RSA SecureID software token update
ID: a09dc0d9-3031-58c7-b3c4-2195032703fa
STIX ID: report--a09dc0d9-3031-58c7-b3c4-2195032703fa
Feed Name: SensePost Blog
SensePost research describes two design weaknesses in RSA SecurID software tokens: (1) a token-binding bypass that allows an attacker who obtains a user’s token configuration file and initial password to import and use the token elsewhere, and (2) the broader issue that software tokens storing secret seeds on general-purpose OS/storage can be cloned or stolen (via DPAPI replication or API hooking). The report explains exploitation methods, discusses smartphone differences, and recommends hardware-backed or trusted-execution protections.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
