RSA servers hacked as SecurID data stolen
By Tom Brewster,
RSA - the security arm of EMC - has admitted to having a number of its servers hacked, as data on its two-factor authentication product SecurID was compromised.
The firm warned the data could be used to “reduce the effectiveness of a current two-factor authentication implementation as part of a broader attack,” and RSA urged customers to take immediate remedial action.
RSA executive chairman Art Coviello said the firm’s security systems had been targeted by an “extremely sophisticated cyber attack.”
It is believed the attack was in the Advanced Persistent Threat (APT) category, which may indicate a well-funded group of individuals were responsible.
APTs involve significant intelligence research and the use of numerous techniques to hack targets. They need serious investment to be carried out.
RSA is now in the process of informing customers about the dangers and how to strengthen SecurID implementations.
“We have no evidence that customer security related to other RSA products has been similarly impacted,” Coviello said in an open letter to customers.
“We are also confident that no other EMC products were impacted by this attack. It is important to note that we do not believe that either customer or employee personally identifiable information was compromised as a result of this incident.”
In an advice note to customers, RSA listed a number of recommendations for customers to follow, with the first point being to increase focus on security for social media applications and the use of them by anyone with access to critical networks.
RSA has a wide range of customers, ranging from high profile private companies to government bodies.
A ‘sad day’
The breach will be damaging for RSA and it could take some time for the EMC division to recover, said SecurEnvoy co-founder Steve Watts.
Watts said it was a “sad day” to see a company with the reputation of RSA being hit by such a significant attack.
“Anyone with an RSA token doesn’t know if they’re going to be compromised. The industry is a bit concerned,” Watts told IT PRO.
“This isn’t just a bit of a marketing booboo, this is a major strategic issue. The problem is that it will take quite a long time to get over it.”
If RSA has to initiate a recall of a large chunk of its tokens, then this would lump the firm with a costly logistical nightmare, Watts added.
“Is it going to be as extreme as changing every token that is sent out into the marketplace? Is it as far as to send out replacement tokens for every user? That’s just beyond measure,” Watts added.
Earlier this week, Jim Fulton, vice president at DigitalPersona, told IT PRO many companies were struggling with token deployments as it was.
“I’ve heard people say that if they could, they’d throw them underneath a lorry and crush them because they hate them so much,” Fulton said.
You may also like...
Sponsored Links
advertisement
You may also like...
Latest Security Analysis & Insight
What is your password worth?
Would you be tempted to sell off company passwords for a fee? If not, seems like you're in the minority, acccording to research.
- Macs under attack?
- Intel: security inside
- Are you spending too much on IT security?
- Does the government want to snoop on your data?
- Eurocrats versus the cyber criminals
- The truth about spam
- Google and privacy: What’s the problem?
- Q&A: Symantec’s CISO on the source code hack
- RSA: Back from the breach?
Latest Security Reviews
Check Point 2210 Appliance review
Rating: ![]()
advertisement
Most popular
- UK regulator shuts down Angry Birds scam
- Apple iPad 3 vs iPad 2 head-to-head review
- IBM bans use of Siri on iPhones
- Chromebooks: What's gone wrong?
- HP plans massive job cuts
- EMC World 2012: Tucci declares Documentum is here to stay
- Dell EqualLogic PS6100XS review
- Macs and Android under malware threat
- RIM loses its head of sales
- Local fibre broadband needs common standards
Latest News Videos in Security
IT PRO Podcast: Are UK data protection laws flawed?
We bring in two experts to talk about the problems with UK data protection law and the way it is managed.
Register for IT PRO
You'll get exclusive member benefits including free whitepapers, downloads, Webinars and weekly newsletters full of the latest IT PRO news, reviews, insight and expertise.






RSA hacked - time for a new security paradigm
The breach at RSA just goes to show that security by obscurity never works. It's a fundamental principle in security called Kerckhoff's principle - you must assume your enemy has the details of your system. If your authentication relies on some level of operational system "secrecy" to work, it is just a matter of when, not if, the system will be compromised. The problem with traditional shared secret tokens, outside of cost, deployment and custody issues, is that they do nothing to establish context of the mutual authentication. They are merely additional layers of "secret passwords", regardless of how those factors are generated or delivered. Another flaw is that their use is dependent on user input into the browser, the very vehicle that has not yet established trust. The primary issue involved in this breach is the wide applicability of the "secret" elements that were compromised. In a properly architected authentication system, any security failure should be at worst, a one-in-a-row event. Clearly, a new way of thinking regarding privacy, security and identity is required that departs from the 20th century notion of shared secrets.
By rossmac2310 on Friday Mar 18