This morning, friend shrdlu pointed out that RSA might indeed have entirely legitimate reasons for being so deliberate in avoiding a rush to disclose information about the breach of SecurID information: Guys, unless you’ve dealt with this from the executive seat before, you don’t know the other issues. She has a point. Like her, I...

Read More »





A short while ago, RSA released an additional customer advisory (customer login required) regarding the breach of SecurID information disclosed last Thursday. In my updated initial take on the breach, I noted that: To date, RSA has disclosed no detail about exactly what was compromised or how, leaving customers with no actionable information regarding their...

Read More »





posted by Scott Crawford   | March 18, 2011 | 0 Comments

(Updated: Commentary on RSA’s disclosure and SecurCare advisory of March 17) Yesterday, RSA Security disclosed that it had been the victim of a security breach that, according to Executive Chairman Art Coviello’s open letter to customers, resulted in the exposure of information “specifically related to RSA’s SecurID two-factor authentication products.” Coviello’s letter goes on to...

Read More »