WIRED Profile picture
May 20, 2021 8 tweets 4 min read Read on X
In 2011, RSA was hacked: the worst breach of a security firm to that date. The hack, carried out by Chinese spies, pulled the rug out from under the world’s model of security. For 10 years, RSA execs have been bound to silence by NDAs—which just expired 1/ wired.trib.al/ffxPoam
The intruders were able to steal the “seeds” underpinning RSA’s SecurID tokens: fobs that let you prove your identity by entering the six-digit codes that update on their screens. The hack erased a critical safeguard protecting 40 million accounts worldwide 2/
RSA’s customers included government agencies, defense contractors, and corporations across the globe.

The new accounts capture the experience of being targeted by sophisticated state hackers who meticulously take on high-value networked targets on a geopolitical scale 3/
And reveal the RSA staffers’ feverish race against the hackers. Large-scale attacks are often discovered months after the fact, but this one was different. Investigators caught up to the intruders and began chasing them in real time 4/
Their stories also show paranoia that took hold of RSA. The company switched mobile carriers; employees were told to talk in person whenever possible; the FBI conducted background checks; some windows were even covered in butcher paper to prevent laser microphone surveillance 5/
After 10 years of rampant state-sponsored hacking and supply chain hijacks, the RSA attack can now be seen as the herald of an era of digital insecurity.

Read its untold story here: 6/ wired.trib.al/ffxPoam
To hear more about the RSA hack, listen to @a_greenberg and several of the subjects interviewed in his story on Cybereason’s @MaliciousLife podcast: 7/ cybereason.com/blog/the-untol…
Want to support journalism like this? Subscribe to WIRED and get unlimited access to the biggest stories in tech 8/ wired.trib.al/f3r0g6N

• • •

Missing some Tweet in this thread? You can try to force a refresh
 

Keep Current with WIRED

WIRED Profile picture

Stay in touch and get notified when new unrolls are available from this author!

Read all threads

This Thread may be Removed Anytime!

PDF

Twitter may remove this content at anytime! Save it as PDF for later use!

Try unrolling a thread yourself!

how to unroll video
  1. Follow @ThreadReaderApp to mention us!

  2. From a Twitter thread mention us with a keyword "unroll"
@threadreaderapp unroll

Practice here first or read more on our help page!

More from @WIRED

Jun 4
SCOOP: Edward Coristine (“Big Balls”), Luke Farritor, and Ethan Shaotran were part of the original DOGE crew. They were brought in under short-term “special government employee” status. Supposed to be temporary. Spoiler: it’s not. wired.com/story/big-ball…
As of May 31 (Coristine & Farritor) and April 10 (Shaotran), the trio officially became full-time federal employees. Their roles at the General Services Administration (GSA) are now permanent.

And they’re not exactly entry-level. wired.com/story/big-ball…
According to documentation viewed by WIRED, they each maintain their “senior advisor” titles.

Their pay? GS-15 for Coristine & Farritor, one of the highest government salary grades. Shaotran’s at GS-14—just one step below. wired.com/story/big-ball…
Read 8 tweets
May 30
SCOOP: Elon Musk will not be fully exiting DOGE.

In fact, federal workers from at least six agencies tell WIRED that DOGE-style work is escalating in their departments, and Trump himself said in a press conference today that “Elon's really not leaving.”
wired.com/story/doge-elo…
Members of Musk’s early DOGE team, including Luke Farritor and Gavin Kliger, have met with a number of departments and agencies in recent days, seemingly continuing business as usual, WIRED has learned.

And the team appears to be actively recruiting.
wired.com/story/doge-elo…
Their latest focus? Canceling contracts.

Over the last week, federal workers have been asked to urgently review contracts across the government, and sources say the pressure to slash contracts has drastically increased in recent weeks.
wired.com/story/doge-elo…
Read 4 tweets
May 6
NEW: Tulsi Gabbard, now the US director of national intelligence, used the same easily cracked password for different online accounts including a personal Gmail account and Dropbox over a period of years, leaked records reviewed by WIRED reveal. wired.com/story/tulsi-ga…
The password associated includes the word “shraddha,” which appears to have personal significance to Gabbard: This year, WSJ reported that she had been initiated into the Science of Identity Foundation, which ex-members have accused of being a cult. wired.com/story/tulsi-ga…
Security experts advise people to never use the same password on different accounts precisely because people often do so. As director of national intelligence, Gabbard oversees the 18 organizations comprising the US intelligence community.

wired.com/story/tulsi-ga…
Read 4 tweets
Apr 18
DOGE is knitting together data from the Department of Homeland Security, Social Security Administration, and IRS that could create a surveillance tool of unprecedented scope. wired.com/story/doge-col…
The scale at which DOGE is seeking to interconnect data, including sensitive biometric data, has never been done before, raising alarms with experts who fear it may lead to disastrous privacy violations.
wired.com/story/doge-col…
“They are trying to amass a huge amount of data,” a senior DHS official tells WIRED. “It has nothing to do with finding fraud or wasteful spending … They are already cross-referencing immigration with SSA and IRS as well as voter data.”
wired.com/story/doge-col…
Read 5 tweets
Apr 17
American police are spending hundreds of thousands on Massive Blue’s unproven and secretive technology that uses AI-generated online personas designed to interact with and collect intelligence on “college protesters,” “radicalized” political activists, and suspected traffickers. Image
Massive Blue calls its product Overwatch, which it markets as an “AI-powered force multiplier for public safety” that “deploys lifelike virtual agents, which infiltrate and engage criminal networks across various channels.”

🔗 wired.com/story/massive-…Image
404 Media obtained a presentation showing some of these AI characters. These include a “radicalized AI” “protest persona,” which poses as a 36-year-old divorced woman who is lonely, has no children, is interested in baking, activism, and “body positivity.” Image
Read 8 tweets
Apr 9
SCOOP: DOGE is getting audited.
wired.com/story/gao-audi…
The audit covers DOGE’s handling of data at several Cabinet-level agencies, including:
–the Departments of Labor, Education, Homeland Security, Health and Human Services
–the Treasury
–the Social Security Administration
–the US DOGE Service (USDS) itself
wired.com/story/gao-audi…
It's being carried out after congressional leaders’ requests and is centered on DOGE’s adherence to privacy and data protection laws and regulations.

A Congressional aide said the requests followed media reports on DOGE’s incursions into federal systems.
wired.com/story/gao-audi…
Read 5 tweets

Did Thread Reader help you today?

Support us! We are indie developers!


This site is made by just two indie developers on a laptop doing marketing, support and development! Read more about the story.

Become a Premium Member ($3/month or $30/year) and get exclusive features!

Become Premium

Don't want to be a Premium member but still want to support us?

Make a small donation by buying us coffee ($5) or help with server cost ($10)

Donate via Paypal

Or Donate anonymously using crypto!

Ethereum

0xfe58350B80634f60Fa6Dc149a72b4DFbc17D341E copy

Bitcoin

3ATGMxNzCUFzxpMCHL5sWSt4DVtS8UqXpi copy

Thank you for your support!

Follow Us!

:(