Results 1 to 10 of 10

Thread: Sony Hacked Again: How Not to Do Network Security

  1. #1
    #DeSantis2024 Teh One Who Knocks's Avatar
    Join Date
    Jan 2011
    Location
    5280' Above Sea Level
    Posts
    256,057
    vCash
    10966
    Mentioned
    20 Post(s)
    Thanks
    23,822
    Thanked 113,107 Times in 59,910 Posts

    Sony Hacked Again: How Not to Do Network Security

    By Tony Bradley, PCWorld


    Yes. As unbelievable as it may seem, Sony was hacked again. It is not (entirely) Sony's fault that it is the target du jour for hackers everywhere. But, it is Sony's fault that its networks and servers seem to be trivial to hack and easy to pwn.

    The trials and tribulations of Sony's epic struggle against hacks and data breaches over the past month or so are well-documented. You can read all about the breach of Sony Ericsson Canada, or Sony BMG Greece, or the Sony Playstation Network, or any of the other network attacks against Sony all over the Web.

    LulzSec, the hacker collective responsible for the Wikileaks hacktivism attack and fake Tupac resurrection story on the PBS site last week, made it clear that Sony was the next target on its radar. Now it has made good on that threat with a hack of the Sony Pictures network, and claims to have compromised the account details of a million users.

    Now, I am of the opinion that there is no such thing as absolute security. Any network is vulnerable given an attacker with sufficient skills, resources, and time. So, it would be very easy for me to be sympathetic to Sony's plight--except Sony seems to ignore compliance requirements and basic security best practices, so it is basically begging to be attacked. Shame on you, Sony. Seriously.

    Andrew Brandt, lead threat research analyst for Webroot, agrees. "Lulz Security says the information they stole was entirely unencrypted, and while we can't verify Lulz's statements, we can say that companies should take this as a warning to check their internal methods of storing their customers' confidential information and make sure they comply with industry standards such as PCI-DSS."

    According to Randy Abrams, director of technical education for ESET, if Sony did, in fact, store passwords in plain-text as LulzSec claims, it is nothing short of blatant negligence.

    Fred Touchette of AppRiver adds. "There is no doubt that Sony needs to spend some major effort in tightening up its network security. This latest hack against them was a series of simple SQL Injection attacks against its web servers. This simply should not have happened."

    So, aside from not pissing off the hacker collectives of the world, what can other companies do to prevent becoming a poster child for network insecurity? The best advice is that following security best practices, and implementing stronger network and data security controls is best done before you're a victim of hacks like these, not after.

    Tim 'TK' Keanini, CTO of nCircle, cautions organizations, though, against security 'silver bullets' or shortcuts. He likens improving network security to losing weight or improving physical fitness. "No matter how hard you work it's going to take more than a few days, even if you focus on nothing else. Great security is about more than technology. It has to be baked into business processes and into every employee's brains as they go about their everyday activities."

    Be proactive about following security best practices and data security compliance requirements. Don't be a Sony.

  2. #2
    Shelter Dweller PorkChopSandwiches's Avatar
    Join Date
    Jan 2011
    Posts
    77,136
    vCash
    5000
    Mentioned
    15 Post(s)
    Thanks
    47,197
    Thanked 29,255 Times in 16,489 Posts
    they may want to hire one of these hackers

  3. #3
    Basement Dweller Dragoness_Cutie's Avatar
    Join Date
    Apr 2011
    Location
    Washington, DC
    Posts
    616
    vCash
    3000
    Mentioned
    0 Post(s)
    Thanks
    0
    Thanked 0 Times in 0 Posts
    Good lord. AGAIN?! Oiya... I don't think I'll ever get to play my PS3 again. *Sighs*

  4. #4
    Crazy Canadian!!! samarchepas's Avatar
    Join Date
    Jan 2011
    Posts
    1,892
    vCash
    3000
    Mentioned
    0 Post(s)
    Thanks
    118
    Thanked 103 Times in 52 Posts
    Quote Originally Posted by Dragoness_Cutie View Post
    Good lord. AGAIN?! Oiya... I don't think I'll ever get to play my PS3 again. *Sighs*
    I'm playing online on mine right now... PSN is not affected by that "hack"...kinda weird that there is no mention of it on their website....
    BTW, The Welcome back pack is on
    Last edited by samarchepas; 06-03-2011 at 06:23 PM.

  5. #5
    I might be losing it... Softdreamer's Avatar
    Join Date
    Jan 2011
    Location
    behind the 2 way mirror in your bathroom.
    Posts
    2,003
    vCash
    3000
    Mentioned
    0 Post(s)
    Thanks
    108
    Thanked 98 Times in 79 Posts
    Do Sony use Norton???


    come back to my place, I'll show you how to drink tequila.

  6. #6
    #DeSantis2024 Teh One Who Knocks's Avatar
    Join Date
    Jan 2011
    Location
    5280' Above Sea Level
    Posts
    256,057
    vCash
    10966
    Mentioned
    20 Post(s)
    Thanks
    23,822
    Thanked 113,107 Times in 59,910 Posts

  7. #7
    weapon of mass consumption redred's Avatar
    Join Date
    Jan 2011
    Location
    Bristol , England
    Posts
    30,600
    vCash
    3793
    Mentioned
    0 Post(s)
    Thanks
    1,838
    Thanked 5,562 Times in 3,632 Posts
    Quote Originally Posted by samarchepas View Post
    The Welcome back pack is on
    i need to get on with that

  8. #8
    Sisukas Jezter's Avatar
    Join Date
    Jan 2011
    Posts
    9,495
    vCash
    2357
    Mentioned
    0 Post(s)
    Thanks
    641
    Thanked 2,139 Times in 1,281 Posts
    Even if it does not affect the PSN right now, this constant hacking and trouble will have an effect on their economy for sure and their brand imago will suffer aswell. As strong as it is, but still. Lets see if they can come up with some sort of campaign to overcome these troubles and win back customers who might have backed off cuz of all this.

  9. #9
    I might be losing it... Softdreamer's Avatar
    Join Date
    Jan 2011
    Location
    behind the 2 way mirror in your bathroom.
    Posts
    2,003
    vCash
    3000
    Mentioned
    0 Post(s)
    Thanks
    108
    Thanked 98 Times in 79 Posts
    I find this latest attack for more worrisome. Who cares if your COD scores get reset? were talking about confirmed credit card details being skimmed.

    come back to my place, I'll show you how to drink tequila.

  10. #10
    Crazy Canadian!!! samarchepas's Avatar
    Join Date
    Jan 2011
    Posts
    1,892
    vCash
    3000
    Mentioned
    0 Post(s)
    Thanks
    118
    Thanked 103 Times in 52 Posts
    Quote Originally Posted by Jezter View Post
    Even if it does not affect the PSN right now, this constant hacking and trouble will have an effect on their economy for sure and their brand imago will suffer aswell. As strong as it is, but still. Lets see if they can come up with some sort of campaign to overcome these troubles and win back customers who might have backed off cuz of all this.
    That's exactly why they made the "Welcome Back Program"...some will go...but the big part of people will stay (I'm in the big part ) I'm just hoping that those hackers will change target soon...

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •