Recommended Posts

Dunno, if this has been posted yet. But it's worth a read:- Key points from the Sony Conference : gaming

Hirai said that no improper CC usage has been reported and they have no evidence of CC info being compromised. They said that Sony will pay for CC reissuing and assist with monitoring/insurance programs for customers. If there are any improper charges, they will be handled on a case-by-case basis.

CC info was encrypted and stored in a different part of the database from user personal information. Because of this, user information and CC information are being categorized separately.

Needs to be nailed into people's heads.

That actually really moved me, I know how big of a deal it is for Japanese people when they do that...

Exactly, this is a MASSIVE gesture by Sony. Admittedly they had no choice but to come clean and say sorry, but the way they have handled it is pretty much perfect.

Exactly, this is a MASSIVE gesture by Sony. Admittedly they had no choice but to come clean and say sorry, but the way they have handled it is pretty much perfect.

I think it shows they are genuinely wanting to resolve all of this and are sorry, where as you'd be led to believe they don't care/just want your money/are incompetent from the comments everywhere. Most of the fanboys though will still create "funny" photoshops of the picture on the last page, or mock it, but we know absolutely nothing Sony done/will do will in anyway will alter even a slight bit of their perception. That however is not unique to this situation.

Don't think there's much point in trying to laugh at America/West and say companies wouldn't bow here, because, well, they wouldn't and that's just the way it is. The Japanese are typically more modest people than us, and that is reflected in their culture.

At the end of the day it was/is a nice gesture to show humility for the actions/lack of actions leading to and following this situation.

Don't think there's much point in trying to laugh at America/West and say companies wouldn't bow here, because, well, they wouldn't and that's just the way it is.

Here, they would ask for a bail-out, then pay themselves billions of dollars in bonuses, all while proclaiming the new PSN is ten times better than it was before.

This is defintely worth a read: Wrongly Jailed Security Whistleblower Caught Up in PlayStation Hacker Hunt | Threat Level | Wired.com

...

To that end, he used a man-in-the-middle hack to monitor the SSL-encrypted traffic from his home console to Sony?s servers. He loaded a self-signed certificate onto the console, and directed the traffic through a proxy server on his own network. When he pored through the traffic, he noticed that Sony was running outdated versions of the Apache web server.

Sony, it turns out, uses a cluster of Apache servers to authenticate PlayStation consoles, a different cluster to serve downloadable content, another to store image files, etc. All of them are directly accessible from the internet, he says ?- there?s no VPN between the console and the PlayStation Network. And he claims all the servers were all at least a little out of date.

?Literally everything goes through a web server somewhere,? he says. ?Different [sony] divisions maintain different servers. I never saw a current version of Apache on any of them.?

Sony did not respond to an inquiry from Threat Level on Friday.

McDanel admits he doesn?t know that Sony?s web servers were vulnerable to attack. The authentication server he mentioned in the chats was running Apache 2.2.15, which was superseded in June 2010, but has no remote-access vulnerabilities listed on Apache?s website.

...

PlayStation Network Security Update

On Tuesday, April 26 we shared that some information that was compromised in connection with an illegal and unauthorized intrusion into our network. Once again, we?d like to apologize to the many users who were inconvenienced and worried abut this situation.

We want to state this again given the increase in speculation about credit card information being used fraudulently. One report indicated that a group tried to sell millions of credit card numbers back to Sony. To my knowledge there is no truth to this report of a list, or that Sony was offered an opportunity to purchase the list.

One other point to clarify is from this weekend?s press conference. While the passwords that were stored were not ?encrypted,? they were transformed using a cryptographic hash function. There is a difference between these two types of security measures which is why we said the passwords had not been encrypted. But I want to be very clear that the passwords were not stored in our database in cleartext form. For a description of the difference between encryption and hashing, follow this link.

To reiterate a few other security measures for your information: Sony will not contact you in any way, including by email, asking for your credit card number, social security number or other personally identifiable information. If you are asked for this information, you can be confident Sony is not the entity asking. When the PlayStation Network and Qriocity services are fully restored, we strongly recommend that you log on and change your password. Additionally, if you use your PlayStation Network or Qriocity user name or password for other unrelated services or accounts, we strongly recommend that you change them, as well. To protect against possible identity theft or other financial loss, we encourage you to remain vigilant, to review your account statements and to monitor your credit reports.

We continue to work with law enforcement and forensic experts to identify the criminals behind the attack. Once again, we apologize for causing users concern over this matter.

Our objective is to increase security so our customers can safely and confidently play games and use our network and media services. We will continue to provide updates as we have them.

Source: http://blog.us.playstation.com/2011/05/02/playstation-network-security-update/

Glad to see them debunking all those false news stories going around.

well, i just re-joined the Sony family so please don't think i'm badmouthing anyone, but their attitude towards security is lax, certainly laxer than MS. i mean just look at the parental control password for the PS3. it's numbers that show up on the screen as you type them! i mean, come on!

The Sony press conference (particularly the images of Kaz Hirai and the other two people bowing) has definitely tempered a lot of the anger that I initially felt toward the company. After all of those posts on the Playstation Blog that look like they were written by a robot, it is moving indeed to see a more emotional response coming from Sony. That humility and that human touch is worth a lot more than a material compensation in my eyes.

Good for Sony (Y) .

Sorry but Sony deserves all the lumps/bruises they get for this, clearly not taking their data security seriously enough. If you want to play the cultural sensitivity card and buy into emotional arguments feel free, but those guys can bow all day, my personal data and CC# (luckily for me an expired CC, not so much for others) is in the wild and their apologies do little for people scrambling to protect their identities and credit scores.

Sorry but Sony deserves all the lumps/bruises they get for this, clearly not taking their data security seriously enough. If you want to play the cultural sensitivity card and buy into emotional arguments feel free, but those guys can bow all day, my personal data and CC# (luckily for me an expired CC, not so much for others) is in the wild and their apologies do little for people scrambling to protect their identities and credit scores.

Wish I could + this one. While I do appreciate the humility, it doesnt change what happened. How any of you can change your opinion based on an apology and a bow is odd to me. I do wish we would get more concrete answers from Sony instead of "to my/our knowledge". There has to be server logs that would contain exact details of what information the hackers got.

Wish I could + this one. While I do appreciate the humility, it doesnt change what happened. How any of you can change your opinion based on an apology and a bow is odd to me. I do wish we would get more concrete answers from Sony instead of "to my/our knowledge". There has to be server logs that would contain exact details of what information the hackers got.

to my knowledge is what politicians say when they caught effing around with money or hookers. sony just refuses to full out admit the full extent of damages that may cause any sort of fear and hurt their stock prices anymore.

This will be thrown out. How naive she is to think that our data is secure in anyone's hands. The US Government has had many more leaks of my information than I believe any company ever has, but they can't be sued for it. They just give a , "oopsie, someone did something" excuse, and that's all we can take. So to think a company will do a better job than one of the top leading nations in the world... that is just stupid.

Nothing they got anyway you couldn't get from any phone book or open facebook profile. People too sensitive about things that aren't even personal. Your name, address, email, all given away at the whim anyway whenever anyone basically ask for them about anything.

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Hasleo Disk Clone 5.8.2.1 by Razvan Serea Hasleo Disk Clone is a free and all-in-one disk cloning software for Windows 11/10/8/7/Vista and Windows Server that can help you migrate Windows OS to another disk, clone one disk to another disk or clone one partition to another location quickly and efficiently. Completely Free Windows Migration and Disk/Partition Cloning Software Migrate Windows from one disk to another without reinstalling Windows, apps. Clone one disk to another and makes the data on 2 disks are exactly the same. Clone a partition to another location without losing any data. Easily adjust the size and location of the destination partition. Convert MBR to GPT or convert GPT to MBR by cloning. Creation of Windows PE emergency disk. Extremely fast cloning speed and multi-language support. Supported OS: Windows Vista/Server 2008 or later, fully compatible with GPT and UEFI. Hasleo Disk Clone 5.8.2.1 changelog: Fixed an issue that caused disk enumeration to fail Fixed an issue where WinPE created under Windows ARM64 26H1 did not work properly Download: Hasleo Disk Clone 5.8.2.1 | 32.3 MB (Freeware) Link: Hasleo Disk Clone Home Page | Screenshot Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • This got me thinking, would you rather a self driving car prioritise protecting its passengers or everyone else? I'd choose the one that keeps me and my kids safest. At some point, these cars have to make those choices already, don't they? Wonder if we have a way to find out what way they lean.
    • The proportion (or number of iterations) has nothing to with this aspect of Copyright I am describing. In short, it doesn't matter how many times the manager tells you to change something or how. Your work product is always YOURS until and unless you then assign that to the person representing the client/company, usually for financial compensation -- either in salary or as a subcontract work for hire payment. if iterations determined copyright, then businesses would have learned to just keep making changes until they could claim they owned the copyright, without having to compensate the artist for their work. And that would be BAD. The only place where the amount of changes does have a role is in how much does a human modify a previous public domain work (from any source) before it is considered fair use or their own work, etc. For example, if a human makes substantial changes to a public domain (re: AI, by definition) work, then they can then claim that derivative work as their own...but NEVER the original version, of course. That's why anyone can make a movie about Dracula, for example, as long as it is based on the public domain novel, but not if they take new ideas from copyrighted movies made afterwards. As one of the people who personally advised the US Copyright Office on their recent ruling on these very issues, be assured that I specifically used the terminology precisely -- though I made it simple enough for laymen to understand it. If I made this confusing by doing so, I apologize. But, to be clear regarding your assumption that I would agree to your second statement that I quoted above -- the answer is NO. If AI does the work, no matter how much "direction" you give it, it cannot be copyrighted. All AI generated content is in the Public Domain and therefore the copyright cannot be assigned to ANYONE, even you -- until and unless substantial modifications are made to it BY A HUMAN BEING (yourself or a contracted artist/writer/etc.) and then that copyright on the derivative work is legally (in writing) transferred to you. This is a critical distinction. And it is important that people, especially AI sloppers, understand this. For example, YouTube is not paying AI slop generators for the copyright, etc. of their AI slop. What YouTube is doing is sharing AD REVENUE for permission to publish your AI slop. Copyright/ownership/rights never come into it. Importantly, that means that anyone can copy any AI slopware on YouTube, etc. and rehost it anywhere they want, even back on YouTube, and there is nothing legal that YouTube can do about it with regards to copyright protections, ownership, DMCA, etc. Anyone is legally free to use any AI slopware in any way they want. When this ruling was pending, I warned Disney legal of all of this before they did their OpenAI deal -- that it would literally dilute their entire IP portfolio forever. They ignored that warning for the PR and stock bump. But that is why, when the ruling came down last year, Disney quickly extricated themselves from that OpenAI deal, even eating the initial upfront fees -- followed closely by OpenAI ending their entire AI video generating business model. They adjusted their PR release dates to make this less obvious to shareholders, of course. Phew. I hope that this clears up the key distinctions for you and anyone reading. If you have any additional questions or even hypotheticals about AI and Copyright, please feel free to ask.
    • Each of the devices displayed on this page now has a little volume meter next to it to show if there is audio actively playing. About time.
    • Owing to the nature of Windows feature enablement updates, it was distributed over Windows Update services as a complete system upgrade rather than as an ordinary cumulative update
  • Recent Achievements

    • Collaborator
      ryansurfer98 went up a rank
      Collaborator
    • Week One Done
      Eurosoft10 earned a badge
      Week One Done
    • One Month Later
      Eurosoft10 earned a badge
      One Month Later
    • One Year In
      Skeet Campbell earned a badge
      One Year In
    • One Month Later
      Sharbel earned a badge
      One Month Later
  • Popular Contributors

    1. 1
      +primortal
      557
    2. 2
      +Edouard
      188
    3. 3
      Michael Scrip
      78
    4. 4
      PsYcHoKiLLa
      74
    5. 5
      neufuse
      71
  • Tell a friend

    Love Neowin? Tell a friend!