Press "Enter" to skip to content

Posts published in “Security”

Users Told Disconnect Certain Netgear Routers

Some popular Netgear routers contain a security flaw that is evidently easy to exploit and can make users vulnerable to a CSRF attack.

security vulnerability

Breaking News

About this time I’m wondering if I’d even purchase a Netgear router.

You’d think that with all of the fuss recently about the insecure Internet of things, especially when it comes to routers, that any router maker would be on top of it and patching vulnerabilities as soon as they’re discovered.

Evidently not, as far as Netgear is concerned.

New IoT Botnet, Attackers Target Tor, and More…

Also included, Flash on life support, Mageia’s new release, Ubuntu sets date for “Zesty Zapus” and our News Wire gets an RSS feed.

Tor logo

FOSS Week in Review

Outside of FOSS, the news becomes too depressing and repetitive to read. Gamergate has taken over our country and is set to move into the White House and to have free rein in the halls of congress. Roles are being reversed and it’s rapidly becoming politically incorrect to express concerns for our mother the earth or for the creatures who inhabit it, while it’s perfectly fine to label anyone who advocates for equality as a “social justice warrior” who should have no place within any organization.

If you think I’m bummed out, you’re right. At least for the time being, in the world of FOSS life goes on as usual…

Christine Hall

Christine Hall has been a journalist since 1971. In 2001, she began writing a weekly consumer computer column and started covering Linux and FOSS in 2002 after making the switch to GNU/Linux. Follow her on Twitter: @BrideOfLinux

What Malware Is on Your Router?

router

Mirai is exposing a serious security issue with the Internet of Things that absolutely must be quickly handled.

Until a few days ago, I had been seriously considering replacing the 1999 model Apple Airport wireless router I’ve been using since it was gifted to me in 2007. It still works fine, but I have a philosophy that any hardware that’s more than old enough to drive probably needs replacing. I’ve been planning on taking the 35 mile drive to the nearest Best Buy outlet on Saturday to see what I could get that’s within my price range.

After the news of this week, that trip is now on hold. For the time being I’ve decided to wait until I can be reasonably sure that any router I purchase won’t be hanging out a red light to attract the IoT exploit-of-the-week.

Christine Hall

Christine Hall has been a journalist since 1971. In 2001, she began writing a weekly consumer computer column and started covering Linux and FOSS in 2002 after making the switch to GNU/Linux. Follow her on Twitter: @BrideOfLinux

Mickey Mouse Open Source, Close Call at WordPress, and More…

Also included: FBI hacks 8,000 with single warrant, new Cinnamon desktop release, “government-backed attackers” after journalists, and FOSS Force adds beef to newsfeed.

FOSS Week in Review

Mickey Mouse Disney

Okay, Thanksgiving is over. Let the sales begin. Which reminds me, I have to buy a new cheap Wi-Fi router — cheap being the operative word. Any suggestions?

Otherwise, it’s back to FOSS news…

Christine Hall

Christine Hall has been a journalist since 1971. In 2001, she began writing a weekly consumer computer column and started covering Linux and FOSS in 2002 after making the switch to GNU/Linux. Follow her on Twitter: @BrideOfLinux

Malware Found on New Windows Computers (Not What You Think)

An investigative team for a Seattle television station discovered that finding malware on clean computers to be an everyday practice at Office Depot.

computer doctor

It appears that the office supply giant, Office Depot, isn’t adverse to tarnishing its reputation if there’s a buck or two to be made in the process.

KIRO TV in Seattle reported on November 15 that it had taken brand new out-of-the-box computers that had never been connected to the Internet to Office Depot stores, both in Washington state and Portland, Oregon, and told the repair desk staff that “it’s running a little slow.” In four out of six cases they were told the computer was infected with viruses and would require an up to $180 fix.

After declining the “fix,” they took the “virus laden” machines to a Seattle security outfit, IOActive, which reexamined the machines. “We found no symptoms of malware when we operated them,” an employee with the firm, Will Longman, said. “Nor did we find any actual malware.”

Christine Hall

Christine Hall has been a journalist since 1971. In 2001, she began writing a weekly consumer computer column and started covering Linux and FOSS in 2002 after making the switch to GNU/Linux. Follow her on Twitter: @BrideOfLinux

Krebs Goes Down, Opera Gets a VPN & More…

Also included: Yahoo’s big hack, Garrett on Lenovo, new Audacious and GNOME, and Ubuntu get’s ready for Yakkety Yak.

FOSS Week in Review

I spent time this week terminating a Yahoo account I’ve had since way back in the last century. For years, the My Yahoo page was my “home” page whenever I fired-up the old dial-up to go online, but over time the portal (remember portals?) became less and less relevant and I found my visits to Yahoo becoming less and less frequent. By the time I closed the account, prompted by news of a massive hack involving 500 million accounts going back to 2014, I hadn’t visited my Yahoo page in well over a year. RIP Yahoo. It was nice knowing you.

Christine Hall

Christine Hall has been a journalist since 1971. In 2001, she began writing a weekly consumer computer column and started covering Linux and FOSS in 2002 after making the switch to GNU/Linux. Follow her on Twitter: @BrideOfLinux

Redesigning Tor, Goodbye OpenOffice & More…

Also included: Remembering Vernon Adams, Red Hat vs. VMware, a new distro release, openSUSE Leap and ransomware that deletes files.

FOSS Week in Review

The summer of ’16 is all but over. Good riddance. Here in my piece of the woods we’ve seen all of the 90 plus days with high humidity I can take. Time to get out the long sleeves and sweaters.

It’s also time to look at this week’s FOSS news.

Christine Hall

Christine Hall has been a journalist since 1971. In 2001, she began writing a weekly consumer computer column and started covering Linux and FOSS in 2002 after making the switch to GNU/Linux. Follow her on Twitter: @BrideOfLinux

The Last LinuxCon, MariaDB Goes Open Core & More…

Also included: Gilles Chanteperdrix passes, corporate Linux, Cisco patches against the NSA, MariaDB’s proprietary moves, Netrunner becomes Maui, Ubuntu to replace Upstart, Fedora and Wayland, and Linux client for Yandex Disk.

FOSS Week in Review

The last LinuxCon: This year’s LinuxCon, held in the city of Toronto which is one of my favorite old haunts, was the last love fest for Linux under the name LinuxCon, which had come to be synonymous for a certain type of Linux festival. In a way, it’s fitting this should be the last as the show ended on the day before Linux’s 25th birthday and was, in many ways, a celebration of the first quarter century of Linux. In another way it’s a crying shame. LinuxCon has come to stand for the community spirited nature of Linux, even though backed by the Linux Foundation, which becomes less of a community organization with the passing of each year.

Linus Torvalds, Dirk Hohndel, LinuxCon 2016
Linus Torvalds being interviewed by VMware’s Dirk Hohndel on the last day of the last LinuxCon North America. Next year’s event in Los Angeles will be renamed Open Source Summit.
Christine Hall

Christine Hall has been a journalist since 1971. In 2001, she began writing a weekly consumer computer column and started covering Linux and FOSS in 2002 after making the switch to GNU/Linux. Follow her on Twitter: @BrideOfLinux

Jay Beale: Linux Security and Remembering Bastille Linux

“Secure by design” doesn’t mean that Linux users should take a carefree approach to security. On the Internet, somebody’s always hiding behind the firewall trying to pick the lock.

The FOSS Force Video Interview

Security expert and co-creator of the Linux-hardening (and now Unix-hardening) project Bastille Linux. That’s Jay Beale. He’s been working with Linux, and specifically on security, since the late 1980s. The greatest threat to Linux these days? According to Beale, the thing you really need to watch out for is your Android phone, which your handset manufacturer and wireless carrier may or may not be good about updating with the latest security patches. Even worse? Applications you get outside of the controlled Google Play and Amazon environments, where who-knows-what malware may lurk.

Robin "Roblimo" Miller

Robin “Roblimo” Miller is a freelance writer and former editor-in-chief at Open Source Technology Group, the company that owned SourceForge, freshmeat, Linux.com, NewsForge, ThinkGeek and Slashdot, and until recently served as a video editor at Slashdot. Now he’s mostly retired, but still works part-time as an editorial consultant for Grid Dynamics, and (obviously) writes for FOSS Force.

Encrypted File Sharing Service Tresorit Offers Linux Desktop Client, But…

At first glance, Tresorit’s end-to-end file sharing service looks like it might be able to overcome its proprietary nature and win favor with some Linux users. Unfortunately, the service comes with another issue that might be an insurmountable deal breaker for some.

The FOSS Force Review

On Thursday I received an email from Eszter Szilva, a PR manager at Tresorit, which is an “end-to-end encrypted file sharing service.” She was offering an invitation to take a peek at the company’s just released client for GNU/Linux. I must admit I was a little excited by this, despite the fact that I already figured the service was also end-to-end proprietary. I was willing to ignore that, thinking it’s about time for companies to start treating Linux users with the same respect given to users of other operating systems.

Christine Hall

Christine Hall has been a journalist since 1971. In 2001, she began writing a weekly consumer computer column and started covering Linux and FOSS in 2002 after making the switch to GNU/Linux. Follow her on Twitter: @BrideOfLinux

Breaking News: