If you’ve ever worked for a company or government agency that has sensitive information, you probably know what SecurID is. It’s a small device issued to you that has a display with a number that changes once a minute. When you login to your account, in addition to entering your userid and password, you have to type in the number. The number (based on the time and a key generator) is compared to what the display should be showing, and only lets you in if the numbers match.
This does two important things – a thief who steals your password still can’t login unless he is in possession of the SecurID card. Stealing the SecurID card does not tell the thief what account it unlocks. A secondary purpose is non-repudiation – the account holder can’t get off the hook by saying “someone must have figured out my password – it wasn’t me!”
According to the story, RSA has notified the Federal Goverment and its customers that the system has been compromised. The people who are in a position to speculate guess that the root key has been cracked or lost – that would mean if someone had a keylogger or logged in through open WiFi – the capture of a single login would enable a bad guy then to generate the key without the physical device.
The attack is described as extremely sophisticated – which implies it probably is a government entity that broke the key. It’s a very short list of countries capable of doing that. Libya is not on that list.