Security

VulnCon 2025

May 29, 2025

Back in April I attended VulnCon, the second year this conference has been held by FIRST and the CVE program. This was a great conference for incident responders working on developing software. There were a ton of great talks, many of which I was unable to attend so I’m …

Security Unscripted

February 15, 2025

Been working on this for a bit and now it’s here! I’m really pleased to announce that I’ve started a new podcast! It’s called Security Unscripted and the goal is to be short 10-12 minute episodes weekly about a variety of security topics. Bite-sized …

Holiday Hacking

December 30, 2024

Normally I do some coding over the holidays as it used to be the one time of the year I could have some dedicated time to work on personal projects, or just fiddle with random non-work things. Normally that would have been updates to the blog platform I had written to run this …

Using LetsEncrypt with Pi-hole

November 14, 2024

I’ve been running Pi-hole in a container on my TrueNAS Scale box for a while and had unfortunately experienced a number of upgrades that required deploying the container from scratch. This was due to incompatibilities in the Helm chart settings, which broke in-place …

ICCC 2024

November 12, 2024

Last week I had the opportunity to attend and speak at the International Common Criteria Conference (ICCC) in Doha, Qatar. This was a first in a number of areas: first time keynoting for longer than five minutes, first time attending a compliance-focused conference, first time …

SOSS Fusion 2024

October 31, 2024

Last week I had the opportunity to attend and speak at the OpenSSF SOSS Fusion 2024 event. This is the first full multi-day OpenSSF security event and it was a privilege to be able to attend and speak. I gave the same talk that I did at BSides back in September as I believe it …

BSides Edmonton 2024

September 28, 2024

Earlier this week I had the opportunity to attend and speak at the BSides Edmonton 2024 event. This is a local event that’s been running for a few years and oddly I’ve only been able to make it every second year, usually due to conflicts in my schedule. This year I …

Python module to read CSAF VEX files

August 9, 2024

Red Hat has been publishing VEX documents for some time now. VEX stands for Vulnerability Exploitability eXchange, and the documents are machine-readable JSON files that describe vulnerabilities and status for them. For example, one CVE could impact a number of different products …

Upstream 2024

June 5, 2024

Today I had the privilege of being involved in Tidelift’s Upstream 2024 virtual conference. The conference as a whole was fantastic, I watched every talk and there is some really great content there about open source security and how it’s being looked at and …

Red Hat Summit 2024

May 26, 2024

Last month I was in Denver for Red Hat Summit 2024. The keynotes are available on YouTube. This was perhaps the most energetic Summit that I’ve been to, even pre-COVID. There was a lot of activity and, of course, the primary topic was AI. We unveiled InstructLab and our …

Rethinking Risk in Vulnerability Management

February 6, 2024

I’ve had the opportunity to write a few blogs and articles on one of my favourite topics: vulnerability management. In particular, the thinking on risk in this space. What’s acceptable risk? What isn’t? You can get into the details on the variety of articles …

15 years at Red Hat

February 2, 2024

It’s been a fantastic 15 years at Red Hat as of today. Started as a Senior Software Engineer on a very small team focused on incident response for two products (RHEL and JBoss EAP) to end up leading a large organization focused on a significant number of products and …

OpenShift Commons Chicago 2023

November 27, 2023

I had the opportunity to speak at the recent OpenShift Commons in Chicago that was an event that coincided with Kubecon in Chicago a few weeks back. I spoke about the Evolution of risk management in software which is a more reent talk that I’ve given a few times; the first …

Red Hat Summit 2023

June 4, 2023

I had the opportunity to attend Red Hat Summit 2023 which you can watch on demand in Boston, MA. Unlike the OSS Summit, this was a 14h door-to-door trip, there and back, due to delays (typically 12h door-to-door). However the annoyance in travel was more than made up for by the …

OSS Summit 2023

May 13, 2023

I had the opportunity to attend the OSS Summit 2023 in Vancouver, BC. Probably the easiest conference I’ve ever attended, travel-wise, as it was about three hours door-to-door. Contrast that to Red Hat Summit in Boston, which is about 12 hours door-to-door. The conference …

SBOMs, CVEs, CVSS and more

April 7, 2023

There have been a few neat opportunities to write and discuss a variety of topics over the last few weeks that have been published. The most recent is a blog post I co-authored with Tracy Ragan at DeployHub entitled SBOMs, So Far, So Good, So What? where we take a look at the …

... And a pelican in a pear tree

December 22, 2022

For a number of years, since getting more and more into management, I’ve had less time to do any real programming. So a highlight of the year, for the first few years at least, was to take time during the Christmas break to do some work, mostly on this blog and for a few …

A new generation of tools for open source vulnerability management

December 18, 2022

I recently wrote for opensource.com on A new generation of tools for open source vulnerability management (the above image is credited to opensource.com). This is my first article written there and while the article itself tends to be vendor-agnostic, this truly is an article …

Interview: When is it secure enough?

December 5, 2022

I had the awesome opportunity to interview professor Daniel Gruss and one of his PhD students, Martin Schwarzl, a while back and the article recently was published in the Red Hat Research Quarterly magazine. For those who don’t know, Daniel was one of the folks behind the …

ZeroBytesGiven podcast appearance

November 22, 2022

I did an ad-hoc interview with Eddie Knight over at Sonatype during the Linux Foundation Member Summit, for his podcast ZeroBytesGiven. It was a lot of fun and got to talk about some supply chain concerns and even dig into little-known history of how we did security at Mandriva …

Risk-based vulnerability management

November 15, 2022

For much of this year I’ve been advocating for a risk-based vulnerability management approach, rather than the “industry standard” checkbox-based approach. I’ve been talking to customers, both directly and at various events (such as Red Hat Summit in …

Interview about CVSS

June 9, 2020

I was recently interviewed by my friend Jack Wallen (whom I’ve known for 20 years as he actually coerced me to start writing for TechRepublic ages ago!). It was about a topic near and dear to my heart: CVSS (or Common Vulnerability Scoring System). With the explosion of …

What Makes Red Hat Enterprise Linux So Secure (Video)

October 3, 2019

I had a great opportunity this summer to be interviewed by TelecomTV. It feels a little weird to post this here since I don’t typically “self-promote” in any way, however this was a neat experience and I think the points are good. If you’ve been looking …

Periodic security reviews (and a bit of a rant)

October 1, 2016

Today marks one month that my “work time” is 100% devoted to Red Hat; last month I “retired” from any of the IT/web work for my church that I’ve been doing for the last 12 or so years. It’s been an interesting month being able to spend time on …

Using FreeIPA for User Authentication

December 5, 2015

After many years of using Using OpenLDAP for User Authentication, and Using Kerberos 5 for Single Sign-On Authentication, it was time to look at FreeIPA as a way of streamlining everything. Important Note: You will want to have FreeIPA on it’s own system (whether this is a …

Getting started with firewalld

August 15, 2015

I’m mostly writing this for my own reference as I spent a bunch of time figuring this out while I was on holidays with some serious oVirt misadventures and didn’t document any of what I did, so since I had to reinstall CentOS 7, I’m stuck doing this all over …

Using Kerberos 5 for Single Sign-On Authentication

December 10, 2012

The purpose of this article is to detail the configuration of a Kerberos realm for single sign-on authentication. In particular, the document will cover installation and configuration on Red Hat Enterprise Linux 5.3, however it should be relevant enough for any recent Linux …

Two-factor SSH authentication via Google secures Linux logins

June 25, 2011

Last week’s TechMail was Two-factor SSH authentication via Google secures Linux logins which talks about using Google two-factor authentication with SSH (and PAM in general). I really like it and it works quite well although the comments in the TechMail indicate another …

Filesystem Security: AIDE

February 25, 2011

AIDE (Advanced Intrustion Detection Environment) is a GPL replacement for the commercial Tripwire tool and does pretty much the same thing. Both tools monitor the local filesystem for changes by building an initial database to which subsequent checks are compared. Both use a …

Filesystem Security: Access Control Lists

February 25, 2011

There are a number of Linux filesystems have support for Access Control Lists (ACLs) beyond just simple ownership and permissions restrictions to files. These file systems include XFS, ext2, ext3, ext4, and btrfs. This ACL support allows you to fine-tune permissions on your Linux …

Filesystem Security

February 25, 2011

There are a number of different filesystems available for the different *NIX-ish operating systems. Linux has perhaps the largest variety of filesystem types, including ext2, ext3, ReiserFS, XFS, JFS, and more. Other systems such as FreeBSD are a little more conservative in what …

Using OpenLDAP for User Authentication

October 31, 2010

NOTE: This is a revision of the previous LDAP authentication article on MandrakeSecure. A second revision is available on that site, but it is also more or less specific to Mandrakelinux whereas this topic will eventually cover as many different Linux and BSD implementations as …

Learn to use extended file attributes in Linux to boost security

December 16, 2009

This week’s TechMail is Learn to use extended file attributes in Linux to boost security which takes a look at using chattr, getfattr, setfattr, getfacl, and setfacl; tools that can be used to offer more granular security to files and directories. Being able to use SELinux …

rsec, msec, sectool.. hmmm... I smell opportunities

September 2, 2009

So I was approached by Eugeni, one of my former fellows at Mandriva, today about some collaboration in regards to Mandriva’s msec and my way-back-when fork for Annvix, rsec. He wrote a blog post about msec’s future and plans detailing the things he wants to do with …

Monitor your system for threats with rsec alerts

August 25, 2009

This week’s TechMail is Monitor your system for threats with rsec alerts which discusses the rsec tool I forked from Mandriva’s msec years ago (for Annvix). It’s been updated and is available for Red Hat Enterprise Linux 5 (and CentOS 5) as I think it’s …

Towards responsible disclosure

July 9, 2009

This week was interesting, dealing with the supposed “OpenSSH 0day” vulnerability stuff… rumours, innuendo, strange logs and packet capture files… it made for a long week trying to keep an eye on this and sort fact from fiction. Instead of focusing on …

Store passwords with pwsafe

May 7, 2009

This week’s techmail is Store passwords with pwsafe which looks at the pwsafe CLI application that can keep track of all your passwords and login credentials in a safe and secure manner (and throws in strong password generation as a bonus). Really useful app.

Use encrypted filesystems with Linux Logical Volume Manager

April 7, 2009

This week’s TechMail is Use encrypted filesystems with Linux Logical Volume Manager which discusses how to setup LVM with encryption right at install-time. I’m finding for myself that having information, particularly on laptops, encrypted is becoming increasingly …

Get started with the security tool OSSEC

February 4, 2009

This week’s TechMail is: Get started with the security tool OSSEC, a quick run-down of what OSSEC is and how to use it. It’s a pretty big “package”, so I couldn’t cover everything, just a single-server-use scenario which I think is what the majority …

Adam's rant on Linux security

January 20, 2009

Adam forwarded me a link to his latest blog post about Linux security. It’s quite amusing to read (I suspect someone must have told him how uber secure Linux is). Anyways, it’s completely true so for all the pundits who preach on how much more secure Linux is than …

Mandriva update statistics

December 17, 2008

Some statistics, before I go on holidays until the end of the year. Looking at bugfix updates, we’ve seen a steady increase since I’ve kept track (going back to 1999, although I think in 1999 it was only a half-year of doing updates). For security updates, it’s …

Get a complete security toolkit with BackTrack 3

August 12, 2008

This week’s techmail is Get a complete security toolkit with BackTrack 3. I was approached a month or so ago by an individual who does forensic work, mostly on Windows and Mac computers and he was in need of something to do forensics with Linux, and wanted a tool that could …

Security holes in other distros

June 17, 2008

Found another good comic inspired by the Debian OpenSSL issue (no, it will never get too old for me). Forget where I came across this one though… just saw it in my downloads folder as I was doing some cleaning up. It’s quite funny though, because it also pokes at …

Security, Open Source Style

June 2, 2008

The announcement just went out for the newly formed oss-security group (which is a similar concept to the private vendor-sec group, but open to anyone interested in helping promote and work with security in open source projects). I’ve mentioned oss-security before, but the …

Find and fix weak OpenSSL/OpenSSH keys: Debian-based Linux vulnerability

May 21, 2008

In light of the recent Debian debacle and to get the word out to more people, this week’s Techmail is Find and fix weak OpenSSL/OpenSSH keys: Debian-based Linux vulnerability which more or less reiterates what happened with the Debian OpenSSL… fun… and points …

The path of least-patching

May 17, 2008

It’s been an amusing morning reading more takes on the Debian OpenSSL issue. While I was in the know before most others due to vendor-sec, and was able to quickly verify this didn’t affect Mandriva, the fallout still continues. For those that think otherwise, this is …

Static User/Group Mappings

April 8, 2008

/start rant Switching my servers from Annvix to Mandriva is absolutely maddening. The biggest problem is dynamic uid/gid mappings. Do you know how frustrating it is to have apache uid 77 on one machine and uid 92 on another? Or svn is gid 75 on one and gid 76 on another? …

Configure Snort to log packets to MySQL

March 26, 2008

This week’s TechMail is Configure Snort to log packets to MySQL which looks at using MySQL to store snort logs and BASE to view them. Already there’s a comment there about someone wanting to know how to do it on Windows. I’m sure it’s possible, but my …

Using djbdns with Mandrakelinux

March 25, 2008

Like qmail, djbdns is open source but has a restrictive license which makes distributing it a trifle difficult for many vendors. However, it is distributable in binary form if you follow the license and the packager assures to the best of their ability that the binary package …

Using Courier-IMAP and SSL

March 25, 2008

Courier-IMAP comes with some bundled scripts to create self-signed certificates. Depending on what operating system you installed Courier-IMAP on, and whether you compiled it yourself or if you installed a pre-compiled RPM package, the location for these scripts may be different. …

Using Apache and SSL for Security and Authentication (incomplete)

March 25, 2008

Apache is probably the most widely used web server currently available. It can be used on any form of UNIX and derivatives (Linux, *BSD, etc.) as well as other operating systems such as Windows and OS/2. It is freely available and open source, scalable, extremely configurable, …

Enabling SASL in Postfix

March 25, 2008

NOTE: This is a revision of the previous “Enabling SASL in Postfix” article on MandrakeSecure. SASL, short for Simple Authentication and Security Layer is a method for adding authentication support to connection-based protocols. In order for SASL to be used, a …

Secure IRC: Authentication and Encryption

March 25, 2008

IRC (Internet Relay Chat) is an awesome means of real-time chat between individuals who share a common interest. There are many IRC servers on the internet; lots of places to find people to talk to. IRC clients exist for every operating system out there; IRC is universal. …

Using GnuPG

March 25, 2008

NOTE: This section was originally written by Vincent Danen as a piece for the MandrakeSecure website. GnuPG, the GNU Privacy Guard, is the open source equivalent to PGP, or Pretty Good Privacy, which has been available for Windows, DOS, and some other operating systems for many …

Personal Privacy and Encryption

March 25, 2008

Your data is your data. What belongs to you should stay with you, until you choose to give it away. Your personal data shouldn’t be subject to theft. It’s for this reason that banks use SSL on their websites; to protect your data in transit. Obviously, banking online …

Encrypted DMG Files in OS X

March 25, 2008

Making an encrypted DMG file (a mountable filesystem that most software for the Mac is distributed with) is extremely simple. The ability to mount these filesystems comes with the OS, using the Disk Copy application. There are many ways of creating an encrypted DMG file in OS X; …

DansGuardian: A Content Filtering System

March 25, 2008

One feature many firewall appliances have been pushing recently is content filtering proxies, whether transparent or authenticated. These content filtering proxies are a boon to individuals with young children in the house, but many of them are extremely basic. Without pointing …

Creating and Maintaining Your Own Certification Authority (incomplete)

March 25, 2008

Face it. Do you really want to spend $200USD to secure POP3 access for a year that only you and your family uses? Probably not. Yet, if you want to secure POP3 access, you need to create a SSL certificate, and these things need to be signed by someone. You can easily generate a …

Preventing Trojan Downloads

March 25, 2008

With a lot of freely available and open source applications, you have a great amount of flexibility and control over what is installed on your computer. For instance, if you had the time, you could audit every single piece of open source software you install on your computer. …

Security with PHP

March 25, 2008

PHP is a server-side scripting language that is extremely versatile, powerful, and in use by many systems. It’s popularity has increased to the point that any web-hosting service worth it’s salt provides the capabilities to use it. That being said, PHP can also be …

Using Sudo to Limit Access

March 25, 2008

One of my favorite security tools is sudo. This isn’t a tool to help you monitor security, but it is a tool to allow you to secure your system a little further, especially if you run a box that needs to at times allow other users some extra (root) privilege. Let’s …

The OS X Keychain

March 25, 2008

Mac OS X comes with a very nice, integrated tool that manages passwords for you. This tool is called Keychain, and anyone who has used OS X, has used Keychain. This is a unique means of storing password information, be it website access or passwords to local programs. Keychain …

Password Protected Booting

March 25, 2008

Locking the system down is important, but a lot of security can be circumvented by an attacker having physical access to your computer. The easiest thing for an attacker to do is push the reset or power button on your computer, pop in their own floppy or CD-ROM, and boot from it. …

Optimizing OpenSSH

March 25, 2008

NOTE: This section was originally written by Vincent Danen as a piece for the MandrakeSecure website (“Making the Most of OpenSSH”). OpenSSH is a secure replacement for deprecated protocols such as telnet and rsh. It has become a De-facto standard as a remote login …

Implementing a Samba LDAP Primary Domain Controller Setup

March 25, 2008

Copyright © 2003 Jim Colling Originally written for the MandrakeSecure website. The example server box is i686 Mandrake 9.0 with all the updates I can get my hands on. To cut down on network traffic and to ease security, it houses both the OpenLDAP server and Samba. It has also …

User Management

March 25, 2008

The management of users on a system can be… interesting, depending on a number of different factors. For some systems, like a home system with one or two users, it’s pretty straightforward. When you start moving into larger networks, or servers with hundreds of …

User Auditing

March 25, 2008

Auditing user accounts is just as important as auditing other parts of your system. In fact, in large multi-user environments, it can be one of the most critical aspects of monitoring your system to prevent attack. For instance, if a user were to leave the company and the account …

Using swatch to Monitor Logfiles

March 25, 2008

A very useful tool for monitoring logfiles is Swatch (aka Simple WATCHer of Logfiles). This is a perl program that essentially watches a logfile. You can run as many instances of it as you want, but you can only watch one logfile per instance. Depending on the log file you want …

Syslog and Klog

March 25, 2008

Most UNIX implementations (Linux, BSD, etc.) use a program called syslogd to handle most of the logging. syslogd is a system logging daemon and what it does is sit and receive messages from various applications. It will receive log messages from other daemons, programs, and even …

Logfile Auditing

March 25, 2008

Logfiles are perhaps one of the most useful facilities available to any sysadmin or user to determine what is going on in the system. They can be used to track down error messages, authentication information (who logged in and when, etc), and a whole slew of other information …

Detect intruders on your network with Snort

March 23, 2008

This past week’s TechMail tip is Detect intruders on your network with Snort which is a quick primer on how to use the Snort IDS (Intrusion Detection System). Snort is pretty cool if you have the patience to deal with it and the time to invest in setting it up properly. The …

Secure temporary files in Linux

March 1, 2008

This week’s TechMail is Secure temporary files in Linux which discusses how to properly secure temporary files, using things like loopback filesystems, separate partitions for /tmp and using appropriate mount flags. It’s pretty simplistic stuff, but can make a huge …

Common Security Mistakes

February 26, 2007

There are a few common mistakes, or bad assumptions, made with regards to security. Here we identify these common mistakes and what can be done to avoid them. This is the very basic premise of security; avoiding these will avoid a large number of problems that may occur. Weak …

Creating and Maintaining a Security Policy

February 26, 2007

Perhaps one of the biggest issues facing companies is the lack of a security policy. This isn’t as much of a problem with home users, but some of the same principles apply. A home user may not need to review their security policy every few months to ensure it still suits …