Lulzsec Member Raynaldo Rivera Pleads Guilty To Sony Pictures Breach 81
hypnosec writes "Raynaldo Rivera has pleaded guilty at the US District Court for the Central District of California to hacking the Sony Pictures Entertainment website in May 2011. The 20-year-old in his plea agreement revealed that he joined Lulzsec in May of last year in a bid to help the hacking collective carry out cyberattacks on governments and businesses. Rivera, who surrendered to the FBI on August 28 this year, admitted that he was the one who launched an SQL injection attack against sonypictures.com that enabled him to extract confidential information from the website's database."
typo in summary (Score:3, Informative)
lof ast year
Well, he should plead guilty of wasting my time (Score:2)
Re: (Score:3)
xkcd (Score:3, Funny)
SONY was breached a bunch of times (Score:4, Informative)
They clearly learned nothing and refused to learn anything or do anything. Lemme guess, SONY is run by copywrite attorneys and Hollywood 'content' types.
Re:SONY was breached a bunch of times (Score:5, Interesting)
Actually this problem is typically caused by MBA "beancounters" that do not have any skills or object knowledge with regard to the things they decide. They are also characterized by a hugely inflated ego and self-assessment. What then happens is best described as "save a penny, lose a million". Add to hat that external and independent security reviews are not done or only companies with no ethics are selected ("the customer is always right" is the road to hell in security evaluations) or reports are blatantly ignored. That is how Fuckupshima happened, that is how RSA was compromised (and why are they still in business????), that is why Sony was conceptually unable to even understand what happened to it.
Only solution: Massive corporate liability (They got your account hacked and cannot prove IT Sec due diligence? $1000 per count to the affected customer, unless the customer can prove even higher damage.) coupled with personal liability on the highest level (No external reviews? Glaring security holes not even looked for or ignored? CTO, CIO and CSO go to jail for a few years. If they can prove being blocked by the CEO and cooperate fully in the investigation, 30% sentence reduction, still at the very least 2 years they have to serve, and CEO goes to jail for a long time. All also have their salary and bonuses impounded for the time they did not perform.) Add to that surprise audits from time to time that have much the same impact if glaring security problems are found.
Of course, this will not happen. It would require a honest and competent government to put something like that in place. They do not exist, except occasionally in small countries.
Re: (Score:2, Informative)
No ad hominem here. I am saying MBAs are the problem because of the way they are educated. The arrogance and inflated sense of self-worth is actually part of many MBA programs as the training providers want to inflate the worth of their programs. Ad hominem would be something like "MBAs have poor personal hygiene, hence they are the problem".
IT security is top priority, because if you build on sand, you never create anything of longer-term worth.
Re: (Score:2)
Now that _is_ ad hominem thinly veiled. Idea: "You do not have an MBA, so you are no able to judge."
Re: (Score:2)
Right, what we need is a government body determining which computer security holes are worth sending people to jail for three years. Of course, even nuclear programs have been hacked successfully, so basically every single person involved with a computer system needs to become liable for something or another, and sent off to jail.
Re: (Score:2)
The question is not whether you get hacked or not. The question is whether you had reasonable security in place or not. If you do not have reasonable security, you should be liable for any and all damage and punished for endangerment. The way some (many) organizations are handling IT security today is like running a nuclear facility without a fence or security guards. Sure, even these do not keep everybody out, but not having them is inviting a catastrophe and should have dire consequences for the bean-coun
Re: (Score:2)
I suppose the worst part is well, he's the only one caught.
Remember when Sony shut down PSN? It wasn't because they detected a breach, but because they found a bunch of people getting free DLC. Yes, free DLC. Basically people were turning their retail PS3s into developer PS3s and accessing the developer PSN store, which gives free DLC for testing purposes.
After that, they discovered the breaches. But that was too late - who knew how long the data was accessible. This guy was stupid and bragged. The smart on
Re: (Score:2)
SONY is run by copywrite attorneys
Attorneys are working as copywriters now...?
These lulzsec guys are pathetic. (Score:2, Informative)
If they hadn't gloated so much and took the proper precautions, they wouldn't have been found. Don't tell anyone, not even anyone on your team, who you are.
Re: (Score:2)
If they hadn't gloated so much and took the proper precautions, they wouldn't have been found. Don't tell anyone, not even anyone on your team, who you are.
The ego the size of the planet.
If you are in it for the laughs you talk, you gloat.
Sony Should Go To Jail (Score:5, Insightful)
When does Sony go to jail, for developing rookits [wikipedia.org]? I bet that affected people on a much larger scale. What about the false advertising regarding the OtherOS feature, which was removed via an updater/backdoor?
Sony screws its customers with DRM and anti-features and attacks software developers. I find it hard to feel sorry for them.
Re: (Score:1)
he who has the money has the power
we serfs will never be able to get justice against those with better means than us
You obviously have never read the history of the French Revolution.
There are plenty of other examples in history as well.
So you need to come up with other excuses for your miserable servile
existence, because the ones you claim above are invalid.
Re: (Score:2)
Re: (Score:2)
And look what the French Revolution produces; the Jacobins, Robespierre, the Reign of Terror, the Directory, and ultimately Napoleon. Yes, poor silly well-meaning ill-advised Louis XVI lost his head, along with a bunch of equally silly foppish aristocrats, but the average Frenchman's lot really didn't improve until the Bourbon Restoration and the rise of Napoleon III.
Re: (Score:2)
England had dispensed with the idea of Absolutism over a century before. The Glorious Revolution was as far reaching as the French Revolution, and considerably less bloody.
Re: (Score:2)
In France's defence, the UK got the bloody parts of its revolution done during the Wars of the Three Kingdoms (1630-50s), which killed off something like 4%, 6% and 40% of the English, Scottish and Irish populations [wikipedia.org] respectively, or around 800,000 people (including Charles I; you can't get a much clearer rejection of the notion of an absolute monarch than Parliament finding one guilty of treason and executing him).
Re: (Score:2)
Just as pathetic a vermin as I suspeced (Score:2)
When they bragged to the world, I was convinced that
1. They would be found (law enforcement is pretty incompetent, but they do get the idiots and only idiots brag like that)
2. They would turn on each other as they have no personal honor
3. They would be utterly pathetic
Seems to have been spot-on. Incompetence combined with arrogance and self-aggrandizement. A pity that other fine examples of this personality profile can continue unhindered, e.g. in lots of government, administration, corporations, banks and
Re: (Score:1)
Re: (Score:2)
I am very specifically referring to Lulzsec. As should be obvious as the story is about Lulzsec, not Anonymous. I do not even remember bragging from anonymous, but Lulzsec was probably the worst offender ever in that category.
I do however not buy into these myths about Anonymous either. It is very much like other things the world has seen before. Quite a few terrorist/freedom fighter (not making a judgment here either way) organizations qualify for example and many of them have never been gotten under contr
Re: (Score:1)
Re: (Score:2)
None of the important Lulzsec members are behind bars? Anonymous is millions? What are you smoking?
Re: (Score:1)
Re: (Score:2)
Truth.
You bought the counterfeit variant. (Possibly made in China.) You should stop using it. It is unhealthy and leads to massive delusions.
Re: (Score:1)
sentencing (Score:4)
Isn't this all backwards? (Score:1)
I mean, really. So, we're punishing the people who find the holes in the software, while the companies who deploy insecure websites get money because they did something insecurely? I mean, I'm thing of a car analogy and it's odd - the person reaching in (because you left the window down) is at fault, but at the same time why the hell would you leave a window open and expect no one to take your iPad? And you could get compensated (even though he was caught and you lost nothing of value)?
I feel like it's sill
Re: (Score:2)
No. There is nothing backwards about punishing low life scumbags like Raynaldo who are the reason companies need to secure their websites in the first place.
What sort of morality is it to suggest that a site being inadequately secured is an invitation to steal? Do you also subscribe to the view that a woman being drunk or dressing provocatively is an invitation for you to rape her?
And... (Score:1)
> admitted that he was the one who launched an SQL injection attack
Ha ha!
To quote Bertram, "Hmmmmmm... Worth it!"
20 year old guy injects some code into sony by sql (Score:1)