Live data from Hacker News

SonyPictures.com hacked, personal information and passwords compromised

pastebin.com

101–110 of 165 posts

Re: SonyPictures.com hacked, personal information and passwords compromised

#101
post #3

For those put off by the first 40 lines, here's the good part: "SonyPictures.com was owned by a very simple SQL injection, one of the most primitive and common vulnerabilities, as we should all know by now. From a single injection, we accessed EVERYTHING. Why do you put such faith in a company that allows itself to become open to these simple attacks? "What's worse is that every bit of data we took wasn't encrypted.…

I noticed that they are willing to give away passwords, but not willing to point out the SQL injection.

They did point it out...

  SonyPictures.com has been owned,
  this is its SQLi hole: 

  ## http://www.sonypictures.com/homevideo/ghostbusters/photoupload/view.php?id=12838 ##
  TEAR THE LIVING SHIT OUT OF IT WHILE YOU CAN; TAKE FROM THEM EVERYTHING!

Re: SonyPictures.com hacked, personal information and passwords compromised

#102
post #46

Earlier quoted context omitted.

The question is whether Sony is really an outlier in terms of security, or if most big corps are getting by with security by obscurity (or no one cares about hacking them).

Most big corps are probably just as bad. I work for a bigcorp, and our security ranges from barely competent to completely ridiculous.

This level of professional negligence isn't reserved exclusively for megacorps. There's YC companies writing their own PHP frameworks that will enable these flaws to live on for another generation.

Re: SonyPictures.com hacked, personal information and passwords compromised

#103
post #91
post #33

Earlier quoted context omitted.

Apple has gone after jailbreakers? Thats news to me. Geohot has hacked (as far as I know) almost every iDevice Apple has put out, but Apple didn't take him to court because of it.

I didn't say that Apple took them to court. http://www.wired.com/threatlevel/2009/07/jailbreak/ I am just saying that Apple is using every means available to them to prevent other people using their software or hardware in a different way.

Do you really think that's true? My impression is more like they're doing just enough to convince groups like the RIAA and MPAA that they're "followinusingusty best practice" until such a time that they are in a powerful enough position to admit "actually, we don't care much about your DRM and your failing business model, it's upsetting our users so it's gone." like they did with the DRM on iTunes music. Maybe Jobs's Pixar relationship will make Apple's movie industry support stronger than their music industry support turned out to be, but long term who knows?

Re: SonyPictures.com hacked, personal information and passwords compromised

#104
post #86

Seems Sony really has kicked up the swarm with that GeoHot clamp down. I am fairly certain that there are some executive meetings that are seriously questioning whether or not that initial action was wise. I never thought this type of extortion could work, but Hot Damn. This is an effective campaign. Talk about relentless! Edit: This is really a losing battle for Sony. They are too big, there are too many vulnerabili…

What the hell did they do that got people so pissed off?

Sony is a big member of the RIAA and MPAA who have been suing people for a decade for downloading mp3s because it's "lost revenues". They recently carried these practices over from alienating people who have little clue about technology but really like music, to people who actively work to hack consoles and phones.

It's rather safe to fire a gun into a crowd and expect no one will challenge you. It's rather different to fire a gun into an army division and not expect everyone to fire back with better guns than your shitty pistol.

Sony has secured its customer data like it's a fucking fire alarm. Sure it has the illusion of safety hidden behind that plate of glass, but when you provide people with a hammer to break the glass and pull the handle it's really rather pointless. They're going to bitch and moan in front of congress, parliament and every other government that asks them WTF about cyber security and blah. When they've installed a turn style at their revenue source and got surprised when people started stealing.

Re: SonyPictures.com hacked, personal information and passwords compromised

#105

http://twitter.com/#!/LulzSec/status/76388576832651265 Stay classy

Another imaginary currency. Very bad. Bitcoin is just another imaginary currency. But now its technofreaks imagining it, what a difference. A real adventure into economics and currencies would be to strive for a society with no currency, where people do things for the lulz. Not for the coins man.

For what it's worth, I completely agree with you. This site is depressingly full of capitalist apologists.

Re: SonyPictures.com hacked, personal information and passwords compromised

#106
post #32

Earlier quoted context omitted.

http://en.wikipedia.org/wiki/Sony_Computer_Entertainment_Ame...

so why isn't there anything done against Apple? Apple's lawyers are on the back of anyone who makes white iPhone cases, jailbreakers, etc.

I wish people would do this stuff to Apple...

Re: SonyPictures.com hacked, personal information and passwords compromised

#107
post #3

For those put off by the first 40 lines, here's the good part: "SonyPictures.com was owned by a very simple SQL injection, one of the most primitive and common vulnerabilities, as we should all know by now. From a single injection, we accessed EVERYTHING. Why do you put such faith in a company that allows itself to become open to these simple attacks? "What's worse is that every bit of data we took wasn't encrypted.…

Yikes - I believe in the PSN hack there was some question as to whether the passwords were encrypted or not. I'm glad it's out in the open for this one. Think we'll see Sony changing their name any time soon?

> Think we'll see Sony changing their name any time soon?

Doubtful, 90% of people won't remember this in a year, just like barely anyone remembers about the BP oil spill or the Toyota brake incident.

Sony might drop their name from some of their tech enterprises. The next playstation will probably just be Playstation rather than Sony, but that's likely the biggest. Considering that Sony Bravia's are often sold as just 'Bravia', I don't see it as a huge change.

Re: SonyPictures.com hacked, personal information and passwords compromised

#108
post #100
post #86

Earlier quoted context omitted.

What the hell did they do that got people so pissed off?

A well known cracker named George Hotz (GeoHot), best known for iPhone jailbreaking, began to target the PS3's security to enable full access to the PS3's graphics capabilities via the Linux install option that the PS3 originally shipped with. Sony was concerned that that would enable piracy, so they removed the Linux install option in a firmware update. If you refused to install that firmware update, you could conti…

George Hotz, who has publicly spoken out against piracy, would object to the title "cracker", which connotes piracy.

Re: SonyPictures.com hacked, personal information and passwords compromised

#109
post #89
post #36

Earlier quoted context omitted.

When did Apple sue iOS jailbreakers? Did it go to court or did the defendants settle? edit: Nevermind, looks like they haven't actually sued any jailbreakers.

did I mention Apple suing iOS jailbreakers?

> Apple's lawyers are on the back of anyone who makes white iPhone cases, jailbreakers, etc.

Yes, you did.

Re: SonyPictures.com hacked, personal information and passwords compromised

#110
post #100

Earlier quoted context omitted.

A well known cracker named George Hotz (GeoHot), best known for iPhone jailbreaking, began to target the PS3's security to enable full access to the PS3's graphics capabilities via the Linux install option that the PS3 originally shipped with. Sony was concerned that that would enable piracy, so they removed the Linux install option in a firmware update. If you refused to install that firmware update, you could conti…

George Hotz, who has publicly spoken out against piracy, would object to the title "cracker", which connotes piracy.

I'm using Stallman's definition of cracker, "people who break computer security"

http://stallman.org/cgi-bin/showpage.cgi?path=/archives/arch...

That's exactly what George Hotz does. He breaks security. iPhone security, PS3 security, etc. He's not a hacker according to the RMS definition, the pg definition, or probably most of the classical definitions. He may fit the current journalist's definition of "hacker" which is much closer to RMS' cracker. Since the web site we are on is named hacker news after the original definition, I think we should probably go with cracker for the people that primarily break security.

Post reply on HN