So it's the Friday after Thanksgiving, I'm on my second cup of coffee, and I still haven't opened my work laptop because half my company's Slack (fine, we still call it group chat, whatever) is just people relaying updates about the Sony Pictures mess. If you missed it because you were busy fighting someone over the last discounted TV at Best Buy, here's the short version: employees showed up Monday morning to find their screens taken over by some red skull graphic and a message signed by a group calling itself Guardians of Peace, threatening to dump internal data if their demands weren't met. Sony reportedly pulled the plug on huge chunks of its own network and had people working off personal phones and, I've heard, actual paper. Nobody outside the company seems to know yet who's really behind it or how deep this goes, and I'd bet nobody inside knows either, not really, not yet.
Everyone I know is treating this like some unprecedented movie-villain hack, and maybe the scale of it is. But the part that's had me thinking all week isn't the mystery of who did it. It's how unsurprised I am that it worked at all.
I spent four years at a mid-size company doing IT-adjacent support work, and I can tell you exactly what corporate password hygiene looks like from the inside, because I lived it. We were required to change passwords every 90 days. Nobody actually came up with a new password every 90 days. Everybody just took whatever they'd been using and tacked a number onto the end, then incremented it. Summer2012 became Summer2013. I watched a coworker do this out loud, laughing about it, two feet from my desk. IT knew. Nobody fixed it, because fixing it would've meant actually enforcing something, and enforcing things is annoying and slows everyone down before a deadline.
That's not a Sony problem. That's basically every company with more than 200 employees, and I include places I've worked that would be mortified to hear me say it. Two-factor authentication existed in 2014. Google had been pushing it for years at that point. Almost nobody used it internally unless someone forced them to, because it added twelve seconds to logging in and people hate twelve seconds more than they fear a breach that probably won't happen to them specifically. I get it, honestly. I've skipped setting up 2FA on accounts I definitely should've locked down, purely out of laziness, and then felt like an idiot a week later reading a story exactly like this one.
The other thing nobody wants to say out loud is that big companies treat their internal network like a locked front door on a house with every window wide open. All the money goes toward the perimeter, the firewall, the stuff a compliance checklist cares about, and once someone's actually inside, they can often just wander. I don't know yet whether that's literally what happened here. I wouldn't be shocked.
Anyway. Black Friday. I did not leave my apartment today, which feels like the correct decision every single year and yet I always spend late November convincing myself this time I'll brave it for a deal on a router or something. I didn't. My roommate went to three stores for a TV that wasn't actually in stock at any of them and came back around 11am with a waffle iron instead, on sale for something like eleven bucks, which honestly might be the best Black Friday outcome I've heard of yet. Meanwhile my inbox is full of the usual doorbuster emails, half of which have subject lines in all caps, which is its own small tragedy of modern marketing.
I don't have a tidy point to land this on. I just keep thinking about how the scariest hacks aren't the ones that break clever new cryptography, they're the ones that walk in through a door somebody left open because closing it was mildly inconvenient. That's true of the internet in general and it was true of my old office's shared drive password, which for a stretch of 2013 was, I kid you not, the word "password1." Nobody ever changed it until someone finally complained loud enough.
Go enjoy your leftover turkey. Change a password while you're at it.