Submission + - Researchers Can Generate RSA SecurID Random Numbers Flawlessly (arstechnica.com)
Fluffeh writes: "A researcher has found and published a way to tune into a RSA SecurID Token. Once a few easy steps are followed anyone can generate the exact numbers shown on the token. The method relies on finding the seed that is used to generate the numbers seemingly randomly, but once known can be used to generate the exact numbers displayed on the targetted Token. The technique, described on Thursday by a senior security analyst at a firm called SensePost, has important implications for the safekeeping of the tokens. An estimated 40 million people use these to access confidential data belonging to government agencies, military contractors, and corporations. Scrutiny of the widely used two-factor authentication system has grown since last year, when RSA revealed that intruders on its networks stole sensitive SecurID information that could be used to reduce its security. Defense contractor Lockheed Martin later confirmed that a separate attack on its systems was aided by the theft of the RSA data."