web analytics
Salı, Haziran 30, 2026
No Result
View All Result
  • Giriş
Türk İnternet
  • Ana Sayfa
  • BİLİŞİM
  • e-TİCARET
  • INTERNET
  • TELEKOM
  • YENİ TEKNOLOJİLER
  • Hakkımızda
  • Kişisel Verilerin Korunması
    • Çerez Aydınlatma Metni
    • İlgili Kişi Başvuru Formu
No Result
View All Result
  • Ana Sayfa
  • BİLİŞİM
  • e-TİCARET
  • INTERNET
  • TELEKOM
  • YENİ TEKNOLOJİLER
  • Hakkımızda
  • Kişisel Verilerin Korunması
    • Çerez Aydınlatma Metni
    • İlgili Kişi Başvuru Formu
No Result
View All Result
Türk İnternet
No Result
View All Result

RSA Hack: Don’t Panic, Keep Calm

Analyst warn against overly hasty reactions to biggest security breach in IT history – corporations should adopt necessary organizational and technical measures sooner rather than later.

turk-internet.com Staff-turk-internet.com Staff
10 Haziran 2011
-Genel
0
Facebook'ta PaylaşTwitter'da PaylaşLinkedin'de Paylaş

Duesseldorf June 10th, 2011 – Following the successful hacking attack against EMC Corp’s RSA Security Division in March of this year, and especially since news of subsequent attacks against large military contractors such as Lockheed Martin, L-3 and Northrop Grumman, which seem to have been based on data stolen from RSA, companies and organizations around the world that use the popular RSA “SecurID” token system are both confused and worried. They are demanding to know whether they can still trust the system and what they are supposed to do now that every SecurID token must be considered potentially compromised.

In an advisory note just published by KuppingerCole, the analyst group warns against panic and hasty decisions. There are measures organizations can adopt, both short and long term that can keep sensitive systems and information safe without going to radical extremes such as throwing out SecurID altogether and replacing it with some other strong authentication systems, a course which is simply not an option in most cases, both for logistical and cost reasons.

“This is clearly the most serious security breach in the history of information technology, and customers are right to be extremely worried”, says Martin Kuppinger, Lead Analyst and Co-Founder of KuppingerCole, a group of identity and security analysts based in Duesseldorf and Boston. “However, there are measures, both organizational and technical, that must be swiftly taken because one thing is eminently clear: We are dealing with some very, very sophisticated hackers here”, he believes.

On the organizational side, Kuppinger recommends raise user awareness to the dangers of revealing passwords to anyone, anytime! Hackers today use so-called “social attacks” such as spear phishing to target individual employees within an organization by disguising themselves as system administrators or members of the IT department and coaxing them into handling them their authentication data. This, together with the stolen Token IDs from RSA, would give the hacker potentially unlimited access to an organization’s IT systems. Additionally, users should be ordered (or persuaded, if enforcement is impossible) to switch to stronger passwords. Kuppinger also recommends Intensify logging and auditing of user activity whenever SecurID tokens are involved. “Of course, you should be doing this anyway”, Martin Kuppinger believes, “but at least there is now a good excuse in case the bean counters object to the extra expense.”

On the technical side, KuppingerCole recommends replace existing SecurID tokens as soon as possible. RSA has already started offering token replacement to its customers. The new token IDs may be assumed to be secure since their token IDs weren’t on the servers at RSA when they were compromised. Adding additional passwords or other types of secrets as additional means for authentication may be an option in some cases.

Where this is not feasible, KuppingerCole suggests shutting down RSA SecurID and blocking off the access paths that these tokens secure. Admittedly, this is a radical step and one that might not work everywhere in practice. In some cases such as remote desktop access, replacing SecurID with (secure) web-based interfaces using username and strong password for authentication could be an option, at least for the interim. Another idea might be to switch to certificate-based protection of laptop access in cases where this can be rolled out quickly or is available anyway.

In the long term, organizations must rethink their basic strategies regarding strong authentication, Martin Kuppinger maintains. “Versatility should be the cornerstone of any new authentication strategy”, he says. This means the ability to switch flexibly between authentication mechanisms as need arises. Too often today, authentication technology is built into each and every application by hard-coding the interface to that mechanism. Versatile authentication, by contrast, is based on the concept of intermediation. It should be a standard feature today.

By de-coupling authentication from the applications themselves, KuppingerCole believes, it becomes much simpler to exchange authentication mechanisms, enabling organizations can react faster if a mechanism becomes too expensive or security problems such as those arising from the RSA hack are detected.

Etiketler: HaberManşet

Türk İnternet'ten buna benzer yazılar için bildirim almak ister misiniz?

ABONELİKTEN ÇIK
turk-internet.com Staff

turk-internet.com Staff

Lütfen yorum yapmak için giriş yapın.

GÜNLÜK BÜLTEN ABONELİĞİ

Aboneliğinizi onaylamak için gelen veya istenmeyen posta kutunuzu kontrol edin.

HAFTANIN ÖNE ÇIKANLARI

  • St. Petersburg Forumu, Rusya’nın Yeni Teknoloji Stratejisinin Sinyallerini Veriyor: Nadir Toprak Elementleri, Yapay Zeka, Yarı İletkenler ve Teknolojik Egemenlik
  • Türkiye Yapay Zeka Stratejisinde Yeni Dönem: Dijital Egemenlik Merkeze Yerleşti, Peki Bu Yeterli mi?
  • Teknoloji Girişimlerini İlgilendiren Yeni Düzenlemeler Yürürlükte
  • Washington Yapay Zekada Yavaşlatma Yerine Hızlanmayı Seçti: Yeni ABD Yapay Zeka Doktrini ve Riskleri
  • Dijital Dönüşüm ve Gazeteciliğin Küresel Krizi

HAFTANIN KELİMESİ

3GPP

3. Nesil Ortaklık Projesi (3GPP), dünya çapında çeşitli mobil (hücresel) ve telekomünikasyon standartlarını geliştiren ve sürdüren bir grup standart kuruluşudur.

3G ile birlikte kurulmuş ve telekom endüstrisinin Birleşmiş Milletleri diye tanımlanabilir. Sonraki nesiller için de standartları belirlemiştir.

Detayı için Wiki-Turk'e bakınız

İNTERNET HIZI

Türkiye'nin İnternet Hızlarını Dünya ile KarşılaştırmakKaynak : https://www.speedtest.net/global-index#mobile
Facebook Twitter LinkedIn

Bildirimler

Turk-internet.com masaüstü bildirimlerini almak için lütfen buraya tıklayın

Son Yorumlar

  • ICANN, Yeterince Temsil Edilmeyen Toplulukları Yeni gTLD Başvuru Destek Programı İle Güçlendiriyor için Tolga Kaprol
  • BTK, Yabancı e-SIM Firmalarını Engelledi için Bulent SEN
  • Sahibinden.com Domain’inin Güncellenmesi Unutulmuş için Tolga Kaprol
  • İngiliz Düzenleyici Ofcom, Bulut Servislerini ve Akıllı Cihaz Pazarını Soruşturuyor için Tolga Kaprol
  • Seçim Yaklaşırken, Kişisel Veriler Kötüye Nasıl Kullanılır? için [email protected]

Türk İnternet'ten ilginize çekecek yazılar için bildirim almak ister misiniz?

Abone Ol

© Copyrights 2000-2025 - Bu sitede yayınlanan haber/söyleşi/makale ve bilgilerin tüm hakkı turk-internet.com'a aittir.

Tekrar Hoşgeldiniz!

Aşağıdan hesabınıza giriş yapınız

Şifremi unuttum?

Şifrenizi geri alın

Lütfen şifrenizi resetlemek için kullanıcı adı veya email adresinizi girin.

Giriş yap
No Result
View All Result
  • Ana Sayfa
  • BİLİŞİM
  • e-TİCARET
  • INTERNET
  • TELEKOM
  • YENİ TEKNOLOJİLER
  • Hakkımızda
  • Kişisel Verilerin Korunması
    • Çerez Aydınlatma Metni
    • İlgili Kişi Başvuru Formu

© Copyrights 2000-2025 - Bu sitede yayınlanan haber/söyleşi/makale ve bilgilerin tüm hakkı turk-internet.com'a aittir.