32 ms·
I would think it would be better to have a provisioning design that did not require that the company retain the seed data for every fob they had sold.
by btbuilder 5y ago
I would think it would be better to have a provisioning design that did not require that the company retain the seed data for every fob they had sold.
- briffle 5y agoOr at least auto-delete them after 30 days, in case a customer didn't get theirs, and needed it resent. Retention policies limit the blast radius when there is a problem.
- runamok 5y agoOr move them to cold storage periodically that's air gapped and they are transferred via sneakernet encrypted.
- benlivengood 5y agoUnlike U2F and similar specs there was no direct communication between the SecurID tokens and any other device, limiting the bandwidth to less entropy than necessary to validate public key signatures. That necessitated having a shared secret between the token and auth server.
- throw0101a 5y ago> That necessitated having a shared secret between the token and auth server. Yes, but why did there have to be a central server with the shared secret for every token on the planet? The way the SecurIDs were designed, there was not way to plug into them, so there was no way to program them. So when you bought a batch you entered each serial number into your RSA auth server, which phoned home, and got the seed/secret. Huge single point of failure. TOTP (and HOTP before it) has a shared secret between the auth server and the token (software), but if Company X is hacked they don't get the secrets to Company Y: * https://en.wikipedia.org/wiki/Time-based_One-Time_Password https://en.wikipedia.org/wiki/Time-based_One-Time_Password
- mrandish 5y ago> but why did there have to be a central server with the shared secret for every token on the planet? Yeah, this struck me as a huge flaw. The breached system was used to create CDs full of IDs for customer deployment. For convenience the manufacturing system was almost but not fully air gapped. They retained the ID data in case the customer needed a copy in the future. However, keeping all of the IDs ever made on one system seems crazy. If they had just deleted the data after backing it up to discrete offline media every week...
- mcfedr 5y agoIt's great that the system that was printing CDs somehow had to be internet connected, it's not like they are emailing these keys
- benlivengood 5y ago> If they had just deleted the data after backing it up to discrete offline media every week... Data loss probably scared them more than risk of breach. The real failure, after all, was not having the system actually airgapped. Aside from electromagnetic leakage through the power system there isn't much difference between spinning disks and tapes if they're not connected to anything else.
- fmajid 5y agoBoth HOTP and TOTP are vulnerable to phishing, unlike U2F.
- throw0101a 5y ago"Perfect is the enemy of good." I'll take whatever improvements I can get in security.
- ianhawes 5y agoAnd a wise business decision since you would also benefit from having to replace the client's fobs in the event that they lost their seeds.
- wolverine876 5y agoI would lose trust if I found out that they retained copies of my private cryptographic data. Isn't that shocking in a company as sophisticated as RSA?