Skip to content
View in the app

A better way to browse. Learn more.

Gamercide

A full-screen app on your home screen with push notifications, badges and more.

To install this app on iOS and iPadOS
  1. Tap the Share icon in Safari
  2. Scroll the menu and tap Add to Home Screen.
  3. Tap Add in the top-right corner.
To install this app on Android
  1. Tap the 3-dot menu (⋮) in the top-right corner of the browser.
  2. Tap Add to Home screen or Install app.
  3. Confirm by tapping Install.
Welcome back to Gamercide!

Sony's Stringer defends PSN response

Featured Replies

"This was an unprecedented situation," he told reporters today. "Most of these breaches go unreported by companies. Forty-three percent notify victims within a month. We reported in a week. You're telling me my week wasn't fast enough?"

So much for remaining humble.

Read the rest, here.

Source - [GI]

Also, some of the comments on that article are spot on. Sony may want to gauge their fans reactions to all this.

I think Sony's PR people need to put tape over some of the mouths at Sony. You can't say a comment like that without it being plastered all over the place. In the end though it comes down to what you want to believe. Either people will think that Sony handled this well or that they didn't. Quite frankly I'm getting sick of hearing about it, lol.

I'm also getting sick of hearing about it.

A week is not too long TBH, just to find out what is happening and ensure everything is getting locked down before going public.

Most websites in Ireland that have these breaches take a week to announce them.

The only reason to expect any sooner in this case is credit card data been taken though it was encrypted and the number of people affected.

  • Author

What about the master key, brim? Should Sony tell their customers that it won't be as secure as it could be?

Also, the rumors about the passwords not being hashed and the credit card information not being encrypted, made many panic. If there are some that think Sony handled it fine, more power to them. lol IMHO and TBPH, I think they're pompous and arrogant. It sucks this happened to them, but maybe it can turn into a valuable lesson. Not just for them, either.

What about the master key, brim? Should Sony tell their customers that it won't be as secure as it could be?

The master key is on the console so it shouldn't affect the security of users details on PSN AFAIK.

Also, the rumors about the passwords not being hashed and the credit card information not being encrypted, made many panic. If there are some that think Sony handled it fine, more power to them. lol IMHO and TBPH, I think they're pompous and arrogant. It sucks this happened to them, but maybe it can turn into a valuable lesson. Not just for them, either.

Well rumors are rumors. Sony can't stop speculation about how they stored their data. They should have said in their statement that data was store following industry best practice if that was the case. Maybe they assumed people would think that. That was probably a mistake.

I think much more alarming is rumours that I don't think have been denied that the servers weren't up to date on security patches which is what allowed the hack to occur in the first place. They need to be fined heavily by governments in all regions in which citizens have accounts if that is the case TBH.

  • Author

<object id="flashObj" width="480" height="270" classid="clsid:D27CDB6E-AE6D-11cf-96B8-444553540000" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=9,0,47,0"><param name="movie" value="http://c.brightcove.com/services/viewer/federated_f9?isVid=1&isUI=1" /><param name="bgcolor" value="#FFFFFF" /><param name="flashVars" value="videoId=949406326001&linkBaseURL=http%3A%2F%2Fgamevideos.1up.com%2Fvideo%2Fid%2F33662&playerID=635383662001&playerKey=AQ~~,AAAABUoMVlk~,Q5X7TGpy-_mNT9cYHA3KsQGGRANgbASB&domain=embed&dynamicStreaming=true" /><param name="base" value="http://admin.brightcove.com" /><param name="seamlesstabbing" value="false" /><param name="allowFullScreen" value="true" /><param name="swLiveConnect" value="true" /><param name="allowScriptAccess" value="always" /><embed src="http://c.brightcove.com/services/viewer/federated_f9?isVid=1&isUI=1" bgcolor="#FFFFFF" flashVars="videoId=949406326001&linkBaseURL=http%3A%2F%2Fgamevideos.1up.com%2Fvideo%2Fid%2F33662&playerID=635383662001&playerKey=AQ~~,AAAABUoMVlk~,Q5X7TGpy-_mNT9cYHA3KsQGGRANgbASB&domain=embed&dynamicStreaming=true" base="http://admin.brightcove.com" name="flashObj" width="480" height="270" seamlesstabbing="false" type="application/x-shockwave-flash" allowFullScreen="true" allowScriptAccess="always" swLiveConnect="true" pluginspage="http://www.macromedia.com/shockwave/download/index.cgi?P1_Prod_Version=ShockwaveFlash"></embed></object>

They claim they were up to date. Soon after it was made public (pre -PSN hack), that they were running old Apache, they did the upgrading.

There servers were up to date. According to the testimony, Sony weren't even running firewalls which always seemed unlikely.

http://news.consumerreports.org/electronics/2011/05/data-security-expert-sony-knew-it-was-using-obsolete-software-months-in-advance.html

It has been revealed that they were running the latest version of Apache contrary to the testimony:

http://www.joystiq.com/2011/05/09/report-sonys-psn-servers-were-up-to-date/

Which is exactly my point. Loads of people are just throwing sh** at Sony and saying anybody looking for evidence is undeniably pro-sony and should be shot on sight. When in reality most people are just claiming that people be able to back up what they say and most people realise that Sony are behaving how any company would behave if this happened to them.

Are they behaving ethically/appropriately? Probably not but I don't think they are behaving differently to any other company that has been in this situation.

Sony can indeed stop speculation. What do you think they just did with that password reset exploit?

Yeah all Sony can do is release statements saying the speculation is false. Then people start speculating about whether they are telling the truth when they tried to stop the earlier speculation.

Basically lots of money to be made of making wild accusations against Sony to get blog hits on this one so many sites are just throwing sh** out there.

I've worked for a company that had a data breach like this of user data and have seen how an incident like this can take a week to go public. Takes about a week for the information to get from the IT team to the CEO and I was working for a smallish company. Why does it take this long? It is bad news and nobody wants to admit to bad news. The IT team try to work out if that was taken before reporting it to IT management. IT management want to review the information before reporting it to their manager. Their manager wants to review the information before consulting with third parties like their lawyers. Lawyers want to analyse everything before making a recommendation about how to release it to the public. All the way during this process, everything is considered highly confidential and nobody is allowed say anything as it has the potential to get you fired and/or drag the company under with bad publicity and lawsuits.

A week turn around for a company the size of Sony is fast when something like this happens.

  • Author

I don't get what you're saying. You brought up that they weren't up to date on their servers etc, and I said that they claimed they were. Then you said that's your point exactly and link to evidence supporting they were up to date.

*edit* Also, I think we're all beyond the week long thing, too. Have you read the news today about Sony and PSN? lol

*edit2* I also don't believe any sites are making wild accusations, to make money off of page views. I really don't. It was a huge story, and it was covered in every way people thought it could be covered. Then again, Sony could have said things much sooner, and nipped a lot of it in the bud. Some will say they couldn't, or that was normal, but others will always believe they didn't do enough. I'm of the latter group.

A week turn around for a company the size of Sony is fast when something like this happens.

A week to tell their consumers their identity may have been compromised, when they themselves didn't know for certain is one thing. But, a week to address the problem of the service even being down is something else entirely and has been the crucks of Sony's complacency throughout this whole ordeal. Using other companies as a litmus test for how well Sony did or didn't not handle this issue is a moot point. You have to look at these on a case by case basis and Sony dropped the ball, time and time again on this. Customers deserve more than to just be told to shut up and forget their recent experiences with this entertainment provider.

This whole thing was handled ham handedly by Sony and that much they are definitely guilty of. Negligence maybe not, arrogance and ignorance absolutely.

Archived

This topic is now archived and is closed to further replies.

Recently Browsing 0

  • No registered users viewing this page.

Account

Navigation

Search

Search

Configure browser push notifications

Chrome (Android)
  1. Tap the lock icon next to the address bar.
  2. Tap Permissions → Notifications.
  3. Adjust your preference.
Chrome (Desktop)
  1. Click the padlock icon in the address bar.
  2. Select Site settings.
  3. Find Notifications and adjust your preference.