Pages

Showing posts with label psn. Show all posts
Showing posts with label psn. Show all posts

Saturday, May 7, 2011

Sony struggles to rebuild Playstation Network

Sony is struggling to meet its own deadline for restoring the Playstation Network downed by a hack that landed hackers with a windfall of millions of gamer's details.
Sony said last week that it expected some parts of the network to be up and running again by now. It did confess, however, that it could be a number of weeks before the whole thing is working again. It looks like the less optimistic forecast could be closer to the truth.
In a "Service Restoration Update" posted on the Playstation Blog yesterday, the firm's senior director of corporate communications and social media, Patrick Seybold - a name increasingly familar to miffed gamers - said that when Sony held its press conference in Japan last week, the outfit was "unaware of the extent of the attack on Sony Online Entertainment servers."
It's now becoming clear that the hack has left Sony is a right state. And, while we take it as read that the outfit is doing its best to restore services and wipe the egg from its mucky chops, the task facing its engineers is such that it can't yet say how long it will take.
"We know many of you are wanting to play games online, chat with your friends and enjoy all of the services PlayStation Network and Qriocity services have to offer, and trust me when I say we’re doing everything we can to make it happen," wrote Seybold. "We will update you with more information as soon as we have it. We apologize for the delay and inconvenience of this network outage."
The announcement was met with muffled [read moderated] dismay by gamers, some of whom are still adjusting to the light of day
Kirafung wrote: "I was expected to play online this weekend… Disappointed this time I must say, but please make sure that the new system is secure. Don’t want to see this happen again."
Clupula668 complained: "I've been really patient, but this is not funny anymore. I know you want to keep things secure, but two weeks is beyond excessive."

PSN was running on unpatched Apache server with no firewall

Few gamers will be feeling sorry for Sony and the mess caused with this PSN hacking debacle. But if you were just annoyed by what has happened, be prepared to now start getting a bit angry.
Dr. Gene Spafford, CERIAS Fellow and professor of Computer Science at Purdue University, has been talking at a hearing about the PSN security breach held by the House Subcommittee on Commerce, Manufacturing, and Trade. He explained that independent security experts monitor Sony’s systems such as PSN, Qriocity, and SOE and report in an open forum Sony employees view about anything they find.
Those security experts apparently reported some major failings with Sony’s servers some three months before the April 17 hack occurred. These weren’t small issues, they are blatant oversights and laziness on the part of Sony’s engineering team.
The issue reported was the fact Sony was running PSN on a server that had an outdated version of Apache and no firewall in place. That meant any vulnerabilities known about for that version of Apache, and patched in more up-to-date releases, were easy to take advantage of. With no firewall in place too, the hacker probably had a very easy time of it.
We don’t know what’s worse here, the fact Sony engineers ran such an unsecure system, or that they knowingly ignored being called out on it be some security experts in a forum. Whatever the case, that $1 billion PSN lawsuit in Canada just got some fresh ammunition to use in court.
As for Sony, they were invited to attend the hearing, but declined and sent a letter instead explaining how their systems will be much more secure in future.

Friday, April 29, 2011

Sony says PSN credit card info was encrypted



After more than a week of investigations into the security breach at Sony HQ, the Japanese mega-corporation still can't say with any certainty whether users of the PlayStation Network have had their credit card information compromised.
The latest update on the PlayStation Blog says, "All of the data was protected, and access was restricted both physically and through the perimeter and security of the network. The entire credit card table was encrypted and we have no evidence that credit card data was taken. The personal data table, which is a separate data set, was not encrypted, but was, of course, behind a very sophisticated security system that was breached in a malicious attack."
Having no evidence that the data was stolen doesn't, of course, mean that it wasn't stolen and Sony's inability or indecision on coming clean about credit card info will do little to repair the company's irreparably tarnished reputation.
Those still worried about the safety of their credit cards will take little comfort from Sony's latest advice:
"While all credit card information stored in our systems is encrypted and there is no evidence at this time that credit card data was taken, we cannot rule out the possibility," writes Patrick Seybold. "If you have provided your credit card data through PlayStation Network or Qriocity, out of an abundance of caution we are advising you that your credit card number (excluding security code) and expiration date may have been obtained. Keep in mind, however that your credit card security code (sometimes called a CVC or CSC number) has not been obtained because we never requested it from anyone who has joined the PlayStation Network or Qriocity, and is therefore not stored anywhere in our system."
In a missive on the subject we received from security outfit Lieberman Software, CEO Phil Lieberman, gave the following advice: "Always assume that the company gathering your personal information is totally incompetent at securing the data, and consider what you share with them and how you are going to recover your personal identity after they lose your information." He also recommends giving a false date of birth when registering with online gaming outfits.