Live data from Hacker News

Sony Got Hacked Hard: What We Know and Don't Know So Far

wired.com

101–110 of 184 posts

Re: Sony Got Hacked Hard: What We Know and Don't Know So Far

#102

Many people suggest that startups not over-optimize on issues like security and performance when it's not their core business. The same could be said of Sony: empathize a little with them. Sony Pictures pays a lot of creative people. Maybe they should have seen the hack coming, but like the PSN outage this story will be maybe a paragraph in a Wikipedia article years from now. Even one great film could be watched by p…

Sony Pictures has an operating income (revenue minus expenses) of $501 million per year. They can afford to pay creatives, but they can't afford to pay for a few more security engineers? Look, I get the creative field costs a lot of money. But Sony Pictures was paying $454,224,070 http://fusion.net/story/30850/ in total salaries as of May. Even hiring 5 more security engineers would have gone a long way. That's $1 mi…

> They can afford to pay creatives, but they can't afford to pay for a few more security engineers?

So how do you measure their risk and the probability of being damaged? Serious security experts are STILL trying to figure out how to calculate these things. Insurance companies still have trouble "properly" pricing cyber insurance. The insurance companies are doing it, but they are way behind their ability to price for other forms of disasters.

So how much should they spend towards cyber security? How far off are they from that amount? We don't know. (well maybe we'll know from the leaked documents).

Re: Sony Got Hacked Hard: What We Know and Don't Know So Far

#104

Many people suggest that startups not over-optimize on issues like security and performance when it's not their core business. The same could be said of Sony: empathize a little with them. Sony Pictures pays a lot of creative people. Maybe they should have seen the hack coming, but like the PSN outage this story will be maybe a paragraph in a Wikipedia article years from now. Even one great film could be watched by p…

Sony Pictures has an operating income (revenue minus expenses) of $501 million per year. They can afford to pay creatives, but they can't afford to pay for a few more security engineers? Look, I get the creative field costs a lot of money. But Sony Pictures was paying $454,224,070 http://fusion.net/story/30850/ in total salaries as of May. Even hiring 5 more security engineers would have gone a long way. That's $1 mi…

Why can't they be like Sony Music, and not pay creatives at all.

Re: Sony Got Hacked Hard: What We Know and Don't Know So Far

#105
post #99
post #76

Earlier quoted context omitted.

I think fraction of their executive bonuses would be quite enough to fully fund a fairly decent security effort. If security were designed into their processes, it would probably cost much less. If the 100 TB figure is correct, this has been going on for some time - it takes time to steal that much data in a way that does not raise a bunch of red flags. If the red flags weren't there to be raised or they were and wer…

100TB? Seems more likely nobody noticed a team carrying out some thirty-five 3TB external drives. If their network was able to maintain operations while somebody sucked out 100TB of data through their gateway, I'm impressed.

Any serious operation dealing with the amount of media (images, videos, various editing files, etc) that Sony was is going to have very fat pipes. They probably moved upwards of a few TBs a day.

Re: Sony Got Hacked Hard: What We Know and Don't Know So Far

#106
post #77

Anecdotally, I knew some guys who worked at (or with?) the global security division at Sony US HQ. The story went that each of the Sony subsidiaries[1] had their own security division that was largely autonomous for reasons of politics and budget, of course. Each part of the company had different vendors, different policies and procedures, and different philosophies on how security should be implemented. When they wo…

> The story went that each of the Sony subsidiaries[1] had their own security division that was largely autonomous for reasons of politics and budget, of course. Each part of the company had different vendors, different policies and procedures, and different philosophies on how security should be implemented. And they could centralize all of that and ... it still wouldn't solve the problem. You'd have a single point…

Absolutely. I think it is a very difficult problem to solve as companies grow larger and larger and rise to behemoth proportions all while trying to tackle something that is relatively new (the security concerns of today, as opposed to say the 80's,90's,2000's when Sony didn't have to be as competitive in the products that they offered) and typically expensive (for a company Sony's size) where funding for these things seem to be viewed in terms of $ now, instead of potential $ later.

Re: Sony Got Hacked Hard: What We Know and Don't Know So Far

#108

Many people suggest that startups not over-optimize on issues like security and performance when it's not their core business. The same could be said of Sony: empathize a little with them. Sony Pictures pays a lot of creative people. Maybe they should have seen the hack coming, but like the PSN outage this story will be maybe a paragraph in a Wikipedia article years from now. Even one great film could be watched by p…

Many people suggest that startups not over-optimize on issues like security and performance when it's not their core business. And that's a fucking stupid thing to say in those cases, so it's a fucking stupid thing to say here. Things like security and performance should be given. This is akin to arguing that small restaurants shouldn't care about food safety, or that small construction firms shouldn't worry about bu…

[deleted]

Re: Sony Got Hacked Hard: What We Know and Don't Know So Far

#109
post #98

Earlier quoted context omitted.

Many people suggest that startups not over-optimize on issues like security and performance when it's not their core business. And that's a fucking stupid thing to say in those cases, so it's a fucking stupid thing to say here. Things like security and performance should be given. This is akin to arguing that small restaurants shouldn't care about food safety, or that small construction firms shouldn't worry about bu…

> Things like security and performance should be given. This is akin to arguing that small restaurants shouldn't care about food safety, or that small construction firms shouldn't worry about building codes. No, it's completely different. Food safety and building codes is akin to good software engineering; on the other hand, security against hacks is more like a restaurant protecting you from a third party poisoning…

If we're talking about security and a small restaurant, it would be more like the restaurant never bothering to lock its doors after hours, having no security cameras, and not bothering to put its money in a safe place, leaving it out in the open to be stolen.
Post reply on HN