|
|
|
|
Author
|
Topic: Sony Hack Hits Home
|
Frank Angel
Film God

Posts: 5305
From: Brooklyn NY USA
Registered: Dec 1999
|
posted 12-12-2014 06:05 PM
In this day and age, anyone who thinks or treats communications on the internet and especially emails on a company server as if it is "secure" is just delusional. There is no such thing as a private email on the internet. You say nasty stuff about your A list clients, actors, directors, whomever, and think it won't ever be discovered, then you get what you deserve. But really, big deal someone says an actress is a brat. Is this a surprise? Anyone really think divas AREN'T brats?
The REAL issue is that 5 Sony films, drek as they may be, were hacked. Any studio that puts multi-million dollar product on server CONNECTED TO THE INTERNET deserves what they get. Given how paranoid the studios seem to be about piracy, the fact that they allow production content to be floating around on hack-able servers is a joke. And you don't need to spend millions on security for production content, you just need to keep it on a closed system. Disconnect it from the internet, period. Sure it will mean the big wigs many not have the convenience of being able to do screenings in their home theatres and they may have to actually go to the studio to see dailies, but in one single disconnect, you slaughter ALL of the hacking possibilities. Keep your film file servers disconnected from the internet; inconvenient, yes, but complicated security, no. NOTHING can be hacked if it's off line.
| IP: Logged
|
|
|
|
|
|
Marcel Birgelen
Film God
Posts: 3357
From: Maastricht, Limburg, Netherlands
Registered: Feb 2012
|
posted 12-14-2014 06:58 AM
quote: Bobby Henderson That doesn't absolve end users from their own responsibility. I'll be the first to blame an end user for deliberately or ignorantly doing risky things with a computer. But the fact remains that a bunch of things are out of our control. Even the notion of buying a Mac or iOS device is no longer a guarantee of safety, as seen by some news-making hacks lately (like the Chinese government hacking iOS devices used by protesters in Hong Kong).
If you look at end-users and small businesses, I couldn't agree more. Those vendors (ironically, Sony amongst them) really need to step up their efforts to release products that just work and are safe to use in every aspect. This whole concept of churning out products, before they're actually finished needs to stop and people should actually just quit buying this junk.
Look at the whole chain from the lowest hardware layer to the end user software, you'll see just a pile up of unfinished, rushed out products, barely working together. Robustness, which used to be an important cornerstone of all IT related products out there, is nowhere to be found.
Still, if you're SPE or any other megacorp, or megadivision of a megacorp and you have budgets of billions, you should be amongst those who know this. Your IT guys, which should earn a good salary, are paid to know this. You should know that, for example, hooking up your smart phones to your internal network, to allow everybody to access everything from everywhere, will open up your network for potential abuse. You know that for almost every shitty product out there, whether or not they’re made by Dell, HP, Microsoft or Apple, there will be countless zero-day exploits around.
Knowing this, and knowing the sensitivity of the information you're dealing with, you might just choose not to hook it all together. Because, there are plenty of solutions out there, which will make it almost impossible for any hacker to get away with whole file servers worth of data. The problem is, they WILL cost serious money, they will, if nothing goes awry like it did now, not earn you one buck extra. And yeah, you will also have to deal with those self-important-persons, who'll urge the IT guy to get their e-mail running on whatever shiny device they'll bring in.
quote: Leo Enticknap This hack is turning into disastrous news for Sony. The Angelina Jolie snarking is ultimately just a bit of a giggle, but it's now being reported that medical records of Sony employees have also been leaked.
I’ve read in some local news today that even the script of the latest Bond movie was supposedly included in the hack.
| IP: Logged
|
|
Leo Enticknap
Film God

Posts: 7474
From: Loma Linda, CA
Registered: Jul 2000
|
posted 12-14-2014 12:20 PM
quote: Marcel Birgelen Still, if you're SPE or any other megacorp, or megadivision of a megacorp and you have budgets of billions...
And especially if you're a megacorp in an industry that is known for being security-sensitive. What irritates me is that the security BS the studios impose on us is a constant impediment to us doing our job properly. KDMs that don't open in time for us to test the movie properly before showtime, the countless hours spent chasing KDMs that don't arrive, film prints that arrive with stupid padlocks on the case, are all irritants that we are forced to put up with in the name of protecting their IP. But yet they themselves operate such poor internal security that it was possible for the North Koreans (and/or people operating on their behalf) to empty their entire servers - including every single email written on their lot for the last ten years, for frig's sake!
IT security should always be proportional to the actual threat. I have TrueCrypted the data volume on my laptop, because it does contain data about some other people that they have a right to expect will not be leaked. The chance of it being stolen, while not great, is significantly higher than zero, and entering in a password every time I boot it up is not too much to ask to protect that data. But I don't change that password daily, or never connect it to the Internet, or take the kind of enhanced precautions I would take if I believed that enemies who knew what they are doing were actively trying to take that data from me.
If the studios didn't believe that enemies who know what they are doing are trying to steal their digital assets, why was DCP encryption ever part of the standard? Why were CSS and the other consumer media protection systems ever invented? Why do I have to sign a NDA when I project a studio preview before its release? Yet Sony feels the need to do all of this, but not to keep its own back end infrastructure secure?
| IP: Logged
|
|
|
|
|
|
|
|
Marcel Birgelen
Film God
Posts: 3357
From: Maastricht, Limburg, Netherlands
Registered: Feb 2012
|
posted 12-16-2014 12:55 PM
You never know how those Hollywood execs think and operate, but pulling the plug on this movie would be stupid from almost any perspective. Sony is already threatening to sue the world, the moon, the sun and everything else orbiting within 100 light years around Planet Sony. Their PR office apparently being totally oblivious to the Streisand effect.
Also, I have serious doubts all this fuzz is really about the movie. You'll always have some crazy folks that jump the bandwagon on such occasions.
Apparently, the hackers are just trying extort Sony for some serious money or they'll release the next bunch of "juicy bits". If those are the real hackers and not just another bunch of idiots jumping the same bandwagon, then the prime motivation seems to be just plain old money...
quote: What do you do when the user who is being inconvenienced is higher on the food chain than you are? When the Vice-President of Mumbo Jumbo tells the Security Minion that he wants to be able to do task X with his shiny new cell phone, the right answer is probably "No", but the only available answer is "I'll set that up for you immediately, sir!"
This is also what differentiates good from bad management. If CxO of Mumbo Jumbo did his own job well and hired a competent CTO, who in turn hired a bunch of competent security minions and IT umpa lumpas, CxO should know when to listen to his minions and when to accept *NO* for an answer.
| IP: Logged
|
|
|
|
Bobby Henderson
"Ask me about Trajan."

Posts: 10973
From: Lawton, OK, USA
Registered: Apr 2001
|
posted 12-16-2014 01:48 PM
quote: Marcel Birgelen Still, if you're SPE or any other megacorp, or megadivision of a megacorp and you have budgets of billions, you should be amongst those who know this. Your IT guys, which should earn a good salary, are paid to know this.
I wouldn't be too sure about that.
So many of these publicly traded corporations are only about making profit and more of it every quarter. Bean counters, board members or whoever in a share holders meeting will push to undermine all sorts of vital things, outsourcing it to the cheapest bidder regardless of any security issues just to make the books look better. I wouldn't be surprised if the well paid IT guys are really a skeleton staff of under-qualified people working 80 hours per week and making shit money.
The really ignorant thing is how companies, such as Sony, put movie theaters through the ringer in terms of security but aren't anywhere near as militant about it in house with their own employees and sub-contractors.
quote: Mike Blakesley It's not as if the bad guys are going to say "Oh hey, thanks for pulling the movie, we'll leave you alone now." Nope, they might as well just go ahead with it. Maybe cut back on the advertising a little.
The hack couldn't have been a better publicity gift to The Interview. There's probably a lot of people who will go to see it just out of curiosity when they wouldn't have bothered seeing the movie if the Sony hack never had happened. Of the reviews that have been published the results are pretty mixed (it has a 50% score at Rotten Tomatoes).
I wasn't the slightest bit interested in seeing The Interview and would probably still rather watch Team America World Police again if I'm in the mood to see North Korea and American culture get lampooned.
| IP: Logged
|
|
|
|
|
|
|
|
Marcel Birgelen
Film God
Posts: 3357
From: Maastricht, Limburg, Netherlands
Registered: Feb 2012
|
posted 12-16-2014 06:57 PM
I agree, this is far beyond a publicity stunt. I've never checked the information that was already out there, but apparently much of it's readily available on several file sharing services. From what you can read in the news, this data is already very detailed. Besides the fact that apparently (former) Sony employees are already being harassed by several low life figures out there using the contact info that has leaked, consider the amount of efforts you would need to put into this to fabricate it in such ways, to make it look legit under the scrutiny of the whole Internet and the world press.
Also, we've got a first-hand account right here, where someone isn't getting paid, because their systems are unavailable.
No, this is just a plain and ordinary FUBAR situation for Sony.
quote: We do now!
Good one, but it will take psychologist years and years to decipher it all.
quote: Bobby Henderson I wouldn't be too sure about that.
The irony is: Indeed, I'm not too sure about it...
quote: Bobby Henderson Some of the language in the threats is so over the top it almost seems like a form of satire -kind of like a publicity stunt.
Those threats could also just be the result of some attention whores jumping the bandwagon in the aftermath.
| IP: Logged
|
|
|
|
All times are Central (GMT -6:00)
|
This topic comprises 17 pages: 1 2 3 4 5 ... 15 16 17
|
Powered by Infopop Corporation
UBB.classicTM
6.3.1.2
The Film-Tech Forums are designed for various members related to the cinema industry to express their opinions, viewpoints and testimonials on various products, services and events based upon speculation, personal knowledge and factual information through use, therefore all views represented here allow no liability upon the publishers of this web site and the owners of said views assume no liability for any ill will resulting from these postings. The posts made here are for educational as well as entertainment purposes and as such anyone viewing this portion of the website must accept these views as statements of the author of that opinion
and agrees to release the authors from any and all liability.
|