Language Selection

English French German Italian Portuguese Spanish

Security: Updates, Equifax, Black Duck FUD, Emacs 25.3, and Measuring Security

Filed under
Security
  • Security updates for Monday
  • Researchers use Windows 10 Linux subsystem to run malware

    The provision of a Linux subsystem on Windows systems — a new Windows 10 feature known as Subsystem for Linux (WSL) — has made it possible to run known malware on such systems and bypass even the most common security solutions, security researchers at Check Point claim.

    In a detailed blog post, researchers Gal Elbaz and Dvir Atias said they had dubbed this technique of getting malware onto a Windows system as Bashware, with Bash being the default shell on a large number of Linux distributions.

  • Episode 62 - All about the Equifax hack
  • Equifax moves to fix weak PINs for “security freeze” on consumer credit reports

    As Equifax moved to provide consumers the ability to protect their credit reports on the heels of a major data breach, some of the details of the company's response were found lacking. As consumers registered and moved to lock their credit reports—in order to prevent anyone who had stolen data from opening credit in their name—they found that the security personal identification number (PIN) provided in the locking process was potentially insecure.

    [...]

    The PIN revelation came on the heels of concerns that Equifax was attempting to block the ability of those checking to see if their data was exposed or enrolling in the TrustedID Premiere service to sue Equifax over the breach. An Equifax spokesperson said that the arbitration clause in the Terms of Service for TrustedID Premier only applied to the service itself, not to the breach.

  • Unpatched Open Source Software Flaw Blamed for Massive Equifax Breach [Ed: But this claim has since then been retracted, so it might be fake news]
  • Equifax Breach Blamed on Open-Source Software Flaw [Ed: This report from a News Corp. tabloid has since been retracted, so why carry on linking to it?]
  • The hidden threat lurking in an otherwise secure software stack [Ed: Yet another attack on FOSS security, courtesy of the Microsoft-connected Black Duck]
  • [ANNOUNCE] Emacs 25.3 released
  • Emacs 25.3 Released To Fix A Security Vulnerability Of Malicious Lisp Scripts

    GNU --
    Emacs 25.3 is now available, but it doesn't offer major new features, rather it fixes a security vulnerability.

    Emacs' x-display decoding feature within the Enriched Text mode could lead to executing arbitrary malicious Lisp code within the text.

  • Measuring security: Part 1 - Things that make money

    If you read my previous post on measuring security, you know I broke measuring into three categories. I have no good reason to do this other than it's something that made sense to me. There are without question better ways to split these apart, I'm sure there is even overlap, but that's not important. What actually matters is to start a discussion on measuring what we do. The first topic is about measuring security that directly adds to revenue such as a product or service.

    [...]

    I see a lot of groups that don't do any of this. They wander in circles sometimes adding security features that don't matter, often engineering solutions that customers only need or want 10% of. I'll never forget when I first looked at actual metrics on new features and realized something we wanted to add was going to have a massive cost and generate zero additional revenue (it may have actually detracted in future product sales). On this day I saw the power in metrics. Overnight my group became heroes for saving everyone a lot of work and headaches. Sometimes doing nothing is the most valuable action you can take.

More in Tux Machines

Today in Techrights

Android Leftovers

Our Favourite Apps for Ubuntu

We enjoy using Ubuntu mainly for gaming, writing, listening to music and browsing the web. (Lots and lots of browsing the web.) There are other apps that we would love to have on Ubuntu like Affinity Photo, a stunning image editor that’s on par with Adobe’s Photoshop that’s available on Windows and Mac as well as Bear, a beautifully designed note taking app that we do most of our writing on that’s only available for macOS. However, the Ubuntu platform has moved forward in leaps and bounds in recent years when it comes to the official availability of popular apps and we are confident that this trend will continue. What’s your favourite Ubuntu apps? Read more

Kernel Space: Plans for Linux 4.16, 4.15 Likely Out Shortly