The Untold Story of the 2011 RSA Hack

Started by ergophobe, May 22, 2021, 06:19:54 PM

Previous topic - Next topic

ergophobe

If you read Cuckoo's Egg by Cliff Stoll back in the day, you'll enjoy this

QuoteIn the decade that followed, many key RSA executives involved in the company's breach have held their silence, bound by 10-year nondisclosure agreements. Now those agreements have expired, allowing them to tell me their stories in new detail.
https://www.wired.com/story/the-full-story-of-the-stunning-rsa-hack-can-finally-be-told

The short version is this: nothing is actually secure if state-sponsored hackers want your account.

QuoteDuane's harrowing experience in response to the intrusion taught him—and perhaps should teach all of us—that "every network is dirty," as he puts it. Now he preaches to companies that they should segment their systems and cordon off their most sensitive data so that it remains impenetrable even to an adversary that's already inside the firewall.

The other short version is: never trust the lawyers

QuoteIn the hours that followed, RSA's executives debated how to go public. One person in legal suggested they didn't actually need to tell their customers, Sam Curry remembers. Coviello slammed a fist on the table: They would not only admit to the breach, he insisted, but get on the phone with every single customer to discuss how those companies could protect themselves.

And this other gem from the CEO
Quoteone executive suggested they call it Project Phoenix. Coviello immediately nixed the name. "Bullshit," he remembers saying. "We're not rising from the ashes. We're going to call this project Apollo 13. We're going to land the ship without injury."