Live data from Hacker News

SonyPictures.com hacked, personal information and passwords compromised

pastebin.com

111–120 of 165 posts

Re: SonyPictures.com hacked, personal information and passwords compromised

#111

Earlier quoted context omitted.

Yikes - I believe in the PSN hack there was some question as to whether the passwords were encrypted or not. I'm glad it's out in the open for this one. Think we'll see Sony changing their name any time soon?

> Think we'll see Sony changing their name any time soon? Doubtful, 90% of people won't remember this in a year, just like barely anyone remembers about the BP oil spill or the Toyota brake incident. Sony might drop their name from some of their tech enterprises. The next playstation will probably just be Playstation rather than Sony, but that's likely the biggest. Considering that Sony Bravia's are often sold as jus…

I'm not so sure. A lot of people still remember the fact that Sony smuggled a malware payload on to Audio CD's and that was in 2005 (http://en.wikipedia.org/wiki/Sony_rootkit).

I for one make it my business to remember people and to point what an evil company with a totally twisted mindset Sony actually is.

Add to that their mindboggling technical ineptitude, which is so bad that I'm sure this will be remembered in a year's time.

(I'm aware that technically Sony BMG was behind the rootkit scandal. But hey: there's the SONY brand name very clearly to see, here)

Re: SonyPictures.com hacked, personal information and passwords compromised

#112
post #59

I have seen lots of web work for Sony-sized companies being awarded to design-heavy advertising agencies with incompetent backend developers when such work should be undertaken by people skilled in making the plumbing of public-facing, secure and scalable websites. This is the kind of mistake only a junior makes that should never pass the most complacent code-review process. Like an old friend of mine used to say, "y…

I've actually been one of those developers working on a site for a major corporation who outsourced the development and design to an advertising agency. I wouldn't be surprised if there were a few holes in our site, despite the external security audit.

The main issue is that the advertising agency handled the development very poorly. Expectations and specifications were not well defined, budgets were not set appropriately, and project management was largely absent. This leads to my fellow developer and I, who were brought in because the agency lacked developer talent, having to scramble to get all the features in before the deadline.

I would blame some of this on lack of technical project management as well, not just on the coders.

Re: SonyPictures.com hacked, personal information and passwords compromised

#113
post #32

Earlier quoted context omitted.

so why isn't there anything done against Apple? Apple's lawyers are on the back of anyone who makes white iPhone cases, jailbreakers, etc.

First, selling unofficial/unreleased parts with an Apple logo on them and jailbreaking are completely different. You can sell all the cases and backplates you want, but you can't start putting someone else's trademarks on them. Second, Apple hasn't sued any jailbreakers.

I'd also be willing to bet Apple isn't very susceptible to SQL injection nor do I suspect they store passwords in plaintext.

Re: SonyPictures.com hacked, personal information and passwords compromised

#114

Seems Sony really has kicked up the swarm with that GeoHot clamp down. I am fairly certain that there are some executive meetings that are seriously questioning whether or not that initial action was wise. I never thought this type of extortion could work, but Hot Damn. This is an effective campaign. Talk about relentless! Edit: This is really a losing battle for Sony. They are too big, there are too many vulnerabili…

I am fairly certain that there are some executive meetings that are seriously questioning whether or not that initial action was wise.

The only thing happening in those executive meetings at Sony is a discussion of which lobbyists to hire and which laws to buy in order to punish their legitimate paying customers even further.

Re: SonyPictures.com hacked, personal information and passwords compromised

#115
post #14

It is just sad that all these hackers think they're doing everybody a favor by attacking "evil corporations" like Sony. But while they may be right in exposing Sony's lousy security, meanwhile they hurt one million people by releasing their information out into the public in a way that can never be taken back. Unless you think hurting one company you deem bad outweighs hurting a million innocent private citizens, the…

Considering Sony's lack of security, it would be careless not to assume that the information is already in the hands of the malicious hackers. A group of mischievous ones publicly releasing it doesn't add much harm, and publicizes the fact that your information is not secure in a way that makes people take notice.

Re: SonyPictures.com hacked, personal information and passwords compromised

#116
post #110

Earlier quoted context omitted.

George Hotz, who has publicly spoken out against piracy, would object to the title "cracker", which connotes piracy.

I'm using Stallman's definition of cracker, "people who break computer security" http://stallman.org/cgi-bin/showpage.cgi?path=/archives/arch... That's exactly what George Hotz does. He breaks security. iPhone security, PS3 security, etc. He's not a hacker according to the RMS definition, the pg definition, or probably most of the classical definitions. He may fit the current journalist's definition of "hacker" which…

However, he primarily breaks security on devices he purchased, so that he and others can repurpose them for their own needs and desires. That is a very "hacker" thing to do. "I have this device. Can I make it do something useful?"

If he were primarily breaking security on other people's computer systems, then the distinction would likely be merited.

Re: SonyPictures.com hacked, personal information and passwords compromised

#117

Earlier quoted context omitted.

What's worse is that every bit of data we took wasn't encrypted. Sony stored over 1,000,000 passwords of its customers in plaintext, which means it's just a matter of taking it. This is disgraceful and insecure: they were asking for it. I'm not sure that is true for any company with as much surface area. I would be extremely disappointed if it were true of any of Canada's five major banks, for example. Google has bee…

"Any" is probably an exaggeration. I'd cede that and accept "most." We can hope that Google is an exception because of the caliber of employee they hire, since obviously they also have a lot of domain knowledge. But, I think that only means we're quibbling about the embarrassment level of these breaches.

Sorry for the delay... Parenting! Any ways, I agree we shouldn't quibble about any/most.

I also agree that a big surface area (such as units with independent web strategies all over the world) increases the likelihood of there being some breach of security. What I find embarrassing here is that we aren't talking about one of the Sony properties having a breach, it's lots and lots of them.

I suggest that this is symptomatic of a problem with Sony itself, not just the surface area they present. What I'd expect from a well-managed company with a big surface area is yes, some property might have a breach, but that would be the exception. It's beginning to look like Sony's lax security with respect to customer information is the rule and not the exception.

JM2C, I am not claiming I know this for a fact.

Re: SonyPictures.com hacked, personal information and passwords compromised

#118

Seems Sony really has kicked up the swarm with that GeoHot clamp down. I am fairly certain that there are some executive meetings that are seriously questioning whether or not that initial action was wise. I never thought this type of extortion could work, but Hot Damn. This is an effective campaign. Talk about relentless! Edit: This is really a losing battle for Sony. They are too big, there are too many vulnerabili…

> I know this sounds extreme, but are we witnessing the end of Sony as we know it ?

Well, Sony (and the rest of Japanese industry) has been on a downward spiral for the last 2 decades. This is just the final blow. Their end has been in sight for at least 5 years now.

Re: SonyPictures.com hacked, personal information and passwords compromised

#119
post #110

Earlier quoted context omitted.

George Hotz, who has publicly spoken out against piracy, would object to the title "cracker", which connotes piracy.

I'm using Stallman's definition of cracker, "people who break computer security" http://stallman.org/cgi-bin/showpage.cgi?path=/archives/arch... That's exactly what George Hotz does. He breaks security. iPhone security, PS3 security, etc. He's not a hacker according to the RMS definition, the pg definition, or probably most of the classical definitions. He may fit the current journalist's definition of "hacker" which…

I disagree with this, let's not forget RMS did a lot of "cracking" himself, like the ITS password hack and some shady things like reverse engineering code from Symbolics and gave it to Lisp Machine.

GeoHotz did a hard and ingenious hack to get his ps3 to do things it's not longer suposed to do. That's not cracking per se. I think cracking mostly happens with things like these folks did. Using a simple SQL injection (probably automated) to hack Sony's site.

It's all in the ingenuity level. That where the distinction should be.

Re: SonyPictures.com hacked, personal information and passwords compromised

#120

I've said this before and I'll say it again: Sony is facing a highly skilled group of hackers that have made it their mission to ruin the company. If you have sensitive data with any of Sonys products, I'd advise you to delete it ASAP. This is not going away. Sony will be fighting attacks like this for years to come and they have only themselves to blame.

lolwut, SQLi is sophisticated and takes mad skills now? The methods employed are very low-brow to be charitable, brah. To be completely honest, I don't think Lulzsec is the first to discover this at all. They're just being loud about it all. For a sophisticated popular hack recently, look at the work by zerofor0wned or the Stuxnet worm (not classifying the two in the same category of course).
Post reply on HN