Live data from Hacker News

SonyPictures.com hacked, personal information and passwords compromised

pastebin.com

71–80 of 165 posts

Re: SonyPictures.com hacked, personal information and passwords compromised

#71
post #21
post #14

It is just sad that all these hackers think they're doing everybody a favor by attacking "evil corporations" like Sony. But while they may be right in exposing Sony's lousy security, meanwhile they hurt one million people by releasing their information out into the public in a way that can never be taken back. Unless you think hurting one company you deem bad outweighs hurting a million innocent private citizens, the…

If they didn't release the information: 1) Sony would just accuse them of lying and people (the general public) would just believe Sony over a bunch of anonymous hackers. 2) Change doesn't happen unless people get off their butts. This is a way to motivate that change. I don't necessarily agree with it, but you're talking as if there is no logic behind this other than recklessness.

Actually a much more reasonable step to take would be to release the data, but to de-identify it in such a way that individual people couldn't have their identities compromised or lives ruined.

I agree that Sony should be taken to task here, but even the simple step of randomizing the password field would be a good idea.

Re: SonyPictures.com hacked, personal information and passwords compromised

#72

Seems Sony really has kicked up the swarm with that GeoHot clamp down. I am fairly certain that there are some executive meetings that are seriously questioning whether or not that initial action was wise. I never thought this type of extortion could work, but Hot Damn. This is an effective campaign. Talk about relentless! Edit: This is really a losing battle for Sony. They are too big, there are too many vulnerabili…

I don't think we're witnessing the end of Sony, but we are certainly witnessing the end of their online ventures.

What is very interesting is that all of their Web properties seem so stove-piped. No common architectural direction, no standards, no common security defenses.

It's almost as if Sony's marketing departments are leading all Web development efforts for the company. No serious enterprise ever lets that happen.

Oh, wait... :) (Tongue in cheek)

Re: SonyPictures.com hacked, personal information and passwords compromised

#73
post #37
post #21

Earlier quoted context omitted.

If they didn't release the information: 1) Sony would just accuse them of lying and people (the general public) would just believe Sony over a bunch of anonymous hackers. 2) Change doesn't happen unless people get off their butts. This is a way to motivate that change. I don't necessarily agree with it, but you're talking as if there is no logic behind this other than recklessness.

I'm not saying there's no logic. I'm just saying it's some pretty messed up logic. Sony has been targeted for several major intrusions lately and I'm certain they have lost a great deal of money because of it. Now if hackers want to damage Sony, how about finding a way that doesn't also involve millions of regular people in the process. I got my one and only Sony product (PS3) because I use it for something. Not beca…

I don't think you get it. I got root access of a box today, reported it to the company, and was told he couldn't notify the developers until next week because they're in meetings. The person was actually more concerned because I mentioned I was blown off the first time I reported a security issue (emailed password, non-https logins/signups, etc). Meanwhile, I can instantly copy/destroy/deface hundreds of sites, all of which have paid initial fees between $10,000-$50,000 for the service and pay annual fees for continued service.

These companies are fucking stupid and the only way to make them change their ways is to kick them in the balls and piss on them while they're down. Otherwise, nothing happens and others who were less kind don't tell them and harvest the data unbeknownst to anybody. How's that for "real issues"? The real issue is the companies fucking suck and it pisses us off when they don't do a goddamn thing when we report it to them.

Re: SonyPictures.com hacked, personal information and passwords compromised

#74
post #49

Earlier quoted context omitted.

Another imaginary currency. Very bad. Bitcoin is just another imaginary currency. But now its technofreaks imagining it, what a difference. A real adventure into economics and currencies would be to strive for a society with no currency, where people do things for the lulz. Not for the coins man.

Man are you a spook? I don't get this anti-Bitcoin thing at all. I'm not for or against it, it's interesting tech for sure - fascinating even - and obviously polarizing to some. But I just don't get this attitude at all, at least amongst HN'ers.

this was for me a good explanation: http://www.quora.com/Is-the-cryptocurrency-Bitcoin-a-good-id...

Re: SonyPictures.com hacked, personal information and passwords compromised

#75
post #48

Earlier quoted context omitted.

What's worse is that every bit of data we took wasn't encrypted. Sony stored over 1,000,000 passwords of its customers in plaintext, which means it's just a matter of taking it. This is disgraceful and insecure: they were asking for it. I'm not sure that is true for any company with as much surface area. I would be extremely disappointed if it were true of any of Canada's five major banks, for example. Google has bee…

Banks hopefully encrypt them, but even a cursory glance when logging in to most nowadays shows they don't hash them (asking for individual characters). Or at least, you hope they aren't storing hashes of individual characters of your password ... even with salt.

A lot of UK ones have two layer, one password which I can only hope is a salted hash, one security key which asks for individual characters.

My business account also has a different two layer, one password, one authentication device.

Re: SonyPictures.com hacked, personal information and passwords compromised

#76
post #3

For those put off by the first 40 lines, here's the good part: "SonyPictures.com was owned by a very simple SQL injection, one of the most primitive and common vulnerabilities, as we should all know by now. From a single injection, we accessed EVERYTHING. Why do you put such faith in a company that allows itself to become open to these simple attacks? "What's worse is that every bit of data we took wasn't encrypted.…

ONE MILLION email addresses and clear-text passwords. Ouch.

That far surpasses the Gawker hack since all of Gawker's passwords were encrypted with a somewhat easily reversible hash (for simple passwords) and only a subset of those passwords were recovered.

Imagine what governments could do with all those email/password combinations. Cross reference email addresses with a target internal database and an agency could (is) within minutes begin to systematically download an enormous amount of emails and other private data.

And the spammers...

And nobody ever uses the same password across different systems, right?

Like I said, ouch.

Re: SonyPictures.com hacked, personal information and passwords compromised

#77
post #28
post #21

Earlier quoted context omitted.

If they didn't release the information: 1) Sony would just accuse them of lying and people (the general public) would just believe Sony over a bunch of anonymous hackers. 2) Change doesn't happen unless people get off their butts. This is a way to motivate that change. I don't necessarily agree with it, but you're talking as if there is no logic behind this other than recklessness.

The public is already predisposed to believing any hacking claims targeted at Sony at the moment. I wouldn't exactly frame their actions as reckless or lacking in logic either. How about malicious? I am particularly put off by this line: "This is disgraceful and insecure: they were asking for it." I get it, they have poor security, as a customer, this makes me really angry. But the general tone there is kind of simil…

That's sort of like saying that software piracy is theft.

Blaming victims for rape is dangerous because it discourages victims from coming forward, and adds to intense feelings of shame and guilt that come with sexual violation. It also tends to come with suggestions that women should restrict their behavior, not seeking to be attractive or acting in 'risky' stereotypically male ways.

Criticizing a cooperation for failing to follow security best practice, and speculating about the effect of outsourcing or technology is completely different. I'd say that as a lot of people here run websites, it's probably a good idea too.

Re: SonyPictures.com hacked, personal information and passwords compromised

#78
post #29

The thing that struck me first about this was the fact that it is in impeccable English, yet written as a kid would write. Something smells funny about that. What is to stop a competitor of Sony from trying to take them down under the guise of disenfranchised youth.

.. how about that it was written by an intelligent adult, intentionally using a childish voice for dramatic effect?

Cracking often has a playful tone to it.

Re: SonyPictures.com hacked, personal information and passwords compromised

#79
post #74
post #49

Earlier quoted context omitted.

Man are you a spook? I don't get this anti-Bitcoin thing at all. I'm not for or against it, it's interesting tech for sure - fascinating even - and obviously polarizing to some. But I just don't get this attitude at all, at least amongst HN'ers.

this was for me a good explanation: http://www.quora.com/Is-the-cryptocurrency-Bitcoin-a-good-id...

Thanks, that is a good read.

Edit: Typo.

Re: SonyPictures.com hacked, personal information and passwords compromised

#80
post #70
post #61

Earlier quoted context omitted.

This is the 3rd or 4th such attack. Even if they're completely clueless: "Once is happenstance. Twice is coincidence. The third time it's enemy action."

11th actually. This article[1] documents the last 10 times up with today making it 11. Starts from the first DDoS by Anonymous on Apr 4. [1]: http://blogs.forbes.com/andygreenberg/2011/05/24/sony-goes-s...

Jeebus, 11? I stand corrected.
Post reply on HN