SecurID Customers Advised To Prepare For Worst Case

  /     /     /  
Publicated : 22/11/2024   Category : security


SecurID Customers Advised To Prepare For Worst Case


EMCs RSA hasnt detailed exactly what was stolen, so security experts advise the authentication systems customers to implement a more layered network defense.



(click image for larger view)
Slideshow: 10 Massive Security Breaches
How serious is the security threat posed by the theft of inside information about SecurID, the two-factor authentication system sold by EMC division RSA? It is important enough that it required an official note to the stock markets, said Martin Kuppinger, founder and principal analyst at KuppingerCole, in a
blog post
.
But, despite the apparent severity of the breach, RSAs failure to detail what was stolen is generating an immense amount of
customer frustration
, because they dont know if their SecurID hardware fobs are still secure, or if they might provide attackers with a conduit through enterprise defenses.
Heres the worst-case scenario: The worry is that source code to the companys SecurID two-factor authentication product was stolen, which would possibly allow hackers to reverse-engineer or otherwise break the system, said Bruce Schneier, chief security technology officer of BT, in a
blog post
. In that case, attackers could spoof SecurID to access corporate systems.
Until RSA coughs up
more information
, security experts advocate conducting a thorough and immediate SecurID risk assessment. Our recommendation for customers which have RSA SecurID cards implemented is to first carefully analyze the situation and their specific risks -- [for example] which type of information is at risk if the RSA SecurID-based authentication is not only at risk -- like now -- but an attack actually takes place? said Kuppinger.
Next, identify specific technologies and remediation activities for securing at-risk data or accounts. These actions might range from increased threat analysis and forensics to adding other authentication technologies, said Kuppinger.
But rather than just shopping for a SecurID replacement, numerous experts are recommending that security managers turn this situation into an opportunity to create a more layered security defense. Many organizations rely too heavily on two-factor authentication and they have historically seen it as a silver bullet, said William Beer, PricewaterhouseCoopers (PwC) director of OneSecurity, in an emailed statement.
Stay tuned for more details about the extent of the attacks, their effect on RSA, and the security and IT management ramifications for their customers. RSA Data Security, Inc. is probably pretty screwed if SecurID is compromised, said BTs Schneier. Those hardware tokens have no upgrade path, and would have to be replaced.
That would be no small task. RSA had 40 million SecurID hardware token customers by 2009, as well as 250 million users of
SecurID software
.

Last News

▸ Some DLP Products Vulnerable to Security Holes ◂
Discovered: 23/12/2024
Category: security

▸ Scan suggests Heartbleed patches may not have been successful. ◂
Discovered: 23/12/2024
Category: security

▸ IoT Devices on Average Have 25 Vulnerabilities ◂
Discovered: 23/12/2024
Category: security


Cyber Security Categories
Google Dorks Database
Exploits Vulnerability
Exploit Shellcodes

CVE List
Tools/Apps
News/Aarticles

Phishing Database
Deepfake Detection
Trends/Statistics & Live Infos



Tags:
SecurID Customers Advised To Prepare For Worst Case