SecurID problem

NY Times

If you’ve ever worked for a company or government agency that has sensitive information, you probably know what SecurID is. It’s a small device issued to you that has a display with a number that changes once a minute. When you login to your account, in addition to entering your userid and password, you have to type in the number. The number (based on the time and a key generator) is compared to what the display should be showing, and only lets you in if the numbers match.

This does two important things – a thief who steals your password still can’t login unless he is in possession of the SecurID card. Stealing the SecurID card does not tell the thief what account it unlocks. A secondary purpose is non-repudiation – the account holder can’t get off the hook by saying “someone must have figured out my password – it wasn’t me!”

According to the story, RSA has notified the Federal Goverment and its customers that the system has been compromised. The people who are in a position to speculate guess that the root key has been cracked or lost – that would mean if someone had a keylogger or logged in through open WiFi – the capture of a single login would enable a bad guy then to generate the key without the physical device.

The attack is described as extremely sophisticated – which implies it probably is a government entity that broke the key. It’s a very short list of countries capable of doing that. Libya is not on that list.

About Art Stone

I'm the guy who used to run StreamingRadioGuide.com (and FindAnISP.com).
This entry was posted in Uncategorized. Bookmark the permalink.