Live data from Hacker News

Sony Got Hacked Hard: What We Know and Don't Know So Far

wired.com

131–140 of 184 posts

Re: Sony Got Hacked Hard: What We Know and Don't Know So Far

#131
post #4

The North Korean theory seems silly. In fact, it's exactly what I might say publicly if I were Sony and I wanted to try and turn lemons (being hacked) into lemonade (free buzz about an upcoming movie). The movie Kim Jong-un doesn't want you to see! In the end, I doubt there was any hacking involved at all: a disgruntled employee leaked documents. Perhaps Sony forgot to disable someone's password after giving them the…

Except for the part where a flaming skull abruptly appeared on the screens of all the employees, forcing everyone to go home? How much more "hack" can you get?

Re: Sony Got Hacked Hard: What We Know and Don't Know So Far

#132

Many people suggest that startups not over-optimize on issues like security and performance when it's not their core business. The same could be said of Sony: empathize a little with them. Sony Pictures pays a lot of creative people. Maybe they should have seen the hack coming, but like the PSN outage this story will be maybe a paragraph in a Wikipedia article years from now. Even one great film could be watched by p…

I once asked a lock pick artist what lock I should get for my house. They pointed out that if you have something valuable in your house, do you want to protect it with a 50 dollar lock or a 250 dollar lock. Basically they should have had better security; and I can bet they will spend the money for proper security now that they got owned so well. It's a great time to be working in the security field today.

That's an amazingly narrow-minded way of looking at a problem. It's easier and quicker to break your window than to pick your lock, $50 or $250.

Re: Sony Got Hacked Hard: What We Know and Don't Know So Far

#133

Re/code is claiming that Sony will officially name North Korea as the source of the attack: http://recode.net/2014/12/03/sony-to-officially-name-north-k... Sony Pictures will officially name North Korea as the source of a hacking attack that has exposed sensitive files and brought down its corporate network last week, two sources close to the investigation tell Re/code. An announcement could come as soon as today. De…

"Harming the regional peace and security and violating human rights for money". Interesting. The focus on this film and these supposed ideals make it sound very regional. I'm not saying it's North Korea, but it's someone in the region. Assuming the "purported hacker" actually had something to do with it.

Re: Sony Got Hacked Hard: What We Know and Don't Know So Far

#134
post #22
post #19

So. Sony America suffered an outage on the Playstation Network due to a hack in 2011 causing 171 million in damages (that's the official figure, who knows how much the lost goodwill cost them ongoing). After that if they did not make cybersecurity priority number 1 then they deserve what they've gotten. Fool me once, shame on you; fool me twice, shame on me.

Effectively, Sony Computer Entertainment and Sony Pictures Entertainment are about as related as Virgin Airlines and Virgin Mobile. Think of Sony (and any conglomerate in general) not as a parent company per se , but more like a VC firm or a majority-shareholder mutual fund; the executives of the Sony conglomerate don't really have any more insight into the component companies than those companies' other shareholders…

and yet this happened http://www.theregister.co.uk/2014/12/03/strange_things_afoot...

PSN computers hosted leak torrent, so PSN was also hacked

Re: Sony Got Hacked Hard: What We Know and Don't Know So Far

#135

Many people suggest that startups not over-optimize on issues like security and performance when it's not their core business. The same could be said of Sony: empathize a little with them. Sony Pictures pays a lot of creative people. Maybe they should have seen the hack coming, but like the PSN outage this story will be maybe a paragraph in a Wikipedia article years from now. Even one great film could be watched by p…

Sony Pictures has an operating income (revenue minus expenses) of $501 million per year. They can afford to pay creatives, but they can't afford to pay for a few more security engineers? Look, I get the creative field costs a lot of money. But Sony Pictures was paying $454,224,070 http://fusion.net/story/30850/ in total salaries as of May. Even hiring 5 more security engineers would have gone a long way. That's $1 mi…

Sony has a culture problem: if it is not a Japanese initiative, it doesn't happen. Unfortunately, the Japanese web executives are at least 10 years behind on Silicon Valley, on knowledge and vision. For as long as there isn't a Japanese security expert, born in Japan and groomed at Sony, Sony will continue taking these types of blows.

Re: Sony Got Hacked Hard: What We Know and Don't Know So Far

#136
Are their backups OK? That's the only real issue.

None of the "leaked" data is that interesting. Some executive pay info is in SEC filings. Talent pay is usually known in Hollywood. Leaking the script of Annie? That's a remake; we know how it comes out.

The real question is, what did the attackers change? Did they add some phony businesses to accounts payable, or initiate financial transactions?

There's a lot to be said for making backups to write-once media.

Re: Sony Got Hacked Hard: What We Know and Don't Know So Far

#137
http://www.theverge.com/2014/12/4/7333263/the-malware-that-t...

in the article it says "and the computer that did the compiling was set up to display its text in Korean characters."

i have a problem digesting this, because as per my experience, the compiler doesn't leave a trace the native host's display language or does it?

what do you people have to say about it?

Re: Sony Got Hacked Hard: What We Know and Don't Know So Far

#138
post #83

Earlier quoted context omitted.

Analogies are not meant to be precisely equivalent in every respect. They're just a tool to illustrate a certain point.

Oh so like, Analogies are like butterflies! Not everyone understands them, and sometimes people who do still miss the point of them.

Analogies are exactly like butterflies. Someone uses one once, and it causes a hurricane in a different comment thread. ;)

Re: Sony Got Hacked Hard: What We Know and Don't Know So Far

#139
Opening an article these days with:

> Who knew that Sony’s top brass, a line-up of mostly white male executives, earn $1 million and more a year?

is just take advantage of a difficult moment and increase the `hate`.

I don't get why this could happen on magazine like Wired...

Reading comments on the article seems that statement is pretty unfair.

I didn't check myself because I think reading those informations is bad as the hack itself, however the author who did that can also feel free to judge others.

Re: Sony Got Hacked Hard: What We Know and Don't Know So Far

#140
post #126

Earlier quoted context omitted.

Yeah but this was clearly UNDER optimized for the security of 100 TB of SSNs, Salaries, and Movies leaked. All of which is classified as sensitive (i.e. anything that can be considered a financial loss to the business).

Think about who would have access to: 1) 100Tb of storage on presumably short notice 2) The bandwidth required to move all of that before sony noticed This [likely] wasn't some script kiddie that exploited some obvious security hole. Of course their security was under optimized. Every single theft in the history of time has been a result of "under optimized" security. Ocean's 11 is about "under optimized" security.

Figure a hacking group is a dozen people. That's ~8.3T per person to stash. I know plenty of folks with that kind of storage lying around, it doesn't seem insane that folks deep in infosec might have even more idle capacity.

Alternatively the first newegg hit for a 6T hard drive is $300 even. That's 17 of them so $5k plus shipping. Either add in a chassis with enough slots or enough smaller machines to distribute it so say double to $10k or less than $1k per person.

Or even lazier, to store all 100T on S3 for a month and pull it back out is ~$12k, again maybe plus a bit for an EC2 instance to do the shuffling. Again, ~$1k per person.

And of course if you're a hacking group the chances that you've got root on some small business servers scattered around the world are probably a bit better than zero.

Post reply on HN