Something went wrong. Try again later

Giant Bomb News

118 Comments

Hey, You Should Read This: Sony Responds to Congress

Evidence of hacker group Anonymous found in one of the attacks.


Sony's answers to Congress spanned eight pages, with plenty of new details on the attack.
Sony's answers to Congress spanned eight pages, with plenty of new details on the attack.
When Congress knocks, you answer. Sony has filed their response to a subcommittee inquiry regarding the PlayStation Network security intrusion, which I've spent the morning reading through and pulling the most relevant details.

The company has continued to face criticism over waiting several days to inform consumers about the intrusion on their personal data. Early in the document, PlayStation executive Kaz Hirai answered that critique directly.

"Sony Network Entertainment America immediately hired a highly regarded information technology firm and supplemented that firm with additional expertise and resources over several days," explained Hirai. "Sony Network Entertainment then released information to its customers we we and those experts believed that information was sufficiently confirmed. The truth is that retracing the steps of experienced cyber attackers is a highly complex process that takes time to carry out effectively."

Hirai's answers provide an update on the evidence Sony has against the intruders. The popular theory has been infamous hacker organization Anonymous, who declared their intentions to disrupt Sony's operations, following a lawsuit against hacker GeoHot, who essentially cracked the PlayStation code. Anonymous had publicly distanced itself from the PSN debacle, but Sony points to tangible evidence.

== TEASER =="When Sony Online Entertainment discovered this past Sunday afternoon that data from its servers had been stolen," said Hirai, "it also discovered that the intrduers had planted a file on one of the servers named 'Anonymous' with the words 'We are Legion.'" 

Asked point blank whether it had positively identified the intruders, however, the company could not.

According to Sony's timeline, the hackers--possibly Anonymous--gained access while its servers were experiencing denial of service attacks. The company became aware on April 19 at 4:15 p.m. PST, with systems performing unscheduled reboots. Sony claims its response to the attack was slow due to the "sophistication of the intrusion" and the attack funneled through a "system software vulnerability." Sony was unable to determine whether those who gained access during the denial of service attacks were knowingly working in cahoots with the people actually perpetuating the denial of service attacks.

Sony informed the FBI on April 22. At the time, the company says it didn't know the full extent of the attack and scheduled a meeting to inform law enforcement on April 27. On April 26, Sony collected what it knew, published some details to the public and contacted regulatory agencies in states nationwide.

And while Sony still cannot rule out whether credit card information was definitely not taken, it has received no reports of mass fraud from any financial institutions assumed to be connected to PSN. The company believes 10 million credit cards were exposed but cannot determine if details were taken.

"Our forensics team have not seen queries and corresponding data transfers of the credit card information," said Hirai.

How many credit cards are even in the system? Sony says PSN account data shows 12.3 million credit cards across the 77 million registered accounts, though only 5.6 of them are here in the United States.

Sony's congressional answers represent our best look yet into the who, what, where and whys of the PSN attack. It's too bad Sony didn't make this same information available to its 77 million consumers.
Patrick Klepek on Google+

118 Comments

Avatar image for patrickklepek
patrickklepek

6835

Forum Posts

1300

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

Edited By patrickklepek

Sony's answers to Congress spanned eight pages, with plenty of new details on the attack.
Sony's answers to Congress spanned eight pages, with plenty of new details on the attack.
When Congress knocks, you answer. Sony has filed their response to a subcommittee inquiry regarding the PlayStation Network security intrusion, which I've spent the morning reading through and pulling the most relevant details.

The company has continued to face criticism over waiting several days to inform consumers about the intrusion on their personal data. Early in the document, PlayStation executive Kaz Hirai answered that critique directly.

"Sony Network Entertainment America immediately hired a highly regarded information technology firm and supplemented that firm with additional expertise and resources over several days," explained Hirai. "Sony Network Entertainment then released information to its customers we we and those experts believed that information was sufficiently confirmed. The truth is that retracing the steps of experienced cyber attackers is a highly complex process that takes time to carry out effectively."

Hirai's answers provide an update on the evidence Sony has against the intruders. The popular theory has been infamous hacker organization Anonymous, who declared their intentions to disrupt Sony's operations, following a lawsuit against hacker GeoHot, who essentially cracked the PlayStation code. Anonymous had publicly distanced itself from the PSN debacle, but Sony points to tangible evidence.

== TEASER =="When Sony Online Entertainment discovered this past Sunday afternoon that data from its servers had been stolen," said Hirai, "it also discovered that the intrduers had planted a file on one of the servers named 'Anonymous' with the words 'We are Legion.'" 

Asked point blank whether it had positively identified the intruders, however, the company could not.

According to Sony's timeline, the hackers--possibly Anonymous--gained access while its servers were experiencing denial of service attacks. The company became aware on April 19 at 4:15 p.m. PST, with systems performing unscheduled reboots. Sony claims its response to the attack was slow due to the "sophistication of the intrusion" and the attack funneled through a "system software vulnerability." Sony was unable to determine whether those who gained access during the denial of service attacks were knowingly working in cahoots with the people actually perpetuating the denial of service attacks.

Sony informed the FBI on April 22. At the time, the company says it didn't know the full extent of the attack and scheduled a meeting to inform law enforcement on April 27. On April 26, Sony collected what it knew, published some details to the public and contacted regulatory agencies in states nationwide.

And while Sony still cannot rule out whether credit card information was definitely not taken, it has received no reports of mass fraud from any financial institutions assumed to be connected to PSN. The company believes 10 million credit cards were exposed but cannot determine if details were taken.

"Our forensics team have not seen queries and corresponding data transfers of the credit card information," said Hirai.

How many credit cards are even in the system? Sony says PSN account data shows 12.3 million credit cards across the 77 million registered accounts, though only 5.6 of them are here in the United States.

Sony's congressional answers represent our best look yet into the who, what, where and whys of the PSN attack. It's too bad Sony didn't make this same information available to its 77 million consumers.
Avatar image for sil
SIL

9

Forum Posts

3

Wiki Points

0

Followers

Reviews: 0

User Lists: 1

Edited By SIL

I just love it...

Avatar image for tesla
Tesla

2299

Forum Posts

1

Wiki Points

0

Followers

Reviews: 0

User Lists: 4

Edited By Tesla

This looks like the work of one Crash Override.

Avatar image for driveuplife
DriveupLife

1214

Forum Posts

233

Wiki Points

0

Followers

Reviews: 1

User Lists: 3

Edited By DriveupLife

fucking 4chan.

Avatar image for chumm
Chumm

347

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

Edited By Chumm

Looks like that Kaz quote wasn't transcribed right, got a "we we", shoudl be ". We" I think

Avatar image for brocool
brocool

706

Forum Posts

4

Wiki Points

0

Followers

Reviews: 0

User Lists: 2

Edited By brocool

Send Hobbs after them

Avatar image for hamz
Hamz

6900

Forum Posts

25432

Wiki Points

0

Followers

Reviews: 2

User Lists: 5

Edited By Hamz

Seem's like Sony just can't catch a break lately.

Avatar image for krazy_kyle
krazy_kyle

740

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 3

Edited By krazy_kyle

Anonymous are just a bunch of nerdy computer geeks who think they are doing justice, but instead they are wasting people's time and inconveniencing others.
Avatar image for seraphim84
Seraphim84

485

Forum Posts

1990

Wiki Points

0

Followers

Reviews: 5

User Lists: 3

Edited By Seraphim84

Anonymous is really more of a not-organization.


Whatever the case, Sony still should've been more upfront no matter how bad the situation is.
Avatar image for authenticm
AuthenticM

4404

Forum Posts

12323

Wiki Points

0

Followers

Reviews: 1

User Lists: 2

Edited By AuthenticM
@brocool said:
" Send Hobbs after them "
Avatar image for striderno9
striderno9

1362

Forum Posts

3

Wiki Points

0

Followers

Reviews: 3

User Lists: 6

Edited By striderno9

Wow, this keeps getting uglier. So Sony says they have evidence.

Avatar image for bonechompski
BoneChompski

421

Forum Posts

2

Wiki Points

0

Followers

Reviews: 0

User Lists: 3

Edited By BoneChompski

Sony relied on point of entry protection and did not deploy sufficient heuristic or otherwise internal monitors.  The problem that this intrusion has exposed is that Sony has a bull $h!t attitude towards safety and sub-competent IT management.

Avatar image for thrice
THRICE

179

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 2

Edited By THRICE

Every time someone mentions Anonymous I immediately envision them less Matthew Lilliard in Hackers and more the player killer from the Make Love Not WarCraft episode of South Park. 

Avatar image for muttersometaxicab
MuttersomeTaxicab

826

Forum Posts

5471

Wiki Points

0

Followers

Reviews: 0

User Lists: 25

@Tesla said:
"This looks like the work of one Crash Override. "


Well shit on me. *puts on mirrorshades*

 

...

 

 

....

 

.....

 

......

 

 

 

YEAHHHHHHHHHHHHHHHHHHHHHHHH.

Avatar image for umdesch4
umdesch4

787

Forum Posts

135

Wiki Points

0

Followers

Reviews: 0

User Lists: 1

Edited By umdesch4
@Chumm said:
" Looks like that Kaz quote wasn't transcribed right, got a "we we", shoudl be ". We" I think "
I read it as "when we", as he's trying to justify the delay in getting info out.
Avatar image for refugee
Refugee

43

Forum Posts

558

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

Edited By Refugee

Reportedly the attack was due to a documented send_mail bug in an out dated version of Apache.

Avatar image for wickedsc3
wickedsc3

1044

Forum Posts

51

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

Edited By wickedsc3

The very last sentence says it all. 

Avatar image for tadthuggish
TadThuggish

1074

Forum Posts

334

Wiki Points

0

Followers

Reviews: 2

User Lists: 41

Avatar image for sbym
SBYM

1203

Forum Posts

377

Wiki Points

0

Followers

Reviews: 7

User Lists: 1

Edited By SBYM

Damn you, Zero Cool!

Avatar image for bumpton
Bumpton

507

Forum Posts

62

Wiki Points

0

Followers

Reviews: 0

User Lists: 4

Edited By Bumpton

Now, I don't have a PS3 or anything, but this whole thing has been super entertaining to read. I'd be kind of annoyed if it happened to XBL... I don't really play any multiplayer stuff though, so I can't imagine freaking out too much.
Avatar image for double0hfor
Double0hFor

416

Forum Posts

47

Wiki Points

0

Followers

Reviews: 1

User Lists: 3

Edited By Double0hFor

Sony should stick to TVs and surround sounds

Avatar image for dingofighter
Dingofighter

1888

Forum Posts

251

Wiki Points

0

Followers

Reviews: 0

User Lists: 3

Edited By Dingofighter

Just because they found a file named Anonymous doesn't have to mean they were really behind it, right? I mean the hackers could have put that there to mislead them.


Or maybe they didn't, but it's possible...
Avatar image for undeadpool
Undeadpool

8424

Forum Posts

10761

Wiki Points

0

Followers

Reviews: 20

User Lists: 18

Edited By Undeadpool

Just remember: they stole your information and credit card numbers (and probably sold them) for YOUR benefit! They're sticking it to The Man by selling your info! Now THANK THEM!

Avatar image for phish09
phish09

1138

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

Edited By phish09

Did Patrick write this article?  Just asking because of the final line "How many credit cards are even in the system? Sony says PSN account data shows 12.3 million credit cards across the 77 million registered accounts, though only 5.6 of them are here in the United States."  I take it Patrick is not trying to say it is any less of an inconvenience for people that don't live in the States, and he is writing the article from in the States, however, this is the internet and it is not inherently American.  So I'm reading this article in Canada, and I read "Here in the States" and I think to myself "What does he mean?  We're reading this in Canada". 

Not a big deal or anything...but with online journalism I think it's should be assumed that your audience is going to be worldwide and the writing should probably reflect that in some way or another.

Avatar image for kjellm87
Kjellm87

1735

Forum Posts

2788

Wiki Points

0

Followers

Reviews: 0

User Lists: 1

Edited By Kjellm87

  While I'm not a fan of this "Anonymous", I think that file seems a little too perfect.
There could be someone else who puts the blame on them.

Avatar image for nazgul11
nazgul11

3

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

Edited By nazgul11
@brocool said:
" Send Hobbs after them "
Avatar image for slaker117
Slaker117

4873

Forum Posts

3305

Wiki Points

0

Followers

Reviews: 1

User Lists: 11

Edited By Slaker117

This ordeal continues to be crazy.

Avatar image for commando
Commando

1999

Forum Posts

249

Wiki Points

0

Followers

Reviews: 0

User Lists: 2

Edited By Commando

Maybe they'll finally be able to shut down 4chan. They're just a bunch of attention whores.

Avatar image for milkman
Milkman

19372

Forum Posts

-1

Wiki Points

0

Followers

Reviews: 2

User Lists: 3

Edited By Milkman

At this point, I think it's everyone's best interest to just get goddamn PSN back up and running. Fuck 4chan and all this other bullshit. As a customer, what it comes down to is that I just want to play my damn games.

Avatar image for noxious
NoXious

1268

Forum Posts

365

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

Edited By NoXious
@phish09:
This letter from Sony is to Congress. You know, the American one, so the response is as literal as it gets. This is the response Sony gives to the US Congress, that the potential Credit Card fraud might not be as big as they expected because of the "low" amount of them being from the US.
It baffled me but that's how Sony looks at it, fuck it that we lost the PRIVATE DATA of 77 million customers across the World.
Avatar image for guypussy
guypussy

30

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

Edited By guypussy
 Asked point blank whether it had positively identified the intruders, however, the company could not.

But, but, the text file they left!
Avatar image for schlorgan
schlorgan

423

Forum Posts

45

Wiki Points

0

Followers

Reviews: 1

User Lists: 7

Edited By schlorgan

"We Are Legion?"
FUCK! IT'S THE REAPERS!!!

Avatar image for milkman
Milkman

19372

Forum Posts

-1

Wiki Points

0

Followers

Reviews: 2

User Lists: 3

Edited By Milkman

That being said, I hope the FBI busts into every basement of every mother of every 14 year old responsible for this and makes the little bitches cry. 

Avatar image for littlemanbodie
littlemanbodie

139

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

Edited By littlemanbodie

Is it just me or does it seem like the same story is now being posted everyday?

Avatar image for chumm
Chumm

347

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

Edited By Chumm
No Caption Provided
Avatar image for nomin
Nomin

1004

Forum Posts

245

Wiki Points

0

Followers

Reviews: 11

User Lists: 9

Edited By Nomin

Sony better prop up some military AI into their ICE so even a Kuang grade virus can't infiltrate it. 

Avatar image for capnmikem
CapnMikeM

21

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 3

Edited By CapnMikeM

i have zero confidence that the PSN is coming back any time soon.  I think, in their minds, having to answer to Congress has bought them more time.  Would be shocked to see the service back up before next Monday.

Avatar image for dagas
dagas

3686

Forum Posts

851

Wiki Points

0

Followers

Reviews: 1

User Lists: 8

Edited By dagas

Why would they leave a file and then claim they had nothing to do with it? Makes no sense. Either they would leave the file and claim responsibility or not leave a file and not claim responsibility. 

Avatar image for mordukai
mordukai

8516

Forum Posts

398

Wiki Points

0

Followers

Reviews: 0

User Lists: 1

Edited By mordukai

Doesn't the congress have better things to do ? I guess when the government you work in and the country you "work for" is that perfect then you need something to fill the time. 

Avatar image for jayzilla
Jayzilla

2709

Forum Posts

18

Wiki Points

0

Followers

Reviews: 0

User Lists: 7

Edited By Jayzilla

I am glad(at the moment) that I don't own a PS3 or play any SOE games. Hackers need to start getting punished to the letter of the law though. Hurting people's entertainment is dumb.

Avatar image for loktarogar
LoktarOgar

698

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

Edited By LoktarOgar

"We are Legion"
next story posted on GiantBomb:
"Mass Effect 3 Delayed into Early 2012"

Sony not too keen on having Anonymous representative Legion in Mass Effect 3, forces Bioware to take him out of the story. Lair of the Shadow Broker pretty much confirmed that Legion's into hacking servers.

Avatar image for crusader8463
crusader8463

14850

Forum Posts

4290

Wiki Points

0

Followers

Reviews: 7

User Lists: 5

Edited By crusader8463

Why is it just the US legal system doing stuff about this? Last time I checked this affected the entire world.

Avatar image for hydraham
HydraHam

1380

Forum Posts

675

Wiki Points

0

Followers

Reviews: 0

User Lists: 6

Edited By HydraHam
@Undeadpool said:
" Just remember: they stole your information and credit card numbers (and probably sold them) for YOUR benefit! They're sticking it to The Man by selling your info! Now THANK THEM! "
Anon proved to the world along time ago they aren't for the people, they are for themselves and i will say it again, FUCK everyone involved with, FUCK anon and at night i pray to god FBI knocks down the basement doors and drags them from their parents basement and locks them up.

I hope they get everything coming to them because they are nothing but petty no-life mother fuckers.
Avatar image for blackjosh
blackjosh

69

Forum Posts

0

Wiki Points

0

Followers

Reviews: 2

User Lists: 4

Edited By blackjosh
@Chumm said:
" Looks like that Kaz quote wasn't transcribed right, got a "we we", shoudl be ". We" I think "
so all this time kaz was french! holy shit.

mindsploded
Avatar image for milkman
Milkman

19372

Forum Posts

-1

Wiki Points

0

Followers

Reviews: 2

User Lists: 3

Edited By Milkman
@Mordukai said:
" Doesn't the congress have better things to do ? I guess when the government you work in and the country you "work for" is that perfect then you need something to fill the time.  "
Millions of people had their credit card information potentially stolen. To us, it may just seem like "oh, those silly video games." But this could be huge issue.
Avatar image for crazedjoker
CrazedJoker

332

Forum Posts

120

Wiki Points

0

Followers

Reviews: 1

User Lists: 3

Edited By CrazedJoker

My email has started sending people weird spam shit. Kinda of wondering if this has to do with PSN...

Avatar image for jensonb
Jensonb

2092

Forum Posts

3407

Wiki Points

0

Followers

Reviews: 3

User Lists: 8

Edited By Jensonb

It's high time someone knocked Anonymous down a peg. Even if they're only being framed for the intrusion - and there's no way of knowing if they are or not - the DDoS was their doing.

Avatar image for mraristocrates
MrAristocrates

197

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

Edited By MrAristocrates
@guypussy:  It's impossible to know whether it's a member of Anonymous who thought it would be amusing to screw everyone else over, or just the real hacker trying to frame someone. Poorly.
Avatar image for quicksand31
quicksand31

83

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 1

Edited By quicksand31

props for using the word "cahoots."