Sony blames 'Anonymous' for data theft
reuters.com
reuters.com
(I personally wouldn't do this, but I do consider it respectable.)
You could argue that selling the credit card numbers makes it look more criminal than "for spite", but I think you have to sell the credit card numbers in order to damage Sony.
"The attack that stole the personal data of millions of Sony customers was launched separately, while the company was distracted protecting itself against the denial-of-service campaign, Sony said."
Wow. I didn't think they could do better than "most people don't know what a rootkit is, so why should they care about it?" but I was wrong.
Sony Command: Quick! All security personnel are immediately ordered to drop what they're doing and guard against that DOS attack!
Sony Security: But Sir, won't that leave our user data "un-guarded"
Sony Command: We don't have time for that now, Soldier, now move Move MOVE!!
Uggh. First off, sorry Sony.. Who has been the victim?
Second, wrapping big fancy words to make this seem like some sort of magical act of God that no company could have with-standed is patently obnoxious. Is Sony not equally capable of careful planning, and stocked with highly professional and sophisticated criminal cyber defense professionals?
Also I can see this being used as pretext for more legal controls over the Internet.
Just about anyone could claim to be part of "Anonymous" and submit a video saying just about anything. If you can't verify something, you probably shouldn't be including it in the news.
Where is the incentive for real security? Businesses need to be directly responsible when these kind of break-ins happen. It can't be treated as if they had a physical break-in where we go looking for the thieves. It must be treated as a security failure and the company must take full responsibility. Of course, this doesn't happen, so Sony is free to blame "the hackers" and call it a day.
Meanwhile, everyone's data on PSN is compromised. Even if you think that perfect internet security is impossible, there is absolutely no excuse for not hashing passwords or encrypting credit card data.
The public needs to realize that break-ins to a physical location (which are always possible with enough firepower) are distinctly different from internet-based break-ins, which are almost always avoidable or can at least have their scope greatly limited.
If technical holes exist, it's inevitable that they'll be exploited. I blame Sony far more than the intruders.
0: I have not found information on how secure the encryption was