• We’re currently investigating an issue related to the forum theme and styling that is impacting page layout and visual formatting. The problem has been identified, and we are actively working on a resolution. There is no impact to user data or functionality, this is strictly a front-end display issue. We’ll post an update once the fix has been deployed. Thanks for your patience while we get this sorted.

RSA attacked, SecurID possibly compromised

I suspect that either

1) A private key that is used to create SecurID hashes was stolen or reverse engineered

or

2) Someone was able to dump the internal Serial->Tokencode database from their internal systems.

in case #1, it seems the risk requires someone to steal your internal database, or perhaps somehow generate the private key via the serial number.

I suspect #2 is more accurate, which means that an attacker still has to know your serial number AND your PIN, but the security of the system is still substantially compromised.

I am interested to see if the DoD or other groups soon ban the use of SecurID, or require new tokens to be purchased, due to this compromise.
 
Back
Top