Upcoming Events

Collapse

There are no results that meet this criteria.

Announcement

Collapse
No announcement yet.

Attack of the Hack

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

  • Attack of the Hack

    I find it interesting how in the news more and more you hear about company breaches in security. This begs the question are hackers getting smarter? Or companies getting dumber?

    Take for instance the now infamous PSN (Playstation Network) outtage. This began as a simple DDoS attack against Sony in retaliation to their police raid on a PS3 hacker who did nothing illegal other than modding a computer he owns. (It would be like buying a Sony VAIO PC and Sony saying you can't install this program on it, and them arresting you as a result).

    The DDoS attack later was found to be a diversion for a well-coordinated breach into Sony's internal network, compromising their database for the PSN network. Not only was information retrieved, but tracks were covered. Logs were removed. Corporate sabotage anyone?

    The Anonymous group claims responsibility for the DDoS attack, but not the breach into their network, are they lying? Question is... why would they.

    Now not even a month later, Codemasters (developer/publisher) gets hacked.... And on the 13th of June (Monday) Bethesda (developer/publisher) also got hacked.

    This same group who hacked Bethesda's site also claims responsibility for hacking US government websites and criticizing them for their lack of security.

    I think in general companies get bigger, and security is increasingly becoming an afterthought -- the value isn't fully understood until the worst happens.

    How ironic that shortly after Sony rushes out a new store system with a new agreement and authentication system (to stop people using PS3's with custom firmware online), that the very system gets hacked. Was it put through it's paces? Probably not.

    These are just my observations as someone heavily involved in this industry and field.
    The very existence of flame-throwers proves that some time, somewhere, someone said to themselves, You know, I want to set those people over there on fire, but I'm just not close enough to get the job done.

    George Carlin

  • #2
    I believe their biggest mistake so far was attacking the US Senate website as they now have the attention of the Federal government, who have considerably more resources at their disposal than the various private companies they have been targeting.
    James Arrow: Potion Vendor

    Comment


    • #3
      Originally posted by Saulus
      I find it interesting how in the news more and more you hear about company breaches in security. This begs the question are hackers getting smarter? Or companies getting dumber?(snip)
      There's an old saying that I think applies to security in general and computer security in particular - "Never a horse that couldn't be rode and never a rider that couldn't be throwed". In that context, probably some of both of the above, and their opposites, too.
      Cheers,
      Dave
      ================
      Tery Mard

      Comment


      • #4
        Hackers are and will always be one step ahead of the security measures in place because before the security measures can be updated or fine tuned and tweaked they have to be breached. Simple fact.

        Comment


        • #5
          You'd do well to read some histories on cryptography Biohazard =P It's always been a battle between the attackers and the defenders and there have been decade long spans where one side held the advantage over the other. The French Revolution and the times surrounding Mary, Queen of the Scots is absolutely fascinating.
          James Arrow: Potion Vendor

          Comment


          • #6
            Originally posted by Biohazard89 View Post
            Hackers are and will always be one step ahead of the security measures in place because before the security measures can be updated or fine tuned and tweaked they have to be breached. Simple fact.
            In our time... hackers will be well ahead of security folks. To be prepared for everything takes tons of resources, wit, organzational skills, governance, money.... yada yada... to be a hacker only takes finding one good weakness.

            I've worked in 4 different security departments over the past 13 years and only one of them even remotely had a clue. But in the end it only takes one dumb user in an organization of thousands to click on that link that says "Click here or we're going to delete your account"... poof... pWnd

            I bet any of ya'all some hacker org is going to shut down an industrial complex through their own industrial software which controls a chemical plant, or an electric grid, or the sort... I give it 3- 7 years before that shit goes down. It already happened to Iran.
            Active Characters:

            Roman Miellthorpe -- Crypt Carver
            Church -- Bastion priest of the 'tough order'
            Dutch -- Blacksmith
            Canus -- Of the Glade Tribe
            Gorri Blackbeard -- Dwarf Stout of the Legion

            Comment


            • #7
              Anyone else get this email?

              Yesterday (June 14), we learned that a hacker gained unauthorized access to the decade-old BioWare community server system associated with the Neverwinter Nights forums. We have taken appropriate steps to protect our consumers' data and launched an ongoing evaluation of the seriousness of the breach. We have determined that no credit card data was compromised, nor did we ever have or store sensitive data like social security numbers. However, hackers may have obtained your user account name and password, email, password, country and date of birth. As a result, we have disabled your legacy Bioware Account. To create a new account please visit social.bioware.com.

              We take the security of your information very seriously and regret any inconvenience this may have caused you. If your username, email address and/or password on the Neverwinter Nights forums are similar to those you use on other sites, we recommend changing the password at those sites as well. We advise all of our fans to always be aware of any suspicious emails or account activity and report any suspicious emails and account activity to Customer Support at 1-866-543-5435.

              If you have questions, please visit our FAQ at http://support.ea.com/app/answers/detail/a_id/5367 or contact Customer Support at the phone number above.

              Aaryn Flynn
              Studio GM, BioWare Edmonton
              VP, Electronic Arts

              Comment


              • #8
                Cant say i did Chip

                Comment


                • #9
                  Originally posted by Chipmunk View Post
                  Anyone else get this email?
                  Gamebanshee picked up on this incident. Change your passwords just to be safe?

                  Comment


                  • #10
                    Well I am a Crypto Techie workin for the US Government ... and what we need to do is find these people and pay them to work for us ... because trust me ... we need the help ... badly.
                    "Service to a cause greater than yourself is the utmost honor you can achieve."

                    Comment


                    • #11
                      Originally posted by Mournas View Post
                      Well I am a Crypto Techie workin for the US Government ... and what we need to do is find these people and pay them to work for us ... because trust me ... we need the help ... badly.
                      LOL. Well if you do then you guys should give me a job, I am comfortable with a six-figure salary.
                      The very existence of flame-throwers proves that some time, somewhere, someone said to themselves, You know, I want to set those people over there on fire, but I'm just not close enough to get the job done.

                      George Carlin

                      Comment


                      • #12
                        Originally posted by Saulus View Post
                        LOL. Well if you do then you guys should give me a job, I am comfortable with a six-figure salary.
                        Really? I personally wouldn't want that much money...







                        LOL!
                        Originally posted by roguethree
                        If I had my way, clerics would have spell failure and a d6 hit die. And Favored Souls wouldn't exist.

                        Comment


                        • #13
                          First, PSN...

                          Then, Bioware...

                          NEXT... SUNDREN!

                          *GASP! - DUN DUN DUN . . . *
                          "We must not believe the man, who say that only free people ought to be educated, but we should rather believe the philosophers who say the only the educated are free." -Epictetus

                          Comment


                          • #14
                            Originally posted by Chipmunk View Post
                            Anyone else get this email?
                            Nope, didn't get the email. I logged on to social.bioware.com when I read this post and it seems to work OK. But it's possible that I signed up for a new account back when I first went there, instead of using a legacy account.
                            Cheers,
                            Dave
                            ================
                            Tery Mard

                            Comment


                            • #15
                              Now even minecraft has been hacked. Nobody is safe.
                              I got one leg missin'
                              How do I get around?

                              One Leg Missin'
                              Meet the Feebles

                              Comment

                              Working...
                              X