Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 51 guests and 2 members online
 
Free Business and Tech Magazines and eBooks

You are here: Home arrow Resourcesarrow News from the Outside Worldarrow RSA SecurID Hacked: 2FA Fob and Software Compromise?
EH-Net
May 22, 2013, 05:27:09 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: RSA SecurID Hacked: 2FA Fob and Software Compromise?  (Read 8363 times)
0 Members and 1 Guest are viewing this topic.
don
Editor-In-Chief
Administrator
Hero Member
*****
Offline Offline

Posts: 4165


Editor-In-Chief


View Profile WWW
« on: March 18, 2011, 09:39:51 AM »

Nice post by Richi Jennings of ComputerWorld with quotes from other blogs on the story.

Quote

Egg meets face, as security company 'fesses up to security breach. Are your RSA SecurID keys safe? Or are we panicking too much?

EMC's RSA says its SecurID two-factor authentication system has been "impacted" thanks to a hack attack. It's not clear whether the company's fob or software 2FA tokens have been compromised. In IT Blogwatch, bloggers push the panic button.

Your humble blogwatcher curated these bloggy bits for your entertainment


For full blog:
http://blogs.computerworld.com/17995/rsa_securid_hacked_2fa_fob_and_software_compromise

Don
Logged

CISSP, MCSE, CSTA, Security+ SME
tturner
Sr. Member
****
Offline Offline

Posts: 432


View Profile WWW
« Reply #1 on: March 18, 2011, 10:14:41 AM »

I'm seeing a lot of panic on the internet as people speculate a master key compromise or identified vulns in the implementation but we really don't know. The bottom line is this damages the trust relationship with RSA and the SecurID tokens. I think it's a good idea to take a closer look at your CSIRT processes and take this into consideration, but I think the assumption that 40 million 2FA tokens are broken is a bit alarmist. I will tell you that I'm not revoking all the tokens in my environment, but I'm keeping a much closer eye on my VPN gateway/fw and probably will continue to do so until we learn a bit more about the risks associated with this breach.

I also question the whole APT thing which bothers me as we see more and more compromises blamed on APT as if that somehow makes it all OK. It seems lately than anything more advanced than a skiddie attack get blamed on APt and that's just foolishness.
« Last Edit: March 18, 2011, 10:26:00 AM by tturner » Logged

Certifications:
CISSP, CISA, GPEN, GWAPT, GAWN, GCIA, GCIH, GSEC, OPSE, CSWAE, CSTP, VCP

WIP: OSWP, GSSP-JAVA, GXPN

Udacity on hold, again. I suck.

http://sentinel24.com/blog  @tonylturner http://bsidesorlando.org
sil
Hero Member
*****
Offline Offline

Posts: 549



View Profile WWW
« Reply #2 on: March 18, 2011, 02:15:14 PM »

RSA Fail - Security Lessons Unlearned
https://infosecisland.com/blogview/12632-RSA-Fail-Security-Lessons-Unlearned.html
Logged

Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.058 seconds with 24 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Advertisement

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.