-
March 21st, 2011, 07:33 AM #1
RSA says hack won't allow "direct attack" on SecureID tokens
RSA says hack won't allow "direct attack" on SecureID tokens
Security firm RSA has been the victim of an "extremely sophisticated" attack that has resulted in exfiltration of certain private information, announced Executive Chairman Art Coviello in an open letter published yesterday. The company also filed a note with the SEC, warning of possible risks due to the attack. Since 2006, RSA has been part of EMC.
I found this interesting since im in the middle of deploying SecureID onto your network
-
June 7th, 2011, 02:23 PM #2
RSA finally comes clean: SecurID is compromised
Wah wah!
I just got finishing deploying a bunch of tokens and having users setup new PINs.
Now I need to pass out all new tokens to users and have them setup PINs again. AWESOME!
-
June 7th, 2011, 02:46 PM #3
Lying to your customers is especially bad when you are a SECURITY firm. Not good for your business. While RSA has lots of contracts that wont go away overnight, it probably will lose a fair amount of customers/businesses over this issue.
They say technology slows down for no one. I know it outruns my wallet. I figure its because my wallet isn't light enough yet.
TechIMO Folding@home Team #111 - Crunching for the cure!
dulce bellum inexpertis
-
June 7th, 2011, 07:05 PM #4
Ok, so what if my company uses SecurID? I'm supposed to worry about....what exactly?
-
June 7th, 2011, 09:07 PM #5
See the problem is companies like Lockheed martin that stopped a compromise wont come out and fully say how the exploit happened. Just that it has to deal with secureid (this is whatever is really concerned about, no one is saying anything really). It took from March 21 - June 7th pretty much for RSA to come clean to its customers.
But here is the low down which makes this kind of a big deal (espically since several government agencies use these devices). If a person has the token seeds (which my understanding they know which companies have what seeds) then the attacker has to find out the username/pin to be able to log in. Something that doesn't sound easy now does it? Well you are right in a way however RSA was hacked with pretty much someone opening up an excel sheet that had some sort of exploit that spread on the network. All it takes is for a keylogger or some other kind of malware to spread on a network to grab that information. So a two authentication method is pretty much back down to a basic username/password (which is only alpha/numeric, I dont remember being able to see users be able to set up symbols in their Pins)
Me personally I would like to move to smart cards
-
June 8th, 2011, 03:12 PM #6
I just got off the phone with RSA, they only need to replace the hardware tokens and will only replace tokens that dont expire in the next 12 months.
-
June 8th, 2011, 04:27 PM #7
So I wonder about PayPal's hardware tokens.
-
June 8th, 2011, 05:17 PM #8
I believe they are using RSA tokens, if you look on the back of the hardware key it could tell you the year it expires.
-
August 28th, 2011, 10:52 AM #9
Researchers uncover RSA phishing attack, hiding in plain sight
Updated information
-
August 28th, 2011, 11:19 AM #10
“I forward this file to you for review. Please open and view it.”
Wow, sounds like a pretty advanced technique.
-
August 28th, 2011, 04:10 PM #11
Can anyone say firewall????
Thread Information
Users Browsing this Thread
There are currently 1 users browsing this thread. (0 members and 1 guests)
Similar Threads
-
"US 'Iran attack plans' revealed" The Democrats Better Stop This!
By Chuckiechan in forum DebateIMO: Politics, Religion, ControversyReplies: 41Last Post: June 9th, 2011, 07:17 PM -
Should the US grant Israel an "Air Corridor" through Iraq to attack Iran?
By Chuckiechan in forum DebateIMO: Politics, Religion, ControversyReplies: 18Last Post: March 3rd, 2007, 02:26 PM -
Win XP "Always ask before opening" registry hack?
By Turnip12 in forum Applications and Operating SystemsReplies: 3Last Post: January 8th, 2003, 09:39 PM -
Low-life "Fans" Attack Sox Coach
By osprey4 in forum IMO CommunityReplies: 3Last Post: September 22nd, 2002, 12:49 PM



LinkBack URL
About LinkBacks



Reply With Quote




For more SEE>>> As Apple ebook trial enters last week, it’s all about Steve Jobs - Yahoo! Finance
APPLE Price-Fixing Trial Begins...