Sony Hacked Again: SQL injection attack against SonyMusic.gr exposes user data
nakedsecurity.sophos.com
nakedsecurity.sophos.com
Sorry to be harsh, but this is a wishful thinking.
When you've been very careless about security for years (PS3 random seed not random, music rootkit that was hackable, OMA master key leaked, PSN servers not up-to-date, PSN trusting the PS3s, etc...), you don't simply turn into a "secure" company, unless you spend years of corporate policies and formation, trying to change the habits of your employees...
Changing (or creating new) employees reflexes and habitudes isn't something easy at all, especially when you are an international company, with different cultures on board. This can be a herculean task.
I wish they will succeed, though...
The problem is getting middle management on board. It's no good if mid-level managers tell their direct reports to go to the training and then go back to business as normal with the same old priorities and no extra time/focus on the new security aspects.
Igby: To where?
D.H. Banes: Success.
Given how brilliant Sony's hardware designers have historically been, I wonder if there is something fundamental going on. Could it be that Sony is simply not good at hiring and retaining good software engineers, perhaps because the hardware engineers get all of the kudos and awards and perks? If so, Sony wouldn't be the only company that has had that problem. Before I gave up on Nokia smartphones (my last Nokia phone was the E70) I've had similar suspicions about Nokia products. I loved their hardware design, but the software didn't seem to live up to the promise of the hardware...
I guess I'm thinking that trying to diagnose the problems with their software as a corporate culture thing might be a bit misguided as Sony literally behaves like several completely separate companies running in parallel, unaware of each other. Although perhaps the quality of their software would improve if they worked together and leveraged each other's work. Seems like a stretch, though.
I'm very surprised that they did it at all. In my opinion it creates a confusing story for PSP owners looking to upgrade. NGP or PSP Phone?
Sometimes I wonder if the two teams were even aware of each other's existence.
Not to say that this is good; it’s awful for your users data to be exposed.
Right now Sony are in the unenviable position of needing to fire-fight their many security issues while the high power spotlight is on them lighting other stray bits of touch paper. Hopefully (yeah, these hope is naive in the extreme I know) Sony will take away from this the need to get security right on all levels before the first attack and subsequent media attention, and hopefully other companies are taking the situation as a wake-up call and instigating a meaningful review of their own security mind-set (or at least double checking their policies and their adherence to them if sufficient security mind-set is already in place).
Nobody can, size just makes it worse. Welcome to the reality of security.
But it would seem that Sony's general culture in that arena is significantly below what could be reasonably expected, and hopefully everyone else is now actively checking to make sure theirs isn't...