Something went wrong. Try again later

Giant Bomb News

714 Comments

Good News: PSN Back (Maybe) Within a Week, Bad News: Everything Else [Updated]

Sony confirms personal information obtained by outside party. That's fantastic.


No Caption Provided
Update 3: Valve has just told me that anyone who connected their PlayStation Network account to Steam via Portal 2 should not be worried, either. 

"Steam has nothing to do with the PSN outage," said the company in the statement.

Update 2: Regarding rumors Sony may have notified banks days ahead of disclosing today's revelations to the public, I have since contacted customer service representatives at both Bank of America and Chase. I personally have accounts at both financial firms and the representatives claimed to have received no information from Sony about a mass breach of credit information.

Update:  For those who were asking, Sony has just confirmed to me there is currently no way to determine what password you were/are using on PSN. If you're worried at all, you should probably change your password used across the Internet.

Some users have suggested counting the number of "stars" in your saved password as a way to help determine what password you may have been using to access PSN. It's a start.

**

Sony has been frustratingly quiet about the problems afflicting PlayStation Network since the downtime started last week. Who caused the issue in the first place? When will the service be back online? More importantly, has the disruption opened up my personal information to the intruders?

One, Sony isn't talking specifics, with the latest update on the PlayStation Blog from senior director of corporate communications and social media Patrick Seybold only outlining that the company has identified "a compromise of personal information as a result of an illegal intrusion on our systems."

Two, probably within a week--at least for some parts of PSN. "We have a clear path to have PlayStation Network and Qriocity systems back online, and expect to restore some services within a week," said Seybold. "We’re working day and night to ensure it is done as quickly as possible."

Three, the answer is yes. Here's what was available to intruders: "name, address (city, state, zip), country, email address, birthdate, PlayStation Network/Qriocity password and login, and handle/PSN online ID." It's also "possible" that "your profile data, including purchase history and billing address (city, state, zip), and your PlayStation Network/Qriocity password security answers" were included.

Unfortunately, credit card details remain a mystery. "While there is no evidence at this time that credit card data was taken, we cannot rule out the possibility," added Seybold. "If you have provided your credit card data through PlayStation Network or Qriocity, out of an abundance of caution we are advising you that your credit card number (excluding security code) and expiration date may have been obtained."

== TEASER ==The continued air of "possibility" regarding how severely PSN was compromised, several work days and a full weekend after PSN initially went down, is not a particularly reassuring concept. I'd implore you to read Sony's full statement on the matter at the PlayStation Blog, as the company has complete details on what companies to contact regarding credit card fraud, should you notice any errant activity.

"We thank you for your patience as we complete our investigation of this incident, and we regret any inconvenience," reads the end of the statement. "Our teams are working around the clock on this, and services will be restored as soon as possible. Sony takes information protection very seriously and will continue to work to ensure that additional measures are taken to protect personally identifiable information."

Stay tuned as more developments unfold. If you notice your personal information was compromised, feel free to drop us an email or leave a comment below.
Patrick Klepek on Google+

714 Comments

Avatar image for euandewar
EuanDewar

5159

Forum Posts

136

Wiki Points

0

Followers

Reviews: 4

User Lists: 0

Edited By EuanDewar
I can't fucking wait to see Sony's E3 conference this year now.
Avatar image for meowshi
Meowshi

2917

Forum Posts

25

Wiki Points

0

Followers

Reviews: 0

User Lists: 1

Edited By Meowshi

Damn that Anonymous!  They truly are legion!

Avatar image for deactivated-6157afb2b3c07
deactivated-6157afb2b3c07

1026

Forum Posts

2483

Wiki Points

0

Followers

Reviews: 2

User Lists: 4

This is a perfect example why Xbox Live is better. One of those reasons, better protection, as you get what you pay for.

Avatar image for dreamfall31
Dreamfall31

2036

Forum Posts

391

Wiki Points

0

Followers

Reviews: 2

User Lists: 8

Edited By Dreamfall31

Changed all passwords online, just hope it doesnt get my credit card number.  This is fucked up and Sony better do something  good for us.  Maybe free Plus accounts for a month or something?

Avatar image for g0rd0nfr33m4n
G0rd0nFr33m4n

826

Forum Posts

2263

Wiki Points

0

Followers

Reviews: 12

User Lists: 18

Edited By G0rd0nFr33m4n

LOL I feel sorry for anyone who sold there XBOX 360 after red rings saying "well i wont have to deal with this when I buy a ps3" XD

Avatar image for siroptimusprime
SirOptimusPrime

2076

Forum Posts

13

Wiki Points

0

Followers

Reviews: 0

User Lists: 3

Edited By SirOptimusPrime
@PainGod89: So you're telling me the reason my credit card information was possibly stolen is because the service is free?

Get the fuck out. Seriously, lrntofallacy. 
Avatar image for tsai
Tsai

98

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

Edited By Tsai
@Make_Me_Mad said:
" So, is this going to affect only PS3 users, or do the people who bought things from the PSP's online store also need to worry?  If it goes that far, I'll be needing to give my brother a call shortly. "
Oh crap... good point, I also bought stuff from the PSP online store
Avatar image for residentrevil2
Residentrevil2

535

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 2

Edited By Residentrevil2

I need to change my password on my PS3...  This sucks...

Avatar image for vexxan
Vexxan

4642

Forum Posts

943

Wiki Points

0

Followers

Reviews: 0

User Lists: 3

Edited By Vexxan

GG Sony. GG.

Avatar image for raccoonusdoodus
raccoonusdoodus

330

Forum Posts

438

Wiki Points

0

Followers

Reviews: 0

User Lists: 6

Edited By raccoonusdoodus

Fuck you, hackers.

Avatar image for daggon55
daggon55

131

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 3

Edited By daggon55

You know one of the sighs where you puff your cheeks out ... I just did like 3 of those.

Its astounding how badly Sony has mangled the PR aspect of this.

Avatar image for gunharp
gunharp

356

Forum Posts

283

Wiki Points

0

Followers

Reviews: 0

User Lists: 3

Edited By gunharp

Yes, I just read this whole thread. I can only hope my comment doesn't get swallowed up in the nonsense. This news is certainly upsetting.

I don't how some of you think you can specifically point out Sony's fault for the intrusion such as "encryption" --thats your own speculation. We don't know the facts of how the intrusion took place and probably never will. Hell what if it was an inside job? 

It's easy to criticize Sony for a long silence, which is valid to me given this recent update. 
But I think we should remember they had a massive corporate restructuring related to the tsunami, just settled the hotz stuff, experienced external attacks on websites, had their new firmware hacked, allowed for portal 2 cross play with pc/steam linking and launched the cloud save service.  

@WinterSnowblind: 

I think Sony can only be partially blamed. Absolutely Sony's PSN/Qriocity services were the target here and were compromised. But by saying that they are largely to blame at this point, are we not just blaming them for being the victim of the crime? I mean we don't know what happened. If you can see what I am driving at.... 

I especially disagree with the opinion that the intrusion was unacceptable on Sony's part. Given that we know next to nothing. 

@Lukin:
Exactly, they have messed up but no way they could have just given the info away.
Avatar image for hermes
hermes

3000

Forum Posts

81

Wiki Points

0

Followers

Reviews: 0

User Lists: 7

Edited By hermes
@KaosAngel said:
" @damswedon said:
" @KaosAngel said:
" Who the fuck puts user information as a .txt file? "
Wait is that true? "
The news story on ArsTechnica and Reddit said it was right.  They don't BS with that kind of stuff.  They said there was no encryption on the user information...so that means it must've been a .txt file. "
Not necessarily... No encryption means some info is readable without further process (using a program specific for the data files or such) and without having to break any password. CC numbers and passwords are usually encrypted, while addresses or emails are not.
Given the amount of users PSN has, it is very unlikely any information is stored in plain text files... that wouldn't work well.
Avatar image for zecks23
Zecks23

204

Forum Posts

333

Wiki Points

0

Followers

Reviews: 0

User Lists: 6

Edited By Zecks23

This sucks big time. ugh

Avatar image for lukin
Lukin

29

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 2

Edited By Lukin
@TranceAddix said:

" You guys should be worried about your address and birthdate not credit card information, as I said earlier.  "

Why should this be what we worry about most, it is extremely easy to find peoples address and birthdays if you put your mind to it.


I mean do you not get birthday cards sent to your house every year??


How can you really trust your postman/mailman :)  
Avatar image for rvone
RVonE

5027

Forum Posts

8740

Wiki Points

0

Followers

Reviews: 0

User Lists: 6

Edited By RVonE


Fucking ridiculous.

Also, they waited a week before breaking this news to us. WTF, Sony?!

Avatar image for siphillis
Siphillis

1357

Forum Posts

6549

Wiki Points

0

Followers

Reviews: 2

User Lists: 17

Edited By Siphillis
@Fira said:
" maybe it is time to switch to the xbox. how does sony keep fucking stuff up like this? "
Because they are a clueless company that has utterly no idea as to how the PlayStation brand was ever successful.

Well that, and they sued GeoHot.  There's a reason no other company would dare to do that, right or wrong.
Avatar image for video_game_king
Video_Game_King

36563

Forum Posts

59080

Wiki Points

0

Followers

Reviews: 54

User Lists: 14

Edited By Video_Game_King

Shit. I'd say that this makes me glad that I don't own a PS3, but I still want to play all those cool games.

Avatar image for tehflan
TehFlan

1954

Forum Posts

693

Wiki Points

0

Followers

Reviews: 1

User Lists: 11

Edited By TehFlan
@I_smell said:
" IT ONLYDOESIDENTITY THEFT! "
Well played, sir.
Avatar image for lutonhatter
lutonhatter

389

Forum Posts

360

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

Edited By lutonhatter
@Poki3:

From here:

Q.6 Does that mean all users’ information was compromised? Tell us more in details of what personal information leaked.

In terms of possibility, yes. We believe that an unauthorized person has obtained the following information that you provided: name, address (city, state/province, zip or postal code), country, email address, birthdate, PlayStation Network/Qriocity password, login, password security answers, and handle/PSN online ID. It is also possible that your profile data may have been obtained, including purchase history and billing address (city, state/province, zip or postal code). If you have authorized a sub-account for your dependent, the same data with respect to your dependent may have been obtained. If you have provided your credit card data through PlayStation Network or Qriocity, it is possible that your credit card number (excluding security code) and expiration date may also have been obtained.

Which I take to mean, er assuming they has enough disk space that their end, yes.
Avatar image for wintersnowblind
WinterSnowblind

7599

Forum Posts

41

Wiki Points

0

Followers

Reviews: 0

User Lists: 4

Edited By WinterSnowblind
@Gunharp: If you don't want to blame Sony, that's up to you.. Knowing that all of my personal information has been lost because of them perhaps makes me somewhat biased.  However, if credit card details and other sensitive personal details have indeed been compromised to this degree, then every single PSN user can take Sony to court over negligence and would most certainly win the case.

I can't overstate how bad this situation is for Sony.
Avatar image for finalcut
FinalCut

133

Forum Posts

2

Wiki Points

0

Followers

Reviews: 0

User Lists: 23

Edited By FinalCut

Nothing is un-hackable, especially the PSN. The only group I blame for this are the hackers as no matter how secure Sony's system was if they wanted that information bad enough they were going to get it. 


 This isn't even sweat off of my back though as I use a multitude of passwords/login information. Hopefully no one will be seriously affected and this whole thing can be put behind us and we can put that focus on games instead.
Avatar image for fallen189
Fallen189

5453

Forum Posts

10463

Wiki Points

0

Followers

Reviews: 1

User Lists: 4

Edited By Fallen189
@RVonE said:
"


Fucking ridiculous.

Also, they waited a week before breaking this news to us. WTF, Sony?!

"
It was the easter break, cut them some slack
Avatar image for rachelepithet
rachelepithet

1646

Forum Posts

1374

Wiki Points

0

Followers

Reviews: 3

User Lists: 11

Edited By rachelepithet

So does this mean people will actually start to care how when a black kid steals a CD from FYE he faces jail time, absurd fines, and a "record"  that will ruin his chances of ever advancing in life, while some white kid that builds explosives in his parents garage and spends his days threatening to kill 11 year old girls on myspace until they send him naked pictures and then threatens to show said pictures to her parents unless they meet him in person... steals 10,000 albums of MP3s and gets a mere "don't ever tamper with security systems again" slap on the wrist?

Avatar image for skald
Skald

4450

Forum Posts

621

Wiki Points

0

Followers

Reviews: 11

User Lists: 7

Edited By Skald

God fucking dammit. Well, I have some passwords that need to be changed now.


Fuck.
Avatar image for hermes
hermes

3000

Forum Posts

81

Wiki Points

0

Followers

Reviews: 0

User Lists: 7

Edited By hermes
@Tsai said:
" @Make_Me_Mad said:
" So, is this going to affect only PS3 users, or do the people who bought things from the PSP's online store also need to worry?  If it goes that far, I'll be needing to give my brother a call shortly. "
Oh crap... good point, I also bought stuff from the PSP online store "
They share the same infrastructure... If I had to guess, I would say: yes.
Avatar image for andymp
andymp

257

Forum Posts

163

Wiki Points

0

Followers

Reviews: 2

User Lists: 4

Edited By andymp

Why were the passwords not encrypted ? Seriously, basic web forum software encrypts passwords. This is much worse than I expected. Do we know if they secured access to card numbers ?

Avatar image for kaj235
Kaj235

51

Forum Posts

114

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

Edited By Kaj235

Can anyone else login or see the login screen? It says the servers are down for maintenance but I just want to see how many letters my password was.

Avatar image for battletoad
Battletoad

146

Forum Posts

1

Wiki Points

0

Followers

Reviews: 2

User Lists: 8

Edited By Battletoad


"599 U.S. Dollars"

 

"So here's this giant enemy crab"

 

"RNG=4"

 

Sony's hosting provider belittled Anonymous' cyber-attack as "medium strength," and something that only "annoyed our network engineers."

 

"Unencrypted txt.files for PSN user information"

 

"Credit Card information "possibly" obtained"

 

"Anybody want to buy a PS Tablet? It can play PSONE games if you give us your CC number"

 

 

 

 

Avatar image for calculating_infinity
Calculating_Infinity

67

Forum Posts

3

Wiki Points

0

Followers

Reviews: 0

User Lists: 1

Wow sony, wow. Not only have people now access to all our details from passwords to addresses to birth dates and so on, also the security question you answered. Identity theft for all PSN users ahoy. I am really happy that I got a new credit card about a month ago and never got to use the new one on psn.

"While there is no evidence at this time that credit card data was taken, we cannot rule out the possibility." Yeah fuck you sony, guess that means that has been stolen to. Great to wait 6 days before warning people of this too.    

Avatar image for elcalavera
elcalavera

392

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 3

Edited By elcalavera
@Fallen189 said:
It was the easter break, cut them some slack "
Yes, because Sony are children in school and not one of the biggest companies in the world.
Avatar image for delusibeta
Delusibeta

71

Forum Posts

30

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

Edited By Delusibeta

 @Little_Socrates said:

WAIT. Do you think they have access to your Steam info through Portal 2? If they do...goddammit..
"
Well, assuming that Valve used their OpenID implementation, they should at worst have your Steam username and/or Steam Community name (in other words, little more than you give to Giant Bomb for achievement scraping purposes). Of course, it's probably wise to change your Steam password regardless, especially if it's the same as your PSN password.
Avatar image for omegapirate
OmegaPirate

5643

Forum Posts

6172

Wiki Points

0

Followers

Reviews: 0

User Lists: 5

Edited By OmegaPirate

Fallens post is the only sensible one in here 


Gonna have to thank all y'all running round screaming about the end of sony and how you are boycotting - next gen etc etc etc. because your headless chicken "WE FINALLY HAVE A LEGITIMATE REASON TO ACT LIKE IDIOTS" knee jerk reaction posts, are providing the comedy to help me laugh through this terrible news.

It aint as if Sony handed the info over to them on a golden platter, it was stolen meaning some asshole wen't out of their way to make your lives miserable. And i'm really not sure that any of you would've handled the responsibility of finding out what is going on, sorting an investigation, shutting down your servers on the launch of 3 AAA titles, as well as managing how badly this is fucking up developers. Rebuilding an online infrastructure from scratch, building new security, and deciding how to handle the news and deliver it to several million people. 

End of the day, your info is just as secure on PSN as anywhere else, screaming THIS IS WHAT YOU PAY FOR WITH LIVE!! is fucking retarded, guess what, some snot nosed punk decides to take a crack at microsofts servers? say hello to another data breach (and dont cry about microsoft knowing about security, i know several people, consoles and pc's that would beg to differ)

I think the funniest thing in all this, is the scuttlebutt mentioning that the 'hack' may have been implemented through a custom firmware uploaded through the OtherOS option that allowed non devkit ps3's access to private servers. 
If this is true, then sony very well DID secure their services and lock down potential loopholes - but your internet white knight hacker gangs demanded the piracy hole be open, and now everyones crying about it.

But hey, what do i know, im just a pissed off gamer with 2 consoles, one of which is out of action right now, why not try taking the advice of someone with a bit more knowledge in the matter?


Or hey, how about running around posting in all caps about how master chief is a cool guy who doesnt afraid of anything and ps3 sux, that's productive too 
Avatar image for cogzwell
Cogzwell

352

Forum Posts

95

Wiki Points

0

Followers

Reviews: 3

User Lists: 11

Edited By Cogzwell

the poop hits the fan in 3...2.....

Avatar image for pickingwings
Pickingwings

185

Forum Posts

689

Wiki Points

0

Followers

Reviews: 0

User Lists: 3

Edited By Pickingwings

Good thing my credit card information had already expired and I was too lazy to add my new one. Though I'm still not too comfortable about the hackers being able to see my other personal information. I just hope that Sony can hurry up and fix this crap up already.

Avatar image for mrhankey
mrhankey

781

Forum Posts

347

Wiki Points

0

Followers

Reviews: 26

User Lists: 2

Edited By mrhankey

While the rate at which they responded was inconvenient...to say the least. Like many other people in this thread think of it this way. You are SONY. You live in a nice house. Then one day you get ROBBED!!!!!! Who is to blame? You for not buying that shotgun? Your wife did in fact tell you she was afraid you'd shoot the kids (e.g. PSP). Or the Robber for deciding that he could blow through your metal door with some TNT? Or, is it a combination of the two? I say it's a combination, and though it is fun to hate on a corporation such as SONY, you need to realize they didn't will it to happen, nor did they invite the hacker to "test" their network. Shit happens. Take the necessary steps to prevent any harm to yourself, cancel your credit cards. Call your bank, etc...

Avatar image for professoress
ProfessorEss

7962

Forum Posts

160

Wiki Points

0

Followers

Reviews: 0

User Lists: 11

Edited By ProfessorEss
@MattyFTM said: 

" It might have been a smart move to let people know that their personal information, possibly including credit card info, had been stolen as soon as it happened. Waiting 5 days before telling anyone about it is amazingly dumb.  "

This to me is the most disturbing aspect of the whole situation and shakes my faith in Sony much more than their poor security. I mean seriously, they can shut down PSN instantly without warning when they think someone's getting something off of them for free, but it takes almost a week for them to let us know this?

And for anyone planning to say "maybe they just found out" I'll add: Them taking a week to find out whether users information was potentially compromised disturbs me just as much. 
Avatar image for tranceaddix
tranceaddix

101

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 1

Edited By tranceaddix
@Lukin:

Birthdays are actually vital to a lot of financial institutions/establishments. I agree about the address being easily accessible. Linked together, though it can be troublesome in the right hands.

Fraudulent charges on the CC can be easily overturned (especially if caught early).  Personally, I know AMEX is great when it comes to that.
Avatar image for jmartnwa
JMartNWA

208

Forum Posts

18

Wiki Points

0

Followers

Reviews: 0

User Lists: 5

Edited By JMartNWA
@theandrewtaylor:  You hurt your point using "black" and "white" in my opinion.  The rest of it makes some sense, but not that portion, at least to me personally.
Avatar image for battletoad
Battletoad

146

Forum Posts

1

Wiki Points

0

Followers

Reviews: 2

User Lists: 8

Edited By Battletoad
@Fallen189:
Easter was 7 days ago?
Avatar image for subjugation
Subjugation

4993

Forum Posts

963

Wiki Points

0

Followers

Reviews: 0

User Lists: 1

Edited By Subjugation

What a monumental screw up.

Avatar image for spankingaddict
spankingaddict

3009

Forum Posts

0

Wiki Points

0

Followers

Reviews: 11

User Lists: 12

Edited By spankingaddict

Hopefully those intruders die a painful,painful death.

Avatar image for fallen189
Fallen189

5453

Forum Posts

10463

Wiki Points

0

Followers

Reviews: 1

User Lists: 4

Edited By Fallen189
@elcalavera said:
" @Fallen189 said:
It was the easter break, cut them some slack "
Yes, because Sony are children in school and not one of the biggest companies in the world. "
You are aware that Easter is one of the biggest religous events on the Christian calendar right? Or are you just ignorant
Avatar image for vetlenm
VetleNM

89

Forum Posts

38

Wiki Points

0

Followers

Reviews: 0

User Lists: 4

Edited By VetleNM

Dude, what the hell, Sony. Seriously. What the hell. Screw the hackers and screw Sony. This sucks. 

Avatar image for crazedjoker
CrazedJoker

332

Forum Posts

120

Wiki Points

0

Followers

Reviews: 1

User Lists: 3

Edited By CrazedJoker

Kind of fucked up that even if you wanted to change your password, you can't, you can't even sign on, on the site currently.


Avatar image for elcalavera
elcalavera

392

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 3

Edited By elcalavera
@Fallen189 said:
You are aware that Easter is one of the biggest religous events on the Christian calendar right? Or are you just ignorant "
I think we'll have to label me as an ignorant.
Avatar image for enigma777
Enigma777

6285

Forum Posts

696

Wiki Points

0

Followers

Reviews: 0

User Lists: 8

Edited By Enigma777

The amount if idiotic fanboy drivel in these comments is disgusting. I mean come the fuck on, this is 2011! I thought we were past the console wars bullshit. 

Avatar image for mijati
Mijati

1086

Forum Posts

526

Wiki Points

0

Followers

Reviews: 0

User Lists: 6

Edited By Mijati
@Fallen189:  That is NO excuse at all. Not only would they have had people in anyway when this situation was known it would have been an emergency, they'd have had to contact everyone involved in the company.

I worked all Weekend (friday/Saturday/Sunday) and we had to make an emergency call out when some servers went down, and that's nothing compared to a possible security breach. It being an easter weekend is a horrid excuse and just Sony fanboys trying to shift the blame elsewhere.
Avatar image for trajan330
Trajan330

9

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

Edited By Trajan330

How are you supposed to change your password and other info if you can't even get into the system?

Avatar image for lazyb
lazyb

58

Forum Posts

2

Wiki Points

0

Followers

Reviews: 0

User Lists: 1

Edited By lazyb

even as a Sony fanboy its hard to defend Sony its completely unacceptable. I'm glad I just bought psn card to refill my account. This a a major set back for Sony to say the least. what a shame