4 ms·
I still dont understand why it's taken so long to get to the point where they're going to renew the tokens. Perhaps I'm misunderstanding SecureID implementation
by samuarl 15y ago
I still dont understand why it's taken so long to get to the point where they're going to renew the tokens. Perhaps I'm misunderstanding SecureID implementation, but If an attacker had accessed the database with the token seeds and serials, wouldn't the security then essentially become little better than single factor authentication?
It almost seems like they didn't actually know for definite if the database had been stolen and where unwilling to burden the cost of replacing all the tokens as a precaution. Now with the Lockheed Martin incident they know it was compromised and are forced to.