The Sony Pictures Hack Was Even Worse Than Everyone Thought
An anonymous reader writes with today's installment of Sony hack news. "It's time to take a moment of silence for Sony Pictures, because more startling revelations about leaked information just came out and employees are starting to panic. BuzzFeed raked through some 40 gigabytes of data and found everything from medical records to unreleased scripts. This is probably the worst corporate hack in history. Meanwhile, Fusion's Kevin Roose is reporting on what exactly happened at Sony Pictures when the hack went down. The hack was evidently so extensive that even the company gym had to shut down. And once the hackers started releasing the data, people started 'freaking out,' one employee said. That saddest part about all of this is that the very worst is probably still to come. Hackers say they stole 100 terabytes of data in total. If only 40 gigabytes contained all of this damning information, just imagine what 100 terabytes contains."
I mean it seems likely they got everything. Even the model numbers of the kitchen sinks.
How long was the attack taking place? What kind of Internet connection does Sony Pictures have? To ex-filtrate 100 TB of data is going to take a while, no matter how you cut it. My guess is that number is significantly inflated.
100 terabytes of data is easily consumed by the raw uncut footage of a few movies, easily. So it could be a whole bunch of stuff that really hurts them or it could just be a couple movies that were shot by M. Night Shyamalan that suck so hard no one cares.
Persistent Volume manager for Kubernetes - https://github.com/dwimsey/openshift-pvmanager
What is Sony doing with medical records?
There's a lot of talk going around right now, mainly from Sony itself, that North Korea is likely behind it. Seriously though - would expect a bunch of people who don't know what Internet is, who likely don't live and breathe IT, security - basically everything capitalism stands for, let alone having a pipe fast enough to rip 100TB of data...
Now I understand they could be trained and based elsewhere, but might as well say the Martians did it...
Really? 20 people - each with 5TB drive? Thats 100TB.
So Sony with its rookits and DRM get owned. Good. How does it feel, Sony? How does it feel?
Hope this causes massive losses for them and horrors for its employees.
http://en.m.wikipedia.org/wiki... TL, DNR: 9 years ago, Sony was root kitting the machines of people who bought their CDs, and living about it.
How long before we see Sony's flagship console jailbroken like the PS3?
For that matter... we'll probably see the PS3's keys brought up to the current version, as well.
How did 100 TB get to North Korea over their dial up modem without anybody else noticing?
NSA sleeping that the wheel?
Five-eyes? All navel gazing?
Nobodies looking at the data going to North Korea?
More and more this seems like a false flag.
As an insider of the SONY Dictatorship, I am shocked this has not happened earlier..
I truly hope this sheds some light on the Wrong doings of this conglomerate.
The time of taking advantage of your constituents in rude, unprofessional, and immature ways should be over..
While I will admit there are some good people inside, but unfortunately they are all covered up, trampled, or set aside for money, ego, fame and or plunder.
to get some background on the statements bade above, look at SCEA's shady past as one example of how the SONY juggernaut runs..
Thank you,
It doesn't burn. It just warms the heart. ;)
The government which is strong enough to protect you from everything is strong enough to take everything from you.
So, does this mean that the Supreme Leader is cutting the cord?
I've just been reading some of the articles, and it seems that in fact Sony has unfortunately been storing a lot of communication that contains discussion of medical issues amongst other things.
This is an example of where a company could have done a better job of assessing the risk of retained data becoming a liability and applied suitable retention policies and other risk mitigation strategies like encryped storage (some articles suggest most files were not meaningfully protected).
IT folks and legal departments in today's climate should be asking themselves what is being stored, what are thr benefits, what is a liability, what is the actual business need, what are the mitigation options.
It would cost ~$3,500 retail for 100TB - easily accomplished by 1 individual.
In case anyone else was looking for the missing link in TFS, Kevin Roose's article at Fusion is here.
Thanks to the War on Drugs, it's easier to buy meth than it is to buy cold medicine!
At first they thought the data was fake; all the scripts read like movies everyone has seen already.
Seriously, how did they manage to steal "100TB" worth of data, without physically going there and copy a bunch of disks? You'd think SOMEONE would notice if there was an intruder downloading everything. 100TB can't exactly be downloaded in a few minutes there, it would take days, if not weeks. Even at 1Gbps, that's about 10TB a day, all day long, top speed. Surely, I'm not the only one who think Sony was highly negligent toward network security, again, here...
The live portion (I.e. Last 2 months) of my companies billing database is 23TB, 100 could be the raw footage of one movie.
Persistent Volume manager for Kubernetes - https://github.com/dwimsey/openshift-pvmanager
This is Sony Pictures. The raw video for movies that they are shooting are stored online for editing equipment. One or two movies could easily take up 100TB of disk.
Is there any information about how long it took hackers to steal this 100TB? Did no one notice the unusual amount of traffic? I have a 40Mbit connection at home and with overhead I can usually download at up to 4Mbytes/sec. At that rate 100TB is something like 300 days of 24/7 downloading. Even if I had a gigabit connection directly to sony that would take 12 days!
I mean it seems likely they got everything. Even the model numbers of the kitchen sinks.
I would expect they also got some fairly damning privileged information--emails exchanged with lawyers on everything from sexual harassment to copyright infringement suits. It's a BIG firm.
Plus Patents. Sony files THOUSANDS of patents a year. If that patent information (or research that could be patented) is published to the wild before SONY patents it, you have a LOT of new prior art and a fortune in IP at risk... SONY would have to patent everything within a year in the US; I am not sure that you even have that grace period everywhere else.
(a) NOVELTY; PRIOR ART.—A person shall be entitled to a patent unless— (1) the claimed invention was patented, described in a printed publication, or in public use, on sale, or otherwise available to the public before the effective filing date of the claimed invention ...
(b) EXCEPTIONS.— (1) DISCLOSURES MADE 1 YEAR OR LESS BEFORE THE EFFECTIVE FILING DATE OF THE CLAIMED INVENTION.—A disclosure made 1 year or less before the effective filing date of a claimed invention shall not be prior art to the claimed invention under subsection (a)(1) if—
(A) the disclosure was made by the inventor or joint inventor or by another who obtained the subject matter disclosed directly or indirectly from the inventor or a joint inventor; or
(B) the subject matter disclosed had, before such disclosure, been publicly disclosed by the inventor or a joint inventor or another who obtained the subject matter disclosed directly or indirectly from the inventor or a joint inventor.
Transferring 100 TB @ 100 Mbit/s would take about 12.5 days 1TB == 1048576 Mb
1048576 / 100 ==> +/- 10485 secs
104857 / 60 ==> +/- 174 mins
1747 / 60 ==> +/- 2.9 hours
That's just 1 TB, so multiply the last number by the number of TB.
I made this: http://www.bpftpserver.com
What makes Sony relevant as a company are it's people, their skills, their connections, the power they have to move the industry, the content rights they own, the technologies and products they develop, their brand, etc. etc.
100tb can leak today and be irrelevant within 12 months because life continues and projects move on. I'd say in the wake of massive disclosure employee morale may be the biggest factor in the recovery.
Note the modifier "business data".... Not videos, not apple pie recipes sent by Aunt Bertha... If you are talking about strategically stored data and not user home folders, the signal/noise ratio is significantly better.
I have no problem with your religion until you decide it's reason to deprive others of the truth.
Why was all that shit stored where it could be hacked?
One word "convenience", if corps (and regular people) would get over "convenience" this crap wouldn't any near as often.
"If any question why we died, Tell them because our fathers lied."
This is either bullshit, or you're doing it very, very wrong.
Even assuming a dumbass flat file at 4 KB per row for 62 days, that's over a thousand rows per second.
Was this hack the result of poor security, or will every single company in the world now see what has happened, over-react, and unleash draconian security measures that far exceed the point of diminishing returns?
No matter what you think of Sony, this will not be good for the productivity of the corporate working world.
"Who are you?" "No one of consequence." "I must know." "Get used to disappointment."
With all the state-sponsored corporate & military espionage caused by China & Russia, with the never-ending probes from government agencies like the NSA/DHS/GCHQ/etc., with malware & ransomware attacks that can encrypt data in (generally) unbreakable forms, with criminal hacking organizations making off with millions of credit card numbers from retailers, with apparently no network controls as to how much data leaves company firewalls & where it goes, and so on, why aren't there more internal air-gapped networks in companies???
This has hit the point of absurdity. If you are working on military plane designs, working on your next corporate acquisition, or even making movies or music worth tens of millions of $$$, why would you put your prized, unreleased digital files on computers that have Internet access? What kind of batshit stupidity is that? What, so your employees can browse Facebook & check Outlook e-mail at the same time? Such an air-gapped network would easily become an island--one that doesn't need Windows Updates, can stay on an old service pack, gets no software updates that solves 2 problems and but makes a new one (e.g. we know the bugs), and the like. And if those employees really need their Outlook e-mail, IM, or the Inter-Webs where they work, they can have a 2nd very low-end PC, connected to the main network, with a KVM between the two. Might even increase efficiency, given the mind's inability to multitask well. Or give them freaking iPads on a wireless network that's not connected to their "sensitive" work computer.
It boggles the mind that given all these problems, which are increasing in frequency & cost every day, we still have little more than software firewalls & hardware routers between a company's most highly-sensitive assets (files & computers) and the big-bad-Wild-West-no-holds-barred-Internet.
Windows 3.1x calc: 3.11 - 3.10 = 0.00
If you aren't in Africa, you can do it to. That's about the only place that doesn't make enough to make it "easily accomplished" by a dedicated person.
Learn to love Alaska
How do you steal 100 TB of sensitive data without any network, database or IDS alerts going off?
I'm pretty sure sony ships out it's films via network to the theaters these days. When a new release comes out, and they dump a terabyte or so to a few thousand theatres... 100 TB could easily be missed or ignored.
"Upon analysis of the same WIPALL malware family, its variant BKDR_WIPALL.D drops BKDR_WIPALL.C, which in turn, drops the file walls.bmp in the Windows directory. The .BMP file is as pictured below: link
What Sony lacks in ethics it makes up for with incompetence.
"This is either bullshit, or you're doing it very, very wrong."
Please. I can use more bandwidth than that (and do) on a daily basis with my Camfrog video chat server.
The raw text data from the multiple horticultural facilities I monitor across the globe hits 30TB daily before compression or conversion into nice little charts.
What fucking era are you from, the stone age? This is (almost) 2015.
Still waiting on Serviscope_minor to wake up to fucking reality and realize that Jessica Price isn't going to fuck him.
If only 40 gigabytes contained all of this damning information, just imagine what 100 terabytes contains
The same thing 2,500 times?
Sony has 140,000 employees; 40 gigabytes is already 280K per employee, so there's probably not much left to reveal just based on quantity alone.
Have you read my blog lately?
This is either bullshit, or you're doing it very, very wrong.
Even assuming a dumbass flat file at 4 KB per row for 62 days, that's over a thousand rows per second.
You don't do databases do you? You have no idea what they are storing.
I did some stuff earlier today that generated over 100Gig of transaction logs in just a few hours.
Granted that's unusual, but it does happen, and if they're not cleaning up after things like that?
Who says it's not ATM transactions and he's logging a video of every transaction as it passes by?
Who says he doesn't work for Equifax and isn't storing 50 million transactions a day?
And his point is valid. The raw footage for a single movie, with all the uncut footage? Easily could surpass 100TB uncompressed.
Well, it is probably linked to the fact most of these companies are international companies with employees all over the world needing some form of interaction with the data.
If you really want to get an internal network that is disconnected from the internet, it means that you will need an army of monkey copying data using memory sticks to feed the data bank and bringing reports back to the employee that needs it. And that induces super high latency in the system.
The problem seems difficult to me. Completely isolated networks might have an unreasonnable operational cost. (Though a massive data breach might just be as bad.)
> If you are talking about strategically stored data and not user home folders, the signal/noise ratio is significantly better.
Not in any business I've worked at. Anything that is slightly valuable goes to the central data store so it will be backed up, and then never gets deleted because who knows when you just might happen to need it.
Sort of like what happens on my home system too.
Note the modifier "business data".... Not videos, not apple pie recipes sent by Aunt Bertha... If you are talking about strategically stored data and not user home folders, the signal/noise ratio is significantly better.
Actually, it may have been all of those things, including personal crap.
This is a hacked account, for which the owner can not be held responsible.
If you aren't in Africa, you can do it to.
Even in Africa it's easy. I get hundreds of emails a week from Africans telling me about how they've got $150 million USD and they need my help...
Maybe this information can undo some of the damage you've done TO YOUR CUSTOMERS.
* Undo the malware drm you put on peoples PC's.
* Restore the ability to run Linux on game consoles that you wrongfully stole back AFTER you sold it.
* Unlock the bootloaders on your android phones.
Who knows what else. Probably a LOT of good can come from this. But the most important? Don't piss off your customers!
This sig intentionally left blank.
I'm not a big fan of Sony (although I like their electronic products because of their high quality) or big companies in general. However, a breach of this size could literally destroy the company if the amount of information that leaked yet to be revealed is even worse than what has already been revealed. The litigation nightmare this could cause in the US is appalling in itself but that could just be the tip of the iceberg because of all the corporate secrets that are now out in the open (or will be).
It's really quite a simple choice: Life, Death, or Los Angeles.
now let us all hurry up and move our entire digital lives to the Cloud!
I can assure you, the best way to get rid of dragons is to have one of your own.
You're forgetting he's using XML...
You are not alone. This is not normal. None of this is normal.
"In the letter, Sony defended its decision to wait five days to admit its security had been compromised and called on the government to help make the internet safer."
They asked for outside help (expected the government to stop it) and apparently took security a bit lax in one area.
"In the letter, Sony defended its decision to wait five days to admit its security had been compromised and called on the government to help make the internet safer." http://www.buzzfeed.com/tomgar...
I did get two free simple games over that one, I expect money this time they need to take their security a bit more serious. I mean even shutting down the gym (who knows why, terminals?
Once burnt twice shy, not something Sony is familiar with.
I'm so glad I didn't take a job at Sony after my last time being interviewed by them....
I employ people in the USA in small IT and EE/IC specialty design shops. Most expert-level employees seem to come with white or grey hair. One of my IT geeks is a "MT Dew Diabetic." Avoiding the maintenance of medical records is simply not an option in the USA, given our laws and court rulings. We have to comply with ADA (Americans with Disabilities Act), keep records of workman's comp medical restrictions, including very specific information, on what an employee may and may not do as well as provide emergency information to first responders. While often inconvenient, these are requirements I cannot avoid. Some of my employees have medical conditions (heart conditions, organ replacement, severe allergies, diabetes, unusual prescriptions of controlled sumstances, etc.) that they want known and available to first responders showing up at the office if they collapse clutching their heart or go into a sugar coma. Complicating this, if one of your customers is a Federal agency or Defense, you must, by law, have a "zero tolerance policy" for controlled substances. All this requires records to prove or excuse. For government accusations, corporations are "effectively guilty" until they prove themselves innocent with appropriate record keeping. Making this even more difficult, USA court rulings say we're also not allowed to store this information in their personal files, but must keep it in a separate, access controlled file, otherwise we could get sued if that person missed a pay raise or promotion because it was available to anyone reviewing their service and discipline records. The separate files seem silly when the teams are small enough that everyone knows each other very well anyway. Also, what if the employee who first greets the medics from the ambulance don't have easy access the secured medical files? Isn't that an even worse problem? Sued if you do. Sued if you don't. Sued if you didn't do it the nuanced way a team of $300/hr attorneys thinks you should have half-way done it. Nuisance suits are common in the USA.
As a practical matter, a lot of valuable talent is not healthy. Many experts are experts because they have been at a speciality for 30-60yrs. If you have an employee that has an epileptic seizure, you don't want the rest of the team to stand there confused and gawking. You want them to recognize it and intervening to protect that individual's head and spine from injury. I had an employee with mental health issues under the care of a psychiatrist. While she was physically 100% capable (she was young and athletic) yet she was restricted from certain emotionally triggering situations. You want their supervisor trained know what those are and how to avoid it. You want a written record, periodically refreshed, that her supervisor knows and understands. You could say "I don't want to deal with that" but then you lose out on some great talent. Imagine a physics institute that didn't want to deal with maintaining medical records for Stephan Hawking.
As you yourself said, "their connections, the power they have to move the industry" carry a lot of weight. A lot of people inside and outside Sony could have their reputations ruined by these leaks. The film industry is full of gossip and jealousy, and people often say things in private that can be incendiary if they get loose. If someone with big clout is offended, a lot of current and future deals could go out the window. Grudges are real, and can last a lifetime.
And even non-bigwigs can be wrecked. Suppose someone takes time off, or has other issues from stress and uses prescription medication as a result. This could easily end up in personal records. This gets out, and that person could find themselves unemployable anywhere. Not even able to get a minimum wage job in retail or fast food, much less the entertainment industry. Remember, there are a lot of show hires and workers are transient, so there are a lot of ex-employees with records at Sony.
Sony could be on the hook for a huge class actions suit, particularly if you consider ex-employees. No matter how long ago it was, if you name shows up online as a result of this breach you have a valid reason to sue.
And Sony is not a well regarded company in Hollywood. They are known for squeezing the life out of people and then giving them the boot. They routinely have layoffs while they are advertising for new hires. (Everyone in Hollywood does this, but Sony is a prime example.)
They keep a few people around but nobody lasts because it's cheaper, and transient workers are no threat to bad upper (or middle) management. Bad practice can be hidden if there is no one around to complain or remind anyone of previous mistakes. (Just ask anyone who has been cycled through Disney about this.)
Given the combination of ill will and a lot of ex-workers, don't be surprised when the civil actions start. Sony doesn't have a leg to stand on, particularly on personal records. They had no partitioned networks/systems, no encryption, and didn't detect the breach until they were screwed. It's going to be just like drug lawsuits: there will be multiple late night commercials fishing for anyone who worked at Sony to join in.
Hollywood is a schadenfreude kind of town. There will be a lot of movie industry types who will derive a lot of satisfaction from watching Sony suffer mightily because of this.
Why is Snark Required?
I "almost" feel bad for Sony.
No. No I don't. Could not have happened to a more deserving corporation.
I do feel bad for the employees though so I'm not completely heartless.
And there we have it. All those bazillions of taxpayer dollars wasted listening in on Aunt Tilly's scintillating description of the quilting bee and they totally missed the biggest ever hacking of a corporate system by a hostile foreign power.
Their faces would be beet red if they weren't so shameless.
Putting on my IT geek hat, I'd say the term "system" or "same system" is rapidly losing its meaning in the age of "server fabric" and virtualized computing resources. You have systems of systems. Accessing everything from video editing apps to timecard and budgeting submission apps or web-pages from the same workstation, possibly at your home, on the day you telecommuted, using your "federated security credential" on your key-logging terminal. The key-logging pretty much by-passes all security from full-disk encryption, VPNs and secure sockets to compartmentalization and containment schemes, all of which become irrelevent. You don't even need to infect or access the target workstation to key-log it to gain access to bigger systems. Many of the attack techniques have been published or hinted at by security firms, ars technica and commented on by slashdotters over the years. In some of the more interesting techniques, attackers use your smartphone's microphone or your Xbox's Kinnect features.
I don't actually know, but I would speculate that a state-sponsored actor, such as North Korea, can point a low-power laser at your window as you type on your keyboard and a small, crude app can statistically deduce which keys are being struck by both the rhythm, frequency and a differential analysis of the resonant frequency signatures inherent in each keystroke. Don't believe it's possible? Try this simple test. Listen carefully to the tap of your ~tilde key in the upper left corner. Now tap a "home" key such as D, F, J or K. They don't sound EVEN CLOSE in tone of click...do they? Precise tonal frequency differentiation is trivial for a low-end 80's era microphone and 80's era processor. While North Korea likely didn't create the acoustic key-logging technology, they likely can get their hands on it as long as the share the "intelligence take" with their Chinese or middle-eastern eavesdropping equipment suppliers, who most likely also hate Sony even more than some of Sony's consumers.
North Korea has it in for anything Japanese. Strict middle-eastern religions include some great electrical engineering types and are likely outraged by the hot women in Sony's movies. who typically don't cover up in Burkas and have the audacity to drive themselves in cars and argue with men. China wants control of the Asian-Pacific region and wants all the intel, server access and compromised foreigners it can manage to obtain without upsetting its western-civilization consumers of Chinese-made goodies like Lenovo Thinkpads and Apple iPhones.
At 50 fps 4K video takes about 3,8 TB / hour. Do double that for 2 hour movie. (8 TB). Count in the shooting ratio of raw material:finished film, which can easily be even bigger than 10:1 in multiple camera multiple shoots scenario. That's 80 TB for just one movie.
Get somebody's SSN, birthdate, name, sex, employer, home address, etc, and identity theft becomes much easier.
I'm not repeating myself
I'm an X window user; I'm an ex-Windows user
My condoleances.
On the other hand, it's very beneficial for our society that this sort of data now becomes a matter of public record simply because I'm pretty sure that the extent of data that is collected on employees hasn't been documented quite so clearly and unequivocally before.
Besides which, it's well-documented that law-makers and public opinion generally aren't pro-active on basis of insight, intelligence, or commonsense. No, it always requires one or two actual cases of things going totally wrong to get people's attention. And even then it takes a couple of repeats before the shoot-the-messenger reflex can be bypassed and the underlying issues addressed.
In addition, the release of business information gives a valuable historical reference on how the corporate world works in a way that transcends books and even court records (which are usually sealed anyway where commercial interests are concerned).
So, in this respect, society as a whole benefits from this example of computer-burglary. Now if we could only make the data available in its entirety, or at least in coherent chunks ...
Maybe such a prime target like Sony ought to lay off the whole 'cloud storage' thing and go a bit luddite. Use paper instead of e-mails, tape instead of digital--older mediums of information. Heck, use typewriters again. Sure, their offices may wind up looking like something out of Brazil, but a lot harder to hack. It certainly is awful what Sony did with their DRM spyware on consumers and some may call it karma. Perhaps this can be a learning experience and a way for Sony to take a new approach. Then again, maybe Sony will watch the end of Brazil and want to go that route with consumers instead.
"SO we bide our time, waiting for a purer kick to bloom and the future is still bleak, uncertain and beautiful" -GSYBE
Saying the attack in from korea just because the attack came from a korean IP and/or there are korean files there, is saying like I was mugged by Stevie Wonder because "I just called..." was playing on the radio. Technical people know better than listening to political propaganda drivel.
and the name of the Operation should be called "OP GEOHOT". Gibson would be proud.
Hackers say they stole 100 terabytes of data in total
Indeed. At, say, 100 Mbps (~ 10MB/s) on the Internet - that's fast - that would take 10 million seconds, or 116 days full time...
Slashdot, fix the reply notifications... You won't get away with it...
http://www.zdnet.com/article/b...
There's been plenty of wakeup calls since the movie "The computer who wore tennis shoes" came out, or maybe even before. Taking the easy and lazy way out is seen as better than waking up and doing something sensible.
A lot of places do it very, very wrong. Amazing how scanned HR paperwork can expand to fill a larger amount of data than highly detailed geological survey data of very large areas.
At 50 fps 4K video takes about 3,8 TB / hour. Do double that for 2 hour movie. (8 TB). Count in the shooting ratio of raw material:finished film, which can easily be even bigger than 10:1 in multiple camera multiple shoots scenario. That's 80 TB for just one movie.
Don't forget to add 5/7/12.1 channels of high quality uncompressed audio to go along with it.
Wanna buy a shirt?
https://www.redbubble.com/people/stealthfinger/shop?asc=u
i helped that prince out once, good guy, he even offered to give me 10 million if i let him park some money in my acct. I should probably go check on it as i am sure the money will be there any day now
have you seen my sig? there are many others like it but none that are the same
Before or after taxes?
I can't answer that for Sony in particular, but I can tell you with absolute certainty why it happens at smaller companies that could easily segregate such sensitive systems from the general corporate network...
"Damnit, $peon, I don't give a damn about HIPAA or PCI or SOX! Make it so I can get to all the files I want, from my desk computer, or I'll find someone who can. Don't worry about it, just keep the bad guys off our network, and we'll have no problems. What??? No you can't lock down my computer so I can't browse por... er... financial news sites at lunch!"
The problem comes from the people who do legitimately need access to such data considering themselves "too important" (and naturally, infallible) to follow the policies and procedures required to maintain meaningful access limitations. That, and the people who actually understand the need for an air gap almost never having the authority to say "tough, you work for this company, and this company requires that you do it this way".
"Do you know who I am???"
After all, all we care about is hacked nude selfies.
Air gaps work great and are cheap when they are only 3 feet wide- everywhere along the circumference of the inner "island".
When your "island" has to cover multiple states and time zones at the same time, it becomes very unwieldy to strictly maintain that air-gap. Why do you think the DOD classified networks cost so much and have so many regulations concerning them? Have you ever priced what REAL hardware encryptors cost?
- speaking only for myself, as always
And you've just failed security 101.
Airgapping does not make you immune to everything. e.g. Windows Updates. A lot of those updates are to fix patches against physical exploits. And by airgapping you've increased your attack vector (because I am assuming here with your basic statement that you didn't think of how data will get in and out of the network including security patches). Then you're also assuming that the reason there was no airgap was due to Outlook and Facebook rather than
Airgapping is rarely ever the answer. Understanding and breeding a culture of corporate security is. Knowing how to design networks with layered protection so that the computers themselves remain useful is.
So how did companies handle such networks 20+ years ago, where employees in "other offices" (cities, other locations in the same city, etc.) could access files, databases, etc., without any vector out to the Internet? Wouldn't be that hard to create a disconnected network island "war room" in each office--disconnect some ports & buy new routers. The real issue ultimately becomes that you now might want to consider multiple such air-gappped networks (e.g. R&D, HR, Finance, etc.)
I have to assume that data breaches are much worse cost... This one has lost sales, lost goodwill, lawsuits, potential government fines (e.g. HR data), network design changes, etc. Even a $10 million air-gapped network would have been a bargain compared to this mess...
I'm still waiting for a massive Salesforce data breach... That'll be interesting when it happens.
Windows 3.1x calc: 3.11 - 3.10 = 0.00
Remember back a few years ago, when Sony decided the best way to combat piracy was to install a rootkit on the machines of anybody who played one of their CD's?
I hope I can be forgiven for reminding them of a couple of good old adages. Adages like, "What goes around comes around", "Karma's a bitch", and "Sauce for the goose is sauce for the gander".
And I hope they'll forgive me for my complete lack of sympathy.
I've calculated my velocity with such exquisite precision that I have no idea where I am.
Wasn't Lockheed hacked a couple of years back? My understanding is that quite a good amount of data regarding a variety of weapons systems, including data on the F-35, was stolen. I don't know how the volume of data stolen compares, but it seems to me like a far more significant hack than stealing a bunch of shitty film scripts and some employee data.
How did companies do things 20 years ago?
They racked up lots of frequent flyer miles, spent hours on long distance calls, and made FedEx a household name (and very profitable). Did I mention the conference calls where people on the East coast had to stay at work late to talk to people on the West Coast?
- speaking only for myself, as always
I suspect that because Sony is a Japanese company, and has their headquarters in Japan, likely has most of their important datacenters in Japan, which unlike the USA, has incredible internet speed, and because Sony is a tech monster, likely has some pretty serious connections to their stuff.
Now couple that with what we have already seen of general network incompetence with the last huge Sony breach to their Playstation network, due to them simply not updating their software to a version several years out of date, I don't think it is all that surprising.
However you are right, 100TB is nothing to sneeze at, and would take some time, and likely multiple connections to work. I suspect that Sony was clueless about what was going on, until someone complained about slow network connectivity, and eventually some sysadmin started looking at things, and started to see connections, and bandwidth saturation, and then trying to figure out who was doing it, and on finding it wasn't Sony, needed approval about severing the connections (if even technically that easy)... and once approvals and technical fix were done, well 100TB is gone.
I suspect with the amount of interconnectedness of distributed networks, it wasn't as simple as walking outside with an axe.
Explain how airgapping doesn't make you immune to Windows Updates? If your PC can't talk to Microsoft, and unless you're going old-school sneakernet with flash drives, how is it going to get updates? Most Windows updates solve some sort of security hole, usually caused by the execution of malicious software or some sort of security hole that's exploitable from the Internet. Take away "the Internet" and lock down what people can execute on their PCs within "the island" and problem solved. Yes, you now have a known unpatched security hole--but one that can't be exploited without access to the Internet. No malicious links, attachments, unauthorized software, browser toolbars, etc. Just people using limited specific software & specific versions on (for example) Windows 7-SP1.
As has been proven by Stuxnet and this breach, unlimited state-sponsored funds ALWAYS beats "networks with layered protection". Big-name companies that spend shitloads of money on security still get breached. 15+ years of "breeding a culture of corporate security" also hasn't worked. But if you require the network to have a physical presence, then you've eliminated your primary attack vector.
Windows 3.1x calc: 3.11 - 3.10 = 0.00
Such an air-gapped network would easily become an island--one that doesn't need Windows Updates, can stay on an old service pack, gets no software updates that solves 2 problems
Well, only assuming you keep all your employees from plugging in any unapproved devices to any of the machines. Whoops instant virus (although still contained), made much worse by your internal security patches being way out of date.
Or does nobody actually write malware for just plain destroying data anymore? Maybe not.
Unity? Screw that: XFCE. Slashdot Beta? Screw that: SoylentNews. Australis? Screw that: Pale Moon. UX developers DIAF
Plus you could presumably go old-school and just download and burn the updates to CD or something (after SHA-1'ing them etc.), couldn't you?
Unity? Screw that: XFCE. Slashdot Beta? Screw that: SoylentNews. Australis? Screw that: Pale Moon. UX developers DIAF
So how did companies handle such networks 20+ years ago, where employees in "other offices" (cities, other locations in the same city, etc.) could access files, databases, etc., without any vector out to the Internet?
Thank you, that's a good question. Companies used to pay for their own, dedicated network connections between various offices - think T1s, T3s, ISDN, etc. Yes, they were much more expensive, which is why they mostly went away. The bean-counters probably saw dollar signs flash in front of their eyes when internet connections became cheap and VPN and other tunneling solutions were worked out that made it possible to replace the old dedicated connections, and that was that.
Another possibility, however, is that the internet made the business need to be interconnected so great (i.e. email, web, saas, etc) that it just became too difficult to justify having duplicate machines on everyone's desks. Remember that IT is a cost center for businesses, so eternally being squeezed to be more efficient and cost-effective.
If the Chief InfoSec Officer doesn't at least get fire
Grep the 40 gig to see if you can find the risk log and/or the emails from the CISO to the CEO going, "We need 30 times the investment or you're going to get a career ending data breach"?
Good move. After all, employing three times the staff to cover for the lost productivity and constantly training new hires after you've sacked people for breaching processes is definitely going to make you competitive with companies that take a more balanced risk based approach to their security.
Incidentally just what the fuck are you installing on the virtual machines if it isn't an operating system (e.g. Windows 8).
I still have not forgiven them for the rootkit and other more recent sins. And no, employees are not innocent. You work for a corrupt company, you are complacent. Just like NSA employees, you don't get a free pass because you are following orders. If 60% of NSA employees quit, it would have forced change a lot faster then anything going on now.
You misunderstood. No surprise I didn't write it very well.
Airgapping your network only protects you from network attacks. It only protects you if people don't expand your network without authorisation. It also by itself is quite useless unless you have systems in place to do things like get Windows Updates onto the machine.
If you think Stuxnet showed that this breach had anything to do with layered networks then you are very very misinformed. Stuxnet entered their systems on a closed network via internal breaches and replicated via USB. It is actually a perfect example of how airgapping doesn't solve problems.
What I mean with "a culture of security" is that the whole picture is taken into account. I've worked at a lot of industrial plants and I've seen everything work, and I've seen it all fail too. One of the refineries we were at had a great airgapped system using sneakernet (burning CDs, no USB sticks as per policy) to get data on and off the network. A major breach was discovered when an operator had plugged a 3G modem into the back of a control systems machine so he could access the internet from his workstation. This is an example of airgapping without a culture of corporate security. Best of all there were no penalty for the operator. The plant was also way behind on security patches and the likes because they aren't connected to anything so why need security right?
On the other hand the plant where I work now has a layered security approach with 3 distinct networks between the internet and the control system. The last layer is a one-way (I hate the term Data-Diode but that seems to be what they are calling it these days) isolation which pushes data to an external box on another network which the 3rd network can access via a firewall. But far more importantly is the view on security. You won't get operators plugging 3G modems into the PC not because the boxes are locked (which they are), but because someone sat down and thought through things like the bored users scenario and they have a second PC off the network which they can do with what they want (within policy). Oh and if this happened at my current work place the operator would be dragged to the gate by his ears and told never to come back.
Airgapping as a security solution typically fails due to lack of security by other means, bored or idiotic users (especially if there's a nightshift), and the management problem where some genius decides it would be great if they can see what's going on in the network and the network grows arms and legs till it eventually gets plugged into something it shouldn't.
A tiered approach on the other hand typically requires careful thought. Don't get me wrong this can be done VERY poorly, but for the most part the tiered network implementations I've seen and what comes with them I would consider to be far more secure because they have gone through a thorough design stage. By contrast the airgap solutions I've seen have typically been an afterthought where "airgap is the security so what else would you need".
Oh also the Windows Update was just an example of something that is typically done poorly. Airgapped networks I have seen have let their software rot from a security point of view. But solutions exist and in the case of Windows Update it's running a WSUS server on the closed network and feeding it the necessary update by some means. This can be done both well and poorly regardless of which method is used, but is almost universally done poorly when the approach to security becomes, "just unplug it".
Any one remember this?
http://en.wikipedia.org/wiki/S...
no matter how good it is, it is human nature always wants to make things better
"In the letter, Sony [...] called on the government to help make the internet safer." http://www.buzzfeed.com/tomgar...
How does the government doing anything to "the internet" help secure private data on a private corporate network?