Pages

Showing posts with label Sony. Show all posts
Showing posts with label Sony. Show all posts

Saturday, May 7, 2011

Sony struggles to rebuild Playstation Network

Sony is struggling to meet its own deadline for restoring the Playstation Network downed by a hack that landed hackers with a windfall of millions of gamer's details.
Sony said last week that it expected some parts of the network to be up and running again by now. It did confess, however, that it could be a number of weeks before the whole thing is working again. It looks like the less optimistic forecast could be closer to the truth.
In a "Service Restoration Update" posted on the Playstation Blog yesterday, the firm's senior director of corporate communications and social media, Patrick Seybold - a name increasingly familar to miffed gamers - said that when Sony held its press conference in Japan last week, the outfit was "unaware of the extent of the attack on Sony Online Entertainment servers."
It's now becoming clear that the hack has left Sony is a right state. And, while we take it as read that the outfit is doing its best to restore services and wipe the egg from its mucky chops, the task facing its engineers is such that it can't yet say how long it will take.
"We know many of you are wanting to play games online, chat with your friends and enjoy all of the services PlayStation Network and Qriocity services have to offer, and trust me when I say we’re doing everything we can to make it happen," wrote Seybold. "We will update you with more information as soon as we have it. We apologize for the delay and inconvenience of this network outage."
The announcement was met with muffled [read moderated] dismay by gamers, some of whom are still adjusting to the light of day
Kirafung wrote: "I was expected to play online this weekend… Disappointed this time I must say, but please make sure that the new system is secure. Don’t want to see this happen again."
Clupula668 complained: "I've been really patient, but this is not funny anymore. I know you want to keep things secure, but two weeks is beyond excessive."

Thursday, May 5, 2011

Sony: Anonymous provided cover for PSN attack

The House Subcommittee on Commerce, Manufacturing and Trade asked Sony to testify at a hearing called "The Threat of Data Theft to American Consumers," so the company could answer a series of questions about its recent PlayStation Network security breach. Sony declined to attend the meeting, but the company did answer a series of questions put to them about the attack, and the letter to committee chairwoman Rep. Mary Bono Mack (R-CA) has been published on the official PlayStation Blog.
Rep. Bono Mack slammed Sony for not showing up in person; during later questioning, she held up Sony's letter and said that her office had received it this morning. The document contains interesting details about the attack, as well as more evidence that Anonymous was involved (perhaps unwittingly) in what went down.
On April 19, Sony noticed that some of the 130 servers in the PlayStation Network had rebooted themselves, an activity that was not officially scheduled. The network service team began digging into the logs to find out what was going on, and on April 20 they found evidence of the attack and reason to believe information had been stolen. "At the time, the network service team was unable to determine what type of data had been transferred, and they therefore shut the PlayStation Network system down," said the letter. On April 26, we were told that our personal data had been compromised.
So how did the attackers gain entrance? Around two weeks ago, Sony was defending itself against constant denial of service attacks, and it seems the entirety of their online team was busy dealing with that threat.
"Detection was difficult because of the sheer sophistication of the intrusion," Sony wrote in the letter. "Second, detection was difficult because the criminal hackers exploited a system software vulnerability." A company executive had previously stated that the hacker gained entrance through a "known vulnerability" that the company was unaware of. Sony also claims that because its team was so busy defending against the denial of service attacks, detection of the hack was even more difficult. Sony claimed that this was "perhaps by design."
Sony also claimed it found a files on its server named "Anonymous," with the text "We are Legion." The document also places the blame of the denial of service attacks directly on Anonymous.
"In any case, those who participated in the denial of service attacks should understand that—whether they knew it or not—they were aiding in a well-planned, well-executed, large-scale theft that not only left Sony a victim, but also Sony's many customers around the world," Sony stated.
Sony didn't provide information on the breach to the FBI until April 22. A briefing to give law enforcement details of the breach was scheduled for April 27. Sony has also revealed that 12.3 million account holders worldwide have credit card information on file with the company, and that number includes both current and expired cards. "As of today, the major credit card companies have not reported any fraudulent transactions that they believe are the direct result of this cyber attack," Sony claimed.

Tuesday, May 3, 2011

Five questions for Sony about PSN breach

After a week of PlayStation users wondering why they couldn't access PlayStation Network, Sony dropped the bomb yesterday: someone had gained access illegally to the personal information of more than 75 million of its users, forcing the company to shut down PlayStation Network and rebuild it, along with the related media download service Qriocity.
Sony had issued a few brief updates late last week and over the weekend acknowledging the service's outage and then an "external intrusion," but it didn't explain the consequences until yesterday.
The information exposed includes customer names; addresses; e-mail addresses; birthdays; PlayStation Network and Qriocity passwords and usernames; as well as online user handles. Sony says there is "no evidence" that credit card information was compromised, but the company advised customers to monitor their credit cards for erroneous charges anyway.
Making matters worse for customers nervous about their personal information being in the hands of someone who shouldn't have it, the service will continue to be unavailable for at least another week. And until then users have no way of resetting their password, or deleting their credit card information. Customers are, understandably, apoplectic.
So while Sony has (finally) given us useful information about the breach, there are still some big questions the company needs to answer. Here's what we'd still like to know.
Who did this and how were they able to access our information?
It's fairly basic, but it's the question on everyone's mind. How was anyone able to worm their way inside Sony's system? Was the security that poor? And even though someone was able to get the data, were our names, birthdates, addresses, and passwords not encrypted?
In regard to who did this, Sony's statement yesterday used the singular when describing the breach as being the work of "an unauthorized person." One person was able to do a lot of damage.
The company has said it is basically rebuilding its PlayStation Network from the ground up to beef up security. Without more answers, all of this calls into question Sony's security and whether the company can be trusted with this type of information again.
Why did it take a week to inform customers their credit card information may have been exposed?
Sony has told us the company found out on April 19, a Tuesday, that someone had accessed user information on PSN. The company did not inform the 75 million registered users of PSN and Qriocity that their personal information had been exposed until April 26, the following Tuesday. Customers are understandably angry, and some are even suing.
Sony did offer this explanation late Tuesday night: When the company found out on April 19 about the hack, it hired a private security firm to do a "forensic analysis" to figure out what, if any personal data, had been stolen or exposed.
But a week is a long time. If the company was even thinking that personal information, and especially credit card information, was in the hands of someone illegally, customers would obviously want to know.
Most states have laws that require companies to notify customers when sensitive personal information has been exposed, including social security numbers and credit card numbers, which could be used for financial and identity fraud. But since Sony has said it "has no evidence" that credit card information was exposed, it doesn't appear the company has violated any state laws by waiting to tell customers.
The timing of Sony's informing its customers has also attracted the attention of Sen. Richard Blumenthal, a Connecticut Democrat who yesterday wrote a letter to Jack Tretton, president and chief executive of Sony Computer Entertainment America, saying he was troubled that the company had not notified customers sooner about the breach. He also called for Sony to provide affected customers with financial data security services, including free access to credit reporting services for two years to protect against identity theft.
Have you contacted law enforcement?
The company has so far refused to answer this question. In response to a query from CNET, Sony issued this statement: "To ensure the confidentiality and effectiveness of this investigation, we cannot discuss details at this time."
How is Sony compensating customers?
While it's free to sign up for PlayStation Network, much of the content that can be downloaded requires a separate subscription to use, and every day that customers can't access that content, they're essentially losing money for something they've prepaid for. And it's not just games.
Other examples include the Netflix app that can be downloaded from the PSN Store and used to access Netflix's Watch Instantly subscription feature; MLB.TV's $100-per-season game package, which lets users watch MLB games on a TV via the PS3; the paid version of Hulu, Hulu Plus; and more.
PSN Plus customers are also losing money, since they pay for year or several month blocks of time to access exclusive content from PSN. As of now, they are also unable to play some games they've already downloaded because PSN has to be operational to play.
What happens to files stored in PSN Plus cloud backup service?
In March, Sony introduced a new feature of PSN Plus that lets gamers store 150MB of saved game data on their PSN account. In other words, users who paid for it could back up game data already saved to their console remotely to this cloud storage service as well.
But now that Sony has shut down PSN and is "rebuilding" it, will all of that data still be there when the service is restored next week?

Sony Online Entertainment data may have been stolen


This is the message displayed on the Sony Online Entertainment Web site, which was taken offline.
This is the message displayed earlier today on the Sony Online Entertainment Web site, which was taken offline. (Click to enlarge.)
(Credit: Sony)
Sony Online Entertainment was taken offline today and the company warned users of the service that their personal data may have been stolen as part of the computer attack that exposed the information of as many as 77 million PlayStation Network accounts two weeks ago.
Earlier today, the SOE site, a multiplayer online game service, said "SOE MAINTENANCE In Progress," followed by a message: "Dear Valued SOE Customers, We have had to take the SOE service down temporarily. In the course of our investigation into the intrusion into our systems we have discovered an issue that warrants enough concern for us to take the service down effective immediately. We will provide an update later today Monday). We apologize for any inconvenience and greatly appreciate your patience."
In an updated announcement this afternoon, the company said that during its investigation into the PlayStation Network breach it discovered that attackers may have also obtained Sony Online Entertainment customer names, addresses, e-mail addresses, gender, birth dates, phone numbers, log-in names, and hashed passwords.
"The information was discovered less than 24 hours ago and in response, we took down our services until we could verify their security," Sony said.
In addition, credit and debit card numbers and expiration dates (but not credit card security codes) for about 12,700 non-U.S. customers that were in an "outdated" database from 2007, and about 10,700 direct debit records listing bank account numbers of customers in Germany, Austria, the Netherlands, and Spain may have been stolen, the statement said.
"There is no evidence that our main credit card database was compromised," the company said. "It is in a completely separate and secured environment. We had previously believed that SOE customer data had not been obtained in the cyber-attacks on the company, but on May 1st we concluded that SOE account information may have been stolen and we are notifying you as soon as possible."
Also today, Sony said the credit card numbers that were potentially exposed in the PlayStation Network breach between April 17 and April 19 were encrypted but passwords were obscured with a weaker hash algorithm.
"While the passwords that were stored were not 'encrypted,' they were transformed using a cryptographic hash function. There is a difference between these two types of security measures which is why we said the passwords had not been encrypted," the company said in a blog post. "But I want to be very clear that the passwords were not stored in our database in cleartext form. For a description of the difference between encryption and hashing, follow this link."
A Sony spokesman said he did not know exactly how the financial information stored by Sony Online Entertainment was protected, but would try to find out.
Sony warned customers on April 26 that their personal information, including names, addresses, e-mail addresses, birthdays, PlayStation Network and Qriocity passwords, and usernames, as well as online user handles, had been obtained illegally by an "unauthorized person." The company has said repeatedly that there is no evidence that credit card information was stolen.
Kazuo Hirai, chairman of Sony Computer Entertainment, held a news conference over the weekend where he apologized for the breach and said the company would provide identity theft protection service and "will consider" helping customers who have to be issued new credit cards. Only 10 million of the accounts had credit cards associated with them, he said. Sony has not provided more details on how the breach occurred. Services, which have kept PlayStation customers from playing games online and other customers from being able to stream movies since April 20, are expected to be restored within the week,

Friday, April 29, 2011

Sony says PSN credit card info was encrypted



After more than a week of investigations into the security breach at Sony HQ, the Japanese mega-corporation still can't say with any certainty whether users of the PlayStation Network have had their credit card information compromised.
The latest update on the PlayStation Blog says, "All of the data was protected, and access was restricted both physically and through the perimeter and security of the network. The entire credit card table was encrypted and we have no evidence that credit card data was taken. The personal data table, which is a separate data set, was not encrypted, but was, of course, behind a very sophisticated security system that was breached in a malicious attack."
Having no evidence that the data was stolen doesn't, of course, mean that it wasn't stolen and Sony's inability or indecision on coming clean about credit card info will do little to repair the company's irreparably tarnished reputation.
Those still worried about the safety of their credit cards will take little comfort from Sony's latest advice:
"While all credit card information stored in our systems is encrypted and there is no evidence at this time that credit card data was taken, we cannot rule out the possibility," writes Patrick Seybold. "If you have provided your credit card data through PlayStation Network or Qriocity, out of an abundance of caution we are advising you that your credit card number (excluding security code) and expiration date may have been obtained. Keep in mind, however that your credit card security code (sometimes called a CVC or CSC number) has not been obtained because we never requested it from anyone who has joined the PlayStation Network or Qriocity, and is therefore not stored anywhere in our system."
In a missive on the subject we received from security outfit Lieberman Software, CEO Phil Lieberman, gave the following advice: "Always assume that the company gathering your personal information is totally incompetent at securing the data, and consider what you share with them and how you are going to recover your personal identity after they lose your information." He also recommends giving a false date of birth when registering with online gaming outfits.

Thursday, April 28, 2011

How Sony Can Recover From Their PSN Nightmare


If you were in the management team at Sony – especially Sony Computer Entertainment – life is probably a little stressful right now. Knowing that you may have lost the personal data of 77 million of your customers, maybe even including their credit card info is cataclysmic. All companies have their ups and downs but this is a huge deal, and the impact of Sony’s
Good thing Sony weren’t trying to start a business in the cloud or anything. Oh, right. Oops.
But presented with a massive PR bungle, companies have no choice but to try and repair the damage and recover. So how does Sony, a company that already has a checkered past go about fixing this massive mess?

Refund paying customers

This should be obvious, but anyone who pays for PSN+ (regular PSN service being free) should be a refund for more than the amount of time the network is down. It’s a no-brainer, but it needs to be said. You cannot simply refund members for the exact number of days PSN was inaccessible in a PR disaster like this.

Give out free stuff

This is crass, but there’s no solution to angry customers like free stuff.
Ideally, the solution should be some kind of voucher system that includes both movie and games. Send out codes that can be redeemed for $5 or $10 for use on the Playstation Store for downloadable titles, DLC, and movies/TV from the Video Store.
But, that solution could cost Sony a couple of hundred million dollars, which may be too much. Better perhaps to have days of discounts or freebies on the Playstation Network where users could get cheap or free access to games or movies on specific days.

Make transparency a new mission.

Sony have already come under fire for what is at least perceived as far too long a gap between the network going down and an announcement of a personal data breach.
So now what they must do is not only be open about their new security (as much as they can, obviously), they must also simply make the functioning, terms and conditions and limitations of their network clear.
Now is not the time to say “yes, we’ve taken care of the problem, trust us”.

Increase the availability of prepaid cards

Wit users understandably edgy about giving credit card details, it’s time to make sure everyone knows about prepaid PSN cards. Print off a hundred thousand or so of those cards, maybe even sell them at a discount. Do what you must to get people using your service again.

Distract users with new services

Again, it’s crass, but it’ll work. Add features to PSN. NOW would be the time to add cross-game chat, a feature users have been clamoring for forever.
But any and all features that would entice users to come back to the network would be a boon for the now beleaguered service.