookmarks on Delicious, and she wrote a book, Practical Open Source Software for Libraries. “[W]hen people come to me and say open source is too risky … I have facts and figures, just what librarians want, to say no, all software has potential risk associated with it. You have to evaluate software side by side, and look at it, and really take the time to compare it. … I know you’re going to pick the open source solution over the proprietary because it is so quickly developed, so quickly fixed, so ahead of the curve as far as technology is concerned.” Read more

Review of Ubuntu Phone – A Work Still Under Progress

However, what one must remember is that the Ubuntu Phone is still a work in progress. The company is issuing updates every month and is relying on its current user base regarding the feedback and ideas. Right now, only three Ubuntu phones are present in the market ranging from $186 to $328 roughly. Ubuntu has been in hibernation mode for the development of this OS for a long time and it looked like they might be consumer ready now, however, after seeing the Ubuntu Phone it looks like they might be far from that scenario right now. Read more

Android M news: Release date delayed, to come out in September or October?

Google reveals that the newest Android operating system initially codenamed as "Android M" will be delaying the release of Android M Developer Preview 3 for selected Nexus devices. The information was shared by the company's employee and moderator Wojtek Kaliciński on the Developer community page in Google+. Read more