NEWS
Ubuntu Takes A U-Turn with 32-Bit Support
Canonical, maker of the popular Ubuntu Linux distribution, has revived support for 32-bit libraries after feedback from WINE, Ubuntu Studio, and Steam communities.
Last week Canonical announced that its engineering teams decided that Ubuntu should not continue to carry i386 forward as an architecture (https://ubuntu.com/blog/statement-on-32-bit-i386-packages-for-ubuntu-19-10-and-20-04-lts). "Consequently, i386 will not be included as an architecture for the 19.10 release, and we will shortly begin the process of disabling it for the eoan series across Ubuntu infrastructure," wrote Will Cooke, Director of Ubuntu Desktop at Canonical.
However, the news was not received well. Canonical was criticized for the move. Responding to the uproar, Canonical decided to continue to support 32-bit applications.
As Steve Langasek, a Debian and Ubuntu developer wrote in a mailing list, maintaining support for 32-bit libraries is "a cost largely paid by Canonical (both in terms of infrastructure and in terms of engineering work to keep the base system working). It's not very compelling to say that Canonical should continue bearing these costs out of pocket on the grounds that some other companies are unwilling to update their software to an ISA from this millennium :)"
OpenSSH Fixes Side Channel Attacks
There is a rise in memory side-channel vulnerabilities like RAMBleed, Spectre, and Meltdown. OpenSSH is often at the center of attacks where a bad actor "exploits memory read vulnerabilities to steal secret SSH private keys from the restricted memory regions of the system," according to The Hacker News.
The root cause of this issue is the fact that the OpenSSH agent stores a copy of the SSH keys in the memory (RAM of CPU), eliminating the need of entering a passphrase to log into the server via SSH. Since these keys are stored in either RAM or CPU in plaintext, they are susceptible to attacks.
The OpenSSH community is now fixing this issue through an update. OpenSSH will now encrypt private keys before storing them into the system memory.
"Attackers must recover the entire prekey with high accuracy before they can attempt to decrypt the shielded private key, but the current generation of attacks have bit error rates that, when applied cumulatively to the entire prekey, make this unlikely," said Damien Miller of the OpenBSD project on a mailing list (https://marc.info/?l=thn&m=156109087822676).
Firefox Fixes Error that Crashed HTTPS Pages
Mozilla has made changes to its Firefox browser that helps sysadmins fix TLS errors due to HTTPS (https://blog.mozilla.org/security/2019/07/01/fixing-antivirus-errors/). These errors are triggered by antivirus software that try to intercept secure connections over HTTPS.
The cause of the problem was the fact that Firefox trusts only those Certificate Authorities (CAs) that are listed in its own store, whereas antivirus software systems use their own CAs. "The antivirus products relying on other trusted CAs provided by the operating system (OS) are not allowed to intercept HTTPS connections on Firefox," said The Hacker News.
This conflict between Firefox and antivirus software led to users experiencing crashed HTTPS pages showing errors like "SEC_ERROR_UNKNOWN_ISSUER."
To fix the issue, Mozilla has created a mechanism to detect when a Firefox error is caused by a MITM. Users can enable the 'enterprise roots' preference that allows Firefox to import any root CAs that have been added to the OS by the user, an administrator, or a program that has been installed on the computer.
This option is available only on Windows and MacOS.
"It might cause some concern for Firefox to automatically trust CAs that haven't been audited and gone through the rigorous Mozilla process. However, any user or program that has the ability to add a CA to the OS almost certainly also has the ability to add that same CA directly to the Firefox root store," said Mozilla in a blog post.
« Previous 1 2 3 Next »
Buy this article as PDF
(incl. VAT)
Buy Linux Magazine
Subscribe to our Linux Newsletters
Find Linux and Open Source Jobs
Subscribe to our ADMIN Newsletters
Support Our Work
Linux Magazine content is made possible with support from readers like you. Please consider contributing when you’ve found an article to be beneficial.
News
-
The Gnome Foundation Struggling to Stay Afloat
The foundation behind the Gnome desktop environment is having to go through some serious belt-tightening due to continued financial problems.
-
Thousands of Linux Servers Infected with Stealth Malware Since 2021
Perfctl is capable of remaining undetected, which makes it dangerous and hard to mitigate.
-
Halcyon Creates Anti-Ransomware Protection for Linux
As more Linux systems are targeted by ransomware, Halcyon is stepping up its protection.
-
Valve and Arch Linux Announce Collaboration
Valve and Arch have come together for two projects that will have a serious impact on the Linux distribution.
-
Hacker Successfully Runs Linux on a CPU from the Early ‘70s
From the office of "Look what I can do," Dmitry Grinberg was able to get Linux running on a processor that was created in 1971.
-
OSI and LPI Form Strategic Alliance
With a goal of strengthening Linux and open source communities, this new alliance aims to nurture the growth of more highly skilled professionals.
-
Fedora 41 Beta Available with Some Interesting Additions
If you're a Fedora fan, you'll be excited to hear the beta version of the latest release is now available for testing and includes plenty of updates.
-
AlmaLinux Unveils New Hardware Certification Process
The AlmaLinux Hardware Certification Program run by the Certification Special Interest Group (SIG) aims to ensure seamless compatibility between AlmaLinux and a wide range of hardware configurations.
-
Wind River Introduces eLxr Pro Linux Solution
eLxr Pro offers an end-to-end Linux solution backed by expert commercial support.
-
Juno Tab 3 Launches with Ubuntu 24.04
Anyone looking for a full-blown Linux tablet need look no further. Juno has released the Tab 3.