Linked by HAL2001 on Sun 20th Mar 2011 08:57 UTC
Thread beginning with comment 467075
To view parent comment, click here.
To read all comments associated with this story, please click here.
To view parent comment, click here.
To read all comments associated with this story, please click here.
RE[2]: Levelling the playing field
by umccullough on Mon 21st Mar 2011 05:06
in reply to "RE: Levelling the playing field"
"Worst case, whatever had been "stolen" from RSA as a result of the breach can't be any worse than if one had used an Open Source solution in the first place.
The worst case is that the entire SecurID system is compromised and rendered useless. Much worse than using an OSS solution in the first place, not to mention that it would probably be the end of RSA. Maybe that's why they're trying to tone it down. "
Yeah, that was a poor choice of words on my part
Per your previous reply, that's scary. I would have thought, like RSA encryption itself, that methods used in SecurID was understood by the security community in general.
As for the "pre-determined random number" - I know what they're trying to suggest - but you're right, totally non-random. Sounds like pseudo-random with a specific key on every token, combined with a timestamp to seed with - at least that's my best-guess of the basic premise after seeing how they work.




Member since:
2005-08-18
The worst case is that the entire SecurID system is compromised and rendered useless. Much worse than using an OSS solution in the first place, not to mention that it would probably be the end of RSA. Maybe that's why they're trying to tone it down.