SUBSIM Radio Room Forums



SUBSIM: The Web's #1 resource for all submarine & naval simulations since 1997

Go Back   SUBSIM Radio Room Forums > General > General Topics
Forget password? Reset here

Reply
 
Thread Tools Display Modes
Old 05-05-11, 03:35 AM   #1
Feuer Frei!
Navy Seal
 
Join Date: Sep 2009
Location: Valhalla
Posts: 5,295
Downloads: 141
Uploads: 17
Default SONY knew it's Software was obsolete months before PSN Breach

according to Security expert.

In congressional testimony this morning, Dr. Gene Spafford of Purdue University said that Sony was using outdated software on its servers — and knew about it months in advance of the recent security breaches that allowed hackers to get private information from over 100 million user accounts.
According to Spafford, security experts monitoring open Internet forums learned months ago that Sony was using outdated versions of the Apache Web server software, which "was unpatched and had no firewall installed." The issue was "reported in an open forum monitored by Sony employees" two to three months prior to the recent security breaches, said Spafford.

Spafford made his comments in a hearing convened by the House Subcommittee on Commerce, Manufacturing, and Trade. Sony was invited to participate in the hearing, but declined to attend. In a letter to the committee, Sony said it has added automated software monitoring and enhanced data security and encryption to its systems in the wake of the recent security breaches.
"If Dr. Spafford's assessment is accurate, it's inexcusable that Sony not only ran obsolete software on servers containing confidential data, but also that the company continued to do so after this information was publicly disclosed," said Jeff Fox, Consumer Reports Technology Editor.



SOURCE


All i can say is...wow.


__________________
"History is the lies that the victors agree on"- Napoleon

LINK TO MY SH 3 MODS
Feuer Frei! is offline   Reply With Quote
Old 05-05-11, 03:51 AM   #2
Fish In The Water
Prince of
the Sea


SUBSIM
Welcome
Committee

 
Join Date: Jul 2009
Location: Watching over U-253
Posts: 3,527
Downloads: 98
Uploads: 2
Default

Quote:
Originally Posted by Feuer Frei! View Post
In a letter to the committee, Sony said it has added automated software monitoring and enhanced data security and encryption to its systems in the wake of the recent security breaches.
Right, let's add the encryption after the hack...

Whatever happened to securing credit card data before someone steals it? Silly idea I guess, after all Sony must know what they're doing.

Sony security = Major fail.
Fish In The Water is offline   Reply With Quote
Old 05-05-11, 04:03 AM   #3
HunterICX
Rear Admiral
 
Join Date: May 2006
Location: Malaga, España
Posts: 10,750
Downloads: 8
Uploads: 0


Default

Quote:
Originally Posted by Fish In The Water View Post
Sony security = Major fail.
from my experience I can say the same for their products and services
whenever I buy a new electronic device I'll avoid Sony like the plague.

but I guess they where taking this risk to save costs...but I figure this will cost them even more.

HunterICX
__________________
HunterICX is offline   Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -5. The time now is 05:22 PM.


Powered by vBulletin® Version 3.8.11
Copyright ©2000 - 2025, Jelsoft Enterprises Ltd.
Copyright © 1995- 2025 Subsim®
"Subsim" is a registered trademark, all rights reserved.