Live data from Hacker News

SonyPictures.com hacked, personal information and passwords compromised

pastebin.com

151–160 of 165 posts

Re: SonyPictures.com hacked, personal information and passwords compromised

#151
post #113

Earlier quoted context omitted.

First, selling unofficial/unreleased parts with an Apple logo on them and jailbreaking are completely different. You can sell all the cases and backplates you want, but you can't start putting someone else's trademarks on them. Second, Apple hasn't sued any jailbreakers.

I'd also be willing to bet Apple isn't very susceptible to SQL injection nor do I suspect they store passwords in plaintext.

And your bet is based on what?

Looking at the URLs that iTunes and friends use behind the scenes it doesn't seem like the apple web-stuff was built by competent programmers either.

Try a few random clicks on https://iforgot.apple.com and look at the url-bar and firebug to get an idea.

Re: SonyPictures.com hacked, personal information and passwords compromised

#152
post #67
post #57

Earlier quoted context omitted.

>If hackers make being a Sony customer unpleasant Unpleasant is the word your choosing to use? Having my credit card information that links to my bank account, and the only bank account I have, and then having that fucked with is more than unpleasant. I'm thankful when the PSN network was compromised I wasn't one of those people with the claims of large sums of money being circulated out of the bank. ( Yes I know, co…

Unpleasant is the word your choosing to use? Irritating, painful, expensive? Choose your favorite word to describe your experience as a Sony customer, I guess. but by all means keep hiding behind this tired old excuse that the end result is to hurt Sony It's not an excuse, it's a hope. I sincerely hope that this will hurt Sony's bottom line in the near future. I hope that some time soon, the general public will assoc…

>Irritating, painful, expensive? Choose your favorite word to describe your experience as a Sony customer, I guess.

Disruptive. I've been going paperless( in regards to money )since 2008, this was a flat out disruption on my day to day life.

>This is hardly the first time Sony's customers have been screwed by Sony's customer-hostile policies, so I don't expect it, but I certainly do hope for it.

Sony's abysmal history is public knowledge, that still had little choice in the limited choice I had with buying a gaming system.

>When I'm caught and sentenced? For schadenfreude, or do you think I'm behind this attack? Kudos for missing that hyperbole.

By all means keep downvoting me. How many of you disagreeing with my point about the extremity of these methods were effected by any this? That's what I thought.

Re: SonyPictures.com hacked, personal information and passwords compromised

#153
post #21
post #14

It is just sad that all these hackers think they're doing everybody a favor by attacking "evil corporations" like Sony. But while they may be right in exposing Sony's lousy security, meanwhile they hurt one million people by releasing their information out into the public in a way that can never be taken back. Unless you think hurting one company you deem bad outweighs hurting a million innocent private citizens, the…

If they didn't release the information: 1) Sony would just accuse them of lying and people (the general public) would just believe Sony over a bunch of anonymous hackers. 2) Change doesn't happen unless people get off their butts. This is a way to motivate that change. I don't necessarily agree with it, but you're talking as if there is no logic behind this other than recklessness.

I don't know if people would believe Sony at this point. Their integrity is kind of shot...

Re: SonyPictures.com hacked, personal information and passwords compromised

#154
post #19
post #8

All the info here: http://lulzsecurity.com/releases/

Isn't it a little strange their irc is on 2600? I thought they owned them the same night as PBS...

If you follow their twitter, they are trying to be ironic. They took down some of the irc servers again to be funny the day before.

Re: SonyPictures.com hacked, personal information and passwords compromised

#155

Earlier quoted context omitted.

"Any" is probably an exaggeration. I'd cede that and accept "most." We can hope that Google is an exception because of the caliber of employee they hire, since obviously they also have a lot of domain knowledge. But, I think that only means we're quibbling about the embarrassment level of these breaches.

Sorry for the delay... Parenting! Any ways, I agree we shouldn't quibble about any/most. I also agree that a big surface area (such as units with independent web strategies all over the world) increases the likelihood of there being some breach of security. What I find embarrassing here is that we aren't talking about one of the Sony properties having a breach, it's lots and lots of them. I suggest that this is sympt…

Understand regarding parenting. I do that myself. :-)

I do see your point about Sony, and they may in fact be an outlier here. I think I've been accustomed to the story of customer information breaches from large corporations though, and so maybe I'm overly pessimistic?

Re: SonyPictures.com hacked, personal information and passwords compromised

#156
post #140

Earlier quoted context omitted.

ONE MILLION email addresses and clear-text passwords. Ouch. That far surpasses the Gawker hack since all of Gawker's passwords were encrypted with a somewhat easily reversible hash (for simple passwords) and only a subset of those passwords were recovered. Imagine what governments could do with all those email/password combinations. Cross reference email addresses with a target internal database and an agency could (…

Hard to believe after initial hack they didn't launch a group wide memo from the CEO to encrypt all personal data. Could have brought some DLP vendor in to find it and roll out rapid database level encryption without changing application code. SQL injection vulnerabilities in this day and age is unforgivable but unfortunatly not uncommon. Sony will not be the only global company with hundreds of such vulnerabilities

>Could have brought some DLP vendor in to find it and roll out rapid database level encryption without changing application code.

Wait... if Sony fully encrypt the database, they need a way to ask the database to be decrypted from their program.

But if the hackers use SQL injection, they would be attacking the database through a SQL call that, by necessity, must decrypt the database.

Wouldn't some sort of full database encryption only protect from someone getting a DB dump? Or am I misunderstanding?

Re: SonyPictures.com hacked, personal information and passwords compromised

#158
post #98

I've said this before and I'll say it again: Sony is facing a highly skilled group of hackers that have made it their mission to ruin the company. If you have sensitive data with any of Sonys products, I'd advise you to delete it ASAP. This is not going away. Sony will be fighting attacks like this for years to come and they have only themselves to blame.

I don't know that deleting it will do much good. Most web apps for performance reasons don't actually do a delete against the database, rather mark a record as deleted and perhaps run a batch job later to clean deleted records from the database. If you've got access to the database via SQL injection, you'll have access to all those "deleted" records as well. Even of you go through the website and update each field wi…

Alternatively, you could SQL inject their databases yourself and personally delete your information.

Re: SonyPictures.com hacked, personal information and passwords compromised

#159
post #98

Earlier quoted context omitted.

I don't know that deleting it will do much good. Most web apps for performance reasons don't actually do a delete against the database, rather mark a record as deleted and perhaps run a batch job later to clean deleted records from the database. If you've got access to the database via SQL injection, you'll have access to all those "deleted" records as well. Even of you go through the website and update each field wi…

Alternatively, you could SQL inject their databases yourself and personally delete your information.

Anything less would not qualify as due diligence!

Re: SonyPictures.com hacked, personal information and passwords compromised

#160
post #32

Earlier quoted context omitted.

so why isn't there anything done against Apple? Apple's lawyers are on the back of anyone who makes white iPhone cases, jailbreakers, etc.

First, selling unofficial/unreleased parts with an Apple logo on them and jailbreaking are completely different. You can sell all the cases and backplates you want, but you can't start putting someone else's trademarks on them. Second, Apple hasn't sued any jailbreakers.

[deleted]
Post reply on HN