4 ms·
The end of RSA (the company)? I find it absurd that a security company no less, would hear many veteran cryptographers say this is backdoored a decade ago, and
by salient 13y ago
The end of RSA (the company)? I find it absurd that a security company no less, would hear many veteran cryptographers say this is backdoored a decade ago, and still going ahead and using it - as the default! Who stakes the whole reputation of their company in the field for a meager $10 million (I assume RSA was pretty big back then, too)? It's insane.
RSA, much like NIST, can not, and should not be trusted any longer. All of their customers should be warned, and advised to quit them ASAP. Companies need to learn this is just unacceptable.
- jtbigwoo 13y agoSerious question: Is there an alternative? I've never seen a secure fob that wasn't from RSA.
- ggreer 13y agoI like Yubikeys: https://www.yubico.com/ https://www.yubico.com/. They show up as a USB keyboard, so you don't have to type the codes in. There are some disadvantages. Yubikeys use a shared secret instead of public key crypto. Also, the one-time password is iteration-based, not time-based. On the bright side, you can program Yubikeys with your own secrets. They may not be as secure as properly configured RSA tokens, but they're much better than authing with just a password or client cert.
- beagle3 13y agoYubikey NEO (latest revision) is like the one you already have + a java card that comes with a PGPcard app (and supposedly, you can write your own apps) They don't have a timer like the RSA key fobs, and need a USB or NFC connection - but are generally very reliable, and given their constraints. The questiion, of course, is what reason you have to believe that yubico (and for that matter, gemalto, g10code and the rest) are not similarly in bed with the NSA.
- apaprocki 13y agoTrusting trust :) This is one of, but not the main reasons why we build our own (Bloomberg B-Unit, PDF is the only good pic I see: http://www.bloomberg.com/professional/files/2013/11/b-unit_3_user_guide.pdf http://www.bloomberg.com/professional/files/2013/11/b-unit_3...)
- PhantomGremlin 13y agoQuis custodiet ipsos custodes? Speaking of "trust", Bloomberg lost quite a lot of it when their reporters spied on their customers. Bloomberg Spying Went On For Years After Execs Knew: Report http://www.valuewalk.com/2013/08/bloomberg-spying-went-on-for-years-after-execs-knew-report/ http://www.valuewalk.com/2013/08/bloomberg-spying-went-on-fo... You were probably just as horrified as most of the other employees at Bloomberg when that info became public. The bad apples cost Bloomberg a lot of reputation. My point is that "trust" is very elusive, very easy to lose, very hard to gain. OTOH, are the "bad apples" at Bloomberg who condoned that behavior still in positions of power? Did they even get a slap on the wrist? If I were at Goldman, JPM, Citi, etc. I wouldn't "trust" Bloomberg until I saw some higher up people fall on their sword for that fiasco.
- a3n 13y agoIf I were at Goldman et al. I would expect Bloomberg to treat employees that successfully use underhanded tactics, as business as usual, the same way I would probably have seen such employees (and maybe myself) treated by my own organization: "Job well done boys, but you better cool it for awhile. BWA ha ha ha! Have a cigar and a hooker."
- cschmidt 13y agoFastmail uses the YubiKey for two factor authentication. http://www.yubico.com/ http://www.yubico.com/
- chrislaco 13y agoand LastPass
- Crito 13y agoGemalto.
- Spearchucker 13y agoI've worked with them on a chip and PIN* port from Java to the .Net Micro Framework. Very talented bunch of guys. * My preference anyway to RSA.
- mukyu 13y agoBoth of mine are http://vasco.com http://vasco.com
- MacsHeadroom 13y agoOne of the original developers behind OpenSSH (Dug Song) started a competitor to RSA called Duo Security just a few years ago. They sell Gemalto IDProve 100 tokens and support Yubikey, but advise using their patent pending push based 2FA authentication because: "Login requests are signed with an asymmetric PKCS#1 v1.5 key pair, which provides a stronger identity assertion than passcodes and prevents “RSA-style” breaches." From https://www.duosecurity.com/duo-push https://www.duosecurity.com/duo-push They're used by companies like Facebook, Twitter, Sony, Arbor Networks, MIT, etc. So yes, RSA has some strong competition.
- unsupak 13y agoMaybe the 10M carrot came with even a bigger stick