Live data from Hacker News

SonyPictures.com hacked, personal information and passwords compromised

pastebin.com

131–140 of 165 posts

Re: SonyPictures.com hacked, personal information and passwords compromised

#131
post #86

Earlier quoted context omitted.

What the hell did they do that got people so pissed off?

Just in case you really don't know, the various branches of Sony have demonstrated technological contempt for [their] customers for years. I'll omit their insistence on promoting their own products over other standards and general push for increased DRM, such as Minidisc/ATRAC, Blu-ray, etc. and focus on their actual attacks. It started with the CD root kit fiasco, in which music CDs distributed by Sony infected Wind…

Not overly fruitful to conversation, but despite myself I love that GeoHot entered an online rapping contest by trying to battle Sony verbally.

http://www.youtube.com/watch?v=9iUvuaChDEg

I honestly think he could outdo more than a couple of their signed artists, is the funny part.

Re: SonyPictures.com hacked, personal information and passwords compromised

#132
While this is incredibly embarrassing for Sony, as it exposes gross incompetence, can someone explain why the FBI/law enforcement is not able to shutdown the hackers by filing criminal charges against the owners/operators of lulzsecurity.com, since they are openly admitting that they are behind all of the attacks.

Re: SonyPictures.com hacked, personal information and passwords compromised

#133

Earlier quoted context omitted.

> Think we'll see Sony changing their name any time soon? Doubtful, 90% of people won't remember this in a year, just like barely anyone remembers about the BP oil spill or the Toyota brake incident. Sony might drop their name from some of their tech enterprises. The next playstation will probably just be Playstation rather than Sony, but that's likely the biggest. Considering that Sony Bravia's are often sold as jus…

I'm not so sure. A lot of people still remember the fact that Sony smuggled a malware payload on to Audio CD's and that was in 2005 ( http://en.wikipedia.org/wiki/Sony_rootkit ). I for one make it my business to remember people and to point what an evil company with a totally twisted mindset Sony actually is. Add to that their mindboggling technical ineptitude, which is so bad that I'm sure this will be remembered in…

what an evil company with a totally twisted mindset Sony actually is

You really need to get out more.

Re: SonyPictures.com hacked, personal information and passwords compromised

#134

Seems Sony really has kicked up the swarm with that GeoHot clamp down. I am fairly certain that there are some executive meetings that are seriously questioning whether or not that initial action was wise. I never thought this type of extortion could work, but Hot Damn. This is an effective campaign. Talk about relentless! Edit: This is really a losing battle for Sony. They are too big, there are too many vulnerabili…

A lot of the large enterprises are run this way. I doubt if any extremely large enterprise can withstand this many ongoing attacks.

Re: SonyPictures.com hacked, personal information and passwords compromised

#136
post #110

Earlier quoted context omitted.

George Hotz, who has publicly spoken out against piracy, would object to the title "cracker", which connotes piracy.

I'm using Stallman's definition of cracker, "people who break computer security" http://stallman.org/cgi-bin/showpage.cgi?path=/archives/arch... That's exactly what George Hotz does. He breaks security. iPhone security, PS3 security, etc. He's not a hacker according to the RMS definition, the pg definition, or probably most of the classical definitions. He may fit the current journalist's definition of "hacker" which…

If you're making something run linux that didn't run linux before, then you're a hacker, in the classic sense.

Re: SonyPictures.com hacked, personal information and passwords compromised

#137
post #3

For those put off by the first 40 lines, here's the good part: "SonyPictures.com was owned by a very simple SQL injection, one of the most primitive and common vulnerabilities, as we should all know by now. From a single injection, we accessed EVERYTHING. Why do you put such faith in a company that allows itself to become open to these simple attacks? "What's worse is that every bit of data we took wasn't encrypted.…

ONE MILLION email addresses and clear-text passwords. Ouch. That far surpasses the Gawker hack since all of Gawker's passwords were encrypted with a somewhat easily reversible hash (for simple passwords) and only a subset of those passwords were recovered. Imagine what governments could do with all those email/password combinations. Cross reference email addresses with a target internal database and an agency could (…

> Imagine what governments could do with all those email/password combinations. Cross reference email addresses with a target internal database and an agency could (is) within minutes begin to systematically download an enormous amount of emails and other private data.

Sadly, governments don't need a hack like this to get at email.

Re: SonyPictures.com hacked, personal information and passwords compromised

#138

Seems Sony really has kicked up the swarm with that GeoHot clamp down. I am fairly certain that there are some executive meetings that are seriously questioning whether or not that initial action was wise. I never thought this type of extortion could work, but Hot Damn. This is an effective campaign. Talk about relentless! Edit: This is really a losing battle for Sony. They are too big, there are too many vulnerabili…

I don't think we're witnessing the end of Sony, but we are certainly witnessing the end of their online ventures. What is very interesting is that all of their Web properties seem so stove-piped. No common architectural direction, no standards, no common security defenses. It's almost as if Sony's marketing departments are leading all Web development efforts for the company. No serious enterprise ever lets that happe…

where did the term "stove-piped" come from? how did "stove piping" come to signify any system built in isolation from other systems?

Re: SonyPictures.com hacked, personal information and passwords compromised

#140
post #3

For those put off by the first 40 lines, here's the good part: "SonyPictures.com was owned by a very simple SQL injection, one of the most primitive and common vulnerabilities, as we should all know by now. From a single injection, we accessed EVERYTHING. Why do you put such faith in a company that allows itself to become open to these simple attacks? "What's worse is that every bit of data we took wasn't encrypted.…

ONE MILLION email addresses and clear-text passwords. Ouch. That far surpasses the Gawker hack since all of Gawker's passwords were encrypted with a somewhat easily reversible hash (for simple passwords) and only a subset of those passwords were recovered. Imagine what governments could do with all those email/password combinations. Cross reference email addresses with a target internal database and an agency could (…

Hard to believe after initial hack they didn't launch a group wide memo from the CEO to encrypt all personal data. Could have brought some DLP vendor in to find it and roll out rapid database level encryption without changing application code. SQL injection vulnerabilities in this day and age is unforgivable but unfortunatly not uncommon. Sony will not be the only global company with hundreds of such vulnerabilities
Post reply on HN