Lockeed Martin network suffers security breach
nytimes.com
nytimes.com
Getting an employee's password and SecurID token was very difficult, as you can imagine. Most phishing attempts failed, but every now and then we found an employee who would enter their password and SecureID pin into a bogus website, which we then had forwarded to us so we could immediately log onto their screen name before the pin changed.
The most notable hack was when BMB, my co-founder, gained access to an account with keyword admin privileges. What this meant is that he could direct any keyword to any destination. He chose to redirect keyword "Welcome", which every AOL member is sent to when they sign on, to our website, aol-files.com. For a period of about half an hour, every single person who signed onto AOL was redirected to our AOL hacking website. We received over 100K hits in 30 minutes.
I've got an archive of AOL-Files up on my blog [1], which has lots more information about this hack and many others. Ah, memories...
Don't you feel in the slightest bit worried by publicly talking about your antics?
http://www.reuters.com/article/2011/05/28/usa-defense-hacker...
I heard something about being able to generate private keys from the serial numbers of the tokens, but even if that's the case, you'd need to know what token/serial number you acutally care about. Not all users are going to have access to anything interesting.
He said the initial RSA attack was followed by malware and phishing campaigns seeking specific data that would link tokens to end-users, which meant the current attacks may have been carried out by the same hackers.
It's not that it's "junk crypto" where the crypto part is mathematically sound. It was more to do with information leakage than source of "junk crypto".
http://blogs.forbes.com/alexknapp/2011/05/25/d-wave-sells-qu...
Perhaps coincidence. Still, interesting.
Almost certainly a coincidence. RSA was under an Advanced Persistent Threat (APT) a while back in March, which might have lead to compromising the security of the SecurID tokens.
http://www.pcworld.com/businesscenter/article/222522/rsa_war...
Do you think the method is scaleable up to the 128 qubits that D-Wave is claiming?
Well, there’s no reason of principle why you couldn’t scale to a larger
number of qubits! But given the history here, I’d be skeptical of
claims by D-Wave to have done so already, and would want to see the
evidence. (As usual, the burden is on D-Wave to prove that they’ve done
something, not on everyone else to prove that they haven’t!)
http://blogs.forbes.com/alexknapp/2011/05/24/q-and-a-with-prof-scott-aaronson-on-d-waves-quantum-computer/