CEO of the SANS Technology Institute, CEO of SANS on the RSA Breach ‘Is Not a Game-Changer’ Northcutt: “If someone was able to intercept your password, but not physical token, is it possible they could deduce the two-factor authentication digits and complete the log in? That’s the question everyone has got to answer one way or another over time,” he says. He was the original author of the Shadow Intrusion Detection system before accepting the position of Chief for Information Warfare at the Ballistic Missile Defense Organization.”]
Source: https://www.bankinfosecurity.com/sans-on-rsa-breach-a-3508