Linux 4.13 Kernel Released with New Accelerated Security Feature

存储架构 2017-09-06

While most Americans were enjoying the Labor Day weekend, Linux creator Linus Torvalds was busy releasing the Linux 4.13 kernel on Sept. 3. Linux 4.13 is the fourth new Linux kernel released in 2017 and follows Linux 4.12, which debuted in July.

The Linux 4.13 kernel is noteworthy for a number of reasons, including multiple security-related enhancements and some health issues that Torvalds dealt with during the development cycle, which included seven release candidates.

"The other excitement this week was purely personal, consisting of seven hours of pure agony due to a kidney stone," Torvalds wrote. "I'm all good, but it sure _felt_ a lot longer than seven hours, and I don't even want to imagine what it is for people that have had the experience drag out for longer."

Among the security-related changes in the Linux 4.13 kernel is one that Torvalds referred to as a generic protocol issue.

Related Reading

"The change in question is simply changing the default cifs behavior: instead of defaulting to SMB 1.0 (which you really should not use: just google for 'stop using SMB1' or similar), the default cifs mount now defaults to a rather more modern SMB 3.0," Torvalds wrote.

The Common Internet File System (CIFS) and the Server Message Block (SMB) protocol enable cross-platform file and folder sharing between different Windows and Linux systems. SMB version 1 has been considered to be insecure for several years, with multiple vendors including Microsoft warning
users since at least 2016 not to use it. SMB-related vulnerabilities have also been a prominent component of several recent high-profile ransomware attacks, including bothWannaCry in May andNotPetya in June

According to Torvalds, most Linux users should not notice the change to the newer SMB 3.0 protocol as the default for CIFS. He noted that for those who do notice the change, they should still move away from SMB version 1 to a newer version.

"Because let's face it, SMB1 is just bad, bad, bad," Torvalds wrote.

KTLS

Linux 4.13 also debuts a new Kernel Transport Layer Security (KTLS) implementation, providing improved HTTPS encryption performance. TLS is widely used on the internet today for encryption of data transport. Normally TLS encryption is handled outside of the Linux kernel in what is known as the user space section of Linux.

Facebook engineer Dave Watson originally proposed
the idea of KTLS as a way to accelerate TLS performance at scale.

"In kernel implementations provide new opportunities for optimization of TLS," Watson wrote in a research paper. "Our implementation saves up to 7 percent CPU copy overhead and up to 10 percent latency improvements when combined with the Kernel Connection Multiplexor (KCM)."

Sean Michael Kerner is a senior editor at eWEEK and InternetNews.com. Follow him on Twitter @TechJournalist.

您可能感兴趣的

BrandPost: Don’t Get Tripped Up; 4 Tips for Secure... More kinds of user authentication options are available today than ever before—two-factor, multi-factor, mobile, push, tokenless, biometric. That’s th...
Tiny Core Linux 8.1 rc3 发布,桌面 Linux 发行版... Tiny Core Linux 8.1 rc3 发布了。TinyCoreLinux 是一份很小(10 MB)的最低限度Linux桌面。最新版本基于Linux 3.x内核、Busybox、Tiny X、FLTK图形用户界面、JWM窗口管理器,全部运行在内存中。它并非一份完整的桌面,也不完整支持所有的硬...
ossutil报”Cannot assign requested addressR... 问题 某用户使用如下命令上传目录到OSS,中间隐去bucket name。 ./ossutil cp oss:///img/330802010400071904 -r -j 15 /home/oss/vis-test/ 出现如下错误。 分析 原因 由于Linu...
Destruction of Service attacks could shut down org... The Cisco 2017 Midyear Cybersecurity Report (MCR) uncovers the rapid evolution of threats and the increasing magnitude of attacks, and forecasts pote...
不用装双系统,直接在 Windows 上体验 Linux:Windows Subsystem for... 「Microsoft Loves Linux!」 说出这句话的不是所谓的 IT 领域那些技术专家或者是意见领袖,而是时任微软 CEO 的萨蒂亚· 纳德拉,在 2015 年的一次活动中,这位第三任微软 CEO 脱口而出的这句话,让这个曾经开源界最大敌人的微软,正式拥抱这个开源世界最大...
0
LXer

责编内容来自:LXer (本文源链)
阅读提示:酷辣虫无法对本内容的真实性提供任何保证,请自行验证并承担相关的风险与后果!
本站遵循[CC BY-NC-SA 4.0]。如您有版权、意见投诉等问题,请通过eMail联系我们处理。