Something went wrong. Try again later

Giant Bomb News

155 Comments

Sony Publishes Q&A to Address More PSN Concerns, Still Unanswered Questions

Your data was encrypted, but credit card information remains an open question.

I realize there's been a massive amount of PlayStation Network coverage on Giant Bomb the past few days, but when potential credit card fraud and data intrusion on 77 million accounts is involved, that happens. Senior director of corporate communications and social media Patrick Seybold, also known as the public face of Sony throughout PSN's disaster, has updated the PlayStation Blog with a new Q&A.

The Q&A reveals a few new details about Sony's decision making process when the initial intrusion was discovered and how the company is handling rebuilding PSN and now ensuring account security.

I've grabbed the most interesting updates (though it's worth reading the whole thing) for you to read:

No Caption Provided
== TEASER ==

Q: Are you working with law enforcement on this matter?
A: Yes, we are currently working with law enforcement on this matter as well as a recognized technology security firm to conduct a complete investigation. This malicious attack against our system and against our customers is a criminal act and we are proceeding aggressively to find those responsible.

Q: Was my personal data encrypted?
A: All of the data was protected, and access was restricted both physically and through the perimeter and security of the network. The entire credit card table was encrypted and we have no evidence that credit card data was taken. The personal data table, which is a separate data set, was not encrypted, but was, of course, behind a very sophisticated security system that was breached in a malicious attack.

Q: Was my credit card data taken? 
A: While all credit card information stored in our systems is encrypted and there is no evidence at this time that credit card data was taken, we cannot rule out the possibility. If you have provided your credit card data through PlayStation Network or Qriocity, out of an abundance of caution we are advising you that your credit card number (excluding security code) and expiration date may have been obtained. Keep in mind, however that your credit card security code (sometimes called a CVC or CSC number) has not been obtained because we never requested it from anyone who has joined the PlayStation Network or Qriocity, and is therefore not stored anywhere in our system.

Q: What if I don’t know which credit card I’ve got attached to my PlayStation Network account?
A: If you’ve added funds to your PlayStation Network wallet in the past, you should have received a confirmation email from “DoNotReply@ac.playstation.net” at the email address associated with your account. This email would have been sent to you immediately after you added the funds, and will contain the first 4 digits and last 4 digits of your credit card number. You can also check your previous credit card statements to determine which card was attached to your PlayStation Network or Qriocity accounts.

Q: When or how can I change my PlayStation Network password?
A: We are working on a new system software update that will require all users to change their password once PlayStation Network is restored. We will provide more details about the new update shortly.

Q: What steps is Sony taking to protect my personal data in the future? 
A: We’ve taken several immediate steps to add protections for your personal data. First, we temporarily turned off PlayStation Network and Qriocity services and, second, we are enhancing security and strengthening our network infrastructure. Moving forward, we are initiating several measures that will significantly enhance all aspects of PlayStation Network’s security and your personal data, including moving our network infrastructure and data center to a new, more secure location, which is already underway. We will provide additional information on these measures shortly.

Q: Has Sony identified the party or parties responsible for the PlayStation Network hack and subsequent theft of personal information? 
A: We are currently conducting a thorough investigation of the situation and are working closely with a recognized technology security firm and law enforcement in order to find those responsible for this criminal act no matter where in the world they might be located.

Q: When will the PlayStation Network and Qriocity be back online?
A: Our employees have been working day and night to restore operations as quickly as possible, and we expect to have some services up and running within a week from yesterday. However, we want to be very clear that we will only restore operations when we are confident that the network is secure.

 I'll be continuing to monitor Sony's progress the rest of the week--and possibly beyond, it seems.    
Patrick Klepek on Google+

155 Comments

Avatar image for little_socrates
Little_Socrates

5847

Forum Posts

1570

Wiki Points

0

Followers

Reviews: 16

User Lists: 23

Edited By Little_Socrates

They're gonna need to be a bit more transparent about how much encryption we're talking about before I even CONSIDER giving them my information again.

Avatar image for gabriel
Gabriel

4139

Forum Posts

638

Wiki Points

0

Followers

Reviews: 0

User Lists: 7

Edited By Gabriel

People in these forums are some of the biggest fucktards imaginable.

Avatar image for winsord
winsord

1642

Forum Posts

86

Wiki Points

0

Followers

Reviews: 0

User Lists: 13

Edited By winsord
@Jefflarz said:

" Nice. E: Wow, actually got it. Anyways, I've been pretty disappointed with how Sony has handled this situation as a whole. The amount of time it has taken them to even attempt to try and answer the public's questions has been somewhat absurd. I understand it's been a difficult situation for them and all, but really Sony when something this big happens you really need to jump on the ball far faster. "

Quoted from Sarcastic Gamer user rothbart (OP: http://forums.sarcasticgamer.com/showpost.php?p=645846&postcount=734)

I work at a company that deals with data security... we wish everyone that lost a laptop or left data unencrypted had used our product(s) first. The fact is, NOBODY is impervious to being hacked. It happens all the time to tons of companies. It happens at a much larger scale than the 75M PSN users.

By data breach standards, what Sony has done here is the absolute text book implementation of what to do correctly. They didn't put protocol aside to keep selling PSN content. They didn't put protocol aside to let gamers keep gaming, potentially muddying up the systems being scoured for clues. They didn't try to hide that this happened. They didn't try to analyze it themselves but instead brought in experts.

The people and sites that are faulting Sony on how they've handled this so far are simply, and I mean no disrespect by the use of the very most accurate word I can think of... "ignorant" as to what they're talking about.

If you think Sony should've battened down the hatched and never gotten hacked... talk to the HUNDREDS of other companies/brands/organizations out there that have endured the exact same fate. If you think Sony shouldn't have been storing credit card information (at all or in a certain way) you should know that all there are now are recommendations or guidelines, there are no LAWS yet that force companies to certain degrees of protection and even if they were adequately protected, depending on the extent and nature of the hack, having them protected to PCI DSS guidelines STILL might not prevent people from getting to our credit card information...

That said, Sony said there was no evidence that our credit cards were compromised. They recommended (and to be honest, this was worded well) that "While there is no evidence at this time that credit card data was taken, we cannot rule out the possibility. If you have provided your credit card data through PlayStation Network or Qriocity, out of an abundance of caution we are advising you that your credit card number (excluding security code) and expiration date may have been obtained." How can they be faulted for that? Would you rather them lie and say "you're safe" or "they were compromised"?

This was a text book reaction to a large scale data breach and unlike MOST companies where we'd simply get an unexpected letter in the mail, we were somewhat kept in the look by the raised awareness that PSN being down leading them to say something. You don't spill details during an investigation and these things take time. Hell, try checking out your computer after you've had a trojan installed and activated... now amplify that work by about a bajillion. Going through that stuff takes time.    

Avatar image for boylie
boylie

321

Forum Posts

287

Wiki Points

0

Followers

Reviews: 0

User Lists: 7

Edited By boylie
@Hailinel: 

We then brought in outside experts to help us learn how the intrusion occurred and to conduct an investigation to determine the nature and scope of the incident.It was necessary to conduct several days of forensic analysis, and it took our expertsuntil yesterday to understand the scope of the breach

Their statement is that they knew someone broke in on the 19th, and closed down the PSN while they investigated. It was during this time they said it'd be back up and running within 2-3 days. They stated didn't know about the loss of personal data until monday(?) night, they then told everyone the next morning. Since then, they've stated that the time till the PSN comes back online has gone to a week, while they continue to research and investigate the matter.

All we have to go on is what they've told us, and this is what they've told us. Everything beyond that is speculation and fear mongering. 

I had my CC info stored on my account dude, don't think I'm not worried. I am not, however, going to start wearing a tinfoil had and claiming some elaborate conspiracy to keep this information from us. I am going to take the time to read what they have to say on the matter, and do what I have to do to protect myself. I am going to take what they have to say right now as truth, since they are the only source that knows what is going on right now. I am going to trust that they are WELL AWARE that fucking with us right now and withholding information from us could result in lawsuits that may very well bring that company to it's knees. That's about all any of us can do right now. 

It's really silly to see everyone else losing their shit on things that no one really has any information on, or worse, have been given information on, and have chosen to gloss over.
Avatar image for m1k3
m1k3

1511

Forum Posts

177

Wiki Points

0

Followers

Reviews: 2

User Lists: 1

Edited By m1k3

Who knows how long the hacker(s) have been working on breaching PSN.

I understand why Sony is being vague on this issue right now. Why would they go into specifics and give the hacker(s) a hint at what they are doing security wise and help them hack it again? Just keep an eye on your credit card statements and activity.

Avatar image for shinluis
shinluis

518

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 4

Edited By shinluis
@RoyCampbell: @RoyCampbell said:
" @MooseyMcMan said:
" @Rockdalf said:
" @MooseyMcMan said:
" So, top men are on it? Hopefully?  "

No Caption Provided
"
I want Sony to make an ad with Kevin Butler storming into basements and beating up hackers.  "
fuuuuck, I need this "
This made my week.
Avatar image for hailinel
Hailinel

25785

Forum Posts

219681

Wiki Points

0

Followers

Reviews: 10

User Lists: 28

Edited By Hailinel
@boylie said:
" @Hailinel: 

We then brought in outside experts to help us learn how the intrusion occurred and to conduct an investigation to determine the nature and scope of the incident.It was necessary to conduct several days of forensic analysis, and it took our expertsuntil yesterday to understand the scope of the breach

Their statement is that they knew someone broke in on the 19th, and closed down the PSN while they investigated. It was during this time they said it'd be back up and running within 2-3 days. They stated didn't know about the loss of personal data until monday(?) night, they then told everyone the next morning. Since then, they've stated that the time till the PSN comes back online has gone to a week, while they continue to research and investigate the matter.

All we have to go on is what they've told us, and this is what they've told us. Everything beyond that is speculation and fear mongering. 

I had my CC info stored on my account dude, don't think I'm not worried. I am not, however, going to start wearing a tinfoil had and claiming some elaborate conspiracy to keep this information from us. I am going to take the time to read what they have to say on the matter, and do what I have to do to protect myself. I am going to take what they have to say right now as truth, since they are the only source that knows what is going on right now. I am going to trust that they are WELL AWARE that fucking with us right now and withholding information from us could result in lawsuits that may very well bring that company to it's knees. That's about all any of us can do right now. 

It's really silly to see everyone else losing their shit on things that no one really has any information on, or worse, have been given information on, and have chosen to gloss over.
"
It is not a tinfoil hat conspiracy to wonder what the fuck Sony was doing for the past week in not informing their customers on what was going on.
Avatar image for boylie
boylie

321

Forum Posts

287

Wiki Points

0

Followers

Reviews: 0

User Lists: 7

Edited By boylie
@Hailinel: 
And I will reiterate, for the last time, that they didn't say what was going on, because until Monday, they didn't know what was going on. If you're not getting this, there's not much more I can say to help you here.
Avatar image for floppypants
Floppypants

814

Forum Posts

67

Wiki Points

0

Followers

Reviews: 0

User Lists: 14

Edited By Floppypants

I wish I had bought Mortal Kombat for 360

Avatar image for hailinel
Hailinel

25785

Forum Posts

219681

Wiki Points

0

Followers

Reviews: 10

User Lists: 28

Edited By Hailinel
@boylie said:

" @Hailinel: 
And I will reiterate, for the last time, that they didn't say what was going on, because until Monday, they didn't know what was going on. If you're not getting this, there's not much more I can say to help you here.
"

Even if they didn't know, they could have done more to inform users that there was a suspected breach in security and that time was necessary to determine its extent, thus giving everyone a very solid explanation of why they couldn't play their games online and also provide advance warning that bad news might be coming.
Avatar image for thehumandove
TheHumanDove

2520

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

Edited By TheHumanDove

Weeeeelp. Good thing my credit card is already maxed out!

Avatar image for xero0
Xero0

61

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

Edited By Xero0

sony has been into so much crap this gen, i feel kinda bad for the company.
on the other hand, a lot of it was their fault. i doubt any of this would have happened if
they just kept all the ps3 features and listened to failoverflow that their so-called
"sophisticated security system" is full of holes.

Avatar image for kerse
kerse

2496

Forum Posts

42

Wiki Points

0

Followers

Reviews: 0

User Lists: 8

Edited By kerse

Personal information was just in plain text... great. Incoming virus emails.

Avatar image for angelfan91
angelfan91

915

Forum Posts

46

Wiki Points

0

Followers

Reviews: 0

User Lists: 7

Edited By angelfan91

Uggh, just realized I made a PSN account to manually update my PSP in 2006. Fuck. (no credit card information shared with them though.)  
Avatar image for boylie
boylie

321

Forum Posts

287

Wiki Points

0

Followers

Reviews: 0

User Lists: 7

Edited By boylie
@Hailinel: 
Sure, they totally could have, though "providing advanced warning that bad news might be coming" implies that they suspected that our information was compromised from day one, which they have stated was not the case. That really doesn't have anything to do with your initial complaint though...

Why did it take them a week to tell users that their personal data might have been compromised and leave everyone in the dark in the meantime? 

I would have liked a press release to the tune of "hacking happened, PSN down, standby" the day, or maybe day after they took the network offline, but that didn't happen. It seemed kinda stupid of them not to at least give everyone a one or two paragraph press release stating it was down due to an intrusion on their system, but you know what? I'll live. And to again go back to your original complaint, who in their right minds would email 75 million users and say "all your information might have been stolen, just a heads up", 6 days before their teams had even discovered that was the case?  The PSN encompases more then just our personal data, you know. There are games, save files, profiles, trophy lists, movies, ads, etc, etc, etc. that are all part of this network. Is it really so hard to fathom that a system so large would take time to comb through to find out the information they presented us with on Tuesday? They're still not even sure if the CC information was taken, but here they are telling us, as a precaution, because they now know our information was accessed. 

Now that they KNOW our information was compromised, they are taking steps to inform us of it and provide us with the tools we need to keep ourselves safe. Asking anymore then that from them right now is silly, and continuing to imply that they had any idea about a loss of personal information a full week before they told us is baseless, and what I was referring to when I mentioned "wearing the tinfoil hat".
Avatar image for rattle618
Rattle618

1504

Forum Posts

58

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

Edited By Rattle618

So anon pulls a publicity stunt while some unknown dude/group takes the network down for weeks, I can't help but smile when I read about this. Sorry for all of you money-spending dudes though.

Avatar image for xanth93
Xanth93

510

Forum Posts

3

Wiki Points

0

Followers

Reviews: 8

User Lists: 5

Edited By Xanth93

Sony has been doing well with video game systems for about 17 years now. How this happened is beyond me.

Avatar image for dangeruss04
dangeRUSS04

107

Forum Posts

2

Wiki Points

0

Followers

Reviews: 0

User Lists: 3

Edited By dangeRUSS04
@Floppypants: 

i wish i bought both portal and mk on the 360
Avatar image for thepantheon
thepantheon

842

Forum Posts

99

Wiki Points

0

Followers

Reviews: 0

User Lists: 4

Edited By thepantheon

This isn't going to change my sticking to Sony. I'm a PC gamer first, but I still like Sony's system for consoles. Meh!

Avatar image for wrathofconn
wrathofconn

1511

Forum Posts

10983

Wiki Points

0

Followers

Reviews: 0

User Lists: 12

Edited By wrathofconn
@MooseyMcMan said:
" @Rockdalf said:
" @MooseyMcMan said:
" So, top men are on it? Hopefully?  "

No Caption Provided
"
I want Sony to make an ad with Kevin Butler storming into basements and beating up hackers.  "
It would actually be a good cop / bad cop act with Butler cracking jokes while Jack Tretton punches hackers in the face.
Avatar image for mooseymcman
MooseyMcMan

12791

Forum Posts

5577

Wiki Points

0

Followers

Reviews: 0

User Lists: 13

Edited By MooseyMcMan
@wrathofconn said:
" @MooseyMcMan said:
" @Rockdalf said:
" @MooseyMcMan said:
" So, top men are on it? Hopefully?  "

No Caption Provided
"
I want Sony to make an ad with Kevin Butler storming into basements and beating up hackers.  "
It would actually be a good cop / bad cop act with Butler cracking jokes while Jack Tretton punches hackers in the face. "
Only if Kaz Hirai is watching from the shadows smiling menacingly. 
Avatar image for arjuna
Arjuna

918

Forum Posts

448

Wiki Points

0

Followers

Reviews: 0

User Lists: 3

Edited By Arjuna

I wanna play MK online. I'm almost done totally unlocking the krypt and still haven't even played online yet.

Avatar image for sushisteve
sushisteve

195

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

Edited By sushisteve
@saroorhai:  Not a bad idea, all considering. The awful insurance company that I worked for last year had a similar breach that resulted in the company offering ID theft protection services to people who may have been compromised for a year.

It's a small price for Sony to pay to ease people's concerns, even if it turns out to be a much smaller problem.
Avatar image for adamfedoruk
adamfedoruk

274

Forum Posts

97

Wiki Points

0

Followers

Reviews: 0

User Lists: 5

Edited By adamfedoruk

I don't care about my credit card info at all. If shit happens, I will report it and get a new card and all my money back. I JUST WANT TO PLAY MORTAL KOMBAT... this whole thing makes me really sad...

Avatar image for jefflarz
Jefflarz

30

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

Edited By Jefflarz
@Winsord said:
"Mad Quotes"
Cool. So security breeches happen all the time. Your point?

No matter how often it happens customers have every right to be pissed when a company they've trusted personal information too loses it. Whether it is a direct result of a company fuck up or something that just happened because it happened is irrelevant. In the end Sony is at the middle of one hell of a mess and they have done a pretty poor job of answering their customers questions.

You also need to keep in mind that Sony isn't a bank or something similar where the customers really don't know about the data breech until something goes wrong or the company notifies them. The fact that the PSN is down has been staring us in the face for days and we certainly knew it was due to an intrusion for a while now. Give the public those two pieces of info and they'll connect the dots. The fact that Sony is only now addressing these concerns just doesn't sit well with me. Going to use the "they didn't even know for themselves until now" argument? I don't care. If my personal information, including credit card info, is at risk I want to know immediately. That's a reasonable expectation for any customer to have when they trust a company with their information.
Avatar image for thedavemagic
TheDaveMagic

73

Forum Posts

151

Wiki Points

0

Followers

Reviews: 1

User Lists: 3

Edited By TheDaveMagic
@skilled_gamer:  Same here man. I have both systems but mainly I'm also a 360 guy as well. Sony had my card as well but I only use my PS3 a few times a month.
Avatar image for kamikazecaterpillar
KamikazeCaterpillar

1160

Forum Posts

1705

Wiki Points

0

Followers

Reviews: 0

User Lists: 11

I don't care what anyone has to say I went up to the bank today to cancel my card. Better safe than sorry especially when you're as tight on money as I am.

Avatar image for wrathofconn
wrathofconn

1511

Forum Posts

10983

Wiki Points

0

Followers

Reviews: 0

User Lists: 12

Edited By wrathofconn
@MooseyMcMan: I believe we have reached an accord.
Avatar image for radixnegative2
RadixNegative2

547

Forum Posts

60

Wiki Points

0

Followers

Reviews: 0

User Lists: 3

Edited By RadixNegative2

...I can't believe personal info wasn't encrypted.

Avatar image for dandy
Dandy

67

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 3

Edited By Dandy

I just got my ps3 too ;(

Avatar image for xeridae
Xeridae

48

Forum Posts

1

Wiki Points

0

Followers

Reviews: 0

User Lists: 1

Edited By Xeridae

This is a terrible thing for Sony and it's customers. It's the sort of thing they may never be able to recover from. I consider the PS3 to be a superior product but  now that their infrastructure has been compromised I am really unsure if I will ever buy from them again. I don't hold any grudges but I also don't want to take any chances.

Avatar image for andorski
Andorski

5482

Forum Posts

2310

Wiki Points

0

Followers

Reviews: 0

User Lists: 3

Edited By Andorski
@Dandy said:
" I just got my ps3 too ;( "
While I hate the shit that I have to go through due to some company's incompetence, I still have to say that getting the PS3 around now is probably the best thing you can do.  Sony, fearing the possibility of having this happen to them again, will probably beef up their security.  I view it like a shuttle launch: When is it the best time to go into space?  Right after a huge catastrophe, because everyone will be on guard to ensure that it won't happen again.
Avatar image for xeridae
Xeridae

48

Forum Posts

1

Wiki Points

0

Followers

Reviews: 0

User Lists: 1

Edited By Xeridae
@Andorski said:
" @Dandy said:
" I just got my ps3 too ;( "
While I hate the shit that I have to go through due to some company's incompetence, I still have to say that getting the PS3 around now is probably the best thing you can do.  Sony, fearing the possibility of having this happen to them again, will probably beef up their security.  I view it like a shuttle launch: When is it the best time to go into space?  Right after a huge catastrophe, because everyone will be on guard to ensure that it won't happen again. "
Normally I would agree with you but NASA just blew up their past two attempts at launching a new satellite...
Avatar image for andorski
Andorski

5482

Forum Posts

2310

Wiki Points

0

Followers

Reviews: 0

User Lists: 3

Edited By Andorski
@Xeridae said:

" @Andorski said:

" @Dandy said:
" I just got my ps3 too ;( "
While I hate the shit that I have to go through due to some company's incompetence, I still have to say that getting the PS3 around now is probably the best thing you can do.  Sony, fearing the possibility of having this happen to them again, will probably beef up their security.  I view it like a shuttle launch: When is it the best time to go into space?  Right after a huge catastrophe, because everyone will be on guard to ensure that it won't happen again. "
Normally I would agree with you but NASA just blew up their past two attempts at launching a new satellite... "
From my point of view, this only means that their third attempt has tremendous odds of being successful.
Now excuse me while I keep doubling my bet after a ten hand losing streak of black jack.
Avatar image for branthog
Branthog

5777

Forum Posts

1014

Wiki Points

0

Followers

Reviews: 2

User Lists: 0

Edited By Branthog

There seems to be some small confusion over encrypted data. Note that TRANSMITTING data over the air encrypted (SSL) and STORING data in a database in an encrypted form are two different things.

Using SSL to transmit the data from your PS3 to Sony's servers just means someone can't snoop on your traffic and easily access your credentials. If it were not also STORED in an encrypted (and salted -- this is important!) manner, then anyone able to access the database itself would have all of the information they needed, whether it was transferred via SSL or not.

In this case, they confirmed that the credit card information - as stored in the database table - was encrypted.

Avatar image for chris2klee
Chris2KLee

2402

Forum Posts

1090

Wiki Points

0

Followers

Reviews: 6

User Lists: 13

Edited By Chris2KLee

I hope they're telling the truth about that credit card encryption. It's a shame this happened, but I hope it acts as a wake up call for Sony to get their crap together on the software/internet side of things. They make pretty neat kit, but the software they run is kinda junky at times.

Avatar image for akeldama
Akeldama

4373

Forum Posts

28

Wiki Points

0

Followers

Reviews: 0

User Lists: 4

Edited By Akeldama
@Cyrisaurus said:
" I really wish people would shut up and calm down about this. Once this is resolved in a few days everything will be back to normal and no harm will be done.Bunch of trigger happy, paranoid idiots. "
nail on the fucking head. People love making waves and sensationalizing everything. Fucking morons.
Avatar image for coakroach
coakroach

2499

Forum Posts

27

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

Edited By coakroach

*gasp*


Not   Qriocity!
Avatar image for faint
Faint

837

Forum Posts

46

Wiki Points

0

Followers

Reviews: 1

User Lists: 7

Edited By Faint

In the email I received to the address I use on my console:

"Although we are still investigating the details of this incident, we believe that an unauthorized person has obtained the following information that you provided: name, address (city, state/province, zip or postal code), country, email address, birthdate, PlayStation Network/Qriocity password and login, and handle/PSN online ID."

So in other words, they do have our passwords. Wouldn't have been better just to tell us that straight off the bat?

Avatar image for hailinel
Hailinel

25785

Forum Posts

219681

Wiki Points

0

Followers

Reviews: 10

User Lists: 28

Edited By Hailinel
@boylie:  Word of advice: Don't accuse others of wearing tinfoil hats when you're the one defending the actions of a company that has all but admitted to fucking up.
Avatar image for kalmis
kalmis

1745

Forum Posts

6127

Wiki Points

0

Followers

Reviews: 115

User Lists: 6

Edited By kalmis

There was some Norwegian dude who allegedly had his credit card stolen an used for multiple PSN purchases. Not sure how that would happen if that data was encrypted.

Avatar image for vividnova
vividnova

27

Forum Posts

68

Wiki Points

0

Followers

Reviews: 0

User Lists: 1

Edited By vividnova
@kalmis: You're not sure how someone on the internet would have their credit card details compromised and used to buy stuff on the internets? That's never happened before!
Avatar image for 1p
1p

798

Forum Posts

42

Wiki Points

0

Followers

Reviews: 0

User Lists: 3

Edited By 1p

The bast part about this has been watching German news hosts struggle to pronounce Qriocity.

Avatar image for boylie
boylie

321

Forum Posts

287

Wiki Points

0

Followers

Reviews: 0

User Lists: 7

Edited By boylie
@Hailinel: 
Word of advice: Listen to what people are telling you instead of making up "us vs. them" scenarios. I am advising level headedness, noting more. You would have to be a SUPREME asshat to think, after I've already told you my own personal CC details along with everything else on their servers have been compromised, that I'm acting as Sony's personal PR troll. I have re-stated what has been told to us, which at this point, is all we have to go on. 

You, on the other hand, are accusing them of having had knowledge of compromised account information a full week before they decided to say anything, based on nothing but what they have told us (despite this being the EXACT OPPOSITE of what they told us), and your apparent pre-disposition to getting really deep into conspiracy theories. 

I don't know how to be any more clear with you without resorting to drawing stick figures here. We're right in the middle of an ongoing investigation, and details are sparse. All we know is what they've told us. What they've told us is they had no idea that our personal information had been obtained until Monday night, and informed us on Tuesday. I'm more then allowed to be pissed my information was stolen without being so blind as to ignore what little facts that we have to go on. The more you argue this VERY SIMPLE concept, the more inept you look.

Now, if any of that sunk in, great. If not, I submit that we agree to disagree, as I have no particular desire to find new and interesting ways to tell you that making baseless accusations during a period of ongoing investigation during which facts are still trickling in makes only serves to make you look uninformed and ignorant.
Avatar image for vodun
Vodun

2403

Forum Posts

220

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

Edited By Vodun
@Hailinel said:
" @boylie:  Word of advice: Don't accuse others of wearing tinfoil hats when you're the one defending the actions of a company that has all but admitted to fucking up. "
Wait, so companies shouldn't admit to fucking up? Cover ups are better?
Avatar image for hailinel
Hailinel

25785

Forum Posts

219681

Wiki Points

0

Followers

Reviews: 10

User Lists: 28

Edited By Hailinel
@Vodun said:
" @Hailinel said:
" @boylie:  Word of advice: Don't accuse others of wearing tinfoil hats when you're the one defending the actions of a company that has all but admitted to fucking up. "
Wait, so companies shouldn't admit to fucking up? Cover ups are better? "
What?  No.  Don't go out of your way to defend companies that fucked up like Sony did.  I don't know how you interpreted what I said the way you apparently did.
Avatar image for hollitz
hollitz

2398

Forum Posts

5

Wiki Points

0

Followers

Reviews: 1

User Lists: 12

Edited By hollitz

Any chance that this has anything to do with Will Smith's potato battery?  Think about the timeline.  That's all I'm sayin.

Avatar image for eloj
eloj

753

Forum Posts

761

Wiki Points

0

Followers

Reviews: 0

User Lists: 7

Edited By eloj

"We are working on a new system software update that will require all users to change their password once PlayStation Network is restored."

Will this update include OtherOS, or are they now shooting themselves in the foot in their argument that nothing stops you from staying on the old firmware version, and therefore no one has a legal standing to complain about its removal? Now you have to chose between your password (and by extension, everything protected by it) and your OtherOS?

I had assumed you can change your password through the PSN website, but this FAQ entry sort of imply that you can't?

Avatar image for hailinel
Hailinel

25785

Forum Posts

219681

Wiki Points

0

Followers

Reviews: 10

User Lists: 28

Edited By Hailinel
@eloj said:
" "We are working on a new system software update that will require all users to change their password once PlayStation Network is restored."Will this update include OtherOS, or are they now shooting themselves in the foot in their argument that nothing stops you from staying on the old firmware version, and therefore no one has a legal standing to complain about its removal? Now you have to chose between your password (and by extension, everything protected by it) and your OtherOS?I had assumed you can change your password through the PSN website, but this FAQ entry sort of imply that you can't? "
This isn't extortion.  This is an update keyed to the new security measures of PSN.  If you've been keeping your firmware up to date through legitimate means at all, then you already lost OtherOS functionality a long time ago.
Avatar image for kalmis
kalmis

1745

Forum Posts

6127

Wiki Points

0

Followers

Reviews: 115

User Lists: 6

Edited By kalmis
@vividnova: Well of course. I am just saying that  if the credit card data on Sony's servers is encrypted how could it be used like this Norwegian guy claims.