The Register® — Biting the hand that feeds IT

Feeds

RSA breach leaks data for hacking SecurID tokens

'Extremely sophisicated' attack targets 2-factor auth

Regcast training : Hyper-V 3.0, VM high availability and disaster recovery

Attackers breached the servers of RSA and stole information that could be used to compromise the security of two-factor authentication tokens used by 40 million employees to access sensitive corporate and government networks, the company said late Thursday.

“Our investigation has led us to believe that the attack is in the category of an Advanced Persistent Threat (APT),” RSA Executive Chairman Art Coviello said in an undated letter posted on the company's website. “Our investigation also revealed that the attack resulted in certain information being extracted from RSA's systems.”

Neither the letter nor a filing (PDF) with the Securities and Exchange Commission identified what the stolen data was, but Coviello went on to say it “could potentially be used to reduce the effectiveness of a current two-factor authentication implementation as part of a broader attack.”

Michael Gallant, a spokesman with RSA owner EMC, declined to answer any questions posed by The Register.

Among the unanswered questions was whether attackers got access to the so-called seed values that SecurID tokens use to generate the six-digit numbers that change every 60 seconds. Workers in both private industry and government agencies use the devices as an additional security measure when logging onto their employers' networks. Requiring the employee to have physical access to the dongle thwarts hackers who may have intercepted the users' password.

If attackers were able to access the seeds for a specific company, they might be able to generate the pseudo-random numbers of one of its tokens, allowing them to clear a crucial hurdle in breaching the company's security.

Other possibilities include the theft of source code that gives attackers a blueprint of vulnerabilities to exploit, or the theft of private cryptographic keys that might allow them to imitate RSA servers or register new employee tokens.

“RSA is going to have to convince people that their stuff still works,” said Nick Owen, CEO of Wikid Systems, a two-factor authentication startup that competes with RSA. “That means they'll have to come clean about the attack. They may be in a position where they have to reissue hardware tokens to their users as well.”

Owen noted that RSA's notice came as one of the company's websites related to the activation of software licenses was down for unexplained reasons. It's not clear if the outage is related to the attack.

Coviello's letter said that company security systems recently identified “an extremely sophisticated cyber attack in progress being mounted against RSA.” That description, and the reference to APT, leaves open the possibility that attacks could have lasted days, weeks, or months – but the company didn't say more. They also evoked memories of attacks Google disclosed early last year that breached security at dozens of companies and made off with highly sensitive data.

The vagueness also generated plenty of criticism among security professionals.

“APT: Yeah, we got pwned, leaked all your data,” web app security guru Mike Bailey tweeted, in a mock paraphrase of Coviello's letter. “Srry about that, but this guy was GOOD.”

RSA sent a communication to customers urging them to follow a variety of security best-practices, including to “enforce strong password and pin policies,” to “re-educate employees on the importance of avoiding suspicious emails,” and to “harden, closely monitor, and limit remote and physical access to infrastructure that is hosting critical security software.”

We're hoping a version of the email has been sent to RSA employees and executives as well. ®

Agentless Backup is Not a Myth

Accident waiting to happen

Well, in this day and age the token key which is used for the seed should be generated on the token by the customer not by RSA. Frankly, it was only a matter of time until this prehistoric solution met its match.

Secret algo, weak crypto (by 2011 standards), security mostly guaranteed by the "secret" value of the seed and the seed generated by a "trusted" third party.

In 2011. Yeah... Right...

10
3

So far, no email from RSA

Paid up RSA customers using SecurID and we only heard about this through the various tech sites (incl El Reg).

Not very happy with RSA/EMC right now.

6
0

It is a sad day

when one of the most trusted security solutions provider (and an industry icon too) admits its security was not that great.

I must admit it's quite depressing to realize we're on our own now.

A sobering memo for all CxOs : start looking for really competent people now because hardware&software off the shelf products can clearly no longer replace them. Yes, firewalls and IDS and anti-malware are as good as the people managing them. You DID know that, didn't you ?

4
0

More from The Register

 breaking news
NSA PRISM snoop-gate: Won't someone think of the children, wails Apple
10,000 things probed, mostly about missing kids, Alzheimer patients, we're told
 breaking news
NSA PRISM-gate: Relax, GCHQ spooks 'keep us safe', says Cameron
Whatever they are up to, it's all above board, we're told
PRISM snitch claims NSA hacked Chinese targets since 2009
Snowden suddenly looks safer in Hong Kong after revelations
 breaking news
US chief spook: Look, we only want to spy on 6.66 BEELLLION of you
Americans assured they are not in the NSA's sights
 breaking news
Number of cops abusing Police National Computer access on the rise
Only a telegram from the Queen can get you off it
Speech-to-text drives motorists to distraction
Will talking to you mean I crash into that car up ahead, Siri?
Flash flaw potentially makes every webcam or laptop a PEEPHOLE
But it's a Google problem - Chrome only, insists Adobe
DHS warns of vulns in hospital medical equipment
Has your doctor's anasthesia machine been hacked?
 breaking news
'BadNews is malware' says outfit that found it
Google says code harmless but Lookout says code base is evolving
Panda-peddlers cuffed for chess gambling gambit
More porridge on the menu for Chinese coders after second offence