Earlier quoted context omitted.
Many people suggest that startups not over-optimize on issues like security and performance when it's not their core business. And that's a fucking stupid thing to say in those cases, so it's a fucking stupid thing to say here. Things like security and performance should be given. This is akin to arguing that small restaurants shouldn't care about food safety, or that small construction firms shouldn't worry about bu…
When it comes to start-ups it's not stupid - it's wise. The food safety analogy is inappropriate. Security is about risk management. Low risks do not justify high expenses. When it comes to a company with hundreds of millions in revenues, however, they have clearly underestimated the risks and have been irresponsible.
Sony Got Hacked Hard: What We Know and Don't Know So Far
71–80 of 184 posts
Re: Sony Got Hacked Hard: What We Know and Don't Know So Far
#72I am not a sysadmin or network security guy, so I have to ask: how could hackers siphon as much as 100 terabytes of data from Sony's network without being noticed? Shouldn't they have indictors to see their bandwidth was running dry? If so, did the GOP do it slowly to avoid drawing attention?
All the "hackers" have to do is copy the date in a matter that does not cause obvious problems. For example, as you said, do it slowly, or do it at night when "nobody's" using the network anyway.
Re: Sony Got Hacked Hard: What We Know and Don't Know So Far
#73I am not a sysadmin or network security guy, so I have to ask: how could hackers siphon as much as 100 terabytes of data from Sony's network without being noticed? Shouldn't they have indictors to see their bandwidth was running dry? If so, did the GOP do it slowly to avoid drawing attention?
For a network the size of Sony's, it seems like that volume should be relatively easy to smuggle out. Maybe not all at once, right?
Re: Sony Got Hacked Hard: What We Know and Don't Know So Far
#74"Or that the company spent half a million this year in severance costs to terminate employees?" That's not much. Is Wired trying to make me think that is a lot? Or are they trying to play it against the salary figures? Considering they spent valuable words in the first sentence to make it clear that the top brass is "mostly" white males I get the impression the comparison was supposed to mean something.
IMO if an article starts with > Who knew that Sony’s top brass, a line-up of mostly white male executives, earn $1 million and more a year? I'm already putting my expectations for the rest of it on the same level as those for this famous one: > I don't care if you landed a spacecraft on a comet, your shirt is sexist and ostracizing. ( http://www.theverge.com/2014/11/13/7213819/your-bowling-shir... ) I wonder when it'…
Re: Sony Got Hacked Hard: What We Know and Don't Know So Far
#75It's Sony Pictures Entertainment that got hacked, not Sony. They're completely separate companies, yet the media fails to recognize that. Very annoying and confusing, it's almost deliberately.
Re: Sony Got Hacked Hard: What We Know and Don't Know So Far
#76Many people suggest that startups not over-optimize on issues like security and performance when it's not their core business. The same could be said of Sony: empathize a little with them. Sony Pictures pays a lot of creative people. Maybe they should have seen the hack coming, but like the PSN outage this story will be maybe a paragraph in a Wikipedia article years from now. Even one great film could be watched by p…
If the 100 TB figure is correct, this has been going on for some time - it takes time to steal that much data in a way that does not raise a bunch of red flags. If the red flags weren't there to be raised or they were and were ignored, well... at least their executives got their bonuses.
Also, in the interest of fairness, while this malware attack seemed to be directed to Windows machines, a dedicated enough intruder would have developed attack strategies for any platform.
Re: Sony Got Hacked Hard: What We Know and Don't Know So Far
#77The story went that each of the Sony subsidiaries[1] had their own security division that was largely autonomous for reasons of politics and budget, of course. Each part of the company had different vendors, different policies and procedures, and different philosophies on how security should be implemented.
When they would all send their representatives to have a global security pow wow, however often it happened, it ended up like an episode of game of thrones.
[1] http://en.wikipedia.org/wiki/Sony_Corporation_shareholders_a...
Re: Sony Got Hacked Hard: What We Know and Don't Know So Far
#78The compensation levels should't be confidential in the first place. This policy is only useful to the wrong people. This is how we get artificially low market rates for developers and ridiculous amounts of money paid to incompetent execs. edit: the downvotes are an indication that you deserve your bullshit laws/status quo
Re: Sony Got Hacked Hard: What We Know and Don't Know So Far
#79Earlier quoted context omitted.
When it comes to start-ups it's not stupid - it's wise. The food safety analogy is inappropriate. Security is about risk management. Low risks do not justify high expenses. When it comes to a company with hundreds of millions in revenues, however, they have clearly underestimated the risks and have been irresponsible.
I would say even the food safety analogy is appropriate. Sure, food safety is important; that doesn't mean you have to spend hundreds of millions of pounds in "food safety researchers" who will conduct rigorous scientific experiments to find out the best ways to limit the spread of germs and implement them, an in-house doctor with medical supplies who will treat customers that get food poisoning, etc. It just means t…
I think it's NOT appropriate. Of course, in the end, it's a matter of value: Do you value your health equally with your digital privacy, your money, etc.? If 'yes' then the analogy yes, if 'no' then it doesn't. I don't so, to me, it doesn't.
Re: Sony Got Hacked Hard: What We Know and Don't Know So Far
#80Many people suggest that startups not over-optimize on issues like security and performance when it's not their core business. The same could be said of Sony: empathize a little with them. Sony Pictures pays a lot of creative people. Maybe they should have seen the hack coming, but like the PSN outage this story will be maybe a paragraph in a Wikipedia article years from now. Even one great film could be watched by p…
Many people suggest that startups not over-optimize on issues like security and performance when it's not their core business. And that's a fucking stupid thing to say in those cases, so it's a fucking stupid thing to say here. Things like security and performance should be given. This is akin to arguing that small restaurants shouldn't care about food safety, or that small construction firms shouldn't worry about bu…