|
|
|
|
Author
|
Topic: Sony Hack Hits Home
|
David Buckley
Jedi Master Film Handler
Posts: 525
From: Oxford, N. Canterbury, New Zealand
Registered: Aug 2004
|
posted 12-20-2014 06:21 PM
quote: Frank Cox When large companies set up the computers that they put onto employees' desktops, they use a standard master image to do so. Therefore, the local admin hashes will all be the same.
I would hope that any modern windows installation (W/7 onwards) would no longer use the local admin account, as the risks of doing so are so well understood.
But the risks of password hashes remain, see Pass the Hash, made worse by adminstrators not understanding basic separation of roles and using separate credentials for each role. Domain admins (of which there should be very few) need three sets of credentials to do their jobs, or bad things will happen.
Another big problem is that most installations have grown up over the years and been through several sets of upgrades, so a lot of old cruft remains, one the worst being LAN Manager support, which if users have passwords of less than 15 characters, they may as well be published on the homepage.
And then there is Windows stupidity. By default, Windows stores a copy of the current user's password in plain text, and will hand it out to an application on request. This behaviour can be disabled, but its something that needs to be done, and is not without impact to convenience.
So although windows can be made to be damned secure, secure to the point that our governments use it for top secret stuff, by default it isn't, and coupled with organisational poor security posture, administrators poor practices, users that don't give a f**k about security, and then general pervasivness of leaky networks, the game is lost before the first dice is rolled.
Welcome to the 21st century.
The problem is: Security is hard. Security inconveniences users. Perhaps worse, Security inconveniences managers and important people.
quote: Mike Blakesley Can't we just hack some North Korea computers and turn off their electricity or something?
Of course. America (so the world believes) fired the first shot in this war with stuxnet, and America told the war that cyberwarefare is OK, because "America does it". But the USA knows that it has far more to lose in this war than everyone else, and they are far more vulnerable than most. America has seen what poking Iran with cyberwarfare has done; Iran has upskilled, and fast. They went from nowhere to a (cyber) world power in just a few years.
The USA is not going to go all assy over something as trivial as the Sony mess, it is leaving Sony to end up with the red faces.
quote: Randy Stankey During the next couple-few decades, Cuba could be a new banana republic and we could leave China and North Korea high and dry.
That is not a strategy without risk; at the moment the USA and China are in a state of detente over the minor matter of the $1.2T that the USA owes China. If China called in that debt then the USA would be farked, as would the USD. But China aren't going to demand debt repayment any time soon, as to do so would also fark China. However, if the USA decides to fark China by abandonment, then China would have little to lose...
| IP: Logged
|
|
|
|
Leo Enticknap
Film God

Posts: 7474
From: Loma Linda, CA
Registered: Jul 2000
|
posted 12-21-2014 02:28 AM
quote: David Buckley The problem is: Security is hard. Security inconveniences users. Perhaps worse, Security inconveniences managers and important people.
It also needs to be proportionate to the nature and extent of the perceived threat. You don't put a cast iron, 300-ton door on the entrance to your house, but you do on the entrance to Fort Knox.
Sony, however, don't seem to have got this point. They had the master level, unencrypted digital assets of their latest mainstream releases on these effectively unsecured servers: the IP the North Koreans uploaded out must have been worth hundreds of millions. Once you add their legal liability for having leaked the personal data of employees, suppliers and customers, and the indirect costs in loss of reputation, you can probably add even more hundreds of millions on to that. That's essentially what shocks me about this episode: that such a large corporation, and in a security-conscious industry, didn't understand this.
| IP: Logged
|
|
Marcel Birgelen
Film God
Posts: 3357
From: Maastricht, Limburg, Netherlands
Registered: Feb 2012
|
posted 12-22-2014 10:04 AM
In the big picture, Sony has done everything wrong it could have done wrong. First, they got their systems breached and tons of information stolen. They apparently have even been warned about it, but failed to act on it.
Then they hired a big shot lawyer and started dishing out big warnings across the world.
Then they decided to cancel the release of the movie it was, apparently all about, getting them nothing but bad press from around the globe.
quote: Mike Blakesley Can't we just hack some North Korea computers and turn off their electricity or something?
Which will probably hurt many people which have absolutely nothing to do with all of this the most.
As of now, it's not even sure it was the North Koreans, even if the president himself claims so. The proof given up until now is of the same quality as the proof we as a public got regarding Weapons of Mass Destruction in Iraq and we all know how well that went.
Nobody is also going to war over this kind of stuff, or it must be part of some kind of false pretext. Still, it would be a pretty lame excuse. It’s SPE who messed up, SPE in the picture of a whole nation, is irrelevant. Even if they would go bankrupt because of the fallout of it all, it is still almost completely irrelevant.
Apparently, a bunch of other hackers has gotten hold of the whole picture already, although that's what they're publicly claiming. They also claimed they got it from a separate hack… They’re threatening to release it to the public. If this turn out to be true, how can we even remotely trusting those other bigshots pointing their fingers at North Korea?
quote: Leo Enticknap Sony, however, don't seem to have got this point. They had the master level, unencrypted digital assets of their latest mainstream releases on these effectively unsecured servers: the IP the North Koreans uploaded out must have been worth hundreds of millions.
At least some of their IP needs to be treated with military grade security. This is true for all multi-billion dollar corporations. For most U.S. and European corporations, their most valuable assets are their Intellectual Property assets. Much of it being governed by copyright and patents, but many trade secrets which are protected by no real law in existence.
There's nothing what the Chinese cannot copy, so you better protect your IP with a proverbial 300-ton door or else you're just a bunch of amateurs. You will be eaten up and spitted out by the global economy in the blink of an eye.
The biggest problem is, this will require you to put your really important stuff on something different than some easily accessible file servers on your local Windows domain or in some Dropbox account "in the cloud". You will also need the tools, training and procedures to keep them safe. A single employee not following the rules can potentially open the floodgates: Copy a bunch of super-important files to an USB dongle and lose it at the local Starbucks… They need to sink millions upon millions into security that actually matters and in return the CxO cannot even have his e-mail on his latest iShiny.
But heck, something needs to change. What we see now is just the beginning of this ever increasing push to "the cloud" and "always on". As long as we keep releasing products before they're finished, we should not even dream about those kind of interconnected worlds as we're creating a nightmare for ourselves.
I for once have started to airgap all kinds of systems both at work and at home once and again. It's really great that I can control the lights at home from my office, but as long as it is strung together via a bunch of systems that need a security upgrade every now and a fortnight to be even remotely secure, I don’t even dare to hook it all together.
| IP: Logged
|
|
Sean Weitzel
Jedi Master Film Handler

Posts: 619
From: Vacaville, CA (1790 miles west of Rockwall)
Registered: Dec 1999
|
posted 12-23-2014 12:21 PM
Predictably, Sony is going ahead with a limited release of The Interview on Christmas Day" http://www.huffingtonpost.com/2014/12/23/sony-the-interview-screenings_n_6373096.html
quote: Huffington Post posted: Moviegoers will be able to see "The Interview" after all. Sony announced on Tuesday that "The Interview" will have a "limited theatrical release" in the Untied States on Christmas Day.
"We have never given up on releasing 'The Interview' and we're excited our movie will be in a number of theaters on Christmas Day," Michael Lynton, Chairman and CEO of Sony Entertainment, said in a statement. "At the same time, we are continuing our efforts to secure more platforms and more theaters so that this movie reaches the largest possible audience.
"I want to thank our talent on 'The Interview' and our employees, who have worked tirelessly through the many challenges we have all faced over the last month," Lynton added. "While we hope this is only the first step of the film's release, we are proud to make it available to the public and to have stood up to those who attempted to suppress free speech."
Following terror threats made by hackers against theaters that planned to show "The Interview," Sony had reportedly told theater owners they could pull the film at their discretion. Last week, after major chains such as AMC Entertainment, Regal Entertainment, Cinemark, Cineplex Entertainment and Carmike Cinemas decided against screening "The Interview," Sony yanked the comedy from the release schedule.
"In light of the decision by the majority of our exhibitors not to show the film 'The Interview,' we have decided not to move forward with the planned Dec. 25 theatrical release," the studio said in a statement on Dec. 17. "We respect and understand our partners' decision and, of course, completely share their paramount interest in the safety of employees and theater-goers."
In the wake of the decision, the studio was criticized by members of the Hollywood community and even President Barack Obama, who said in a press conference on Friday that Sony had made "a mistake."
TheWrap reports that Sony will soon announce plans to release the film on video on demand as well, but that was not confirmed by Sony. Some theaters planning screenings of the film include the Alamo Drafthouse. Tim League, the theater's founder, was first to tweet news about Sony's change of plans:
The Alamo's Dallas location is now offering showtimes and tickets on its website, and Atlanta's Plaza theater also tweeted that it would have showtimes for "The Interview" available soon.
Seth Rogen, who co-directed "The Interview" and stars in the film alongside James Franco, was pleased with the studio's decision:
This story is developing ...
| IP: Logged
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Powered by Infopop Corporation
UBB.classicTM
6.3.1.2
The Film-Tech Forums are designed for various members related to the cinema industry to express their opinions, viewpoints and testimonials on various products, services and events based upon speculation, personal knowledge and factual information through use, therefore all views represented here allow no liability upon the publishers of this web site and the owners of said views assume no liability for any ill will resulting from these postings. The posts made here are for educational as well as entertainment purposes and as such anyone viewing this portion of the website must accept these views as statements of the author of that opinion
and agrees to release the authors from any and all liability.
|