RSA offers token replacement after Lockheed attacks
By Tom Brewster,
RSA has offered to replace certain users' SecurID tokens following significant attacks on the security firm in March.
The company also admitted yesterday the SecurID data taken during the breaches had been used in an attack on US defence supplier Lockheed Martin.
“On Thursday 2 June 2011, we were able to confirm that information taken from RSA in March had been used as an element of an attempted broader attack on Lockheed Martin, a major US government defence contractor,” said Art Coviello, executive chairman of RSA, in an open letter.
“We recognise that the increasing frequency and sophistication of cyber attacks generally, and the recent announcements by Lockheed Martin, may reduce some customers' overall risk tolerance.”
RSA offered token replacement to those customers “with concentrated user bases typically focused on protecting intellectual property and corporate networks.”
“We will continue to work with all customers to assess their unique risk profiles and user populations and help them understand which options may be most effective and least disruptive to their business and their users,” Coviello said.
For anyone who thought tokens might be on their way out as a two-factor authentication mechanism, RSA appeared to disagree.
“We will continue to invest heavily in both our SecurID and our risk-based authentication technologies,” Coviello added.
“We believe that SecurID is the most powerful multi-factor authentication solution in the industry.”
Lockheed lament
RSA's confirmation of the information used in the attempt on Lockheed came after much speculation duplicates of the SecurID tokens were used in the attack.
Rick Moy, president and chief executive (CEO) of NSS Labs, claimed Lockheed had long enough to change its tokens following the strike on RSA.
“Lockheed had slightly over two months from the time that EMC notified them and other RSA SecurID customers about their breach,” Moy said in a blog post.
“Based upon their remediation actions for this breach, Lockheed Martin’s senior executives chose to do very little about the compromised SecurID token technology in spite of many warnings issued by security specialists about the potential aftereffects of the RSA attack."
At the time of publication, Lockheed had not offered IT PRO a response to Moy's criticisms.
You may also like...
Sponsored Links
advertisement
You may also like...
Latest Intellectual Property Analysis & Insight
The Digital Economy Act: Is it doomed to never happen?
As a further delay hits part of the implementation of the Digital Economy Act, is this just a small hiccup, or is the Act being rendered toothless already? Simon Brew takes a look.
- There's more to IP than taming pirates
- Does the government want to snoop on your data?
- 2011: The year in news
- How the Data Protection Act's death will punish the UK economy
- Why tech patents have become an arms race
- Copyright overtaken by technology
- Copyright on the tracks
- Litigating against innovation: Legal attacks on Linux
advertisement
Most popular
- UK regulator shuts down Angry Birds scam
- Apple iPad 3 vs iPad 2 head-to-head review
- IBM bans use of Siri on iPhones
- Chromebooks: What's gone wrong?
- HP plans massive job cuts
- EMC World 2012: Tucci declares Documentum is here to stay
- Dell EqualLogic PS6100XS review
- Macs and Android under malware threat
- RIM loses its head of sales
- Local fibre broadband needs common standards
Register for IT PRO
You'll get exclusive member benefits including free whitepapers, downloads, Webinars and weekly newsletters full of the latest IT PRO news, reviews, insight and expertise.



