Recommended Posts

The reason everyone is freaking out is because this affects 77 million people. Yes, hacking occurs every day. Yes Apple and MS was hacked in the past. But this is 77 million people were talking about.

Stop blaming Sony on this? Lack of communication and gaping security holes isn't their fault at all. /sarcasm

what you said about "lack of communication" yes i agree on that part.

how does that justify this? If they had a decent system in place and still got hacked they it'd have been understandable...as of now - this just seems a giant cluster****. (this is assuming that unsecured dev. network caused the whole mess)

It doesn't justify it. They are just pointing out that this isn't anything really unusual or new as the various fanboys seem to be making out (like Sony are the first company to be hacked).

I wouldn't consider the dev network "unsecured". As far as Sony was concerned, the only user's who would have dev access were those who had been given a dev console. Is it great security? No way whatsoever. It could definitely use another layer of security as I previously said, especially given the amount of power devs reportedly have. But it wasn't "unsecure" until the hackers managed to spoof their console as a developer one.

"Unsecure", for me, is when a website or service just doesn't bother to even prevent ways of attack. For example, a client's osCommerce site was compromised via an admin file upload feature that was not correctly behind the admin-wall. So any user could upload any file to anywhere on the server (and did).

Just read the update. Sony did a really good job handling the situation IMHO. Whats done is done just got to move on now.

New blog post:

Source: http://blog.us.playstation.com/2011/04/26/clarifying-a-few-psn-points/

Clarifying a few points my ass. They're *trying* to revise the history of how they completely dropped the ball and let millions of their customers and subscribers information loose to hackers.

"Lets clarify this, we let you know fast and early"...sure ya did.

Nobody's moving on from anything.

Source? If Sony are doing it though you can guarantee many other companies are just as lax.

Your argument seems to be that because it's been proven true that a company has lax security in this one instance makes it true for all companies. That's not much of an argument. Is it true that this could have happened to any company? Absolutely, yes. Any company that instituted the same policies as Sony, which no one has any way of knowing. Hell, Microsoft could have similar security holes and we wouldn't know. But there's no way of knowing what companies have inadequate security, so while you're correct in telling people not to assume it can't happen to someone else without information to back that up, you're just as wrong as the people you're decrying. Because you're saying that other companies have the same flaws with no information to back it up.

http://lmgtfy.com/?q=list+of+companies+hacked

Many of companies have been hacked. The proof is there. To say Sony is bad because of it, would also say that almost every other company out there is just as bad, along with many government agencies. Texas Workforce Commission, which handles foodstamps, unemployment, medicade, and other social services, had the information of their databases compromised. If the government has holes in it, I would suspect any other service to as well.

Also, while PSN have 70+million users, I doubt all 70 million users information was taken. Most likely a lot was, but I doubt all of the users.

People can over react and do what they want, hell, the network when it comes up will hopefully be faster with less people on it. But safety is a delusion. Your data is only safe as long as you never give it out. Once any company has it, it is available to anyone with the right tools.

The sad thing is, people over look the hackers in this. They think it is all Sony, yet they don't put the blame on the actual people who caused the harm. Some people have a totally ass backwards approach to life.

Many of companies have been hacked. The proof is there. To say Sony is bad because of it, would also say that almost every other company out there is just as bad, along with many government agencies. Texas Workforce Commission, which handles foodstamps, unemployment, medicade, and other social services, had the information of their databases compromised. If the government has holes in it, I would suspect any other service to as well.

Just because other services are doing it doesn't make it okay. Reusing a nonce or storing passwords in plaintext shows either complete ignorance of encryption or complete apathy for the protection of user data, neither of which is acceptable. Sony is just lucky they don't store more sensitive data, if either of these flaws were found at a Medical Records Facility they would be sued in to the ground for non-compliance without mercy. Worst case for Sony they have to settle a class action law suit and give every PSN member with credit card info in the system a free year of LifeLock

Just because other services are doing it doesn't make it okay. Reusing a nonce or storing passwords in plaintext shows either complete ignorance of encryption or complete apathy for the protection of user data, neither of which is acceptable. Sony is just lucky they don't store more sensitive data, if either of these flaws were found at a Medical Records Facility they would be sued in to the ground for non-compliance without mercy. Worst case for Sony they have to settle a class action law suit and give every PSN member with credit card info in the system a free year of LifeLock

Doesn't make it right, but it does show that Sony isn't doing anything out of the ordinary.

Trying to justify Sony's negligence in this case because it might or has happened with other companies is stupid. Of course other companies can be hacked and no information is entirely safe, but my personal information has not been stolen from any of those companies, and if it was I would just be as angry at them as I am at Sony right now - especially if they were storing passwords in plain text.

This is one of the worst cases of data theft ever and I can't understand why people are trying to justify it, regardless of their loyalties with Sony. Sony had suspicions for almost a week that the hackers might have accessed personal data, but said nothing. Obviously I hate the hackers with all I have for doing this, but I can't blame them for the fact it took Sony a week to tell us that they might have stolen all of our information. Poor communication, poor security, and just poor handling of the entire issue.

At the very least, I hope this causes other companies to double-check their own security.

Welp, I don't know about the rest of you but I just got done calling my bank and having them ship me a new debit card. :unsure:

I know this won't end well for Sony...

Never use a debit card online. You are much safer with a credit card. With a debit card they can drain your bank account.

http://lmgtfy.com/?q=list+of+companies+hacked

Many of companies have been hacked. The proof is there. To say Sony is bad because of it, would also say that almost every other company out there is just as bad, along with many government agencies. Texas Workforce Commission, which handles foodstamps, unemployment, medicade, and other social services, had the information of their databases compromised. If the government has holes in it, I would suspect any other service to as well.

Also, while PSN have 70+million users, I doubt all 70 million users information was taken. Most likely a lot was, but I doubt all of the users.

People can over react and do what they want, hell, the network when it comes up will hopefully be faster with less people on it. But safety is a delusion. Your data is only safe as long as you never give it out. Once any company has it, it is available to anyone with the right tools.

The sad thing is, people over look the hackers in this. They think it is all Sony, yet they don't put the blame on the actual people who caused the harm. Some people have a totally ass backwards approach to life.

Posting a Google search doesn't prove your point. Not to mention the search phrase you used doesn't specify the kind of hack, how severe the hack, the data stolen, the size of the company, the type of network being infiltrated (read: we're not talking about a simple website here, nor are we even talking about a corporate website), and countless other variables. In other words: your search is absolutely useless for the sake of comparison.

Furthermore, I don't see anywhere in your search where a document proves that "almost every other company out there is just as bad." You're posting your own beliefs on the matter that do not relate to the findings of your flawed search. I also don't see how you can compare a state agency to a multibillion dollar technology corporation running a large scale technology service in terms of technology security.

You seem to be missing the point: I'm not saying that it is impossible for companies to have similar flaws to Sony. I'm saying it's stupid to attempt to shame someone for saying "well Microsoft doesn't have this flaw!" by insisting that Microsoft does have this flaw. Neither scenario is known, and either could be correct or could be wrong.

Never use a debit card online. You are much safer with a credit card. With a debit card they can drain your bank account.

Never used a debit card anywhere in my opinion (unless you're withdrawing cash obviously).

With a credit card, the money that's spent isn't yours. So as long as you're responsible in terms of paying off your transactions every month, the credit card is the safest and most efficient way to spend.

(Of course, far too many people are careless fools when it comes to anything financial, so things don't always play out so well)

Holy corporate shilling Batman!

I could understand the support for Sony during the whole homebrew lawsuit debacle, but this, this is absolutely horrendous on Sony?s part.

First it was ?don?t blame Sony, blame the hackers?. But I do blame the hackers, and there?s a nice jail sentence waiting for them if they?re ever caught. But I blame Sony, because I gave them my information under the impression that they would secure it properly. In fact, the ToS that they attempted to sue hackers over outlines exactly how they will treat your data. They had a duty to protect your data and failed, plain and simple.

Now it?s ?don?t blame Sony, every company leaks your data?. Do they? Steam and the Wii have yet to leak personal details. So, no, while some companies may not take the proper precautions, most will. And those that won?t receive likewise bad press. Was the Epsilon data breach not heavily covered in mainstream media even though it was just the user?s email that was leaked? With a headline like ?Citibank, Sears, MasterCard Data Stolen? how could they not. Was the Gawkers data breach not heavily covered on tech site even though it was a fraction (1.4 million) of Sony?s (75 million) and only the encrypted passwords? Considering the scope (75 million) and nature (email, password, DoB, address, CC info), this deserves a measure more coverage.

I really don?t know why anyone would defend Sony in this case. Do you all own Sony stock? Actually, if you did own Sony stock, you should be ****ed too. The outage of PSN on Easter weekend on the heels of 3 major releases is a financial disaster for Sony, and that?s not even taking into account the cost of cleaning up this disaster.

Holy corporate shilling Batman!

I could understand the support for Sony during the whole homebrew lawsuit debacle, but this, this is absolutely horrendous on Sony?s part.

First it was ?don?t blame Sony, blame the hackers?. But I do blame the hackers, and there?s a nice jail sentence waiting for them if they?re ever caught. But I blame Sony, because I gave them my information under the impression that they would secure it properly. In fact, the ToS that they attempted to sue hackers over outlines exactly how they will treat your data. They had a duty to protect your data and failed, plain and simple.

Now it?s ?don?t blame Sony, every company leaks your data?. Do they? Steam and the Wii have yet to leak personal details. So, no, while some companies may not take the proper precautions, most will. And those that won?t receive likewise bad press. Was the Epsilon data breach not heavily covered in mainstream media even though it was just the user?s email that was leaked? With a headline like ?Citibank, Sears, MasterCard Data Stolen? how could they not. Was the Gawkers data breach not heavily covered on tech site even though it was a fraction (1.4 million) of Sony?s (75 million) and only the encrypted passwords? Considering the scope (75 million) and nature (email, password, DoB, address, CC info), this deserves a measure more coverage.

I really don?t know why anyone would defend Sony in this case. Do you all own Sony stock? Actually, if you did own Sony stock, you should be ****ed too. The outage of PSN on Easter weekend on the heels of 3 major releases is a financial disaster for Sony, and that?s not even taking into account the cost of cleaning up this disaster.

Then sue Sony.

If you think Sony did something wrong, go find a lawyer. I bet he'd gladly work for a contingency fee basis because there are 70 million potential plaintiffs.

i don't think i can add any more than has already been said, but i really cannot believe that this data was stored as plain text in a database which was internet facing. worse still, the passwords tied to each account were not stored in the database as a non-reversible hash. it really is unbelievable and it really is terrible design.

but this has been a pr disaster for sony. here in the uk this data breach is all over the news with fairly high billing. it even made the pm programme on radio 4.

we don't know whether the entire database and credit card info has been exposed, truth is, we may never know. but the headlines and innuendo are hugely embarrassing.

the time it's taking for them to bring the platform back up seems to suggest that it is being re-written with levels of abstration in place so it's not possible for direct db access by some means. it wouldn't surprise me if there is a mandatory firmware update required to enable you to get back on psn as soon as it's up and running again with re-enforced api.

but it does go to show though, with the root key to the ps3 readily available the platform is effectively broken until the ps4 and this game of cat and mouse will not end here.

I need to ignore Twitter right now... there are tons of people (and site feeds) spewing ignorance galore...

I work at a company that deals with data security... we wish everyone that lost a laptop or left data unencrypted had used our product(s) first. The fact is, NOBODY is impervious to being hacked. It happens all the time to tons of companies. It happens at a much larger scale than the 75M PSN users.

By data breach standards, what Sony has done here is the absolute text book implementation of what to do correctly. They didn't put protocol aside to keep selling PSN content. They didn't put protocol aside to let gamers keep gaming, potentially muddying up the systems being scoured for clues. They didn't try to hide that this happened. They didn't try to analyze it themselves but instead brought in experts.

The people and sites that are faulting Sony on how they've handled this so far are simply, and I mean no disrespect by the use of the very most accurate word I can think of... "ignorant" as to what they're talking about.

If you think Sony should've battened down the hatched and never gotten hacked... talk to the HUNDREDS of other companies/brands/organizations out there that have endured the exact same fate. If you think Sony shouldn't have been storing credit card information (at all or in a certain way) you should know that all there are now are recommendations or guidelines, there are no LAWS yet that force companies to certain degrees of protection and even if they were adequately protected, depending on the extent and nature of the hack, having them protected to PCI DSS guidelines STILL might not prevent people from getting to our credit card information...

That said, Sony said there was no evidence that our credit cards were compromised. They recommended (and to be honest, this was worded well) that "While there is no evidence at this time that credit card data was taken, we cannot rule out the possibility. If you have provided your credit card data through PlayStation Network or Qriocity, out of an abundance of caution we are advising you that your credit card number (excluding security code) and expiration date may have been obtained." How can they be faulted for that? Would you rather them lie and say "you're safe" or "they were compromised"?

This was a text book reaction to a large scale data breach and unlike MOST companies where we'd simply get an unexpected letter in the mail, we were somewhat kept in the look by the raised awareness that PSN being down leading them to say something. You don't spill details during an investigation and these things take time. Hell, try checking out your computer after you've had a trojan installed and activated... now amplify that work by about a bajillion. Going through that stuff takes time.

Source: http://forums.sarcasticgamer.com/showpost.php?p=645846

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Dead on arrival at that price. Like they missed the mark by multiple hundreds of dollars - this should actually undercut the Macbook Air at $899 if they want any sort of sales / further adoption of WoA
    • Wow, 50% increase for the base model. That's steep!
    • A group made up of dozens of cybersecurity experts, including several well-known veterans of the industry, published an open letter to the U.S. government asking it to lift the export control order on Anthropic’s Fable and Mythos models. According to the open letter, “this action has taken the best models away from [cybersecurity] defenders” who now can’t use the models to find vulnerabilities and make their software and products more secure. “To pull the best capabilities away from defenders without a good reason when our adversaries are rapidly advancing is dangerous,” read the letter. On Friday, the U.S. government ordered Anthropic to limit the export of Fable and Mythos, citing national security concerns, without explaining the specific reasons behind the order, according to Anthropic. In response, the company suspended access to the models to all users worldwide.     https://techcrunch.com/2026/06/15/cybersecurity-vets-protest-dangerous-us-government-ban-on-anthropics-most-powerful-models/
    • Vivaldi 8.0.4033.48 by Razvan Serea Vivaldi is a cross-platform web browser built for – and with – the web. A browser based on the Blink engine (same in Chrome and Chromium) that is fast, but also a browser that is rich in functionality, highly flexible and puts the user first. A browser that is made for you. Vivaldi is produced with love by a founding team of browser pioneers, including former CEO Jon Stephenson von Tetzchner, who co-founded and led Opera Software. Vivaldi’s interface is very customizable. Vivaldi combines simplicity and fashion to create a basic, highly customizable interface that provides everything a internet user could need. The browser allows users to customize the appearance of UI elements such as background color, overall theme, address bar and tab positioning, and start pages. Vivaldi features the ability to "stack" and "tile" tabs, annotate web pages, add notes to bookmarks and much more. Vivaldi 8.0.4033.48 changes: [Chromium] Update to 148.0.7778.267 ESR (includes security fixes from 149.0.7827.114/115) [Crash] When closing devtools with input caret in a CSS property field (VB-128998) [Linux][Media] Fetch an updated proprietary media support file (VB-129132) [Permissions] Global Permissions counter shows all permissions (64) as overridden (VB-127713) Download: Vivaldi 64-bit | 139.0 MB (Freeware) Download: Vivaldi 32-bit | ARM64 View: Vivaldi Home Page | Screenshot Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • Two variants of the KAMRUI H2 mini PC receive deeper discounts on Amazon by Steven Parker KAMRUI (sister company of AceMagic) reached out to us, letting us know that they are applying further discounts to two of their H2 mini PC variants, and in times like these, every little helps. First off, it's the Core i5 14450HX 32GB+1TB variant, which already received a discount from $699 to $567.99 on Amazon, so you may be asking what you get for that. Its most important features are listed below. 32GB Memory Configuration, Exceptional Value. Driven by rising AI demand, the DDR memory supply is tightening, making high-capacity memory more valuable. KAMRUI maintains high-quality standards while offering strong value with a 32GB RAM + 1TB SSD configuration, which delivers excellent performance and storage. Intel i5-14450HX, HX-Class Performance Powered by the Intel Core i5-14450HX (10 cores/16 threads, up to 4.8GHz, 54W TDP)-HX series delivers desktop-class performance. Enjoy up to 120% higher multi-core performance vs. i7-1185G7 and stronger sustained performance than Ryzen 9 6900HX under heavy workloads. With 14450HX performance, it handles coding, compiling, Docker with ease, runs 10+ apps simultaneously—Excel, Chrome, Zoom, video editing—with smooth multitasking and fast load times. 32GB RAM & 1TB NVMe SSD - expandable up to 4TB Mini pc W-11 Pro equipped with 32GB (16GB×2) DDR4 dual-channel memory and a 1TB NVMe PCIe 4.0×4 SSD, mini pc delivers fast system response and efficient data access for demanding workloads. Dual M.2 slots support storage expansion up to 4TB. Large memory support running multiple virtual machines simultaneously, enabling fast deployment and isolated sandbox testing, significantly improving development efficiency and multitasking performance. HX-Class Heat Dissipation, Higher Productivity 14450HX Mini computers W-11 pro equipped with upgraded silent centrifugal fans, dual copper heat pipes, dual fin-stack cooling modules, and an optimized dual-airflow design, the processor can maintain ≥95% of multi-core performance even under long-duration heavy workloads. The HX platform is specifically designed for multitasking, rendering, and content creation, and multitasking, delivering desktop-class stability and powerful performance. Triple 4K Productivity Power Supports triple 4K displays and handles complex workflows like coding, data processing, and multitasking with ease. WiFi 6 delivers fast, reliable connectivity for video, conferencing, and transfers. Bluetooth 5.2 ensures stable, low-latency wireless connections. Versatile Connectivity This mini computer comes with 1x Type-C(10Gbps data transfer), 1x RJ45 Ethernet, 2x USB3.2 Gen2 (10Gbps), 4x USB3.2 Gen1 Type-A (5Gbps), PD output, 1x HDMI 2.0, 1x DP 1.4, and 1x 3.5mm audio jack. It offers versatile connectivity to connect multiple devices effortlessly, reducing the need for frequent plugging and unplugging. Small Size, Big Performance Mini PC measures just 5.04 × 5.04 × 1.63 inches, over 80% smaller than a traditional desktop, yet equipped with the high-performance 14450HX processor for near-desktop-level power. With VESA mounting support, it transforms cluttered desks into clean, organized setups. Normally costing $699, but now down to $ 535.79, which includes an additional 6% off the Amazon listed price. That equals a total of 24% off the MSRP. KAMRUI Hyper H2 (Core i5 14450HX 32GB+1TB) for $ 535.79 (was $699) Use code 2UD2IW7D for the above price during checkout (expires on June 30) Editors note: This appears to be listed as a "frequently returned item" on Amazon, but you should take into account the reviews on the page that discuss a completely different PC, it would seem that this is yet another recycled sales page that is now listing this newer item, possibly to retain the positive 4.5 star rating on the page. Next up, we have the Core i9 14900HX/32GB+1TB variant, which normally costs $799.99 but is already discounted to $759.99 on Amazon. Again, the most important highlights for this variant are listed below. Upgrade 14th Intel Core i9-14900HX Processor KAMRUI Mini Computers features the 14th Gen Intel Core i9-14900HX processor (up to 5.8GHz, TDP 55W, 36MB cache, 24C/32T), delivering 25%–40% higher performance than the i5-14450HX (24C/32T) and i7-1280P in multitasking, creative work, and high-load applications. Manufactured using Intel 7 (10 nm) process technology, Mini Computer efficiently allocates workloads to deliver faster response times, smoother operation, and heightened productivity. 32GB DDR4 & 1TB SSD - Expandable to 4TB KAMRUI Intel Core i9-14900HX mini PC features dual-channel 32GB DDR memory (expandable to 64GB) and 1TB NVMe PCIe 4.0×4 SSD, delivering speeds 40% faster than PCIe Gen3. The KAMRUI Micro PC features two M.2 2280 SSD slots, each expandable up to 2TB, effortlessly accommodating a high-capacity system drive and an ultra-fast cache drive. This achieves a perfect balance of speed, capacity, and flexibility, effortlessly handling large projects and high-speed workflows. 4K UHD Triple Display KAMRUI 14900HX Mini PC features a 4K@60Hz UHD graphics card (Intel UHD Graphics), supporting 4K@60Hz high-definition video playback for a premium visual experience. Mini Gaming PC incorporates an HDMI 2.0 port + DP 1.4 port + USB3.2 Gen2 Type-C port, supporting 4K triple display output. Mini PC can connect to three monitors to fulfil your multi-screen collaboration requirements. Ultra-high-definition visuals and ultra-fast connectivity significantly enhance your productivity. RJ45 LAN Port+WiFi6E+BT5.2 KAMRUI Mini PC features a 1.0Gbps LAN port, suitable for high-speed broadband environments in homes, offices, and large enterprises. Bluetooth 5.2 enables connection to peripherals such as headphones, mice, and keyboards. Dual-band WiFi 6E and BT 5.2 deliver enhanced interference resistance and more stable wireless signals. Regardless of your network environment's complexity, the KAMRUI H2 mini computer delivers a relatively stable and smooth network experience. Professional-Grade Cooling System KAMRUI Mini gaming PC features an upgraded silent centrifugal fan, dual copper heat pipes, and a dual-fin module. Its all-copper structure enhances thermal conductivity, boosting airflow efficiency by 35% and overall heat dissipation by 40%, ensuring the CPU can stably deliver up to 55W performance under full load. Upgraded aluminum heatsink keeps the SSD cool to maintain read/write speeds, ensuring desktop-level stability and power for demanding workloads. Compact Size, Infinite Possibilities KAMRUI H2 mini computers measure just 5.04 x 5.04 x 1.63 inches, a fraction of the size of a traditional desktop, yet deliver powerful performance for demanding workloads. With the included VESA mount, you can easily attach a small pc behind a monitor or place it in your TV cabinet, turning your display into a sleek mini PC while saving valuable desk space. Versatile Connectivity This KAMRUI mini gaming computer comes with 1*USB3.2 Gen2 Type-C(up to 10Gbps data transfer), 1*RJ45 Ethernet, 2*USB3.2 Gen2 (10Gbps), 4*USB3.2 Gen1 Type-A (5Gbps), 1*HDMI 2.0, 1*DC, 1*DP 1.4, and 1*3.5mm audio jack. It offers versatile connectivity to connect multiple devices effortlessly, reducing the need for frequent plugging and unplugging. Normally costing $799, but now down to $721.99, which includes an additional 5% off the Amazon listed price. That equals a total of 10% off the MSRP. KAMRUI Hyper H2 (Core i9 14900HX/32GB+1TB) for $ 721.99 (was $799) Use code AQ5Z6A47 for the above price during checkout (expires on June 30) KAMRUI claims that they offer lifetime technical support along with a 12-month warranty. For either of these mini PCs, should you encounter any issues during use, KAMRUI claims it will do its utmost to assist customers. As an Amazon Associate, we earn from qualifying purchases.
  • Recent Achievements

    • One Year In
      Console General earned a badge
      One Year In
    • One Year In
      Twozo Technologies earned a badge
      One Year In
    • One Month Later
      Twozo Technologies earned a badge
      One Month Later
    • Week One Done
      Twozo Technologies earned a badge
      Week One Done
    • Veteran
      branfont went up a rank
      Veteran
  • Popular Contributors

    1. 1
      +primortal
      510
    2. 2
      +Edouard
      201
    3. 3
      PsYcHoKiLLa
      108
    4. 4
      Steven P.
      89
    5. 5
      Nick H.
      71
  • Tell a friend

    Love Neowin? Tell a friend!