TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Scientists crack RSA SecurID 800 tokens, steal cryptographic keys

116 pointsby alsothingsalmost 13 years ago

5 comments

moonbootsalmost 13 years ago
Direct link to researcher's blog post about the exploit: <a href="http://blog.cryptographyengineering.com/2012/06/bad-couple-of-years-for-cryptographic.html" rel="nofollow">http://blog.cryptographyengineering.com/2012/06/bad-couple-o...</a>
评论 #4157185 未加载
andrewaylettalmost 13 years ago
Note that this is the 800 token, with a USB port, and it's the USB bit that's been broken, not the six-digit ID part that people usually associate with SecurID. My understanding is that the USB port enables the token to sign data on demand, and it's this signing key that's been compromised -- not just for SecurID, but for a whole range of similar encryption tokens.
评论 #4157282 未加载
ajrossalmost 13 years ago
The title is correct, but misleading if you don't know the product. "RSA SecurID" is the name of a two-factor authentication product from RSA Security. This isn't a crack of RSA, what they did is pull private keys out of a "secure" device.<p>(<i>Edit: never mind, it looks like it's a chosen plaintext attack against the RSA on the device, not a direct hack. So yeah, this is cryptographically impressive. It looks like they're exploiting a bad padding protocol?</i>)
评论 #4157496 未加载
gourangaalmost 13 years ago
When we start shipping revokable 64gb compressed one time pad data sticks, I'll have some faith in crypto.<p>Until then, one eye always open.
评论 #4157504 未加载
评论 #4157500 未加载
zokieralmost 13 years ago
Reducing number of iterations by two orders of magnitude is quite impressive. But I don't like how one product is singled out when the attack seems rather generic.