Sony slammed over new data breach
Passwords unencrypted, says hacker group that posted them online
The Associated Press
Posted: Jun 3, 2011 1:43 AM ET
Last Updated: Jun 3, 2011 9:45 PM ET
Related
Yet another massive data breach at Sony has left hackers exulting, customers steaming and security experts questioning why basic fixes haven't been made to the company's crisis-stricken cybersecurity program.
Hackers say they managed to steal a massive trove of personal information from Sony Pictures' website using a basic technique which they claim shows how poorly the company guards its users' secrets. Security experts agreed Friday, saying that the company's security was bypassed by a well-known attack method that could easily have been prevented.
"Any website worth its salt these days should be built to withstand such attacks," said Graham Cluley, of web security firm Sophos.
Coming on the heels of a massive security breach that compromised more than 100 million user accounts associated with Sony's PlayStation and online entertainment networks, Cluley said the latest attack suggested that hackers were lining up to give the company a good kicking.
Sony CEO Kazuo Hirai, centre, bows in apology along with two other executives in Tokyo on May 1 regarding a security breach in April. Shizuo Kambayashi/Associated Press"They are becoming the whipping boy of the computer underground," he said.
Culver City, Calif.-based Sony Pictures has so far declined to comment beyond saying that it is looking into the reported attack — which saw many users' names, home addresses, phone numbers, emails, and passwords posted to the web.
It wasn't clear how many people were affected. The hackers, who call themselves Lulz Security — a reference to the internetspeak for "laugh out loud" — boasted of compromising more than a million users' personal information — although it said that a lack of resources meant it could only leak a selection to the web.
The group ridiculed Sony for the ease with which it stole the data, saying that the company stored peoples' passwords in a simple text file — something it called "disgraceful and insecure."
Several emails sent to accounts associated with the hackers as well as messages posted to the microblogging site Twitter were not returned, but in one of its tweets Lulz Security expressed no remorse.
"Hey innocent people whose data we leaked: blame Sony," it said.
Sony's customers — many of whom had given the company their information for sweepstakes draws — appeared to agree.
Tim Rillahan, a 39-year-old computer instructor in Ohio, said he was extremely upset to find his email address and password posted online for "the whole world to see."
"I have since been changing my passwords on every site that uses a login," he said in an email Friday. "Sony stored our passwords in plain text instead of encrypting the information. It shows little respect to us, their customers."
He and others complained that they had yet to hear from the company about the breach, news of which is nearly a day old.
John Bumgarner, the chief technology officer for the U.S. Cyber Consequences Unit — a research group devoted to monitoring internet threats — was emphatic when asked whether users' passwords could be left unencrypted.
"Never, never, never," he said. "Passwords should always be hashed. Some kind of encryption should be used."
Bumgarner, who's been critical of Sony's security in the past, said the company needed to take a hard look at how it safeguards its data.
"It's time for Sony to press reset button on their cybersecurity program before another incident occurs," he said.
LulzSec recently claimed responsibility for hacking the website of the PBS television network to post a fake story in protest of a recent Frontline investigative news program on WikiLeaks.
Share Tools
Top News Headlines
- Air Canada jet with falling debris had previous mishaps
- The airplane that had its engine shut down and was forced into an emergency landing Monday in Toronto has had two previous documented cases of mechanical damage since it started flying five years ago, according to Transport Canada. more »
- Montreal streets flooded after flash storm
- Flash flooding and popped manhole covers were reported across Montreal as heavy rain blew through the city. more »
- Canada has higher proportion of seniors than ever before
- New census data shows Canada now has a higher proportion of seniors than ever before -- a development that has crept up on society with far-reaching implications for health, finance, policy and everyday family relationships. more »
- Redford's energy plan supported by western premiers
- Alberta Premier Alison Redford says she is pleased that her counterparts supported her idea for a Canadian energy strategy at the Western Premiers' Conference in Edmonton on Tuesday. more »
Latest World News Headlines
- Italy cleans up after 2nd deadly quake in 9 days
- A magnitude 5.8 earthquake hit northern Italy on Tuesday, killing at least 15 people in the same region still struggling to recover from another fatal tremor on May 20. more »
- Canadian climber's body taken off Everest
- The body of a Toronto woman who died while descending from the summit of Mount Everest earlier this month has been taken by helicopter to her family in the Nepalese capital of Kathmandu. more »
- Suu Kyi makes 1st trip out of Burma in 24 years
- Democracy activist and long-time political prisoner Aung San Suu Kyi is resuming world travels, arriving Tuesday night in neighbouring Thailand after an 85-minute flight from her homeland. more »
- Mitt Romney to clinch Republican nomination
- Mitt Romney is set to clinch the Republican presidential nomination Tuesday night with a win in the Texas primary, a triumph of endurance for a candidate who came up short four years ago and watched this year as voters flirted for months with a carousel of GOP rivals. more »
Dispatches »
- Foreign slaves serving the U.S. military machine May. 24, 2012 3:33 PM How does a hairdresser recruited for work in Dubai, wind up slaving for the U.S. military in a war zone in Iraq? There are tens of thousands serving in what's come to be known as America's "Invisible Army."
Connect Newsroom Blog
#bullyPROOF, Syria's Tipping Point & Old Age Comedy May. 29, 2012 6:40 PM As Ontario gets ready to debate anti-bullying legislation, we're asking are bullies and victims all that different?
- Human foot sent to Conservative Party HQ
- Richard Branson suggests naked kitesurfing to premier
- Air Canada jet with falling debris had previous mishaps
- 'Engine shutdown' forced Air Canada jet to land
- Evolution skeptics will soon be silenced by science: Richard Leakey
- Storm warnings over in eastern Ontario
- Alberta couple, child found dead in Saskatchewan ditch
- Canada has higher proportion of seniors than ever before
- Newly discovered malware most lethal cyberweapon to date

