Live data from Hacker News

Sony Got Hacked Hard: What We Know and Don't Know So Far

wired.com

121–130 of 184 posts

Re: Sony Got Hacked Hard: What We Know and Don't Know So Far

#121
post #53

Earlier quoted context omitted.

Many people suggest that startups not over-optimize on issues like security and performance when it's not their core business. And that's a fucking stupid thing to say in those cases, so it's a fucking stupid thing to say here. Things like security and performance should be given. This is akin to arguing that small restaurants shouldn't care about food safety, or that small construction firms shouldn't worry about bu…

When it comes to start-ups it's not stupid - it's wise. The food safety analogy is inappropriate. Security is about risk management. Low risks do not justify high expenses. When it comes to a company with hundreds of millions in revenues, however, they have clearly underestimated the risks and have been irresponsible.

A better analogy:

A start up is like a restaurant with 2 doors into the kitchen. 1 door from the outside, 1 door for servers to enter/exit.

In a restaurant the workers can easily spot problems. And if someone walks in usually you kick them out, or lose a batch of food. The cost is much smaller than hiring 2 full-time bouncers.

If, however, you now have a giant catering hall with 50 entrances to the kitchen and hundreds of people there, security / bouncers are necessary.

The problem is how to go from one to the other, and not realize you need security when it is too late.

Re: Sony Got Hacked Hard: What We Know and Don't Know So Far

#122

Earlier quoted context omitted.

Many people suggest that startups not over-optimize on issues like security and performance when it's not their core business. And that's a fucking stupid thing to say in those cases, so it's a fucking stupid thing to say here. Things like security and performance should be given. This is akin to arguing that small restaurants shouldn't care about food safety, or that small construction firms shouldn't worry about bu…

Firstly - What's with the fucking attitude? Secondly - Did you see the words over optimize? There is certainly such a thing as too much optimization in terms of security. Would you hire police men to patrol your kid's lemonade stand startup? No.

Yeah but this was clearly UNDER optimized for the security of 100 TB of SSNs, Salaries, and Movies leaked. All of which is classified as sensitive (i.e. anything that can be considered a financial loss to the business).

Re: Sony Got Hacked Hard: What We Know and Don't Know So Far

#124

Many people suggest that startups not over-optimize on issues like security and performance when it's not their core business. The same could be said of Sony: empathize a little with them. Sony Pictures pays a lot of creative people. Maybe they should have seen the hack coming, but like the PSN outage this story will be maybe a paragraph in a Wikipedia article years from now. Even one great film could be watched by p…

I once asked a lock pick artist what lock I should get for my house. They pointed out that if you have something valuable in your house, do you want to protect it with a 50 dollar lock or a 250 dollar lock. Basically they should have had better security; and I can bet they will spend the money for proper security now that they got owned so well.

It's a great time to be working in the security field today.

Re: Sony Got Hacked Hard: What We Know and Don't Know So Far

#125

Even though I am a massive supporter and advocate of whistle-blowing and leaking (in the public interest), the state of a lot of the journalism around this is appalling - esp the Gawker article. (Though the Wired one is pretty responsible in fairness.) Unless Sony has shown to be doing something malicious (which I don't think it has - other than some horrific Adam Sandler movies recently), then the angle of mining th…

During/after the recent leak of celebrities' private photos, the condemnation was swift and serious. People can see how that directly applies to their own life, they wouldn't want their photos out there like that.

But when it's a company -- it's apparently OK to just look through all their shit. It's already publicly available anyway, so what's the big deal?

Re: Sony Got Hacked Hard: What We Know and Don't Know So Far

#126

Earlier quoted context omitted.

Firstly - What's with the fucking attitude? Secondly - Did you see the words over optimize? There is certainly such a thing as too much optimization in terms of security. Would you hire police men to patrol your kid's lemonade stand startup? No.

Yeah but this was clearly UNDER optimized for the security of 100 TB of SSNs, Salaries, and Movies leaked. All of which is classified as sensitive (i.e. anything that can be considered a financial loss to the business).

Think about who would have access to:

1) 100Tb of storage on presumably short notice

2) The bandwidth required to move all of that before sony noticed

This [likely] wasn't some script kiddie that exploited some obvious security hole. Of course their security was under optimized. Every single theft in the history of time has been a result of "under optimized" security.

Ocean's 11 is about "under optimized" security.

Re: Sony Got Hacked Hard: What We Know and Don't Know So Far

#127

Earlier quoted context omitted.

Yes, there are. You can over-invest into security and performance. That doesn't mean that should shouldn't meet a competent standard!

Did Sony fail to meet a competent standard? The fact that they got hacked is not sufficient proof they failed that standard. "Competent" does not mean invulnerable.

The exfiltration of 100TB of data from systems across their entire organization suggests so.

On a 100Mbit/s pipe that would take something like 3 months of full saturation to get that amount of data out. Realistically, we're probably talking about a hack spanning nearly every one of their systems for upwards of a year.

Re: Sony Got Hacked Hard: What We Know and Don't Know So Far

#128
post #76

Earlier quoted context omitted.

I think fraction of their executive bonuses would be quite enough to fully fund a fairly decent security effort. If security were designed into their processes, it would probably cost much less. If the 100 TB figure is correct, this has been going on for some time - it takes time to steal that much data in a way that does not raise a bunch of red flags. If the red flags weren't there to be raised or they were and wer…

Let's talk numbers. A "fraction" of a bonus. Let's assume their bonus is a paltry 100k. A good infosec pro expects on average to be making at least 200k, so you have already blown out your budget. You can take a swing at hiring a consultant, but that gets you 5 weeks at around 70k, so you are eating a huge chunk of your fractional bonus budget. Consultants don't really work for systemic problems like this though. Son…

> A "fraction" of a bonus. Let's assume their bonus is a paltry 100k. A good infosec pro expects on average to be making at least 200k, so you have already blown out your budget.

I agree with your overall point, but the first page of the leaked salary list alone has something like $35M worth of bonuses. Say the high-level execs are the only ones sacrificing their pay, and the 'fraction' of bonuses was 20%, you'd have $7M annually to spend on infosec -- in addition to all of the money they're already spending (and apparently wasting). This would pay the salaries of ~30 top-notch security people.

Re: Sony Got Hacked Hard: What We Know and Don't Know So Far

#129

Many people suggest that startups not over-optimize on issues like security and performance when it's not their core business. The same could be said of Sony: empathize a little with them. Sony Pictures pays a lot of creative people. Maybe they should have seen the hack coming, but like the PSN outage this story will be maybe a paragraph in a Wikipedia article years from now. Even one great film could be watched by p…

Many people suggest that startups not over-optimize on issues like security and performance when it's not their core business. And that's a fucking stupid thing to say in those cases, so it's a fucking stupid thing to say here. Things like security and performance should be given. This is akin to arguing that small restaurants shouldn't care about food safety, or that small construction firms shouldn't worry about bu…

this entire thread of conversations is a joke. Do you know more about this breach than what was written in the article because they clearly state they don't know exactly what happened. Which isn't to say that Sony doesn't know more but from details released how can you know anything about what Sony does or doesn't do security wise that they should have been?

Like literally the first rule of Security is that as the person trying to defend, protect, secure something you are always at a disadvantage. Of course Sony has money to hire top notch Security Engineers to protect their interests and I'm sure they do but like anyone else they can be beat.

This is all not even accounting for the security black hole that is user idiocy, or the fact that the article makes several references to potential inside help.

In short Sony's past exploits don't give them a ton of credit but it's also a bit ridiculous to go from they could have done better to where this whole thread went.

Re: Sony Got Hacked Hard: What We Know and Don't Know So Far

#130

Earlier quoted context omitted.

Many people suggest that startups not over-optimize on issues like security and performance when it's not their core business. And that's a fucking stupid thing to say in those cases, so it's a fucking stupid thing to say here. Things like security and performance should be given. This is akin to arguing that small restaurants shouldn't care about food safety, or that small construction firms shouldn't worry about bu…

this entire thread of conversations is a joke. Do you know more about this breach than what was written in the article because they clearly state they don't know exactly what happened. Which isn't to say that Sony doesn't know more but from details released how can you know anything about what Sony does or doesn't do security wise that they should have been? Like literally the first rule of Security is that as the pe…

* Of course Sony has money to hire top notch Security Engineers to protect their interests and I'm sure they do but like anyone else they can be beat.*

Maybe they do; I don't know. That's not really relevant to the point which I'm making, which is more along the lines of:

"Disregarding security as a startup because it's not a 'core competency' is ill-advised. History suggests that you're likely to be compromised, and it causes harm not only to your business, but also to your users, and is absolutely irresponsible."

Post reply on HN