All the latest UK technology news, reviews and analysis

RSA warns customers of sophisticated security breach

by Iain Thomson

18 Mar 2011

Comment: 1

  • Tweet this

RSA is warning its customers that the company has suffered a security breach after hackers sought out details on its SecureID system.

In an open letter to customers, Art Coviello, RSA's former chief executive and current executive chairman, warned that an Advanced Persistent Threat (APT) attack had partially succeeded in getting into RSA's confidential systems.

So far the intrusion seems to be limited to the SecureID software but customers are warned to be on their guard. Coviello said that other EMC corporate systems had not been breached.

"While at this time we are confident that the information extracted does not enable a successful direct attack on any of our RSA SecurID customers, this information could potentially be used to reduce the effectiveness of a current two-factor authentication implementation as part of a broader attack," he said.

"We are very actively communicating this situation to RSA customers and providing immediate steps for them to take to strengthen their SecurID implementations."

The SecureID system is used by over 20,000 corporations and banking companies to provide two-factor authentication. Software generates seemingly random numbers of a hardware token or software tool and those are synchronised with a central server to provide login identification.

The term APT refers to a combination attack that uses hacking, social engineering and more traditional espionage to breach security systems over an extended period. Experts acknowledge that such attacks are impossible to defeat over time.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

Flame virus poll

Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?

35%

0%

10%

55%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Symanteccloud

Social networking: a guide for IT managers

Social networking is almost ubiquitous. This white paper examines the benefits and risks and it looks at the different ways companies can reconcile them

Riverbed

Mitigating the risks of IT change

The importance of understanding your infrastructure

Flash Developer- actionscript, AJAX, JSON

Flash Developer- Actionscript 3.0, AJAX, JSON, computer...

Business Analyst, Risk platform, Equity Derivs, Investment Bank

Business Analyst - Risk platform - Equity Derivatives...

Java Developer - Algorithmic Trading - Global Trading Business

Java Developer - Algorithmic Trading - Global Trading...

Junior Treasury Project Manager, Tier One Investment Bank

Junior Middle Office Project Manager, Treasury, IB...

To send to more than one email address, simply separate each address with a comma.