Recommended Posts

Dunno, if this has been posted yet. But it's worth a read:- Key points from the Sony Conference : gaming

Hirai said that no improper CC usage has been reported and they have no evidence of CC info being compromised. They said that Sony will pay for CC reissuing and assist with monitoring/insurance programs for customers. If there are any improper charges, they will be handled on a case-by-case basis.

CC info was encrypted and stored in a different part of the database from user personal information. Because of this, user information and CC information are being categorized separately.

Needs to be nailed into people's heads.

That actually really moved me, I know how big of a deal it is for Japanese people when they do that...

Exactly, this is a MASSIVE gesture by Sony. Admittedly they had no choice but to come clean and say sorry, but the way they have handled it is pretty much perfect.

Exactly, this is a MASSIVE gesture by Sony. Admittedly they had no choice but to come clean and say sorry, but the way they have handled it is pretty much perfect.

I think it shows they are genuinely wanting to resolve all of this and are sorry, where as you'd be led to believe they don't care/just want your money/are incompetent from the comments everywhere. Most of the fanboys though will still create "funny" photoshops of the picture on the last page, or mock it, but we know absolutely nothing Sony done/will do will in anyway will alter even a slight bit of their perception. That however is not unique to this situation.

Don't think there's much point in trying to laugh at America/West and say companies wouldn't bow here, because, well, they wouldn't and that's just the way it is. The Japanese are typically more modest people than us, and that is reflected in their culture.

At the end of the day it was/is a nice gesture to show humility for the actions/lack of actions leading to and following this situation.

Don't think there's much point in trying to laugh at America/West and say companies wouldn't bow here, because, well, they wouldn't and that's just the way it is.

Here, they would ask for a bail-out, then pay themselves billions of dollars in bonuses, all while proclaiming the new PSN is ten times better than it was before.

This is defintely worth a read: Wrongly Jailed Security Whistleblower Caught Up in PlayStation Hacker Hunt | Threat Level | Wired.com

...

To that end, he used a man-in-the-middle hack to monitor the SSL-encrypted traffic from his home console to Sony?s servers. He loaded a self-signed certificate onto the console, and directed the traffic through a proxy server on his own network. When he pored through the traffic, he noticed that Sony was running outdated versions of the Apache web server.

Sony, it turns out, uses a cluster of Apache servers to authenticate PlayStation consoles, a different cluster to serve downloadable content, another to store image files, etc. All of them are directly accessible from the internet, he says ?- there?s no VPN between the console and the PlayStation Network. And he claims all the servers were all at least a little out of date.

?Literally everything goes through a web server somewhere,? he says. ?Different [sony] divisions maintain different servers. I never saw a current version of Apache on any of them.?

Sony did not respond to an inquiry from Threat Level on Friday.

McDanel admits he doesn?t know that Sony?s web servers were vulnerable to attack. The authentication server he mentioned in the chats was running Apache 2.2.15, which was superseded in June 2010, but has no remote-access vulnerabilities listed on Apache?s website.

...

PlayStation Network Security Update

On Tuesday, April 26 we shared that some information that was compromised in connection with an illegal and unauthorized intrusion into our network. Once again, we?d like to apologize to the many users who were inconvenienced and worried abut this situation.

We want to state this again given the increase in speculation about credit card information being used fraudulently. One report indicated that a group tried to sell millions of credit card numbers back to Sony. To my knowledge there is no truth to this report of a list, or that Sony was offered an opportunity to purchase the list.

One other point to clarify is from this weekend?s press conference. While the passwords that were stored were not ?encrypted,? they were transformed using a cryptographic hash function. There is a difference between these two types of security measures which is why we said the passwords had not been encrypted. But I want to be very clear that the passwords were not stored in our database in cleartext form. For a description of the difference between encryption and hashing, follow this link.

To reiterate a few other security measures for your information: Sony will not contact you in any way, including by email, asking for your credit card number, social security number or other personally identifiable information. If you are asked for this information, you can be confident Sony is not the entity asking. When the PlayStation Network and Qriocity services are fully restored, we strongly recommend that you log on and change your password. Additionally, if you use your PlayStation Network or Qriocity user name or password for other unrelated services or accounts, we strongly recommend that you change them, as well. To protect against possible identity theft or other financial loss, we encourage you to remain vigilant, to review your account statements and to monitor your credit reports.

We continue to work with law enforcement and forensic experts to identify the criminals behind the attack. Once again, we apologize for causing users concern over this matter.

Our objective is to increase security so our customers can safely and confidently play games and use our network and media services. We will continue to provide updates as we have them.

Source: http://blog.us.playstation.com/2011/05/02/playstation-network-security-update/

Glad to see them debunking all those false news stories going around.

well, i just re-joined the Sony family so please don't think i'm badmouthing anyone, but their attitude towards security is lax, certainly laxer than MS. i mean just look at the parental control password for the PS3. it's numbers that show up on the screen as you type them! i mean, come on!

The Sony press conference (particularly the images of Kaz Hirai and the other two people bowing) has definitely tempered a lot of the anger that I initially felt toward the company. After all of those posts on the Playstation Blog that look like they were written by a robot, it is moving indeed to see a more emotional response coming from Sony. That humility and that human touch is worth a lot more than a material compensation in my eyes.

Good for Sony (Y) .

Sorry but Sony deserves all the lumps/bruises they get for this, clearly not taking their data security seriously enough. If you want to play the cultural sensitivity card and buy into emotional arguments feel free, but those guys can bow all day, my personal data and CC# (luckily for me an expired CC, not so much for others) is in the wild and their apologies do little for people scrambling to protect their identities and credit scores.

Sorry but Sony deserves all the lumps/bruises they get for this, clearly not taking their data security seriously enough. If you want to play the cultural sensitivity card and buy into emotional arguments feel free, but those guys can bow all day, my personal data and CC# (luckily for me an expired CC, not so much for others) is in the wild and their apologies do little for people scrambling to protect their identities and credit scores.

Wish I could + this one. While I do appreciate the humility, it doesnt change what happened. How any of you can change your opinion based on an apology and a bow is odd to me. I do wish we would get more concrete answers from Sony instead of "to my/our knowledge". There has to be server logs that would contain exact details of what information the hackers got.

Wish I could + this one. While I do appreciate the humility, it doesnt change what happened. How any of you can change your opinion based on an apology and a bow is odd to me. I do wish we would get more concrete answers from Sony instead of "to my/our knowledge". There has to be server logs that would contain exact details of what information the hackers got.

to my knowledge is what politicians say when they caught effing around with money or hookers. sony just refuses to full out admit the full extent of damages that may cause any sort of fear and hurt their stock prices anymore.

This will be thrown out. How naive she is to think that our data is secure in anyone's hands. The US Government has had many more leaks of my information than I believe any company ever has, but they can't be sued for it. They just give a , "oopsie, someone did something" excuse, and that's all we can take. So to think a company will do a better job than one of the top leading nations in the world... that is just stupid.

Nothing they got anyway you couldn't get from any phone book or open facebook profile. People too sensitive about things that aren't even personal. Your name, address, email, all given away at the whim anyway whenever anyone basically ask for them about anything.

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • BrowserOS 0.46.0 by Razvan Serea BrowserOS is a free, open-source Chromium-based browser that runs AI agents natively, offering a smarter, more productive browsing experience. It supports Chrome extensions and integrates AI agents to automate tasks, fill forms, and streamline workflows. Your data stays on your computer: you can use your own API keys or run local models via Ollama, making it a privacy-first alternative to tools like Perplexity, Comet, or Dia. With built-in productivity tools and app integrations, BrowserOS boosts efficiency while keeping control firmly in your hands. Being Chromium-based, BrowserOS lets you effortlessly import your bookmarks, passwords, and Chrome extensions in just a few clicks. BrowserOS works with OpenAI GPT models, Anthropic Claude, Google Gemini, and local AI models via Ollama or LMStudio. You can use your own API keys and effortlessly switch between providers. BrowserOS Agent Your AI productivity assistant that organizes and manages your browsing effortlessly Quickly list, group, or close tabs Save and resume browsing sessions Search your history and organize bookmarks Switch instantly to the tab you need BrowserOS Navigator – Automate web tasks with ease Navigate websites and search automatically Interact with pages without manual effort Handle repetitive tasks in seconds What makes BrowserOS special Feels like home - same familiar interface as Google Chrome, works with all your extensions AI agents that run on YOUR browser, not in the cloud Privacy first - bring your own keys or use local models with Ollama. Your browsing history stays on your computer Open source and community driven - see exactly what's happening under the hood MCP store to one-click install popular MCPs and use them directly in the browser bar (coming soon) Built-in AI ad blocker that works across more scenarios! BrowserOS 0.46.0 changelog: Run Claude Code & Codex right in your browser — We've extended the agent harness to bring full coding agents into BrowserOS. Claude Code and Codex now come bundled and plug straight into the assistant, so you can drive your browser with the agent — and the subscription — you already use. A brand new experience — A redesigned new tab, a calmer composer, and a rebuilt command center for switching between agents. The whole assistant is cleaner, faster to reach, and easier to live in. New MCP tools — We rebuilt the browser tool surface from the ground up — a tighter, more reliable set of tools for agents to drive the browser. Plus one-click install of BrowserOS as an MCP server into the agents you already run, with automatic URL sync. Chromium 148 — Updated to the latest Chromium base with all recent upstream fixes and security patches. Streamlined — We've pulled back a few features that weren't getting much use — Skills, Soul, and Memory — so we can focus and ship better versions of them soon. Download: BrowserOS 0.46.0 | 181.0 MB (Open Source) Download: BrowserOS for macOS | 485.0 MB Links: BrowserOS Homepage | Github | Screenshot Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • Microsoft finally admits its default Windows 11 25H2, 24H2 action broke key legacy component by Sayan Sen Microsoft last week released Windows 11 KB5094126 and KB5093998 as the latest Patch Tuesday updates. Following that the company also published the accompanying dynamic updates under KB5094149, KB5095971, and KB5094156. So far the company has acknowledged two known issues that have popped up after the release which include bugged-out Office apps as well as the Recycle Bin; though there could be more at play too. Speaking of bugs and issues, Microsoft seems to have finally acknowledged a problem that probably has been around for close to a year. That's because back in July of 2025 the company made a default change to the latest Windows 11 versions, wherein it switched to JScript9Legacy on Windows 11 24H2 and later releases. Hence following the release of version 25H2 in October 2025, JScript9Legacy also remained default-enabled. As a result there has been a compatibility issue ever since then. For those wondering, by switching to JScript9Legacy Microsoft intended to improve the security of modern Windows PCs by reducing vulnerabilities tied to legacy scripting like cross-site scripting (XSS), among others. XSS exploits can allow cyber-attackers to attach malicious code onto legitimate websites and use them to execute the code when a potential victim loads such a website. Hence the new JScript9Legacy engine enforced stricter execution policies and improved object handling, which should help mitigate such attacks. Microsoft today has published a new support article detailing the problem. Neowin spotted it while browsing. The company says that JScript global definitions and execution context may fail to persist across scripts, potentially breaking older dependent apps and web-based components that relied on this legacy behavior. In the article Microsoft has confirmed that the issue stems from its move away from the older jscript9.dll engine in favor of jscript9legacy.dll. As mentioned above, while the newer engine was designed to address vulnerabilities and strengthen security it also changes how JScript handles execution context. As a result functions and definitions loaded by one script could no longer remain available to subsequent scripts once execution ended. The company notes that some applications worked correctly on earlier Windows versions because the older JScript engine automatically retained global definitions and execution state between scripts. Under the newer model though that behavior is disabled by default causing certain legacy workloads and polyfill-dependent scripts to fail. Microsoft says it addressed the problem via the KB5077241 update though the fix had not been enabled automatically in the following updates. As such admins must explicitly turn on persistent JScript execution context using a Registry setting that the tech giant shared today. The configuration can be applied to individual processes or system-wide through the FEATURE_ENABLE_PERSISTENCE registry key. The steps have been outlined below: Run the following command to create the feature control registry key: reg add "HKLM\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ENABLE_PERSISTENCE" Under this key, create a new DWORD (32-bit) value. Configure the value as follows: To enable persistence for specific processes only: Set the value to 1 for each target process name. To enable persistence for all processes: Add * as the key name and set its value to 1. You can find the official support article here on Microsoft's website.
    • The possibility that milk gathers back into a glass implies that gravity can be 'reversed'.
  • Recent Achievements

    • Week One Done
      Jordan Smith earned a badge
      Week One Done
    • Reacting Well
      BizSAR earned a badge
      Reacting Well
    • First Post
      AndreaB earned a badge
      First Post
    • Week One Done
      Huge Trailer earned a badge
      Week One Done
    • Week One Done
      Classifyskilleducation earned a badge
      Week One Done
  • Popular Contributors

    1. 1
      +primortal
      590
    2. 2
      +Edouard
      186
    3. 3
      PsYcHoKiLLa
      76
    4. 4
      Michael Scrip
      73
    5. 5
      Steven P.
      66
  • Tell a friend

    Love Neowin? Tell a friend!