Earlier quoted context omitted.
Very common. https://www.google.com/search?q=pastebin.com%20email%20and%2...
Don't they have some kind of policy to get rid of these things?
Sony Got Hacked Hard: What We Know and Don't Know So Far
81–90 of 184 posts
Re: Sony Got Hacked Hard: What We Know and Don't Know So Far
#82Re: Sony Got Hacked Hard: What We Know and Don't Know So Far
#83Earlier quoted context omitted.
I would say even the food safety analogy is appropriate. Sure, food safety is important; that doesn't mean you have to spend hundreds of millions of pounds in "food safety researchers" who will conduct rigorous scientific experiments to find out the best ways to limit the spread of germs and implement them, an in-house doctor with medical supplies who will treat customers that get food poisoning, etc. It just means t…
> I would say even the food safety analogy is appropriate. I think it's NOT appropriate. Of course, in the end, it's a matter of value: Do you value your health equally with your digital privacy, your money, etc.? If 'yes' then the analogy yes, if 'no' then it doesn't. I don't so, to me, it doesn't.
Re: Sony Got Hacked Hard: What We Know and Don't Know So Far
#84Re: Sony Got Hacked Hard: What We Know and Don't Know So Far
#85Earlier quoted context omitted.
Many people suggest that startups not over-optimize on issues like security and performance when it's not their core business. And that's a fucking stupid thing to say in those cases, so it's a fucking stupid thing to say here. Things like security and performance should be given. This is akin to arguing that small restaurants shouldn't care about food safety, or that small construction firms shouldn't worry about bu…
When it comes to start-ups it's not stupid - it's wise. The food safety analogy is inappropriate. Security is about risk management. Low risks do not justify high expenses. When it comes to a company with hundreds of millions in revenues, however, they have clearly underestimated the risks and have been irresponsible.
What is the expense associated with, for example, not concatenating user-supplied input in SQL queries?
Re: Sony Got Hacked Hard: What We Know and Don't Know So Far
#86Earlier quoted context omitted.
> "It's changing our business," says one producer of its impact on Hollywood. "From now on, money and time will be allocated by studios to deal with this full-time." Shame that most of Sony's Finance and HR are blaming the IT department - so bloody typical! "Everyone’s looking to the IT department to say, ‘How did you let this happen?'" said one employee in Sony Pictures’ finance department." http://fusion.net/story/…
I work in an IT department. Pretty sure IT Security would be the responsibility of somebody here.
It got ignored.
If they ever get hacked, I won't be surprised.
Re: Sony Got Hacked Hard: What We Know and Don't Know So Far
#87Earlier quoted context omitted.
Many people suggest that startups not over-optimize on issues like security and performance when it's not their core business. And that's a fucking stupid thing to say in those cases, so it's a fucking stupid thing to say here. Things like security and performance should be given. This is akin to arguing that small restaurants shouldn't care about food safety, or that small construction firms shouldn't worry about bu…
You're acting like there are no tradeoffs for these things. There are always tradeoffs.
Re: Sony Got Hacked Hard: What We Know and Don't Know So Far
#88Earlier quoted context omitted.
You're acting like there are no tradeoffs for these things. There are always tradeoffs.
Yes, there are. You can over-invest into security and performance. That doesn't mean that should shouldn't meet a competent standard!
Re: Sony Got Hacked Hard: What We Know and Don't Know So Far
#89We created a security environment that prioritizes surveillance over security, especially in creating a market for zero-day exploits. That's a market that might exist without the US as a buyer, but the size and value of that market is dominated by US spending.
We would not tolerate the development and auctioning of weaponized disease microbes. But we funded a similar market that threatens our technology infrastructure.
Re: Sony Got Hacked Hard: What We Know and Don't Know So Far
#90Many people suggest that startups not over-optimize on issues like security and performance when it's not their core business. The same could be said of Sony: empathize a little with them. Sony Pictures pays a lot of creative people. Maybe they should have seen the hack coming, but like the PSN outage this story will be maybe a paragraph in a Wikipedia article years from now. Even one great film could be watched by p…
I think fraction of their executive bonuses would be quite enough to fully fund a fairly decent security effort. If security were designed into their processes, it would probably cost much less. If the 100 TB figure is correct, this has been going on for some time - it takes time to steal that much data in a way that does not raise a bunch of red flags. If the red flags weren't there to be raised or they were and wer…
A "fraction" of a bonus. Let's assume their bonus is a paltry 100k. A good infosec pro expects on average to be making at least 200k, so you have already blown out your budget. You can take a swing at hiring a consultant, but that gets you 5 weeks at around 70k, so you are eating a huge chunk of your fractional bonus budget.
Consultants don't really work for systemic problems like this though. Sony has cancer. They need empowered specialists to come in and tear out and then replace. These are both technical and managerial problems that exceed the capabilities of your average defcon attendee.
I disagree with both the approach you have taken here in envoking executive pay envy, as well as the substance. Security is hard. Practicing good security is expensive. You don't get to throw a couple of hundred grand around once and call it good. It is an ongoing and expensive investment.