Welcome to DU! The truly grassroots left-of-center political community where regular people, not algorithms, drive the discussions and set the standards. Join the community: Create a free account Support DU (and get rid of ads!): Become a Star Member Latest Breaking News General Discussion The DU Lounge All Forums Issue Forums Culture Forums Alliance Forums Region Forums Support Forums Help & Search

Jesus Malverde

(10,274 posts)
Wed Dec 17, 2014, 10:41 PM Dec 2014

Stolen emails reveal lapses in Sony security practices

In the weeks before hackers broke into Sony Pictures Entertainment, the studio suffered significant technology outages it blamed on software flaws and incompetent technical staffers who weren't paying attention, even as hackers targeted executives to trick them into revealing their online credentials.

Its chief executive was regularly reminded in unsecure emails of his own secret passwords for his and his family's mail, banking, travel and shopping accounts, according to a review of more than 32,000 stolen corporate emails circulating on the Internet.

Scrutiny of Sony's stolen computer data hasn't yet revealed exactly how hackers managed to slip inside to steal such an enormous cache, when it happened, who was behind the theft or their motives.

But late Wednesday, a U.S. official told The Associated Press that federal investigators have now connected the Sony hack to North Korea. The official was not authorized to discuss an ongoing criminal case openly, and spoke on condition of anonymity.

http://www.utsandiego.com/news/2014/dec/17/stolen-emails-reveal-lapses-in-sony-security/

Wonder what the cheap bastards invested in their IT group. Not much is my guess.

2 replies = new reply since forum marked as read
Highlight: NoneDon't highlight anything 5 newestHighlight 5 most recent replies
Stolen emails reveal lapses in Sony security practices (Original Post) Jesus Malverde Dec 2014 OP
Is that really an IT issue? Erich Bloodaxe BSN Dec 2014 #1
When they have a folder on the central server called "passwords"... Jesus Malverde Dec 2014 #2

Erich Bloodaxe BSN

(14,733 posts)
1. Is that really an IT issue?
Thu Dec 18, 2014, 10:46 AM
Dec 2014

Or is it more a social engineering issue? Bosses generally don't want to be told even their access to sensitive info has to be limited, so they often have more access than they should, and they are going to be more careless than actual IT types.

Jesus Malverde

(10,274 posts)
2. When they have a folder on the central server called "passwords"...
Thu Dec 18, 2014, 11:14 AM
Dec 2014

Full excel documents full of passwords.

It's an IT issue.

Latest Discussions»Retired Forums»Website, DB, & Software Developers»Stolen emails reveal laps...