SecurIDã®å®å ¨æ§ã¯æ¬å½ã«å¤§ä¸å¤«ãªã®ã?
(2011/06/07 æ´æ°) RSAãä»åã®ä»¶ã«ã¤ãã¦å ¬å¼ã«çºè¡¨ããã¾ããããããã¼ãã¸ã®ä¸æ£ä¾µå ¥ã®åå ã«ãªã£ããã¨ãèªãã顧客ã«å¯¾ã㦠SecurIDã®äº¤æãªã©ã«å¿ããææ¡ããã¦ãã¾ãã
ãã®é±æ«ãã¢ã¡ãªã«ã§èµ·ãããããã¼ãã»ãã¼ãã³(Lockheed Martin)ã®ãããã¯ã¼ã¯ã«å¯¾ããä¸æ£ä¾µå ¥ã話é¡ã«ãªã£ã¦ããããããã¼ãã»ãã¼ãã³ã¨ããã°ãã¢ã¡ãªã«ã代表ããä¼æ¥ã®ä¸ã¤ã§ãããF22ã F35ãªã©ã®ææ°éæ©ãéçºãã¦ãããã¨ã§ãæåã§ããã
ãã®ãããã¼ãã§å é±æ«ã«ãããã¯ã¼ã¯ã«å¯¾ãããªã¢ã¼ãããã®ä¸æ£ä¾µå ¥ãèµ·ããããã®ä»¶ãæåã«ä¼ããã®ã¯ Robert X. Cringelyæ°*1ã5/25のブログã§ãããå½é²é¢é£ä¼æ¥ã®è©±ã¨ãã¦ããããã¯ã¼ã¯ã§åé¡ãèµ·ãããã¨ãã¦ã¼ã¶ã¼ã«ãããªã¢ã¼ãã¢ã¯ã»ã¹ãåæ¢ãããã¨ãå ¨ã¦ã®ã¦ã¼ã¶ã¼ã®ãã¹ã¯ã¼ãããªã»ãããããã¨ãSecurIDãæ°é±éã®ãã¡ã«å ¨ã¦æ°ãããã®ã«äº¤æãããã¨ããªã©ã®å 容ãæ¸ããã¦ããããã®æç¹ã§ã¯ãããã¼ãã®ååã¯ä¼ãã¦ãã£ãã®ã ããç¿æ¥ã«ãªãã¨ãã¤ã¿ã¼ããããã¼ãã®ãã¨ã ã¨ãã¦å ±éãããã¾ãä»ã®å½é²é¢é£ä¼æ¥ã§ãåæ§ã®è¢«å®³ãèµ·ãã¦ããã¨ä¼ããããã®å¾ãè¤æ°ã®ã¡ãã£ã¢ãããã«ç¶ãã5/28になるとロッキードも事実として認めるコメントをだしたããã®ä»¶ã®èª¿æ»ã«ã¯ãDoDã¨DHSãååãã¦ããããã ããã¤ã¿ã¼ã¯ãã®å¾ãæ´æ°æ å ±ãä¼ãã¦ããã(ææ°ã®è¨äºã¯こちら)
ãã¦å½é²ã«é¢ããä¼æ¥ã¸ã®ä¾µå ¥ã ããã¢ã¡ãªã«ã«ã¨ã£ã¦ã¯ããã ãã§ã大äºã ããåé¡ã¯ããä¸ã¤ããããããã¼ãã対å¿çã®ä¸ã¤ã¨ã㦠SecurIDãåé å¸ããã¨ã®æ å ±ã *2ããªããã¾ãã«ããä¸æ£ã¢ã¯ã»ã¹ãåããã®ã ã¨ããã¨ãSecurIDãç´å¤±ãã¦æªç¨ããããã¨ãèãããããããããã®å ´åã«ã¯è©²å½ãã SecurIDãç¡å¹ã«ããã°ãããã§ã¯å©ç¨ãã¦ãã SecurIDãå ¨ã¦æ°ããããã®ã¯ä¸ä½ã©ãããããã ããã?
ããã§é¢ä¿ãã¦ããã®ãã3月に起きた RSAへの不正侵入事件ã§ããã3/17ã« RSAã顧客へのレターã§ä¼ããã¨ããã«ããã¨ãä¾µå ¥è 㯠SecurIDã«é¢ä¿ããæ å ±ãä¸æ£ã«å ¥æããã¨ããããã®æç¹ã§ã¯ã©ãããæ å ±ãæµåºããã®ã詳ãã説æã¯ãªãã顧客に対してセキュリティ強化を促す注意喚起をしたã ãã ã£ãããããã»ãã¥ãªãã£ç 究è ã®ä¸ã«ã¯ãSecurIDã®ãã¼ã¯ã³ã³ã¼ããè¨ç®ããã¢ã«ã´ãªãºã ãè¨ç®ã®å ã«ãªãã·ã¼ããã·ãªã¢ã«ãã³ãã¼ã顧客ãªã¹ããªã©ã®éè¦ãªæ å ±ãå ¨ã¦æµåºããå¯è½æ§ãããã®ã§ã¯ãªãããã¨ããææãããã¦ããã(RSAä¾µå ¥äºä»¶ã®å½±é¿ã«ã¤ãã¦ã¯ãSANS㨠SecureWorksã®è§£èª¬ã詳ããã)
ããã§åé¡ãç解ããããã«ãSecurIDã®èªè¨¼ã®ä»çµã¿ã復ç¿ãããã(ã¨ãã£ã¦ããç§ããã£ããå¿ãã¦ããã®ã§ãä»åæ ã¦ã¦èª¿ã¹ç´ããã)
SecurIDã«ã¯ããã¤ã種é¡ãããã*3ããã¼ãã¦ã§ã¢ã¿ã¤ãã®ãã®ã¯ä¾ãã°ãããªæãã
6æ¡ã®æ°åã表示ããå°ããªãã£ã¹ãã¬ã¤ãã¤ãã¦ãã¦ããã®æ°åã¯ä¸å®éé(30ç§ã¾ãã¯60ç§)ãã¨ã«èªåçã«æ´æ°ãããããã®æ°å(ãã¼ã¯ã³ã³ã¼ã)ã¨ã¦ã¼ã¶ã¼ãèªåã§æ±ºãã4æ¡ãã8æ¡ã® PIN (Personal Identification Number)ããããã¦ãã¯ã³ã¿ã¤ã ãã¹ã¯ã¼ããçæãããããã¼ãã¦ã§ã¢ãã¼ã¯ã³ã¨ããç©ççãªããã¤ã¹ã¨(ã½ããã¦ã§ã¢ã®å ´åãããããã ãâ¦)ãPINã®2ã¤ããªããã°ãªããªãã®ã§äºè¦ç´ èªè¨¼ã¨å¼ã°ãããã¾ããçæããããã¹ã¯ã¼ãã¯ä¸åéãã®ãã®ãªã®ã§ãä»®ã«éä¿¡çµè·¯ä¸ã§çè´ããã¦ãåå©ç¨ã¯ã§ããªã*4ã過去15年間に一度もセキュリティ侵害が起きていないã¨ãã RSA社èªæ ¢ã®èªè¨¼ã·ã¹ãã ã§ããã
ãã¼ã¯ã³ã³ã¼ã㯠RSAã®å·¥å ´åºè·æã«è¨å®ãããã·ã¼ãã¨ã·ãªã¢ã«ãã³ãã¼ãããã¦æå»æ å ±ãããããã¢ã«ã´ãªãºã ãç¨ãã¦ç®åºããããåãæ å ±ãèªè¨¼ãµã¼ãã¼å´ã§ãä¿æãã¦ããã®ã§èªè¨¼ãå¯è½ã¨ãªã(ãã¡ããæå»ã®åæã¯å¿ è¦)ãã¢ã«ã´ãªãºã ã¯ä¸è¬ã«å ¬éããã¦ã¯ããªãããå¤ããã SecurIDãã¨ãã¥ã¬ã¼ãããããã°ã©ã ãå ¬éããã¦ãããæ¢ç¥ã¨è¨ã£ã¦ãã*5ãããããããã¢ã«ã´ãªãºã ãããã£ã¦ããéµã¨ãªãæ å ±(ãã®å ´åã¯ã·ã¼ãã¨ã·ãªã¢ã«ãã³ãã¼)ãããããªããã°ã©ããããããªãã
ããä¸ã¤ãå®éã«ãã°ã¤ã³ããæã«ã¯ã¦ã¼ã¶ã¼IDãå¿ è¦ã¨ãªãããããã£ã¦ã©ã®ã¦ã¼ã¶ã¼ãã©ã®ã·ãªã¢ã«ãã³ãã¼ã® SecurIDã使ã£ã¦ããã®ãã¨ãããããã³ã°ãå¿ è¦ã«ãªããããã¯èªè¨¼ãµã¼ãã¼ãä¿æãã¦ããæ å ±ã§ããã
以ä¸ãã¾ã¨ããã¨ãæ»æè ã SecurIDã«ããèªè¨¼ãçªç ´ããã«ã¯ã以ä¸ã®æ å ±ãå¿ è¦ã«ãªãã
- ã¦ã¼ã¶ã¼ID
- ã¦ã¼ã¶ã¼ã® PIN (4ã8æ¡ã®æ°å)
- SecurIDã表示ãããã¼ã¯ã³ã³ã¼ãããã ãããã® SecurIDã¯ã¦ã¼ã¶ã¼ã¨ãããã³ã°ãããã·ãªã¢ã«ãã³ãã¼ãæã£ã¦ãããã¨ã
ããã¦ãã¼ãã¦ã§ã¢ãã¼ã¯ã³ãªã©ãæããã«ãã¼ã¯ã³ã³ã¼ããç®åºããã«ã¯ã以ä¸ã®æ å ±ãå¿ è¦ã«ãªãã
- ã·ã¼ã
- ã·ãªã¢ã«ãã³ãã¼
- ãã¼ã¯ã³ã³ã¼ããç®åºããã¢ã«ã´ãªãºã (ããã¯æ¢ç¥)
ã¨ãããã¨ã§ãããªããã¼ãã«ãé«ããã¨ãããã¾ã§ã¯æããã¦ããã
ããã§è©±ã¯3æã®RSAä¾µå ¥äºä»¶ã«æ»ããRSAã¯èªãã¦ããªãããææªã®ã±ã¼ã¹ã¨ãã¦é¡§å®¢ãå©ç¨ãã¦ãã SecurIDã®ã·ã¼ãã¨ã·ãªã¢ã«ãã³ãã¼ãããå ¨ã¦æµåºãã¦ãããã©ããªããããã®å ´åãæ»æè ã¯ä»»æã® SecurIDã®ãã¼ã¯ã³ã³ã¼ããç®åºã§ããããããããã ãã§ã¯ãã¡ã ããã¼ã¯ã³ã³ã¼ããå©ç¨ãã¦å®éã«ä¸æ£ãã°ã¤ã³ãããã®ã§ããã°ãã¦ã¼ã¶ã¼IDãPINãããã¦ãã®ã¦ã¼ã¶ã¼ã使ã£ã¦ããã·ãªã¢ã«ãã³ãã¼ãå¿ è¦ã«ãªãã
ããã¦ããããä»åã®ãããã¼ãã®è©±ã«æ»ãããã ãSecurIDãå ¨ã¦åçºè¡ããã¨ãããã¨ã¯ãSecurIDã®å®å ¨æ§ã«ä½ããã®åé¡ãçããå¯è½æ§ããããèªè¨¼ãµã¼ãã¼ããã·ã¼ããã·ãªã¢ã«ãã³ãã¼æ å ±ãæ¼ããã®ã ããã? ããããããã¼ãã¯ä»åã®ä»¶ã«ã¤ãã¦ãæ©æã«æ¤ç¥ã«æåãããããç¹ã«æ¼æ´©ããæ å ±ã¯ãªãã£ãã¨è¨ã£ã¦ãã*6ãã§ã¯ãªã?
ãããã¼ãã¯äºä»¶ã®è©³ç´°ã«ã¤ãã¦ããã以ä¸ä½ãå
¬è¡¨ãã¦ããªãã®ã§ãããããã¯æ¨æ¸¬ãããã¦åã¡ãã£ã¢ã®å ±éãä¼¼ããããªæ¨æ¸¬ããã¦ããã
æ»æè
㯠RSAããä¸æ£ã«å
¥æãã SecurIDã«é¢ããæ
å ±ãå©ç¨ããã®ã§ã¯ãªãã*7ãä¾µå
¥ã«å¿
è¦ã¨ãªãã¦ã¼ã¶ã¼ID㨠PINã¯å¥ã®æ¹æ³ã§(ãã¨ãã°ãã¼ãã¬ã¼ãªã©ã§)å
¥æããã®ã§ã¯ãªãããã·ãªã¢ã«ãã³ãã¼ã¨ã®ãããã³ã°ã¯é£ããããããæç¹ã®ãã¼ã¯ã³ã³ã¼ããåå¾ãã¦ããããéã«æ¢ããã®ã§ã¯ãªããããããã¯åã«ãã«ã¼ããã©ã¼ã¹ããã®ãããã£ã¨ç°¡åãªæ¹æ³ã§å
¥æã§ããã®ãã
ãããããã®æ¨æ¸¬ãæ£ãããã°ãä»ã®SecurIDãå©ç¨ãã¦ããä¼æ¥ãçµç¹ã¸ã®å½±é¿ã大ããããã ããã¨ã㨠3æã® RSAã¸ã®ä¾µå ¥ã®éã«ããRSAã¯ããã¾ã§ãä¸éã¿ã¼ã²ããã§ãããSecurIDã«é¢ããæ å ±ã欲ããã£ãã®ã§ã¯ãªãããæçµã¿ã¼ã²ããã¯å¥ã«ããã®ã§ã¯ãªããã¨è¨ããã¦ãããä»åã®æ»æè ã RSAä¾µå ¥ã®æ»æè ã¨åããªã®ã§ããã°ããã®æ¨æ¸¬ã¯æ£ããã£ããã¨ã«ãªããããã¦ãããããªããããã¼ã®ä¸è¬ä¼æ¥ãçããããã¨ã¯ãããããªãã ããã
ãã¦çç¸ã¯ããã«??
(2011/05/31 è£è¶³)
ãããããã«ããã£ããããããªãã®ã§è£è¶³ãä¸è¨ã®å
容㯠Cringleyæ°ã®ããã°ã¨ Reutersã®è¨äºã®å
ã«ãªã£ã¦ããå
é¨ããã®ãªã¼ã¯æ
å ±ããæ£ãããã¨ããåæã§æ¸ãã¦ããããããå½äºè
ã§ãã Lockheedã RSAãä¾µå
¥ã®åå ã«ã¤ãã¦å
¬å¼ã«ã¯ä½ãã³ã¡ã³ããã¦ããããSecurIDã«ã¯å
¨ãè¨åãã¦ããªãããã¹ã¦ã¯å
é¨ãªã¼ã¯æ
å ±ã«ãã¨ã¥ãä¸ç¢ºããªæ¨æ¸¬ã«ãããªãããããã£ã¦ä»ã® SecurIDã¦ã¼ã¶ã¼ãä»ããã«å±éºã«ãããããã¨ããç¶æ³ã§ã¯ãªããããä½ãå½±é¿ãããã®ã§ããã°ãRSAããå
¬å¼ã«ã¢ãã¦ã³ã¹ãããã¯ããç¶å ±ãå¾
ã¨ãã
(2011/06/02 追è¨)
Wired㨠Fox Newsããããã L-3 Communications㨠Northrop Grummanãæ»æããã¦ãããããããªãã¨ããè¨äºãæ¸ãã¦ãããããããå
é¨ããã®ãªã¼ã¯æ
å ±ã«ãã¨ã¥ãã¦ããããã ãã両社ã¨ãå
¬å¼ã«ã¯ã³ã¡ã³ããã¦ããããçå½ã¯ä¸æã§ããã
Second Defense Contractor L-3 'Actively Targeted' With RSA SecurID Hacks | WIRED
EXCLUSIVE: Northrop Grumman May Have Been Hit by Cyberattack, Source Says | Fox News
(2011/06/04 追è¨)
Lockheedã¸ã®ä¸æ£ä¾µå
¥ã®åå ã«ã¤ãã¦ãRSAããæµåºããæ
å ±ãæªç¨ããããã¨ã¯ã»ã¼ééããªãã㨠Lockheedã¯çµè«ã¥ããããã ã以ä¸ãNYTImesの記事ããä¸é¨å¼ç¨ã
Lockheed Martin said Friday that it had proof that hackers breached its network two weeks ago partly by using data stolen from a vendor that supplies coded security tokens to tens of millions of computer users.
In response to questions on Friday, Lockheed said in an e-mail that its computer experts had concluded that the breach at RSA in March was âa direct contributing factorâ in the attack on its network. Government and industry officials said the hackers had used some of the RSA data and other techniques to piece together the coded password of a Lockheed contractor who had access to Lockheedâs system.
(2011/06/07 追è¨)
RSAããå
¬å¼çºè¡¨ãã§ãããããã¼ãã¸ã®ä¸æ£ä¾µå
¥ã« RSAããä¸æ£ã«æã¡åºããã SecurIDé¢é£æ
å ±ãæªç¨ããããã¨ãèªããå
容ã
Open Letter to RSA SecurID Customers
Against this backdrop of increasingly frequent attacks, on Thursday, June 2, 2011, we were able to confirm that information taken from RSA in March had been used as an element of an attempted broader attack on Lockheed Martin, a major U.S. government defense contractor. Lockheed Martin has stated that this attack was thwarted.
ã¾ã顧客ã«å¯¾ã㦠SecurIDã®äº¤æãªã©ã®å¯¾å¿çãæä¾ããããã ã
As a result, we are expanding our security remediation program to reinforce customers' trust in RSA SecurID tokens and in their overall security posture. This program will continue to include the best practices we first detailed to customers in March, and will further expand two offers we feel will help assure our customers' confidence:
- An offer to replace SecurID tokens for customers with concentrated user bases typically focused on protecting intellectual property and corporate networks.
- An offer to implement risk-based authentication strategies for consumer-focused customers with a large, dispersed user base, typically focused on protecting web-based financial transactions.
We will continue to work with all customers to assess their unique risk profiles and user populations and help them understand which options may be most effective and least disruptive to their business and their users.
ã²ã¨ã¤ã®ã¤ãå ´ãè¿ããã¨ããæãâ¦
(2011/06/08 追è¨)
EMC Japanããã®ã¢ãã¦ã³ã¹ã¯こちらã
ä»åãOpen Letter to RSA SecurID Customersãã®æä¸ã§å ¬è¡¨ããã¦ããã ãã交æããã°ã©ã ã¯ããã¹ã¦ã®RSA SecurIDãå ¨æ°äº¤æããã¨ãããã¨ã§ã¯ããã¾ãããå¾è¿°ã§ç¤ºããã¾ãããã«ä¸é¨ãæ¸å¿µããã¦ããã客æ§ã«å¯¾å¿ããããã«ã交æããã°ã©ã ãç¨æããã¦ããã ããã¨ãããã¨ãäºå®ã§ãã
ã ããã§ãã
*1:ããã¯ãã³ãã¼ã ã ããã§ãããWikipedia参照
*2:ãã ãããããã¼ãããã®å ¬å¼çºè¡¨ã§ã¯ãªãã
*3:ãã¼ãã¦ã§ã¢ãã¼ã¯ã³ãã½ããã¦ã§ã¢ãã¼ã¯ã³ãOn-Demandãã¼ã¯ã³ã®3種é¡ããã
*4:å¤å°ã®æå»ã®ããã許容ãããããä¸åéãã¨ã¯è¨ã£ã¦ãé常ã¯2-3åéã¯æå¹ã§ããã
*5:ä¾ãã° Cain&Abelã¨ãããã¼ã«ã«ã¯ RSA SecurID Token Calculatorã¨ããæ©è½ãã¤ãã¦ããã
*6:ãã ããäºåã«ãããã®æ å ±ãæ¼æ´©ãã¦ããå¯è½æ§ã¯æ®ã£ã¦ããã
*7:RSAã¯ãã®ä»¶ã«ã¤ãã¦ã³ã¡ã³ããæå¦ãã¦ããããã ã