Feeds

RSA breach leaks data for hacking SecurID tokens

'Extremely sophisicated' attack targets 2-factor auth

Using blade systems to cut costs and sharpen efficiencies

Attackers breached the servers of RSA and stole information that could be used to compromise the security of two-factor authentication tokens used by 40 million employees to access sensitive corporate and government networks, the company said late Thursday.

“Our investigation has led us to believe that the attack is in the category of an Advanced Persistent Threat (APT),” RSA Executive Chairman Art Coviello said in an undated letter posted on the company's website. “Our investigation also revealed that the attack resulted in certain information being extracted from RSA's systems.”

Neither the letter nor a filing (PDF) with the Securities and Exchange Commission identified what the stolen data was, but Coviello went on to say it “could potentially be used to reduce the effectiveness of a current two-factor authentication implementation as part of a broader attack.”

Michael Gallant, a spokesman with RSA owner EMC, declined to answer any questions posed by The Register.

Among the unanswered questions was whether attackers got access to the so-called seed values that SecurID tokens use to generate the six-digit numbers that change every 60 seconds. Workers in both private industry and government agencies use the devices as an additional security measure when logging onto their employers' networks. Requiring the employee to have physical access to the dongle thwarts hackers who may have intercepted the users' password.

If attackers were able to access the seeds for a specific company, they might be able to generate the pseudo-random numbers of one of its tokens, allowing them to clear a crucial hurdle in breaching the company's security.

Other possibilities include the theft of source code that gives attackers a blueprint of vulnerabilities to exploit, or the theft of private cryptographic keys that might allow them to imitate RSA servers or register new employee tokens.

“RSA is going to have to convince people that their stuff still works,” said Nick Owen, CEO of Wikid Systems, a two-factor authentication startup that competes with RSA. “That means they'll have to come clean about the attack. They may be in a position where they have to reissue hardware tokens to their users as well.”

Owen noted that RSA's notice came as one of the company's websites related to the activation of software licenses was down for unexplained reasons. It's not clear if the outage is related to the attack.

Coviello's letter said that company security systems recently identified “an extremely sophisticated cyber attack in progress being mounted against RSA.” That description, and the reference to APT, leaves open the possibility that attacks could have lasted days, weeks, or months – but the company didn't say more. They also evoked memories of attacks Google disclosed early last year that breached security at dozens of companies and made off with highly sensitive data.

The vagueness also generated plenty of criticism among security professionals.

“APT: Yeah, we got pwned, leaked all your data,” web app security guru Mike Bailey tweeted, in a mock paraphrase of Coviello's letter. “Srry about that, but this guy was GOOD.”

RSA sent a communication to customers urging them to follow a variety of security best-practices, including to “enforce strong password and pin policies,” to “re-educate employees on the importance of avoiding suspicious emails,” and to “harden, closely monitor, and limit remote and physical access to infrastructure that is hosting critical security software.”

We're hoping a version of the email has been sent to RSA employees and executives as well. ®

The smart choice: opportunity from uncertainty

More from The Register

next story
Yorkshire cops fail to grasp principle behind BT Fon Wi-Fi network
'Prevent people that are passing by to hook up to your network', pleads plod
HIDDEN packet sniffer spy tech in MILLIONS of iPhones, iPads – expert
Don't panic though – Apple's backdoor is not wide open to all, guru tells us
NEW, SINISTER web tracking tech fingerprints your computer by making it draw
Have you been on YouPorn lately, perhaps? White House website?
LibreSSL RNG bug fix: What's all the forking fuss about, ask devs
Blow to bit-spitter 'tis but a flesh wound, claim team
Black Hat anti-Tor talk smashed by lawyers' wrecking ball
Unmasking hidden users is too hot for Carnegie-Mellon
Attackers raid SWISS BANKS with DNS and malware bombs
'Retefe' trojan uses clever spin on old attacks to grant total control of bank accounts
Manic malware Mayhem spreads through Linux, FreeBSD web servers
And how Google could cripple infection rate in a second
Don't look, Snowden: Security biz chases Tails with zero-day flaws alert
Exodus vows not to sell secrets of whistleblower's favorite OS
prev story

Whitepapers

Seven Steps to Software Security
Seven practical steps you can begin to take today to secure your applications and prevent the damages a successful cyber-attack can cause.
Consolidation: The Foundation for IT Business Transformation
In this whitepaper learn how effective consolidation of IT and business resources can enable multiple, meaningful business benefits.
Designing a Defense for Mobile Applications
Learn about the various considerations for defending mobile applications - from the application architecture itself to the myriad testing technologies.
Build a business case: developing custom apps
Learn how to maximize the value of custom applications by accelerating and simplifying their development.
Consolidation: the foundation for IT and business transformation
In this whitepaper learn how effective consolidation of IT and business resources can enable multiple, meaningful business benefits.