Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

This is nitpicky, but shouldn't the title (on Ars I guess, since it was used verbatim) be "was compromised" since this was a one-time data theft that rendered all currently-live SecurID tokens useless?


True, on the other hand there are still 40 million of those tokens out there, which are all compromised and have to be replaced. So that is still very much present tense.


It's hard to tell from the information given if ALL seeds have been compromised or just SOME which RSA may have been holding.


Given RSA's reluctance to come clean on this, I don't think anyone's going to trust "oh, but your SecureID wasn't compromised" from them.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: