You'd think they would've learned a thing or two after they were made the hackers' pinata the last time around. Sony continues to come up as the poster-boy company for weak security.
That was a different Sony company that was hacked. I don't think they share much in common except the Sony name.
Sony Got Hacked Hard: What We Know and Don't Know So Far
91–100 of 184 posts
Re: Sony Got Hacked Hard: What We Know and Don't Know So Far
#92Many people suggest that startups not over-optimize on issues like security and performance when it's not their core business. The same could be said of Sony: empathize a little with them. Sony Pictures pays a lot of creative people. Maybe they should have seen the hack coming, but like the PSN outage this story will be maybe a paragraph in a Wikipedia article years from now. Even one great film could be watched by p…
Sony Pictures has an operating income (revenue minus expenses) of $501 million per year. They can afford to pay creatives, but they can't afford to pay for a few more security engineers? Look, I get the creative field costs a lot of money. But Sony Pictures was paying $454,224,070 http://fusion.net/story/30850/ in total salaries as of May. Even hiring 5 more security engineers would have gone a long way. That's $1 mi…
software engineers wont magically fix executives handing over credentials to hackers.
if you were designing a network and interface to access your files, maybe you could design it without resorting to passwords, but that wasn't practical in sonys case.
maybe they could have designed their network to notice the data leaving, but again, the hackers could always find a way to win. (physical infiltration of the company and a verizon hotspot?)
Re: Sony Got Hacked Hard: What We Know and Don't Know So Far
#93Earlier quoted context omitted.
> "It's changing our business," says one producer of its impact on Hollywood. "From now on, money and time will be allocated by studios to deal with this full-time." Shame that most of Sony's Finance and HR are blaming the IT department - so bloody typical! "Everyone’s looking to the IT department to say, ‘How did you let this happen?'" said one employee in Sony Pictures’ finance department." http://fusion.net/story/…
I work in an IT department. Pretty sure IT Security would be the responsibility of somebody here.
Re: Sony Got Hacked Hard: What We Know and Don't Know So Far
#94Anecdotally, I knew some guys who worked at (or with?) the global security division at Sony US HQ. The story went that each of the Sony subsidiaries[1] had their own security division that was largely autonomous for reasons of politics and budget, of course. Each part of the company had different vendors, different policies and procedures, and different philosophies on how security should be implemented. When they wo…
And they could centralize all of that and ... it still wouldn't solve the problem. You'd have a single point of failure that might still leave them with their pants down at the end of the day.
Some days, you just can't win. You can have the smartest people (they probably didn't), the best hardware and software (ditto) and you're still gonna get punched in the junk.
Re: Sony Got Hacked Hard: What We Know and Don't Know So Far
#95Earlier quoted context omitted.
Sony Pictures has an operating income (revenue minus expenses) of $501 million per year. They can afford to pay creatives, but they can't afford to pay for a few more security engineers? Look, I get the creative field costs a lot of money. But Sony Pictures was paying $454,224,070 http://fusion.net/story/30850/ in total salaries as of May. Even hiring 5 more security engineers would have gone a long way. That's $1 mi…
Security is also incredibly, incredibly hard. Google were hacked quite hard as well, remember?
My account was included yet my password was 18 months out of date.
Re: Sony Got Hacked Hard: What We Know and Don't Know So Far
#96Earlier quoted context omitted.
I think fraction of their executive bonuses would be quite enough to fully fund a fairly decent security effort. If security were designed into their processes, it would probably cost much less. If the 100 TB figure is correct, this has been going on for some time - it takes time to steal that much data in a way that does not raise a bunch of red flags. If the red flags weren't there to be raised or they were and wer…
Let's talk numbers. A "fraction" of a bonus. Let's assume their bonus is a paltry 100k. A good infosec pro expects on average to be making at least 200k, so you have already blown out your budget. You can take a swing at hiring a consultant, but that gets you 5 weeks at around 70k, so you are eating a huge chunk of your fractional bonus budget. Consultants don't really work for systemic problems like this though. Son…
In any case, thanks to the leaked information, it should be easy to tell exactly how much Sony paid the people who are responsible for this mess.
Security is hard, but this looks like a lot of low hanging fruit being picked effortlessly. My bet is that just a tiny bit of effort would have made the intruders work much harder.
Re: Sony Got Hacked Hard: What We Know and Don't Know So Far
#97I am not a sysadmin or network security guy, so I have to ask: how could hackers siphon as much as 100 terabytes of data from Sony's network without being noticed? Shouldn't they have indictors to see their bandwidth was running dry? If so, did the GOP do it slowly to avoid drawing attention?
Re: Sony Got Hacked Hard: What We Know and Don't Know So Far
#98Many people suggest that startups not over-optimize on issues like security and performance when it's not their core business. The same could be said of Sony: empathize a little with them. Sony Pictures pays a lot of creative people. Maybe they should have seen the hack coming, but like the PSN outage this story will be maybe a paragraph in a Wikipedia article years from now. Even one great film could be watched by p…
Many people suggest that startups not over-optimize on issues like security and performance when it's not their core business. And that's a fucking stupid thing to say in those cases, so it's a fucking stupid thing to say here. Things like security and performance should be given. This is akin to arguing that small restaurants shouldn't care about food safety, or that small construction firms shouldn't worry about bu…
No, it's completely different. Food safety and building codes is akin to good software engineering; on the other hand, security against hacks is more like a restaurant protecting you from a third party poisoning your food, or a building withstanding planes crashing into it. Most building and most restaurants don't offer such protection.
Re: Sony Got Hacked Hard: What We Know and Don't Know So Far
#99Many people suggest that startups not over-optimize on issues like security and performance when it's not their core business. The same could be said of Sony: empathize a little with them. Sony Pictures pays a lot of creative people. Maybe they should have seen the hack coming, but like the PSN outage this story will be maybe a paragraph in a Wikipedia article years from now. Even one great film could be watched by p…
I think fraction of their executive bonuses would be quite enough to fully fund a fairly decent security effort. If security were designed into their processes, it would probably cost much less. If the 100 TB figure is correct, this has been going on for some time - it takes time to steal that much data in a way that does not raise a bunch of red flags. If the red flags weren't there to be raised or they were and wer…
Re: Sony Got Hacked Hard: What We Know and Don't Know So Far
#100Earlier quoted context omitted.
Sony Pictures has an operating income (revenue minus expenses) of $501 million per year. They can afford to pay creatives, but they can't afford to pay for a few more security engineers? Look, I get the creative field costs a lot of money. But Sony Pictures was paying $454,224,070 http://fusion.net/story/30850/ in total salaries as of May. Even hiring 5 more security engineers would have gone a long way. That's $1 mi…
you are talking about human problems. people clicking links. people typing their passwords into foreign web forms. software engineers wont magically fix executives handing over credentials to hackers. if you were designing a network and interface to access your files, maybe you could design it without resorting to passwords, but that wasn't practical in sonys case. maybe they could have designed their network to noti…
and all those important files were just lying around
You can't project a film without a dedicated digital link to Sony's servers in London authorising it. For some movies they send personnel to your cinema to record the audience with IR cameras. For some movies you are not allowed to let the staff watch the film for free.