Slashdot Mirror


The Sony Pictures Hack Was Even Worse Than Everyone Thought

An anonymous reader writes with today's installment of Sony hack news. "It's time to take a moment of silence for Sony Pictures, because more startling revelations about leaked information just came out and employees are starting to panic. BuzzFeed raked through some 40 gigabytes of data and found everything from medical records to unreleased scripts. This is probably the worst corporate hack in history. Meanwhile, Fusion's Kevin Roose is reporting on what exactly happened at Sony Pictures when the hack went down. The hack was evidently so extensive that even the company gym had to shut down. And once the hackers started releasing the data, people started 'freaking out,' one employee said. That saddest part about all of this is that the very worst is probably still to come. Hackers say they stole 100 terabytes of data in total. If only 40 gigabytes contained all of this damning information, just imagine what 100 terabytes contains."

19 of 528 comments (clear)

  1. ... Everything? by itsenrique · · Score: 5, Funny

    I mean it seems likely they got everything. Even the model numbers of the kitchen sinks.

    1. Re: ... Everything? by Anonymous Coward · · Score: 5, Interesting

      That's bad, but I remember when
      they released a root kit disguised as a music Compact Disc.

    2. Re:... Everything? by Buchenskjoll · · Score: 5, Funny

      Didn't he notice when you came back as a woman?

      --
      -- Make America hate again!
  2. Over what time interval? by man_ls · · Score: 5, Insightful

    How long was the attack taking place? What kind of Internet connection does Sony Pictures have? To ex-filtrate 100 TB of data is going to take a while, no matter how you cut it. My guess is that number is significantly inflated.

    1. Re:Over what time interval? by JMJimmy · · Score: 5, Insightful

      The big question is, how did they not notice that much data going out regardless of time frame.

    2. Re:Over what time interval? by ShaunC · · Score: 5, Funny

      Trouble is they're all marked up with Sharpie around the outside...

      --
      Thanks to the War on Drugs, it's easier to buy meth than it is to buy cold medicine!
    3. Re: Over what time interval? by reanjr9417 · · Score: 5, Informative

      Sony Pictures is likely sending out huge amounts of data as it is. It's the movie industry. Their daily backups could be 100 TiB.

    4. Re: Over what time interval? by ColdWetDog · · Score: 5, Insightful

      This. And consider that it may well have been taken out on a bunch of physical drives rather than the Internet. Pretty much everyone is saying this has some component of physical access - likely from a disgruntled employee. If the person or persons downloaded a couple of hundred GB every day to some hard drives, likely no one would notice. So it likely didn't happen all at once.

      IF this is true, it makes the timing suspicious for NK involvement. If this had been ongoing for say, 6 months, it was well before the Kim could get his panties in a bunch over the Interview. But what do I know?

      --
      Faster! Faster! Faster would be better!
  3. 100 terabytes of data - a few movies? by BitZtream · · Score: 5, Informative

    100 terabytes of data is easily consumed by the raw uncut footage of a few movies, easily. So it could be a whole bunch of stuff that really hurts them or it could just be a couple movies that were shot by M. Night Shyamalan that suck so hard no one cares.

    --
    Persistent Volume manager for Kubernetes - https://github.com/dwimsey/openshift-pvmanager
  4. Sad? Saddest? by rubycodez · · Score: 5, Insightful

    So Sony with its rookits and DRM get owned. Good. How does it feel, Sony? How does it feel?

    Hope this causes massive losses for them and horrors for its employees.

    1. Re:Sad? Saddest? by Jeremi · · Score: 5, Funny

      And, Godwin'd. That's a wrap everyone, have a great evening, see you in the next thread.

      --


      I don't care if it's 90,000 hectares. That lake was not my doing.
  5. Sauce for the goose; sauce for the gander by cryptoengineer2 · · Score: 5, Informative

    http://en.m.wikipedia.org/wiki... TL, DNR: 9 years ago, Sony was root kitting the machines of people who bought their CDs, and living about it.

    1. Re:Sauce for the goose; sauce for the gander by sumdumass · · Score: 5, Funny

      Wouldn't it be interesting if the initial breach into their systems was an exploit on a server that involved the sony rootkit because an IT stooge wanted to listen to some tunes while reviewing log files years ago.

  6. Scripts leaked by JThundley · · Score: 5, Funny

    At first they thought the data was fake; all the scripts read like movies everyone has seen already.

  7. Lawsuits and Patents by Etherwalk · · Score: 5, Interesting

    I mean it seems likely they got everything. Even the model numbers of the kitchen sinks.

    I would expect they also got some fairly damning privileged information--emails exchanged with lawyers on everything from sexual harassment to copyright infringement suits. It's a BIG firm.

    Plus Patents. Sony files THOUSANDS of patents a year. If that patent information (or research that could be patented) is published to the wild before SONY patents it, you have a LOT of new prior art and a fortune in IP at risk... SONY would have to patent everything within a year in the US; I am not sure that you even have that grace period everywhere else.

    (a) NOVELTY; PRIOR ART.—A person shall be entitled to a patent unless— (1) the claimed invention was patented, described in a printed publication, or in public use, on sale, or otherwise available to the public before the effective filing date of the claimed invention ...
    (b) EXCEPTIONS.— (1) DISCLOSURES MADE 1 YEAR OR LESS BEFORE THE EFFECTIVE FILING DATE OF THE CLAIMED INVENTION.—A disclosure made 1 year or less before the effective filing date of a claimed invention shall not be prior art to the claimed invention under subsection (a)(1) if—
                    (A) the disclosure was made by the inventor or joint inventor or by another who obtained the subject matter disclosed directly or indirectly from the inventor or a joint inventor; or
                    (B) the subject matter disclosed had, before such disclosure, been publicly disclosed by the inventor or a joint inventor or another who obtained the subject matter disclosed directly or indirectly from the inventor or a joint inventor.

    1. Re:Lawsuits and Patents by mysidia · · Score: 5, Informative

      SONY would have to patent everything within a year in the US; I am not sure that you even have that grace period everywhere else.

      No..... 1 year following lawful disclosure.

      The unlawful disclosure of confidential information by criminals is subject to adjudication by the courts.

      The unlawfully disclosed material may very well be deemed to be a condition that allows Sony to continue to pursue the patents, and publications made from unlawfully disclosed materials may be excluded from valid prior art.

    2. Re:Lawsuits and Patents by sjames · · Score: 5, Insightful

      The real risk to Sony Pictures is having the real books behind the Hollywood accounting revealed.

  8. Can't avoid medical records by Green+Salad · · Score: 5, Insightful

    I employ people in the USA in small IT and EE/IC specialty design shops. Most expert-level employees seem to come with white or grey hair. One of my IT geeks is a "MT Dew Diabetic." Avoiding the maintenance of medical records is simply not an option in the USA, given our laws and court rulings. We have to comply with ADA (Americans with Disabilities Act), keep records of workman's comp medical restrictions, including very specific information, on what an employee may and may not do as well as provide emergency information to first responders. While often inconvenient, these are requirements I cannot avoid. Some of my employees have medical conditions (heart conditions, organ replacement, severe allergies, diabetes, unusual prescriptions of controlled sumstances, etc.) that they want known and available to first responders showing up at the office if they collapse clutching their heart or go into a sugar coma. Complicating this, if one of your customers is a Federal agency or Defense, you must, by law, have a "zero tolerance policy" for controlled substances. All this requires records to prove or excuse. For government accusations, corporations are "effectively guilty" until they prove themselves innocent with appropriate record keeping. Making this even more difficult, USA court rulings say we're also not allowed to store this information in their personal files, but must keep it in a separate, access controlled file, otherwise we could get sued if that person missed a pay raise or promotion because it was available to anyone reviewing their service and discipline records. The separate files seem silly when the teams are small enough that everyone knows each other very well anyway. Also, what if the employee who first greets the medics from the ambulance don't have easy access the secured medical files? Isn't that an even worse problem? Sued if you do. Sued if you don't. Sued if you didn't do it the nuanced way a team of $300/hr attorneys thinks you should have half-way done it. Nuisance suits are common in the USA.

    As a practical matter, a lot of valuable talent is not healthy. Many experts are experts because they have been at a speciality for 30-60yrs. If you have an employee that has an epileptic seizure, you don't want the rest of the team to stand there confused and gawking. You want them to recognize it and intervening to protect that individual's head and spine from injury. I had an employee with mental health issues under the care of a psychiatrist. While she was physically 100% capable (she was young and athletic) yet she was restricted from certain emotionally triggering situations. You want their supervisor trained know what those are and how to avoid it. You want a written record, periodically refreshed, that her supervisor knows and understands. You could say "I don't want to deal with that" but then you lose out on some great talent. Imagine a physics institute that didn't want to deal with maintaining medical records for Stephan Hawking.

    1. Re:Can't avoid medical records by dave562 · · Score: 5, Interesting

      As a practical matter, a lot of valuable talent is not healthy.

      This is so true. It is difficult to deal with as a boss and even more so as an employer. One of my guys is seriously over weight, and has a number of health complications that come with it. He is also highly intelligent and very capable. It is challenge because I want to be able to depend on him, and for the most part I can. But I also have to mitigate risk and make sure that there are people shadowing his projects and documenting his recommendations so that they can carry on if the time comes that he is no longer able to come into work.

      As his boss, I want to have a legitimate, sincere conversation with him about his health and his value to the company. I also want to have it with him as a friend and someone who cares about him. But due to the way employment law works, I have to avoid the subject.