The full story of the shocking RSA Hack can finally be told

[ad_1]

That afternoon, Coviello published an open letter to RSA customers on the company’s website. The letter read: “Recently, our security system has discovered an extremely complex cyber attack.” “Although we are currently confident that the information extracted cannot successfully carry out a direct attack on any of our RSA SecurID customers, it is more extensive. This information may be used to reduce the effectiveness of the current implementation of two-factor authentication. Attacks,” the letter continued, somewhat downplaying the crisis.

In Bedford, Castignara was given a meeting room and had the right to recruit as many volunteers from the company as needed. A rotating team of 90 employees began a week of work day and night, arranging one-on-one phone calls with each customer. They use scripts to work and guide customers to take protective measures, such as adding or extending a PIN code in the SecurID login name, making it more difficult for hackers to copy. Castignara remembered walking along the lobby of the building at 10 o’clock in the evening and heard the speaker phone behind each closed door. In many cases, customers are yelling. Castignola, Curry and Coviello all made hundreds of calls. Curry started jokingly saying that his title was “Chief Apology Officer.”

At the same time, delusions began to take a place in the company. On the first day after the announcement, Castignara remembered walking in a wiring closet and seeing countless people coming out of it, far beyond his imagination. “Who are these people?” he asked another executive nearby. The executive replied vaguely: “That’s the government.”

In fact, when Castignola landed in Massachusetts, both the National Security Agency (NSA) and the Federal Bureau of Investigation (FBI) had been asked to assist the company’s investigations. The defense contractor Northrop · The same goes for Northrop Grumman and Mandiant, an incident response company. (Once there was an opportunity, Mandiant employees had been on site before the violation, and installed security sensor equipment on the RSA network.)

RSA staff began to take drastic measures. Fearing that their phone system might be threatened, the company moved the operator from AT&T to Verizon Phone. Executives don’t even trust the new phones, hold meetings in person and share paper copies of documents. The FBI was worried that the intruder seemed to have a clear level of understanding of the company’s systems, so it was worried about RSA’s associates and began a background investigation. Duan said: “I make sure to investigate all members of the team (I don’t care who they are or what reputation they have) because you have to be sure.”

The windows of some executive offices and conference rooms are covered with a thin layer of butcher paper to prevent laser microphone surveillance (a remote monitoring technology that uses the vibration of the window glass to pick up conversations). This spy is the surrounding woods Imaginary spy in the middle. The building was swept away from bugs. Several executives insisted that they did find hidden listening devices, even though some of them were so old that the batteries were dead. It is not clear whether these errors have anything to do with the violation.

At the same time, as Curry said, the RSA security team and the investigators who brought in the investigators are “dismantling the house into nails.” He said that in every part of the network that hackers came into contact with, they cleaned up the contents of potentially threatening machines, even the contents of machines adjacent to them. “We walked physically, and if there was a box in it, it would be wiped off,” Curry said. “If you lose data, it’s too bad.”

[ad_2]

Source link