Linux Foundation, Linux.com Sites Down To Fix Security Breach
An anonymous reader writes "All Linux Foundation sites seem to be down due to a security breach, which occured on 8 sep. (according to a notice displayed on the site)." From the email I received this morning, sent to all Linux.com and LinuxFoundation.org users: "On September 8, 2011, we discovered a security breach that may have compromised your username, password, email address and other information you have given to us. We believe this breach was connected to the intrusion on kernel.org. As with any intrusion and as a matter of caution, you should consider the passwords and SSH keys that you have used on these sites compromised. ... We have taken all Linux Foundation servers offline to do complete re-installs. Linux Foundation services will be put back up as they become available. We are working around the clock to expedite this process and are working with authorities in the United States and in Europe to assist with the investigation."
Uh...isn't the point of using public keys that you do not have to keep them secret to remain secure? If people uploaded their public keys to the compromised systems...how is that a problem?
Palm trees and 8
Gentlemen, start your engines.
A few more details of the breach, including the content of the message from the Linux Foundation, can be found on ITWorld.
LinuxScribe
The attack that compromised some high-value servers belonging to kernel.org — but not the Linux kernel source code — may have been the work of hackers who simply got lucky and didn't realize the value of the servers that they had gotten their hands on.
Sure.
First Kernel.org and now this? Has someone got it in for FLOSS at the moment?
CheShA: Manchester Breakcore / Drill and Bass Yes I'm a s
FOSS FTL!
I am not sure what is gained by breaking into, compromising and exploiting a foundation like The Linux Foundation when the perps were more than likely using a Linux driven OS and tools to do what they did. Seems like some need a re-education in not harming the hand that builds your house...
Mod -1 Troll
Seriously?
Mod -1 Troll
Learn to use the '. Oh no - you're right. You are Ill.
Do you ever post anything other than instructions on how to mod other posts?
Having said that, reasonable people may conclude that the occasional security breach is an acceptable price to pay to avoid dealing with Theo. :-)
Not like when a CA gets its webserver compromised, has a quick self audit and then declares everything is OK, really, honest....
Assume everything is compromised unless you can prove otherwise and get the staff in on overtime to reinstall from scratch.
ahahahaha. And dozens more where that came from.
http://www.exploit-db.com/platform/?p=linux
I wonder what would happen if slashdot ran a front page story for every single linux security bug like they do for windows.
For years I've been told by /. trolls that Linux can't be hacked, only Windoze.
mod post insightful +1
Should I be concerned?
I hate how the software log viewer doesn't show any information other than the package names. A history with the release notes for each update would be MUCH more useful.
Really people? No one criticizes the Linux Foundation for leaking who knows what to hackers, but if it happened on a Windows site or machine, suddenly, that's just laughable. As if they 'deserved' it for running a Windows server.
Hypocrisy at its finest.
Breaches: Linux 1, Windows 2317
Still some margin...
Slashdot, fix the reply notifications... You won't get away with it...
Thats unpossible.
How could an attacker getting hold of the public key "compromise" anything? It doesn't contain any personal information, and -- barring an earth-shattering breakthrough in cryptanalysis of RSA (or DSA, if you chose a DSA key pair) -- it can't be used to gain access to anything, not even the system it was stolen from.
That's the whole point of using asymmetric cryptography for authentication!
Note to ACs: I usually delete AC replies without reading them. If you want to talk to me, log in.
I hope they are using all new hardware too! Hardware rootkits, though unlikely, are too great a risk for something so critical.
Linux 1? Have you heard about bug reports, patches, updates and that stuff on Linux?
You don't get it. The difference is Microsoft is a giant multi-billion dollar corporate machine with an insane marketting and advertising arm that helps them get into places that Linux simply can't because of lack of finances. If a well-funded corporation slips up its schadenfreude because 'even with all that' they still couldn't get it right. While Linux enjoys SOME corporate backing, its still largely a labour of love by independant developers. Most people side with the little guy. ;-)
Just some speculation, but I haven't seen anyone talking about the elephant in the room: Just who would stand to profit from manufacturing FUD surrounding Linux as a result of security breaches? A large software company comes to mind, one that happens to have a very outspoken hatred of free software.
No OS is secure. Take precautions. Having random members of the public from around the world with abilities to get shell access on your systems makes it hard.
I run: Windows, OS X, Linux, FreeBSD. Just because you have a hammer, doesn't mean everything is a nail.
I haven't seen anyone talking about the elephant in the room: Just who would stand to profit from manufacturing FUD surrounding Linux as a result of security breaches?
Alfred Pennyworth: A long time ago, I was in Burma...working for the local government. ... One day I saw a child playing with a ruby the size of a tangerine. The bandit had been throwing them away.
Bruce Wayne: Then why steal them?
Alfred Pennyworth: Because he thought it was good sport. Because some men aren't looking for anything logical, like money. They can't be bought, bullied, reasoned or negotiated with. Some men just want to watch the world burn.
...is a bit fucking obvious.
Some of these open source people should really put some work in to the security side of this linux thing.
Same here! It's not worth the risk of using software that has opened its source so that every hacker out there can find it vulnerabilities. How do we know that Linux can be trusted? It's developed by a foreigner who could be a socialist like Wiki Leaks. We don't trust Catholics and their foreign masters so why do we trust Linux?
"you should consider the passwords and SSH keys that you have used on these sites compromised."
How the heck can ssh keys compromised by this breakin? Doesn't the site just have access to the developer's public key? With a sufficiently large ssh key (say 1k or 2k) how is anyone going to derive the ssh private key from the public key? The fact that if is effectively impossible is supposed to be the whole point of public key encryption.
Breaches: Linux 1, Windows 2317
That's the problem. Complacency? Ignorance? Denial? Or just another bash on Windows?
That's the problem. Complacency? Ignorance? Denial? Or just another bash on Windows?
Bash on Linux, actually.
Slashdot, fix the reply notifications... You won't get away with it...
I'm new to Linux, and have become quite worried with Linux security.
Looking at your post, I went to the links you provided.
http://secunia.com/advisories/product/6436/?task=statistics_2011
Scrolling down reveals this:
"PLEASE NOTE: The statistics provided should NOT be used to compare the overall security of products against one another. It is IMPORTANT to understand what the below comments mean when using the statistics, especially when using the statistics to compare the vulnerability aspects of different products."
If you continue reading it goes goes into further detail.
Then I look at these pages
http://secunia.com/advisories/product/27467/
http://secunia.com/advisories/product/2719/?task=advisories
This supports your comment.
Can you explain this?
The question is did they have one?
Now Linux system administrators are being asked to put their money where their mouth is, as to say.
Personally, I wouldn't trust GIT or the developers. For example:
1. How many times have developers overwritten their work because of a severe mistake?
2. Can GIT seriously backtrack to a date prior to the supposed date the hack took place?
3. Are the developers and system administrators going to invest the time to check all the changes for all the kernels for at least 90 days?
Maybe you all trust Linux kernel source now. But I sure as hell don't.
I'm going back to an unpatched Slackware and old ass Ubuntu.
1.) Can you explain why Linux has more unpatched security vulnerabilities in its KERNEL ALONE (minus all the rest of what goes into a Linux distro mind you) than does nearly ALL of what Microsoft gives folks to do business & development with (by 4x as many unpatched security vulnerabilities, which would be MORE if all of a Linux distro was shown, not just the kernel's problems there alone)?
2.) Why does the LAMP stack show that it's being abused in said security vulnerabilities from a valid report, than does Windows Server 2008, IIS7, SQLServer 2008, & Visual Studio 2010??
* "Argue with the numbers..."
APK
P.S.=> Why is that (on both accounts above)??? Even despite all those "Open SORES eyes" allegedly poring over LAMP's code no less (Most of whom couldn't code to SAVE THEIR OWN LIVES)???? apk
http://linux.slashdot.org/story/11/08/31/2321232/Kernelorg-Compromised
You should be worried. Look at that.
OMG OMG so Linux is not secure? Oooppps!
In London horse bureaus betting already started that the Linux.com perpetrator is the iranian IchSunX2 aka. the "1000 talent" hacker of Comodo fame, it now stands at 1:2.5. It is of regret to note that bets quickly fell to 1:7 regarding his longevity beyond the end of 2011, after he openly threatened Israel in the latest Pastebin rant on Friday.
(You can bet money on everything in London, not just horse races, but the number of Raspberrys which Emmerich will win next time or the number of days the newly appointed japanese PM spends in office before stepping down, etc.)
linux is mainstream
Android (a Linux variant) shows Linux's "True Colors": It's less secure than Windows is. The "security-by-obscurity" (lack of users vs. those using Windows) advantage that Linux has enjoyed faded as an excuse to say "Linux is more secure than Windows is" with the advent of Android's malware explosion as well. No, the lines of pure bullshit you see from the "FUD" spreaders in the "Pro-Penguin camp" have been shown to all what they are: Bullshit artists. Wait until (IF ever) Linux gets more market-share - watch it become "Shredded Wheat" even more than Android's showing it to be, because then? Then, it will become attractive to malware-makers & such (but then again, I've been hearing "this is the year of Linux" for what? Nearly 20 yrs. now?? Funny, that year never comes eh??? Might as well say "The 12th of never when the clock strikes 13").