5 ms·
Disagree on absurdity. I'm certain that if you focused enough eyes on any company with as much surface area exposed to the internet you'd poke just as many hole
by kevindication 15y ago
Disagree on absurdity. I'm certain that if you focused enough eyes on any company with as much surface area exposed to the internet you'd poke just as many holes.
- MediaBehavior 15y ago>...as many holes. But would you find most storing passwords in plain text? in 2011?
- kevindication 15y agoI had to stop a previous employer from doing just that in 2003. It was bad practice then, too. Big companies are just more susceptible to these kinds of short-cuts. Especially shortcuts with no clear benefit except to a lazy programmer. I remain pessimistic.
- rosser 15y agoFailing to encrypt user passwords isn't a short-cut; it's an inexcusable and egregious failure — especially when it's done by a company that has the resources to do it right in the first place.
- ary 15y agoGiven how much bad publicity and legal exposure costs a corporation of Sony's size I'd say that getting their affairs in order across the board should have been a bigger priority. As it is wildly unreasonable not to have taken a good hard look at every piece of infrastructure after the fist major breach I'd say absurd describes this situation pretty well.
- spydum 15y agoEven if they had hired all of the top ranked security firms the first day PSN was hacked, they would still be open to attacks like this. The amount of public properties Sony hosts internationally is huge -- it would take a long time securing it all.
- raganwald 15y agoWhat's worse is that every bit of data we took wasn't encrypted. Sony stored over 1,000,000 passwords of its customers in plaintext, which means it's just a matter of taking it. This is disgraceful and insecure: they were asking for it. I'm not sure that is true for any company with as much surface area. I would be extremely disappointed if it were true of any of Canada's five major banks, for example. Google has been under continuous hacking attack from China and so far they haven't had to 'fess up to storing passwords in plaintext.
- kevindication 15y ago"Any" is probably an exaggeration. I'd cede that and accept "most." We can hope that Google is an exception because of the caliber of employee they hire, since obviously they also have a lot of domain knowledge. But, I think that only means we're quibbling about the embarrassment level of these breaches.
- raganwald 15y agoSorry for the delay... Parenting! Any ways, I agree we shouldn't quibble about any/most. I also agree that a big surface area (such as units with independent web strategies all over the world) increases the likelihood of there being some breach of security. What I find embarrassing here is that we aren't talking about one of the Sony properties having a breach, it's lots and lots of them. I suggest that this is symptomatic of a problem with Sony itself, not just the surface area they present. What I'd expect from a well-managed company with a big surface area is yes, some property might have a breach, but that would be the exception. It's beginning to look like Sony's lax security with respect to customer information is the rule and not the exception. JM2C, I am not claiming I know this for a fact.
- kevindication 15y agoUnderstand regarding parenting. I do that myself. :-) I do see your point about Sony, and they may in fact be an outlier here. I think I've been accustomed to the story of customer information breaches from large corporations though, and so maybe I'm overly pessimistic?
- bh42222 15y agoSonyPictures.com was owned by a very simple SQL injection... From a single injection, we accessed EVERYTHING ... every bit of data we took wasn't encrypted. Sony stored over 1,000,000 passwords of its customers in plaintext... I have to disagree. Lots of big companies are not great at security, but this is just horrible!
- sp332 15y agoSony didn't even have a CISO before they shut PSN down.