Slashdot Mirror


Amazon Servers Used In Sony Playstation Hack

the simurgh writes "Amazon servers may have been used to carry out the massive Playstation hack that compromised the personal information of more than 100 million Playstation Network users. According to a report from Bloomberg, sources close to the ongoing investigation say the attack was mounted from Amazon Web Service's cloud computing platform."

95 of 135 comments (clear)

  1. It's a conspiracy. by Anonymous Coward · · Score: 1

    Obviously. Who is better equipped to take down Sony than the elusive Amazon?

  2. A cloud attacks another by mehrotra.akash · · Score: 3, Funny

    Will there be a thunderstorm?

    1. Re:A cloud attacks another by Gaelinda · · Score: 1

      This gives a whole meaning to the slogan "To the cloud"!

    2. Re:A cloud attacks another by the_humeister · · Score: 1

      So Amazon brought down Sony, but their banning yaori. Are they good or evil???

    3. Re:A cloud attacks another by somersault · · Score: 3, Insightful

      You mean it actually had a meaning before?

      --
      which is totally what she said
    4. Re:A cloud attacks another by Anonymous Coward · · Score: 1

      yaoi*

      Lern to spellz teh enrgish

    5. Re:A cloud attacks another by lostthoughts54 · · Score: 1

      Lern to spellz teh enrgish

      Yaoi is a Japanese word. If u are going to be a douche, the least you could do is be right.

      Nihongo superu o manabu. there fixed.

    6. Re:A cloud attacks another by Killall+-9+Bash · · Score: 1

      Part of a meaning, apparently.

      --
      "Prediction: within 10 years, Windows will be a Linux distribution." Me, 7-6-2016
    7. Re:A cloud attacks another by cyber-vandal · · Score: 1

      Those adverts are so fucking patronizing - I want to kill everyone involved in making them.

    8. Re:A cloud attacks another by pandrijeczko · · Score: 1

      Sony and "Yaoi" - a pair of crappy Japanese comics.

      --
      Gentoo Linux - another day, another USE flag.
    9. Re:A cloud attacks another by vegiVamp · · Score: 1

      > yaori

      Mmm, Maori yaoi.

      --
      What a depressingly stupid machine.
    10. Re:A cloud attacks another by d.the.duck · · Score: 1

      If you need any help, let me know.

      --
      Where does the signature go?
  3. So it came from an Anonymous Cloud? by toygeek · · Score: 4, Funny

    Is it an Anonymous Cloud or Anonymous' Cloud?

    So if the attack came from a cloud, then wouldn't it be a lightning attack instead of a "hacking" attack?

    We really need to get this internet meteorology right.

    1. Re:So it came from an Anonymous Cloud? by Anonymous Coward · · Score: 1, Informative

      I simply do not like those rules in your link. The English that I learned says that toygeek did it right. Word's ending in "s" should not get the "'s" after them, the apostrophe is sufficient.

    2. Re:So it came from an Anonymous Cloud? by larry+bagina · · Score: 1

      Not liking something doesn't make it wrong. Learning something doesn't make it right.

      --
      Do you even lift?

      These aren't the 'roids you're looking for.

    3. Re:So it came from an Anonymous Cloud? by AvitarX · · Score: 2

      Too bad English is a living language.

      Though in general things lean the way you've said it, there is definitely space to do it either way with a "polysyllabic word ending in a sibilant" (generally based on intention of how it is to be said).

      And "some contemporary writers omit the extra s in all cases"

      http://en.wikipedia.org/wiki/Apostrophe#Standardisation

      I don't see the issue with the "new" way of adding an apostrophe only for words ending in "s" and an "'s" for words that don't, and in 15 years, I bet that's how it goes.

      --
      Wow, sent an e-mail as suggested when clicking on "use classic" banner, and got a fast response that addressed my msg
    4. Re:So it came from an Anonymous Cloud? by Vectronic · · Score: 1

      An anonymou is the singular of anonymii. "that anonymou really stands out from the rest of the anonymii", and anonymous is a pejorative, like emos. "being unidentifiable is a characteristic of anonymous's"

      now you know.

    5. Re:So it came from an Anonymous Cloud? by lostthoughts54 · · Score: 1

      Too bad English is a living language.

      \

      living language= a language so butchered it has no true rules, making it illogical and inefficient.
      Even at 7 i knew there was a issue with having to learn, "For every rule there is a rule breaker."
      English would be much better if people just followed rules. Exceptions only when absolutely necessary. But instead we make rules then break them at our leisure and as long as others like the rule breaker, it is now considered correct. It due to this stupid mentality that i still have difficulty with the English language(my native language, even if i grew up in the Southeast U.S.) , but i had absolutely no problems in Spanish or Japanese(Japanese, i just started learning).

      and in 15 years, I bet that's how it goes.

      in 15 years u will need this. http://en.wikipedia.org/wiki/Mandarin_Chinese

    6. Re:So it came from an Anonymous Cloud? by Bing+Tsher+E · · Score: 1

      Please don't harp on other people about the way they butcher language, and then use 'u' as a word. This isn't your little chatspeak den here.

    7. Re:So it came from an Anonymous Cloud? by PCM2 · · Score: 1

      The English that I learned says that toygeek did it right. Word's ending in "s" should not get the "'s" after them, the apostrophe is sufficient.

      I do not think you learned the rule completely. Look carefully at what Strunk & White says in the linked text: "Form the possessive singular of nouns with 's." Words that end with S that are not singular still just take the apostrophe, as you say. So it would be "the witch's cauldron," but in the case of Shakespeare's MacBeth, it would be "the witches' cauldron." For singular words, though, adding the apostrophe-S is generally preferred, because it helps avoid ambiguity. If you think about it, though, this almost never applies to anything but proper names. There really aren't many (any?) words in the English language that end in S but have the same form whether they are plural or singular. Most add -es to make them plural, in which case they just take the apostrophe.

      --
      Breakfast served all day!
    8. Re:So it came from an Anonymous Cloud? by mug+funky · · Score: 1

      i think it's terribly efficient actually. if a little hodge-podge.

      i love the fact that one can say something and completely fuck the grammar out of it, and yet still be understood.

      redundancy is actually quite important in a language, especially when the phonics we've inherited from the Romans can have such similar sounds.

      try distinguish between "n" and "m" over the phone. you can't.

    9. Re:So it came from an Anonymous Cloud? by SheeEttin · · Score: 1

      We really need to get this internet meteorology right.

      Well, if I ever get into the The Cloud business, I know what to put on my business cards...

    10. Re:So it came from an Anonymous Cloud? by Kalriath · · Score: 1

      And who did i correct? i dont think i even mentioned any specific rules or violations of said rules. I said the language is completely fubared. Did my use of "u" in place of "You" throw your comprehension off? I commented on the english language and the adaptive include whats popular way of evolving

      Parse Error.

      --
      For a site about things like basic rights, Slashdot users sure do like to censor "dissent".
    11. Re:So it came from an Anonymous Cloud? by AvitarX · · Score: 1

      Well, I had one teacher recommend it, but you're right.

      I expect it to be divided like the oxford comma.

      It's definitely moving towards the simple rule in think though.

      --
      Wow, sent an e-mail as suggested when clicking on "use classic" banner, and got a fast response that addressed my msg
  4. Liability by Sprouticus · · Score: 1

    It will be interesting to see what sony does with this if it is true. I mean, it is not like they care about burning bridges. I could totally see them suing Amazon, if only to give them a PR black eye.

    1. Re:Liability by houstonbofh · · Score: 1

      It will be interesting to see what sony does with this if it is true. I mean, it is not like they care about burning bridges. I could totally see them suing Amazon, if only to give them a PR black eye.

      Your post was not totally clear. Is the intent to give Amazon a PR Black Eye, or to freshen up the Sony PR Black Eye? I think Amazon would actually end up with a PR win if they handled it right.

    2. Re:Liability by jhoegl · · Score: 1

      I dont know that this kind of law suit would go anywhere anyways. Amazon provides a service, much like ISPs provide service. If you sue one, you would have to sue all.
      However, if Sony were smart, they would put pressure on Congress to require companies to gain stronger knowledge about those they lease server space to.

    3. Re:Liability by MaxBooger · · Score: 1

      Amazon does a lively business selling Playstation 3 consoles and games. I doubt Sony will want to bite one of the hands that feeds it.

  5. In other news.. by Anonymous Coward · · Score: 1

    Thieves were recently caught shoplifting. They wearing clothes from Gap, calling into question the influence and security of such clothing.

    Yes, the story makes about as much sense as that...

    1. Re:In other news.. by mehrotra.akash · · Score: 1

      More like using a pepper spray (meant for self defence) to steal stuff from others

    2. Re:In other news.. by moonbender · · Score: 1

      Not a very good analogy. This is more like (car analogy time) hiring a tow car for a vehicle you don't own as a way of stealing it. The tow car driver facilitates the crime without being aware that they are doing anything illicit.

      --
      Switch back to Slashdot's D1 system.
    3. Re:In other news.. by hoytak · · Score: 1

      Rather, it's like they were using Amazon Fresh when they suddenly learned this: http://www.smbc-comics.com/index.php?db=comics&id=876#comic

      --
      Does having a witty signature really indicate normality?
    4. Re:In other news.. by zarzu · · Score: 1

      Not really. It would be more like a tow car rental company. Amazon only provides the basic hardware, they were used as anonymizer, just like a rental would if you provide fake information (which was done in this case).

  6. I don't see it... by Junta · · Score: 2

    I suspect most all of the people that are amazon customers only vaguely know what's going on and won't bother to learn the detail on the hosting provider for the attackers systems.

    I suspect the minority that are that inclined almost all know that in this specific scenario, Amazon was just a hosting provider and understand that means they aren't particularly responsible for what happened any more than AT&T would be responsible for a house downloading a video illegally.

    Sure, there is probably a very small population that will stumble upon the facts and falsely presume Amazon is an evil company for cracking into Sony's stuff (as opposed to an evil company for other reasons). I have a feeling that change in revenue would be lost in the noise and small compared to any arbitrary boycott over seemingly small and/or inane things Amazon does on any given day.

    --
    XML is like violence. If it doesn't solve the problem, use more.
    1. Re:I don't see it... by the_humeister · · Score: 1

      Or maybe they'll like the fact that they were utilized in attacking Sony.

    2. Re:I don't see it... by Pseudonym+Authority · · Score: 1
      That is so stupid. There is no way I would bother with a provider that I had to talk to. Also, my rebuttal is in your comment.

      calling them on the phone and verifying the signup information, much less fraud would be possible as it eliminates the anonymity. The banks have no problems doing this

      And just how much bank fraud does that stop exactly? HINT: NONE.

      Online games are often an used for money laundering, by putting all the ill gotten money into the

      OH YAH, I can just imagine some hard looking mafia types trading gold on Runescape, with the FBI monitoring them and hiding as a noob while waiting for the transaction to complete. How totally ridiculous.

      The online service pays for it, and if they are too cheap to afford it, they shouldn't be in business.

      Fascism! Socialism! Unamerican! But really, that is just a way to further consolidate power and money for the large corporation, which it is quite clear that you are just shilling for, you asshat fucktard apologist.

    3. Re:I don't see it... by Anonymous Coward · · Score: 3, Insightful

      They cannot legally monitor for abuse... Or they can then get sued for "not finding abuse fast enough" and shit like that.

      It is the same reason why no shared or VPS hosting company says they actively monitor your usage / files. This is a form of liability control for them. The second they start taking responsibility for "catching pirates, hackers, crackers, and pedophiles" is the second they can then be named in a lawsuit and sued.

    4. Re:I don't see it... by turbidostato · · Score: 1

      "Competent hosting companies monitor for this abuse. Amazon doesn't, and turns a blind eye towards it"

      Just like competent gun makers will monitor for gun abuses? Is this the "Colt should pay for murderings produced using its weapons" argument?

    5. Re:I don't see it... by grcumb · · Score: 1

      Just like competent gun makers will monitor for gun abuses? Is this the "Colt should pay for murderings produced using its weapons" argument?

      If Colt were renting out the firearms by the hour and selling ammunition by the crate, then yes, you could reasonably expect them to monitor who is using them and for what stated purpose.

      --
      Crumb's Corollary: Never bring a knife to a bun fight.
    6. Re:I don't see it... by ipwndk · · Score: 1

      The banks in Denmark certainly doesn't require you to identify yourself over the phone, or physically. I created an account yesterday in five minutes flat.

      Of course they use a digital signature that is linked to my citizen ID that all the Danish banks made together in collaboration to remove that very check you are describing.

      This can however be exploited as well as you describe :S Problem here is that it's my citizen ID. It's not just money then. They can change my name, my taxes, healthcare services and anything else that is between me and the state. Ack, I began the comment to say that we're far more advanced, but the pitfall with a totally digitalized citizenship is that our identify is at stake :|

      --
      01 REDEFINE REALITY.
    7. Re:I don't see it... by Rakishi · · Score: 1

      So Hertz has to have a guy sitting in every car that people rent to prevent someone from using the rented car to commit a crime?

    8. Re:I don't see it... by dakameleon · · Score: 1

      Online games are often an used for money laundering, by putting all the ill gotten money into the

      OH YAH, I can just imagine some hard looking mafia types trading gold on Runescape, with the FBI monitoring them and hiding as a noob while waiting for the transaction to complete. How totally ridiculous.

      Actually, that's not as utterly ridiculous as you make it out to be: http://www.policeone.com/police-technology/articles/3115040-Online-games-are-new-choice-for-money-laundering/

      --
      Man who leaps off cliff jumps to conclusion.
    9. Re:I don't see it... by datapharmer · · Score: 3, Insightful

      Seriously. I've grown tired of reporting abuse to amazon, whose policy is to "send the complaint on to the customer". I now just block their IP ranges. Unfortunate for anyone who legitimately wants to crawl my sites using their service, but if enough people block them they will start seeing customers head elsewhere. Blocking about a half dozen abusive ISPs has cut my attack logs down exponentially, so failure to regulate your service = banned appears to be an acceptable policy in many cases.

      --
      Get a web developer
    10. Re:I don't see it... by TooMuchToDo · · Score: 1

      If you abuse a gun, there isn't much that can be done. You cause problems for others on the Internet? That's a fast way to get NANOG on your back and have your IP blocks and AS numbers blackholed at a variety of large networks (transit, peering fabrics, etc).

    11. Re:I don't see it... by dkf · · Score: 1

      If every company stepped out of this mindset and had a "human" verify every signup, eg calling them on the phone and verifying the signup information, much less fraud would be possible as it eliminates the anonymity.

      You've got a lovely trust in the ability of people to spot liars over the phone there. And in the general Power of Bureaucracy to Do Good.

      How many people are you going to employ doing this? How are you going to pay for them? (Hint: the cost of getting signups verified would be passed on to you.) And it wouldn't stop fraud, just give a bigger opportunity for bribery and corruption. Automated systems, for all their faults, are at least honest and fair in a limited sense (because it is hugely easier to write them that way). All your suggestion would do is cripple large parts of the market to no great benefit of anyone. And yes, you can see evidence of this sort of thing with excessive regulation in large parts of the world.

      --
      "Little does he know, but there is no 'I' in 'Idiot'!"
    12. Re:I don't see it... by turbidostato · · Score: 1

      "No, it's the "a gun-range should monitor the weapons it gives out, and how all weapons on the grounds are used - or be liable for any killing/injuries incurred on it's land or with it's property" argument."

      So a cab driver is responsible if he happens to drive an assassin to his victim. Quite understandable.

  7. really? by cratermoon · · Score: 4, Interesting

    Considering how Amazon has become known for caving to the slightest pressure from law enforcement or even just a nosy senator, to host such an attack from EC2 seems extraordinarily stupid.

    It would make much more sense to launch it from somewhere hosted by a company that doesn't have a reputation for giving up their customer's data and shutting down even legitimate stuff that happens to run afoul of their vague guidelines.

    1. Re:really? by VortexCortex · · Score: 1

      Considering how Amazon has become known for caving to the slightest pressure from law enforcement or even just a nosy senator, to host such an attack from EC2 seems extraordinarily stupid.

      It would make much more sense to launch it from somewhere hosted by a company that doesn't have a reputation for giving up their customer's data and shutting down even legitimate stuff that happens to run afoul of their vague guidelines.

      ?? Huh?

      If you're in the business of stealing credentials, why not use some of the Amazon services those credentials allow you to access in order to get even more credentials?

      As a benefit this also allows moronic assumpteers to take a distracting trip down "IP + Credentials == People" or "Shoot the Messenger" lane. If UPS delivers you a bomb or an envelope full of anthrax, it's not UPS's fault -- It's the malcontent that sent the package (Well, it's partially your fault too for accepting mail from a company who's name is "Oops!"). Of course the return address is a fake, unless, you assume the identity thieves are careless with their own identities...

    2. Re:really? by Hardhead_7 · · Score: 5, Insightful

      Considering how Amazon has become known for caving to the slightest pressure from law enforcement or even just a nosy senator, to host such an attack from EC2 seems extraordinarily stupid.

      It would make much more sense to launch it from somewhere hosted by a company that doesn't have a reputation for giving up their customer's data and shutting down even legitimate stuff that happens to run afoul of their vague guidelines.

      Nah, once you do something on the scale of the PSN hack, it doesn't matter if the service provider caves too easily or not, because everyone gives up information when they get served a warrant. And there will be warrants. They just had to make sure Amazon has no way to trace it back to them, and it seems very unlikely the perpetrators accessed Amazon's servers from anything other than a laptop bought at a yard sale with a fake MAC address on a public wi-fi hotspot.

      And the cloud services were paid for with a Visa gift card that was bought with cash.

    3. Re:really? by DrXym · · Score: 2

      Nah, once you do something on the scale of the PSN hack, it doesn't matter if the service provider caves too easily or not, because everyone gives up information when they get served a warrant. And there will be warrants. They just had to make sure Amazon has no way to trace it back to them, and it seems very unlikely the perpetrators accessed Amazon's servers from anything other than a laptop bought at a yard sale with a fake MAC address on a public wi-fi hotspot.

      You'd like to think so but hackers can do stupid things, or fail to cover their tracks sufficiently, e.g. can't wipe logs. It's also possible that if anonymous were responsibles that internal ructions over the attack could lead to the person being identified via an informant which in turn leads to a raid which in turn leads to information being found that way.

    4. Re:really? by drolli · · Score: 2

      Why? If you stole the credit card numbers before to buy the computation time, its not a big deal it they later fine the virtual machine afterwards. I would obviously only use the EC2 to collect and encrypt the data, but obviously not process it. If you need a lot of bandwidth to handle the incoming data, but you can afford a few days to transfer them out.

    5. Re:really? by colinrichardday · · Score: 1

      And the cloud services were paid for with a Visa gift card that was bought with cash.

      The last time I purchased a Visa gift card with cash, I had to show ID.

    6. Re:really? by Anonymous Coward · · Score: 1

      Which wasn't yours. So, there.

    7. Re:really? by colinrichardday · · Score: 1

      This occurred at a Safeway.

    8. Re:really? by SomePgmr · · Score: 1

      Considering how Amazon has become known for caving to the slightest pressure from law enforcement or even just a nosy senator [talkingpointsmemo.com], to host such an attack from EC2 seems extraordinarily stupid.

      You're probably right, but I had to laugh that just a few posts up someone was complaining that they're not trigger-happy enough. Maybe they really have found a middle-ground.

      It would make much more sense to launch it from somewhere hosted by a company that doesn't have a reputation for giving up their customer's data and shutting down even legitimate stuff that happens to run afoul of their vague guidelines.

      I expect the doer[s] knew the hack would be done-and-over by the time anyone was issuing shut-downs. I'd guess the way to find them now has everything to do with the stolen data. Where it went, where it's being sold or used, etc.

    9. Re:really? by Syberz · · Score: 1

      If CSI taught me anything, it's that there's a traffic camera picture of the person having purchased the VISA gift card that the authorities will use to run a visual basic interface on it to cross-check with their "everyone on the planet" database.

      --
      ~Syberz
    10. Re:really? by cratermoon · · Score: 1

      Good analysis of how they would probably foil the backtrace. As far as caving when there are warrants, I was thinking of a hosting company off in a small island country that doesn't put a lot of effort into complying with international law enforcement efforts. I don't know of such places, but I'm sure they must exist.

  8. DANGER! Corny alert by xeroedouttwice · · Score: 1

    Looks like the "cloud" rained on PS3 network's parade, so to speak. Hyuk-Hyuk-Hyuk!!! (Imitates Goofy Disney character)

  9. Was the cloud hacked too? by Anonymous Coward · · Score: 4, Interesting

    Wait a minute... Amazon's cloud crashed 4/21, the day after Sony realized they'd been pwned and took down PSN.

    Is there something Amazon isn't saying, like maybe they were pwned too??

    1. Re:Was the cloud hacked too? by ColdWetDog · · Score: 5, Funny

      Wait a minute... Amazon's cloud crashed 4/21, the day after Sony realized they'd been pwned and took down PSN.

      Is there something Amazon isn't saying, like maybe they were pwned too??

      And it was the day after 4/20 - therefore it had something to do with stoners.

      George Bush didn't support legalization of marijuana.

      Goddamnit. It's GEORGE BUSH'S FAULT!

      --
      Faster! Faster! Faster would be better!
    2. Re:Was the cloud hacked too? by maxwell+demon · · Score: 1

      Or maybe Sony fought back? :-)

      --
      The Tao of math: The numbers you can count are not the real numbers.
    3. Re:Was the cloud hacked too? by wmbetts · · Score: 1

      Finally someone with some sense and logic posting on this story. I wish more people realized it was all his fault.

      --
      "Ubuntu" -- an African word, meaning "Slackware is too hard for me". - stolen from Dan C alt.os.linux.slackware
    4. Re:Was the cloud hacked too? by ColdWetDog · · Score: 1

      Everything is George Bush's fault. Well, except for a few things that are Ronald Regan's fault....

      --
      Faster! Faster! Faster would be better!
    5. Re:Was the cloud hacked too? by ColdWetDog · · Score: 1

      Ronald Regan is George Bush's fault!

      Temporally, I'd be a little happier if it were the other way around. If Ronald Regan is George Bush's fault we have a problem in the Time Tunnel.

      --
      Faster! Faster! Faster would be better!
  10. sources close to the investigation by doperative · · Score: 1

    > sources close to the ongoing investigation say the attack was mounted from Amazon Web Service's cloud computing platform ..

    What evidence is there that Amazon Cloud was the source and why the need to keep the source of these allegations anonymous.

    Web Services cloud- computing unit was used by hackers in last month’s attack against Sony Corp. (6758)’s online entertainment systems, according to a person with knowledge of the matter

    I see, asome 'person'

    1. Re:sources close to the investigation by Platinum+Dragon · · Score: 2

      In other words, about as much evidence as other claims that Anonymous, PS3 hackers, or Osama bin Laden were involved.

      Hey, gotta fill that news cycle. Gotta draw eyeballs for advertisers. Content is just a vehicle for making money. Truth is incidental, and at this point often accidental.

      --

      Someday, you're going to die. Get over it.
    2. Re:sources close to the investigation by eulernet · · Score: 2

      TFA is totally bullshit.

      I think that the hackers used a few open L1 proxies on Amazon AWS.

      In my list of open proxies, there are around 20 proxies on Amazon AWS, of the form
      ec2-??-??-??-???.us-west-1.compute.amazonaws.com:80
      ec2-??-??-??-??.ap-southeast-1.compute.amazonaws.com:80
      ec2-??-??-??-??.compute-1.amazonaws.com:80
      ec2-??-??-??-??.eu-west-1.compute.amazonaws.com:80
      where ??-??-??-?? is an IP address.

    3. Re:sources close to the investigation by Giant+Ape+Skeleton · · Score: 1

      TFA is totally bullshit.

      I think that the hackers used a few open L1 proxies on Amazon AWS.

      In my list of open proxies, there are around 20 proxies on Amazon AWS, of the form ec2-??-??-??-???.us-west-1.compute.amazonaws.com:80 ec2-??-??-??-??.ap-southeast-1.compute.amazonaws.com:80 ec2-??-??-??-??.compute-1.amazonaws.com:80 ec2-??-??-??-??.eu-west-1.compute.amazonaws.com:80 where ??-??-??-?? is an IP address.

      ...so in order to find the perpetrators, we simply need to determine which seven of those proxies were used in the attack!

      --
      The difference between stupidity and genius is that genius has its limits.
  11. Re:Amazon PR Disaster by Charliemopps · · Score: 1

    I think you underestimate the revenue growth "The Cloud" generates for it's vendors.
    I also think you over estimate how many people will ever even hear that Amazon was involved, much less care about it.

  12. Re:Amazon PR Disaster by fuzzyfuzzyfungus · · Score: 1

    Hey, not every VPS service has the advanced management APIs that make operating 7 proxies on demand hassle free...

  13. Is This Supposed To Be News? by RoFLKOPTr · · Score: 2

    So the hackers chose to bounce their packets off a server rented from Amazon. They could have chosen a server rented from a thousand others. Hell, they could have done it with a server rented from me. Thankfully, they did not. But really who the hell cares?

    1. Re:Is This Supposed To Be News? by Captain+Spam · · Score: 1

      Just wait for this upcoming week's headlines...

      "Logitech Mice Used In Sony Playstation Hack"
      "64-Bit Processors Used In Sony Playstation Hack"
      "Store-Brand Clothing Used In Sony Playstation Hack"
      "Mountain Dew Used In Sony Playstation Hack"

      --
      Demanding constant attention will only lead to attention.
    2. Re:Is This Supposed To Be News? by RoFLKOPTr · · Score: 2

      Just wait for this upcoming week's headlines...

      "Logitech Mice Used In Sony Playstation Hack" "64-Bit Processors Used In Sony Playstation Hack" "Store-Brand Clothing Used In Sony Playstation Hack" "Mountain Dew Used In Sony Playstation Hack"

      "Sony VAIO Used In Sony Playstation Hack"

    3. Re:Is This Supposed To Be News? by nickb64 · · Score: 1

      maybe MY stolen VAIO was used in the attack.

      It was stolen randomly less than a week before PSN went down, coincidence, I think not.

      /puts on tin foil hat

    4. Re:Is This Supposed To Be News? by pandrijeczko · · Score: 1

      It's just so the PS3 fanbois can feel a bit more comfortable renting their rectums back to Sony & paying for the privilege when the PSN comes back online because it will all have been Amazon's fault, not Sony's.

      --
      Gentoo Linux - another day, another USE flag.
    5. Re:Is This Supposed To Be News? by lev400 · · Score: 1

      Agreed. What does it matter what servers they used to attack from? Normaly attacks are done from zombie PC's or hacked web serers but guess they wanted a good connection to PSN etc. Also title is mis-leading. It should read "Servers Rented from Amazon Used In Sony Playstation Hack".

  14. "Hosted by" Amazon? by identity0 · · Score: 4, Funny

    An attack from Anonymous? Pshaw, yeah right.

    We all know Amazon really did the hack themselves, because they were mad they couldn't get Sony on the One-Click patent, since PS3 users don't use mice.

    1. Re:"Hosted by" Amazon? by AmiMoJo · · Score: 1

      More like the loss of £80 per PS3 when they gave out refunds to people over the removal of OtherOS.

      Seriously though I doubt there is any love lost between Amazon and Sony.

      --
      const int one = 65536; (Silvermoon, Texture.cs)
      SJW, n: "Someone I don't like, and by the way I'm a fuckwit" - AC
  15. Outpriced by Amazon? by malacandrian · · Score: 2

    Presumably, they chose Amazon's network as they were cheaper than renting time on a botnet. I'm intruiged as to the ramifications on the distributed computing black market as it were, whether it will force their prices down in this age of cheap computing (especially as none of the resources used are theirs per say) or they'll raise them as a charge for the anonymity Amazon and Google would never provide.

  16. Good by JockTroll · · Score: 1, Offtopic

    Would be cool to see Sony and Amazon sue the hell out of each other. A bit like two rapists/murderers buttfucking and then disemboweling each other. Unfortunately such huge corporations always reach some sort of agreement in these cases - smart thieves don't steal from each other. A shame, because watching them fighting it out, maybe sending their security teams to do battle in their rival's offices, while we laugh on the faces of grieving widows and throw dog feces at weeping orphans would be AWESOME.

    --
    Geeks are so full of shit that "beating the crap out of them" takes a whole new meaning.
  17. Re:used != may have been used by easyTree · · Score: 1

    Is it that hard to write a headline that isn't sensationalist?

    The question is, why would you want to?

  18. Re:Amazon PR Disaster by maxwell+demon · · Score: 1

    Revenue from cloud services: 1.5%

    Retail revenue lost from consumers who will forever link one of the greatest breaches in history with the Amazon brand: Priceless

    You mean, just like the customers are fleeing the Windows platform in droves?

    --
    The Tao of math: The numbers you can count are not the real numbers.
  19. Amazon Prime Members? by tgeek · · Score: 4, Funny

    Shame the hackers weren't Amazon Prime members - then they could have had everything they wanted in 2 days at no extra charge.

    1. Re:Amazon Prime Members? by ajo_arctus · · Score: 1

      They probably are Amazon Prime members now. You'll see the $79 fee appear on your next CC bill*

      * assuming you own a PS3

  20. a third way by OrangeTide · · Score: 1

    stealing a few AWS accounts is cheaper than either of the options you mentioned.

    --
    “Common sense is not so common.” — Voltaire
  21. lightning attack by nurb432 · · Score: 1

    we called that blitzkrieg in wwii

    --
    ---- Booth was a patriot ----
  22. Big Business Security by lordkamon · · Score: 1

    If a large corporation's site like the Sony site could be so easily compromised, how are we supposed to guage the level of security of any other site? Another question, if the security of Sony was compromised by using Amazon in some way, doesn't that mean that those who use Amazon are potentially at just as much risk as those who were compromised at Sony? So let's say nono it's a completely different thing, how can you 100% guarantee that? On a more constructive note, how do we eliminate this kind of access in future? My suggestion.... eliminate anonymous internet access permanently.

    1. Re:Big Business Security by V!NCENT · · Score: 1

      "If a large corporation's site like the Sony site could be so easily compromised, how are we supposed to guage the level of security of any other site?"
      You can't.

      "Another question, if the security of Sony was compromised by using Amazon in some way, doesn't that mean that those who use Amazon are potentially at just as much risk as those who were compromised at Sony?"
      No? Amazon has nothing to do with this. They just let you rent a PC.

      " So let's say nono it's a completely different thing, how can you 100% guarantee that?"
      Because there is absolutely no relationship between Amazon security and Sony's secutiry.

      "On a more constructive note, how do we eliminate this kind of access in future?"
      Stop being a moron and not hand over information you do not like to get stolen. Do you also not lock your door on your way out? Prevention is what it is called.

      "My suggestion.... eliminate anonymous internet access permanently."
      Let's see how that works below:

      Jack: "Hi, my name is John"
      Computer: "Are you?"
      Jack: "Yes I am. I am using John's WiFi to connect to you, computer"
      Computer: "Well OK then, John. Do what you like"
      [Two months later]
      *Knock-Knock*
      John: "Who's there?"
      "NYPD! Open the door!"
      [one month later]
      Investigator: "Confess now and you'll get your food. We know it's you who did it!"
      John: "OK OK I confess, just let me eat"
      Court: "John you admitted you're guilty, therefor you will not pass GO and go directly to jail'

      Jack is now enjoying his vacation on some exotic resort.

      --
      Here be signatures
    2. Re:Big Business Security by V!NCENT · · Score: 1

      OK, I'm sorry. Strong emotions come out easyer on the internet.

      By reading Slahdot you are expected to know what has been going around lately with respect to law enforcement and political engineering. By destroying things like Wikileaks due to destruction of anonimity and then piling upon that not being knowledgeable on the subject kind of makes me very mad. Especialy because the politicians that have enforced many shit upon society were not knowledgeable at all.

      We can start this discussion again in a civilized manner if you are still open for it ;-)

      --
      Here be signatures
  23. Hosted BackTrack OS by elephantsaroundhere · · Score: 1

    In the future the attackers may want to go straight to this new hosting provider : http://www.hostedbacktrack.com/ All the required tools are already installed as they are planning on offering hosted BackTrack Operating Systems.

  24. How legitimate companies sign up by nacturation · · Score: 1

    The hackers didn’t break into the Amazon servers, the person said. Rather, they signed up for the service just as a legitimate company would, using fake information.

    And to think that by providing accurate information, I've been doing things wrong all this time.

    --
    Want to improve your Karma? Instead of "Post Anonymously", try the "Post Humously" option.
  25. They obviously didn't use S3 then! by mysqlbytes · · Score: 1

    Because the hack, and Amazons S3 outage occured at about the same time!

  26. Lieberman and PNAC, Version 2.0 by sgt_doom · · Score: 1
    Nosy senator? Did you mean Joey Lieberman, a member of that ultra-neocon Foundation in Defense of Democracies (whose, one wonders???), PNAC version 2.0?

    Recently, they have financed a pile of drivel, in support of the Cheney-Rumsfeld conspiracy theory on 9/11, and attacking all those critics who know stuff like math, science, engineering, aviation and are retired intelligence professionals and military professionals, as well as former heads of state (i.e., really "flaky" guys as opposed to goatherds like Cheney and Rumsfeld, no doubt?).

    Yup, sure wouldn't ever want anyone to investigate the backgrounds of those 64 passengers aboard the four commericial airliners involved that day.

    After all, in homicide cases, it is always routine to investigate the background of the victim or victims, as in the majority of cases the murderer knows their victims. And on 9/11/01, the certain group of victims were those passengers with ahead-of-time reservations that day!

  27. Re:Amazon PR Disaster by mug+funky · · Score: 1

    That's like saying it's Microsoft's fault that someone used a Windows computer to write a virus.

    can we leave Apple fanboys out of this, just this once? this doesn't involve them.

  28. Re:So The Cloud(TM) is useful after all... by d.the.duck · · Score: 1

    I think the hackers would disagree. I think they found it eminently useful.

    --
    Where does the signature go?