4 ms·
I think most of what you say is generally assumed to be the case although they haven't disclosed this. I think you may have oversimplified cloning a token thoug
by samuarl 15y ago
I think most of what you say is generally assumed to be the case although they haven't disclosed this. I think you may have oversimplified cloning a token though.
In order to clone a given token you require the token seed, token serial and its current token code[1]. The attacker my have the token seeds and serial numbers from the RSA security hack but not a token code without physical access to the token or a keylogger.
If the attacker could install a keylogger on some employee computer they could perhaps capture a token code and then use that to start emulating say 20,000 tokens with the seed and serial pairs stolen from the database. Next time they capture a code compare it with all the tokens being emulated to see if there is a match, if yes, possible success, you have cloned their token and a keylogger will also capture their pin. If there is no match, move onto next set of seed serial pairs with the code you just captured.
[1]http://seclists.org/bugtraq/2000/Dec/459 http://seclists.org/bugtraq/2000/Dec/459