+ Reply to Thread
Results 1 to 11 of 11
  1. #1
    Goverment property now GroundZero3's Avatar
    Join Date
    Oct 2001
    Location
    NOVA
    Posts
    33,902
    Blog Entries
    46

    RSA says hack won't allow "direct attack" on SecureID tokens

     
    RSA says hack won't allow "direct attack" on SecureID tokens

    Security firm RSA has been the victim of an "extremely sophisticated" attack that has resulted in exfiltration of certain private information, announced Executive Chairman Art Coviello in an open letter published yesterday. The company also filed a note with the SEC, warning of possible risks due to the attack. Since 2006, RSA has been part of EMC.
    I found this interesting since im in the middle of deploying SecureID onto your network

  2. #2
    Goverment property now GroundZero3's Avatar
    Join Date
    Oct 2001
    Location
    NOVA
    Posts
    33,902
    Blog Entries
    46
    RSA finally comes clean: SecurID is compromised

    Wah wah!

    I just got finishing deploying a bunch of tokens and having users setup new PINs. Now I need to pass out all new tokens to users and have them setup PINs again. AWESOME!

  3. #3
    ΜΟΛΩΝ ΛΑΒΕ no1_vern's Avatar
    Join Date
    Apr 2002
    Location
    Albany, Ga.
    Posts
    18,625
    Lying to your customers is especially bad when you are a SECURITY firm. Not good for your business. While RSA has lots of contracts that wont go away overnight, it probably will lose a fair amount of customers/businesses over this issue.
    They say technology slows down for no one. I know it outruns my wallet. I figure its because my wallet isn't light enough yet.

    TechIMO Folding@home Team #111 - Crunching for the cure!
    dulce bellum inexpertis

  4. #4
    Ultimate Member osprey4's Avatar
    Join Date
    Oct 2001
    Location
    South Jersey
    Posts
    11,368
    Ok, so what if my company uses SecurID? I'm supposed to worry about....what exactly?

  5. #5
    Goverment property now GroundZero3's Avatar
    Join Date
    Oct 2001
    Location
    NOVA
    Posts
    33,902
    Blog Entries
    46
    See the problem is companies like Lockheed martin that stopped a compromise wont come out and fully say how the exploit happened. Just that it has to deal with secureid (this is whatever is really concerned about, no one is saying anything really). It took from March 21 - June 7th pretty much for RSA to come clean to its customers.

    But here is the low down which makes this kind of a big deal (espically since several government agencies use these devices). If a person has the token seeds (which my understanding they know which companies have what seeds) then the attacker has to find out the username/pin to be able to log in. Something that doesn't sound easy now does it? Well you are right in a way however RSA was hacked with pretty much someone opening up an excel sheet that had some sort of exploit that spread on the network. All it takes is for a keylogger or some other kind of malware to spread on a network to grab that information. So a two authentication method is pretty much back down to a basic username/password (which is only alpha/numeric, I dont remember being able to see users be able to set up symbols in their Pins)

    Me personally I would like to move to smart cards

  6. #6
    Goverment property now GroundZero3's Avatar
    Join Date
    Oct 2001
    Location
    NOVA
    Posts
    33,902
    Blog Entries
    46
    I just got off the phone with RSA, they only need to replace the hardware tokens and will only replace tokens that dont expire in the next 12 months.

  7. #7
    Banned
    Join Date
    Feb 2009
    Location
    KFNL FS2004
    Posts
    11,886
    Blog Entries
    1
    So I wonder about PayPal's hardware tokens.

  8. #8
    Goverment property now GroundZero3's Avatar
    Join Date
    Oct 2001
    Location
    NOVA
    Posts
    33,902
    Blog Entries
    46
    I believe they are using RSA tokens, if you look on the back of the hardware key it could tell you the year it expires.

  9. #9
    Goverment property now GroundZero3's Avatar
    Join Date
    Oct 2001
    Location
    NOVA
    Posts
    33,902
    Blog Entries
    46

  10. #10
    Thaumaturge Member howste's Avatar
    Join Date
    Oct 2001
    Location
    West Haven, Utah
    Posts
    32,763
    “I forward this file to you for review. Please open and view it.”

    Wow, sounds like a pretty advanced technique.

  11. #11
    Banned
    Join Date
    Feb 2009
    Location
    KFNL FS2004
    Posts
    11,886
    Blog Entries
    1
    Can anyone say firewall????

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Similar Threads

  1. "US 'Iran attack plans' revealed" The Democrats Better Stop This!
    By Chuckiechan in forum DebateIMO: Politics, Religion, Controversy
    Replies: 41
    Last Post: June 9th, 2011, 07:17 PM
  2. Should the US grant Israel an "Air Corridor" through Iraq to attack Iran?
    By Chuckiechan in forum DebateIMO: Politics, Religion, Controversy
    Replies: 18
    Last Post: March 3rd, 2007, 02:26 PM
  3. Win XP "Always ask before opening" registry hack?
    By Turnip12 in forum Applications and Operating Systems
    Replies: 3
    Last Post: January 8th, 2003, 09:39 PM
  4. Low-life "Fans" Attack Sox Coach
    By osprey4 in forum IMO Community
    Replies: 3
    Last Post: September 22nd, 2002, 12:49 PM

Tags for this Thread

Posting Permissions

  • You may post new threads
  • You may post replies
  • You may not post attachments
  • You may not edit your posts
  •  
Recommended Sites: ResellerRatings Store Reviews