Security
May 29, 2025
Back in April I attended VulnCon, the second year this conference has been held by FIRST and the CVE program. This was a great conference for incident responders working on developing software. There were a ton of great talks, many of which I was unable to attend so I’m …
February 15, 2025
Been working on this for a bit and now it’s here! I’m really pleased to announce that I’ve started a new podcast! It’s called Security Unscripted and the goal is to be short 10-12 minute episodes weekly about a variety of security topics. Bite-sized …
December 30, 2024
Normally I do some coding over the holidays as it used to be the one time of the year I could have some dedicated time to work on personal projects, or just fiddle with random non-work things. Normally that would have been updates to the blog platform I had written to run this …
November 14, 2024
I’ve been running Pi-hole in a container on my TrueNAS Scale box for a while and had unfortunately experienced a number of upgrades that required deploying the container from scratch. This was due to incompatibilities in the Helm chart settings, which broke in-place …
November 12, 2024
Last week I had the opportunity to attend and speak at the International Common Criteria Conference (ICCC) in Doha, Qatar. This was a first in a number of areas: first time keynoting for longer than five minutes, first time attending a compliance-focused conference, first time …
October 31, 2024
Last week I had the opportunity to attend and speak at the OpenSSF SOSS Fusion 2024 event. This is the first full multi-day OpenSSF security event and it was a privilege to be able to attend and speak. I gave the same talk that I did at BSides back in September as I believe it …
September 28, 2024
Earlier this week I had the opportunity to attend and speak at the BSides Edmonton 2024 event. This is a local event that’s been running for a few years and oddly I’ve only been able to make it every second year, usually due to conflicts in my schedule. This year I …
August 9, 2024
Red Hat has been publishing VEX documents for some time now. VEX stands for Vulnerability Exploitability eXchange, and the documents are machine-readable JSON files that describe vulnerabilities and status for them. For example, one CVE could impact a number of different products …
June 5, 2024
Today I had the privilege of being involved in Tidelift’s Upstream 2024 virtual conference. The conference as a whole was fantastic, I watched every talk and there is some really great content there about open source security and how it’s being looked at and …
May 26, 2024
Last month I was in Denver for Red Hat Summit 2024. The keynotes are available on YouTube. This was perhaps the most energetic Summit that I’ve been to, even pre-COVID. There was a lot of activity and, of course, the primary topic was AI. We unveiled InstructLab and our …
February 6, 2024
I’ve had the opportunity to write a few blogs and articles on one of my favourite topics: vulnerability management. In particular, the thinking on risk in this space. What’s acceptable risk? What isn’t?
You can get into the details on the variety of articles …
February 2, 2024
It’s been a fantastic 15 years at Red Hat as of today. Started as a Senior Software Engineer on a very small team focused on incident response for two products (RHEL and JBoss EAP) to end up leading a large organization focused on a significant number of products and …
November 27, 2023
I had the opportunity to speak at the recent OpenShift Commons in Chicago that was an event that coincided with Kubecon in Chicago a few weeks back. I spoke about the Evolution of risk management in software which is a more reent talk that I’ve given a few times; the first …
June 4, 2023
I had the opportunity to attend Red Hat Summit 2023 which you can watch on demand in Boston, MA. Unlike the OSS Summit, this was a 14h door-to-door trip, there and back, due to delays (typically 12h door-to-door). However the annoyance in travel was more than made up for by the …
May 13, 2023
I had the opportunity to attend the OSS Summit 2023 in Vancouver, BC. Probably the easiest conference I’ve ever attended, travel-wise, as it was about three hours door-to-door. Contrast that to Red Hat Summit in Boston, which is about 12 hours door-to-door.
The conference …
April 7, 2023
There have been a few neat opportunities to write and discuss a variety of topics over the last few weeks that have been published. The most recent is a blog post I co-authored with Tracy Ragan at DeployHub entitled SBOMs, So Far, So Good, So What? where we take a look at the …
December 22, 2022
For a number of years, since getting more and more into management, I’ve had less time to do any real programming. So a highlight of the year, for the first few years at least, was to take time during the Christmas break to do some work, mostly on this blog and for a few …
December 18, 2022
I recently wrote for opensource.com on A new generation of tools for open source vulnerability management (the above image is credited to opensource.com).
This is my first article written there and while the article itself tends to be vendor-agnostic, this truly is an article …
December 5, 2022
I had the awesome opportunity to interview professor Daniel Gruss and one of his PhD students, Martin Schwarzl, a while back and the article recently was published in the Red Hat Research Quarterly magazine. For those who don’t know, Daniel was one of the folks behind the …
November 22, 2022
I did an ad-hoc interview with Eddie Knight over at Sonatype during the Linux Foundation Member Summit, for his podcast ZeroBytesGiven. It was a lot of fun and got to talk about some supply chain concerns and even dig into little-known history of how we did security at Mandriva …
November 15, 2022
For much of this year I’ve been advocating for a risk-based vulnerability management approach, rather than the “industry standard” checkbox-based approach. I’ve been talking to customers, both directly and at various events (such as Red Hat Summit in …
February 18, 2022
Recently I had the opportunity to join a few other Red Hatters to talk about software supply chains with SiliconAngle. They did a writeup “Controlling software supply chain security will require new tools, automation and vigilance” that was great and included the …
February 1, 2022
Published on the Red Hat blog, noting here that Curated, tested and supported: How enterprise vendors mitigate open source supply chain risk was posted yesterday. It’s an article that talks about supply chain risk and associated costs – after all, no software is …
June 9, 2020
I was recently interviewed by my friend Jack Wallen (whom I’ve known for 20 years as he actually coerced me to start writing for TechRepublic ages ago!). It was about a topic near and dear to my heart: CVSS (or Common Vulnerability Scoring System). With the explosion of …
October 3, 2019
I had a great opportunity this summer to be interviewed by TelecomTV. It feels a little weird to post this here since I don’t typically “self-promote” in any way, however this was a neat experience and I think the points are good. If you’ve been looking …
October 24, 2016
This year we celebrated 15 years of Red Hat Product Security. I’ve not been with Red Hat that long, but I’ve been doing product security work for longer (slightly over a year longer). I was asked to write a little something to stroll down memory lane with the …
October 1, 2016
Today marks one month that my “work time” is 100% devoted to Red Hat; last month I “retired” from any of the IT/web work for my church that I’ve been doing for the last 12 or so years. It’s been an interesting month being able to spend time on …
December 5, 2015
After many years of using Using OpenLDAP for User Authentication, and Using Kerberos 5 for Single Sign-On Authentication, it was time to look at FreeIPA as a way of streamlining everything.
Important Note: You will want to have FreeIPA on it’s own system (whether this is a …
August 15, 2015
I’m mostly writing this for my own reference as I spent a bunch of time figuring this out while I was on holidays with some serious oVirt misadventures and didn’t document any of what I did, so since I had to reinstall CentOS 7, I’m stuck doing this all over …
December 10, 2012
The purpose of this article is to detail the configuration of a Kerberos realm for single sign-on authentication. In particular, the document will cover installation and configuration on Red Hat Enterprise Linux 5.3, however it should be relevant enough for any recent Linux …
June 25, 2011
Last week’s TechMail was Two-factor SSH authentication via Google secures Linux logins which talks about using Google two-factor authentication with SSH (and PAM in general). I really like it and it works quite well although the comments in the TechMail indicate another …
February 25, 2011
AIDE (Advanced Intrustion Detection Environment) is a GPL replacement for the commercial Tripwire tool and does pretty much the same thing. Both tools monitor the local filesystem for changes by building an initial database to which subsequent checks are compared. Both use a …
February 25, 2011
There are a number of Linux filesystems have support for Access Control Lists (ACLs) beyond just simple ownership and permissions restrictions to files. These file systems include XFS, ext2, ext3, ext4, and btrfs. This ACL support allows you to fine-tune permissions on your Linux …
February 25, 2011
There are a number of different filesystems available for the different *NIX-ish operating systems. Linux has perhaps the largest variety of filesystem types, including ext2, ext3, ReiserFS, XFS, JFS, and more. Other systems such as FreeBSD are a little more conservative in what …
October 31, 2010
NOTE: This is a revision of the previous LDAP authentication article on MandrakeSecure. A second revision is available on that site, but it is also more or less specific to Mandrakelinux whereas this topic will eventually cover as many different Linux and BSD implementations as …
December 16, 2009
This week’s TechMail is Learn to use extended file attributes in Linux to boost security which takes a look at using chattr, getfattr, setfattr, getfacl, and setfacl; tools that can be used to offer more granular security to files and directories. Being able to use SELinux …
September 2, 2009
So I was approached by Eugeni, one of my former fellows at Mandriva, today about some collaboration in regards to Mandriva’s msec and my way-back-when fork for Annvix, rsec. He wrote a blog post about msec’s future and plans detailing the things he wants to do with …
August 25, 2009
This week’s TechMail is Monitor your system for threats with rsec alerts which discusses the rsec tool I forked from Mandriva’s msec years ago (for Annvix). It’s been updated and is available for Red Hat Enterprise Linux 5 (and CentOS 5) as I think it’s …
July 9, 2009
This week was interesting, dealing with the supposed “OpenSSH 0day” vulnerability stuff… rumours, innuendo, strange logs and packet capture files… it made for a long week trying to keep an eye on this and sort fact from fiction. Instead of focusing on …
May 7, 2009
This week’s techmail is Store passwords with pwsafe which looks at the pwsafe CLI application that can keep track of all your passwords and login credentials in a safe and secure manner (and throws in strong password generation as a bonus). Really useful app.
April 7, 2009
This week’s TechMail is Use encrypted filesystems with Linux Logical Volume Manager which discusses how to setup LVM with encryption right at install-time. I’m finding for myself that having information, particularly on laptops, encrypted is becoming increasingly …
February 4, 2009
This week’s TechMail is: Get started with the security tool OSSEC, a quick run-down of what OSSEC is and how to use it. It’s a pretty big “package”, so I couldn’t cover everything, just a single-server-use scenario which I think is what the majority …
January 20, 2009
Adam forwarded me a link to his latest blog post about Linux security. It’s quite amusing to read (I suspect someone must have told him how uber secure Linux is). Anyways, it’s completely true so for all the pundits who preach on how much more secure Linux is than …
December 17, 2008
Some statistics, before I go on holidays until the end of the year.
Looking at bugfix updates, we’ve seen a steady increase since I’ve kept track (going back to 1999, although I think in 1999 it was only a half-year of doing updates).
For security updates, it’s …
August 12, 2008
This week’s techmail is Get a complete security toolkit with BackTrack 3. I was approached a month or so ago by an individual who does forensic work, mostly on Windows and Mac computers and he was in need of something to do forensics with Linux, and wanted a tool that could …
June 17, 2008
Found another good comic inspired by the Debian OpenSSL issue (no, it will never get too old for me). Forget where I came across this one though… just saw it in my downloads folder as I was doing some cleaning up. It’s quite funny though, because it also pokes at …
June 2, 2008
The announcement just went out for the newly formed oss-security group (which is a similar concept to the private vendor-sec group, but open to anyone interested in helping promote and work with security in open source projects). I’ve mentioned oss-security before, but the …
May 21, 2008
In light of the recent Debian debacle and to get the word out to more people, this week’s Techmail is Find and fix weak OpenSSL/OpenSSH keys: Debian-based Linux vulnerability which more or less reiterates what happened with the Debian OpenSSL… fun… and points …
May 17, 2008
It’s been an amusing morning reading more takes on the Debian OpenSSL issue. While I was in the know before most others due to vendor-sec, and was able to quickly verify this didn’t affect Mandriva, the fallout still continues. For those that think otherwise, this is …
April 8, 2008
/start rant
Switching my servers from Annvix to Mandriva is absolutely maddening. The biggest problem is dynamic uid/gid mappings. Do you know how frustrating it is to have apache uid 77 on one machine and uid 92 on another? Or svn is gid 75 on one and gid 76 on another? …
March 28, 2008
Copyright © 2003 Buchan Milne
Originally written for the MandrakeSecure website.
In what is now becoming a series on LDAP, previous articles have already covered basic LDAP setup and UNIX authentication, and the basics of building a samba PDC backended on OpenLDAP. However, many …
March 26, 2008
This week’s TechMail is Configure Snort to log packets to MySQL which looks at using MySQL to store snort logs and BASE to view them. Already there’s a comment there about someone wanting to know how to do it on Windows. I’m sure it’s possible, but my …
March 25, 2008
Like qmail, djbdns is open source but has a restrictive license which makes distributing it a trifle difficult for many vendors. However, it is distributable in binary form if you follow the license and the packager assures to the best of their ability that the binary package …
March 25, 2008
Courier-IMAP comes with some bundled scripts to create self-signed certificates. Depending on what operating system you installed Courier-IMAP on, and whether you compiled it yourself or if you installed a pre-compiled RPM package, the location for these scripts may be different. …
March 25, 2008
Apache is probably the most widely used web server currently available. It can be used on any form of UNIX and derivatives (Linux, *BSD, etc.) as well as other operating systems such as Windows and OS/2. It is freely available and open source, scalable, extremely configurable, …
March 25, 2008
NOTE: This is a revision of the previous “Enabling SASL in Postfix” article on MandrakeSecure.
SASL, short for Simple Authentication and Security Layer is a method for adding authentication support to connection-based protocols. In order for SASL to be used, a …
March 25, 2008
IRC (Internet Relay Chat) is an awesome means of real-time chat between individuals who share a common interest. There are many IRC servers on the internet; lots of places to find people to talk to. IRC clients exist for every operating system out there; IRC is universal. …
March 25, 2008
NOTE: This section was originally written by Vincent Danen as a piece for the MandrakeSecure website.
GnuPG, the GNU Privacy Guard, is the open source equivalent to PGP, or Pretty Good Privacy, which has been available for Windows, DOS, and some other operating systems for many …
March 25, 2008
Your data is your data. What belongs to you should stay with you, until you choose to give it away. Your personal data shouldn’t be subject to theft. It’s for this reason that banks use SSL on their websites; to protect your data in transit. Obviously, banking online …
March 25, 2008
Making an encrypted DMG file (a mountable filesystem that most software for the Mac is distributed with) is extremely simple. The ability to mount these filesystems comes with the OS, using the Disk Copy application. There are many ways of creating an encrypted DMG file in OS X; …
March 25, 2008
One feature many firewall appliances have been pushing recently is content filtering proxies, whether transparent or authenticated. These content filtering proxies are a boon to individuals with young children in the house, but many of them are extremely basic. Without pointing …
March 25, 2008
Face it. Do you really want to spend $200USD to secure POP3 access for a year that only you and your family uses? Probably not. Yet, if you want to secure POP3 access, you need to create a SSL certificate, and these things need to be signed by someone. You can easily generate a …
March 25, 2008
With a lot of freely available and open source applications, you have a great amount of flexibility and control over what is installed on your computer. For instance, if you had the time, you could audit every single piece of open source software you install on your computer. …
March 25, 2008
PHP is a server-side scripting language that is extremely versatile, powerful, and in use by many systems. It’s popularity has increased to the point that any web-hosting service worth it’s salt provides the capabilities to use it. That being said, PHP can also be …
March 25, 2008
One of my favorite security tools is sudo. This isn’t a tool to help you monitor security, but it is a tool to allow you to secure your system a little further, especially if you run a box that needs to at times allow other users some extra (root) privilege.
Let’s …
March 25, 2008
Mac OS X comes with a very nice, integrated tool that manages passwords for you. This tool is called Keychain, and anyone who has used OS X, has used Keychain. This is a unique means of storing password information, be it website access or passwords to local programs. Keychain …
March 25, 2008
Locking the system down is important, but a lot of security can be circumvented by an attacker having physical access to your computer. The easiest thing for an attacker to do is push the reset or power button on your computer, pop in their own floppy or CD-ROM, and boot from it. …
March 25, 2008
NOTE: This section was originally written by Vincent Danen as a piece for the MandrakeSecure website (“Making the Most of OpenSSH”).
OpenSSH is a secure replacement for deprecated protocols such as telnet and rsh. It has become a De-facto standard as a remote login …
March 25, 2008
Copyright © 2003 Jim Colling
Originally written for the MandrakeSecure website.
The example server box is i686 Mandrake 9.0 with all the updates I can get my hands on. To cut down on network traffic and to ease security, it houses both the OpenLDAP server and Samba. It has also …
March 25, 2008
The management of users on a system can be… interesting, depending on a number of different factors. For some systems, like a home system with one or two users, it’s pretty straightforward. When you start moving into larger networks, or servers with hundreds of …
March 25, 2008
Auditing user accounts is just as important as auditing other parts of your system. In fact, in large multi-user environments, it can be one of the most critical aspects of monitoring your system to prevent attack. For instance, if a user were to leave the company and the account …
March 25, 2008
A very useful tool for monitoring logfiles is Swatch (aka Simple WATCHer of Logfiles). This is a perl program that essentially watches a logfile. You can run as many instances of it as you want, but you can only watch one logfile per instance.
Depending on the log file you want …
March 25, 2008
Most UNIX implementations (Linux, BSD, etc.) use a program called syslogd to handle most of the logging. syslogd is a system logging daemon and what it does is sit and receive messages from various applications. It will receive log messages from other daemons, programs, and even …
March 25, 2008
Logfiles are perhaps one of the most useful facilities available to any sysadmin or user to determine what is going on in the system. They can be used to track down error messages, authentication information (who logged in and when, etc), and a whole slew of other information …
March 23, 2008
This past week’s TechMail tip is Detect intruders on your network with Snort which is a quick primer on how to use the Snort IDS (Intrusion Detection System). Snort is pretty cool if you have the patience to deal with it and the time to invest in setting it up properly. The …
March 1, 2008
This week’s TechMail is Secure temporary files in Linux which discusses how to properly secure temporary files, using things like loopback filesystems, separate partitions for /tmp and using appropriate mount flags. It’s pretty simplistic stuff, but can make a huge …
February 26, 2007
There are a few common mistakes, or bad assumptions, made with regards to security. Here we identify these common mistakes and what can be done to avoid them. This is the very basic premise of security; avoiding these will avoid a large number of problems that may occur.
Weak …
February 26, 2007
Perhaps one of the biggest issues facing companies is the lack of a security policy. This isn’t as much of a problem with home users, but some of the same principles apply. A home user may not need to review their security policy every few months to ensure it still suits …