A cloned SecurID software token created by security consultant Behrang Fouladi. Credit: Behrang Fouladi A researcher has devised a method that attackers with control over a victim's computer can use to clone the secret software token that RSA's SecurID uses to generate one-time passwords. The technique, described on Thursday by a senior security analyst at a firm called SensePost, has important im
ããã¥ã¼ã¨ã¼ã¯=å°å·ç¾©ä¹ãç±³ã»ãã¥ãªãã£ã¼å¯¾ç大æRSAã»ãã¥ãªãã£ã¯6æ¥ãå社ã®ä¸»å製åã®1ã¤ã§ãä¸çã§ç´¯è¨ç´4000ä¸å°ãåºè·ããã¦ããã使ãæ¨ã¦ãã¹ã¯ã¼ãã端æ«ã®äº¤æã«å¿ããæ¹éãæããã«ãããå社ã®ã·ã¹ãã ã«ããã«ã¼ãä¸æ£ä¾µå ¥ãã使ãæ¨ã¦ãã¹ã¯ã¼ãæè¡ã«é¢ããæ å ±ãçã¾ãããããå端æ«ã¯æ¥æ¬ã®éèæ©é¢ãä¼æ¥ã§ãåºã使ããã¦ãããå½±é¿ãåºããå¯è½æ§ããããRSAã»ãã¥ãªãã£ã®ã¢ã¼ãµã¼ã»ã³
(2011/06/07 æ´æ°) RSAãä»åã®ä»¶ã«ã¤ãã¦å ¬å¼ã«çºè¡¨ããã¾ããããããã¼ãã¸ã®ä¸æ£ä¾µå ¥ã®åå ã«ãªã£ããã¨ãèªãã顧客ã«å¯¾ã㦠SecurIDã®äº¤æãªã©ã«å¿ããææ¡ããã¦ãã¾ãã ãã®é±æ«ãã¢ã¡ãªã«ã§èµ·ãããããã¼ãã»ãã¼ãã³(Lockheed Martin)ã®ãããã¯ã¼ã¯ã«å¯¾ããä¸æ£ä¾µå ¥ã話é¡ã«ãªã£ã¦ããããããã¼ãã»ãã¼ãã³ã¨ããã°ãã¢ã¡ãªã«ã代表ããä¼æ¥ã®ä¸ã¤ã§ãããF22ã F35ãªã©ã®ææ°éæ©ãéçºãã¦ãããã¨ã§ãæåã§ããã ãã®ãããã¼ãã§å é±æ«ã«ãããã¯ã¼ã¯ã«å¯¾ãããªã¢ã¼ãããã®ä¸æ£ä¾µå ¥ãèµ·ããããã®ä»¶ãæåã«ä¼ããã®ã¯ Robert X. Cringelyæ°*1ã5/25ã®ããã°ã§ãããå½é²é¢é£ä¼æ¥ã®è©±ã¨ãã¦ããããã¯ã¼ã¯ã§åé¡ãèµ·ãããã¨ãã¦ã¼ã¶ã¼ã«ãããªã¢ã¼ãã¢ã¯ã»ã¹ãåæ¢ãããã¨ãå ¨ã¦ã®ã¦ã¼ã¶ã¼ã®ãã¹ã¯ã¼ãããªã»ãããããã¨ãSecurIDãæ°é±éã®ãã¡
åºæ¬ã¯å°ã£ã¦ãã飲ãã§ããã§ããããã趣å³ã§ã«ã©ãªã±ã»PKIã»ç½²åã»èªè¨¼ã»ããã°ã©ãã³ã°ã»æ å ±ã»ãã¥ãªãã£ããã£ã¦ãã¾ããæ 好ãããã¬ã好ãã§è¸è½é ã»ãã¥ãªãã£é¢ä¿ã«èå³ãããæ¹ã¯å¾¡åããã¨æãã¾ããRSA SecurIDã¯ä¸çã§æã使ç¨ããã¦ããã¨æã(The Registerã®è¨äºã§ã¯4000ä¸ã¦ã¼ã¶ã¨ãï¼)ã¯ã³ã¿ã¤ã ãã¹ã¯ã¼ããã¼ã¯ã³ã¨ããéå ·ã§ã大ããªä¼æ¥ã®ãã¤ã¢ã«ã¢ãããVPNãªã©ã®ãã°ã¤ã³ã®éã«ãIDãã¹ã¯ã¼ãã®ä»ã«60ç§ããã«è¡¨ç¤ºããã6æ¡ã®æ°å(ã¯ã³ã¿ã¤ã ãã¹ã¯ã¼ã)ãå ¥åãããã¨ã«ãããªã¢ã¼ããã°ã¤ã³ã®ã»ãã¥ãªãã£å¼·åº¦ãå¼·åãããã®ã§ããã¤ã¾ãã¯ã³ã¿ã¤ã ãã¹ã¯ã¼ããçæããéå ·ããã£ã¦ãªãã¨çµå±ãã°ã¤ã³ãã§ããªãäºã«ãªãã¾ãã ããæ°æ¥Twitterã®ã¿ã¤ã ã©ã¤ã³ãªã©ã§ãRSAã®ã¦ã§ããµã¤ããæ»æããSecurIDãå±ãããããSecurID 40ä¸(?)ã¢ã«ã¦ã³ããç
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}