The Main Street Journal
May 24, 2013, 09:44:34 PM *

Login with username, password and session length
French German Italian Dutch Spanish Portuguese Korean Chinese Simplified Japanese Greek Arabic Russian
News: Enjoy and post your your articles. Have fun in with the entertainment features.
 
  Home   Forum   Help Search Blog Shop Media Posts Tags Login Register  
Featured | Topics | Op-Ed | Media | Chat | MSJ+ | Videos | Music | Games | ShuttlePop | Cognition Factor | Alex Karamanis | Healing |


+ The Main Street Journal » Forum » News » Science and TechnologyTopic:
|- March RSA Hack Hits Lockheed, Remote Systems Breached

Login with username, password and session length




Pages: [1]   Go Down
  Print  
Author Topic: March RSA Hack Hits Lockheed, Remote Systems Breached  (Read 109 times)
0 Members and 1 Guest are viewing this topic.
KB723
Guest
« on: May 28, 2011, 01:51:24 PM »
ReplyReply

A March attack on RSA's SecurID authentication service has possibly claimed its first big victim: Lockheed Martin.

According to a source speaking to Reuters, unknown hackers have broken into Lockheed Martin's security systems by using duplicate SecurID tokens to spoof legitimate authentications into the network. These SecurID tokens are analogous to Blizzard's World of Warcraft Authenticators: Tiny little keyfobs that display an ever-changing code one must enter to log into a protected service.

Lockheed hasn't issued comment on alleged breach itself, leading only to speculation as to what data, if any, those breaching the company's network were able to acquire. But the plunder could be vast: Lockheed is the nation's largest military contractor, and it undoubtedly has treasure troves of data about existing and future weapons systems as well as information related to the various cybersecurity services the company provides.

Classified information is likely out of hackers' hands: Due to the volume of attacks that these kinds of systems on a daily basis, it's highly doubtful that Lockheed—or any security contractor—would keep top-secret information within reach, should one ever breach the remote access gates.

"To counter any threats, we regularly take actions to increase the security of our systems and to protect our employee, customer and program data," said Lockheed spokesman Jeffery Adams in an interview with the Wall Street Journal. "We have policies and procedures in place to mitigate the cyber threats to our business, and we remain confident in the integrity of our robust, multilayered information systems security."

According to a source, once Lockheed was made aware of the attack, the company began instigating new security measures to prevent future breaches. These included shutting down some of the company's remote access capabilities on its systems, as well as a new order for 90,000 replacement SecurID tokens for the company's employees. Users were also asked to change their passwords company-wide.

So how did the hackers do it? It's been speculated that hackers obtained master key files during the March RSA attacks—as implied, a hacker then would be able to penetrate a SecurID-protected network by replicating an individual's exact keys generated by the particular device.

An anonymous source confirmed this fact to Reuters. But, for semi-obvious reasons, neither EMC–RSA's parent company–nor most other security contractors are commenting about anything related to RSA's breach, including any additional safeguards they might have put in place since news of the attacks broke.

According to officials, RSA and other companies have produced around 250 million security tokens in total. RSA has been briefing its customers on how to better secure their networks in the aftermath of the March attack.

For more from David, follow him on Twitter @TheDavidMurphy.


For the top stories in tech, follow us on Twitter at @PCMag.




* COMPUTER.jpg (47.6 KB, 150x150 - viewed 10 times.)
« Last Edit: May 28, 2011, 01:52:50 PM by KB723 »

Logged
 
ArthurDent
Jr. Member
**

Vote: +27/-0
Offline Offline

Posts: 64
2680.00 credits

View Inventory
Send Money to ArthurDent
Join Date: Jun, 2011



« Reply #1 on: June 07, 2011, 10:31:24 AM »
ReplyReply

I have a buddy who works there and he's worked 24/7 through the breach cycle.  The real problem for there IT guys was all the system restores.
Logged
KB723
Guest
« Reply #2 on: June 07, 2011, 01:41:26 PM »
ReplyReply

The real problem for there IT guys was all the system restores.
Hey Cool, Thanks, I would have never known that... =)
Logged
ArthurDent
Jr. Member
**

Vote: +27/-0
Offline Offline

Posts: 64
2680.00 credits

View Inventory
Send Money to ArthurDent
Join Date: Jun, 2011



« Reply #3 on: June 08, 2011, 06:22:44 PM »
ReplyReply

You take a system down you have to run all the usual diagnostics and then bring them online and then they had to validate all their users per system.  100K employees.  BRUTAL.
Logged
KB723
Guest
« Reply #4 on: June 08, 2011, 09:14:09 PM »
ReplyReply

system.  100K employees.  BRUTA
You take a system down you have to run all the usual diagnostics and then bring them online and then they had to validate all their users per system.  100K employees.  BRUTAL.
''

I learn something new every time you reply... Thanks... =)
Logged
Tags: lockheed nationalsecurity hackers 
Pages: [1]   Go Up
  Print  

+ The Main Street Journal » Forum » News » Science and TechnologyTopic:
|- March RSA Hack Hits Lockheed, Remote Systems Breached

Login with username, password and session length

 
Jump to:  

* Share this topic...
In a forum
(BBCode)
In a site/blog
(HTML)


+- IMPORTANT INSTRUCTIONS
Untitled Document
IMPORTANT - READ ME!!
To use the Quick Reply is easy, just type and click "Post". If you prefer the full editor, just type anything for example an "a" and click preview. This will open the full editor. If you wish to send a PM just click the "Change to Quick PM" link on the right of the "Quick Reply" bar.  
+- Topic Discussion
blog comments powered by Disqus
Powered by EzPortal
Powered by MySQL Powered by PHP Powered by SMF | SMF © 2013, Simple Machines
Valid XHTML 1.0! Valid CSS!

Bad Behavior has blocked 341 access attempts in the last 7 days.