Democratic Underground Latest Greatest Lobby Journals Search Options Help Login
Google

EMC's anti-hacking division hacked

Printer-friendly format Printer-friendly format
Printer-friendly format Email this thread to a friend
Printer-friendly format Bookmark this thread
This topic is archived.
Home » Discuss » Latest Breaking News Donate to DU
 
kpete Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Mar-18-11 10:04 AM
Original message
EMC's anti-hacking division hacked
Source: Psysorg

Hacker Masters - Learn Cutting Edge Techincal And Legal Hacking Skills - Apply Now! - www.UAT.edu/ia

The world's biggest maker of data storage computers on Thursday said that its security division has been hacked, and that the intruders compromised a widely used technology for preventing computer break-ins.

...................

The incident is a rare public acknowledgement by a security company that its internal anti-hacking technologies have been hacked. It is especially troubling because the technology sold by EMC's security division, RSA, plays an important role in making sure unauthorized people aren't allowed to log into heavily guarded networks.

The scope of the attack wasn't immediately known, but the potential fallout could be widespread. RSA's customers include the military, governments, various banks and medical facilities and health insurance outfits. EMC, which is based Hopkinton, Mass., itself is an RSA customer.

EMC said in a filing with the Securities and Exchange Commission that RSA was the victim of what is known as an "advanced persistent threat," industry jargon for a sophisticated computer attack. The term is often associated with corporate espionage, nation-state attacks, or high-level cybercriminal gangs.



Read more: http://www.physorg.com/news/2011-03-emc-anti-hacking-division-hacked.html
Printer Friendly | Permalink |  | Top
bemildred Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Mar-18-11 10:10 AM
Response to Original message
1. The headline stretches the situation a bit, from what they say.
It's more of a partially successful attempted hack.
Printer Friendly | Permalink |  | Top
 
Taverner Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Mar-18-11 10:20 AM
Response to Original message
2. Bwahahahaha - EMC=Evil Marketing Company
They're the Darth Vader of the Computer Storage Industry
Printer Friendly | Permalink |  | Top
 
Rebubula Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Mar-18-11 10:58 AM
Response to Original message
3. Hype or not...
...we pulled all of our source code machines offline yesterday.

You never know and you NEVER want anyone to have your source code
Printer Friendly | Permalink |  | Top
 
bongbong Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Mar-18-11 11:12 AM
Response to Reply #3
4. Source code on line?
Seems to be a unnecessary risk.
Printer Friendly | Permalink |  | Top
 
AtheistCrusader Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Mar-18-11 11:50 AM
Response to Reply #4
5. Most likely LAN not WAN.
Printer Friendly | Permalink |  | Top
 
bongbong Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Mar-18-11 11:53 AM
Response to Reply #5
6. Yeah?
If it was LAN and not WAN, why did the company need to take the source code machines off line?
Printer Friendly | Permalink |  | Top
 
Snoutport Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Mar-18-11 11:56 AM
Response to Reply #6
7. speak english!!!!
you guys think it might be Anonymous?
Printer Friendly | Permalink |  | Top
 
bongbong Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Mar-18-11 01:10 PM
Response to Reply #7
11. Probably not
Probably not anonymous, as those guys don't have much dispute with SecureID. But there are lots of businesses, both legal & illegal, who would love to get EMC's algorithms.
Printer Friendly | Permalink |  | Top
 
hootinholler Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Mar-18-11 03:36 PM
Response to Reply #7
17. No Most likely China
Maybe N. Korea. Unless I'm mistaken, this is the SecureID folks. The little number generator you put on your keychain to enter in addition to your user name and password.

If they have been compromised to where that number can be predicted for a specific user, this is a huge fucking deal, keys to the kingdom huge.

-Hoot
Printer Friendly | Permalink |  | Top
 
AtheistCrusader Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Mar-18-11 11:56 AM
Response to Reply #6
8. He didn't say "off line". He said "offline".
Different common usage.

"Off Line" implies off WAN or internet access.
"Offline" implies disconnecting the server from all network access, or turning it off completely.


It would be highly unusual for any source control system to be exposed directly to the internet. Remote developers would usually tunnel in or use an RDP gateway or something like that.
Printer Friendly | Permalink |  | Top
 
bongbong Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Mar-18-11 01:03 PM
Response to Reply #8
10. Huh?
I don't want to be mean, but it's ironic that you make a distinction between "off line" and "offline" when I, and scores of other computer engineers use them interchangeably.

Why ironic? Because then you use lower-case "internet" to refer to the Internet. :shrug:
Printer Friendly | Permalink |  | Top
 
AtheistCrusader Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Mar-18-11 01:51 PM
Response to Reply #10
13. I fix things that computer engineers create, for a living.
Edited on Fri Mar-18-11 01:53 PM by AtheistCrusader
I've noted a clear distinction between the intent in the usage on those two terms, at least among my customers.

I guess we need the person you responded to, to clarify for certain. I'm willing to bet he meant that he either severed those EMC servers from the local intranet, or he shut them cold-off completely.

Edit: I have never in my life seen an EMC device of any type plugged into a WAN connection, ever. Maybe they make some device my customer's don't normally use, and i'm just not familiar with it.

It seems to me that 'internet' has become a non-proper noun, like 'building' or 'plumbing' at this point, but I could be wrong.
Printer Friendly | Permalink |  | Top
 
Doctor_J Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Mar-18-11 12:38 PM
Response to Original message
9. These corporations have finally drawn the ire of people
who can actually do something about them. No sign-waving, boycotts, petitions. Some actual retribution
Printer Friendly | Permalink |  | Top
 
Snoutport Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Mar-18-11 01:23 PM
Response to Original message
12. ANONYMOUS?
kick...this is an important story.
Printer Friendly | Permalink |  | Top
 
notadmblnd Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Mar-18-11 02:39 PM
Response to Reply #12
15. not likely.
Printer Friendly | Permalink |  | Top
 
notadmblnd Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Mar-18-11 02:38 PM
Response to Original message
14. So who else is in the ata storage business that stands
to gain business that EMC loses because of the breach?
Printer Friendly | Permalink |  | Top
 
Snoutport Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Mar-18-11 03:10 PM
Response to Reply #14
16. follow the money....nt
Printer Friendly | Permalink |  | Top
 
DU AdBot (1000+ posts) Click to send private message to this author Click to view 
this author's profile Click to add 
this author to your buddy list Click to add 
this author to your Ignore list Thu Apr 25th 2024, 09:17 AM
Response to Original message
Advertisements [?]
 Top

Home » Discuss » Latest Breaking News Donate to DU

Powered by DCForum+ Version 1.1 Copyright 1997-2002 DCScripts.com
Software has been extensively modified by the DU administrators


Important Notices: By participating on this discussion board, visitors agree to abide by the rules outlined on our Rules page. Messages posted on the Democratic Underground Discussion Forums are the opinions of the individuals who post them, and do not necessarily represent the opinions of Democratic Underground, LLC.

Home  |  Discussion Forums  |  Journals |  Store  |  Donate

About DU  |  Contact Us  |  Privacy Policy

Got a message for Democratic Underground? Click here to send us a message.

© 2001 - 2011 Democratic Underground, LLC