By using this site, you agree to our Privacy Policy and our Terms of Use. Close

Forums - Sony - Sony Pictures Hacked, Over 1 Million Accounts Stolen

Question to those defending Sony. Is it okay to store passwords in plain text?



Around the Network
Galaki said:

Question to those defending Sony. Is it okay to store passwords in plain text?

No but then it's illegal to hack your way into servers. Failings on Sony's part should not be used in an arguement to justify hacking of any sort even if that hacking reveals the failing.

 

In this whole thing, all I'm wondering is about Sony's security and what firm/software they hired in all these. Security is only as good as what you pay for and as far as I am aware Sony does not make security software or firewalls. If these people really have hacked some other Sony servers then I'm sure they've done well to outline security wholes in a network, got someone fired for it and helped a security company lose a large contract. Well done.



Hmm, pie.

Galaki said:

Question to those defending Sony. Is it okay to store passwords in plain text?

Of course it is not! I have been running a single person company for 2 years now and I know that, Sony is simply inexcusable for such errors. It's like paying in a parking lot that has no bars, cameras or security...



The Fury said:
Galaki said:

Question to those defending Sony. Is it okay to store passwords in plain text?

No but then it's illegal to hack your way into servers. Failings on Sony's part should not be used in an arguement to justify hacking of any sort even if that hacking reveals the failing.

 

In this whole thing, all I'm wondering is about Sony's security and what firm/software they hired in all these. Security is only as good as what you pay for and as far as I am aware Sony does not make security software or firewalls. If these people really have hacked some other Sony servers then I'm sure they've done well to outline security wholes in a network, got someone fired for it and helped a security company lose a large contract. Well done.

I wasn't asking about the hacking. Just the practice of keeping password in plain text.



Galaki said:

I wasn't asking about the hacking. Just the practice of keeping password in plain text.

As said then, no, it's not okay. How did we find out that they were stored in plain text?



Hmm, pie.

Around the Network
The Fury said:
Galaki said:

I wasn't asking about the hacking. Just the practice of keeping password in plain text.

As said then, no, it's not okay. How did we find out that they were stored in plain text?

If you read the news from the OP, it said not encrypted.

If you read tech news sites that post more technical stuff, such as Ars and Slashdot, they said the entire db of over 1M people are in plain text, including the passwords.

It boggles the mind.



Galaki said:
The Fury said:
Galaki said:

I wasn't asking about the hacking. Just the practice of keeping password in plain text.

As said then, no, it's not okay. How did we find out that they were stored in plain text?

If you read the news from the OP, it said not encrypted.

If you read tech news sites that post more technical stuff, such as Ars and Slashdot, they said the entire db of over 1M people are in plain text, including the passwords.

It boggles the mind.

Yes it does. I have assumptions that many companies have the same thing going on. How did these people gain this information?



Hmm, pie.

The Fury said:

Yes it does. I have assumptions that many companies have the same thing going on. How did these people gain this information?

LOL. Read the OP at least? Lulzsec released partial of the db as evidence of hack.

Right now, I just want to beat up the coder(s). LOL. Where the hell does Sony get their programmers?



Galaki said:
The Fury said:

Yes it does. I have assumptions that many companies have the same thing going on. How did these people gain this information?

LOL. Read the OP at least? Lulzsec released partial of the db as evidence of hack.

Right now, I just want to beat up the coder(s). LOL. Where the hell does Sony get their programmers?

Surely Database Administrators but then if this is just a website with mainly information on (and the details released from this illegal hack by an outside source were that of customer details for what? A mailing list?) then the people involved might only be web developers not security experts. We don't know the full story, we know one side which is that of criminals who released information about what they had done, we don't know that the database was encrypted by simple functions that the hackers got around yet claim it wasn't ever encrypted. 



Hmm, pie.

The Fury said:
Galaki said:
The Fury said:

Yes it does. I have assumptions that many companies have the same thing going on. How did these people gain this information?

LOL. Read the OP at least? Lulzsec released partial of the db as evidence of hack.

Right now, I just want to beat up the coder(s). LOL. Where the hell does Sony get their programmers?

Surely Database Administrators but then if this is just a website with mainly information on (and the details released from this illegal hack by an outside source were that of customer details for what? A mailing list?) then the people involved might only be web developers not security experts. We don't know the full story, we know one side which is that of criminals who released information about what they had done, we don't know that the database was encrypted by simple functions that the hackers got around yet claim it wasn't ever encrypted. 

That's a terrible excuse. Hackers often use smaller sites as gateways to access other resources. So at this point, Sony should have had all their properties go through a thorough security review to prevent such a situation.



Anyone can guess. It takes no effort to throw out lots of predictions and have some of them be correct. You are not and wiser or better for having your guesses be right. Even a blind man can hit the bullseye.