Film-Tech Cinema Systems
Film-Tech Forum ARCHIVE


  
my profile | my password | search | faq & rules | forum home
  next oldest topic   next newest topic
» Film-Tech Forum ARCHIVE   » Operations   » Ground Level   » Sony Hack Hits Home (Page 2)

 
This topic comprises 17 pages: 1  2  3  4  5  ...  15  16  17 
 
Author Topic: Sony Hack Hits Home
Frank Angel
Film God

Posts: 5305
From: Brooklyn NY USA
Registered: Dec 1999


 - posted 12-12-2014 06:05 PM      Profile for Frank Angel   Author's Homepage   Email Frank Angel   Send New Private Message       Edit/Delete Post 
In this day and age, anyone who thinks or treats communications on the internet and especially emails on a company server as if it is "secure" is just delusional. There is no such thing as a private email on the internet. You say nasty stuff about your A list clients, actors, directors, whomever, and think it won't ever be discovered, then you get what you deserve. But really, big deal someone says an actress is a brat. Is this a surprise? Anyone really think divas AREN'T brats?

The REAL issue is that 5 Sony films, drek as they may be, were hacked. Any studio that puts multi-million dollar product on server CONNECTED TO THE INTERNET deserves what they get. Given how paranoid the studios seem to be about piracy, the fact that they allow production content to be floating around on hack-able servers is a joke. And you don't need to spend millions on security for production content, you just need to keep it on a closed system. Disconnect it from the internet, period. Sure it will mean the big wigs many not have the convenience of being able to do screenings in their home theatres and they may have to actually go to the studio to see dailies, but in one single disconnect, you slaughter ALL of the hacking possibilities. Keep your film file servers disconnected from the internet; inconvenient, yes, but complicated security, no. NOTHING can be hacked if it's off line.

 |  IP: Logged

Jim Cassedy
Phenomenal Film Handler

Posts: 1661
From: San Francisco, CA
Registered: Dec 2006


 - posted 12-12-2014 06:58 PM      Profile for Jim Cassedy   Email Jim Cassedy   Send New Private Message       Edit/Delete Post 
quote: Frank Angel
Any studio that puts multi-million dollar product on server CONNECTED TO THE INTERNET deserves what they get
100% in agreement with Frank, except maybe I'd add the word "unencrypted" product.

Getting back to the original reason for starting this post, this blurb
is currently the first item at the top of the page (above the headline!)
on DRUDGE:
 -

Since Sony has already told me they've 'lost' the paperwork for all
the screenings I did for them in November, this represents quite a sum
of money when you consider that I get several hundred dollars per show.

I'm not looking for sympathy- - I'm not going to starve. I've got money
in the bank and I'm 'booked solid' with film festival & projection work
almost right till the end of the year. It's just that "I earned it. . . I want it".

(and I think that's not an unreasonable whine. . )

 |  IP: Logged

Leo Enticknap
Film God

Posts: 7474
From: Loma Linda, CA
Registered: Jul 2000


 - posted 12-12-2014 07:31 PM      Profile for Leo Enticknap   Author's Homepage   Email Leo Enticknap   Send New Private Message       Edit/Delete Post 
This hack is turning into disastrous news for Sony. The Angelina Jolie snarking is ultimately just a bit of a giggle, but it's now being reported that medical records of Sony employees have also been leaked.

I'm guessing that suppliers' invoices might also be among the leaked files. I hope Jim's didn't have his SSN on them. A co-worker suggested to me some time ago that I get an EIN and put that on the W-9 I send out with private rental invoices, in order to avoid having to give my SSN out, as an identity theft precaution. After this story, I'm glad I did.

 |  IP: Logged

Marcel Birgelen
Film God

Posts: 3357
From: Maastricht, Limburg, Netherlands
Registered: Feb 2012


 - posted 12-14-2014 06:58 AM      Profile for Marcel Birgelen   Email Marcel Birgelen   Send New Private Message       Edit/Delete Post 
quote: Bobby Henderson
That doesn't absolve end users from their own responsibility. I'll be the first to blame an end user for deliberately or ignorantly doing risky things with a computer. But the fact remains that a bunch of things are out of our control. Even the notion of buying a Mac or iOS device is no longer a guarantee of safety, as seen by some news-making hacks lately (like the Chinese government hacking iOS devices used by protesters in Hong Kong).
If you look at end-users and small businesses, I couldn't agree more. Those vendors (ironically, Sony amongst them) really need to step up their efforts to release products that just work and are safe to use in every aspect. This whole concept of churning out products, before they're actually finished needs to stop and people should actually just quit buying this junk.

Look at the whole chain from the lowest hardware layer to the end user software, you'll see just a pile up of unfinished, rushed out products, barely working together. Robustness, which used to be an important cornerstone of all IT related products out there, is nowhere to be found.

Still, if you're SPE or any other megacorp, or megadivision of a megacorp and you have budgets of billions, you should be amongst those who know this. Your IT guys, which should earn a good salary, are paid to know this. You should know that, for example, hooking up your smart phones to your internal network, to allow everybody to access everything from everywhere, will open up your network for potential abuse. You know that for almost every shitty product out there, whether or not they’re made by Dell, HP, Microsoft or Apple, there will be countless zero-day exploits around.

Knowing this, and knowing the sensitivity of the information you're dealing with, you might just choose not to hook it all together. Because, there are plenty of solutions out there, which will make it almost impossible for any hacker to get away with whole file servers worth of data. The problem is, they WILL cost serious money, they will, if nothing goes awry like it did now, not earn you one buck extra. And yeah, you will also have to deal with those self-important-persons, who'll urge the IT guy to get their e-mail running on whatever shiny device they'll bring in.

quote: Leo Enticknap
This hack is turning into disastrous news for Sony. The Angelina Jolie snarking is ultimately just a bit of a giggle, but it's now being reported that medical records of Sony employees have also been leaked.
I’ve read in some local news today that even the script of the latest Bond movie was supposedly included in the hack.

 |  IP: Logged

Leo Enticknap
Film God

Posts: 7474
From: Loma Linda, CA
Registered: Jul 2000


 - posted 12-14-2014 12:20 PM      Profile for Leo Enticknap   Author's Homepage   Email Leo Enticknap   Send New Private Message       Edit/Delete Post 
quote: Marcel Birgelen
Still, if you're SPE or any other megacorp, or megadivision of a megacorp and you have budgets of billions...
And especially if you're a megacorp in an industry that is known for being security-sensitive. What irritates me is that the security BS the studios impose on us is a constant impediment to us doing our job properly. KDMs that don't open in time for us to test the movie properly before showtime, the countless hours spent chasing KDMs that don't arrive, film prints that arrive with stupid padlocks on the case, are all irritants that we are forced to put up with in the name of protecting their IP. But yet they themselves operate such poor internal security that it was possible for the North Koreans (and/or people operating on their behalf) to empty their entire servers - including every single email written on their lot for the last ten years, for frig's sake!

IT security should always be proportional to the actual threat. I have TrueCrypted the data volume on my laptop, because it does contain data about some other people that they have a right to expect will not be leaked. The chance of it being stolen, while not great, is significantly higher than zero, and entering in a password every time I boot it up is not too much to ask to protect that data. But I don't change that password daily, or never connect it to the Internet, or take the kind of enhanced precautions I would take if I believed that enemies who knew what they are doing were actively trying to take that data from me.

If the studios didn't believe that enemies who know what they are doing are trying to steal their digital assets, why was DCP encryption ever part of the standard? Why were CSS and the other consumer media protection systems ever invented? Why do I have to sign a NDA when I project a studio preview before its release? Yet Sony feels the need to do all of this, but not to keep its own back end infrastructure secure?

 |  IP: Logged

Terry Lynn-Stevens
Phenomenal Film Handler

Posts: 1081
From: Toronto, Ontario, Canada
Registered: Dec 2012


 - posted 12-16-2014 11:31 AM      Profile for Terry Lynn-Stevens   Email Terry Lynn-Stevens   Send New Private Message       Edit/Delete Post 
quote: Joe Redifer
But I think they are trying to make the most of a bad situation by saying the hackers are demanding them to not release or delay The Interview.
I have a feeling that SONY Corporate Japan is going to pull the plug on the movie at the last minute. I think they just need the FBI to confirm the hackers are from/linked to North Korea. SONY makes a hell of lot electronics and other things and having this movie incident ruin their reputation is not worth it IMO.

 |  IP: Logged

Mike Blakesley
Film God

Posts: 12767
From: Forsyth, Montana
Registered: Jun 99


 - posted 12-16-2014 12:00 PM      Profile for Mike Blakesley   Author's Homepage   Email Mike Blakesley   Send New Private Message       Edit/Delete Post 
We got a letter through NATO from the Department of Homeland Security warning that even theaters playing the movie (exhibition chain companies) might be at some sort of risk. Apparently some other threats have been identified. The letter says:
quote:
These threats are directed at a specified company but anyone associated with the production, distribution, and promotion of an upcoming movie release could possibly become the target of cyber-attacks.
quote: Terry Lynn-Stevens
I have a feeling that SONY Corporate Japan is going to pull the plug on the movie at the last minute.
They'd be foolish to do that. It's not as if the bad guys are going to say "Oh hey, thanks for pulling the movie, we'll leave you alone now." Nope, they might as well just go ahead with it. Maybe cut back on the advertising a little.

 |  IP: Logged

Frank Cox
Film God

Posts: 2234
From: Melville Saskatchewan Canada
Registered: Apr 2011


 - posted 12-16-2014 12:41 PM      Profile for Frank Cox   Author's Homepage   Email Frank Cox   Send New Private Message       Edit/Delete Post 
It isn't a wise idea to give in to extortion, even if giving in to it is the easiest solution. What happens when North Korea (or whoever) objects to the next movie coming down the line?

I suspect that the IT security folks are between the proverbial rock and the hard place. Good security creates a certain amount of inconvenience for the users. This applies both online and off -- it's more inconvenient to unlock and open the door on a bank vault than to open the door on the broom closet beside it.

What do you do when the user who is being inconvenienced is higher on the food chain than you are? When the Vice-President of Mumbo Jumbo tells the Security Minion that he wants to be able to do task X with his shiny new cell phone, the right answer is probably "No", but the only available answer is "I'll set that up for you immediately, sir!"

When something like this hack happens later on, then it's obviously the Security Minon's fault, and he should be demoted or fired immediately.

 |  IP: Logged

Marcel Birgelen
Film God

Posts: 3357
From: Maastricht, Limburg, Netherlands
Registered: Feb 2012


 - posted 12-16-2014 12:55 PM      Profile for Marcel Birgelen   Email Marcel Birgelen   Send New Private Message       Edit/Delete Post 
You never know how those Hollywood execs think and operate, but pulling the plug on this movie would be stupid from almost any perspective. Sony is already threatening to sue the world, the moon, the sun and everything else orbiting within 100 light years around Planet Sony. Their PR office apparently being totally oblivious to the Streisand effect.

Also, I have serious doubts all this fuzz is really about the movie. You'll always have some crazy folks that jump the bandwagon on such occasions.

Apparently, the hackers are just trying extort Sony for some serious money or they'll release the next bunch of "juicy bits". If those are the real hackers and not just another bunch of idiots jumping the same bandwagon, then the prime motivation seems to be just plain old money...

quote:
What do you do when the user who is being inconvenienced is higher on the food chain than you are? When the Vice-President of Mumbo Jumbo tells the Security Minion that he wants to be able to do task X with his shiny new cell phone, the right answer is probably "No", but the only available answer is "I'll set that up for you immediately, sir!"
This is also what differentiates good from bad management. If CxO of Mumbo Jumbo did his own job well and hired a competent CTO, who in turn hired a bunch of competent security minions and IT umpa lumpas, CxO should know when to listen to his minions and when to accept *NO* for an answer.

 |  IP: Logged

Adam Martin
I'm not even gonna point out the irony.

Posts: 3686
From: Dallas, TX
Registered: Nov 2000


 - posted 12-16-2014 01:10 PM      Profile for Adam Martin   Author's Homepage   Email Adam Martin       Edit/Delete Post 
quote: Marcel Birgelen
You never know how those Hollywood execs think and operate
We do now! [Big Grin]

 |  IP: Logged

Bobby Henderson
"Ask me about Trajan."

Posts: 10973
From: Lawton, OK, USA
Registered: Apr 2001


 - posted 12-16-2014 01:48 PM      Profile for Bobby Henderson   Email Bobby Henderson   Send New Private Message       Edit/Delete Post 
quote: Marcel Birgelen
Still, if you're SPE or any other megacorp, or megadivision of a megacorp and you have budgets of billions, you should be amongst those who know this. Your IT guys, which should earn a good salary, are paid to know this.
I wouldn't be too sure about that.

So many of these publicly traded corporations are only about making profit and more of it every quarter. Bean counters, board members or whoever in a share holders meeting will push to undermine all sorts of vital things, outsourcing it to the cheapest bidder regardless of any security issues just to make the books look better. I wouldn't be surprised if the well paid IT guys are really a skeleton staff of under-qualified people working 80 hours per week and making shit money.

The really ignorant thing is how companies, such as Sony, put movie theaters through the ringer in terms of security but aren't anywhere near as militant about it in house with their own employees and sub-contractors.

quote: Mike Blakesley
It's not as if the bad guys are going to say "Oh hey, thanks for pulling the movie, we'll leave you alone now." Nope, they might as well just go ahead with it. Maybe cut back on the advertising a little.
The hack couldn't have been a better publicity gift to The Interview. There's probably a lot of people who will go to see it just out of curiosity when they wouldn't have bothered seeing the movie if the Sony hack never had happened. Of the reviews that have been published the results are pretty mixed (it has a 50% score at Rotten Tomatoes).

I wasn't the slightest bit interested in seeing The Interview and would probably still rather watch Team America World Police again if I'm in the mood to see North Korea and American culture get lampooned.

 |  IP: Logged

Mike Blakesley
Film God

Posts: 12767
From: Forsyth, Montana
Registered: Jun 99


 - posted 12-16-2014 03:32 PM      Profile for Mike Blakesley   Author's Homepage   Email Mike Blakesley   Send New Private Message       Edit/Delete Post 
Here is another communique we got from NATO just now. This is from the Hollywood Reporter.

quote:
Sony Hackers Release Latest Batch of Data Tied to "Christmas Gift"
by THR Staff 12/16/2014 9:47am PDT

The Sony hackers have released the latest batch of data from a cyberattack on the studio, according to an email sent to reporters.

"We have already promised a Christmas gift to you. This is the beginning of the gift," the group, which calls itself Guardians of Peace, wrote in the email.

The statement also reads: "We will clearly show it to you at the very time and places “The Interview” be shown, including the premiere, how bitter fate those who seek fun in terror should be doomed to. Soon all the world will see what an awful movie Sony Pictures Entertainment has made. The world will be full of fear. Remember the 11th of September 2001. We recommend you to keep yourself distant from the places at that time. (If your house is nearby, you’d better leave.) Whatever comes in the coming days is called by the greed of Sony Pictures Entertainment. All the world will denounce the SONY."


 |  IP: Logged

Bobby Henderson
"Ask me about Trajan."

Posts: 10973
From: Lawton, OK, USA
Registered: Apr 2001


 - posted 12-16-2014 05:36 PM      Profile for Bobby Henderson   Email Bobby Henderson   Send New Private Message       Edit/Delete Post 
Some of the language in the threats is so over the top it almost seems like a form of satire -kind of like a publicity stunt.

With the FBI now getting involved the situation seems very real. But wouldn't it be kind of mind blowing if the whole thing turned out to be a subversive marketing ploy?

 |  IP: Logged

Mike Blakesley
Film God

Posts: 12767
From: Forsyth, Montana
Registered: Jun 99


 - posted 12-16-2014 06:48 PM      Profile for Mike Blakesley   Author's Homepage   Email Mike Blakesley   Send New Private Message       Edit/Delete Post 
I think if it turns out to be a publicity stunt, people at Sony will have A LOT OF 'SPLAINING to do. (I really doubt this is publicity though....not with all these peoples' salaries and medical records being exposed.)

 |  IP: Logged

Marcel Birgelen
Film God

Posts: 3357
From: Maastricht, Limburg, Netherlands
Registered: Feb 2012


 - posted 12-16-2014 06:57 PM      Profile for Marcel Birgelen   Email Marcel Birgelen   Send New Private Message       Edit/Delete Post 
I agree, this is far beyond a publicity stunt. I've never checked the information that was already out there, but apparently much of it's readily available on several file sharing services. From what you can read in the news, this data is already very detailed. Besides the fact that apparently (former) Sony employees are already being harassed by several low life figures out there using the contact info that has leaked, consider the amount of efforts you would need to put into this to fabricate it in such ways, to make it look legit under the scrutiny of the whole Internet and the world press.

Also, we've got a first-hand account right here, where someone isn't getting paid, because their systems are unavailable.

No, this is just a plain and ordinary FUBAR situation for Sony.

quote:
We do now!
Good one, but it will take psychologist years and years to decipher it all. [Wink]

quote: Bobby Henderson
I wouldn't be too sure about that.
The irony is: Indeed, I'm not too sure about it...

quote: Bobby Henderson
Some of the language in the threats is so over the top it almost seems like a form of satire -kind of like a publicity stunt.
Those threats could also just be the result of some attention whores jumping the bandwagon in the aftermath.

 |  IP: Logged



All times are Central (GMT -6:00)
This topic comprises 17 pages: 1  2  3  4  5  ...  15  16  17 
 
   Close Topic    Move Topic    Delete Topic    next oldest topic   next newest topic
 - Printer-friendly view of this topic
Hop To:



Powered by Infopop Corporation
UBB.classicTM 6.3.1.2

The Film-Tech Forums are designed for various members related to the cinema industry to express their opinions, viewpoints and testimonials on various products, services and events based upon speculation, personal knowledge and factual information through use, therefore all views represented here allow no liability upon the publishers of this web site and the owners of said views assume no liability for any ill will resulting from these postings. The posts made here are for educational as well as entertainment purposes and as such anyone viewing this portion of the website must accept these views as statements of the author of that opinion and agrees to release the authors from any and all liability.

© 1999-2020 Film-Tech Cinema Systems, LLC. All rights reserved.