Microsoft blames recent Sony and RSA hacks on 'rookie mistakes'

By Stuart Sumner

04 Jul 2011

Comments: 2

Security threats - password theft

Microsoft has blamed Sony and security firm RSA for making 'rookie mistakes' that led to both firms' recent and widely-publicised hacking incidents.

John Howie, senior director, online services security and compliance governance at Microsoft said that the security breaches at Sony could have beeen avoided if it had kept its servers patched.

Further reading

"Sony was brought down because it didn't patch its servers, it ran out of date software and it coded badly. These are rookie mistakes," said Howie.

He added that the breach at secure token specialists RSA could also have been avoided.

"RSA got hacked because someone got socially engineered and opened a dodgy email attachment. A rookie mistake."

He claimed that processes in place at Microsoft meant that such mistakes were extremely unlikely to happen within his organisation.

"At Microsoft we have robust mechanisms to ensure we don't have unpatched servers. We have training for staff so they know how to be secure and be wise to social engineering."

In a statement that could be construed as goading to hackers, he also made the claim that Microsoft's internet capacity renders it almost impervious to denial-of-service (DoS) attacks. 

This form of attack has been used in recent months by hacktivist group Anonymous and now-disbanded hacking group Lulzsec to temporarily take down the internet sites of Mastercard, Paypal, the CIA and the Serious and Organised Crime Agency (SOCA).

"We have massively overbuilt our internet capacity, this protects us against DoS attacks," said Howie.

DoS attacks bombard a web-facing server with requests for information until the volume of data that it attempts to pass exceeds its output limit, often causing the server to fail.

"We won't notice until the data column gets to 2GB/s, and even then we won't sweat until it reaches 5GB/s. Even then we have edge protection to shun addresses that we suspect of being malicious," he said.

Reader comments

I wonder

sometimes I think Microsoft is a rookie mistake.

Posted by: cyber  23 Aug 2011

He's joking, right?

Not a week after he slams Sony for lax security MS had their own "Safety and Security Center search engine to return adult-oriented results, studded with malware links." IMHO, this guy should be fired by the MS board and/or investors for making such comments given there is no such thing as a truly secure network.

Posted by: B Bergin  12 Jul 2011

Have your say on this article

All fields required. Your email address will not be displayed on the site.

By submitting a comment you agree to abide by our Terms & Conditions

Do you think the G-Cloud will be a success?

The government’s £60m G-Cloud framework continues to take shape with infrastructure, platform and software-as-a-service suppliers named on 19 February. The cloud services will be made available via a CloudStore and it is hoped that it will erode government IT silos, as well as make IT cheaper and more flexible. Do you think the G-Cloud will be a success?

81 %

5 %

9 %

5 %