Attacks/Breaches
3/21/2011
11:51 AM
50%
50%

SecurID Customers Advised To Prepare For Worst Case

EMC's RSA hasn't detailed exactly what was stolen, so security experts advise the authentication system's customers to implement a more layered network defense.

10 Massive Security Breaches
(click image for larger view)
Slideshow: 10 Massive Security Breaches
How serious is the security threat posed by the theft of inside information about SecurID, the two-factor authentication system sold by EMC division RSA? "It is important enough that it required an official note to the stock markets," said Martin Kuppinger, founder and principal analyst at KuppingerCole, in a blog post.

But, despite the apparent severity of the breach, RSA's failure to detail what was stolen is generating an immense amount of customer frustration, because they don't know if their SecurID hardware fobs are still secure, or if they might provide attackers with a conduit through enterprise defenses.

Here's the worst-case scenario: "The worry is that source code to the company's SecurID two-factor authentication product was stolen, which would possibly allow hackers to reverse-engineer or otherwise break the system," said Bruce Schneier, chief security technology officer of BT, in a blog post. In that case, attackers could spoof SecurID to access corporate systems.

Until RSA coughs up more information, security experts advocate conducting a thorough and immediate SecurID risk assessment. "Our recommendation for customers which have RSA SecurID cards implemented is to first carefully analyze the situation and their specific risks -- [for example] which type of information is at risk if the RSA SecurID-based authentication is not only at risk -- like now -- but an attack actually takes place?" said Kuppinger.

Next, identify specific technologies and remediation activities for securing at-risk data or accounts. "These actions might range from increased threat analysis and forensics to adding other authentication technologies," said Kuppinger.

But rather than just shopping for a SecurID replacement, numerous experts are recommending that security managers turn this situation into an opportunity to create a more layered security defense. "Many organizations rely too heavily on two-factor authentication and they have historically seen it as a silver bullet," said William Beer, PricewaterhouseCoopers (PwC) director of OneSecurity, in an emailed statement.

Stay tuned for more details about the extent of the attacks, their effect on RSA, and the security and IT management ramifications for their customers. "RSA Data Security, Inc. is probably pretty screwed if SecurID is compromised," said BT's Schneier. "Those hardware tokens have no upgrade path, and would have to be replaced."

That would be no small task. RSA had 40 million SecurID hardware token customers by 2009, as well as 250 million users of SecurID software.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2012-1978
Published: 2015-05-21
Multiple cross-site request forgery (CSRF) vulnerabilities in Simple PHP Agenda 2.2.8 and earlier allow remote attackers to hijack the authentication of administrators for requests that (1) add an administrator via a request to auth/process.php, (2) delete an administrator via a request to auth/admi...

CVE-2015-0741
Published: 2015-05-21
Multiple cross-site request forgery (CSRF) vulnerabilities in Cisco Prime Central for Hosted Collaboration Solution (PC4HCS) 10.6(1) and earlier allow remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCut04596.

CVE-2015-0742
Published: 2015-05-21
The Protocol Independent Multicast (PIM) application in Cisco Adaptive Security Appliance (ASA) Software 9.2(0.0), 9.2(0.104), 9.2(3.1), 9.2(3.4), 9.3(1.105), 9.3(2.100), 9.4(0.115), 100.13(0.21), 100.13(20.3), 100.13(21.9), and 100.14(1.1) does not properly implement multicast-forwarding registrati...

CVE-2015-0746
Published: 2015-05-21
The REST API in Cisco Access Control Server (ACS) 5.5(0.46.2) allows remote attackers to cause a denial of service (API outage) by sending many requests, aka Bug ID CSCut62022.

CVE-2015-0915
Published: 2015-05-21
Cross-site scripting (XSS) vulnerability in RAKUS MailDealer 11.2.1 and earlier allows remote attackers to inject arbitrary web script or HTML via a crafted attachment filename.

Dark Reading Radio
Archived Dark Reading Radio
Join security and risk expert John Pironti and Dark Reading Editor-in-Chief Tim Wilson for a live online discussion of the sea-changing shift in security strategy and the many ways it is affecting IT and business.