‘All of Sony Systems’ Allegedly Hacked by New Ransomware Group
kotaku.com
kotaku.com
Furthermore, is there any categorization of the method that was used? I am curious of the ratio: X% mix-configured cloud permissions, Y% bad defaults, Z% unpatched 9-year old vulnerability, N% most minimal social hacking, etc
Probably too much egg on everyone's face to get public post-mortems, but I would enjoy knowing more.
> It can sometimes take months or years for credentials exposed in a data breach to appear on the dark web. Breaches get added to our database as soon as they have been discovered and verified.
Edit - Depending on what you count, this appears to be number 7? https://firewalltimes.com/sony-data-breach-timeline/
*with purchase of a 2 year subscription
He didn't get fired after the first round of hacks, and he wasn't fired after the 2014 round either. I wonder where he is now?
And for the comedy factor: those hacks were dictionary password attacks against leaked usernames, and a plain text file left laying on an open network share with key credentials. Not exactly oceans' eleven.
"Your Guide To Good-Enough Compliance" (2007)
https://www.cio.com/article/272225/risk-management-your-guid...
Noncompliance is a fact of life as the list of security and privacy regulations grows. The key is knowing how to comply just enough so that you don't waste your time or bankrupt your company.
An interesting piece of info in the Time article is that Sony only had 3 people working on infosec, excluding managers.
The key detail. If Sonys not willing to pay these 6000 files are not important.
There is no doubt the hackers would take sonys money and then sell the data anyway. You will lose badly by paying them. You have to consider the breach as a total loss if you are Sony, paying up ransomware is foolish decision.
The target for these hacks is always for the company to pay, so companies not paying is a very good play.
And to make things worse, this would just signal to other hacker groups that hacking Sony is very profitable, since they apparently are happy to pay. So they would just increase the target on their back. No upside.
The business pays to unencrypt the files and achieve business as usual operations.
The business doesn't need to trust the attackers not to further share data to get their upside, though I'm sure that helps.
The ransomware groups hit lots of companies. Their reputation for holding up their side of the bargain is how they get paid. So they tend to keep their side of the deal.
The money is better spent improving security. Them spending money with hackers won't stop GDPR from ripping them new asshole either.
Wrong. The "return" is pointing a bigger target on your back because now future attackers know it is worth it to attack you.
As for the backups, the groups running ransomware are very aware of the importance of backups. Therefore they have developed best practices targeting the backup systems in a variety of ways. If the backups are online, delete them. If the backups are offline, compromise the backup server so it stops taking backups, leave that for a while, then do your attack. (You'd be shocked at how many companies don't test backups regularly...) If whole computers are backed up, insert a malware timebomb - as soon as the computer realizes the date, it destroys itself. When it is restored from backup, the backup also destroys itself.
Most companies pay too little attention to backups. And therefore highly motivated attackers regularly succeed in attacking them.
It sounds like they compromised a backwater CI/CD system or something.
https://en.wikipedia.org/wiki/Sony_BMG_copy_protection_rootk...
I forget the specifics on the service, but they tricked teenager me. I didn't realize that they intended to charge some fees
Anyway, funny they were basically giving these away and putting egregious 'DRM' all at the same time.
Malware wasn't the point. They sent off unsold stocks of old CDs, made you "buy" new releases which would count for Billboard and the such, and charged you a ton for doing it.
There was some selection for what was sent. Not just some random collection of whatever... at least entirely; I'm not sure. Maybe only the original set - doesn't matter anyway.
Case in point: https://www.washingtonpost.com/national-security/2023/08/07/...
Ok, I never got this one. What exactly is that supposed to achieve?
Probably because they tend to work on a honor system and are generally well behaved. I think the subconscious idea is "Why would people try to hack the system? It is wrong", because they wouldn't do it themselves, the threat is like an alien concept.
It works in a day-to-day life. In fact, it is a very pleasant experience and often one of the top things people say when you ask them what the like about Japan. But for IT security where the threat can come out of anywhere, it doesn't work.
I had quite a few calls with their people about the insanity of these CDs at the time.
Corporations are wild
Plenty of legitimate software used installers.
>What’s a rootkit again?
Malware that attains root and maintain it as long as possible.
Occasionally you'd get a fancy album with a music video on a data track, or something. But other than that, there was never any legitimate reason for inserting a music CD to install anything.
Also in the early days cd drives were wired up to the sound card. But I feel that went away later on with SATA drives and dvd drives. I must say I haven’t see a laptop with a disc drive that worked as you suggest.
Yes, that is what we are talking about. OP claimed that the Sony malware was "just a part of the software you installed for playing the CDs." I'm pointing out that there was no such legitimate software, and the malware was just malware.
https://en.m.wikipedia.org/wiki/Sony_BMG_copy_protection_roo...
More: this wikipedia article you're using to try to validate your claims that it wasn't a rootkit says it's a rootkit in the first paragraph. It also says the software would install itself even when the EULA was refused, while you claim the opposite.
My only question is why are you so vehemently defending Sony's actions? Do you somehow believe that it is a company's right to fuck over your devices security in an attempt at selling more licenses to infinitely-reproducible content? My guess is that you have something to gain from the public perception shifting to "actually this is fine" but i can't put my finger on what.
It was present on the CDs as its the way you very supposed to use the CDs.
>this wikipedia article you're using to try to validate your claims that it wasn't a rootkit
I was using just the image on there to show you that there was a whole software package that was included with the CD. It wasn't just DRM, but also a media player and a disc burner. Wikipedia is just copying media propagania of the subject. That's how the site works.
>It also says the software would install itself even when the EULA was refused, while you claim the opposite.
The article is confusing there because it's talking about a different DRM solution than XCP. The article is claiming a different DRM solution was doing that.
>My only question is why are you so vehemently defending Sony's actions?
I am not defending Sony. I am just not going to join in with made up outrage of malware when there was no malicious intent.
>Do you somehow believe that it is a company's right to fuck over your devices security in an attempt at selling more licenses to infinitely-reproducible content?
Insecure software with elevated priviledges is not something unique to this situation and it still is happening to this day. This is an industry wide problem. Thankfully in these times we have proper DRM that is built into silicon and the operating system so that companies don't reinvent something worse and buggy.
I'm getting the impression that you don't understand how CDs worked. You're acting like it was perfectly normal and expected for music CDs to include an installer for a CD player app. But it wasn't; essentially any computer that had a CD-ROM drive had the ability to play music CDs with no software installation needed, the same as any computer with a floppy drive had the ability to load files from disk. Yes, some CDs shipped with branded player software anyway; this was all useless advertising shovelware even when it didn't also contain harmful rootkits.
The CD bundled an audio player which is the only software which is supposed to be able to play the music.
"_A Copy of Products 2004-01-03 Final (Copy) Final.doc"