RSA breach leaks data for hacking SecurID tokens
'Extremely sophisicated' attack targets 2-factor auth
Attackers breached the servers of RSA and stole information that could be used to compromise the security of two-factor authentication tokens used by 40 million employees to access sensitive corporate and government networks, the company said late Thursday.
“Our investigation has led us to believe that the attack is in the category of an Advanced Persistent Threat (APT),” RSA Executive Chairman Art Coviello said in an undated letter posted on the company's website. “Our investigation also revealed that the attack resulted in certain information being extracted from RSA's systems.”
Neither the letter nor a filing (PDF) with the Securities and Exchange Commission identified what the stolen data was, but Coviello went on to say it “could potentially be used to reduce the effectiveness of a current two-factor authentication implementation as part of a broader attack.”
Michael Gallant, a spokesman with RSA owner EMC, declined to answer any questions posed by The Register.
Among the unanswered questions was whether attackers got access to the so-called seed values that SecurID tokens use to generate the six-digit numbers that change every 60 seconds. Workers in both private industry and government agencies use the devices as an additional security measure when logging onto their employers' networks. Requiring the employee to have physical access to the dongle thwarts hackers who may have intercepted the users' password.
If attackers were able to access the seeds for a specific company, they might be able to generate the pseudo-random numbers of one of its tokens, allowing them to clear a crucial hurdle in breaching the company's security.
Other possibilities include the theft of source code that gives attackers a blueprint of vulnerabilities to exploit, or the theft of private cryptographic keys that might allow them to imitate RSA servers or register new employee tokens.
“RSA is going to have to convince people that their stuff still works,” said Nick Owen, CEO of Wikid Systems, a two-factor authentication startup that competes with RSA. “That means they'll have to come clean about the attack. They may be in a position where they have to reissue hardware tokens to their users as well.”
Owen noted that RSA's notice came as one of the company's websites related to the activation of software licenses was down for unexplained reasons. It's not clear if the outage is related to the attack.
Coviello's letter said that company security systems recently identified “an extremely sophisticated cyber attack in progress being mounted against RSA.” That description, and the reference to APT, leaves open the possibility that attacks could have lasted days, weeks, or months – but the company didn't say more. They also evoked memories of attacks Google disclosed early last year that breached security at dozens of companies and made off with highly sensitive data.
The vagueness also generated plenty of criticism among security professionals.
“APT: Yeah, we got pwned, leaked all your data,” web app security guru Mike Bailey tweeted, in a mock paraphrase of Coviello's letter. “Srry about that, but this guy was GOOD.”
RSA sent a communication to customers urging them to follow a variety of security best-practices, including to “enforce strong password and pin policies,” to “re-educate employees on the importance of avoiding suspicious emails,” and to “harden, closely monitor, and limit remote and physical access to infrastructure that is hosting critical security software.”
We're hoping a version of the email has been sent to RSA employees and executives as well. ®
Accident waiting to happen
Well, in this day and age the token key which is used for the seed should be generated on the token by the customer not by RSA. Frankly, it was only a matter of time until this prehistoric solution met its match.
Secret algo, weak crypto (by 2011 standards), security mostly guaranteed by the "secret" value of the seed and the seed generated by a "trusted" third party.
In 2011. Yeah... Right...
So far, no email from RSA
Paid up RSA customers using SecurID and we only heard about this through the various tech sites (incl El Reg).
Not very happy with RSA/EMC right now.
It is a sad day
when one of the most trusted security solutions provider (and an industry icon too) admits its security was not that great.
I must admit it's quite depressing to realize we're on our own now.
A sobering memo for all CxOs : start looking for really competent people now because hardware&software off the shelf products can clearly no longer replace them. Yes, firewalls and IDS and anti-malware are as good as the people managing them. You DID know that, didn't you ?