Live data from Hacker News

Sony Got Hacked Hard: What We Know and Don't Know So Far

wired.com

111–120 of 184 posts

Re: Sony Got Hacked Hard: What We Know and Don't Know So Far

#111

Many people suggest that startups not over-optimize on issues like security and performance when it's not their core business. The same could be said of Sony: empathize a little with them. Sony Pictures pays a lot of creative people. Maybe they should have seen the hack coming, but like the PSN outage this story will be maybe a paragraph in a Wikipedia article years from now. Even one great film could be watched by p…

> Many people suggest that startups not over-optimize on issues like security and performance when it's not their core business. > The same could be said of Sony:

How so? The whole point of saying it about startups is that they are startups.. they have severely limited capital and resources and need to optimize for growth/revenue/continuing to exist.

This does not apply to Sony. If you are storing medical records and SSNs and you are multi-billion dollar company; there is no viable excuse that looks anything like, "uhh.. yeah well we are really just an entertainment company."

Re: Sony Got Hacked Hard: What We Know and Don't Know So Far

#112

Earlier quoted context omitted.

Sony Pictures has an operating income (revenue minus expenses) of $501 million per year. They can afford to pay creatives, but they can't afford to pay for a few more security engineers? Look, I get the creative field costs a lot of money. But Sony Pictures was paying $454,224,070 http://fusion.net/story/30850/ in total salaries as of May. Even hiring 5 more security engineers would have gone a long way. That's $1 mi…

> They can afford to pay creatives, but they can't afford to pay for a few more security engineers? So how do you measure their risk and the probability of being damaged? Serious security experts are STILL trying to figure out how to calculate these things. Insurance companies still have trouble "properly" pricing cyber insurance. The insurance companies are doing it, but they are way behind their ability to price fo…

You do that through a Security Risk Assessment. There are plenty of models (e.g. Octave) out there to help a security engineer conduct a Risk assessment on an organization's infrastructure. Moreover, a Security Risk Assessment is very strongly suggested by any Security Compliance Program that deals with sensitive information.

This dump clearly shows personally identifiable information, something that would be easily classified as sensitive (e.g. SSNs). I'm very sure Sony Pictures classified their leaked movies as sensitive since it would cause massive financial loss (which happened) if it was stolen.

If anybody was doing a Risk Assessment, protecting this critical part of the infrastructure would have been number 1 on the list.

Hackers are even claiming that a physical door with access to the sensitive environment was left unlocked. That's security 101!

Re: Sony Got Hacked Hard: What We Know and Don't Know So Far

#113
post #92

Earlier quoted context omitted.

you are talking about human problems. people clicking links. people typing their passwords into foreign web forms. software engineers wont magically fix executives handing over credentials to hackers. if you were designing a network and interface to access your files, maybe you could design it without resorting to passwords, but that wasn't practical in sonys case. maybe they could have designed their network to noti…

> software engineers wont magically fix executives handing over credentials to hackers and all those important files were just lying around You can't project a film without a dedicated digital link to Sony's servers in London authorising it. For some movies they send personnel to your cinema to record the audience with IR cameras. For some movies you are not allowed to let the staff watch the film for free.

> and all those important files were just lying around

That's it. Whether a designer was comprised through a phishing attack or a physical door with access to the sensitive environment was left unlocked, there were clearly no controls in place to manage all the files just laying around like money under a mattress.

Re: Sony Got Hacked Hard: What We Know and Don't Know So Far

#114

Many people suggest that startups not over-optimize on issues like security and performance when it's not their core business. The same could be said of Sony: empathize a little with them. Sony Pictures pays a lot of creative people. Maybe they should have seen the hack coming, but like the PSN outage this story will be maybe a paragraph in a Wikipedia article years from now. Even one great film could be watched by p…

Many people suggest that startups not over-optimize on issues like security and performance when it's not their core business. And that's a fucking stupid thing to say in those cases, so it's a fucking stupid thing to say here. Things like security and performance should be given. This is akin to arguing that small restaurants shouldn't care about food safety, or that small construction firms shouldn't worry about bu…

Firstly - What's with the fucking attitude?

Secondly - Did you see the words over optimize? There is certainly such a thing as too much optimization in terms of security. Would you hire police men to patrol your kid's lemonade stand startup? No.

Re: Sony Got Hacked Hard: What We Know and Don't Know So Far

#115
post #92

Earlier quoted context omitted.

Sony Pictures has an operating income (revenue minus expenses) of $501 million per year. They can afford to pay creatives, but they can't afford to pay for a few more security engineers? Look, I get the creative field costs a lot of money. But Sony Pictures was paying $454,224,070 http://fusion.net/story/30850/ in total salaries as of May. Even hiring 5 more security engineers would have gone a long way. That's $1 mi…

you are talking about human problems. people clicking links. people typing their passwords into foreign web forms. software engineers wont magically fix executives handing over credentials to hackers. if you were designing a network and interface to access your files, maybe you could design it without resorting to passwords, but that wasn't practical in sonys case. maybe they could have designed their network to noti…

Security is multiple layers. A phishing attack (as you described) should only gets you 1 layer deep, it shouldn't give you access to everything. You still need to bypass the rest of the controls to get the delicious sensitive data. With a leak like this (100 TB of sensitive SSNs, Salaries, and Movies leaked), there clearly weren't very many controls, if any.

I think you're thinking too much about UX, Passwords, and phishing links when you're forgetting all the other layers that a usable security environment can provide without the needs of passwords (e.g. authorization control, segmented file servers for each department). A security engineer can definitely create a very safe and secure environment WITHOUT negatively impacting the usability, experience, or workflow of the creatives working on their designs and art.

Re: Sony Got Hacked Hard: What We Know and Don't Know So Far

#116
post #2

"Or that the company spent half a million this year in severance costs to terminate employees?" That's not much. Is Wired trying to make me think that is a lot? Or are they trying to play it against the salary figures? Considering they spent valuable words in the first sentence to make it clear that the top brass is "mostly" white males I get the impression the comparison was supposed to mean something.

Actually the "mostly white males" comment struck me as an interesting side note. Sony is a Japanese company, so for it to be run by "mostly white males" is something that seems noteworthy in itself. Though I doubt that's what they were going for when they wrote that.

Re: Sony Got Hacked Hard: What We Know and Don't Know So Far

#117
post #4

The North Korean theory seems silly. In fact, it's exactly what I might say publicly if I were Sony and I wanted to try and turn lemons (being hacked) into lemonade (free buzz about an upcoming movie). The movie Kim Jong-un doesn't want you to see! In the end, I doubt there was any hacking involved at all: a disgruntled employee leaked documents. Perhaps Sony forgot to disable someone's password after giving them the…

If they did it on purpose it's even sillier. They may think that it would be cool to say they "got hacked by a state" especially if it's related to an upcoming movie about it, but to me it seems like amateur hour at Sony if they got hacked by North Korea , a country not exactly known for its advanced technology and high computer usage.

> If they did it on purpose it's even sillier.

Doubtful. Several still-in-theater or unreleased movies are apparently up on torrent sites from this hack. I don't think that they would do this just to promote another film...

Re: Sony Got Hacked Hard: What We Know and Don't Know So Far

#118
post #116
post #2

"Or that the company spent half a million this year in severance costs to terminate employees?" That's not much. Is Wired trying to make me think that is a lot? Or are they trying to play it against the salary figures? Considering they spent valuable words in the first sentence to make it clear that the top brass is "mostly" white males I get the impression the comparison was supposed to mean something.

Actually the "mostly white males" comment struck me as an interesting side note. Sony is a Japanese company, so for it to be run by "mostly white males" is something that seems noteworthy in itself. Though I doubt that's what they were going for when they wrote that.

Not Sony but Sony Pictures Entertainment which is an american subsidiary.

Re: Sony Got Hacked Hard: What We Know and Don't Know So Far

#119
post #83
post #79

Earlier quoted context omitted.

> I would say even the food safety analogy is appropriate. I think it's NOT appropriate. Of course, in the end, it's a matter of value: Do you value your health equally with your digital privacy, your money, etc.? If 'yes' then the analogy yes, if 'no' then it doesn't. I don't so, to me, it doesn't.

Analogies are not meant to be precisely equivalent in every respect. They're just a tool to illustrate a certain point.

Oh so like, Analogies are like butterflies! Not everyone understands them, and sometimes people who do still miss the point of them.

Re: Sony Got Hacked Hard: What We Know and Don't Know So Far

#120

Even though I am a massive supporter and advocate of whistle-blowing and leaking (in the public interest), the state of a lot of the journalism around this is appalling - esp the Gawker article. (Though the Wired one is pretty responsible in fairness.) Unless Sony has shown to be doing something malicious (which I don't think it has - other than some horrific Adam Sandler movies recently), then the angle of mining th…

[deleted]
Post reply on HN