Skip to content
View in the app

A better way to browse. Learn more.

Gamercide

A full-screen app on your home screen with push notifications, badges and more.

To install this app on iOS and iPadOS
  1. Tap the Share icon in Safari
  2. Scroll the menu and tap Add to Home Screen.
  3. Tap Add in the top-right corner.
To install this app on Android
  1. Tap the 3-dot menu (⋮) in the top-right corner of the browser.
  2. Tap Add to Home screen or Install app.
  3. Confirm by tapping Install.
Welcome back to Gamercide!

Sony Gets the Finger Pointed at Them During a Congressional Testimony, Sony Issues Another Apology

Featured Replies

500x_stringer_3d.jpg

Yesterday Sony blamed the “hacktivist” group Anonymous for the late April attack on the Playstation Network that has their online servers down for weeks and angered their users and sparked a congress wide investigation.   Now that the investigation has begun the testimonial stage, can Sony point the finger at themselves after recent findings?

Dr. Gene Spafford, a professor at Purdue Universtity and a security expert took to the stand yesterday and made claims that Sony knew that their servers were at risk for months, because of out of date Apache software.

“….some news reports indicate that Sony was running software that was badly out of date, and had been warned about that risk….

Nonetheless, the increase in sophistication of attackers, and the growth in data do not totally explain all the incidents. My personal conclusion from reviews of reports in the pressand discussions at professional meetings is that operators of these systems — both in government and the private sector — continue to run outmoded, 
flawed software, fail to
follow some basic good practices of security and privacy, and often have insufficient training
or support. The most commonly cited reason for these failings is cost. The cost of providing better security and privacy protection is viewed as overhead that is not recovered in increased revenue, and it is usually one of the first things trimmed in budget cuts. Running outdated software and unpatched operating systems exposes citizens to risks and consequences whose cost a company does not bear. Therefore a company does not have an immediate economic incentive to make the investment needed to prevent breaches.”  – Dr. Gene Shappord

 

If this revelation proves to be true, Jeff Fox a Consumer Reports Techonology Editor told The Consumerist that Sony needs to blame Sony.

 
“If Dr. Spafford’s assessment is accurate, it’s inexcusable that Sony not only ran obsolete software on servers containing confidential data, but also that the company continued to do so after this information was publicly disclosed…” – Jeff Fox, Consumer Reports Technology Editor

Sony did not directly respond to the latest allegations, however Sony President Sir Howard Stringer released another apology on behalf of Sony.  During the apology Stringer still blamed the hackers for the main reason for the security breach.

“I know some believe we should have notified our customers earlier than we did. It’s a fair question. As soon as we discovered the potential scope of the intrusion, we shut down the PlayStation Network and Qriocity services and hired some of the best technical experts in the field to determine what happened. I wish we could have gotten the answers we needed sooner, but forensic analysis is a complex, time-consuming process. Hackers, after all, do their best to cover their tracks, and it took some time for our experts to find those tracks and begin to identify what personal information had — or had not — been taken.” – Sir Howard Stringer, Sony President

While the hackers may have caused the security intrusion that left millions of users wondering if their credit card and personal information had been comprimised, Sony needs to start thinking about if the recent allegations of known outdated server software can hold up in court and what this means for the future of Sony in the video game industry if it can be proven.

via Playstation Blog

View the full article

I wonder now if some Anons will help "find out" exactly how far the rabbit hole goes. If Sony wants to blame Anonymous, I'm sure they'll be more than glad to show Sony the error of their ways like they did with that one security firm a few months back.

Those security experts were neither secure nor experts.

^ haha, that's great. It is a good point to note, that if a high level users computer was breached, the amount of security would likely not matter. So, though I still believe Sony had a lack security system, it's not too hard to believe that some dumbass opened an email they shouldn't have and compromised everything.

There is all kind of FUD being posted at the moment.

Saw one report saying they didn't have a firewall which would be moronic at best.

No way a system such as PSN was running with no firewall.

My little brother hangs out in the Playstation hacking forums and has seen reports that they were running an old Linux Kernel with a known security hole and they weren't given the time by management to update the servers for financial reasons which seems like the most likely scenario TBH.

Apparently, they had too many servers and were having problems maintaining and upgrading in time with a refusal to provide more resources to update them. Which would also explain Playstation Plus or whatever it is called (subscription service). An attempt by management to raise the money required to run the service with proper security.

Looks like they were caught out before they got a chance TBH but not that they were sitting idly by really. Although an organisation the size of Sony should have taken the hit to keep it secure and then worked on recouping the costs from the subscription service.

It's unclear what Reuters meant when it reported that the information "had been stolen by hackers and posted on a website" that Sony subsequently removed. It appears that Sony was able to remove the data from the website because ... it was Sony's own website! While this isn't related to the PSN attack, it is similarly emblematic of Sony's overall inability to protect sensitive customer data.

http://www.joystiq.com/2011/05/07/sony-removes-2500-names-and-partial-addresses-from-exposed-son/

^Which really sucks, since many smaller developers will be hurt by this downtime. Even bigger companies will feel this. Consider SOCOM 4. It's exclusive to the PS3 and released just as this whole debacle began.

Capcom said today, that this downtime is costing them hundreds of thousands of dollars. http://www.computerandvideogames.com/300658/playstation-network-down-time-costing-us-hundreds-of-thousands-capcom/

I don't think many saw the ramifications of what something like this could do. In fact, it may be some time before any of us know how much this will have impacted many things.

PSN restoration update: "I know you all want to know exactly when the services will be restored. At this time, I can’t give you an exact date, as it will likely be at least a few more days. We’re terribly sorry for the inconvenience and appreciate your patience as we work through this process."

http://blog.us.playstation.com/2011/05/10/psn-restoration-timeline-update/?utm_source=twitter&utm_medium=social&utm_campaign=psn_restoration_051011

Archived

This topic is now archived and is closed to further replies.

Recently Browsing 0

  • No registered users viewing this page.

Account

Navigation

Search

Search

Configure browser push notifications

Chrome (Android)
  1. Tap the lock icon next to the address bar.
  2. Tap Permissions → Notifications.
  3. Adjust your preference.
Chrome (Desktop)
  1. Click the padlock icon in the address bar.
  2. Select Site settings.
  3. Find Notifications and adjust your preference.