• Some users have recently had their accounts hijacked. It seems that the now defunct EVGA forums might have compromised your password there and seems many are using the same PW here. We would suggest you UPDATE YOUR PASSWORD and TURN ON 2FA for your account here to further secure it. None of the compromised accounts had 2FA turned on.
    Once you have enabled 2FA, your account will be updated soon to show a badge, letting other members know that you use 2FA to protect your account. This should be beneficial for everyone that uses FSFT.

Sony Blames "Anonymous"

HardOCP News

[H] News
Joined
Dec 31, 1969
Messages
0
Sony is now blaming Anonymous for, get this, "setting the stage" for the loss of customer's personal information and credit card data. Gee Sony, ya think?

Sony said on Wednesday that Anonymous targeted it several weeks ago using a denial of service attack in protest of Sony defending itself against a hacker in federal court in San Francisco. The attack that stole the personal data of millions of Sony customers was launched separately, while the company was distracted protecting itself against the denial of service campaign, Sony said.
 
HAHAHAHA what a great way to tell 4chan "You guys won :( We are butt-hurt thanks to you guys"
 
:rolleyes: Yes because people with the level of technical knowledge & skill needed for a hack of this scale cannot think for themselves... :rolleyes:

whatever sony...
 
Thats either one great cover-up excuse or they are just trying to pass the buck any way they can.
 
Wow. What has been up with Sony lately. Sony used to be my favorite, now not so much.
 
I'm not the world's biggest fan of Anon, but Sony's excuse is pure bullshit. They're trying to deflect fault. Shit security lead to the loss of data, not a DoS attack.
 
Allow me to translate that statement from an IT perspective.

"Because we outsourced our IT to the lowest bidder, our staff is completely incompetent and is unable to secure our network against more then 1 intrusion threat at a given time. We don't actually hire IT guys, we hire CSR's from india and have them read a script. The actual work however is done by a group of monkeys that fling poo at a large board and the CSR's do whatever the poo lands on."
 
I'm not the world's biggest fan of Anon, but Sony's excuse is pure bullshit. They're trying to deflect fault. Shit security lead to the loss of data, not a DoS attack.

Am I mistaken in that DoS is what LEADS to a lacking of security which then opens it up to more legitimate types of hack? I completely think Anonymous had a large part to play in this unless I am mistaken...
 
Am I mistaken in that DoS is what LEADS to a lacking of security which then opens it up to more legitimate types of hack? I completely think Anonymous had a large part to play in this unless I am mistaken...

It can, but the level of data loss we're seeing from Sony goes pretty far beyond anything that can be blamed on Anon completely. Sony's security had to be utterly incompetent for it to be this bad.
 
Wow. What has been up with Sony lately. Sony used to be my favorite, now not so much.

Same here. I was a HUGE Sony fan[whore] back in the day. I had a walkman, a discman, a PS1, PS2.... but as soon the the root kit scandal broke, I stopped buying their products. I decided to give them a second chance earlier this year and bought a PS3.... and look what happened.

They really need some new executive blood in house. The people currently running the show are ruining the reputation of an otherwise decent company.
 
A smart attacker does exactly what was done...make a bunch of noise over here, while in the background the real work is going on. Anonymous probably pulled both attacks, or a contingent of them did.
 
I just think its hilarious that they tried to make an example out of George Hotz, and that riled up all the wrong people, and this whole thing blew up in their face. Its totally not George's fault at all, but its gotta be a weird feeling to be "that guy" that basically started a war
 
It seems like if they weren't adequately prepared for the Denial of Service (which its clear they weren't) they may not have had all of their logging configured to easily distinguish between your run of the mill DOS traffic and more purposeful port scans/network intrusion attempts. I assume an intelligent DOS attack could also combine it with a distributed port/vulnerability scan to make it more difficult to detect or stop.

And not on this board, but I did see some people on other tech sites who were claiming that ever since Sony BMG had the rootkit issue ( which was hiding a device driver ) they were anti Sony and siding with Anonymous. Didn't make much sense since almost every Denial of Service attack makes use of botnets where people have installed far more malicious rootkits on your brother-in-law's computer.
 
Somewhere in all this a "Who's on first?" joke is just waiting in the wings...

Dude 1: Ok so who attacked Sony?
Dude 2: Some Anonymous group.
Dude 1: Right, I get that, but who was it?
Dude 2: Like I said, it was Anonymous.
Dude 1: No, I GET THAT, but who really did it?
Dude 2: ANONYMOUS.
Dude 1: Fuck it.

Or words to that effect...
 
Am I mistaken in that DoS is what LEADS to a lacking of security which then opens it up to more legitimate types of hack? I completely think Anonymous had a large part to play in this unless I am mistaken...

Can you provide proof. I suppose your going to tell us that every corporation that has been hacked was instigated by Anon. Your proving that marketing ads work, if you see and read a name long enough that's all you will remember.
 
Am I mistaken in that DoS is what LEADS to a lacking of security which then opens it up to more legitimate types of hack? I completely think Anonymous had a large part to play in this unless I am mistaken...

I just don't see how that follows. If you know you're going to be attacked,and Sony had ample warning,then your security should have been at a heightened state. Even if this was a case of misdirection,if Sony had decent security they would have planned for that possibility.
 
Sony should have learned from their ancestors:

"I fear all we have done is to awaken a sleeping giant and fill him with a terrible resolve." - (credited to) Admiral Isoroku Yamamoto

They have earned the ire of Anonymous. They are now feeling the pain of it. One must be careful not to anger the giants...
 
I blame it on Jesus. He should have done something to stop that devil worshiping Anon group from attacking that poor company and allowing all of those peoples data to be stolen. WWJD is not looking good in this matter.
 
Somewhere in all this a "Who's on first?" joke is just waiting in the wings...

Dude 1: Ok so who attacked Sony?
Dude 2: Some Anonymous group.
Dude 1: Right, I get that, but who was it?
Dude 2: Like I said, it was Anonymous.
Dude 1: No, I GET THAT, but who really did it?
Dude 2: ANONYMOUS.
Dude 1: Fuck it.

Or words to that effect...


3RD BASE!
 
I just don't see how that follows. If you know you're going to be attacked,and Sony had ample warning,then your security should have been at a heightened state. Even if this was a case of misdirection,if Sony had decent security they would have planned for that possibility.
Agree,if you read HBGary's emails they new they were being DOS attacked for days and never shut the servers down. This was a security company, now maybe this is the same bimbo outfit that sony hired.:)
 
I blame it on Jesus. He should have done something to stop that devil worshiping Anon group from attacking that poor company and allowing all of those peoples data to be stolen. WWJD is not looking good in this matter.

LOL Me likey....Methinks you might have Sony management potential!
 
Agreed with the statement.

Whether or not this applies to Sony's predicament is unknown to me as I have no idea if Sony outsources for their security needs.

Allow me to translate that statement from an IT perspective.

"Because we outsourced our IT to the lowest bidder, our staff is completely incompetent and is unable to secure our network against more then 1 intrusion threat at a given time. We don't actually hire IT guys, we hire CSR's from india and have them read a script. The actual work however is done by a group of monkeys that fling poo at a large board and the CSR's do whatever the poo lands on."
 
While I agree Sony should not be passing the buck, I am not finding fault with them. Theft happens, Data breaches happen, we can't go a week without hearing about it happening somewhere. The fact so little credit card numbers got taken is actually commendable, when you consider just how many they have. ((now the sad thing is, sony might still be bullshitting and the number is much much higher)). If your on the internet, your open to being hacked, doesn't matter what you put into place, doesn't matter how much security, logging, private networks or public, you can be hacked by someone determined enough. If people are really this grumpy over it, would you prefer they just stopped all online interaction? closed down PSN for good? get rid of x-box live?

About the only way I could possibly see to ever prevent it, would be if the system storing user information / credit card numbers was in a clean room, with no network, and someone manually typed in the information or transfered via cd / usb key new accounts / updates, then destroyed all original....
 
Agree,if you read HBGary's emails they new they were being DOS attacked for days and never shut the servers down. This was a security company, now maybe this is the same bimbo outfit that sony hired.:)

Rule one in DDOS stop troubleshooting Null route out whatever endpoints are being attacked and re-evaluate security. OR SHIT LIKE THIS WILL HAPPEN.

(I'm sure other people some where will disagree, but this is the most efficient way I know to breath in an attack.)
 
Hey Sony, blame yourself, you corporate dumb asses that spend more on lawyers and lawsuits instead of security engineers! :rolleyes:
 
While I agree Sony should not be passing the buck, I am not finding fault with them. Theft happens, Data breaches happen, we can't go a week without hearing about it happening somewhere. The fact so little credit card numbers got taken is actually commendable, when you consider just how many they have. ((now the sad thing is, sony might still be bullshitting and the number is much much higher)). If your on the internet, your open to being hacked, doesn't matter what you put into place, doesn't matter how much security, logging, private networks or public, you can be hacked by someone determined enough. If people are really this grumpy over it, would you prefer they just stopped all online interaction? closed down PSN for good? get rid of x-box live?

About the only way I could possibly see to ever prevent it, would be if the system storing user information / credit card numbers was in a clean room, with no network, and someone manually typed in the information or transfered via cd / usb key new accounts / updates, then destroyed all original....

So because it happens to other people we should excuse Sony? I'd say because it happens so often Sony should have increased their damn security so it didn't happen to them. There is NO excuse for having poor network security. Sony doesn't deserve the rabid fanbase they have defending this bullshit.
 
So because it happens to other people we should excuse Sony? I'd say because it happens so often Sony should have increased their damn security so it didn't happen to them. There is NO excuse for having poor network security. Sony doesn't deserve the rabid fanbase they have defending this bullshit.

Who says they had poor network security? point out to me where it says how exactly they managed to get hacked. The point of my post was that no matter how much security they had in place, if someone was determained enough they could of gotten in.
 
How much you want to be this ends up in court with Sony getting everything they want?
 
Who says they had poor network security? point out to me where it says how exactly they managed to get hacked. The point of my post was that no matter how much security they had in place, if someone was determained enough they could of gotten in.

Sony is in massive damage control mode trying to turn everyone's attention away from their own security. That is telling enough. Beyond that you're still trying to excuse this shit because "it happens to other companies".
 
Any company would be in massive damage control after something bad happens, That's a fact of business and why they hire PR departments. And i'm not excusing it, it shouldn't of happened, i'm not going to jump to conclusions either until I know all the facts of who did it, how they did it, and possibly why they did it. I'm not getting all up in a huff over it either because I know it does happen, hell if I got pissed at anything that got hacked/compromised and refused to use them, I wouldn't be here checking out the [H] either.
 
There is already a class action in canada, does anonymous release the credit card information to thieves so that more lawsuits start coming up?


If my card starts getting used, and i have to get another one, i'm gonna be pissed at having to drive to the bank and carry cash around for a week, and i will be suing sony in small claims for 2500 bones.
 
So Sony's message to congress is more or less this:
What we need right now is a message to the people of this country. This message must be read in every newspaper, heard on every radio, seen on every television. This message must resound through the entireinternet. I want this country to realize that we stand on the edge of oblivion. I want every man, woman, and child how close we are to chaos. I want everyone to remember why they need us.

These "anonymous" hackers hate our freedom!
 
There is already a class action in canada, does anonymous release the credit card information to thieves so that more lawsuits start coming up?


If my card starts getting used, and i have to get another one, i'm gonna be pissed at having to drive to the bank and carry cash around for a week, and i will be suing sony in small claims for 2500 bones.

Anon is denying involvement in the hacking. Its not really their MO. They'd rather take down the network and Sony's networks than steal information.
 
So liek, I can sue [H]ardOCP for distracting me from doing my job? (wait, does Steve actually get paid???)
 
The larger point everyone seems to be missing.

Sony gets caught Red handed with root kit, doesn't learn continues to screw consumer.

Then screws the little guy "george" or multiple little people "ps3 users" in court, b/c they don't put enough efforts into their PS3.

Here is Sony's thinking... Shat! We can just sue people that use what they purchased from us in a method it wasn't intended. Instead of spending time and moeny to make the PS3 Hack proof...
Sony Engineer/Programmer: "Guys it's going to take XXX million to secure the platform..."
Sony Lawyer: "Guys this could be a money win through the court system and law suits as opposed to a money loss in development time."
Sony CEO: "O.K. I like that plan better!!! Lets sue everyone."

It's the equivalent of buying a car from GM, then for whatever reason folding down the seats and deciding to sleep in that car on a road trip, perhaps post a few pictures on the web of your trip and how the sleeping bag fit.

Then GM turning in a joint lawsuit with Holiday inn. They sue you for future lost revenue since you didn't need a hotel. Also yank your title so you cant insure it due to modifiy your car for unintended use, make you have to buy another one. Would the cort side with you or GM???...

... Court sided with Sony, Anon doesn't...

So the question isn't so much the breach in security; but the overall actions of Sony towards consumers. Will Sony learn that if they quit acting the way they do they will quit being attacked?
 
Back
Top