Home / Blogs

RSA Breach Fallout?

Steven Bellovin

Back in March, it was widely reported that RSA had suffered a serious security breach that (to some extent) weakened the security of its SecurID token. However, the NY Times reported then that the chairman said that the penetration wasn't absolute but "it could potentially reduce the effectiveness of the system in the face of a 'broader attack.'".

That broader attack may now have happened. Press reports say that Lockheed Martin was attacked, possibly by someone exploiting the RSA penetration.

This incident reveals the dangers of companies like RSA not being open about security incidents. Many companies (and many government agencies) have long relied on SecurID tokens. Without details about the problem, though, it is unclear how they should protect themselves. Get new tokens? Change employee PINs? Firewall off the administrative servers? We don't know — and that's the real problem.

(I confess that it isn't clear to me just what RSA is protecting by not revealing details of the danger. Its own reputation? That suffered a big hit in March. Its product sales? They might drop very sharply now, since it seems that even a sophisticated customer couldn't protect itself following the breach. What attack was enabled by the stolen data? If the RSA penetration really was an "advanced persistent threat", as they claimed at the time, the attackers certainly had the skills to discover that on their own even if they hadn't known it already.)

The really interesting question is what proper response is. Should companies be required to disclose problems that could adversely affect their customers? Are companies that do not make such disclosures civilly liable if harm could be prevented by timely disclosure? If they aren't liable, should they be? It is past time, I think, for such a discussion to take place.

By Steven Bellovin, Professor of Computer Science at Columbia University. Visit the blog maintained by Steven Bellovin here.

Related topics: Cyberattack, Policy & Regulation, Security

WEEKLY WRAP — Get CircleID's Weekly Summary Report by Email:

Comments

To post comments, please login or create an account.

Related Blogs

Related News

Topics

Industry Updates – Sponsored Posts

Nominum Launches 1st Comprehensive Mobile Security Solution That Protects Both Network and End User

Frontline and Nominum Deliver Integrated DNS-Based Platform to Enhance Enterprise Security

Nominum Launches Comprehensive Suite of DNS-Based Security Solutions for Russian Service Providers

Nominum Sets New Record for Network Speed and Efficiency

Implementing a Cyber-Security Code of Conduct: Real-Life Lessons From Australia (Webinar)

DDoS Attacks: Top 10 Trends and Truths (Video)

Internet Governance Update: Battle Royale Is Here

DotConnectAfrica Participates at ICANN 43 In Costa Rica, the "Rich Coast"

DDoS Attacks: Top Trends and Truths (Webinar)

Sedari Seeking Certainty in the ICANN TLD Process

Internet Grows to More Than 225 Million Domain Names in the Fourth Quarter of 2011

Neustar UltraDNS Basic Launches Add-On Services for Website Monitoring and DNS Server Failover

Neustar And Arbor Networks Cloud Signaling Coalition to Stop Evolving DDoS Threat to Data Centers

Nominum Launches World's First Purpose-Built Suite of DNS‐Based Solutions for Mobile Operators

MarkMonitor Fraud Intelligence Report, Q4 2011

MarkMonitor to Exhibit at Internet Tech Policy Exhibition and Reception to be Held on Capitol Hill

Verisign to Award New Infrastructure Research Grants

Nixu SNS 2.5 Series Gives Fresh Views on DNS

Afilias Says "No" to SOPA

Breaking the DNS: Another Look at How SOPA Could Be Destructive

Hot Topics

Neustar UltraDNS

DNS

Sponsored by
Neustar UltraDNS
Afilias

DNS Security

Sponsored by
Afilias
Minds + Machines

Top-Level Domains

Sponsored by
Minds + Machines
Nominum

IPv6

Sponsored by
Nominum
Verisign

Security

Sponsored by
Verisign
dotMobi

Mobile

Sponsored by
dotMobi