Hacker Leaks Episodes from Netflix Show and Threatens Other Networks
nytimes.com
nytimes.com
And I wonder how many TV customers are doing what I do, where I subscribe to Netflix and go months without watching it (and my in-laws do); my in-laws have a cable subscription that my wife uses to watch stuff online; I can find the stuff I want to watch through torrents.
At best, this person would be signing up for a month then cancelling after finishing the season, and Netflix had a one month free trial, so I'm having a hard time seeing how Netflix is materially impacted here at all.
> If the hacker somehow put up all the episodes on a site and it was just one click to stream then maybe I'd go for it.
I just don't think that's ethical, given Netflix isn't only about ease of use, but content creation too!
Amongst the things specified are: o air gapped network
o All internet through a RDP/VDI service (no copy and paste..)
o all devices to be physically locked away
o all mass storage drivers to be removed
o Physical segmentation of all workspaces
o many other things
http://www.mpaa.org/content-security-program/
The other thing to note is that this is an audio facility, which is usually the last, or second to last point before release. It also by default has the whole film/show in one place, which outside of finishing and distribution is quite rare.
When I left, AD, 90 day password rotation, air gaps, RDP internet and no copy and paste.
That made the google debugger rather hard (along with phone home licensing...)
Well, considering that virtually all VFX houses now have fully isolated networks (more or less), I'd say the audits are pretty effective.
As an addendum, Most if not all leaks from VFX have been caused by "inside people" or drunk/coked producers leaving non-compliant laptops on planes.
As I said, toothless. That such practices are allowed to persist demonstrates how inept their security is. Non-compliant laptops shouldn't exist. The audits miss them. For a group that champions DRM, they cannot keep track of who has access to what within their own houses.
The security drive has been exceptionally effective in london and vancouver, not sure about LA.
The only money netflix could potentially lose here is the small cross section of people who only subscribe for a single month to watch this show along with people who know how to use bittorrent.
Kinda surprised netflix hasn't gone for a strategy where they post the first three episode of a series online for free and then require a subscription for the rest.
They always end up on torrent around the release, sometimes before. It's fact of life. Videos are simply not valuable.
P.S. Apparently, that guy used to deface hospitals and ask for a ransom to restore their files.
Most organisations wouldn't feel comfortable with:
a) Not having locks on their buildings
b) Having known-defective locks on their building
c) Not doing regular audits of the locks their using vs. what criminals can crack
d) Not having reasonable organisation-wide policies to make sure the locks are used properly and kept secure
Yet I don't think that there is quite enough attention given to IT security. It still seems like primarily a "box ticking" exercise, or a case of throwing rules and regulations at the problem which make sense at face value, but are inherently flawed.
Now, some businesses use better stuff - Abloy or Medeco stuff, but many still don't.
A lock is only as good at stopping someone entering as the windows and doors are resistant to being removed. The advantages to locking something are: * There is evidence that the door was forced after the event * Very clear signaling of who is and isn't supposed to have access to a room.
Unless serious money is spent, I would expect that locks are delaying access by a matter of maybe up to hours. If IT security were that poor, the world would look different. A better analogy would be spending the money on security guards.
You're right about the signaling aspect, though. You can't very well pretend you didn't know you were supposed to be in a room if you had to get past a locked door to get in.
Impressive!
Super common with event venues during rehearsals and preparation (below the level of production value where there's a security desk checking IDs).
A lot of security is visual deterrent and to make legal clarity in the instance of "Did you enter the room or break the lock then enter the room?" since former doesn't imply criminal intent, the latter does.
If there were as many offline crime attemptps as there were cyber crime attempts, you would definitely see more investment in physical security.
I have been through the industry body audit, and it sucked.
We had to remove internet access for the entire staff, and give them locked down RDP instead.
That made us _very_ popular.
^ that basically. A number of large servers (ex file servers in this case, so 2x e5-2690v2 and 384 gigs of ram).
Each person uses an AD login to connect to a terminal server. We would get about ~200 to a server, assuming people didn't have too many tabs open.
If you want smooth browsing, then you'll need to limit tabs and adverts. Cgroups will help you in memory allocation per user.
much much cheaper. seemed to scale reasonably well too.
Doesn't even the relatively small amount of latency introduced over RDP make things like video/audio editing difficult and dealing with things like audio sync impossible?
Or were/are they doing something where the actual video/files/apps are on the local machine, but any outside access is via RDP only?
With those kind of stringent controls, how do you think they could have gotten in?
as for how they did it..
I only have experience with Visual effects, the post house that was "hacked" was an audio place.
They are much smaller, and have much less engineering staff to deal with this sort of thing.
If I was a hacker, I'd be targeting the FTP/aspera server, or the cinesync machine(its a way of showing what work you've done without having to move the data, like logmein, but colour correct, and with doodling features.)
Or they might have just walked in dressed as a runner and stole a bunch of drives.
there are regular audits, that test physical and software security.
the most notable being that all areas dealing with content must be on a separate air gapped network, with physical locking capable of logging.
Any business that did this would quickly discover that all their locks can be quickly bypassed by criminals.
Physical entry is easy to do but involves much more risk. Remote entry via computers is much harder but much less risky.
We are left with a minority that has watched the first four seasons but left Netflix sometime in the last year and were planning to come before season 5 but with the leak would decide to pirate it instead.
I think the reason for Netflix to release Orange is the New Black in June is to have fresh new contents space out for the year.
Seeing how Netflix pivoting into a content creator and content provider is second (gonna be distant second because of Hulu). I think the spacing/pacing between contents is a good think for them.
Hulu is own by several production companies btw so they're eating into Netflix as a content provider.
Also Amazon and HBO is adding pressure to Netflix.
It's interesting because Netflix is always on that tight path and one misstep will cost them very big.
I'm guessing that "they must also rely on" means that they outsource to non-union shops to cut expenses.
One could argue that the fact that a leak of this scope and scale hasn't happened before (OITNB is just one of possibly dozens of shows leaked) is evidence supporting that the policies and audits are working.