|
|
|
|
|
by jvdh
5494 days ago
|
|
Quote from the article: Sources close to RSA tell Ars that the March breach did indeed result in seeds being compromised. The algorithm is already public knowledge. As a result, SecurID offered no defense against the hackers that broke into RSA in March. For those hackers, SecurID was rendered equivalent to basic password authentication, with all the vulnerability to keyloggers and password reuse that entails. So they got a lot of the seeds and then were basically down to trial and error, similar to know passwords. |
|
One would have hoped that the LMC admins would have detected a brute force attack against their RSA servers, I guess they were already infested with keyloggers?