4 ms·
It's a bigger deal they didn't replace the devices when they found out. I was surprised to find out that a large number of tokens were still in use. I think so
by trotsky 15y ago
It's a bigger deal they didn't replace the devices when they found out.
I was surprised to find out that a large number of tokens were still in use. I think some of the problem may be with a few large organizations that simply didn't have the logistics in place to replace their tokens quickly.
Two organizations that I'm familiar with had each replaced their thousands of tokens by early May.
- RockyMcNuts 15y agoIt's logistics, and also RSA to their eternal discredit did not recommend or pay for replacement. Those aren't cheap (like $50 apiece). If you're a CTO with 1000 users and rudimentary security knowledge, are you going to spend $50,000 and a bunch of time tracking down every single user (who will think it's all a terrible bore) and replace their token, if the company you rely on to keep you secure doesn't say it's necessary? I give credit to the people who didn't screw around, and switched vendors.
- trotsky 15y agoRSA to their eternal discredit did not recommend replacement Is that just your assumption? I believe everyone who received guidance from RSA on the subject was asked to sign a non-disclosure, but I think some of them might be surprised to hear you say that.
- RockyMcNuts 15y agoas a small client and in touch with other small clients, no, very definitely NOT just an assumption.
- trotsky 15y agoSounds like they didn't have enough in the supply chain in the short run and picked and choosed. ouch.