4 ms·
The money quote is: While at this time we are confident that the information extracted does not enable a successful direct attack on any of our RSA SecurID cus
by werrett 16y ago
The money quote is:
While at this time we are confident that the information extracted does not enable a successful direct attack on any of our RSA SecurID customers, this information could potentially be used to reduce the effectiveness of a current two-factor authentication implementation as part of a broader attack.
To me that sounds a lot stronger than "the thieves took the SecureID implementation plans and could theoretically build a 'soft' SecureID. Your long, random, hard-to-guess seed still protects you."
To me, what Coviello is saying is don't worry the thieves haven't stolen some secret 0-day that would provide them immediate access through your RSA kit. But they did get something that will make the RSA part of your 2-Factor authentication scheme null and void.
- caf 16y agoThe algorithm necessary to build a software SecurID was leaked long ago. This sounds like they could well have stolen copies of some customers seeds, which would reduce the RSA authentication from two-factor to one-factor.
- peterwwillis 16y agocorrect me if im wrong, but iirc that second factor is a 4 digit number you pick at your first login.
- nuclear_eclipse 16y agoIt is. Where I work, I have to use account name, 4 digit PIN, and the current token value to log in to systems protected by the RSA token.
- nradov 16y agoI think you're wrong. My work uses RSA SecurID and my password is longer and more complex than a 4-digit number.
- caf 16y agoThe second factor is called a "PIN" in the RSA documentation, but the details can be configured by the administrator in a particular deployment. The administrator can set an allowed length range (with minimum and maximum between 4 and 8), and can choose to allow alphanumeric "PIN"s. RSA's recommendation is for alphanumeric PINs of at least 6 characters. Note also that a small number of tries with an incorrect PIN but correct tokencode will lock the account as "token stolen".
- oasisbob 16y agoTo me, what Coviello is saying is don't worry the thieves haven't stolen some secret 0-day that would provide them immediate access through your RSA kit I am no security expert (far from it!), but I've seen enough compromise disclosures with inside information to read this the exact same way as you, especially with this note from the advisory: We recommend customers enforce strong password and pin policies. Advisories like this are like poetry: every word matters, and a phrase like "... reduce the effectiveness of a current two-factor authentication implementation as part of a broader attack" is too pretty to not raise my suspicion. RSA could be 100% busted, and this phrase would still be technically true.