PeiterZ reported that he and his associates were able to penetrate
SecurID-protected systems, apparently from the Internet. I don't doubt it,
particularly if he was using TCP-splicing with, say, Hobbit's Netcat. An
OTP, admittedly, does not secure the network.
We did not use TCP-splicing / session hi-jacking to penetrate
the SecurID-protected systems. The attacks we used are in the white paper
at ftp://ftp.secnet.com.
PeiterZ