Attacks/Breaches
3/21/2011
11:51 AM
Connect Directly
RSS
E-Mail
50%
50%

SecurID Customers Advised To Prepare For Worst Case

EMC's RSA hasn't detailed exactly what was stolen, so security experts advise the authentication system's customers to implement a more layered network defense.

10 Massive Security Breaches
(click image for larger view)
Slideshow: 10 Massive Security Breaches
How serious is the security threat posed by the theft of inside information about SecurID, the two-factor authentication system sold by EMC division RSA? "It is important enough that it required an official note to the stock markets," said Martin Kuppinger, founder and principal analyst at KuppingerCole, in a blog post.

But, despite the apparent severity of the breach, RSA's failure to detail what was stolen is generating an immense amount of customer frustration, because they don't know if their SecurID hardware fobs are still secure, or if they might provide attackers with a conduit through enterprise defenses.

Here's the worst-case scenario: "The worry is that source code to the company's SecurID two-factor authentication product was stolen, which would possibly allow hackers to reverse-engineer or otherwise break the system," said Bruce Schneier, chief security technology officer of BT, in a blog post. In that case, attackers could spoof SecurID to access corporate systems.

Until RSA coughs up more information, security experts advocate conducting a thorough and immediate SecurID risk assessment. "Our recommendation for customers which have RSA SecurID cards implemented is to first carefully analyze the situation and their specific risks -- [for example] which type of information is at risk if the RSA SecurID-based authentication is not only at risk -- like now -- but an attack actually takes place?" said Kuppinger.

Next, identify specific technologies and remediation activities for securing at-risk data or accounts. "These actions might range from increased threat analysis and forensics to adding other authentication technologies," said Kuppinger.

But rather than just shopping for a SecurID replacement, numerous experts are recommending that security managers turn this situation into an opportunity to create a more layered security defense. "Many organizations rely too heavily on two-factor authentication and they have historically seen it as a silver bullet," said William Beer, PricewaterhouseCoopers (PwC) director of OneSecurity, in an emailed statement.

Stay tuned for more details about the extent of the attacks, their effect on RSA, and the security and IT management ramifications for their customers. "RSA Data Security, Inc. is probably pretty screwed if SecurID is compromised," said BT's Schneier. "Those hardware tokens have no upgrade path, and would have to be replaced."

That would be no small task. RSA had 40 million SecurID hardware token customers by 2009, as well as 250 million users of SecurID software.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Flash Poll
Current Issue
Cartoon
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2012-4988
Published: 2014-07-09
Heap-based buffer overflow in the xjpegls.dll (aka JLS, JPEG-LS, or JPEG lossless) format plugin in XnView 1.99 and 1.99.1 allows remote attackers to execute arbitrary code via a crafted JLS image file.

CVE-2014-0207
Published: 2014-07-09
The cdf_read_short_sector function in cdf.c in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 and 5.5.x before 5.5.14, allows remote attackers to cause a denial of service (assertion failure and application exit) via a crafted CDF file.

CVE-2014-0537
Published: 2014-07-09
Adobe Flash Player before 13.0.0.231 and 14.x before 14.0.0.145 on Windows and OS X and before 11.2.202.394 on Linux, Adobe AIR before 14.0.0.137 on Android, Adobe AIR SDK before 14.0.0.137, and Adobe AIR SDK & Compiler before 14.0.0.137 allow attackers to bypass intended access restrictions via uns...

CVE-2014-0539
Published: 2014-07-09
Adobe Flash Player before 13.0.0.231 and 14.x before 14.0.0.145 on Windows and OS X and before 11.2.202.394 on Linux, Adobe AIR before 14.0.0.137 on Android, Adobe AIR SDK before 14.0.0.137, and Adobe AIR SDK & Compiler before 14.0.0.137 allow attackers to bypass intended access restrictions via uns...

CVE-2014-3309
Published: 2014-07-09
The NTP implementation in Cisco IOS and IOS XE does not properly support use of the access-group command for a "deny all" configuration, which allows remote attackers to bypass intended restrictions on time synchronization via a standard query, aka Bug ID CSCuj66318.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Marilyn Cohodas and her guests look at the evolving nature of the relationship between CIO and CSO.