<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>AllThingsD &#187; Art Coviello</title>
	<atom:link href="http://allthingsd.com/tag/art-coviello/feed/" rel="self" type="application/rss+xml" />
	<link>http://allthingsd.com</link>
	<description></description>
	<lastBuildDate>Sat, 11 Feb 2012 15:49:25 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
<atom:link rel="hub" href="http://pubsubhubbub.appspot.com"/><image>
		  <url>http://allthingsd.com/theme/images/logo-rss.jpg</url>
		  <title>All Things Digital</title>
		  <link>http://allthingsd.com/</link>
		  <width>144</width>
		  <height>22</height>
	</image>		<item>
		<title>SecurIDs Come Under Siege</title>
		<link>http://allthingsd.com/20110606/securids-come-under-siege/</link>
		<comments>http://allthingsd.com/20110606/securids-come-under-siege/#comments</comments>
		<pubDate>Tue, 07 Jun 2011 00:36:45 +0000</pubDate>
		<dc:creator>Siobhan Gorman and Shara Tibken</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Voices]]></category>
		<category><![CDATA[Art Coviello]]></category>
		<category><![CDATA[EMC]]></category>
		<category><![CDATA[intruders]]></category>
		<category><![CDATA[Lockheed Martin]]></category>
		<category><![CDATA[RSA Security]]></category>
		<category><![CDATA[SecurID]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://allthingsd.com/?p=83453</guid>
		<description><![CDATA[RSA Security is offering to replace its well-known SecurID tokens--devices used by 40 million corporate workers to securely log on to their computers--"for virtually every customer we have," the company's chairman, Art Coviello, said in an interview.]]></description>
			<content:encoded><![CDATA[<p>RSA Security is offering to replace its well-known SecurID tokens&#8211;devices used by 40 million corporate workers to securely log on to their computers&#8211;&#8221;for virtually every customer we have,&#8221; the company&#8217;s chairman, Art Coviello, said in an interview.</p>
<p>In a letter to customers Monday, the EMC Corp. unit openly acknowledged for the first time that intruders had breached its security systems at defense contractor Lockheed Martin Corp.</p>
<p><a href="http://online.wsj.com/article/SB10001424052702304906004576369990616694366.html">Read the rest of this post on the original site »</a></p>
]]></content:encoded>
			<wfw:commentRss>http://allthingsd.com/20110606/securids-come-under-siege/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>RSA Under &quot;Extremely Sophisticated&quot; Attack; Yes, That Includes Those Tokens</title>
		<link>http://allthingsd.com/20110317/rsa-under-extremely-sophisticated-attack-yes-the-tokens-are-involved/</link>
		<comments>http://allthingsd.com/20110317/rsa-under-extremely-sophisticated-attack-yes-the-tokens-are-involved/#comments</comments>
		<pubDate>Fri, 18 Mar 2011 00:15:41 +0000</pubDate>
		<dc:creator>Arik Hesseldahl</dc:creator>
				<category><![CDATA[Enterprise]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[advanced persistent threat]]></category>
		<category><![CDATA[Arik Hesseldahl]]></category>
		<category><![CDATA[Art Coviello]]></category>
		<category><![CDATA[EMC]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[information secrity]]></category>
		<category><![CDATA[NewEnterprise]]></category>
		<category><![CDATA[RSA]]></category>
		<category><![CDATA[script kiddie]]></category>
		<category><![CDATA[SecurID]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[security feature]]></category>

		<guid isPermaLink="false">http://newenterprise.allthingsd.com/?p=4110</guid>
		<description><![CDATA[Security company RSA has disclosed an attack on its systems. Data regarding its SecurID tokens, widely used by companies and governments, was taken.]]></description>
			<content:encoded><![CDATA[<p><img src="http://newenterprise.allthingsd.com/files/2011/03/RSA_SecurID_SID800-275x130.jpg" alt="" title="RSA_SecurID_SID800" width="275" height="130" class="alignright size-medium wp-image-4111" />Security company RSA today disclosed what it described as an &#8220;extremely sophisticated attack&#8221; against its technology. The disclosure came in a <a href="http://www.rsa.com/node.aspx?id=3872">blog post by Art Coviello</a>, the former RSA CEO who saw the company through its 2006 acquisition by EMC.</p>
<p>Coviello didn&#8217;t disclose many details about the attack, but said the attackers were able to extract some information about the company&#8217;s SecurID products. The backbone of the SecurID system is the keychain-sized tokens like the one pictured that generate a new number every 30 seconds or so, and used to log in to computer networks and other systems. The tokens and software that generates numbers in the same way on smart phones are widely used by corporations and governments to keep attackers out. As of 2009, RSA estimated that 40 million people used the tokens and another 250 million used RSA software on their smart phones.</p>
<p>Coviello said that so far it doesn&#8217;t look like the SecurID system has been compromised. But the information taken by the attackers could make an attack that would compromise it somewhat easier. &#8220;While at this time we are confident that the information extracted does not enable a successful direct attack on any of our RSA SecurID customers, this information could potentially be used to reduce the effectiveness of a current two-factor authentication implementation as part of a broader attack,&#8221; he wrote. &#8220;We are very actively communicating this situation to RSA customers and providing immediate steps for them to take to strengthen their SecurID implementations.&#8221;</p>
<p>RSA has classified the attack as an &#8220;Advanced Persistent Threat&#8221; which in security industry parlance means it&#8217;s sophisticated enough that it may require the resources of a nation state to carry out, though the phrase is often met with mild derision by security professionals. As one put it, APT is another way of saying &#8220;<a href="http://twitter.com/thierryzoller/statuses/48514483492102144">not attacked by a script kiddie</a>.&#8221;</p>
<p>It remains to be seen exactly how significant this incident will prove to be over the long term. As one security expert put it to me, if algorithm used to generate the numbers displayed by the token is compromised in any way, confidence in the SecurID system will plummet, and the cost to RSA and EMC could be serious. Not only will there be the cost to replace all those tokens, but work will have to be done to change the software algorithm used to generate the numbers. Neither will be inconsequential. EMC shares finished the day up 25 cents or nearly 1 percent, but are falling slightly in after-hours trading as the news about this attack has come to light.</p>
]]></content:encoded>
			<wfw:commentRss>http://allthingsd.com/20110317/rsa-under-extremely-sophisticated-attack-yes-the-tokens-are-involved/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>

