Live data from Hacker News

Sony: All personal data stolen from PSN

blog.us.playstation.com

271–280 of 292 posts

Re: Sony: All personal data stolen from PSN

#271

Notice how they never apologize? The closest thing to apology, but it's not an apology, is: > "We thank you for your patience as we complete our investigation of this incident, and we regret any inconvenience." Sony apologizes only to Chuck Norris.

The Japanese announcement is full of apology: "2011年4月21日よりPlayStation®NetworkおよびQriocity™の障害が継続しており、お客様および関係各位に多大なるご迷惑をおかけしておりますことを深くお詫び申しあげます。" Which is a polite and flowery way of apologizing for the ongoing interruption of service. http://cdn.jp.playstation.com/msg/sp_20110427_psn.html

Would you mind giving a rough translation of that? Google Translate is doing a terrible job, and I speak absolutely no Japanese.

Re: Sony: All personal data stolen from PSN

#272
post #237
post #223

Earlier quoted context omitted.

> Credit card sent as plain text This was debunked. It's encrypted on the wire.

What's your source on that?

It's talked about right in these very comments: http://news.ycombinator.com/item?id=2487412

The data is POSTed over SSL. C'mon, do you really think Sony sends credit card data across the wire in plaintext? If so, it would have been discovered the day the PS3 launched, like five years ago. And, its discovery wouldn't have required any system hacking, as described above. Is it amateur hour here?

Re: Sony: All personal data stolen from PSN

#273

http://psx-scene.com/forums/f177/sony-has-been-bad-boy-ridic... "A well known hacker i don’t want to reveal here had all the Sony PlayStation Network functions 100% decrypted as well as providing some nice info about how Sony dealing with PSN members privacy in their online servers. Apparently, Sony server gathered everything they can from the PSN connected PS3 console. When i said everything, i meant it. Here, i mak…

This is interesting. I remember hearing a story about Apple and the record labels. Basically, it took a long time for the labels to trust Apple with their entire catalogues DRM on Apple's servers (DRM was added at time of purchase). It required lots of work on Apple's side to gain that trust so that the labels felt comfortable with Apple essentially housing all of their prized assets.

If Sony was trusting all transactions on the dev network, that seems like they weren't protecting the assets of the movie/TV studios and record labels (not sure if they sell music through the PS Store).

Either way, this seems like a larger shit-storm than just user account details being stolen. It could very well impact future content deals for Sony, and possibly help the other, more trustworthy companies that have demonstrated discipline.

Re: Sony: All personal data stolen from PSN

#274
post #225

Earlier quoted context omitted.

Sigh. The CDs said "Sony." That means "Sony" is the party responsible for the rootkit. The goodwill (or lack thereof) accrues entirely to Sony. As a consumer, I'm not the least bit interested in a detailed breakdown of the corporate structure. Sony pays brand managers very well to encourage me to think of it as a single monolithic company, and I'm happy to oblige.

You sigh too quickly. The CDs said "Sony BMG." The merger with BMG was in March of 2004 and the rootkit was in 2005. The reason you associate it with Sony corporate and not Bertelsmann (of Bertelsmann Music Group) is because reporters are lazy and shorten the name of the company to just Sony. Maybe Germans were boycotting magazines because that was the part of the name familiar to them. I don't recall that. Its fair…

The executive in charge at the time of the fiasco came over to Sony BMG from Bertelsmann.

What actually happened to him? I don't think I ever heard.

Re: Sony: All personal data stolen from PSN

#275
I like the first comment on the post:

"Hope it come back quickly"

And ultimately that's what people care about, that information most of them already share it via Facebook for FREE, funny thing, is that we already get spam deliver to our homes in shape of publicity.

About the credit cards, these days most credit card issuers have pretty good security so they'll let you know and block your credit card if people used it in a weird way and believe me, I was a "victim" a couple of times already and it works very well.

I join the 1st commenter. I wont be changing my credit cards because of this and I just care about playing my online games again... really I already got bored of Gran Turismo, Final Fantasy offline ;-).

Re: Sony: All personal data stolen from PSN

#276
post #149

Earlier quoted context omitted.

I would argue the cost of the RRoD was a heck of a lot more than $1B because of all the lost sales. People didn't want to invest in hardware that was going to break 5 times over. Agreed. Microsoft only wrote down the $1B as an expected total cost of fixing broken Xboxes. Who knows how much money they lost?

I've been seeing the notion of accounting for the loss of sales due to "reputation" come up on HN recently and I wish to dispute it. First, most of the time when we're talking about business and we talk about costs we're clearly talking about accounting costs. This applies to startups, too. When you're talking about accounting costs, you don't get to include economic costs (e.g., opportunity cost.) Second, isn't tryi…

I definitely agree, and any "lost sales" are clearly evident in future revenue data. Opportunity costs are factors in economic decisions, but writing them down would be laughable.

My point was that Microsoft probably had some revenue trajectory with slope X before the write-down, and experienced a new revenue trajectory with slope Y < X after the write-down. I'm curious about the area between the two lines.

Re: Sony: All personal data stolen from PSN

#277

Earlier quoted context omitted.

"Goodwill" is the difference between the book value of a company (value of tangible assets) and what it can be sold for. A manufacturer with tooling, machines and inventory might not have much, but a software company's book value is near zero. People are asked to put value on intangibles all the time. You might want to write them all down to zero, but the rest of us value Wordsworth more than the dead trees his words…

No. Goodwill is the difference between the price paid to acquire a company and the book value of the acquired company. To put goodwill on the books, you must buy a company.

Right, the key here is that goodwill is measurable. Opportunity costs are not.

Re: Sony: All personal data stolen from PSN

#278

Earlier quoted context omitted.

No. Goodwill is the difference between the price paid to acquire a company and the book value of the acquired company. To put goodwill on the books, you must buy a company.

Right, the key here is that goodwill is measurable. Opportunity costs are not.

Opportunity costs are measurable. It all depends on your assumptions whether the measurements are reasonable or not.

Ex. If I make $2000 a week as a contractor on a steady contract, I know that the opportunity cost of taking a week of unpaid vacation time is $2000. That's a reasonable, measurable assumption.

However, I could also say that the opportunity cost of that week of vacation will be $12000, because there might be a one-week rush project that will come in that I can bill for $10000 in addition to my normal steady contract. Assuming there's not a pattern of that happening in the past, it's not a reasonable assumption and thus measurable in that way.

I'd say this second scenario is akin to the record companies assuming that every instance of piracy is also an instance of lost sales.

Re: Sony: All personal data stolen from PSN

#279
post #42

Earlier quoted context omitted.

It does carry a risk though - if you make securing a major online service sound too easy by ridiculing your competitor then down the line when you get breached its more damaging imo. eg I dont remember any Car companies in recent history pointing to Service recalls of their competitors in their advertisements, ditto for Airlines and crashes.

Airline crashes would be such a bad PR idea I mean, that's just bad taste.

It is, and that's the example I thought of in response to the point. But car companies do advertise the safety of their cars. The situation is different, though, since different cars do have different safety measures, and such things do get rated.

Re: Sony: All personal data stolen from PSN

#280
post #84

Earlier quoted context omitted.

When credit cards are involved you really need to prepare for the worst case scenario.

Thankfully that's what's great about credit cards (and let's not forget that) - you just ask the bank to deactivate the old one and no more transactions can go through. Also, you should in general not be liable for any fraudulent use of the number. Just dispute it. (my contract said I could be held liable for up to $50 of fraudulent use only in the case where the CARD was stolen and used prior to my reporting it.)

Right, but it's those poor schmucks who used their debit cards online as if they're credit cards that can get really screwed by this.
Post reply on HN