Something went wrong. Try again later

Giant Bomb News

118 Comments

Hey, You Should Read This: Sony Responds to Congress

Evidence of hacker group Anonymous found in one of the attacks.


Sony's answers to Congress spanned eight pages, with plenty of new details on the attack.
Sony's answers to Congress spanned eight pages, with plenty of new details on the attack.
When Congress knocks, you answer. Sony has filed their response to a subcommittee inquiry regarding the PlayStation Network security intrusion, which I've spent the morning reading through and pulling the most relevant details.

The company has continued to face criticism over waiting several days to inform consumers about the intrusion on their personal data. Early in the document, PlayStation executive Kaz Hirai answered that critique directly.

"Sony Network Entertainment America immediately hired a highly regarded information technology firm and supplemented that firm with additional expertise and resources over several days," explained Hirai. "Sony Network Entertainment then released information to its customers we we and those experts believed that information was sufficiently confirmed. The truth is that retracing the steps of experienced cyber attackers is a highly complex process that takes time to carry out effectively."

Hirai's answers provide an update on the evidence Sony has against the intruders. The popular theory has been infamous hacker organization Anonymous, who declared their intentions to disrupt Sony's operations, following a lawsuit against hacker GeoHot, who essentially cracked the PlayStation code. Anonymous had publicly distanced itself from the PSN debacle, but Sony points to tangible evidence.

== TEASER =="When Sony Online Entertainment discovered this past Sunday afternoon that data from its servers had been stolen," said Hirai, "it also discovered that the intrduers had planted a file on one of the servers named 'Anonymous' with the words 'We are Legion.'" 

Asked point blank whether it had positively identified the intruders, however, the company could not.

According to Sony's timeline, the hackers--possibly Anonymous--gained access while its servers were experiencing denial of service attacks. The company became aware on April 19 at 4:15 p.m. PST, with systems performing unscheduled reboots. Sony claims its response to the attack was slow due to the "sophistication of the intrusion" and the attack funneled through a "system software vulnerability." Sony was unable to determine whether those who gained access during the denial of service attacks were knowingly working in cahoots with the people actually perpetuating the denial of service attacks.

Sony informed the FBI on April 22. At the time, the company says it didn't know the full extent of the attack and scheduled a meeting to inform law enforcement on April 27. On April 26, Sony collected what it knew, published some details to the public and contacted regulatory agencies in states nationwide.

And while Sony still cannot rule out whether credit card information was definitely not taken, it has received no reports of mass fraud from any financial institutions assumed to be connected to PSN. The company believes 10 million credit cards were exposed but cannot determine if details were taken.

"Our forensics team have not seen queries and corresponding data transfers of the credit card information," said Hirai.

How many credit cards are even in the system? Sony says PSN account data shows 12.3 million credit cards across the 77 million registered accounts, though only 5.6 of them are here in the United States.

Sony's congressional answers represent our best look yet into the who, what, where and whys of the PSN attack. It's too bad Sony didn't make this same information available to its 77 million consumers.
Patrick Klepek on Google+

118 Comments

Avatar image for test0r
test0r

121

Forum Posts

7

Wiki Points

0

Followers

Reviews: 0

User Lists: 1

Edited By test0r
People should be pissed off at Sony, since they are so far the only party that we know did something wrong.
Avatar image for 234rqsd2323d2
234r2we232

3175

Forum Posts

2007

Wiki Points

0

Followers

Reviews: 0

User Lists: 16

Edited By 234r2we232

Hackers are hackers. None of them can be trusted.


I hope they're all caught and consequently abused in jail. All of them.
Avatar image for jeust
Jeust

11739

Forum Posts

15085

Wiki Points

0

Followers

Reviews: 8

User Lists: 15

Edited By Jeust
@Tesla said:

" This looks like the work of one Crash Override. "

Zero Cool. ^^
Avatar image for ultimatepunchrod
ultimatepunchrod

361

Forum Posts

0

Wiki Points

0

Followers

Reviews: 3

User Lists: 1

Edited By ultimatepunchrod
@Jeust said:
" @Tesla said:

" This looks like the work of one Crash Override. "

Zero Cool. ^^ "
except for neither of them would hack anything that isnt the gibson. PSN is sort of a step down dont you think? lol
Avatar image for jeust
Jeust

11739

Forum Posts

15085

Wiki Points

0

Followers

Reviews: 8

User Lists: 15

Edited By Jeust
@ultimatepunchrod said:
" @Jeust said:
" @Tesla said:

" This looks like the work of one Crash Override. "

Zero Cool. ^^ "
except for neither of them would hack anything that isnt the gibson. PSN is sort of a step down dont you think? lol "
Boredom. :p
Avatar image for hagridore
hagridore

529

Forum Posts

481

Wiki Points

0

Followers

Reviews: 0

User Lists: 21

Edited By hagridore

Well if you can't trust hackers to be honest, I don't know where we are as a society...

Avatar image for meierthered
MeierTheRed

6084

Forum Posts

1701

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

Edited By MeierTheRed
@crusader8463 said:
" Why is it just the US legal system doing stuff about this? Last time I checked this affected the entire world. "
I'm guessing my fellow European countries are just plain lazy?
Avatar image for jasonefmonk
jasonefmonk

396

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 1

Edited By jasonefmonk
@sofacitysweetheart: Well, that's not a rash response.
Avatar image for nintendoeats
nintendoeats

6234

Forum Posts

828

Wiki Points

0

Followers

Reviews: 4

User Lists: 9

Edited By nintendoeats

I'm going to go out on a limb and say that pretty much the only thing that we can confirm about the hackers is that they ARE, beyond a shadow of a doubt, anonymous.

Avatar image for olivaw
Olivaw

1309

Forum Posts

6

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

Edited By Olivaw
@Nomin said:

" Sony better prop up some military AI into their ICE so even a Kuang grade virus can't infiltrate it.  "

Finally, someone makes a classy reference instead of just stupid Hackers jokes.

Also Anonymous does usually take responsibility for the stupid shit that they do, but maybe if they thought that they might actually get some significant authority's attention and actually catch some heat they might deny it. Or it could be the real perp figured to plant it since Anonymous publicly declared war a while back.

Who knows? Hackers who lie? That's just crazy.
Avatar image for crash_happy
Crash_Happy

816

Forum Posts

283

Wiki Points

0

Followers

Reviews: 1

User Lists: 3

Edited By Crash_Happy

Seems like a stupid move by anonymous, could spell there end in the long run.

Avatar image for nate
Nate

798

Forum Posts

1073

Wiki Points

0

Followers

Reviews: 3

User Lists: 6

Edited By Nate

So, Anonymous is to blame OR maybe someone is trying to make it look like it was them. They're an easy target for taking the fall on this one.

Avatar image for president_barackbar
President_Barackbar

3648

Forum Posts

853

Wiki Points

0

Followers

Reviews: 0

User Lists: 2

I knew this had the stink of Anon all over it.

Avatar image for demarcon
demarcon

297

Forum Posts

886

Wiki Points

0

Followers

Reviews: 0

User Lists: 6

Edited By demarcon

I personally believe that anonops had nothing to do with this. Granted, I could hack someone and say it was anonymous, because that is technically what I would be. Either way, it really isn't difficult for anyone to have planted that file into the system, or even Sony could have done it when they were asked "who do you think did it?"

Avatar image for onarum
onarum

3212

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

Edited By onarum

" The company became aware on April 19 at 4:15 p.m. "

Holy shit, a self aware Sony... that's scary.

Avatar image for keeng
Keeng

1023

Forum Posts

2513

Wiki Points

0

Followers

Reviews: 5

User Lists: 3

Edited By Keeng

Fuck what the internet is saying, Sony is handling this the way a company should. It's downright impressive. I hope it was Anonymous and I hope they're caught.

Avatar image for skillface
Skillface

585

Forum Posts

35

Wiki Points

0

Followers

Reviews: 1

User Lists: 2

Edited By Skillface

Still love seeing the blue names in the comments wildly defending Sony.

Avatar image for thunderbear
thunderbear

10

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

Edited By thunderbear

" It's too bad Sony didn't make this same information available to its 77 million consumers. "

But they did! They couldn't rush out with information that wasn't verified. It was very important that they were careful what they said. Nothing could have satisfied all you mongers. Stop blaming Sony and blame the hackers FFS.

Avatar image for punk1984
Punk1984

595

Forum Posts

133

Wiki Points

0

Followers

Reviews: 1

User Lists: 2

Edited By Punk1984
@Skillface: Yeah what do the colors mean?

@test0r said:
"People should be pissed off at Sony, since they are so far the only party that we know did something wrong."
Or you could be pissed at the hackers who broke in to a system and stole your information.
Avatar image for makoma
Makoma

107

Forum Posts

43

Wiki Points

0

Followers

Reviews: 0

User Lists: 2

Edited By Makoma
@thunderbear:  The responsibility of a company involved in a potentially hazardous situation is to advise their customers of the worst case scenario. Similar to Toyota denying everything until proven guilty, they fucked up and should have mentioned the possibility even if there was no evidence that credit information was stolen.

If things didn't go that far, they prove they care. If they did, then they showed they were in control of the situation and trying to stay a step ahead of the game. It's just the japanese mentality of saving face until proof is uncovered that you fucked up. Unfortunately, this doesn't really fly with most customers: see the pissed off internet for results.

To quote Jeff's formspring:

All of it is Somy's fault. 100%. If credit card information was part of the data, it's just about the worst thing that could happen to them. It's disgusting that even billing addresses and emails have gotten out in the open because of this security issue.

Either they didn't offer a secure service or they failed to compensate for the possibility that they would get reamed like this. Lose-lose for them.

   
Avatar image for blackheronblue
BlackHeronBlue

789

Forum Posts

1722

Wiki Points

0

Followers

Reviews: 8

User Lists: 3

Edited By BlackHeronBlue

hacking is so 1990s.

Avatar image for frankxiv
frankxiv

2600

Forum Posts

8534

Wiki Points

0

Followers

Reviews: 1

User Lists: 11

Edited By frankxiv

what difference would it have made if sony told it's "77 million" consumers "hey anon did it"?

in fact one could argue, they knew all the important parts the same time congress did, if not before.

Avatar image for onarum
onarum

3212

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

Edited By onarum
@Punk1984:

it means what are you a fanboy of, red is Nintendo, green is MS and blue is Sony.
Avatar image for nekuctr
NekuCTR

1712

Forum Posts

128

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

Edited By NekuCTR

Man, has it really already been 2 weeks of this?

Avatar image for xpgamer7
xpgamer7

2488

Forum Posts

148

Wiki Points

0

Followers

Reviews: 12

User Lists: 5

Edited By xpgamer7

I doubt it was anonymous. They're prettty obnoxious about what they do an would have yelled it out.

Avatar image for swaboo
Swaboo

460

Forum Posts

159

Wiki Points

0

Followers

Reviews: 1

User Lists: 2

Edited By Swaboo

What i want to know is how the hell are people posting comments on the us playstation blog if you can't sign in...

Avatar image for commando
Commando

1999

Forum Posts

249

Wiki Points

0

Followers

Reviews: 0

User Lists: 2

Edited By Commando

A bunch of attention whores at 4chan did it? I doubt that... They would have bragged about it all over the internet the second they did it.

Avatar image for chilipeppersman
chilipeppersman

1319

Forum Posts

4

Wiki Points

0

Followers

Reviews: 26

User Lists: 4

Edited By chilipeppersman

this has been one ridiculous ordeal, PS needs to fix their shit.

Avatar image for steelknight2000
steelknight2000

654

Forum Posts

96

Wiki Points

0

Followers

Reviews: 1

User Lists: 0

Edited By steelknight2000

I hope we get some indictments and arrests out of this case. It's gonna be funny watching these hackers realize they can't hide behind the internet.

Avatar image for clstirens
clstirens

854

Forum Posts

15

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

Edited By clstirens

Wait, we have colored names? Why have I never noticed this?

Avatar image for vidiot
vidiot

2891

Forum Posts

397

Wiki Points

0

Followers

Reviews: 4

User Lists: 1

Edited By vidiot
@krazy_kyle said:
" Anonymous are just a bunch of nerdy computer geeks who think they are doing justice, but instead they are wasting people's time and inconveniencing others. "
Avatar image for azteck
Azteck

7415

Forum Posts

5

Wiki Points

0

Followers

Reviews: 0

User Lists: 2

Edited By Azteck

Jesus, Sony. Do you believe everything you read? Why would they claim no responsibility for the attack, then leave a note inside their servers saying it was them? It's not like they run any risk of being found under the name "Anonymous" so why the hell would they say they didn't have a part of it?

Avatar image for tehmaxxorz
TEHMAXXORZ

1190

Forum Posts

4491

Wiki Points

0

Followers

Reviews: 1

User Lists: 2

Edited By TEHMAXXORZ

'We are legion', hahaha, at least they used a biblical reference for their stupid little joke.

Avatar image for btman
btman

1114

Forum Posts

2974

Wiki Points

0

Followers

Reviews: 0

User Lists: 5

Edited By btman
@clstirens said:
" Wait, we have colored names? Why have I never noticed this? "
haha too funny.  do you know why they're different colors??
Avatar image for yakov456
yakov456

2021

Forum Posts

133

Wiki Points

0

Followers

Reviews: 0

User Lists: 3

Edited By yakov456

Still support ya Sony. Seem to be handling everything as they should. As for the last sentence in that article, it shows your intention when you write the headlines for these articles. I don't want your opinion, give me the news.

Avatar image for burn1n9m4n
Burn1n9m4n

321

Forum Posts

7455

Wiki Points

0

Followers

Reviews: 9

User Lists: 6

Edited By Burn1n9m4n
@yakov456: Well with all due respect man that last sentence is news. It shows that Sony told all this to a Congressional subcommittee but didn't tell the publc. Whatever Patrick's personal feelings on the matter are they are irrelevant when you consider that Kaz told all this to Congress when they ordered it, but didn't send out a plainly worded blog post until after sending a letter to Congress.

There are no opinions there. Its all fact.
Avatar image for lotan
Lotan

255

Forum Posts

558

Wiki Points

0

Followers

Reviews: 5

User Lists: 2

Edited By Lotan

What does the FBI need to do to stop these "Anonymous" hacking assholes?  Here's hoping it doesn't take as long as it took to find Osama.

Avatar image for xsheps
Xsheps

123

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 1

Edited By Xsheps
       This is the only reasonable response to all this:
  

Avatar image for vegasacevii
VegasAceVII

33

Forum Posts

16

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

Edited By VegasAceVII

You all are so dramatic.  Don't worry about your information, that isn't what they were after.  This was all done to make Sony look bad.  Sony just found out it really was ANON who did it.  They have no interest in your CC numbers.

Avatar image for sammann31415
Sammann31415

80

Forum Posts

36

Wiki Points

0

Followers

Reviews: 1

User Lists: 2

Edited By Sammann31415

Sigh.  People, don't jump the gun just yet.  If I were some criminal fishing for personal data and credit card numbers for a company recently DDoS'd by Anonymous, I'd put a file in there leading Sony to believe it was Anonymous too - it would throw people off the scent.  But, you know, that plan would be stupid, because they wouldn't ever use that as evidence, and they won't use it to find the criminal. It would be unbecoming of someone who was educated enough in breaking into a giant company's databases.  


Meaning the file in question is completely neutral in assessing who or what organization did this thing.  
Avatar image for deusx
Deusx

1943

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 2

Edited By Deusx
@Sammann31415 said:
" Sigh.  People, don't jump the gun just yet.  If I were some criminal fishing for personal data and credit card numbers for a company recently DDoS'd by Anonymous, I'd put a file in there leading Sony to believe it was Anonymous too - it would throw people off the scent.  But, you know, that plan would be stupid, because they wouldn't ever use that as evidence, and they won't use it to find the criminal. It would be unbecoming of someone who was educated enough in breaking into a giant company's databases.  

Meaning the file in question is completely neutral in assessing who or what organization did this thing.  
"
Exactly this, why would anonymous do this without informing people about this? They are proud of being the "internet hate machine" because they do not fear to be public about this things. This just goes AGAINST, everything anonymous "stands" for. So yeah... I don't think it was them. Also, I browse 4chan from time to time to find more info about this things but there is NOTHING about PSN attacks in there...
Avatar image for vegasacevii
VegasAceVII

33

Forum Posts

16

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

Edited By VegasAceVII
@Undeadpool: They didn't do anything like that.  Many false reports have come out since all this began.  No credit card companies have detected any fraud from this situation.  This is called spreading paranoia.
Avatar image for z0phi3l
z0phi3l

2

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

Edited By z0phi3l

If anyone really believes Anonymous had anything to do with it, I bet they also believe the Moon landings were faked. Sony just picked on Anonymous because of the Goehot deal. I highly doubt that with all their combined experience that Anonymous would do something as noobish as leaving a file on the server

Avatar image for ajamafalous
ajamafalous

13992

Forum Posts

905

Wiki Points

0

Followers

Reviews: 0

User Lists: 9

Edited By ajamafalous

Because if someone broke into my home and left a note that said "Jeff Gerstmann was here," clearly it had to have been Jeff, right?

Avatar image for whitebrightknight
WhiteBrightKnight

170

Forum Posts

29

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

@MaFoLu said:
" Just because they found a file named Anonymous doesn't have to mean they were really behind it, right? I mean the hackers could have put that there to mislead them.

Or maybe they didn't, but it's possible...
"
@Kjellm87 said:
"   While I'm not a fan of this "Anonymous", I think that file seems a little too perfect. There could be someone else who puts the blame on them. "
This was my first reaction as well, although idk if anonymous always works as a group or if there could be a couple rogues.

But I think no matter who did it this is probably related to the GeoHot case.  I think Sony was a dick to him but completely shutting down PSN is going way to far for some flawed sense of justice.
Avatar image for simplexity
Simplexity

1430

Forum Posts

0

Wiki Points

0

Followers

Reviews: 2

User Lists: 0

Edited By Simplexity

If they still had Linux support none of this would have ever happened.


Teaches us to not mess with hackers I guess.
Avatar image for hairytoeknuckles
HairyToeKnuckles

118

Forum Posts

1

Wiki Points

0

Followers

Reviews: 0

User Lists: 3

Edited By HairyToeKnuckles
@ajamafalous said:

" Because if someone broke into my home and left a note that said "Jeff Gerstmann was here," clearly it had to have been Jeff, right? "

God damnit! Why did Jeff do such a thing?!    
Avatar image for deactivated-5a1a3d3c6820c
deactivated-5a1a3d3c6820c

3235

Forum Posts

37

Wiki Points

0

Followers

Reviews: 0

User Lists: 2

Wish people would stop calling Anonymous a "group". They are literally the opposite.

Avatar image for ajamafalous
ajamafalous

13992

Forum Posts

905

Wiki Points

0

Followers

Reviews: 0

User Lists: 9

Edited By ajamafalous
@HairyToeKnuckles said:
" @ajamafalous said:

" Because if someone broke into my home and left a note that said "Jeff Gerstmann was here," clearly it had to have been Jeff, right? "

God damnit! Why did Jeff do such a thing?!     "
Hey man, don't ask me. All I know is that he did it, and that he should be ashamed.
Avatar image for mikey87144
mikey87144

2114

Forum Posts

3

Wiki Points

0

Followers

Reviews: 0

User Lists: 2

Edited By mikey87144
@Prodstep:  They removed it because a Geohot used Linux to hack the system.