Language Selection

English French German Italian Portuguese Spanish

Security

Homeland Security gets into software security

Filed under
OSS
Security

Personally, while I still think the DHS is an unlikely sponsor for this project — the National Security Agency (NSA) or NIST seem like its more natural home — I think the SWAMP sounds like a very useful one-stop for anyone wanting to double-check their pre-production code for errors before release.

Read more

The world's most secure OS may have a serious problem

Filed under
GNU
Linux
Security
Debian

The Tails operating system is one of the most trusted platforms in cryptography, favored by Edward Snowden and booted up more than 11,000 times per day in May. But according to the security firm Exodus Intelligence, the program may not be as secure as many thought. The company says they've discovered an undisclosed vulnerability that will let attackers deanonymize Tails computers and even execute code remotely, potentially exposing users to malware attacks. Exodus is currently working with Tails to patch the bug, and expects to hand over a full report on the exploit next week.

Read more

Docker security with SELinux

Filed under
GNU
Linux
Server
Security

This article is based on a talk I gave at DockerCon this year. It will discuss Docker container security, where we are currently, and where we are headed.

Read more

Tor, trust and the NSA

Filed under
OSS
Security

Tor is an anonymizing network that’s designed to protect you by “bouncing your communications around a distributed network of relays run by volunteers all around the world: it prevents somebody watching your Internet connection from learning what sites you visit, and it prevents the sites you visit from learning your physical location.”

That’s cool, but does Tor really guarantee you what you think or assume it does? I can’t say for sure, but when facing a state-sponsored entity with time and resources on its side, you cannot be too careful. At least if pays to know what other people think about Tor, especially when what they have to say runs counter to what you know, or what you think you know.

Read more

Avoid the Android vampire apps

Filed under
Android
Security

Some Android applications will drain your smartphone or tablet of battery life, storage or bandwidth like a blood-sucking fiend. Here's what's what with the worst of the worst.

Read more

Snowden on Dropbox: It’s hostile to privacy

Filed under
Software
Security

Dropbox is a very popular Cloud storage services, but is it good for the privacy-conscious?

According to Edward Snowden, it’s not.

In an interviewed published on GuardianNews, Snowden described Dropbox as “hostile to privacy.”

So what are the better alternatives. Snowden recommended Cloud storage services with zero-knowledge as a key feature.

Read more

How to use public PCs safely with Linux

Filed under
GNU
Linux
Security
HowTos

Public PCs aren't safe, so what's a PC user to do? Carry a Linux distribution on a USB stick in their backpocket of course!

Read more

Announcing Project Zero

Filed under
Google
OSS
Security

Security is a top priority for Google. We've invested a lot in making our products secure, including strong SSL encryption by default for Search, Gmail and Drive, as well as encrypting data moving between our data centers. Beyond securing our own products, interested Googlers also spend some of their time on research that makes the Internet safer, leading to the discovery of bugs like Heartbleed.

The success of that part-time research has led us to create a new, well-staffed team called Project Zero.

Read more

LibreSSL Portable Encounters Its First Release

Filed under
OSS
Security

OpenBSD developers have announced their first release of LibreSSL portable.

LibreSSL 2.0.0 is the release and is tested to build on Linux, Solaris, Mac OS X, and FreeBSD systems. Bob Beck of OpenBSD explains, "This is intended as an initial release to allow the community to start using and providing feedback. We will be adding support for other platforms as time and resources permit."

Read more

Samsung Nixes Knox: The Android Security Saga Continues

Filed under
Android
Security

Granted, Google has been updating handset issues at a quicker pace – particularly when it comes to security patches, via Play Services –and so far, the telcos have not played spoilers. But remember: Google has not initiated a move to push an entirely new OS directly to users except to those who own Google’s telco independent Nexus brand devices. Keep in mind that there’s a big difference between updating a feature or security patch and producing an entirely new OS. OS updates typically up the Kernel and the radios. It will be interesting (and historical) if the telcos continue to stay out of the way.

Read more

Syndicate content

More in Tux Machines

KDE: Simple by Default, Powerful When Needed

KDE (back when it was still the name of the desktop environment) and our applications historically stood for powerful features and great flexibility and customizeability. This is what our users love about our software, this is why they choose Plasma and KDE software instead of one of the other Free desktop offerings. And it is also something they would fight tooth and nail for if we wanted to take it away (as many a KDE maintainer who dared to remove a feature he thought was unnecessary can tell). Read more

BitTorrent Bleep alpha released for Android

As an alpha it still has some issues “As with any Alpha, there are some known issues and bugs to work out. Android users will need to set the app to “Wi-Fi Only” unless you have an unlimited data plan; this is only for the time being while we iron out and issue related to battery and data-plan. And while you can move a username from desktop to mobile, Bleep does not yet support moving an existing account from Android to the desktop. And while you can receive messages on multiple devices; messages sent will not be seen across all devices. As with our previous release, communications happen only when all parties are online – you cannot send offline photos or group chats asynchronously.” Read more

During Akademy 2014

This year there were lot of fast track (10 minutes) talks on different areas around KDE. All of them were quite interesting, some of them are: Bruno Coudoin talked about how and why GCompris moved to QtQuick with the support of KDE. What all challenges project faced while moving from GTK to Qt. Daniel Vrátil talked about his one year journey with Akonadi Martin Gräßlin gave an overview of current state of Kwin in adding Wayland support and future plans. Kevin Ottens talked about KDE craftsmen where analysis was on the way we handle our software production, how can we make our software even better. Kai Uwe Broulik talked about current status of Qt port on Android and iOS. Currently, 3 iOS apps in Apple store and 8 Android apps in Google play since December 2013. Read more

Leftovers: Software