Attacks/Breaches
3/21/2011
11:51 AM
50%
50%

SecurID Customers Advised To Prepare For Worst Case

EMC's RSA hasn't detailed exactly what was stolen, so security experts advise the authentication system's customers to implement a more layered network defense.

10 Massive Security Breaches
(click image for larger view)
Slideshow: 10 Massive Security Breaches
How serious is the security threat posed by the theft of inside information about SecurID, the two-factor authentication system sold by EMC division RSA? "It is important enough that it required an official note to the stock markets," said Martin Kuppinger, founder and principal analyst at KuppingerCole, in a blog post.

But, despite the apparent severity of the breach, RSA's failure to detail what was stolen is generating an immense amount of customer frustration, because they don't know if their SecurID hardware fobs are still secure, or if they might provide attackers with a conduit through enterprise defenses.

Here's the worst-case scenario: "The worry is that source code to the company's SecurID two-factor authentication product was stolen, which would possibly allow hackers to reverse-engineer or otherwise break the system," said Bruce Schneier, chief security technology officer of BT, in a blog post. In that case, attackers could spoof SecurID to access corporate systems.

Until RSA coughs up more information, security experts advocate conducting a thorough and immediate SecurID risk assessment. "Our recommendation for customers which have RSA SecurID cards implemented is to first carefully analyze the situation and their specific risks -- [for example] which type of information is at risk if the RSA SecurID-based authentication is not only at risk -- like now -- but an attack actually takes place?" said Kuppinger.

Next, identify specific technologies and remediation activities for securing at-risk data or accounts. "These actions might range from increased threat analysis and forensics to adding other authentication technologies," said Kuppinger.

But rather than just shopping for a SecurID replacement, numerous experts are recommending that security managers turn this situation into an opportunity to create a more layered security defense. "Many organizations rely too heavily on two-factor authentication and they have historically seen it as a silver bullet," said William Beer, PricewaterhouseCoopers (PwC) director of OneSecurity, in an emailed statement.

Stay tuned for more details about the extent of the attacks, their effect on RSA, and the security and IT management ramifications for their customers. "RSA Data Security, Inc. is probably pretty screwed if SecurID is compromised," said BT's Schneier. "Those hardware tokens have no upgrade path, and would have to be replaced."

That would be no small task. RSA had 40 million SecurID hardware token customers by 2009, as well as 250 million users of SecurID software.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2015-0192
Published: 2015-07-02
Unspecified vulnerability in IBM Java 8 before SR1, 7 R1 before SR2 FP11, 7 before SR9, 6 R1 before SR8 FP4, 6 before SR16 FP4, and 5.0 before SR16 FP10 allows remote attackers to gain privileges via unknown vectors related to the Java Virtual Machine.

CVE-2015-1914
Published: 2015-07-02
IBM Java 7 R1 before SR3, 7 before SR9, 6 R1 before SR8 FP4, 6 before SR16 FP4, and 5.0 before SR16 FP10 allows remote attackers to bypass "permission checks" and obtain sensitive information via vectors related to the Java Virtual Machine.

CVE-2015-1916
Published: 2015-07-02
Unspecified vulnerability in IBM Java 8 before SR1 allows remote attackers to cause a denial of service via unknown vectors related to SSL/TLS and the Secure Socket Extension provider.

CVE-2015-3157
Published: 2015-07-02
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

CVE-2015-3202
Published: 2015-07-02
fusermount in FUSE before 2.9.3-15 does not properly clear the environment before invoking (1) mount or (2) umount as root, which allows local users to write to arbitrary files via a crafted LIBMOUNT_MTAB environment variable that is used by mount's debugging feature.

Dark Reading Radio
Archived Dark Reading Radio
Marc Spitler, co-author of the Verizon DBIR will share some of the lesser-known but most intriguing tidbits from the massive report