Many people suggest that startups not over-optimize on issues like security and performance when it's not their core business.
The same could be said of Sony: empathize a little with them. Sony Pictures pays a lot of creative people. Maybe they should have seen the hack coming, but like the PSN outage this story will be maybe a paragraph in a Wikipedia article years from now. Even one great film could be watched by people a century from now, and I respect that their priorities are around figuring out economically viable filmmaking, not I.T.
The film industry regards Sony Pictures as the major studio that still takes risks on edgy comedies and dramas. They are known to respect directors more than the other majors.
Gawker will surface their ridiculous PowerPoints which truthfully exist everywhere. Or journalists will scandalize the executive pay and severances, nevermind that Nick Denton's and Anna Wintour's paychecks and perks are probably far more offensive.
But I don't mean to engage in whataboutism. In fact I mean the opposite: Just because some tech companies care a lot about security doesn't mean everyone should.
Sony Pictures has an operating income (revenue minus expenses) of $501 million per year. They can afford to pay creatives, but they can't afford to pay for a few more security engineers?
Look, I get the creative field costs a lot of money. But Sony Pictures was paying $454,224,070 http://fusion.net/story/30850/ in total salaries as of May.
Even hiring 5 more security engineers would have gone a long way. That's $1 million if we assume a $200k salary for good security engineers. A drop in the bucket for Sony Pictures.
I personally could do a lot with 5 security engineers.
Exactly. Let's not engage in this faux polemic about art-v-practicality. Sony are not mumblecore aesthetes from Bushwick. They are a megalith that should have their security locked down hard. Sorry you got owned, but seriously get with consensual reality: hackerfolk tend to hate owners of Big Content like you. Should have seen this coming ...
> They can afford to pay creatives, but they can't afford to pay for a few more security engineers?
So how do you measure their risk and the probability of being damaged? Serious security experts are STILL trying to figure out how to calculate these things. Insurance companies still have trouble "properly" pricing cyber insurance. The insurance companies are doing it, but they are way behind their ability to price for other forms of disasters.
So how much should they spend towards cyber security? How far off are they from that amount? We don't know. (well maybe we'll know from the leaked documents).
You do that through a Security Risk Assessment. There are plenty of models (e.g. Octave) out there to help a security engineer conduct a Risk assessment on an organization's infrastructure. Moreover, a Security Risk Assessment is very strongly suggested by any Security Compliance Program that deals with sensitive information.
This dump clearly shows personally identifiable information, something that would be easily classified as sensitive (e.g. SSNs). I'm very sure Sony Pictures classified their leaked movies as sensitive since it would cause massive financial loss (which happened) if it was stolen.
If anybody was doing a Risk Assessment, protecting this critical part of the infrastructure would have been number 1 on the list.
Hackers are even claiming that a physical door with access to the sensitive environment was left unlocked. That's security 101!
Sony has a culture problem: if it is not a Japanese initiative, it doesn't happen. Unfortunately, the Japanese web executives are at least 10 years behind on Silicon Valley, on knowledge and vision. For as long as there isn't a Japanese security expert, born in Japan and groomed at Sony, Sony will continue taking these types of blows.
you are talking about human problems. people clicking links. people typing their passwords into foreign web forms.
software engineers wont magically fix executives handing over credentials to hackers.
if you were designing a network and interface to access your files, maybe you could design it without resorting to passwords, but that wasn't practical in sonys case.
maybe they could have designed their network to notice the data leaving, but again, the hackers could always find a way to win. (physical infiltration of the company and a verizon hotspot?)
> software engineers wont magically fix executives handing over credentials to hackers
and all those important files were just lying around
You can't project a film without a dedicated digital link to Sony's servers in London authorising it. For some movies they send personnel to your cinema to record the audience with IR cameras. For some movies you are not allowed to let the staff watch the film for free.
> and all those important files were just lying around
That's it. Whether a designer was comprised through a phishing attack or a physical door with access to the sensitive environment was left unlocked, there were clearly no controls in place to manage all the files just laying around like money under a mattress.
If they can find the money and staff to implement securing third party cinemas to prevent copyright infringement by members of the public, perhaps they should spend a few dollars to secure their own premises.
People in cinemas with cameras are physically detectable.
Network attacks on infrastructure and/or exfiltration by rogue (or rouge) elements within your own workforce are vastly more difficult to detect. Not impossible, but they involve both violations of trust and allegiance, and plausible cover under other activities.
Though, once you're aware of / suspect such exfiltration, there are generally a limited number of places to look for suspects / points of access.
I should have made more of the fact that to screen the movie on your own projector you have to have a dedicated ISDN line to Sony in London which authenticates your machine with an online DRM system.
You also have to give them a share of your ticket sales, provide sales figures and you cannot offer discounted tickets for concessions or special offers.
Much of that is effectively exercising control over the market venue though. The studio gets to specify which facilities do or don't meet the standards required to show their content. To that extent, the technical restrictions are less about keeping the content from being pirated (there are plenty of other leak channels, typically pre-release review copies, which have their own copy controls, yes), and far more about keeping cinemas beholden to the studio vassal lords.
Security is multiple layers. A phishing attack (as you described) should only gets you 1 layer deep, it shouldn't give you access to everything. You still need to bypass the rest of the controls to get the delicious sensitive data. With a leak like this (100 TB of sensitive SSNs, Salaries, and Movies leaked), there clearly weren't very many controls, if any.
I think you're thinking too much about UX, Passwords, and phishing links when you're forgetting all the other layers that a usable security environment can provide without the needs of passwords (e.g. authorization control, segmented file servers for each department). A security engineer can definitely create a very safe and secure environment WITHOUT negatively impacting the usability, experience, or workflow of the creatives working on their designs and art.
Let me rephrase the question here, we could either spend $1m on some gobbledegook that those fast talking nerds saying we need, or we could get bigger bonuses. We worked hard and bonuses would be tangible, when asked about how we will know if $1m expenditure a year is working fast talking nerds talk even more quicker about something that amounts to 'nothing bad will happen'.
We are arguing here from position of knowledge that guys who make these decisions likely do not have. Should they have it? Probably not, but they definitely should listen to someone who knows and who can present solid risk/cost/benefit analysis that they can understand.
I completely agree with you that they should know what they are doing and make robust decisions. But when you are at the top, and you tell board what is going on, and you define what it means to be a professional the line blurs. It is very easy to omit certain tail risks by simply not knowing and not taking time to know about them.
The most recent google hack [1] wasn't actually a Google hack. It was just a combined list of various email/password dumps of various hacked webservices over the years. That all ended in @gmail.com
My account was included yet my password was 18 months out of date.
Google was hacked quite as hard? You mean, where all their employee SSNs were posted online, along with their technology roadmap? No, sorry, I don't remember that.
Many people suggest that startups not over-optimize on issues like security and performance when it's not their core business.
And that's a fucking stupid thing to say in those cases, so it's a fucking stupid thing to say here.
Things like security and performance should be given. This is akin to arguing that small restaurants shouldn't care about food safety, or that small construction firms shouldn't worry about building codes. If you ignore these things, you'll fuck it up and people will get hurt.
Did Sony fail to meet a competent standard? The fact that they got hacked is not sufficient proof they failed that standard. "Competent" does not mean invulnerable.
The exfiltration of 100TB of data from systems across their entire organization suggests so.
On a 100Mbit/s pipe that would take something like 3 months of full saturation to get that amount of data out. Realistically, we're probably talking about a hack spanning nearly every one of their systems for upwards of a year.
> Things like security and performance should be given. This is akin to arguing that small restaurants shouldn't care about food safety, or that small construction firms shouldn't worry about building codes.
No, it's completely different. Food safety and building codes is akin to good software engineering; on the other hand, security against hacks is more like a restaurant protecting you from a third party poisoning your food, or a building withstanding planes crashing into it. Most building and most restaurants don't offer such protection.
If we're talking about security and a small restaurant, it would be more like the restaurant never bothering to lock its doors after hours, having no security cameras, and not bothering to put its money in a safe place, leaving it out in the open to be stolen.
this entire thread of conversations is a joke. Do you know more about this breach than what was written in the article because they clearly state they don't know exactly what happened. Which isn't to say that Sony doesn't know more but from details released how can you know anything about what Sony does or doesn't do security wise that they should have been?
Like literally the first rule of Security is that as the person trying to defend, protect, secure something you are always at a disadvantage. Of course Sony has money to hire top notch Security Engineers to protect their interests and I'm sure they do but like anyone else they can be beat.
This is all not even accounting for the security black hole that is user idiocy, or the fact that the article makes several references to potential inside help.
In short Sony's past exploits don't give them a ton of credit but it's also a bit ridiculous to go from they could have done better to where this whole thread went.
* Of course Sony has money to hire top notch Security Engineers to protect their interests and I'm sure they do but like anyone else they can be beat.*
Maybe they do; I don't know. That's not really relevant to the point which I'm making, which is more along the lines of:
"Disregarding security as a startup because it's not a 'core competency' is ill-advised. History suggests that you're likely to be compromised, and it causes harm not only to your business, but also to your users, and is absolutely irresponsible."
Secondly - Did you see the words over optimize? There is certainly such a thing as too much optimization in terms of security. Would you hire police men to patrol your kid's lemonade stand startup? No.
Yeah but this was clearly UNDER optimized for the security of 100 TB of SSNs, Salaries, and Movies leaked. All of which is classified as sensitive (i.e. anything that can be considered a financial loss to the business).
2) The bandwidth required to move all of that before sony noticed
This [likely] wasn't some script kiddie that exploited some obvious security hole. Of course their security was under optimized. Every single theft in the history of time has been a result of "under optimized" security.
Figure a hacking group is a dozen people. That's ~8.3T per person to stash. I know plenty of folks with that kind of storage lying around, it doesn't seem insane that folks deep in infosec might have even more idle capacity.
Alternatively the first newegg hit for a 6T hard drive is $300 even. That's 17 of them so $5k plus shipping. Either add in a chassis with enough slots or enough smaller machines to distribute it so say double to $10k or less than $1k per person.
Or even lazier, to store all 100T on S3 for a month and pull it back out is ~$12k, again maybe plus a bit for an EC2 instance to do the shuffling. Again, ~$1k per person.
And of course if you're a hacking group the chances that you've got root on some small business servers scattered around the world are probably a bit better than zero.
When it comes to start-ups it's not stupid - it's wise. The food safety analogy is inappropriate. Security is about risk management. Low risks do not justify high expenses.
When it comes to a company with hundreds of millions in revenues, however, they have clearly underestimated the risks and have been irresponsible.
I would say even the food safety analogy is appropriate. Sure, food safety is important; that doesn't mean you have to spend hundreds of millions of pounds in "food safety researchers" who will conduct rigorous scientific experiments to find out the best ways to limit the spread of germs and implement them, an in-house doctor with medical supplies who will treat customers that get food poisoning, etc.
It just means there's a minimum, a bar, that they shouldn't go below. Everyone has a different bar, but most people generally agree on things like don't pick up food off the floor, don't leave things open or out, put things in the right places, make sure you wash your hands, etc. (I am not a food safety expert).
Of course, for a startup, it depends on the product or service they're offering. A startup payment processor should be very security conscious, as the stakes are high. A movie logger should have the bare minimum that all startups should have, i.e. strong encryption, basic security protocols, etc.
> I would say even the food safety analogy is appropriate.
I think it's NOT appropriate. Of course, in the end, it's a matter of value: Do you value your health equally with your digital privacy, your money, etc.? If 'yes' then the analogy yes, if 'no' then it doesn't. I don't so, to me, it doesn't.
At my previous job, I made $25k less per year than the idiot who nearly exposed us to RFI risks before I looked over his code.
Developers are developers. If you're going out of your way to hire extremely untalented people, because they're cheap, you're going to get owned.
If you're hiring people who understand their own craft, you can get a junior developer for under $70k and a senior for under $100k. Unless you're in SF in which case multiply everything by 2 or 3.
A start up is like a restaurant with 2 doors into the kitchen. 1 door from the outside, 1 door for servers to enter/exit.
In a restaurant the workers can easily spot problems. And if someone walks in usually you kick them out, or lose a batch of food. The cost is much smaller than hiring 2 full-time bouncers.
If, however, you now have a giant catering hall with 50 entrances to the kitchen and hundreds of people there, security / bouncers are necessary.
The problem is how to go from one to the other, and not realize you need security when it is too late.
I empathize with them not at all. I know how much Sony pays their high level security folks, it's a laughable amount and there is no possible way they could retain anyone even remotely qualified for those roles. If you do your best and get hacked, I'll empathize. If you deprioritize security to an extreme degree and get hacked I won't feel sorry for you.
I think fraction of their executive bonuses would be quite enough to fully fund a fairly decent security effort. If security were designed into their processes, it would probably cost much less.
If the 100 TB figure is correct, this has been going on for some time - it takes time to steal that much data in a way that does not raise a bunch of red flags. If the red flags weren't there to be raised or they were and were ignored, well... at least their executives got their bonuses.
Also, in the interest of fairness, while this malware attack seemed to be directed to Windows machines, a dedicated enough intruder would have developed attack strategies for any platform.
A "fraction" of a bonus. Let's assume their bonus is a paltry 100k. A good infosec pro expects on average to be making at least 200k, so you have already blown out your budget. You can take a swing at hiring a consultant, but that gets you 5 weeks at around 70k, so you are eating a huge chunk of your fractional bonus budget.
Consultants don't really work for systemic problems like this though. Sony has cancer. They need empowered specialists to come in and tear out and then replace. These are both technical and managerial problems that exceed the capabilities of your average defcon attendee.
I disagree with both the approach you have taken here in envoking executive pay envy, as well as the substance. Security is hard. Practicing good security is expensive. You don't get to throw a couple of hundred grand around once and call it good. It is an ongoing and expensive investment.
> A "fraction" of a bonus. Let's assume their bonus is a paltry 100k. A good infosec pro expects on average to be making at least 200k, so you have already blown out your budget.
I agree with your overall point, but the first page of the leaked salary list alone has something like $35M worth of bonuses. Say the high-level execs are the only ones sacrificing their pay, and the 'fraction' of bonuses was 20%, you'd have $7M annually to spend on infosec -- in addition to all of the money they're already spending (and apparently wasting). This would pay the salaries of ~30 top-notch security people.
Ostensibly, executive bonuses in publicly traded companies are tied to actions that are a proxy for increasing shareholder value. Massive damaging hacks are not good for shareholder value.
In any case, it was just a comparative point, they clearly have the cash flows to hire competent security staff without impacting others' pay if they so desire.
In any case, thanks to the leaked information, it should be easy to tell exactly how much Sony paid the people who are responsible for this mess.
Security is hard, but this looks like a lot of low hanging fruit being picked effortlessly. My bet is that just a tiny bit of effort would have made the intruders work much harder.
100TB? Seems more likely nobody noticed a team carrying out some thirty-five 3TB external drives. If their network was able to maintain operations while somebody sucked out 100TB of data through their gateway, I'm impressed.
Any serious operation dealing with the amount of media (images, videos, various editing files, etc) that Sony was is going to have very fat pipes. They probably moved upwards of a few TBs a day.
> Many people suggest that startups not over-optimize on issues like security and performance when it's not their core business.
> The same could be said of Sony:
How so? The whole point of saying it about startups is that they are startups.. they have severely limited capital and resources and need to optimize for growth/revenue/continuing to exist.
This does not apply to Sony. If you are storing medical records and SSNs and you are multi-billion dollar company; there is no viable excuse that looks anything like, "uhh.. yeah well we are really just an entertainment company."
No one suggests that startups not over-optimize on security or performance because these are not their core business. They suggest that they don't optimize for them because they have extremely limited resources compared to big corporations like Sony.
It doesn't matter how much time a startup spends on security and performance if they never find product-market fit and get to the explosive growth phase. Once they do however, this is when they need to raise real money and start addressing these "non-core" issues as well.
Sony is not a startup, is not resource constrained, etc. There's absolutely no reason to empathize with them.
> The film industry regards Sony Pictures as the major studio that still takes risks on edgy comedies and dramas. They are known to respect directors more than the other majors.
I'm not in touch with the film industry, so could you link me to a discussion about this somewhere? I find the idea of Sony taking risks hard to reconcile with the mess that was "The Amazing Spider-Man 2", but as I only know the comic book fan side of things I could use some extra background.
Thing about that is, the movie business is all about risk deference sometimes: making a dumb obvious move now, so you can afford to take the bigger risk later.
And remember too that while the sequels of both SM film series have been largely crap, the originals were big risks in some respect. The first Spider-Man gave a massive budget to a director largely known only for low-budget shlock, and the ASM reboot meant deciding only a few scant years after the last one to completely dump and start over a franchise that was circling the drain.
I once asked a lock pick artist what lock I should get for my house. They pointed out that if you have something valuable in your house, do you want to protect it with a 50 dollar lock or a 250 dollar lock. Basically they should have had better security; and I can bet they will spend the money for proper security now that they got owned so well.
It's a great time to be working in the security field today.
Yep. And it misses the simpler solution of not having things in your house that are worth stealing. Sure, TVs, laptops, etc., but those can be stolen anywhere. Eliminating cash and jewelry from your home can make that $50 lock the right trade-off.
> do you want to protect it with a 50 dollar lock or a 250 dollar lock
It's not obvious to me that the $250 lock actually performs better in any relevant way. You might trust the guy, but when I'm hearing an anecdote second-hand I want to hear something more convincing than "trust the price".
Which is very much the problem -- it's quite hard for security non-experts to distinguish between good security and security theatre.
The same could be said of Sony: empathize a little with them. Sony Pictures pays a lot of creative people. Maybe they should have seen the hack coming, but like the PSN outage this story will be maybe a paragraph in a Wikipedia article years from now. Even one great film could be watched by people a century from now, and I respect that their priorities are around figuring out economically viable filmmaking, not I.T.
The film industry regards Sony Pictures as the major studio that still takes risks on edgy comedies and dramas. They are known to respect directors more than the other majors.
Gawker will surface their ridiculous PowerPoints which truthfully exist everywhere. Or journalists will scandalize the executive pay and severances, nevermind that Nick Denton's and Anna Wintour's paychecks and perks are probably far more offensive.
But I don't mean to engage in whataboutism. In fact I mean the opposite: Just because some tech companies care a lot about security doesn't mean everyone should.