Slashdot Mirror


Sony Music Greece Falls To Hackers

xsee writes "Hackers: 6, Sony: 0. It appears an attacker has performed a SQL injection attack against SonyMusic.gr. The latest attack has exposed usernames, real names, email addresses and more. Is Sony's network being used as the world's largest public penetration test?"

303 comments

  1. SQL Injection... by yarnosh · · Score: 5, Funny

    The most preventable of all security holes. How sad.

    1. Re:SQL Injection... by hedwards · · Score: 4, Interesting

      I'm enjoying this for the lulz and the epic security fail. I just wish I could buy a drink for whomever it is that's doing this to Sony.

    2. Re:SQL Injection... by Bacon+Bits · · Score: 4, Informative

      I thought the most preventable of all security holes was blank administrator passwords. Granted, the most notorious instance of this was the default install of SQL Server 2000's sa account....

      --
      The road to tyranny has always been paved with claims of necessity.
    3. Re:SQL Injection... by yarnosh · · Score: 1

      I guess I meant from a code perspective. I suppose there are plenty of other ways to leave your system wide open. /shrug

    4. Re:SQL Injection... by networkzombie · · Score: 1

      Windows does not allow network access to any account with a blank password. Using a blank password with the SA account in SQL is incompetence.

    5. Re:SQL Injection... by Anonymous Coward · · Score: 0

      Them hackers are sneaky sons of bitches!

    6. Re:SQL Injection... by Anonymous Coward · · Score: 1

      You'd buy a drink to people stealing personal info? They are driven by profit just like sony exec. JUST LIKE sony execs....
      I wonder if all this fail is just some insider at sony doing a new version of the "stolen laptop full of personal info" trick.
      Anyway Sony is currently the perfect target for crackers, just like a political demonstration is perfect for common criminals who want to smash a glass and steal some (corporations' branded) items from a shop.

    7. Re:SQL Injection... by mcgrew · · Score: 0

      I'm enjoying it for the sweet revenge for what they did to my PC when my daughter installed XCP. Karma's a bitch. Whoever hacked them, kudos. I'll raise my glass in a toast tonight.

      Die, Sony, Die.

    8. Re:SQL Injection... by mrman18766 · · Score: 1

      I thought the most preventable of all security holes was blank administrator passwords.

      One small exception to this rule. On Windows >= Vista, if an account has a blank password, it is not allowed to connect remotely.

    9. Re:SQL Injection... by Phoghat · · Score: 1
      From Wikipedia

      SQLIA is one of the Top 10 Web Application vulnerabilities

      My sympathy goes out to Sony because they were once considered the top innovator in almost everything electronic. Then they just F'd up over and over again. I want to root my PS3? Sorry sucker everything you buy still belongs to us.

      Well Sony, Up yours!

      --
      Think of how stupid the average person is, and realize half of them are stupider than that.
  2. Sell short SNE by ub3r+n3u7r4l1st · · Score: 1

    Time to sell short Sony stocks while we are at it.

    1. Re:Sell short SNE by Nrrqshrr · · Score: 1

      If you waited till Sony got screwed 6 times before realizing it was time to sell, you'r way too late, buddy.
      I guess I would have bought LT stocks on Sony around the first hack, when it became pretty cheap, and expected a rise. But honestly, right now, there is no way you can tell whether Sony will ever get up from this, or no.

  3. HAHAHAHAH!!!!! by Anonymous Coward · · Score: 0, Troll

    LOLZZZZZ!!!!!!

    seriously sony?

    RONFLMFAO!!!!!!

    hahahahahahahahahah!!!!!!!!!!!!

    1. Re:HAHAHAHAH!!!!! by Anonymous Coward · · Score: 0

      Yep, the day Sony turned into an American company and started suing people for alleged copyright violations instead of making cool hardware, they were doomed.

    2. Re:HAHAHAHAH!!!!! by andydread · · Score: 1

      +1 indeed. I too got a bad taste in my mouth when they got into the content production business. Back then I think it was their purchase of Columbia Records that started their downhill slide. Before that they used to make cool hardware and the fought many moons ago for consumer rights and the right to build unencumbered consumer hardware. I Remember getting Sony Style catalogs etc and wanting everything in it. I recommended and Sold many a Sony product over the years and now will not touch a Sony product nor recommend/sell their products to anyone.

  4. Being positive here... apk by Anonymous Coward · · Score: 0

    SONY now knows 1 good thing from this: How to stop it from happening again on this and other sites/domains they own & host websites from.

    That's the only good result.

    Now, they ought to do fixes based on that data for their own good now that it's been pointed out & for the good of their viewers.

    (I hope that this thing wasn't anything that puts worse crap onto others' systems that visit it. Imo, those are the worst - spreads like plague).

    I haven't read the "detailed findings" so far, only the summary type articles...

    APK

    P.S.=> In any event here, I'd think it's good to stay positive when things are looking down, & then do something about it once you're armed with data to look for, + fix it!

    apk

    1. Re:Being positive here... apk by compro01 · · Score: 4, Insightful

      SONY now knows 1 good thing from this: How to stop it from happening again on this and other sites/domains they own & host websites from.

      How to stop this particular attack.

      Available evidence suggests they have no shortage of dailyWTF-worthy screwups that people can continue to exploit.

      --
      upon the advice of my lawyer, i have no sig at this time
    2. Re:Being positive here... apk by Opportunist · · Score: 2

      SONY now knows 1 good thing from this: How to stop it from happening again on this and other sites/domains they own & host websites from.

      Well, if the recent weeks told us one thing then that they do NOT learn anything from the penetrations. PSN was penetrated and they took it down, but it seems they didn't really learn much from it, since SOE followed. PSN went back up, only to be torn down again near instantly because it was AGAIN penetrated with an allegedly similar attack. And now that. An SQL injection, the one attack that can be prevented the easiest and with the least hassle (hell, there's even free frameworks for nearly every script language in the world that do it automatically for you).

      I'd say if one thing's certain, then that Sony doesn't learn jack from the attacks.

      --
      We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
    3. Re:Being positive here... apk by DI4BL0S · · Score: 1

      it was AGAIN penetrated with an allegedly similar attack.

      This is not true, The secondary attack was just resetting passwords from users that did not reset their password yet, made possible by the data stolen (email & date of birth) from PSN hack earlier. I saw this comming the second I read sony would force every user to change their password on first logon.

    4. Re:Being positive here... apk by Anonymous Coward · · Score: 0

      You forgot to add how hosts files would have prevented this whole fiasco

    5. Re:Being positive here... apk by Anonymous Coward · · Score: 0

      First off, why don't you just get an account instead of posting AC? Some (many) of us are tired of you're trolling and would like to be able to mod you down. I realise that you honestly believe what you say APK, but you don't think before you post, and you do stupid things. Like sign the above post twice. Hell, I am posting AC, since I know how you will stalk people, and I can't think of the last time I did, because I don't really care about hiding my identity. But you scare me, and others too.

      Some look at your posting history (way before /.)and laugh. I just get concerned. Not sure if this helps, but I'll put it this way. From reading someone's collection of posting links and your hatred of certain people you claim that have impersonated you, I can tell this is actually you by your writing style and not an impostor.

      Personally, I think you don't get outside enough and have very many friends. You don't have that "life experience" and it holds you back. You probably don't even know what I am tlaking about, but as someone with health issues and was reading before my peers, yet luckily grew up in a bad neighborhood, I see that I once, and you also, think you have a grip on life and you don't.

      You're right, think positive. But that doesn't mean think positive about someone that so negatively didn't care to patch something that I, as someone who doesn't even program knows, you just don't do if you give a damn at all. A more correct and logical positive reaction would be, maybe they finally learned a lesson and will take better security actions. But I think most of us know here this isn't over yet.

  5. Public penetration test by mehrotra.akash · · Score: 4, Insightful

    Isnt every network exposed to the public (esp. mid size or larger commercial ones) continously under attempted attack?

    1. Re:Public penetration test by techno-vampire · · Score: 2
      Isnt every network exposed to the public (esp. mid size or larger commercial ones) continously under attempted attack?

      Yes, of course they are. However, there are examples of SQL injection attacks going back to November, 2005. There's no excuse for a company as big as Sony to be vulnerable to them almost five years later.

      --
      Good, inexpensive web hosting
    2. Re:Public penetration test by smash · · Score: 2

      Well given they were running apache 1.3 on various things, which was not really suggested as the basis for new installs even way back in 2003-2004, its no great surprise they're still vulnerable to shit that was popular / exposed back in 2005.

      --
      I run: Windows, OS X, Linux, FreeBSD. Just because you have a hammer, doesn't mean everything is a nail.
    3. Re:Public penetration test by Anonymous Coward · · Score: 0

      Isnt every network exposed to the public (esp. mid size or larger commercial ones) continously under attempted attack?

      Yes, of course they are. However, there are examples of SQL injection attacks going back to November, 2005. There's no excuse for a company as big as Sony to be vulnerable to them almost five years later.

      No, actually they aren't. An exploit riddled site can sit out there for years without being noticed; this is pretty common. The fact is that Sony is a high-profile target.

    4. Re:Public penetration test by MagusSlurpy · · Score: 5, Insightful

      Yes, but to be fair to Sony (which really pains me), they are currently the focus of every bored script kiddie in the world right now, as well as most of the legitimately pissed-off, skilled hackers. While there may not be such a thing as "security through obscurity," there is a lot to be said for not having a target the size of Montana painted on your servers.

      --
      My sister opened a computer store in Hawaii. She sells C shells by the seashore.
    5. Re:Public penetration test by Anonymous Coward · · Score: 1

      Examples, sure. The attacks existed long before that.

      My (at the time) boss's sons website got hit by an SQL injection somewhere around 2001. My boss told us about it, and mentioned that he had been told that it was a brand new kind of attack, so it wasn't a surprise that his site was insecure.

      I sat there shaking my head, because our development tool at the time (Dreamweaver Ultradev) already had a simple built in protection against it: When it generated SQL code, it added a Replace() around every variable, replacing quotes with escaped quotes. Not the best way, but it shows that people were aware of the problem. Plus, a couple of years before that - in 1999, I was looking for shell command injection holes in Unix shell scripts. Though the language is different, the problem is the same. User input that become part of a command, which - if not escaped perfectly - allows someone to end the quote and turn the rest of the user input into a command.

      And from where did I know about injection attacks? From a Unix book I got from the library around 1993. A book where some parts were outdated when I read it.

      The concept of injection attacks has been known for a loooong time, and once you understand the concept, seeing that it applies to SQL as well as shell scripts shouldn't take more than 2 extra brain cells.

    6. Re:Public penetration test by AmiMoJo · · Score: 1

      What surprises me is that it took this long to uncover the vulnerability. I would expect every script kiddie to be testing for SQL injections and ancient versions of software.

      --
      const int one = 65536; (Silvermoon, Texture.cs)
      SJW, n: "Someone I don't like, and by the way I'm a fuckwit" - AC
    7. Re:Public penetration test by Anonymous Coward · · Score: 0

      Well given they were running apache 1.3 on various things, which was not really suggested as the basis for new installs even way back in 2003-2004, its no great surprise they're still vulnerable to shit that was popular / exposed back in 2005.

      might want to talk with some OpenBSD guys about that assumption...

    8. Re:Public penetration test by Anonymous Coward · · Score: 0

      going back to November, 2005. There's no excuse for a company as big as Sony to be vulnerable to them almost five years later.

      That would be "almost six years later", Sparky. Or "Over five years".

    9. Re:Public penetration test by krazytekn0 · · Score: 1

      almost 5? uh... ok

      --
      Not all life is cyber. Extra Income
    10. Re:Public penetration test by techno-vampire · · Score: 1

      Brain fart.

      --
      Good, inexpensive web hosting
    11. Re:Public penetration test by Anonymous Coward · · Score: 0

      ...there is a lot to be said for not having a target the size of Montana painted on your servers.

      There's also a lot to be said for not painting that Montana-sized target on your own servers, with the paint of your own self-serving actions.

    12. Re:Public penetration test by Anonymous Coward · · Score: 0

      And they are the focus because they painted that target the size of Montana on not just themselves, but on their customers as well. Shame on Sony. I'm no Microsoft fan, but when someone exploits Microsoft code, they're invited to Microsoft to teach R&D how to protect against it. They aren't persecuted in court like George Hotz was. http://windowsphone7reviews.net/microsoft-invites-ps3-hacker-geohot-to-work-on-windows-phone-7 http://en.wikipedia.org/wiki/Sony_Computer_Entertainment_America_v._George_Hotz

  6. Karma's a bitch, Sony. by jaskelling · · Score: 4, Insightful

    Years of half baked products, poor reliability, hostile customer service, lazy innovation, and a general disdain for security are what your customers have had to deal with. I really don't care who is doing it to you or why - but I applaud them teaching you the hard lessons of the evolving technological age. You can't keep repeatedly flipping people the finger anymore and tell them to deal with it. Evolve or die. And no, my loathing isn't related to just the recent PS3 debacle. It extends to experiences with consumer audio, professional theatrical projection equipment, and so on right down the line. The fact that you're being taken out by the simplest of attacks in most cases just makes my smile grow a little more.

    1. Re:Karma's a bitch, Sony. by rrohbeck · · Score: 1, Insightful

      +5.
      Remember when Sony products were cool because they were innovative? Today you're outing yourself as a mindless consumer if you buy anything Sony.

    2. Re:Karma's a bitch, Sony. by seanvaandering · · Score: 2, Insightful

      Other than getting a free Sony Blu-Ray player recently, I really try to avoid Sony products as a rule. I used to LOVE them, their receiver line was one of the best ten years ago, but the only thing I would entertain buying these days is MAYBE a LCD TV. There is just so much better choices out there these days and i'm not into buying name brand for the name anymore.. having a family will do that to ya :)

    3. Re:Karma's a bitch, Sony. by Anonymous Coward · · Score: 1

      take it easy fanboi.

    4. Re:Karma's a bitch, Sony. by Opportunist · · Score: 5, Insightful

      Remember when Sony products were cool because they were innovative?

      Yes, I'm actually that old.

      I guess we should explain for the kids here since I guess they can't even imagine it: Sony was cool. Not just like Apple today, with fanboys liking it and everyone else hating it, it was THE cool brand. They had innovative products with never seen before features and a kickass support that didn't bother to ask for details, they just threw a new model at you if the old one croaked, which was actually unlikely because, hey, it was a SONY, they don't fall apart! People were proud to have Sony speakers and Sony radios in their cars, they were proud to have a Sony walkman (as if you could get any others, after all it was a brand name) and they had every right to be proud, they bought something of lasting value!

      I admit, it's very hard to believe that today.

      --
      We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
    5. Re:Karma's a bitch, Sony. by Swarley · · Score: 1

      Don't even bother with the Sony TVs. They do make some nice TVs, but so do Samsung and Sharp (Aquos anyway, their budget sets don't hold the same value proposition) for quite a bit less money. I can't think of a single line of Sony products that doesn't butt up against better and cheaper competition. They are just coasting and selling the name to people old enough to have bought their first nice TV 20+ years ago when Sony actually gave a crap.

    6. Re:Karma's a bitch, Sony. by Bacon+Bits · · Score: 1

      Remember when Sony products were cool because they were innovative?

      Yes, I'm actually that old.

      That's OK. I'm old enough to remember before Sony meant good. I remember when Sony meant cheap knock-off from Japan.

      --
      The road to tyranny has always been paved with claims of necessity.
    7. Re:Karma's a bitch, Sony. by Anonymous Coward · · Score: 0, Informative

      If you catch a cold your doctor should tell to to suck it up and go live somewhere less cold?

      That's not how colds work.

    8. Re:Karma's a bitch, Sony. by Luckyo · · Score: 1

      No, somewhere more cold. Bacteria and virii that cause various diseases that go under "cold" umbrella enter state similar to hibernation at around -5C.

    9. Re:Karma's a bitch, Sony. by Anonymous Coward · · Score: 0

      No, this is karma and Sony we're talking about. It's like if someone breaks into your house and steals your address book and starts blackmailing your ex-girlfriends for money, except instead of being a normal person, you're a sociopath who runs a crime ring.

      Sony is a dirty, dirty corporation who is abusing democracy around the world, pushing crap like the secret WIPO treaties through parliaments too corrupt or stupid to realize what they're doing. They can't get enough of what they really deserve.

    10. Re:Karma's a bitch, Sony. by SuperQ · · Score: 2

      Yup, I loved my walkman and and then discman. And decent earbuds. I tried to love minidisc, but it was just too painful to keep using sony's proprietary bullshit. Between the minidisc fail, the memory stick fail, and the general shit-tastic quality of stuff these days I've just given up.

    11. Re:Karma's a bitch, Sony. by johanatan · · Score: 1

      He has a lower slashdot ID than you though. Fail!

    12. Re:Karma's a bitch, Sony. by _xeno_ · · Score: 5, Informative

      professional theatrical projection equipment

      There was an interesting story in the Boston Globe this weekend about how Sony projectors are projecting 2D digital movies up to 85% darker than they should.

      The reason? It turns out to be Sony DRM, although the article doesn't ever come out and say it directly. Basically, there's a special 3D lens required to display 3D movies, but this lens reduces the brightness of 2D movies.

      So why aren't theater personnel simply removing the 3-D lenses? The answer is that it takes time, it costs money, and it requires technical know-how above the level of the average multiplex employee. James Bond, a Chicago-based projection guru who serves as technical expert for Roger Ebert's Ebertfest, said issues with the Sonys are more than mechanical. Opening the projector alone involves security clearances and Internet passwords, "and if you don't do it right, the machine will shut down on you."

      In other words, you have to deal with Sony DRM. Rather than jump through the Sony-imposed hoops, theaters just leave the 3D lens on all the time.

      Why bother with Sony projectors at all if they have this problem and others don't?

      The reason appears to be a basic business quid pro quo. Sony provides projectors to the chains for free in exchange for the theaters dedicating part of their preshow ads to Sony products.

      So, yeah. Another wonderful example of Sony in general and Sony DRM in specific giving customers an inferior product.

      Obviously the theaters deserve some blame for this too.

      --
      You are in a maze of twisty little relative jumps, all alike.
    13. Re:Karma's a bitch, Sony. by siddesu · · Score: 2

      That's what American management does to you.

    14. Re:Karma's a bitch, Sony. by Pentium100 · · Score: 1

      I have two Sony Walkmans (Walkmen?) and they are very good and solidly built (quite a lot of metal parts, compared to today's mostly plastic devices). Whatever they make now will most likely break beyond repair before the cassette players do. Yes, the players needed a belt change, but that was relatively easy to do and the new belts should last a long time. I still listen to cassette, since I have a lot of tapes so it makes sense to record new stuff to tape instead of copying all tapes to a digital format, buy portable and car digital players, in a sense I am "locked in". Also, it is more convenient to record to a cassette compared to PC, and digital recorders are quite expensive.

    15. Re:Karma's a bitch, Sony. by Anonymous Coward · · Score: 0

      I'm not that old, but my home has Sony TV's older than I am, so I know what you are saying

    16. Re:Karma's a bitch, Sony. by mehrotra.akash · · Score: 2

      "Opening the projector alone involves security clearances and Internet passwords"

      Is it a projector or an ATM?

    17. Re:Karma's a bitch, Sony. by JohnRoss1968 · · Score: 1

      And they both have a lower Slashdot ID than you do, for that matter so do I. That doesn't mean a damn thing.
      Sorry but the fail is on you.

    18. Re:Karma's a bitch, Sony. by JohnRoss1968 · · Score: 1

      LMFAO I love you fanboys, you always make me smile.
      A better analogy would be If you leave your widescreen TV down at the end of your driveway and someone steals it. The Police would probably chick it out for you but don't expect them to bust their humps doing it. Then You leave your computer system down there the next day and someone steals that. At that point you can expect the police to tell you to go fuck yourself.
      Or
      If If you have a habit of hosing yourself down with water then running around outside in the snow and you get sick, the doctor might chide you a bit for it but would probably treat you. then the next day you start drinking drain cleaner. Im hoping for your sake that the doctor has you sent to a nice safe place.

    19. Re:Karma's a bitch, Sony. by JohnRoss1968 · · Score: 1

      Dont confuse him with the FACTS, he's just a FANBOY. Im not sure his brain could take it.

    20. Re:Karma's a bitch, Sony. by Anonymous Coward · · Score: 0

      Sony and Samsung formed a joint venture company call S-LCD to produce LCD panels since 2004. There's no reason to buy Sony TVs over Samsung ones since the chances are they are from the same plant anyway.

      The days of Sony TV being higher quality ie Trinitron CRT days are LONG gone.

    21. Re:Karma's a bitch, Sony. by andydread · · Score: 1

      There was a time when people had Trinitrons or just a regular old TV. Trinitrons rocked back then in the 80s and early 90s. They never failed. Nowadays I see Sony products and i say "oh looks nice....oh well...its Sony, they are hostile to their customers I'll pass."

    22. Re:Karma's a bitch, Sony. by andydread · · Score: 1

      It is a Sony product. Do not open/disassemble Sony Products without the proper authorization. You are just a mere customer who purchased the product. You do not own it.

    23. Re:Karma's a bitch, Sony. by Anonymous Coward · · Score: 0

      Let me get this straight. You're an unhappy customer, so you support other customers' personal information being sold on the black market? And this is supposed to teach Sony what lesson, exactly? And, after being burned numerous times by a large, multinational corporation, you continue to use their products again and again, and support vigilante justice / privacy invasions of third parties, rather than simply boycotting the corporation?

      When I opened up a safety deposit box with my bank, I expected them to keep it in a secure vault. Well, they got robbed and it turns out they actually stored those boxes in a 5"x5" aluminum shed with a paper mache door which didn't lock or even shut all the way.
      Well, a few months later, after I'd already moved to another institution, another one of their "vaults" got hit. And I laughed. Why? Because anybody who still banks with them ought to know what is going on, and deserves what they get. Plus, it's amusing to watch them epic fail over and over again.

      Yep. Sounds like Slashdot alright.

      Sounds like normal human nature to me. People tend to laugh at the misfortune of those who have previously done them wrong. As well as suckers and idiots who are wronged by those same people repeatedly yet still come back for more abuse. I'm sorry you're too simple minded to understand that this is not the same thing as supporting vigilante justice.

    24. Re:Karma's a bitch, Sony. by sinan · · Score: 2

      I remember Sony and Sanyo transistor radios from 1960. Used to listen to one crossing Bosphorus every night on a ferry. All the onlookers were mesmerized by it.

    25. Re:Karma's a bitch, Sony. by Anonymous Coward · · Score: 0

      People were proud to have Sony speakers

      True. I still use the Sony hi-fi system I got from my parents 16 years ago (except for the casette and CD modules which I retired years ago). Which is kind of impressive for electronic equipment considering I use it daily. That thing was a great investment.

      It's really a bit sad I wouldn't touch current Sony products with a ten foot pole.

    26. Re:Karma's a bitch, Sony. by AmiMoJo · · Score: 0

      It turns out to be Sony DRM

      No, that is just the polarising lens/filter combo needed for passive 3D glasses. Like sunglasses polarisation makes the image darker.

      --
      const int one = 65536; (Silvermoon, Texture.cs)
      SJW, n: "Someone I don't like, and by the way I'm a fuckwit" - AC
    27. Re:Karma's a bitch, Sony. by Stone2065 · · Score: 1

      As a former ATM tech... sounds like it's EASIER to get into an ATM than one of those pieces of Sony shit.

      --
      Stone
    28. Re:Karma's a bitch, Sony. by Anonymous Coward · · Score: 0

      Thats quite funny actually since there was *never* a time where that was the case.. unless your trying to make a point about being a youngster who cannot remember a time when Sony meant anything other than crappy products? Either way your post fails no matter what you where trying to do...

    29. Re:Karma's a bitch, Sony. by Anonymous Coward · · Score: 0

      I switched to canon kit for everything I had sony versions of. The MemoryStick ->Pro->etc thing really pissed me off in ways I can't explain.
      The only sony kit I still have and use are second-hand speakers and the PS2.

      Given the Canon has done the same with the SD->SDHC->SDXC, but it's more forgivable as that is the standard media, and not the 3x more expensive proprietary device.

      I'm just going to freaking wait for the SD4.0 specification before buying anything new. Most of the existing devices are SDHC or SD3.0 SDXC but won't support the higher speed. My existing kit works with the existing SDHC.

    30. Re:Karma's a bitch, Sony. by _xeno_ · · Score: 5, Informative

      No, that is just the polarising lens/filter combo needed for passive 3D glasses. Like sunglasses polarisation makes the image darker.

      Yes, that would be the technical reason why the image is darker, but that's not the DRM part. The DRM is the reason that the projectionist doesn't simply replace the lens: if they do, they risk tripping Sony's DRM and locking the projector out.

      Rather than risk that, they just leave the lens on. Thereby making the movie look absolutely horrible.

      So it may not be DRM making the movie dark directly, but DRM is the root cause: Sony doesn't trust the people who own the projector to change the lens, and it's DRM that enforces that policy.

      --
      You are in a maze of twisty little relative jumps, all alike.
    31. Re:Karma's a bitch, Sony. by Nrrqshrr · · Score: 1

      I still have one of those old TVs with only 8 channels that you switch to and from with 8 different buttons. It also has a knob under each button to "fine-tune" the image. This TV never saw a repairman's face.


      And I spent entire summers playing with the Xbox on it.

    32. Re:Karma's a bitch, Sony. by bhtooefr · · Score: 1

      The point is that Sony DRM freaks out if you screw up when reconfiguring the projector for the 2D lens.

    33. Re:Karma's a bitch, Sony. by Hamsterdan · · Score: 1
      --
      I've got better things to do tonight than die.
    34. Re:Karma's a bitch, Sony. by Hamsterdan · · Score: 1

      And as *if* ...

      --
      I've got better things to do tonight than die.
    35. Re:Karma's a bitch, Sony. by TheRaven64 · · Score: 1

      Is 16 years considered a long time for HiFi equipment to last? I'm still using the amplifier and speakers that my father bought in the early '80s. It was in my parents living room for a couple of decades, and I got it afterwards. It's getting on for 30 years old now, and still works fine. Looking on eBay, the same model amplifier seems to be pretty common. I'm pretty sure that HiFi stuff lasting 20 years or more is common, not exceptional.

      --
      I am TheRaven on Soylent News
    36. Re:Karma's a bitch, Sony. by Anonymous Coward · · Score: 1

      You miss the point. The polarizing lens are needed only for 3D movies, so for non-3D movies they darken the image without need. The point is that removing the 3D lenses is not possible due to Sony's DRM measures build in the projection itself, so they are left in place for all projections, even if the movie would require them removed because it's not 3D.

    37. Re:Karma's a bitch, Sony. by Anonymous Coward · · Score: 0

      Okay, okay, I'll get off your lawn. Gee wiz.

    38. Re:Karma's a bitch, Sony. by guybrush3pwood · · Score: 1

      I'm not a fanboy, I just disagree with that schmuck who think he's living inside Hackers and someday will wear a dress and fuck Angelina Jolie if he keeps hacking the planet. But thanks for feeding my point with more analogies, anyway.

      --
      Perhaps I'm trolling, perhaps I'm not.
    39. Re:Karma's a bitch, Sony. by JohnRoss1968 · · Score: 1

      now thats a low slashdot ID number.

    40. Re:Karma's a bitch, Sony. by JohnRoss1968 · · Score: 1

      Feeding your point. lol If you think what I wrote strengthens your point then you need to learn to read.

    41. Re:Karma's a bitch, Sony. by javanree · · Score: 1

      Even worse; if you manage to find the cause it almost always comes down to some Sony-only part, which is impossible to buy in any regular (web)shop. And if you then have the nerve to call Sony tech support, asking for a specific part... let's not even go there :( After 2 TV sets with such issues I've stopped buying Sony, at least some other brands still have decent consumer service (Technics and Philips to name a few)

    42. Re:Karma's a bitch, Sony. by Anonymous Coward · · Score: 0

      Sony pocket radio. Still the most amazing piece of tech I've ever held.

    43. Re:Karma's a bitch, Sony. by Anonymous Coward · · Score: 0

      The first CD player I bought was a Sony. I bought the first DVD player model that came out -- also a Sony. Both were ridiculously expensive at the time, but I could see that they were the future, and that tapes and vinyl would eventually become niche markets. I got rid of the CD player a long time ago, but the DVD player still works today, and my son still uses it in his room. A DVD player almost as old as he is, still working. Sony did make good gear.

      Did.

      Besides the decline in quality, ever since the rootkit fiasco I no longer buy or recommend anything Sony.

    44. Re:Karma's a bitch, Sony. by Des+Herriott · · Score: 1

      Nah.

    45. Re:Karma's a bitch, Sony. by Anonymous Coward · · Score: 0

      Absolutely. I'll never forget how cool my Walkman was in 1981. Now Sony is a "media" company, rather than an electronics company. Same thing is happening to HP. Every now and then a great engineer with some management skills takes a company and makes it great. Sooner or later the MBA's infest the company and it all goes downhill from there.

    46. Re:Karma's a bitch, Sony. by Anonymous Coward · · Score: 0

      Aww man, you're making me feel old...

      I'm only 20, and I remember being the envy of my neighborhood because I had a sony walkman that lasted for 15 hours and had 120 second anti-skipping.

      At this rate I'll be yelling "Get off my lawn!" by the end of June...

    47. Re:Karma's a bitch, Sony. by Tetsujin · · Score: 1

      Nah.

      Aw, if you'd just signed up a little later, you'd have "6510", the model number of the Commodore 64's CPU!

      --
      Bow-ties are cool.
    48. Re:Karma's a bitch, Sony. by Omestes · · Score: 2

      We had a Sony receiver from the early-mid 80's that my girl friends parents gave us. I was a wondrous thing. Then it died, and we replaced it with a second-hand high-end Pioneer receiver from the early 80's, which is a slightly more wondrous thing, though it doesn't turn on with the nice "brang!" noise the Sony had.

      Sony used to be a good brand, they were known for their quality, and long life. This started to go away in the mid-90s, though. I had a Sony stereo (over grown boombox) from 1992, hooked to a CD-player from 1993, they rocked. When I wanted something beefier in ~1996 I got another Sony (it was ugly as sin) and it died within a year, and had terrible sound. I got another, it died almost as quickly, and was uglier (fake chrome, bight colors, shaped like something from a B sci-fi movie!), and had worse sound, and the volume knob made everything crackle, it had no EQ outside of silly presets.

      Finally I just moved on to using my computer as a music player, and using my iPod (gotten for free) with my old Sony stereo from 1992 via mic-in and radio.

      I don't actually think that Sony devolved in quality much more than anyone else. Its damn hard to find good equipment, since everything is built as a disposable commodity these days. Without spending high premium rates (200-300% of the average), your getting crap that is going to die within a year or two, and has sub-bar build quality and bad audio/video/whatever its function is. There is no good brand at the consumer level.

      I'm being general. Recently we ran into this with vacuum cleaners, our $400 vacuum died (we got it on a good deal, no box) 3 months after the warranty. We were going to buy a Dyson, and realized that it felt as cheap and crappy as the $100 store-brand specials, and was made with thinner, more bendy, plastics than most other, cheaper, vacuums. Why bother spending $500-600 for a piece of plastic shit? Even if it "works better", its going to die a couple months after warranty too. I miss my 150lb Kirby. It was built like a tank, and saved me going to the gym. Further, it was almost 30 years old and would have worked fine, but some damn sales-man convinced me that new=better.

      90% of the time new != better. New = cheaper for the same price. New = greater profit margin for the manufacturer and no real consumer benefit.

      Sorry for the rant.

      --
      A patriot must always be ready to defend his country against his government. -edward abbey
    49. Re:Karma's a bitch, Sony. by Anonymous Coward · · Score: 0

      I am not surprised. Years back I had a JVC projection TV with a DVI interface that online references said would "self destruct" if you didn't follow a complex procedure before opening it (it was there to prevent tampering with the HDCP code.)

    50. Re:Karma's a bitch, Sony. by Mindcontrolled · · Score: 1

      Walkman? Anti-Skipping? Young Padawan, if you put a shiny silver disc into it, it is NOT a Walkman... Now get off MY lawn, if you please. ;)

      --
      Ubi solitudinem faciunt, pacem appellant.
    51. Re:Karma's a bitch, Sony. by garyebickford · · Score: 1

      Remember when Sony products were cool because they were innovative?

      Yes, I'm actually that old.

      That's OK. I'm old enough to remember before Sony meant good. I remember when Sony meant cheap knock-off from Japan.

      So does this mean they've gone full circle?

      --
      It's easier to be a result of the past, but more fun to be a cause of the future! http://www.spacefinancegroup.com/
    52. Re:Karma's a bitch, Sony. by garyebickford · · Score: 1

      I think they still make the Kirby, pretty much like before. But maybe not.

      --
      It's easier to be a result of the past, but more fun to be a cause of the future! http://www.spacefinancegroup.com/
  7. But... why?! by MrEricSir · · Score: 1

    The Application String Interface was a poor idea from the start. It's the 21st century, we shouldn't be building strings to do DB queries.

    --
    There's no -1 for "I don't get it."
    1. Re:But... why?! by betterunixthanunix · · Score: 3, Insightful

      I would classify this as part of the more general category of "in band signalling." The telephone network learned the hard way why such a design is bad when people began to use blue boxes, but it still took decades for them to fix the problem. I suspect that it will be a while before we see a real fix to the SQL injection problem as well.

      --
      Palm trees and 8
    2. Re:But... why?! by MrEricSir · · Score: 1

      I wouldn't go so far as to use the comparison to in band signalling for this particular problem. After all, that comparison might be more fitting for the notoriously sloppy way modern PCs fail to distinguish between program storage and data storage.

      --
      There's no -1 for "I don't get it."
    3. Re:But... why?! by Chatterton · · Score: 1

      Not distinguishing between program storage and data storage permit all kind of nice meta programming. LISP is beautiful in its kind for that. But not checking your inputs is the worst offender and the source of all sins. It is so easy to cut corners on input validation :-(

    4. Re:But... why?! by Anonymous Coward · · Score: 0

      Already solved -> NoSQL databases ;)

    5. Re:But... why?! by garyebickford · · Score: 1

      I was going to mention that, but not in the nicely ironic way you did. :) Considering that merging the two is one of the half-dozen most important concepts in 'stored program' computers.

      --
      It's easier to be a result of the past, but more fun to be a cause of the future! http://www.spacefinancegroup.com/
  8. PPT?! by microcuts · · Score: 1

    i'm sorry, but was the phrase: "world's largest public penetration test?" really necessary?

    1. Re:PPT?! by Anonymous Coward · · Score: 0

      Giggity!

    2. Re:PPT?! by plover · · Score: 3, Funny

      i'm sorry, but was the phrase: "world's largest public penetration test?" really necessary?

      Sony acts like the world's largest orifice so it's only fitting.

      --
      John
    3. Re:PPT?! by nospam007 · · Score: 1

      "Sony acts like the world's largest orifice so it's only fitting."

      It's not a trick, it's a Sony!

    4. Re:PPT?! by JohnRoss1968 · · Score: 1

      No But It Sure Was Funny.....

    5. Re:PPT?! by MagusSlurpy · · Score: 1

      Sony acts like the world's largest orifice so it's only fitting.

      Sarah Palin's mouth?

      --
      My sister opened a computer store in Hawaii. She sells C shells by the seashore.
  9. Sony = Consistent by alphax45 · · Score: 5, Insightful

    Well at least they are consistent - none of their systems seem to have more than basic security.

    --
    K Man
    1. Re:Sony = Consistent by Tamran · · Score: 1

      Consistency - It's only a virtue if you're not a srew-up.

      http://www.despair.com/consistency.html

    2. Re:Sony = Consistent by ub3r+n3u7r4l1st · · Score: 1

      Simplicity is beauty -- at least it comes from the mouth of those who are against spaghetti and obfuscated code.

      There are still places for spaghetti and obfuscated code, and this is why.

    3. Re:Sony = Consistent by Ecuador · · Score: 1

      Yeah, because "basic security" does not involve sanitizing your sql queries...

      --
      Violence is the last refuge of the incompetent. Polar Scope Align for iOS
  10. people are stealing user info by YesIAmAScript · · Score: 3, Insightful

    And you're egging them on?

    They aren't just doing this to Sony, they're doing this to the people who use the services too.

    Take it from a person had a gawker account. When they were hacked, it caused a great inconvenience for me.

    --
    http://lkml.org/lkml/2005/8/20/95
    1. Re:people are stealing user info by fotbr · · Score: 5, Insightful

      In this case....I don't feel sorry for anyone doing business with sony. From my point of view, they made their bed, now they get to lay in it.

    2. Re:people are stealing user info by Killerchronic · · Score: 4, Insightful

      It maybe a problem for users but this is a serious wakeup call to said users, no your data is not as safe as you think it is when you are handing it over to all these companies, its about time the cracks were shown to customers and just how slack these companies can be in keeping their protocols and systems running correctly. I am still laughing, im not a sony fan in any way, shape or form, obviously its bad its happening but its hilarious that a company this big has such lax security and is being exposed on an almost daily basis.

    3. Re:people are stealing user info by Anonymous Coward · · Score: 0, Troll

      It is your own fault giving inconvenient information away to the internet.

      People like you have been warned since 2 decades now.

      Stop whining and deal with the consequences of doing business with Sony.

    4. Re:people are stealing user info by Anonymous Coward · · Score: 0, Troll

      People who use Sony, deserve it.

    5. Re:people are stealing user info by Isaac+Remuant · · Score: 2

      You're right. While we might enjoy this bullying because we dislike a company there is a larger context than, OMGZ 0WN3D!1!!!!11

      I had a gawker account as well and, while it wasn't a problem for me to change my level lame password for that and other sites, it might turn out worse for other people.

      --
      "Science can amuse and fascinate us all, but it is engineering that changes the world. " - Asimov.
    6. Re:people are stealing user info by LordLucless · · Score: 5, Insightful

      So your saying, by doing this they're going to drive customers away from Sony, reduce their income stream, and eventually remove them from the world of global commerce?

      Wow, that sounds...terrible

      --
      Just because you're paranoid doesn't mean there isn't an invisible demon about to eat your face
    7. Re:people are stealing user info by Anonymous Coward · · Score: 1, Interesting

      Quite frankly we need more of this type of action where it can actually dent Sony's reputation. Sony is a horrible company you shouldn't be doing business with in the first place. The same can be said for Microsoft and Apple.

    8. Re:people are stealing user info by naz404 · · Score: 2

      Did Sony fall for Little Bobby Tables again?

      http://xkcd.com/327/

    9. Re:people are stealing user info by JohnRoss1968 · · Score: 1, Insightful

      At this point I would have to say this is SONY's fault.
      How inept can your IT dept be.
      They should just shut the whole thing down and redo it right, like they should have done it the first time.
      3....
      2....
      1.....
      Let the Fanboys commence defending SONY for their lackluster performance.

    10. Re:people are stealing user info by hedwards · · Score: 4, Interesting

      Honestly is this really that much worse than when Sony decides to vandalize customer equipment?

    11. Re:people are stealing user info by maxwell+demon · · Score: 1

      Indeed. I could enjoy it if they had extracted Sony's DRM keys. But extracting user names etc., no.

      --
      The Tao of math: The numbers you can count are not the real numbers.
    12. Re:people are stealing user info by Anonymous Coward · · Score: 0

      Yes, objectively provable given the customers continue to trade with sony even with such trade terms and, as the gawker example shows, do not want others interfering with that arrangement. Simply look at what people want: they may not prefer sony being restrictive, but the deal they get with sony is still worth their patronage, else they wouldn't be customers anymore.

    13. Re:people are stealing user info by AmiMoJo · · Score: 1

      Browsers could do a lot to mitigate the damage if they just enabled some basic password protection features. Firefox, for example, has a master password system but it isn't enabled by default, and even when it is on there is no secure password generator. It can all be done with add-ons but should really be the default so everyone starts using it.

      In case you don't know what I am talking about the ideal way for a browser to manage passwords is for it to generate a random secure password for each site. It stores that password and fills it in for you when you try to log in, thus saving the user from having to remember hundreds of random passwords while preventing the hacking of one site affecting others. An optional master password can be requested before the random password is filled in.

      --
      const int one = 65536; (Silvermoon, Texture.cs)
      SJW, n: "Someone I don't like, and by the way I'm a fuckwit" - AC
    14. Re:people are stealing user info by Stone2065 · · Score: 1

      It's heading rapidly towards the level of incompetence that the rootkit fiasco was...

      --
      Stone
    15. Re:people are stealing user info by justforgetme · · Score: 5, Insightful

      ohh, wait I have to say something about this!!!!

      I was in a bank once, while it was being robed! Ok, it wasn't the nicest experience I ever had and I might have been inconvenienced a bit.
      Did I lose the money I had in the bank? No.
      Did I loose the info I had stored in it? No.
      Did I manage to do the jobs I had with the bank? Yes, I just went to another branch.

      So if you are going to create a service infrastructure that hasn't enough failsaves and backup plans to deal with a simple digital break in then you damn well deserve to be reduced to the economic equivalent of decarbonized organic material... And all people who trusted your Services (including Yours truly) deserve a very big refund for your incompetence and a big slap in the face for being such fools!

      --
      -- no sig today
    16. Re:people are stealing user info by erroneus · · Score: 3, Insightful

      There are no Sony fanboys. There are people who are addicted enough to their games that they can't see who is behind them or that they don't care who they work with or where the data flows. But to call them fanboys is a stretch of the imagination. Sony doesn't have "fans." Just consumers.

    17. Re:people are stealing user info by Anonymous Coward · · Score: 0

      best xkcd ever!

    18. Re:people are stealing user info by Anonymous Coward · · Score: 1

      Sony deserves it.

    19. Re:people are stealing user info by tiddlydum · · Score: 1

      But what if you have multiple computers? Or don't just use firefox, like me? That's the problem with leaving it all up to your browser. Lose your hard disk? Bye bye passwords.

      A different password for every account is overkill. You just need a few, like one for services you don't trust, one for services you do, and one for your computers.

    20. Re:people are stealing user info by PReDiToR · · Score: 1

      My Gawker account was compromised too.
      Oh dear, I had to wait until they got the system back up and change my password.

      My PSN account has been compromised.
      Oh dear. I had to wait a couple of weeks for them to bring their service up again.

      In both cases the password change was done in seconds. I went to the web page, entered my old password, clicked the "Password Hasher" icon next to the "new Password" box, clicked "Bump" and entered my passphrase. Click OK. Completely new 26 character UPPER/lower/1234/!"£$ as easy as that. And I don't have to remember it, I just had to have it to hand when I typed it into my PS3.

      If having to change a password is a "great inconvenience" then maybe you're doing something wrong? Are you using the password in multiple places? You're on Slashdot, you should know better.

      Password hasher, a little paper address book, KeePass, SecureLogin/OperaWand all go to make life easy when it comes to long random secure passwords that you don't have to remember and that take a couple of clicks to recreate or update.

      --

      Do not meddle in the affairs of geeks for they are subtle and quick to anger
    21. Re:people are stealing user info by CastrTroy · · Score: 1

      I do this using password safe. Just back up the file to your phone and an USB key every so often. You sync your phone everyday anyway. If you don't sync your phone, pick another device you sync all the time,like your mp3 player, or what have you. Or just sync the file to drop box if you like and it syncs to all your comupters. It's encrypted anyway. Choose a single strong password and you've gone a long way to opening yourself up to all kinds of attack vectors.

      --

      Anthropic principle: We see the universe the way it is because if it were different we would not be here to see it.
    22. Re:people are stealing user info by TheRaven64 · · Score: 3, Informative

      On OS X, the keychain is a system service that is separate from the end user applications. Any app can use it with a couple of function calls, and the service has fine-grained ACLs, so you have to explicitly grant an application access to each password (except ones that it created), so multiple browsers can share the passwords. It's encrypted on disk and is trivial to back up.

      --
      I am TheRaven on Soylent News
    23. Re:people are stealing user info by petermgreen · · Score: 2

      The same can be said for Microsoft and Apple.

      mmm, I find it sad, on the one hand I want to play the big hit games and I want to reward the developers for what they have created (I don't want to pirate stuff). OTOH I find the direction the gaming market is going with forced firmware updates on consoles and online activation (or worse) on the PC very unattractive.

      If anything the XBOX seems to be the lesser of three evils at the moment, afaict they aren't requiring online activation (though they are taking steps towards it with in-box DLC) and afaict their firmware updates don't retroactively remove functionality.

      I hope an actual customer friendly option comes out of this but I wouldn't hold my breath.

      --
      note: i'm known as plugwash most places but i screwd up registering that here somehow in the past and now can't register
    24. Re:people are stealing user info by DarkOx · · Score: 1

      That sounds great, that way nobody can logon to any site from a machine that is not theirs because they won't have the password safe on that machine and don't know any of the passwords. We might as well just forget this whole cloud thing and go back to fat clients for every service. Oh and before you say lastpass, we all know how well that worked out for people recently; also a service like that presents to valuable a target, even if its a hard one it will be attacked often.

      --
      Repeal the 17th Amendment TODAY! Also Please Read http://www.gnu.org/philosophy/right-to-read.html
    25. Re:people are stealing user info by airfoobar · · Score: 1

      its about time the cracks were shown to customers

      I think Geohot already did that, quite literally.

    26. Re:people are stealing user info by maxwell+demon · · Score: 4, Interesting

      It's heading rapidly towards the level of incompetence that the rootkit fiasco was...

      It would be funny if the vulnerability that was exploited came from that very rootkit, installed by some unsuspecting employee putting a Sony CD into the computer ...

      --
      The Tao of math: The numbers you can count are not the real numbers.
    27. Re:people are stealing user info by spliffington · · Score: 1

      Except now people can sync their encrypted locally stored password files across devices. I use 1password on OS X and sync it to my phone.

    28. Re:people are stealing user info by Stone2065 · · Score: 1

      Touche', good sir/ma'am. Well said.

      --
      Stone
    29. Re:people are stealing user info by vegiVamp · · Score: 1

      > it caused a great inconvenience for me.

      Oh, you poor widdle thing.

      You can't be 100% secure, but you can at least do your god damn best. Being open to SQL injections is not doing your god damn best, it's saying "fuck this security thing, money belongs in my pockets and fuck the customers up the arse".

      As an aside, I also had a gawker account. The inconvenience for me was limited to being forced to change my password on their site. It's not as if the password I use on junk sites like gawker is the same I'm using for my email or banking.

      --
      What a depressingly stupid machine.
    30. Re:people are stealing user info by Anonymous Coward · · Score: 0

      people are stealing user info

      They didn't *steal* it, they copied it.

      Isn't that what everyone says here?

    31. Re:people are stealing user info by Anonymous Coward · · Score: 0

      So your saying, by doing this they're going to drive customers away from Sony, reduce their income stream, and eventually remove them from the world of global commerce?

      Yeah, that's what is going to happen. The end of global world commerce. -rolling eyes- If anything, eliminating a stifling/restricting influence like SONY is going to increase commerce.
      Personally, I welcome our anarchic SONY-hating anonylords.

    32. Re:people are stealing user info by ian_from_brisbane · · Score: 1

      I was in a bank once, while it was being robed!

      The robe must have been size XXXXXL to fit a bank.

    33. Re:people are stealing user info by memyselfandeye · · Score: 2

      It is Sony's fault, but it's not the victims fault. I still remember when I moved from small town New Mexico to Cleveland. It wasn't very long before my car was broken into, and it was "my fault" for leaving valuables in it. How is what happened to the victims of Sony's inept security, and victims of criminals who violated said inept security, their fault. That's akin to saying it's the fault of a rape victim for happening to be attractive towards a rapist. I'm not necessarily saying this is what you meant, but there sure are an awful lot of comments eluding that the victim who was stupid enough to use Sony deserves it.

      Why can't you live in a world where you can provide details to Sony without worrying about having your identity stolen? Why can't you live in a world where you don't need to lock your car? Why do we need SSH and public key encryption? Why can't you live in a world where you don't have to worry about any crime against property or person? I say it's because we've build a society that is great about protecting the rights of the accused, but does little to protect the rights of the victims. If these guys get caught, the will be afforded every conceivable protection against prejudiced trials... yet there will be no such guarantees for the victims.

    34. Re:people are stealing user info by malkavian · · Score: 1

      And what about people that only use people, not just techs?
      Most people I know wouldn't even know how to begin doing that.
      Could be a market opportunity to set up a simple one click thing to do it.

    35. Re:people are stealing user info by JohnRoss1968 · · Score: 1

      They have these neat little things called THUMB-DRIVES.
      You can store your passwords on those using several programs. I use Keepass myself but there are others out there if you just open up your eyes and look around.

    36. Re:people are stealing user info by justforgetme · · Score: 1

      well, it was morning. So I forgive me (see? I could have written myself there but I didn't)

      --
      -- no sig today
    37. Re:people are stealing user info by Dan541 · · Score: 1

      Users = People who fund Sony.

      --
      An SQL query goes to a bar, walks up to a table and asks, "Mind if I join you?"
    38. Re:people are stealing user info by jimshatt · · Score: 1

      Very small bank. Probably a sandbank.

    39. Re:people are stealing user info by N0Man74 · · Score: 1

      In this case....I don't feel sorry for anyone doing business with sony. From my point of view, they made their bed, now they get to lay in it.

      This was modded Insightful? This statement is moronic!

      Some of us did business with Sony years ago. Before they screwed over the 'Other OS" users of PS3s, before the rootkit fiasco, or even before the Playstation 2 disk read error epidemic was well known.

      My last dealings with Sony Online Entertainment were 6 or 7 years ago, and yet they still had data on me on their servers, Luckily *most* of it (addresses, CC info, etc) is out of date, but things like my email address, date of birth, and perhaps answers to some secret questions may have been compromised.

      So, it's *my* fault that I didn't predict the depths to which Sony would stoop in the future?

      I am a critic of Sony, as I think any sane person should be. You, on the other hand, are being anti-fanboy idiot.

    40. Re:people are stealing user info by Clever7Devil · · Score: 1

      I don't think there are many here who believe the hackers are doing the morally correct thing. Certainly far less evil than rape though. Furthermore, I find it hard to believe that Sony is being attacked due to its attractiveness as a target.

      It's a little bit more like a man calling a bunch of prisoners' mothers whores and then walking around outside the penitentiary backwards with your pants down. Sure, there's a wall between you and them, how long and how many do you think it will hold?

      --
      "By the time they had diminished from 50 to 8, the other dwarves began to suspect 'Hungry.'" -Gary Larson
    41. Re:people are stealing user info by Clever7Devil · · Score: 1

      Don't ask me how he got your pants. That's another story and it's early. ;-)

      --
      "By the time they had diminished from 50 to 8, the other dwarves began to suspect 'Hungry.'" -Gary Larson
    42. Re:people are stealing user info by Aldenissin · · Score: 1

      I agree with you quite a bit. However, I have to say that hardly anyone, even you, take security completely serious. It's not as if you never dreamed any of these companies could be "bad". You just don't care and are apathetic in a sense as virtually everyone is, since it is more convenient.

      In the end, you can't trust any company. Ok, that isn't correct. I trust everyone. That is what all relationships are based on, even enemies. I trust an enemy will try to screw me over. I trust these companies will sell me out for the sake of their "shareholders", even if I was one.

      Oh how much better the world would be if we did business with those self employed and perhaps even small business, instead of corporations. You hear all of the time, it isn't personal, it's just business. Bullshit. All business is personal, and anyone who says otherwise is just trying to shirk their civic responsibilities to their fellow man. Man is man because we work together, not because we can conquer each other. We conquered this earth together, and if we ever stop screwing each other over we can conquer virtually anything.

      But we won't. We instead want to listen and laugh at Doomsday predictors. Stay short-sighted and live to excess, living void and unfulfilling, meaningless lives.

      --
      Like a city whose walls are broken down is a man who lacks self-control.
    43. Re:people are stealing user info by Aldenissin · · Score: 1

      Mod parent insightful, not troll. He's right, it's not as if we haven't been warned that this info. is has easy transferability, and not securely watched over.

      --
      Like a city whose walls are broken down is a man who lacks self-control.
    44. Re:people are stealing user info by Anonymous Coward · · Score: 0

      WHAT THE FUCK! Hackers are the ones doing the bad here, yet they are being championed for showing how bad Sony is for letting them do what the do? Circular logic, fuckwad. GRAH! This whole thing with Sony really pisses me off. The fact is nothing is safe and we all know that, so fuck you for glorifying the stealing of documents as if pointing out nothing is 100% safe is noble.

    45. Re:people are stealing user info by Aldenissin · · Score: 1

      It is Sony's fault, but it's not the victims fault. I still remember when I moved from small town New Mexico to Cleveland. It wasn't very long before my car was broken into, and it was "my fault" for leaving valuables in it. How is what happened to the victims of Sony's inept security, and victims of criminals who violated said inept security, their fault. That's akin to saying it's the fault of a rape victim for happening to be attractive towards a rapist. I'm not necessarily saying this is what you meant, but there sure are an awful lot of comments eluding that the victim who was stupid enough to use Sony deserves it.

      It isn't "wholly" one's fault. However, with a but a few exceptions, we let most of what happens to us happen. If you stored a friend's expensive diamond jewellery (or left a kid and they were kidnapped, etc.) in your car, and it was stolen while you were living in Cleveland, I would bet she'd blame you. I don't live and Cleveland, and I know about Cleveland. No, you didn't and Sony customer's don't deserve it, but they did put themselves out there. Most here are being smug because they do it right now with the next bad boy corporation that will pop up on the radar.

      Why can't you live in a world where you can provide details to Sony without worrying about having your identity stolen? Why can't you live in a world where you don't need to lock your car? Why do we need SSH and public key encryption? Why can't you live in a world where you don't have to worry about any crime against property or person? I say it's because we've build a society that is great about protecting the rights of the accused, but does little to protect the rights of the victims. If these guys get caught, the will be afforded every conceivable protection against prejudiced trials... yet there will be no such guarantees for the victims.

      Why? Because people are evil in their hearts, that's why. Even under total surveillance people will still try to screw others over fi they think there is a chance to get away with it or they feel it is worth it.

      Those rights are to protect the innocents. They are put on trial too, which is the purpose of a trial, or did you forget? I agree we don't protect the rights of the victims. Even the evil people luckily for the most part still see they are better off (for now) with protections of the accused. If we wanted to protect victims, we wouldn't send people to schools for criminals (jail and prison) and instead bring back indentured servitude, for example. But we let those that are evil twist and distort logic to where indentured servitude=slavery.

      --
      Like a city whose walls are broken down is a man who lacks self-control.
    46. Re:people are stealing user info by Aldenissin · · Score: 1

      copying is akin to sharing. Stealing is taking something not meant to be shared. It is still copying if I share a movie/song and meant to, i.e. with a friend. If you take it from the publisher's servers and had to crack to get to it, that is stealing.

      --
      Like a city whose walls are broken down is a man who lacks self-control.
    47. Re:people are stealing user info by chickenarise · · Score: 1

      You always happen upon the gem after you used up all your mod points. *shakes fist*

      --
      One convenient locations...in Africa.
    48. Re:people are stealing user info by Anonymous Coward · · Score: 0

      My god, a positive comment about apple that wasn't modded into oblivion! The anti-apple trolls are slacking.

    49. Re:people are stealing user info by SuperTechnoNerd · · Score: 1

      Serves them right for buying an evil product from and evil company.
      You reap what you sow.

    50. Re:people are stealing user info by heypete · · Score: 1

      What, like LastPass?

    51. Re:people are stealing user info by memyselfandeye · · Score: 1

      A perfect example is our grand jury system. It used to be that any citizen could convene a grand jury and present evidence to convince the jury to indict a person. I don't see that happening anymore, and good luck trying to do it. So, let's say I was a victim of this crime and I thought it was my neighbor. I can't go and convene a grand jury on my own, I have to file a report at the police department and hope they will arrest the bugger and that the prosecutor will convene the grand jury. Thus, as a victim, I have no guaranteed right to try and get my pound of flesh, so to speak. I have to hope and pray my case is deemed worthy enough. This is why in small town America, where I grew up, there is an inherit distrust of non elected law enforcement. You have absolutely no recourse if the police decide they do not want to investigate your claim. And let's be honest, identity theft is rarely investigated because hey, they should have known better.

      I was really ranting about the claims that if you didn't know better it's your fault. Not locking your doors, or not using SSLcommunication against a sanitized SQL sever for Sony Service XYZ, doesn't magically make it OK to steal from you, or less severe if you get caught because hey "the guy was asking for it." As it stands now, we have no way of going after these guys on our own and the legal system has no incentive to do so. So the only solution is to keep updating your anti-virus, keep downloading patches, and keep on top of the latest security trends so that, hopefully, this doesn't happen to you. Don't you think that's unfortunate? I don't know about you, but I'd much prefer to spend my time elsewhere.

  11. Sony will be secure? by ohnocitizen · · Score: 2
    From TFA, some curious speculation:

    While it's cruel to kick someone while they're down, when this is over, Sony may end up being one of the most secure web assets on the net.

    Is there any evidence to back this up? I keep thinking of counter examples, the best one being Sony. They've been attacked how many times now, and they are still leaving security holes of this nature up? One would think after the first attack a company wide IT effort to harden their servers would have been given something other than the lowest priority...

    1. Re:Sony will be secure? by Anonymous Coward · · Score: 2, Insightful

      Yes, and you would think the airlines would strengthen the door after the first cockpit invasion back in the 30s or 40s, whenever it was, but we had to wait until the mother of all hijackings before this most basic move was undertaken.. What we will probably get is some kind of 'TSA' for the internet instead. History repeats itself in many ways.

    2. Re:Sony will be secure? by dakameleon · · Score: 1

      Give Sony a bit of a break, it's only been a month, and SCE & Sony Music are far enough apart within the overall Sony group for it to not necessarily have filtered all the way to testing the vulnerabilities in Hungary.

      --
      Man who leaps off cliff jumps to conclusion.
    3. Re:Sony will be secure? by the_enigma_1983 · · Score: 1

      I don't see how it'd take even a month to get that far. By the second attack, memos or something should be going company-wide, saying "People are trying to break into our networks, make sure stuff is secure".
      If it takes more than 4 weeks for an IT team to do a basic security audit (SQL injection means not using parameterized queries, so basic to spot and fairly simple to stop), then you simply haven't budgeted enough for IT. Which is a reason for the new problem but still a problem they had control over.

    4. Re:Sony will be secure? by Stone2065 · · Score: 1

      To add to your comment... a single person, working 8 hour days, works about 168 hours a month. Assuming even 5 people on this (a pathetically low number, I'll grant you), that's 840 man-hours. How much coding/investigating can YOU ALL do in 840 fucking hours?

      --
      Stone
    5. Re:Sony will be secure? by sgbett · · Score: 1

      Probably about 840 hours worth. I can't tell if you think thats a lot or a bit. Seems like a lot to me. Reckon they could at least have looked over all the code they have in that time, and spotted anything basic like, you know, SQL injection ...

      --
      Invaders must die
    6. Re:Sony will be secure? by Anonymous Coward · · Score: 0

      You're a fag.

    7. Re:Sony will be secure? by ohnocitizen · · Score: 1

      This ^. +1. These are very basic mistakes we are seeing exploited. Its almost as if this is a company that is unaware of basic security practices (they could check out owasp for some hints). What seems more likely is a company that has been hacked, and begun playing the blame game rather than taking even the most rudimentary steps to secure their system. A press release is not an effective server hardening tool, its more of a provocation. So "Its only been a month" doesn't seem like any kind of excuse for a company as large and wealthy as Sony. A company with an apparently cavalier attitude towards sensitive user data.

    8. Re:Sony will be secure? by plover · · Score: 1

      If we didn't have it in place already, I'd be using those hours to bring in a static code analysis tool like Fortify or Coverity or Klocwork to begin scanning my source code repositories for security flaws. Could I fix them all in that time? Highly doubtful. It mostly depends on the size of the codebase, but once you get millions of lines of code that have never been scanned before, the tools will likely identify hundreds or even thousands of vulnerabilities, including many false positives that would have to be weeded out. I just saw a presentation where the vendor estimated each XSS bug identified by a code scan takes about 94 minutes to fix, after he factored in testing and everything else.

      --
      John
    9. Re:Sony will be secure? by garyebickford · · Score: 1

      In a corporation that large, in an emergency it would probably take a month for management and legal to get the memo written, edited and approved for sending. If not an emergency, it could take much longer.

      Then, each team would have to reschedule other activities to make room for the 'mission from the Suits On High', figure out what things need to be fixed, work up a fix plan, build the fixes on the dev server, test there, get through the release process, and rollout to the production servers. After all, accidentally creating a new hole while fixing the old one would not be a good thing. So that's another month, or two.

      Since some of these teams work for various companies in various parts of the world, which are loosely held by the top level holding company, add another month just for the various companies to get the word from the holding company that something needs to be done.

      To add to that, from what I've read, the approach to work scheduling in Greece (and many other countries) is rather casual, so it might take an extra month to get the whole thing done there. "After all, who's going to go after us? We're just a little music service in East Podunk. Nobody's heard of us, and if they have, nobody cares!" (A too-common attitude of many companies toward security.)

      So, they're probably right on schedule, but the hackers can move much faster. Think PT boat vs. Battleship.

      --
      It's easier to be a result of the past, but more fun to be a cause of the future! http://www.spacefinancegroup.com/
  12. CL Jpb Ad by Anonymous Coward · · Score: 1

    Established company seeking security professionals, all positions open

    1. Re:CL Jpb Ad by Anonymous Coward · · Score: 0

      Established company seeking security professionals, all web sites largely opened

      FTFY

  13. Like it matters. by MrQuacker · · Score: 5, Interesting
    Anyone who's ever visited Greece knows nobody buys music there. For 2euro an hour you can visit an internet cafe, get the password from the guy at the front desk, and connect to the cafes local file server. Last time I was there they had something like 20TB+ worth of movies, music, tv shows, games, and porn.

    They decided that since people download stuff anyways, might as well save on the bandwidth and store it locally. Any time you download a file its mirrored in the cafes file server, so others can copy it without having to re-download.

    And if you dont go that route, you can buy bootleg copies from any number of African immigrants on the street for just a few euro. Many times for better quality than available in stores for retail price.

    1. Re:Like it matters. by Eravnrekaree · · Score: 3, Interesting

      Especially about the better quality, is the ironic truth. Remember those who were copying Star Wars Laserdiscs and making them into movie files, because the DVDs were often so slow in coming, and then the DVD releases were only of the new doctored versions and the original versions of star wars were impossible to purchase? The Laserdiscs of Star Wars were also reported to have better special features compared to the later DVD releases.Often times its impossible to get movies on DVDs from the companies, which basically is the companies tell fans, screw you, so fans just share the copies with themselves. For years companies have treated their customers like shit, and they then expect people to love them?

    2. Re:Like it matters. by Anonymous Coward · · Score: 0

      And people were wondering why the greeks needed a bailout...

    3. Re:Like it matters. by Psychotria · · Score: 2

      I don't think the music piracy is the point. I think that the point is that the public perception on Sony is being degraded; it has nothing to do with piracy as far as I can see. This is being reported in mainstream media now... would I trust Sony with any of my details? Not a chance. Additionally, these "attacks" must be costing Sony money... probably a lot of money due to not only customer's trusting them less, but the extra employees (or current employees overtime) and resources they need to spend to fix things.

    4. Re:Like it matters. by drinkypoo · · Score: 1

      I can verify that if you have the fat boxed set there are some nifty features. It also came with a big picture book if you bought the extra-fat boxed set.

      I only wish I had an LD player that would play more than 1 disc 2 sides. All the LD players which play 2 discs that I see any more are Karaoke units and they want real money for them... as if that were a selling point.

      --
      "You're right," Fisheye says. "I should have set it on 'whip' or 'chop.'"
    5. Re:Like it matters. by erdraug · · Score: 1

      Given that the average bootleg CD has an approximate lifespan of six months i doubt Greeks rely on them to build a music collection. I know mine is of the expensive variety. In hindsight, i could have listened to the radio more and done something else with that money instead. Like go to more concerts. Now what was the average price of a concert ticket in Greece again?

    6. Re:Like it matters. by PReDiToR · · Score: 1

      Also take it as given that if you're on holiday in Greece the music you're listening to there has a lifespan of six weeks and the longevity of the CD doesn't figure.
      Rip the thing to your hard drive if you want to have a copy of the latest Euro-pop to give your nephew/neice in a couple of months to keep them ahead of the curve and make them sound cool by having it before everyone else has it.
      But FGS, once your holiday drinkfest is over you won't ever want to hear that squeaky trash again.

      --

      Do not meddle in the affairs of geeks for they are subtle and quick to anger
    7. Re:Like it matters. by Colonel+Korn · · Score: 1

      Rip the thing to your hard drive if you want to have a copy of the latest Euro-pop to give your nephew/neice in a couple of months to keep them ahead of the curve and make them sound cool by having it before everyone else has it.

      Good luck finding a radio station or public space in Greece that doesn't play >75% bad American music.

      --
      "I zero-index my hamsters" - Willtor (147206)
  14. Your Mom by Anonymous Coward · · Score: 0

    Reading the last line of the description, I can guess what Sony's comeback line is going to be

  15. Plain text passwords?? by wvmarle · · Score: 5, Informative

    The linked article also provides a screen shot with obscured personal information.

    It appears the passwords are stored in plain text, not as hash: formatting makes it unclear but it seems the length varies, and the password fields are short (6-10 characters or so), while hashes are much longer than that.

    Bad bad security! No wonder they also fall victim to the age-old SQL injection attack... which I thought most SQL interface libraries can automatically intercept by adding the appropriate escaping... many years ago I used Pythons MySQLdb and they were doing that for very very long already... so there should be no excuse for allowing this to happen still.

  16. the world's largest public penetration test? by Anonymous Coward · · Score: 0

    the world's largest public penetration test?
    That title belongs to Snookie

    1. Re: the world's largest public penetration test? by CyberDong · · Score: 1

      Actually, I think it's Lisa Sparxxx at 919 guys.

    2. Re: the world's largest public penetration test? by Anonymous Coward · · Score: 0

      Mod parent informative.

  17. expect more by smash · · Score: 2

    Evidently, the playstation 3 firmware/network isn't the only instance where sony totally fails at securing their shit. SQL injection? Really? In this day and age? I'm simply shocked that it hasn't happened a lot earlier; they've been pissing people off for years now, its amazing its taken this long for a collective group to make a serious effort to try and break in.

    --
    I run: Windows, OS X, Linux, FreeBSD. Just because you have a hammer, doesn't mean everything is a nail.
  18. Public Shaming Test! by Anonymous Coward · · Score: 0

    Penetration test? Try Public Shaming test.

    It's simple. Piss off enough of the wrong people for reasons nothing more than you can, and you think it protects your bottom line, and they will embarrass you. Be it a Corporation, Government, or private citizen. The net is the ultimate perceptive level playing field. What we perceive as justice on-line, is in fact retribution.

  19. "Is Sony's network being used as ..." by QuasiSteve · · Score: 5, Insightful

    Is Sony's network being used as the world's largest public penetration test?

    No, every other scriptkiddie is just joining in on teh lulz of flogging the dead horse. "ZOMG I sql injectioned a SONY site! Yeah, it's got nothing to do with PS3 or PSN, and yeah it's some site in Greece, but lulz amirite!?"

    It's even in the bloody article, isn't it?

    As I mentioned in the Sophos Security Chet Chat 59 podcast at the beginning of the month, it is nearly impossible to run a totally secure web presence, especially when you are the size of Sony. As long as it is popular within the hacker community to expose Sony's flaws, we are likely to continue seeing successful attacks against them.

    It appears someone used an automated SQL injection tool to find this flaw. It's not something that requires a particularly skillful attacker, but simply the diligence to comb through Sony website after website until a security flaw is found.

    I mean.. honestly?

    They could be running this against $random_site and try to hit the news with it, too.. but they wouldn't.. because nobody cares about a random hack at a random site right now.. but if it's got SONY attached to it.. well.. lulz rules the news.

    None of which excuses the poor security.. but none of which excuses the submitter from his choice of words either.

    1. Re:"Is Sony's network being used as ..." by flimflammer · · Score: 1, Insightful

      Jesus Christ, man. How far did that stick get wedged up your ass?

    2. Re:"Is Sony's network being used as ..." by DurendalMac · · Score: 3, Insightful

      Kinda makes you wonder why Sony was vulnerable to exploits that could be found in skiddie tools. If someone had to actually dig for an exploit or found a new one to use against them, then that would be something, but when skiddies can breach your network then you seriously need to fire the guys in charge of security because they suck at their jobs.

    3. Re:"Is Sony's network being used as ..." by LordLucless · · Score: 5, Insightful

      As long as it is popular within the hacker community to expose Sony's flaws, we are likely to continue seeing successful attacks against them.

      It almost seems as if deliberately screwing people over doesn't really pay off, doesn't it?

      --
      Just because you're paranoid doesn't mean there isn't an invisible demon about to eat your face
    4. Re:"Is Sony's network being used as ..." by Cyberllama · · Score: 2

      There's a difference between "running a totally secure web presence" and "exploited by an automated SQL injection tool". If an auomated tool could find it, then you have to wonder why the hell Sony hadn't just run the damn tool themselves. There are levels of insecurity, and this level is well below what a company like Sony should be at.

    5. Re:"Is Sony's network being used as ..." by Anonymous Coward · · Score: 0

      Sure, the guy in charge SHOULD get fired. But let's face it, if anybody will be punished it will be some low-level IT worker. The one who wasn't allowed to update software and create secure systems because of management restricting resources to do so and creating a convoluted bureaucracy that makes security-critical updates impossible.

    6. Re:"Is Sony's network being used as ..." by Anonymous Coward · · Score: 0

      ... but when skiddies can breach your network then you seriously need to fire the guys in charge of security because they suck at their jobs.

      Like there ever were some guys in charge of security, eh?

    7. Re:"Is Sony's network being used as ..." by TheVelvetFlamebait · · Score: 1

      Right, because nobody with good customer service ever had bad security.

      --
      You know, there is a difference between trolling and pointing out the flaws in your reasoning. Just saying.
    8. Re:"Is Sony's network being used as ..." by Anonymous Coward · · Score: 0

      That or it was their objective all along to become the hacker community's world-wide punching ball.

      I mean, what's to like about Sony's corporate attitude these days anyways?

    9. Re:"Is Sony's network being used as ..." by LordLucless · · Score: 1

      But people with really, really bad customer "service" give people a reason to try and violate that security.

      --
      Just because you're paranoid doesn't mean there isn't an invisible demon about to eat your face
    10. Re:"Is Sony's network being used as ..." by TheVelvetFlamebait · · Score: 1

      Be honest; which situation do you think is more likely:

      a) After the PSN network went down and everyone's credit card details were stolen, other hackers just started to realise how evil Sony is, or
      b) After the PSN network went down and everyone's credit card details were stolen, other hackers just started to realise how weak Sony's security is, how easy it would be to gain the ability to brag that they took down a large corporation's security, and how much money they could spend with pilfered credit card details.

      Look me in the eyes and tell me that Google would be treated differently if their security was on par with Sony's.

      --
      You know, there is a difference between trolling and pointing out the flaws in your reasoning. Just saying.
    11. Re:"Is Sony's network being used as ..." by LordLucless · · Score: 1

      Fine, I'll tell you. Looking in the eyes is a bit hard, given the medium. And I'll have to go sort-a.

      It wasn't because everyone suddenly realised Sony had particularly porous security. I'm sure that their Greek web-portal's security had bugger-all to do with the security of the PSN. You speak like Sony's security is some monolithic entity; in reality, there's probably at least a dozen different teams responsible for security, from the ones who work on their DRM, the engineers who designed the PSN, the various CMSes used to run a multitude of public facing websites, and the internal network security of dozens of Sony offices around the world.

      What happened is, Sony became a "cool" target. Part of it is due to their behaviour, part of it was to do with a successful high-profile attack against them, and a large part of it is to do with the herd behaviour of the groups that do this sort of thing. It makes them feel good, like they are fighting "the man", and it gives them a whole lot of attention, because defacing some other company's server wouldn't get merely as much press as another Sony victim.

      --
      Just because you're paranoid doesn't mean there isn't an invisible demon about to eat your face
  20. SQL injection attacks fixed long ago by SuperKendall · · Score: 5, Informative

    I suspect that it will be a while before we see a real fix to the SQL injection problem as well.

    It's called a paramterized query and pretty much every language on the planet supports this mechanism.

    SQL injection is mostly a solved problem, except for programmers.

    --
    "There is more worth loving than we have strength to love." - Brian Jay Stanley
    1. Re:SQL injection attacks fixed long ago by plover · · Score: 2

      Parameterized queries by themselves aren't the panacea that people make them out to be. They still allow attack code to be stored in the database. Bad handling of the data deeper in the application stack, where protections aren't expected, might still choke on the code. You need 100% of the SQL queries in the system to be parameterized. Even then, they do nothing to prevent other language injection attacks to pass through, such as XSS attacks.

      As you say, it's a solved problem, if the programmers use it. And parameterized queries absolutely protect those particular queries from the malicious bastards, so I'm not knocking them in any way. I'm just saying that someone shouldn't naïvely claim "we're secure" based solely on that premise.

      --
      John
    2. Re:SQL injection attacks fixed long ago by Splab · · Score: 1

      Indeed you can inject JS or whatever if data isn't parsed correctly, but using parametrized queries will at least never ever expose the users credit cards, username, passwords etc.

    3. Re:SQL injection attacks fixed long ago by yarnosh · · Score: 1

      As you say, it's a solved problem, if the programmers use it. And parameterized queries absolutely protect those particular queries from the malicious bastards, so I'm not knocking them in any way. I'm just saying that someone shouldn't naïvely claim "we're secure" based solely on that premise.

      I think that goes without saying. The GP just said that SQL injection is a solved problem.

    4. Re:SQL injection attacks fixed long ago by maxwell+demon · · Score: 1

      You know, "we're secure against SQL injection" isn't the same as "we're secure". Of course storing non-SQL related things which might be used in other attack forms (like XSS) in the data base is completely unrelated to SQL injection attacks (unless the SQL injection is used to get that code in because otherwise the system is well secured against it). Just like it won't help your security if you protect against all sorts of attacks, but post your admin password on the main page.

      --
      The Tao of math: The numbers you can count are not the real numbers.
    5. Re:SQL injection attacks fixed long ago by nstlgc · · Score: 1

      You failed to refute his point that parameterized queries fix SQL injection attacks. Indeed it does not protect against XSS attacks, buffer overflows, aids, cancer and greed, but nobody claimed that it would.

      --
      I'm Rocco. I'm the +5 Funny man.
    6. Re:SQL injection attacks fixed long ago by RyuuzakiTetsuya · · Score: 1

      Parameterized queries still don't keep you off the hook from sanitizing your database inputs. Even if you're using something like the PDO object to generate and prep DB queries, in the end, MySQL's looking for a string for input.

      The real solution is getting away from sending SQL queries to DBs in string format, as the root poster hinted at, but, sanitizing DB inputs really isn't the hardest job to do, nor is it the biggest problem we face.

      --
      Non impediti ratione cogitationus.
    7. Re:SQL injection attacks fixed long ago by vegiVamp · · Score: 1

      If your "deeper" code chokes on your data, it hasn't been coded correctly, and neither has your data insert mechanism. You never, ever, ever trust input. Ever. You validate and clean input as it comes in, before it goes into the database. If you're going to do things to data you get out of the database that could be dangerous - say, eval() it, you check it again when you fetch it.

      Yes, that makes proper programming look like a lot of error handling. That's because IT IS, because that's the only way to prevent that kind of shit from happening. Live with it.

      Also, XSS attacks through database-stored content, while also preventable by validating data input, does not fall under the header of SQL injection, and thus aren't expected to be stopped by bind variables.

      --
      What a depressingly stupid machine.
    8. Re:SQL injection attacks fixed long ago by Anonymous Coward · · Score: 0

      I suspect that it will be a while before we see a real fix to the SQL injection problem as well.

      It's called a paramterized query and pretty much every language on the planet supports this mechanism.

      SQL injection is mostly a solved problem, except for programmers, testers, and managers.

      That's better.

    9. Re:SQL injection attacks fixed long ago by Anonymous Coward · · Score: 0

      By your words, 100% of SQL needs to be parameterized. That's not insurmountable.

      And the parent only said parameterized queries would prevent SQL injection, not all forms of XSS/injection attacks. We're only talking "LIttle Bobby Tables" type problems.

    10. Re:SQL injection attacks fixed long ago by tequila13 · · Score: 1

      paramterized query

      Now with SQL injection solved, if only we could figure out a way to make computers check the spelling ..

    11. Re:SQL injection attacks fixed long ago by SuperKendall · · Score: 1

      Now with SQL injection solved, if only we could figure out a way to make computers check the spelling ..

      The need for consistent spelling is the mark of a little mind - or a QA person.

      --
      "There is more worth loving than we have strength to love." - Brian Jay Stanley
  21. Almost by kimvette · · Score: 1

    I almost feel bad for Sony.

    Almost.

    --
    The Christian Right is Neither (Christian nor right). See: Matthew 23, Matthew 25, Ezekiel 16:48-50
  22. If these hackers had REAL balls... by Anonymous Coward · · Score: 0

    ...they would do this against Islamic sites. But like I say, no balls.

  23. anon nymous by Anonymous Coward · · Score: 0

    Double penetration test, i'd say...

  24. Sony by SigmaTao · · Score: 1

    *facepalm*

  25. Sony LCD TV one of the better ones. by syousef · · Score: 1

    Don't even bother with the Sony TVs. They do make some nice TVs, but so do Samsung and Sharp (Aquos anyway, their budget sets don't hold the same value proposition) for quite a bit less money. I can't think of a single line of Sony products that doesn't butt up against better and cheaper competition. They are just coasting and selling the name to people old enough to have bought their first nice TV 20+ years ago when Sony actually gave a crap.

    When I was shopping for TVs last year the Sony was one of the better ones for input lag. Not great mind you. The Aquos was great for input lag but had terrible sharpening artifacts. It was like watching a cheap and cheerful Chinese brand TV and I couldn't stand it in the store so I didn't buy it. Samsung has become awful for input lag - as in unplayable on a console.

    I ended up with the Sony 55ex500. Not a bad tele but some annoyances. Definitely would do better with a second tuner as the guide sucks, and some annoying bugs on the menu (like most recently watched channels don't work). Apart from these 2 annoyances and first unit replaced due to dead pixels in the first week, the TV has been trouble free and served my young family well. Great sound and picture (with minor tweaking to set up). Great fun with the Wii. Fantastic Bluray. Lots of inputs. (Some slight picture stutter in full res panning for some titles, even with 100Mhz gimmick, but livable). And it was the cheapest of the bunch. The geek in me also hates that you can't downgrade firmware - new firmware always a risk with the tele. If I could find better I would have bought it. I have no love of Sony.

    What was striking was how bad input lag had gotten on most models, and how quality had gone down even quicker than price for all manufacturers. Few now have decent dead pixel policies.

    --
    These posts express my own personal views, not those of my employer
    1. Re:Sony LCD TV one of the better ones. by drinkypoo · · Score: 1

      How much time did you spend playing with the controls on the Aquos? Mine was a bit that way when I got it but I was able to tone it down. I had a 32", traded it for a compressor and air tools, and now we have a larger one in the living room. (The 32" was in my room, then it migrated out, then it was too small for the living room... it worked out great.) This set (which we got at costco) seems to have just one problem, getting input7 and input8 (both hdmi) confused on occasion. It would be hilarious if it weren't the single most expensive thing we own that doesn't roll. It's still kind of amusing since it rarely happens, is cleared up by a power cycle, and is the only blemish on an otherwise fantastic set. And it has the absolute minimum lag...

      --
      "You're right," Fisheye says. "I should have set it on 'whip' or 'chop.'"
    2. Re:Sony LCD TV one of the better ones. by syousef · · Score: 1

      I only spent a minute or 2. I didn't need to tweak the other TVs in the shop, nor was I confident that I would find a set of settings that would work well for all movies etc. It really was awful. ANY of the other sets - even the cheap ones - looked stellar compared to that grainy pixelated picture. I was horrified and ran a mile in the opposite direction.

      I really do wish they'd fix those 2 issues on a newer firmware...but I'm not holding my breath. Sony seems to only take things away with firmware upgrades.

      --
      These posts express my own personal views, not those of my employer
  26. Root kit by Anonymous Coward · · Score: 0

    Sorry, Sony deserves it all. Root kit!

  27. Story Tags by Anonymous Coward · · Score: 0

    so is the tags for this article really just a game of "one of these things is not like the other"?

  28. public penetration test by n1hilist · · Score: 2

    Heh heh, Sony's gettin' shafted!

  29. Sony should have learned from Little Bobby Tables by Cyberllama · · Score: 1, Redundant

    This never gets old to me.
    http://xkcd.com/327/

  30. I am a sick and twisted little man.... by Anonymous Coward · · Score: 0

    ... that the first thing I thought of upon reading the article summary found myself thinking that it was a lead-in to a "that's what she said" joke.

  31. I love the smell of napalm in the morning by ras · · Score: 5, Insightful

    Is Sony's network being used as the world's largest public penetration test?"

    No more than HB Gary was.

    To wit: This is the prescription for being attacked mercilessly, for months on end:

    1. 1. Produce an item that is clearly advertised as having feature X, where feature X is useful only to really, really good programmers. You know - the ones who spend their time cracking the hardest problems using array of specialised parallel processors.
    2. 2. Sell the item to lots of people, who hand over their money on the basis of having feature X.
    3. 3. Some years later, withdraw feature X, so the all the software these people have invested years in creating is blown away.
    4. 4. When said programmers then fairly legitimately, extract your secret keys so they can restore feature X, unleash a phalanx of lawyers to peruse them within an inch of their financial lives, until they recant.

    At that point you will discover what sort of damage a bunch of really pissed off top notch programmers can do.

    With luck all the other psychopathic mega corporations around the world are watching and learning. The lesson is simple: don't poke a hornets nest.

    1. Re:I love the smell of napalm in the morning by andydread · · Score: 0

      +5

    2. Re:I love the smell of napalm in the morning by Anonymous Coward · · Score: 0

      Money says... Of all the lessons sony will learn from this... They won't learn that one.
      The right one.

      On the upside we can look fwd to more of these epic sony fuckups because they are clueless.

    3. Re:I love the smell of napalm in the morning by Anonymous Coward · · Score: 0

      "top notch programmers" are shitty little sociopaths?

    4. Re:I love the smell of napalm in the morning by thsths · · Score: 2

      > This isn't about other OS, it is about blocking people like you who don't think that they should have to pay for games. Freeloading pirate.

      There seems to be absolutely no evidence to support this statement. The position of Sony on illegal games has not changed, but the position on other OS has. And the whole thing started just weeks after other OS was disabled - is that a coincidence? I don't think so.

    5. Re:I love the smell of napalm in the morning by Anonymous Coward · · Score: 0

      Funny, I seem to recall a few obscure stories about a genius filesystem developer who also happened to be a murderer...

    6. Re:I love the smell of napalm in the morning by Bios_Hakr · · Score: 1

      If you build software on top of locked hardware, then you should *never* update the systems until you test what the updated will break.

      Now, there may be a group out there that is concerned about not being able to replace failed units. But I doubt any *really* good programmers were bothered by a PS3 firmware update.

      --
      I'd rather you do it wrong, than for me to have to do it at all.
    7. Re:I love the smell of napalm in the morning by Anonymous Coward · · Score: 0

      "top notch programmers" are shitty little sociopaths?

      Ah, no. That would be you. Being the shitty little sociopath, that is. Yeah, I had to spell it out, since your inadequate little excuse for a "brain" would most likely not understand it, unless I did.

  32. LULZ by elucido · · Score: 1

    Poor Sony.

    Maybe if they cared as much about their customers as they do about profits and making money, this could have been avoided or at least negotiated. But now it's out of control. It's game over.

    The hackers aren't going to stop. Sony needs to hire cyber warriors.

  33. How does this even happen? by rebelwarlock · · Score: 4, Insightful

    One of the first things you learn about web programming is to clean any string a user touches. If there's even a remote possibility that a user submitted something, clean it before putting it in your query. How is it even possible that someone would be given money for web programming before learning this? That's not even a rhetorical question; I'm genuinely interested in the answer.

    1. Re:How does this even happen? by Roobles · · Score: 0

      How is it even possible that someone would be given money for web programming before learning this? That's not even a rhetorical question; I'm genuinely interested in the answer.

      First thing that comes to my mind is nepotism.

    2. Re:How does this even happen? by Anonymous Coward · · Score: 0

      Then I shall answer: Because he was charging less than the the guy who would have done a good job. It's that simple.

      There are two type of corporate management: Managers and Leaders.

      Leaders are the current trend and have been for over a decade.

      Leaders are brain dead morons when it comes to risk assessment. After all, it's money spent over a "maybe".

    3. Re:How does this even happen? by Anonymous Coward · · Score: 0

      No, please don't do that. What you're describing here is a way to break your program while retaining a false sense of security.

      SQL injections and the like involve putting untrusted user input where you shouldn't, i.e. placing it where code execution takes place. SQL libraries support parametrized queries which allow you to pass user input separately from the SQL code completely avoiding the problem altogether. You can never filter any possible malicious user input, and you'd always break legitimate user input that your program should handle, ending up with a program that is not only insecure but doesn't work. To look at a failure of early filtering/escaping see PHP's magic quotes - now that's a disaster. And if you do it right before putting it in the query there's always a risk that you forget to escape it - not so if you use paramterized queries where this doesn't matter.

    4. Re:How does this even happen? by Tei · · Score: 1

      Maybe that was the first program written in PHP for the people that created this. Literally, the first program (even before a hello world), created even before the programmer learned everything else. Is even possible that the original author/authors have now the experience to know that you don't have to do this, but have never be able to go back and fix things. The "if is not broken, don't fix" is broken.

      --

      -Woof woof woof!

    5. Re:How does this even happen? by Anonymous Coward · · Score: 0

      One of the first things you learn about web programming is to clean any string a user touches. If there's even a remote possibility that a user submitted something, clean it before putting it in your query. How is it even possible that someone would be given money for web programming before learning this? That's not even a rhetorical question; I'm genuinely interested in the answer.

      Because Management said "Git 'R Dun! If you don't get it out the door in 2 days for $50, we've got some folks in India who will!"

    6. Re:How does this even happen? by WuphonsReach · · Score: 1

      Because 80-90% of the people out there think testing and QA is answered by the question, "does it work?". And they believe that as long as it works then it is written correctly.

      Proper QA requires knowledge of the system and understanding the weak points. Then you construct test cases to break the software on purpose and make sure that the tests cover those weak points. It is not testing for success, it is testing to make sure it doesn't fail.

      --
      Wolde you bothe eate your cake, and have your cake?
  34. 7:0 not 6:0 by Anonymous Coward · · Score: 0

    From the original source:

    Yesterday , we have reported that On 5th May, 2011 - Sony BGM's Greek website was also got hacked. One of Them Provided the Full extract database from the site. b4d_vipera was the hacker who Deface the site using SQL injection method. There are 8385 users on this website. Sample of hacked Database was leaked at http://pastebin.com/WqLysjiN. This was 7th Attack on Sony.

  35. They probably wanted to save money by elucido · · Score: 4, Insightful

    It's cheaper not to hire or pay for information security.

    And when they do they probably don't hire the best. Let's face it, Sony is not innocent and I could care less what happens to Sony. I don't own Sony stock, I don't work for Sony, and I don't own any Sony products except for an old PSX. So I just don't care what happens to Sony.

    Maybe other companies will now give a shit about information security.

  36. Sony. Hacked. Again. Yawn. by Anonymous Coward · · Score: 0

    About time someone went after Apple? Comparatively Sony isn't THAT evil.

  37. testing whether Slashdot... by BlueScreenO'Life · · Score: 1

    ... is vulnerable... ' ;  SELECT * FROM master.dbo.tables; DROP DATABASE master;

    1. Re:testing whether Slashdot... by Posting=!Working · · Score: 4, Interesting

      I know you were trying to make a joke, but since about 2-3 weeks ago, if I click my username in the top right, I get "The user you requested does not exist, no matter how much you wish this might be the case. "

      It's just a theory, but I think the != in the middle of my username has something to do with it.

      --
      This sentence no verb.
    2. Re:testing whether Slashdot... by jonamous++ · · Score: 1

      happens to me, too (++). If you use the character codes in the URL it works; for me, I have to use http://slashdot.org/~jonamous%2B%2B

    3. Re:testing whether Slashdot... by LearnToSpell · · Score: 1

      I know you were trying to make a joke, but since about 2-3 weeks ago, if I click my username in the top right, I get "The user you requested does not exist, no matter how much you wish this might be the case. "

      It's just a theory, but I think the != in the middle of my username has something to do with it.


      I think so too, since your username appears to be 'Posting =! Working'

    4. Re:testing whether Slashdot... by Posting=!Working · · Score: 1

      For some reason that didn't work for mine. However, I just found out that you can replace the username with the UID and it will pull up my comments.

      --
      This sentence no verb.
  38. this only needs to be done when changing the movie by YesIAmAScript · · Score: 1

    And to get a digital movie to play also requires security clearances and internet passwords, it won't simply play on any projector, you need to get it authorized. So not changing the lens at the same time is a problem with incompetence or sloth.

    No, it isn't the Sony DRM giving customers an inferior product, it is the theaters. Analog projection showed us they don't really see image quality as a big factor in their business success. You were lucky to get a projector with the film held steady in the gate, well lit and in focus, so is it a surprise theaters don't take their responsibilities any more seriously for digital?

    As a person who is sensitive to flicker (a bit) and to jumpy film images, I have to say the rock-steady images of digital (and with quite even brightness usually too!) is not an inferior product. It's a greatly superior product. I don't know who is making the projectors I'm seeing though, could be Sony, could be anybody.

    --
    http://lkml.org/lkml/2005/8/20/95
  39. Good. by crhylove · · Score: 0

    How about Sony come out, publicly apologize, disintegrate their entire company, and give all their money to a fund to help end corporate power globally.

    Until they do all that, I fully applaud Anonymous. ROCK ON BROTHERS! FREEDOM!

    --
    I hold very few opinions. I hold information based on observation and fact. If you wish to disagree, please use facts.
  40. I really *really* wish... by Zapotek · · Score: 1

    ...they used my scanner. It would be so fitting. Sony BMG Greece hacked by a vulnerability found by a scanner written by a Greek dude.
    That would be completely worth the development effort.

  41. world's largest public penetration test? by Anonymous Coward · · Score: 0

    world's largest public penetration test

    Dude, that's my sister you're talking about!

  42. I don't believe that record by Anonymous Coward · · Score: 0

    As much as I love watching Sony get their comeuppance, I find a report of "Hackers: 6, Sony: 0" to be a bit sensationalistic. Are we to believe that Sony hasn't beaten any hacker attempts? We only hear about the ones that work in favor of the hackers, so a more believable record is likely to be "Hackers: 6, Sony 10000".

  43. could NOT care less!! by pablo_max · · Score: 0, Troll

    For the love of God, the saying is COULD NOT CARE LESS!
    Think about it. By saying, I could care less, you are saying that it is possible for you to care less then you do, which means you do care what happens to Sony.
    It is endless annoying that people cannot get the simplest things right.

    1. Re:could NOT care less!! by Lillebo · · Score: 5, Funny

      endlessly

      ftfy

    2. Re:could NOT care less!! by Anonymous Coward · · Score: 0

      I'd change the saying, but I could care less what you think.

    3. Re:could NOT care less!! by maxwell+demon · · Score: 2

      For the love of God, the saying is COULD NOT CARE LESS!

      But he could care less: He could care so little that he wouldn't even bother to post about how little he cares about it.

      --
      The Tao of math: The numbers you can count are not the real numbers.
    4. Re:could NOT care less!! by Anonymous Coward · · Score: 3, Informative

      It comes from the full phrase "I know naught and could care less." So when people say they could care less, they mean they could care less than naught. People who are unfamiliar with the classics hear "I could care less," and get confused and angry because they aren't familiar with the actual quote. But their anger just displays their ignorance. "I could care less" is the original and correct, and "I couldn't care less" is the ignorant "correction."

    5. Re:could NOT care less!! by bipedalhominid · · Score: 1

      Ok, I don't care very much at all. That still leaves plenty of room to care even less. Am I right? Besides saying "I could care less", sounds way cooler than I could care even less. It just rolls off the tongue so well that it has become the way to express this particular sentiment. This is about the Cool Hand Luke factor not being technically accurate.

      --
      This aint Daytona and you aint Dale Earnhardt. So stop trying to draft on Interstate 40.
    6. Re:could NOT care less!! by Anonymous Coward · · Score: 1

      The original phrase is "You know nothing and you care less, as people say." (Mansfield Park (1815), which precedes the usage of "couldn't care less" by about 130 years ("couldn't care less" became a popular phrase in the 1940s). It's the people who think they're being grammatically correct who are wrong on this one.

    7. Re:could NOT care less!! by bipedalhominid · · Score: 1

      I could care more but I find myself caring less. Could not you just say I couldn't care less?

      --
      This aint Daytona and you aint Dale Earnhardt. So stop trying to draft on Interstate 40.
    8. Re:could NOT care less!! by Anonymous Coward · · Score: 0

      Amen Bro

    9. Re:could NOT care less!! by Anonymous Coward · · Score: 0

      It is endless annoying that people cannot get the simplest things right.

      Hey pablo_max, here's a tip for ya... when you're being a spelling or grammar Nazi, you should use that "preview" function to make damn sure your response is utterly perfect before submitting. When you don't do this, it ends up being you who looks like the moron.

    10. Re:could NOT care less!! by garyebickford · · Score: 1

      Hmm. I think that the result is two phrases that are both OK.

      "I couldn't care less" is a perfectly reasonable, grammatically and logically 'true' statement (if said truthfully.

      "I could care less" is a shorthand phrase derived from a longer original phrase. It can also be considered as assuming a prepended "as if", which adequately describes its ironic character.

      So, they're both right! :D

      Of course, I could[n't] care less. :)

      --
      It's easier to be a result of the past, but more fun to be a cause of the future! http://www.spacefinancegroup.com/
    11. Re:could NOT care less!! by doccus · · Score: 1

      You might be interested to know, that i received a failing grade in a post-secondary essay, in large part because the *english* teacher was insistent that the correct term was 'could care less' .. over my protestations.. my insistence that *he* needed a refresher is what led to the less than stellar grade (!)

  44. Sony Music Greece Falls To Hackers by Anonymous Coward · · Score: 0

    People need to learn that "they get what they deserve".

    When dealing with a corporation (or any corporation, for that matter), one only needs to look at their history of behavior. Almost all behave "badly". Years ago I took this to a personal extreme: I explained to my family that if they decided to continue supporting certain corporations by purchasing their products or services, that upon my passing they would be required to submit to an audit of their purchases for the preceding 3 years. For every dollar they spent with a corporation that I did not approve of, they would forfeit $5 of potential inheritance. They were flabbergasted, to say the least. Sony was one of the listed companies. My decision to add Sony to my list of banned economic entities was initially based upon their inclusion of the now infamous music CD root-kit. In hindsight, a good decision. They have not learned from their mistakes. IMO, they deserve to lose their charter.

    Having said all of this, if the average Joe decides to continue to support a company that obviously has no scruples, then Joe gets what Joe deserves. Better sign up for that identity theft insurance ASAP, Joe. That's my advice. /anon.

  45. Someone forgot to post the actual dox by Anonymous Coward · · Score: 0

    Here it is: http://pastebin.com/WqLysjiN

    You can thank me later...

  46. Only six? by RyuuzakiTetsuya · · Score: 1

    I'm going to stop being a blatant sony fanboy and defend the ridiculous shit they've done, but, only six?

    between PSP releases 1.50 and 6.20, there's way more than just six points for the hacker team.

    --
    Non impediti ratione cogitationus.
  47. But should not encourage laziness by Kupfernigk · · Score: 1

    Obviously a parameterised[sic] query prevents the most obvious forms of injection attack, but it alone does not protect against everything. Although it can be tedious, all data returned in forms should really be checked for syntactical legitimacy. Apart from anything else, this makes it easy to distinguish between accident and malice, and so know when to pop up a box saying "please check that the contents of each box make sense before clicking Submit" and when to put up a 404 and block the IP for a while. On a large commercial website, the development cost per submission is quite low, and failing to validate data is a stupid corner to cut.

    --
    From scarped cliff or quarried stone she cries "A thousand types are gone, I care for nothing, no not one."
  48. Hit a Honeypot ? by What+the+Frag · · Score: 1, Interesting

    http://pastebin.com/WqLysjiN

    If these is actually an excerpt of the actual data, then it looks like test data for me. Look at the passwords. They repeat a lot but grouped with ascending order. For example in the middle of the file there are a lot of "123456" passwords, but nowhere else. As the data seems to be ordered by u_usr this seems to be very unlikely.

  49. Re:this only needs to be done when changing the mo by makomk · · Score: 1

    And to get a digital movie to play also requires security clearances and internet passwords, it won't simply play on any projector, you need to get it authorized.

    The normal theater staff have the authorizations for that, though. I'm not sure what Sony, theater chain or distributor policy is on giving access to projector innards, and I suspect this is a closely guarded secret.

  50. Hell yes. by Stone2065 · · Score: 1

    Yes... yes it was... as it was funny as shit. :)

    --
    Stone
  51. As expected by Anonymous Coward · · Score: 0

    Well, Sony has a skilled security staff, the only issue is that they are too busy implementing DRM in the PS3 and all their other products to have some time left to secure their web servers.

  52. less THAN you do by starsky51 · · Score: 1

    Think about it.

    --
    There are 2 types of people in this world. Those who understand ternary and those who don't.
  53. Re:Applied for a job lately? by Anonymous Coward · · Score: 0

    When was the last time you applied for a job that didn't require dumping all you're info into some company's (or their 3rd party contractor’s) website?

    But I'm sure they have way better security than that small under funded company from Japan hardly anyone had heard of before the last month. /snark

  54. Warning: Spoiler by Eevee · · Score: 1

    In the Robin Hood stories, Little John was actually a rather large person.

    1. Re:Warning: Spoiler by smelch · · Score: 2

      Just because a phrase becomes idiomatic and loses its full context when spoken or written does not mean you need to get on the internet and "correct" people for using the idiom simply because you do not understand where it came from.

      In other news, when people say they "literally" did something when obviously they didn't, they don't misunderstand what the word "literally" means, they are just exaggerating. By correcting them you either come off as a jackass, or you come off as somebody that really struggles with the meaning of the word yourself.

      Nothing is worse than a know-it-all who doesn't.

      --
      If I can just reach out with my words and touch a butthole, just one, it will all be worth it.
  55. Sorry, but.. by mcgrew · · Score: 2

    Anybody who trusts Sony after all the various customer-rapings Sony has committed in the last ten or fifteen years deserves to have their data stolen.

    Fool me once, shame on you. Fool me twice, shame on me. If you buy Sony you're begging to be abused.

  56. Dear Sony.... by Lumpy · · Score: 1

    How is that new PR plan going?
    was it really a good idea to make everyone hate you?

    --
    Do not look at laser with remaining good eye.
  57. Irony by Gi0 · · Score: 1

    One user, when he registered in Sony's site, entered this "8elo pl na ma8o pios diavazei ayta ta e-mail" which is greek for "i would really like to know who's reading these emails".

    --
    There's no patch for stupidity
  58. I'll get my coat by queBurro · · Score: 1

    sql injection? since it's a greek site maybe they were only worried about... trojan horses?

    --
    sag
  59. Obligatory by Willtor · · Score: 1

    Little Bobby Tables' mom strikes again.

    --
    "The knee is the elbow of the leg." -- My wife
    1. Re:Obligatory by Tetsujin · · Score: 1

      Little Bobby Tables' mom strikes again.

      I guess those kids at school actually were right, when they said his mom was at the center of the biggest public penetration test ever performed.

      --
      Bow-ties are cool.
  60. Sony and the Internet by TheNinjaroach · · Score: 1

    Sony just doesn't get it. They don't know how to do business online. The internet has been a pain in the side of their movie and record labels, so Sony neglects it as much as they can get away with and this is what happens.

    --
    I went to eat some animal crackers and the box said, "Do not eat if seal is broken." I opened the box and sure enough..
  61. Sony DRM by Anonymous Coward · · Score: 0

    If Sony DRM is involved, it probably is closer to an ATM than a generic projector. Need I remind you about the insane Sony rootkit disaster? They have a history of going overboard on such things.

  62. Hopefully they have by THIS point though by Anonymous Coward · · Score: 0

    Stored Procedures &/or Bind Variables are that lesson:

    "I'd say if one thing's certain, then that Sony doesn't learn jack from the attacks." - by Opportunist (166417) on Monday May 23, @12:41AM (#36214128)

    I think that by THIS point though, they will have. It's very "public" @ this point, & embarassing.

    Imo @ least? For SONY to "stall out" the possibility of SQL Injection attacks, they need to check on their sites + implement the techniques I noted above, keeping as much business logic out of their "front ends" on their sites & do more server-side too (being sure said DB engines & webservers are secured also, of course).

    APK

    P.S.=> Not a SONY user here (well, I do have a SONY burner but it's been problem-free for ages now, since 2006 iirc?), so this doesn't affect ME personally or directly.

    I hope the same holds true for you folks also, & if not? I hope some of you have @ least written them as to what needs doing (e.g.- stored procs + bind variables usage on interactive data utilizing websites)... apk

  63. Secure in all the wrong places.... by ThreeDeeNut · · Score: 1

    What I find most intriguing in all of this is that "security of their product" is more important than the "security of their customers information". I mean seriously how many millions did SONY spend on securing their music, videos, and other "media". I forget what device it was but I remember my last SONY product was one where the data could only be read by a SONY reader... I think it was a voice recorder I bought for a client. None the less, their products are secured from the user, but the user is not secured at all. Maybe if they spent the money they wasted on DRM on securing their network and innovating like they did in the past they would be a viable company, but i guess that being greedy got in the way of their profits. Didn't they recently try and jail/sue some kid for modding his PS3? I mean seriously, shame on you SONY. Get your house in order and try to remember that your customers wants and needs dictate your ability to do business. Your profits will soar if you bring back your old ways of being innovative, delivering quality and most importantly delivering what the customers want. Your lawyers and money guys should be the ones jailed for your pathetically weak grip on reality. Forcing people to buy your crap will never equate to growth... instead it will be a slow downward spiral like a dookie in a toilet bowl. On the topic of DRM also, wasn't it sony who's profits soared through blank cassettes? That was thinking outside the box and winning on both sides of the coin. DRM, suing modders, proprietizing every piece of media (ie: mini-disk, memory stick, etc) is certainly the fastest way to the bottom of the bowl. JMHO As for HiFi audio, SONY never peaked my interest... I went Denon long ago and ill prolly never go back.

  64. HOSTS files won't help here by Anonymous Coward · · Score: 0

    Some "FYI" above in my subject-line: Though HOSTS files are excellent for giving users more speed & security online, and vs. many things like malware or adbanners that may be infested with malscripted content (& just slow you down as is and you pay for it literally in your billing from your ISP/BSP, worse if they go by "bandwidth cap used" billings)? This is 1 circumstance where a HOSTS files' versatility is not helpful really.

    APK

    P.S.=> I also realize that you're trying to "troll me"... do something useful with your life instead of attempting to bother myself, or others, with b.s. trolling & sarcasm! apk

  65. SQL injection? Stored Procs & Bind Vars by Anonymous Coward · · Score: 0

    Either way? Those "generic procedures" should cover OTHER attacks like this one!

    Until then?? They'll either:

    ---

    1.) Learn by it & correct it (stored procedures &/or bind variables usage in website code, for starters)

    OR

    2.) Keep looking poorly!

    ---

    Then, it's a matter of gaining back folks' trust... the hardest part I imagine!

    APK

    P.S.=> It's not THAT "big of a deal", nowadays @ least, to create a bind variable + stored procedures driven site that uses DB access...

    (Heck - I've done it myself professionally, a few times, since 1998 for various businesses, & if I can manage it? So can the coding teams for SONY!)

    * After all - It's not as if they don't have the coin to hire on teams for it, or even license softwares IF needed (if they're not using a LAMP/WAMP stack that is) in DB engines &/or WebServer programs! apk

  66. One phrase: by MarkVVV · · Score: 1

    What goes around, comes around.

  67. The real score by AdamHaun · · Score: 1

    Hackers: 6, Sony customers: 0

    Let's not lose sight of who's actually being hurt here.

    --
    Visit the
  68. Off topic troll "tips his hand", lol... apk by Anonymous Coward · · Score: 0

    Talk about "tipping your hand' troll! To wit:

    "Some (many) of us are tired of you're trolling and would like to be able to mod you down." - by Anonymous Coward on Monday May 23, @01:08PM (#36219132)

    Speaking for "everyone" now? Why don't you GET ON TOPIC instead, first of all... &, LMAO - Well, the "TRUTH COMES OUT": You're only out to "down mod" me... lol, how badly have I utterly kicked your ass on things technical here that you have to resort to THAT "old troll trick"? Pretty badly evidently!

    Well, too bad: You're not going to EVER 'get your wish'...

    So I get that "last laugh" on THAT account, easily!

    (And, I get to post as much as I like as well, as AC... no stupid "10 posts per 24 hr. period" unfair discrimination of AC's holds me down on that note either!)

    ---

    Secondly: Quit giving orders & acting as if you are "the master of life", ok? New NEWS/Newsflash: You're not!

    "First off, why don't you just get an account instead of posting AC?" - by Anonymous Coward on Monday May 23, @01:08PM (#36219132)

    Why? I post as much as I like as AC, & I don't give a hoot about "mod points". If I have something good to say, I say it in reply. I do the same even if I have critique. I.E.-> I gain NOTHING by being a registered user, and if anything based on what you state below? I gain hugely by posting as AC instead!

    ---

    "I realise that you honestly believe what you say APK, but you don't think before you post, and you do stupid things." - by Anonymous Coward on Monday May 23, @01:08PM (#36219132)

    Stupid according to you, but what's even more stupid is saying you want to "mod me down"? For what?? B.S. reasons??? Too bad. You can still mod me down even if I post as AC... I just make it harder for you fools that stalk me here doing it is all, by my posts as AC instead!

    (Tough cookies for you).

    ---

    "Like sign the above post twice. " - by Anonymous Coward on Monday May 23, @01:08PM (#36219132)

    Oh, yes, I see: YOU are the "master of things posting", right? Just like you are the "master of living life" too, right??

    (WRONG! Get over yourself, lol!)

    ---

    "Hell, I am posting AC, since I know how you will stalk people, and I can't think of the last time I did, because I don't really care about hiding my identity. " - by Anonymous Coward on Monday May 23, @01:08PM (#36219132)

    Then why are you trolling me as AC then?

    (No, your b.s. here, it doesn't fool anyone... give up, lol!)

    ---

    "But you scare me, and others too." - by Anonymous Coward on Monday May 23, @01:08PM (#36219132)

    Well, "you & yours" troll? You don't scare me in the least... especially with your typical "off topic trolling" replies like this one!

    ---

    "Some look at your posting history (way before /.)and laugh. " - by Anonymous Coward on Monday May 23, @01:08PM (#36219132)

    Oh, really? I have hundreds of mod ups, even as an AC poster.... would you like to see them??

    ---

    "I just get concerned. " - by Anonymous Coward on Monday May 23, @01:08PM (#36219132)

    No, you're a troll that's off topic & full of it... and you KNOW it.

    You "tipped your hand" above, with saying you want to "down moderate me" IF I had a registered account. Give us a break - talk about a "very telling reply" on your part!

    ---

    "Not sure if this helps, but I'll put it this way. From reading someone's collection of posting links and your hatred of certain people you claim that have impersonated you" - by Anonymous Coward on Monday May 23, @01:08PM (#36219132)

    I don't "hate" anyone here. I merely find them amusing and VERY easy/simple to get the better of on t

  69. Learn English and get on topic by Anonymous Coward · · Score: 0

    Learn to write English properly

    Some (many) of us are tired of you're trolling and would like to be able to mod you down.by Anonymous Coward on Monday May 23, @01:08PM (#36219132)

    You need to stay on topic here, troll. In that statement of yours quoted above alone, You've given away your motivations by saying you want to down mod the person you replied to.

    You are the one who is off topic here and deserve the down moderation.

  70. Sounds like You stalk apk by Anonymous Coward · · Score: 0

    Between you're stating you're down modding him and want to continue to do so, offtopic as you are

    Some look at your posting history (way before /.)and laugh. by Anonymous Coward on Monday May 23, @01:08PM (#36219132)

    That gives me the impression you've been stalking him online for quite a while now. Your posting as ac and not even giving anyone an indication of who you are only furthers that impression in fact. You've given yourself away as just another offtopic stalking online troll.

  71. Comment removed by account_deleted · · Score: 1

    Comment removed based on user account deletion

  72. tomhudson: AC stalking/trolling me AGAIN? by Anonymous Coward · · Score: 0

    tomhudson's coming around here trolling myself via AC posts again, AND TELLING OTHERS TO JOIN him in it also!

    Proof?

    Ok, I'll let tomhudson speak for himself on that very account:

    "Wait until he starts on another kick, then reply to him as an AC. It's the new meme". - by tomhudson (43916) on Sunday May 09 2010, @08:29PM (#32150544) Homepage Journal

    QUOTED VERBATIM FROM -> http://slashdot.org/comments.pl?sid=1646272&cid=32150544

    AND, "True to AC STALKING TROLL FORM"?

    Tomhudson did so again, repeatedly, here:

    http://slashdot.org/comments.pl?sid=2086424&cid=35841122

    and here also:

    http://slashdot.org/comments.pl?sid=2086920&cid=35840680

    It's obvious this is you yet again, tomhudson.

    (You can stop now, the jig's up: Your own words did you in, as per your usual!)

    APK

    P.S.=> tomhudson - If the "best you've got" is AC stalking & trolling me, instead of disproving any technical points I make? LOL @ U, tomhudson

    ... apk

  73. Re:Sony should have learned from Little Bobby Tabl by Cyberllama · · Score: 1

    Whoever modded me down as redundant really should have noticed that my post was 40 minutes before the other one. The other just happened to be in response to one of the first threads posted. Bah, oh well!

  74. Great more problems! by Anonymous Coward · · Score: 0

    I hope this has nothing to do with the Qriocity or Music Unlimited because its working great now! I don't want to get bad news again from Sony! Also damn you kids or hacker's for messing up the PlayStation Network! You should all be put in prison for hacking it! maybe you should look it up Invasion of Privacy act!