Live data from Hacker News

Sony Got Hacked Hard: What We Know and Don't Know So Far

wired.com

61–70 of 184 posts

Re: Sony Got Hacked Hard: What We Know and Don't Know So Far

#61
Even though I am a massive supporter and advocate of whistle-blowing and leaking (in the public interest), the state of a lot of the journalism around this is appalling - esp the Gawker article. (Though the Wired one is pretty responsible in fairness.)

Unless Sony has shown to be doing something malicious (which I don't think it has - other than some horrific Adam Sandler movies recently), then the angle of mining the data just to create click-bait headlines is particularly infuriating.

Yes, it is right to report such a large cyber intrusion in the public interest, especially if people's data has been taken (and Sony already had this problem occur before - so it is worth pointing out that they had a chance to tighten up security) but trawling through the internal data of an innocent private company and exposing it online, just to gossip, is particularly poor journalism. Having worked with a lot of media, you can be sure they rightly wouldn't be too happy if people did that to them - just for kicks.

Re: Sony Got Hacked Hard: What We Know and Don't Know So Far

#62
post #58
post #54

Earlier quoted context omitted.

Apparently North Korea has fairly substantial IT (and animation) outsourcing businesses: this paywalled A¢M article http://cacm.acm.org/magazines/2012/8/153816-inside-the-hermi... claims 10,000 workers in IT outsourcing. The great majority of the population may be living as peasants, but that's not the case universally.

Just found a link to the other article I read on the subject. http://h30499.www3.hp.com/hpeb/attachments/hpeb/off-by-on-so... It focuses more on cyber warfare, but does cover quite a bit about CS education in North Korea.

Very interesting, thanks.

Re: Sony Got Hacked Hard: What We Know and Don't Know So Far

#63
post #53

Earlier quoted context omitted.

Many people suggest that startups not over-optimize on issues like security and performance when it's not their core business. And that's a fucking stupid thing to say in those cases, so it's a fucking stupid thing to say here. Things like security and performance should be given. This is akin to arguing that small restaurants shouldn't care about food safety, or that small construction firms shouldn't worry about bu…

When it comes to start-ups it's not stupid - it's wise. The food safety analogy is inappropriate. Security is about risk management. Low risks do not justify high expenses. When it comes to a company with hundreds of millions in revenues, however, they have clearly underestimated the risks and have been irresponsible.

I would say even the food safety analogy is appropriate. Sure, food safety is important; that doesn't mean you have to spend hundreds of millions of pounds in "food safety researchers" who will conduct rigorous scientific experiments to find out the best ways to limit the spread of germs and implement them, an in-house doctor with medical supplies who will treat customers that get food poisoning, etc.

It just means there's a minimum, a bar, that they shouldn't go below. Everyone has a different bar, but most people generally agree on things like don't pick up food off the floor, don't leave things open or out, put things in the right places, make sure you wash your hands, etc. (I am not a food safety expert).

Of course, for a startup, it depends on the product or service they're offering. A startup payment processor should be very security conscious, as the stakes are high. A movie logger should have the bare minimum that all startups should have, i.e. strong encryption, basic security protocols, etc.

Re: Sony Got Hacked Hard: What We Know and Don't Know So Far

#65
post #53

Earlier quoted context omitted.

Many people suggest that startups not over-optimize on issues like security and performance when it's not their core business. And that's a fucking stupid thing to say in those cases, so it's a fucking stupid thing to say here. Things like security and performance should be given. This is akin to arguing that small restaurants shouldn't care about food safety, or that small construction firms shouldn't worry about bu…

When it comes to start-ups it's not stupid - it's wise. The food safety analogy is inappropriate. Security is about risk management. Low risks do not justify high expenses. When it comes to a company with hundreds of millions in revenues, however, they have clearly underestimated the risks and have been irresponsible.

[deleted]

Re: Sony Got Hacked Hard: What We Know and Don't Know So Far

#66
I am not a sysadmin or network security guy, so I have to ask: how could hackers siphon as much as 100 terabytes of data from Sony's network without being noticed? Shouldn't they have indictors to see their bandwidth was running dry? If so, did the GOP do it slowly to avoid drawing attention?

Re: Sony Got Hacked Hard: What We Know and Don't Know So Far

#67

Many people suggest that startups not over-optimize on issues like security and performance when it's not their core business. The same could be said of Sony: empathize a little with them. Sony Pictures pays a lot of creative people. Maybe they should have seen the hack coming, but like the PSN outage this story will be maybe a paragraph in a Wikipedia article years from now. Even one great film could be watched by p…

Sony Pictures has an operating income (revenue minus expenses) of $501 million per year. They can afford to pay creatives, but they can't afford to pay for a few more security engineers? Look, I get the creative field costs a lot of money. But Sony Pictures was paying $454,224,070 http://fusion.net/story/30850/ in total salaries as of May. Even hiring 5 more security engineers would have gone a long way. That's $1 mi…

Security is also incredibly, incredibly hard. Google were hacked quite hard as well, remember?

Re: Sony Got Hacked Hard: What We Know and Don't Know So Far

#68

It's Sony Pictures Entertainment that got hacked, not Sony. They're completely separate companies, yet the media fails to recognize that. Very annoying and confusing, it's almost deliberately.

A bunch of Amazon EC2 machines that were also running web sites seemingly part of the Sony Playstation network were seeding the torrent for a day or so after the leak:

http://www.theregister.co.uk/2014/12/03/strange_things_afoot...

Re: Sony Got Hacked Hard: What We Know and Don't Know So Far

#69
Re/code is claiming that Sony will officially name North Korea as the source of the attack:

http://recode.net/2014/12/03/sony-to-officially-name-north-k...

Sony Pictures will officially name North Korea as the source of a hacking attack that has exposed sensitive files and brought down its corporate network last week, two sources close to the investigation tell Re/code. An announcement could come as soon as today.

Details of what Sony and the security firm Mandiant will announce are still being finalized. But the sources confirm that North Korea will be named as the source of the attack.

A Sony spokeswoman declined to comment on the timing or the news, but said “The investigation continues into this very sophisticated cyber attack.”

Re: Sony Got Hacked Hard: What We Know and Don't Know So Far

#70

I am not a sysadmin or network security guy, so I have to ask: how could hackers siphon as much as 100 terabytes of data from Sony's network without being noticed? Shouldn't they have indictors to see their bandwidth was running dry? If so, did the GOP do it slowly to avoid drawing attention?

For a network the size of Sony's, it seems like that volume should be relatively easy to smuggle out. Maybe not all at once, right?
Post reply on HN