12 Sep 2011
The Linux community has been hit by more security woes after a breach forced the temporary closure of the web sites of the Linux Foundation and others.
At the time of writing, LinuxFoundation.org, Linux.com and all sub domains were offline and replaced with a message informing visitors that a security breach occurred on 8 September, most likely as a result of an intrusion on Kernel.org at the end of August.
"We are in the process of restoring services in a secure manner as quickly as possible. As with any intrusion and as a matter of caution, you should consider the passwords and SSH keys that you have used on these sites compromised," the message continued.
"If you have reused these passwords on other sites, please change them immediately. We are currently auditing all systems and will update this statement when we have more information."
The Kernel.org site was also down at the time of writing and replaced with a message indicating that it too is undergoing "maintenance".
The Linux Foundation was at pains to point out that the breach did not affect the Linux kernel or its code repositories.
Paul Ducklin, head of technology at Sophos Asia Pacific, argued that the incident might actually act in a positive way for Linux by persuading its more die hard proponents that "insecurity isn't just about Microsoft".
"Whilst Linux malware is not new, this is probably the closest it has ever come to the heart of their beloved operating system," he said in a blog post.
"In a perversely back-handed sort of way, perhaps this incident is just what Linux needs to raise its profile outside the world of cloud service providers."
Latest stories from Security
Related videos
Related articles
Related jobs
Poll
Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?
Orange and Intel talk us through the ins and outs of their San Diego smartphone
Connect with V3.co.uk
Social networking is almost ubiquitous. This white paper examines the benefits and risks and it looks at the different ways companies can reconcile them
The importance of understanding your infrastructure
Premier Consulting Firm - Procurement/P2P Transformation...
Premier consulting firm - IT Strategy and Cloud Consulting...
Software developer/ C# developer, (ASP.NET, C#, MVC...
Oracle Developer/ Programmer- Oracle ebusiness suite...
Keep up to date with the latest products, services and technologies from the world's leading IT companies. IThound.com brings you over 2,000 white papers, case studies and analyst reports.
Do you agree?
Everything is Vulnerable
EVERYTHING is vulnerable. There is no way that any given system is 100% invulnerable. The only remedy is to make yourself aware of the threats and learn to reduce your risk profile when using connecting devices of any kind through responsible use and diligent maintenance. Any network connection where you can't be certain who is on the other end entails risk that the person there may have nefarious objectives. It doesn't mean you have to hide in a hole and disconnect. It means you have to be aware of the risk and act appropriately and responsibly.
Posted by: RalphDaly28 15 Sep 2011
Vulnerable
Are we vulnerable on Android devices and any solid remedies?
Posted by: David Kinlay 13 Sep 2011