Yet again Sony is making the news for the wrong reasons – another one of their web sites has been hacked with personal details, usernames and passwords of about one million people being stolen.
It certainly looks as though they are being deliberately targeted but you have to ask yourself why this might be the case?
If I was Sony’s CEO or CIO apart from hiding my head in shame and looking to lob one or two off my staff I’d be seriously looking at my operating practices.
The websites themselves are obviously vulnerable to various hacking techniques and are in desperate need of a formal programme of vulnerability assessment and penetration testing.
This would highlight security weaknesses in the web applications and allow Sony to focus their remediation efforts to maximum effect.
In addition Sony need to seriously look into their practices of storing personal details including usernames and passwords unencrypted.
This is totally unacceptable in an online world and exposes their customers to untold dangers not least of which are ID theft and fraud.
Usernames and passwords are priceless commodities to the criminal gangs who perpetrate these crimes because so many of us reuse them across lots of different online resources.
So whilst on its own, gaining access to Sony customers details might not be of immediate threat, it can have potentially huge repercussions for those whose details have been accessed.
And this goes for any online application or resource, not just those of Sony.
If you have a web site, whether you store usernames and passwords, personal details or even nothing at all, you should get it security tested to make sure it’s not exposing your clients to online threats.

