Attacks/Breaches
3/21/2011
11:51 AM
Connect Directly
RSS
E-Mail
50%
50%

SecurID Customers Advised To Prepare For Worst Case

EMC's RSA hasn't detailed exactly what was stolen, so security experts advise the authentication system's customers to implement a more layered network defense.

10 Massive Security Breaches
(click image for larger view)
Slideshow: 10 Massive Security Breaches
How serious is the security threat posed by the theft of inside information about SecurID, the two-factor authentication system sold by EMC division RSA? "It is important enough that it required an official note to the stock markets," said Martin Kuppinger, founder and principal analyst at KuppingerCole, in a blog post.

But, despite the apparent severity of the breach, RSA's failure to detail what was stolen is generating an immense amount of customer frustration, because they don't know if their SecurID hardware fobs are still secure, or if they might provide attackers with a conduit through enterprise defenses.

Here's the worst-case scenario: "The worry is that source code to the company's SecurID two-factor authentication product was stolen, which would possibly allow hackers to reverse-engineer or otherwise break the system," said Bruce Schneier, chief security technology officer of BT, in a blog post. In that case, attackers could spoof SecurID to access corporate systems.

Until RSA coughs up more information, security experts advocate conducting a thorough and immediate SecurID risk assessment. "Our recommendation for customers which have RSA SecurID cards implemented is to first carefully analyze the situation and their specific risks -- [for example] which type of information is at risk if the RSA SecurID-based authentication is not only at risk -- like now -- but an attack actually takes place?" said Kuppinger.

Next, identify specific technologies and remediation activities for securing at-risk data or accounts. "These actions might range from increased threat analysis and forensics to adding other authentication technologies," said Kuppinger.

But rather than just shopping for a SecurID replacement, numerous experts are recommending that security managers turn this situation into an opportunity to create a more layered security defense. "Many organizations rely too heavily on two-factor authentication and they have historically seen it as a silver bullet," said William Beer, PricewaterhouseCoopers (PwC) director of OneSecurity, in an emailed statement.

Stay tuned for more details about the extent of the attacks, their effect on RSA, and the security and IT management ramifications for their customers. "RSA Data Security, Inc. is probably pretty screwed if SecurID is compromised," said BT's Schneier. "Those hardware tokens have no upgrade path, and would have to be replaced."

That would be no small task. RSA had 40 million SecurID hardware token customers by 2009, as well as 250 million users of SecurID software.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-3345
Published: 2014-08-28
The web framework in Cisco Transport Gateway for Smart Call Home (aka TG-SCH or Transport Gateway Installation Software) 4.0 does not properly check authorization for administrative web pages, which allows remote attackers to modify the product via a crafted URL, aka Bug ID CSCuq31503.

CVE-2014-3347
Published: 2014-08-28
Cisco IOS 15.1(4)M2 on Cisco 1800 ISR devices, when the ISDN Basic Rate Interface is enabled, allows remote attackers to cause a denial of service (device hang) by leveraging knowledge of the ISDN phone number to trigger an interrupt timer collision during entropy collection, leading to an invalid s...

CVE-2014-4199
Published: 2014-08-28
vm-support 0.88 in VMware Tools, as distributed with VMware Workstation through 10.0.3 and other products, allows local users to write to arbitrary files via a symlink attack on a file in /tmp.

CVE-2014-4200
Published: 2014-08-28
vm-support 0.88 in VMware Tools, as distributed with VMware Workstation through 10.0.3 and other products, uses 0644 permissions for the vm-support archive, which allows local users to obtain sensitive information by extracting files from this archive.

CVE-2014-0761
Published: 2014-08-27
The DNP3 driver in CG Automation ePAQ-9410 Substation Gateway allows remote attackers to cause a denial of service (infinite loop or process crash) via a crafted TCP packet.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
This episode of Dark Reading Radio looks at infosec security from the big enterprise POV with interviews featuring Ron Plesco, Cyber Investigations, Intelligence & Analytics at KPMG; and Chris Inglis & Chris Bell of Securonix.