Live data from Hacker News

Sony Got Hacked Hard: What We Know and Don't Know So Far

wired.com

171–180 of 184 posts

Re: Sony Got Hacked Hard: What We Know and Don't Know So Far

#171

Many people suggest that startups not over-optimize on issues like security and performance when it's not their core business. The same could be said of Sony: empathize a little with them. Sony Pictures pays a lot of creative people. Maybe they should have seen the hack coming, but like the PSN outage this story will be maybe a paragraph in a Wikipedia article years from now. Even one great film could be watched by p…

No one suggests that startups not over-optimize on security or performance because these are not their core business. They suggest that they don't optimize for them because they have extremely limited resources compared to big corporations like Sony.

It doesn't matter how much time a startup spends on security and performance if they never find product-market fit and get to the explosive growth phase. Once they do however, this is when they need to raise real money and start addressing these "non-core" issues as well.

Sony is not a startup, is not resource constrained, etc. There's absolutely no reason to empathize with them.

Re: Sony Got Hacked Hard: What We Know and Don't Know So Far

#172

Many people suggest that startups not over-optimize on issues like security and performance when it's not their core business. The same could be said of Sony: empathize a little with them. Sony Pictures pays a lot of creative people. Maybe they should have seen the hack coming, but like the PSN outage this story will be maybe a paragraph in a Wikipedia article years from now. Even one great film could be watched by p…

I once asked a lock pick artist what lock I should get for my house. They pointed out that if you have something valuable in your house, do you want to protect it with a 50 dollar lock or a 250 dollar lock. Basically they should have had better security; and I can bet they will spend the money for proper security now that they got owned so well. It's a great time to be working in the security field today.

> do you want to protect it with a 50 dollar lock or a 250 dollar lock

It's not obvious to me that the $250 lock actually performs better in any relevant way. You might trust the guy, but when I'm hearing an anecdote second-hand I want to hear something more convincing than "trust the price".

Which is very much the problem -- it's quite hard for security non-experts to distinguish between good security and security theatre.

Re: Sony Got Hacked Hard: What We Know and Don't Know So Far

#173
post #92

Earlier quoted context omitted.

you are talking about human problems. people clicking links. people typing their passwords into foreign web forms. software engineers wont magically fix executives handing over credentials to hackers. if you were designing a network and interface to access your files, maybe you could design it without resorting to passwords, but that wasn't practical in sonys case. maybe they could have designed their network to noti…

> software engineers wont magically fix executives handing over credentials to hackers and all those important files were just lying around You can't project a film without a dedicated digital link to Sony's servers in London authorising it. For some movies they send personnel to your cinema to record the audience with IR cameras. For some movies you are not allowed to let the staff watch the film for free.

How much of that is really security vs. excercising power and control over a market?

Re: Sony Got Hacked Hard: What We Know and Don't Know So Far

#174

Earlier quoted context omitted.

> A "fraction" of a bonus. Let's assume their bonus is a paltry 100k. A good infosec pro expects on average to be making at least 200k, so you have already blown out your budget. I agree with your overall point, but the first page of the leaked salary list alone has something like $35M worth of bonuses. Say the high-level execs are the only ones sacrificing their pay, and the 'fraction' of bonuses was 20%, you'd have…

Why would the high-level execs sacrifice their pay? Is their pay really at risk from this breach?

Indeed. Why would they ever act to sacrifice themselves to benefit the company?

Re: Sony Got Hacked Hard: What We Know and Don't Know So Far

#175

Earlier quoted context omitted.

> A "fraction" of a bonus. Let's assume their bonus is a paltry 100k. A good infosec pro expects on average to be making at least 200k, so you have already blown out your budget. I agree with your overall point, but the first page of the leaked salary list alone has something like $35M worth of bonuses. Say the high-level execs are the only ones sacrificing their pay, and the 'fraction' of bonuses was 20%, you'd have…

Why would the high-level execs sacrifice their pay? Is their pay really at risk from this breach?

Ostensibly, executive bonuses in publicly traded companies are tied to actions that are a proxy for increasing shareholder value. Massive damaging hacks are not good for shareholder value.

In any case, it was just a comparative point, they clearly have the cash flows to hire competent security staff without impacting others' pay if they so desire.

Re: Sony Got Hacked Hard: What We Know and Don't Know So Far

#176

Earlier quoted context omitted.

"White" has been used as a common term for a race longer than anyone living has been alive, so, no, I don't think anyone alive could miss the days when "white" wasn't a race. People can, I suppose, miss the days when "white", as a term for a race, had almost exclusivey positive connotations when used by anyone with any influence in society and pine for the days when white privilege was so strong as to be virtually un…

In a history of American cities, I read that the Polish, Irish, Italian, German, etc. identities shifted to 'white' around the 1930s or 1940s (my memory is a little hazy).

Its true that before then, Polish, Irish, Italian (German not so much, AFAIK, but possibly) were ethnic identities often viewed as distinct from -- and frequently discriminated against by -- the dominant white-identifying group (in the same what whites of Hispanic origin have continued to be since), but white racial identity existed before then.

Re: Sony Got Hacked Hard: What We Know and Don't Know So Far

#177

Earlier quoted context omitted.

> Low risks do not justify high expenses. What is the expense associated with, for example, not concatenating user-supplied input in SQL queries?

I don't know, what does a low-skill developer who doesn't know better cost compared to someone actually qualified for the job?

At my previous job, I made $25k less per year than the idiot who nearly exposed us to RFI risks before I looked over his code.

Developers are developers. If you're going out of your way to hire extremely untalented people, because they're cheap, you're going to get owned.

If you're hiring people who understand their own craft, you can get a junior developer for under $70k and a senior for under $100k. Unless you're in SF in which case multiply everything by 2 or 3.

Re: Sony Got Hacked Hard: What We Know and Don't Know So Far

#178

Many people suggest that startups not over-optimize on issues like security and performance when it's not their core business. The same could be said of Sony: empathize a little with them. Sony Pictures pays a lot of creative people. Maybe they should have seen the hack coming, but like the PSN outage this story will be maybe a paragraph in a Wikipedia article years from now. Even one great film could be watched by p…

I mean with all their experience from CD root kit. You think they know how to prevent hackers.

Re: Sony Got Hacked Hard: What We Know and Don't Know So Far

#179
post #132

Earlier quoted context omitted.

I once asked a lock pick artist what lock I should get for my house. They pointed out that if you have something valuable in your house, do you want to protect it with a 50 dollar lock or a 250 dollar lock. Basically they should have had better security; and I can bet they will spend the money for proper security now that they got owned so well. It's a great time to be working in the security field today.

That's an amazingly narrow-minded way of looking at a problem. It's easier and quicker to break your window than to pick your lock, $50 or $250.

Exactly, you have to invest in your security percautions. It will take more than a single lock to make a house secure.

Re: Sony Got Hacked Hard: What We Know and Don't Know So Far

#180

Earlier quoted context omitted.

> software engineers wont magically fix executives handing over credentials to hackers and all those important files were just lying around You can't project a film without a dedicated digital link to Sony's servers in London authorising it. For some movies they send personnel to your cinema to record the audience with IR cameras. For some movies you are not allowed to let the staff watch the film for free.

How much of that is really security vs. excercising power and control over a market?

If they can find the money and staff to implement securing third party cinemas to prevent copyright infringement by members of the public, perhaps they should spend a few dollars to secure their own premises.
Post reply on HN