Join the Community

24,134
Expert opinions
40,682
Total members
332
New members (last 30 days)
206
New opinions (last 30 days)
29,290
Total comments

Hackers say unencrypted data is there for the asking

So, Sony got hacked. Again. According to Lulzsec, the collective who hacked internal Sony networks and websites, they compromised over 1 million accounts, including admin details and passwords, along with 75,000 "music codes" and 3.5 million "music coupons".

What caught my attention in the LulzSec statement was the following:

"What's worse is that every bit of data we took wasn't encrypted. Sony stored over 1,000,000 passwords of its customers in plaintext, which means it's just a matter of taking it. This is disgraceful and insecure: they were asking for it."

Thales has written often in the past about the importance of complementing perimeter firewalls and other defence with protection inside the perimeter. Now here is a hacker who is saying pretty much the same thing. But hackers never stand still. Data protection needs to be data centric. Sensitive data should be encrypted at the point it enters a system using techniques that ensure the encryption key used can only be used subsequently to decrypt data for legitimate business transactions and data volumes. Protecting the key and using a key policy that enforces its use by legitimate applications only and ensuring it cannot be [ab]used to decrypt large blocks of data is the most effective way to do this.

 

External

This content is provided by an external author without editing by Finextra. It expresses the views and opinions of the author.

Join the Community

24,134
Expert opinions
40,682
Total members
332
New members (last 30 days)
206
New opinions (last 30 days)
29,290
Total comments

Trending

Mete Feridun

Mete Feridun Chair at EMU Centre for Financial Regulation and Risk

The Crypto Crash: A Stress Test for Global Financial Stability

Alex Kreger

Alex Kreger Founder and CEO at UXDA Financial UX Design

From Inside-Out to Outside-In: Why UX Now Underpins Future Banking

Robert Kraal

Robert Kraal Co-founder and CBDO at Silverflow

What Do Merchants Really Want from Payments Technology?

Now Hiring