Live data from Hacker News

Sony: All personal data stolen from PSN

blog.us.playstation.com

241–250 of 292 posts

Re: Sony: All personal data stolen from PSN

#241
post #11

I wonder how many times a company can install trojans on your computer, destroy your OS's security, secretly watch all your actions, then proceed to not properly protect your data when you voluntarily give it to them...before going out of business. Sony's size and momentum must be pretty crazy. Or maybe it's our society. I just can't imagine a small record store in the 1960s, after being caught spying through the bed…

I would expect Sony to be bought out and split up and sold off in the next few years. They have been in trouble for a while now.

A number of PE firms have been looking at doing this deal with Apple mentioned as a potential purchaser of the fabs, chips and personal computing divisions

Re: Sony: All personal data stolen from PSN

#242

Earlier quoted context omitted.

Don't read this as a defense of the company, but there hasn't really been a single, monolithic Sony for decades. Sony Music Entertainment, perpetrators of 2005's rootkit debacle, is pretty far removed from Sony Computer Entertainment, the division responsible for Playstation. Sony Electronics, makers of TVs, home theater systems, and Walkmans, is another silo, as is Sony Pictures. Of course, every act of incompetence…

every act of incompetence under the Sony name tarnishes that name, and in the marketplace, that's ultimately all that matters As it should. When these companies merge, buy other companies out, or execute reverse takeovers, there's always talk of "brand synergies" and all of the business advantages of having one set of products associated with another. There's absolutely no reason why that particular sword shouldn't h…

This is precisely my view. I haven't knowingly given Sony any of my money since Lik-Sang.

Re: Sony: All personal data stolen from PSN

#243
post #168

Earlier quoted context omitted.

There have been rumors that Sony Music/Pictures has "oh no, piracy!" veto power over the rest of Sony, though. Either that or every division of Sony happens to be really DRM-happy.

Sony Music's meddling is the reason Sony failed to make a successful Mp3 player, all the more remarkable because Sony created the individual portable music market and dominated it with the Walkman.

Not only that, but they're responsible for the Minidisc's failure. That could have been a really nice format, but they had to slap a bunch of restrictions on it.

Re: Sony: All personal data stolen from PSN

#244

Notice how they never apologize? The closest thing to apology, but it's not an apology, is: > "We thank you for your patience as we complete our investigation of this incident, and we regret any inconvenience." Sony apologizes only to Chuck Norris.

The Japanese announcement is full of apology: "2011年4月21日よりPlayStation®NetworkおよびQriocity™の障害が継続しており、お客様および関係各位に多大なるご迷惑をおかけしておりますことを深くお詫び申しあげます。" Which is a polite and flowery way of apologizing for the ongoing interruption of service. http://cdn.jp.playstation.com/msg/sp_20110427_psn.html

True, they are different probably because this (the Japanese announcement) is from Sony Corporation, and the link in English is probably from Sony Corporation of America.

Re: Sony: All personal data stolen from PSN

#245
post #38
post #11

I wonder how many times a company can install trojans on your computer, destroy your OS's security, secretly watch all your actions, then proceed to not properly protect your data when you voluntarily give it to them...before going out of business. Sony's size and momentum must be pretty crazy. Or maybe it's our society. I just can't imagine a small record store in the 1960s, after being caught spying through the bed…

Momentum and hydra-esque qualities. Sony manufactures parts for a lot of tech companies, who would suffer if Sony ceased to exist. So it's in their best interest to keep them alive, especially in the short-term as it would be crippling to have to change suppliers suddenly.

Large companies like Sony don't just go out of business - they are bought out, maybe broken up in the progress. This "cease to exist" idea is really removed from reality.

Re: Sony: All personal data stolen from PSN

#246
post #14

Earlier quoted context omitted.

Frankly I'm more concerned with their words about changing credit cards if you've made a purchase through PSN. This seems to be an admission that they were storing CC#'s in plain text.

PCI requires that CC#'s are stored encrypted in the database. A service this big has had a full PCI compliance overview, and they wouldn't miss a basic requirement like that (I hope).

But if the keys are also stored somewhere where the hackers managed to gain access, they may be able to make use of the information.

Re: Sony: All personal data stolen from PSN

#247
post #173

Earlier quoted context omitted.

Salted hashes are better than unsalted hashes.

Against a GPU that can calculate five million hashes per second your salt isn't worth the paper it's printed on.

Who prints out password salts anyway?

Re: Sony: All personal data stolen from PSN

#248

Does anyone else find it odd that they "strongly recommend that you log on and change your password" instead of just force-resetting everyone's password and sending them an email with an activation link? Out of 60M subscribers, I'm certain that a large proportion will never see this message.

[deleted]

Re: Sony: All personal data stolen from PSN

#250

Earlier quoted context omitted.

It took them a week to release a non-statement, which they only issued after Congresspeople started complaining about why the service was down for so long. This is not a victory for transparency.

What do you want them to do? What's reasonable? How long do you think it took them to figure out the extent? (They still don't fully know it!) There are absolutely business concerns that warrant acting with some measured prudence. The parent is true, there are a lot more attacks than you hear about. Sony only loses here, they lie and under play it they look bad, they over play the concerns and they look bad, they tel…

Well, it's a little late now, but they could have kept to security best practices (hashed passwords, external hardware credit card encryption/decryption seem like two obvious things they chose not to do.) For a large network, that doesn't seem like an unreasonable burden.

Their business concerns are merely for their own good to try to protect their brand, not to actually benefit their customers. They will spend more on just PR, never mind making good any actual losses, than on just doing it right in the first place. At this point, they deserve to look shitty, because they were shitty. In the case of lying about it, that should be a serious corporate crime (and I think this sort of disclosure is required in most jurisdictions.)

More generally, why do businesses pay almost anything to protect their good names, but only after they themselves have let their reputation fall into the deep shit? Look at how much BP must have spent over the deepwater horizon spill, compared to how much it would have cost to maintain their equipment. Never mind the banking crisis. An ounce of rational prevention is worth a tonne of PR fire-fighting — why do companies struggle so much with mitigating downside risk?

Post reply on HN