Live data from Hacker News

Sony Got Hacked Hard: What We Know and Don't Know So Far

wired.com

71–80 of 184 posts

Re: Sony Got Hacked Hard: What We Know and Don't Know So Far

#71
post #53

Earlier quoted context omitted.

Many people suggest that startups not over-optimize on issues like security and performance when it's not their core business. And that's a fucking stupid thing to say in those cases, so it's a fucking stupid thing to say here. Things like security and performance should be given. This is akin to arguing that small restaurants shouldn't care about food safety, or that small construction firms shouldn't worry about bu…

When it comes to start-ups it's not stupid - it's wise. The food safety analogy is inappropriate. Security is about risk management. Low risks do not justify high expenses. When it comes to a company with hundreds of millions in revenues, however, they have clearly underestimated the risks and have been irresponsible.

You are assuming that the risk is only to the company, not it's customers.

Re: Sony Got Hacked Hard: What We Know and Don't Know So Far

#72

I am not a sysadmin or network security guy, so I have to ask: how could hackers siphon as much as 100 terabytes of data from Sony's network without being noticed? Shouldn't they have indictors to see their bandwidth was running dry? If so, did the GOP do it slowly to avoid drawing attention?

Although it's possible to monitor bandwidth use pretty closely, none of the companies I've worked for ever did that unless we where having problems.

All the "hackers" have to do is copy the date in a matter that does not cause obvious problems. For example, as you said, do it slowly, or do it at night when "nobody's" using the network anyway.

Re: Sony Got Hacked Hard: What We Know and Don't Know So Far

#73

I am not a sysadmin or network security guy, so I have to ask: how could hackers siphon as much as 100 terabytes of data from Sony's network without being noticed? Shouldn't they have indictors to see their bandwidth was running dry? If so, did the GOP do it slowly to avoid drawing attention?

For a network the size of Sony's, it seems like that volume should be relatively easy to smuggle out. Maybe not all at once, right?

If my math is right, it would take ~120 days at 10 MB / second.

Re: Sony Got Hacked Hard: What We Know and Don't Know So Far

#74
post #12
post #2

"Or that the company spent half a million this year in severance costs to terminate employees?" That's not much. Is Wired trying to make me think that is a lot? Or are they trying to play it against the salary figures? Considering they spent valuable words in the first sentence to make it clear that the top brass is "mostly" white males I get the impression the comparison was supposed to mean something.

IMO if an article starts with > Who knew that Sony’s top brass, a line-up of mostly white male executives, earn $1 million and more a year? I'm already putting my expectations for the rest of it on the same level as those for this famous one: > I don't care if you landed a spacecraft on a comet, your shirt is sexist and ostracizing. ( http://www.theverge.com/2014/11/13/7213819/your-bowling-shir... ) I wonder when it'…

Take it to stormfront.

Re: Sony Got Hacked Hard: What We Know and Don't Know So Far

#75

It's Sony Pictures Entertainment that got hacked, not Sony. They're completely separate companies, yet the media fails to recognize that. Very annoying and confusing, it's almost deliberately.

That's just corporate sophistry.

Re: Sony Got Hacked Hard: What We Know and Don't Know So Far

#76

Many people suggest that startups not over-optimize on issues like security and performance when it's not their core business. The same could be said of Sony: empathize a little with them. Sony Pictures pays a lot of creative people. Maybe they should have seen the hack coming, but like the PSN outage this story will be maybe a paragraph in a Wikipedia article years from now. Even one great film could be watched by p…

I think fraction of their executive bonuses would be quite enough to fully fund a fairly decent security effort. If security were designed into their processes, it would probably cost much less.

If the 100 TB figure is correct, this has been going on for some time - it takes time to steal that much data in a way that does not raise a bunch of red flags. If the red flags weren't there to be raised or they were and were ignored, well... at least their executives got their bonuses.

Also, in the interest of fairness, while this malware attack seemed to be directed to Windows machines, a dedicated enough intruder would have developed attack strategies for any platform.

Re: Sony Got Hacked Hard: What We Know and Don't Know So Far

#77
Anecdotally, I knew some guys who worked at (or with?) the global security division at Sony US HQ.

The story went that each of the Sony subsidiaries[1] had their own security division that was largely autonomous for reasons of politics and budget, of course. Each part of the company had different vendors, different policies and procedures, and different philosophies on how security should be implemented.

When they would all send their representatives to have a global security pow wow, however often it happened, it ended up like an episode of game of thrones.

[1] http://en.wikipedia.org/wiki/Sony_Corporation_shareholders_a...

Re: Sony Got Hacked Hard: What We Know and Don't Know So Far

#78
post #30

The compensation levels should't be confidential in the first place. This policy is only useful to the wrong people. This is how we get artificially low market rates for developers and ridiculous amounts of money paid to incompetent execs. edit: the downvotes are an indication that you deserve your bullshit laws/status quo

The down votes may not be because people disagree with open salaries, but because this has no value in the discussion.

Re: Sony Got Hacked Hard: What We Know and Don't Know So Far

#79
post #63
post #53

Earlier quoted context omitted.

When it comes to start-ups it's not stupid - it's wise. The food safety analogy is inappropriate. Security is about risk management. Low risks do not justify high expenses. When it comes to a company with hundreds of millions in revenues, however, they have clearly underestimated the risks and have been irresponsible.

I would say even the food safety analogy is appropriate. Sure, food safety is important; that doesn't mean you have to spend hundreds of millions of pounds in "food safety researchers" who will conduct rigorous scientific experiments to find out the best ways to limit the spread of germs and implement them, an in-house doctor with medical supplies who will treat customers that get food poisoning, etc. It just means t…

> I would say even the food safety analogy is appropriate.

I think it's NOT appropriate. Of course, in the end, it's a matter of value: Do you value your health equally with your digital privacy, your money, etc.? If 'yes' then the analogy yes, if 'no' then it doesn't. I don't so, to me, it doesn't.

Re: Sony Got Hacked Hard: What We Know and Don't Know So Far

#80

Many people suggest that startups not over-optimize on issues like security and performance when it's not their core business. The same could be said of Sony: empathize a little with them. Sony Pictures pays a lot of creative people. Maybe they should have seen the hack coming, but like the PSN outage this story will be maybe a paragraph in a Wikipedia article years from now. Even one great film could be watched by p…

Many people suggest that startups not over-optimize on issues like security and performance when it's not their core business. And that's a fucking stupid thing to say in those cases, so it's a fucking stupid thing to say here. Things like security and performance should be given. This is akin to arguing that small restaurants shouldn't care about food safety, or that small construction firms shouldn't worry about bu…

You're acting like there are no tradeoffs for these things. There are always tradeoffs.
Post reply on HN