04 Jul 2011, Stuart Sumner, Computing
http://www.computing.co.uk/ctg/news/2083236/microsoft-blames-recent-sony-rsa-hacks-rookie-mistakes
Microsoft has blamed Sony and security firm RSA for making 'rookie mistakes' that led to both firms' recent and widely-publicised hacking incidents.
John Howie, senior director, online services security and compliance governance at Microsoft said that the security breaches at Sony could have beeen avoided if it had kept its servers patched.
"Sony was brought down because it didn't patch its servers, it ran out of date software and it coded badly. These are rookie mistakes," said Howie.
He added that the breach at secure token specialists RSA could also have been avoided.
"RSA got hacked because someone got socially engineered and opened a dodgy email attachment. A rookie mistake."
He claimed that processes in place at Microsoft meant that such mistakes were extremely unlikely to happen within his organisation.
"At Microsoft we have robust mechanisms to ensure we don't have unpatched servers. We have training for staff so they know how to be secure and be wise to social engineering."
In a statement that could be construed as goading to hackers, he also made the claim that Microsoft's internet capacity renders it almost impervious to denial-of-service (DoS) attacks.
This form of attack has been used in recent months by hacktivist group Anonymous and now-disbanded hacking group Lulzsec to temporarily take down the internet sites of Mastercard, Paypal, the CIA and the Serious and Organised Crime Agency (SOCA).
"We have massively overbuilt our internet capacity, this protects us against DoS attacks," said Howie.
DoS attacks bombard a web-facing server with requests for information until the volume of data that it attempts to pass exceeds its output limit, often causing the server to fail.
"We won't notice until the data column gets to 2GB/s, and even then we won't sweat until it reaches 5GB/s. Even then we have edge protection to shun addresses that we suspect of being malicious," he said.
Reader comments
© Incisive Media Investments Limited 2012, Published by Incisive Financial Publishing Limited, Haymarket House, 28-29 Haymarket, London SW1Y 4RX, are companies registered in England and Wales with company registration numbers 04252091 & 04252093
He's joking, right?
Not a week after he slams Sony for lax security MS had their own "Safety and Security Center search engine to return adult-oriented results, studded with malware links." IMHO, this guy should be fired by the MS board and/or investors for making such comments given there is no such thing as a truly secure network.
Posted by: B Bergin 12 Jul 2011
I wonder
sometimes I think Microsoft is a rookie mistake.
Posted by: cyber 23 Aug 2011