Recommended Posts

Dunno, if this has been posted yet. But it's worth a read:- Key points from the Sony Conference : gaming

Hirai said that no improper CC usage has been reported and they have no evidence of CC info being compromised. They said that Sony will pay for CC reissuing and assist with monitoring/insurance programs for customers. If there are any improper charges, they will be handled on a case-by-case basis.

CC info was encrypted and stored in a different part of the database from user personal information. Because of this, user information and CC information are being categorized separately.

Needs to be nailed into people's heads.

That actually really moved me, I know how big of a deal it is for Japanese people when they do that...

Exactly, this is a MASSIVE gesture by Sony. Admittedly they had no choice but to come clean and say sorry, but the way they have handled it is pretty much perfect.

Exactly, this is a MASSIVE gesture by Sony. Admittedly they had no choice but to come clean and say sorry, but the way they have handled it is pretty much perfect.

I think it shows they are genuinely wanting to resolve all of this and are sorry, where as you'd be led to believe they don't care/just want your money/are incompetent from the comments everywhere. Most of the fanboys though will still create "funny" photoshops of the picture on the last page, or mock it, but we know absolutely nothing Sony done/will do will in anyway will alter even a slight bit of their perception. That however is not unique to this situation.

Don't think there's much point in trying to laugh at America/West and say companies wouldn't bow here, because, well, they wouldn't and that's just the way it is. The Japanese are typically more modest people than us, and that is reflected in their culture.

At the end of the day it was/is a nice gesture to show humility for the actions/lack of actions leading to and following this situation.

Don't think there's much point in trying to laugh at America/West and say companies wouldn't bow here, because, well, they wouldn't and that's just the way it is.

Here, they would ask for a bail-out, then pay themselves billions of dollars in bonuses, all while proclaiming the new PSN is ten times better than it was before.

This is defintely worth a read: Wrongly Jailed Security Whistleblower Caught Up in PlayStation Hacker Hunt | Threat Level | Wired.com

...

To that end, he used a man-in-the-middle hack to monitor the SSL-encrypted traffic from his home console to Sony?s servers. He loaded a self-signed certificate onto the console, and directed the traffic through a proxy server on his own network. When he pored through the traffic, he noticed that Sony was running outdated versions of the Apache web server.

Sony, it turns out, uses a cluster of Apache servers to authenticate PlayStation consoles, a different cluster to serve downloadable content, another to store image files, etc. All of them are directly accessible from the internet, he says ?- there?s no VPN between the console and the PlayStation Network. And he claims all the servers were all at least a little out of date.

?Literally everything goes through a web server somewhere,? he says. ?Different [sony] divisions maintain different servers. I never saw a current version of Apache on any of them.?

Sony did not respond to an inquiry from Threat Level on Friday.

McDanel admits he doesn?t know that Sony?s web servers were vulnerable to attack. The authentication server he mentioned in the chats was running Apache 2.2.15, which was superseded in June 2010, but has no remote-access vulnerabilities listed on Apache?s website.

...

PlayStation Network Security Update

On Tuesday, April 26 we shared that some information that was compromised in connection with an illegal and unauthorized intrusion into our network. Once again, we?d like to apologize to the many users who were inconvenienced and worried abut this situation.

We want to state this again given the increase in speculation about credit card information being used fraudulently. One report indicated that a group tried to sell millions of credit card numbers back to Sony. To my knowledge there is no truth to this report of a list, or that Sony was offered an opportunity to purchase the list.

One other point to clarify is from this weekend?s press conference. While the passwords that were stored were not ?encrypted,? they were transformed using a cryptographic hash function. There is a difference between these two types of security measures which is why we said the passwords had not been encrypted. But I want to be very clear that the passwords were not stored in our database in cleartext form. For a description of the difference between encryption and hashing, follow this link.

To reiterate a few other security measures for your information: Sony will not contact you in any way, including by email, asking for your credit card number, social security number or other personally identifiable information. If you are asked for this information, you can be confident Sony is not the entity asking. When the PlayStation Network and Qriocity services are fully restored, we strongly recommend that you log on and change your password. Additionally, if you use your PlayStation Network or Qriocity user name or password for other unrelated services or accounts, we strongly recommend that you change them, as well. To protect against possible identity theft or other financial loss, we encourage you to remain vigilant, to review your account statements and to monitor your credit reports.

We continue to work with law enforcement and forensic experts to identify the criminals behind the attack. Once again, we apologize for causing users concern over this matter.

Our objective is to increase security so our customers can safely and confidently play games and use our network and media services. We will continue to provide updates as we have them.

Source: http://blog.us.playstation.com/2011/05/02/playstation-network-security-update/

Glad to see them debunking all those false news stories going around.

well, i just re-joined the Sony family so please don't think i'm badmouthing anyone, but their attitude towards security is lax, certainly laxer than MS. i mean just look at the parental control password for the PS3. it's numbers that show up on the screen as you type them! i mean, come on!

The Sony press conference (particularly the images of Kaz Hirai and the other two people bowing) has definitely tempered a lot of the anger that I initially felt toward the company. After all of those posts on the Playstation Blog that look like they were written by a robot, it is moving indeed to see a more emotional response coming from Sony. That humility and that human touch is worth a lot more than a material compensation in my eyes.

Good for Sony (Y) .

Sorry but Sony deserves all the lumps/bruises they get for this, clearly not taking their data security seriously enough. If you want to play the cultural sensitivity card and buy into emotional arguments feel free, but those guys can bow all day, my personal data and CC# (luckily for me an expired CC, not so much for others) is in the wild and their apologies do little for people scrambling to protect their identities and credit scores.

Sorry but Sony deserves all the lumps/bruises they get for this, clearly not taking their data security seriously enough. If you want to play the cultural sensitivity card and buy into emotional arguments feel free, but those guys can bow all day, my personal data and CC# (luckily for me an expired CC, not so much for others) is in the wild and their apologies do little for people scrambling to protect their identities and credit scores.

Wish I could + this one. While I do appreciate the humility, it doesnt change what happened. How any of you can change your opinion based on an apology and a bow is odd to me. I do wish we would get more concrete answers from Sony instead of "to my/our knowledge". There has to be server logs that would contain exact details of what information the hackers got.

Wish I could + this one. While I do appreciate the humility, it doesnt change what happened. How any of you can change your opinion based on an apology and a bow is odd to me. I do wish we would get more concrete answers from Sony instead of "to my/our knowledge". There has to be server logs that would contain exact details of what information the hackers got.

to my knowledge is what politicians say when they caught effing around with money or hookers. sony just refuses to full out admit the full extent of damages that may cause any sort of fear and hurt their stock prices anymore.

This will be thrown out. How naive she is to think that our data is secure in anyone's hands. The US Government has had many more leaks of my information than I believe any company ever has, but they can't be sued for it. They just give a , "oopsie, someone did something" excuse, and that's all we can take. So to think a company will do a better job than one of the top leading nations in the world... that is just stupid.

Nothing they got anyway you couldn't get from any phone book or open facebook profile. People too sensitive about things that aren't even personal. Your name, address, email, all given away at the whim anyway whenever anyone basically ask for them about anything.

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Qwen 3.6 is better value per dollar, and you can run it locally for free.
    • I don't believe them that anyone using threads, at least meaningfully. It's the same thing for Facebook, people just don't engage with Meta platforms like they are thinking. This isn't 2006.
    • Not taking AI slop on the go with me, hard pass for me.
    • Same Internet Archive seemed to grab the new version https://web.archive.org/web/20...d/Setup_MakeMKV_v1.18.4.exe Here's the link to an additional file it periodically downloads https://web.archive.org/web/20260213092148/https://www.makemkv.com/sdf.bin I think update's keys, etc. To manually trigger this update, put the sdf.bin file in the root of where the program is installed. When you launch the program it will pick up the file and import it. Typically put it here: C:\Program Files (x86)\MakeMKV\sdf.bin
    • Windows 11 KB5094126, KB5093998 bugging out Office apps but it may not be Microsoft's fault by Sayan Sen Microsoft last week released Windows 11 KB5094126 and KB5093998 as the latest Patch Tuesday updates. Following that the company also published the accompanying dynamic updates under KB5094149, KB5095971, and KB5094156. Although the tech giant did not acknowledge any major problems, some users online reported various issues ranging from OneDrive and Dropbox access problems, BitLocker recovery lockouts, to blue screens and BSODs. You can read about them in this dedicated piece. While there is still no confirmation about those problems from Microsoft the company has admitted to another bug which we did not report on. The tech giant has confirmed it has received reports of an issue in which certain third-party applications may be unable to launch Microsoft Office apps or open Office documents after installing the Patch Tuesday. This affects both Windows 11 as well as Windows 10. The company says the problem impacts a subset of applications that rely on OLE (Object Linking and Embedding) automation to communicate with Microsoft Office programs. According to Microsoft, affected scenarios involve third-party software attempting to open Office applications or documents from within their own interface. In such cases, the Office program may fail to launch altogether, or the requested document may not open. Oddly there may not be any error message, which probably makes the issue difficult to diagnose. The bug affects several Office products, including Word, Excel, PowerPoint, Access, and other apps in the Microsoft Office suite when they are launched through the affected software. These include tax and accounting software such as CCH Engagement and Workpaper Manager, dental practice management solutions like Dentrix and Softdent, as well as the popular research and reference management tool Zotero. Microsoft adds that other applications using similar Office integration methods could also experience the same problematic behavior. To understand the issue it is important to look at OLE, the Microsoft technology involved. OLE allows different applications to work together and share data, while its Automation feature lets one program control another. Thus this enables third-party software to launch Microsoft Office apps, open documents, and perform tasks automatically without requiring users to switch between programs. Because many accounting, healthcare, research, and business applications rely on OLE automation to interact with Word, Excel, PowerPoint, and other Office apps, any disruption can break those workflows. As a result, affected software may be unable to open Office documents or launch Office applications even though the programs themselves continue to work normally. At the moment the company has not provided a permanent fix though it has confirmed that engineers are actively working on a resolution, which will be delivered through a future Windows update. As such additional details will be shared once more information becomes available. In the meantime, Microsoft recommends a simple workaround for affected users whic is to open the Office application or document directly rather than launching it through the third-party program. For enterprise customers and organizations managing larger deployments, Microsoft says an additional mitigation is available. Admins experiencing the problem on their managed devices are advised to contact Microsoft Support for business to obtain and apply the workaround.
  • Recent Achievements

    • Reacting Well
      Dys Topia earned a badge
      Reacting Well
    • Conversation Starter
      NovaEdgeX earned a badge
      Conversation Starter
    • One Year In
      Console General earned a badge
      One Year In
    • Week One Done
      Twozo Technologies earned a badge
      Week One Done
    • One Month Later
      Twozo Technologies earned a badge
      One Month Later
  • Popular Contributors

    1. 1
      +primortal
      517
    2. 2
      +Edouard
      184
    3. 3
      PsYcHoKiLLa
      106
    4. 4
      Steven P.
      88
    5. 5
      ATLien_0
      68
  • Tell a friend

    Love Neowin? Tell a friend!