Language Selection

English French German Italian Portuguese Spanish

Security

IPFire 2.15 Core 80 Is a Powerful and Free Linux Firewall OS

Filed under
GNU
Linux
Security

Michael Tremer, a developer for the ipfire.org team, has announced that IPFire 2.13 Core 80, a new stable build of the popular Linux-based firewall distribution, has been released and is now available for download.

Read more

Mozilla's Developer Network Site Has Leaks

Filed under
Moz/FF
Security

Mozilla's website dedicated to developers has suffered from a database error that has exposed email addresses and encrypted passwords of registered users for about a month, the company announced.
About 76,000 Mozilla Development Network (MDN) users had their email addresses exposed, along with around 4,000 encrypted passwords, said Stormy Peters, director of development relations, and Joe Stevensen, operations security manager. Many of those affected have already been notified.

Read more

Answering questions regarding the Fedora Security Team

Filed under
Red Hat
Security

Wow, I had no idea that people would care about the start of this project. There seems to be a few questions out there that I’d like to address here to clarify what we are doing and why.

Read more

Mitro Releases a New Free & Open Source Password Manager

Filed under
OSS
Security

Today, Twitter acquired a password manager startup called Mitro. As part of the deal, Mitro will be releasing the source to its client and server code under the GPL.

Read more

DHS Wants To Help Developers Secure Open-Source Software

Filed under
OSS
Security

The Department of Homeland Security is funding a project aimed at protecting the nation's critical infrastructure and networks by providing tools that test for defects in open source and commercial software.

Read more

Tor anonymity service says unknown attackers compromised its network

Filed under
Moz/FF
OSS
Security

The Tor encryption service is a high-profile bastion of computer security, but the project appears to have been compromised earlier this year. Today, the Tor Project blog announced that an unknown party likely managed to gather information about people who were looking up hidden services — websites that users can operate and visit anonymously, like Silk Road — and could theoretically have compromised other parts of the network.

Read more

The security flaws in Tails Linux are not its only problem

Filed under
Security
Debian

If you want to use Tor, then Tails is your best friend. Tails is a version of Linux that sends data through the Tor network.

All Internet traffic to/from Tails goes through Tor, making it resistant to end user mistakes. Tails is not normally installed on a computer, instead it's run from a bootable DVD, USB flash drive or flash memory card. Compared to the Tor Browser Bundle, Tails is unquestionably the way to go. Ed Snowden uses it.

Read more

Also related:

Homeland Security gets into software security

Filed under
OSS
Security

Personally, while I still think the DHS is an unlikely sponsor for this project — the National Security Agency (NSA) or NIST seem like its more natural home — I think the SWAMP sounds like a very useful one-stop for anyone wanting to double-check their pre-production code for errors before release.

Read more

The world's most secure OS may have a serious problem

Filed under
GNU
Linux
Security
Debian

The Tails operating system is one of the most trusted platforms in cryptography, favored by Edward Snowden and booted up more than 11,000 times per day in May. But according to the security firm Exodus Intelligence, the program may not be as secure as many thought. The company says they've discovered an undisclosed vulnerability that will let attackers deanonymize Tails computers and even execute code remotely, potentially exposing users to malware attacks. Exodus is currently working with Tails to patch the bug, and expects to hand over a full report on the exploit next week.

Read more

Docker security with SELinux

Filed under
GNU
Linux
Server
Security

This article is based on a talk I gave at DockerCon this year. It will discuss Docker container security, where we are currently, and where we are headed.

Read more

Syndicate content

More in Tux Machines

Red Hat News

Fedora: The Latest

  • Korora 22 Flash Update
    As we announced when Korora 22 was released, Adobe Flash is no longer included by default.
  • Fedora repository for Doom stuff: Zandronum, Doomseeker, CnDoom
    I had a bit of free time over the last few days, and looked at the current state of the art for Doom on Linux. The awesome Rahul Sundaram has been looking after several Doom-related packages for a while – including the Chocolate Doom package – but there are some things that seem to be commonly used these days that we didn’t have packaged. So I packaged them up, and put them in a new repository!
  • CUDA 7.0 enabled programs for Fedora 22
    I’ve udpated the CUDA version in the Fedora 22 Nvidia repository, it now contains CUDA 7.0.28 along with the cuFFT 7.0.35 patch. Note that from this version, CUDA is x86_64 bit compatible only, so there are no more i386 packages. There is still the cudart library available for 32 bit, but I don’t think it’s worth packaging.
  • Secure Boot — Fedora, RHEL, and Shim Upstream Maintenance: Government Involvement or Lack Thereof
    Note that there are parts of this chain I’m not a part of, and obviously linux distributions I’m not involved in that support Secure Boot. I encourage other maintainers to offer similar statements for their respective involvement.
  • Remi repository is changing
    The "remi" repository exists for > 10 years, it have changed a lot, and some recent changes worth to be explained.

Android Leftovers

Leftovers: OSS