Something went wrong. Try again later
    Follow

    Sony Interactive Entertainment

    Company »

    Sony Interactive Entertainment is a subsidiary of the Sony Corporation responsible for Research & Development, production, and sales of hardware and software for the PlayStation line of handheld and video game consoles.

    Security Expert Testifies That Sony Knew Its Security Was Out of Date for 'Months'

    • 99 results
    • 1
    • 2
    • 3
    Avatar image for alex
    alex

    3983

    Forum Posts

    7447

    Wiki Points

    0

    Followers

    Reviews: 0

    User Lists: 1

    Edited By alex

    During yesterday's hearings held by the Congressional House Subcommittee on Commerce, Manufacturing, and Trade on the subject of data theft--and, largely, the current situation with Sony and the PlayStation Network--the committee heard testimony from Dr. Gene Spafford, the executive director at Purdue University's Center For Education and Research in Information Assurance and Security. During his testimony, Spafford dropped a potentially damning piece of info regarding the Sony breach.

     Dr. Gene Spafford.
     Dr. Gene Spafford.
    Specifically, Spafford claims that Sony employees were well aware that the company's security measures were out of date and vulnerable to attack. Spafford's claims come from an open Internet forum used by security experts, including several Sony employees. According to him, several people on those forums realized that Sony's systems were using "very old versions of Apache software that were unpatched and had no firewall installed." The issue was reported "two or three months" prior to the attack that brought down the PSN service. In that time frame, no acknowledgment of the report nor any visible updates to the systems came about from Sony.

    Spafford himself was not a part of these original forum discussions. Rather, he cited reports from others reportedly involved in these security forum discussions. While that can lead to a bit of speculation on exactly how accurate his time line is, a statement like that under oath is still likely to add a great deal of fuel to the federal government's investigation, not to mention the various civil suits that have begun to spring up like wildfire since the scope and severity of the Sony attack became public.
    Avatar image for alex
    alex

    3983

    Forum Posts

    7447

    Wiki Points

    0

    Followers

    Reviews: 0

    User Lists: 1

    #1  Edited By alex

    During yesterday's hearings held by the Congressional House Subcommittee on Commerce, Manufacturing, and Trade on the subject of data theft--and, largely, the current situation with Sony and the PlayStation Network--the committee heard testimony from Dr. Gene Spafford, the executive director at Purdue University's Center For Education and Research in Information Assurance and Security. During his testimony, Spafford dropped a potentially damning piece of info regarding the Sony breach.

     Dr. Gene Spafford.
     Dr. Gene Spafford.
    Specifically, Spafford claims that Sony employees were well aware that the company's security measures were out of date and vulnerable to attack. Spafford's claims come from an open Internet forum used by security experts, including several Sony employees. According to him, several people on those forums realized that Sony's systems were using "very old versions of Apache software that were unpatched and had no firewall installed." The issue was reported "two or three months" prior to the attack that brought down the PSN service. In that time frame, no acknowledgment of the report nor any visible updates to the systems came about from Sony.

    Spafford himself was not a part of these original forum discussions. Rather, he cited reports from others reportedly involved in these security forum discussions. While that can lead to a bit of speculation on exactly how accurate his time line is, a statement like that under oath is still likely to add a great deal of fuel to the federal government's investigation, not to mention the various civil suits that have begun to spring up like wildfire since the scope and severity of the Sony attack became public.
    Avatar image for drumpsycho89
    drumpsycho89

    513

    Forum Posts

    1

    Wiki Points

    0

    Followers

    Reviews: 0

    User Lists: 0

    #2  Edited By drumpsycho89

    ooooooooooooh

    Avatar image for strawhat_npc
    StrawHat_NPC

    583

    Forum Posts

    2367

    Wiki Points

    0

    Followers

    Reviews: 0

    User Lists: 6

    #3  Edited By StrawHat_NPC

    damn :)

    Avatar image for skald
    Skald

    4450

    Forum Posts

    621

    Wiki Points

    0

    Followers

    Reviews: 11

    User Lists: 7

    #4  Edited By Skald
    Avatar image for nadafinga
    Nadafinga

    1045

    Forum Posts

    36764

    Wiki Points

    0

    Followers

    Reviews: 2

    User Lists: 10

    #5  Edited By Nadafinga

    Wait, this guy testified that he read something on the internet?

    Huh?

    Avatar image for bretthancock
    bretthancock

    798

    Forum Posts

    751

    Wiki Points

    0

    Followers

    Reviews: 2

    User Lists: 5

    #6  Edited By bretthancock

    You can insert this phrase for nearly every company that deals with internet services or hosting.  If it's related to the internet, it's security is probably out of date.  It's all of matter of who is targeted and the resources available to combat it.  That being said, step it up next time Sony.

    Avatar image for beej
    beej

    1675

    Forum Posts

    417

    Wiki Points

    0

    Followers

    Reviews: 0

    User Lists: 1

    #7  Edited By beej

    Wow, this combined with not showing up when a congressional committee summons you? This is looking rough for Sony.

    Avatar image for ajamafalous
    ajamafalous

    13992

    Forum Posts

    905

    Wiki Points

    0

    Followers

    Reviews: 0

    User Lists: 9

    #8  Edited By ajamafalous

    That seems potentially dealbreaking for Sony.

    Avatar image for lockwoodx
    lockwoodx

    2531

    Forum Posts

    6

    Wiki Points

    0

    Followers

    Reviews: 0

    User Lists: 0

    #9  Edited By lockwoodx

    Sony made an open declaration for hackers to come at them so any compromise to the integrity of their system is 100% Sony's fault for not being "up to date" and prepared for said attack they instigated.

    Avatar image for ontheocho
    Ontheocho

    200

    Forum Posts

    0

    Wiki Points

    0

    Followers

    Reviews: 3

    User Lists: 2

    #10  Edited By Ontheocho

    That E3 Sony press conference is going to be so uncomfortable.  It's going to be like Pee Wee Herman's first stage appearance after his arrest.  It's going to be so cringe worthy, and I'm not going to miss a minute of it.

    Avatar image for buscemi
    Buscemi

    1125

    Forum Posts

    3757

    Wiki Points

    0

    Followers

    Reviews: 0

    User Lists: 2

    #11  Edited By Buscemi

    OH SNAP

    Avatar image for commisar123
    Commisar123

    1957

    Forum Posts

    1368

    Wiki Points

    0

    Followers

    Reviews: 4

    User Lists: 14

    #12  Edited By Commisar123

    oh snap

    Avatar image for burn1n9m4n
    Burn1n9m4n

    321

    Forum Posts

    7455

    Wiki Points

    0

    Followers

    Reviews: 9

    User Lists: 6

    #13  Edited By Burn1n9m4n

    If this is true then it opens the way for some criminal indictments of Sony's corporate ladder. It will also probably affect the way that corporations are treated in the future as all sorts of precedents are going to be set by this.

    Avatar image for dtat
    dtat

    1750

    Forum Posts

    546

    Wiki Points

    0

    Followers

    Reviews: 1

    User Lists: 9

    #14  Edited By dtat

    Surprise surprise surprise

    Avatar image for legend
    Legend

    2735

    Forum Posts

    17405

    Wiki Points

    0

    Followers

    Reviews: 3

    User Lists: 28

    #15  Edited By Legend

    Sony is fucked.

    Avatar image for afroman269
    Afroman269

    7440

    Forum Posts

    103

    Wiki Points

    0

    Followers

    Reviews: 0

    User Lists: 6

    #16  Edited By Afroman269

    Reminds me of all the other disasters that occur, people get lax with security and or protocol and eventually some shitstorm occurs. 

    Avatar image for kowalskimandown
    KowalskiManDown

    4170

    Forum Posts

    3525

    Wiki Points

    0

    Followers

    Reviews: 1

    User Lists: 19

    #17  Edited By KowalskiManDown

    Ehh, no doubt those fucking hackers will attack PSN again as soon as it's up again.

    Avatar image for nomin
    Nomin

    1004

    Forum Posts

    245

    Wiki Points

    0

    Followers

    Reviews: 11

    User Lists: 9

    #19  Edited By Nomin

    That Dr. Spafford, rarin' to regulate with his BOWTIE! 

    Avatar image for n7
    N7

    4159

    Forum Posts

    23

    Wiki Points

    0

    Followers

    Reviews: 4

    User Lists: 2

    #20  Edited By N7
    @SRanker said:
    " I would assume this is not true. Theres no proof. It's not an offical report from a company. "
    But... Look at how old he is! Life is too short to tell lies!
    Avatar image for bravetoaster
    BraveToaster

    12636

    Forum Posts

    250

    Wiki Points

    0

    Followers

    Reviews: 0

    User Lists: 1

    #21  Edited By BraveToaster
    @SRanker said:
    " I would assume this is not true. Theres no proof. It's not an offical report from a company. "
    Why would Dr. Spafford lie? Why did Sony refuse to comment after this was made public?
    Avatar image for wintersnowblind
    WinterSnowblind

    7599

    Forum Posts

    41

    Wiki Points

    0

    Followers

    Reviews: 0

    User Lists: 4

    #22  Edited By WinterSnowblind
    @SRanker said:
    " I would assume this is not true. Theres no proof. It's not an offical report from a company. "
    Sony aren't exactly going to come out and say "it happened because our security sucked".  That would be admitting to negligence and that's their biggest worry at the moment.
    Avatar image for kaosangel-DELETED
    KaosAngel

    14251

    Forum Posts

    6507

    Wiki Points

    0

    Followers

    Reviews: 8

    User Lists: 3

    #23  Edited By KaosAngel

    How many idiots are going to still say Sony did no wrong? 

    Avatar image for the_laughing_man
    The_Laughing_Man

    13807

    Forum Posts

    7460

    Wiki Points

    0

    Followers

    Reviews: 1

    User Lists: 0

    #24  Edited By The_Laughing_Man
    @alex said: 

    I beat ya to the punch! Yay me...lol 
    Avatar image for kaosangel-DELETED
    KaosAngel

    14251

    Forum Posts

    6507

    Wiki Points

    0

    Followers

    Reviews: 8

    User Lists: 3

    #25  Edited By KaosAngel
    @WinterSnowblind said:
    " @SRanker said:
    " I would assume this is not true. Theres no proof. It's not an offical report from a company. "
    Sony aren't exactly going to come out and say "it happened because our security sucked".  That would be admitting to negligence and that's their biggest worry at the moment. "
    That also allows all open lawsuits for Sony to get hit with.  Sony would be fucked beyond belief they they admitted negligence for the information they stored.
    Avatar image for vexxan
    Vexxan

    4642

    Forum Posts

    943

    Wiki Points

    0

    Followers

    Reviews: 0

    User Lists: 3

    #26  Edited By Vexxan

    Old software and no firewalls? Great, just great....

    Avatar image for toyboxx
    TOYBOXX

    327

    Forum Posts

    0

    Wiki Points

    0

    Followers

    Reviews: 7

    User Lists: 1

    #27  Edited By TOYBOXX

    There is no denying that Sony is boned here. And to protect them like a fanboy won't help anyone's case either so don't bother. I'm not sure if it was incompetence, or sheer arrogance, that prevented Sony from protecting itself and it's customers. I'd like to think that they didn't know what they were doing. But if that was the case then why are they in the online business in the first place? 


    As a gamer I don't care how much free content Sony is willing to throw my way. I simply won't buy into that shit. My credit card information may have been compromised - I don't know. Even if the users personal information hadn't been stolen people still scrambled to protect themselves by any means possible. Knowing that gamers came to PSN for entertainment only to be fucked in the end is unforgivable. This could mess up a lot of gamers lives - or the lack thereof. 

    Sony is going to need to do something to get me back on the Playstation with their next console. As of now with the PS3? I'm done. It's being packed up and sold along with the games.
    Avatar image for renegade
    Renegade

    377

    Forum Posts

    4

    Wiki Points

    0

    Followers

    Reviews: 0

    User Lists: 0

    #28  Edited By Renegade
    @Ontheocho said:
    " That E3 Sony press conference is going to be so uncomfortable.  It's going to be like Pee Wee Herman's first stage appearance after his arrest.  It's going to be so cringe worthy, and I'm not going to miss a minute of it. "
    Yup, the press conference may actually be interesting for once!
    Avatar image for mackj
    MackJ

    52

    Forum Posts

    463

    Wiki Points

    0

    Followers

    Reviews: 0

    User Lists: 2

    #29  Edited By MackJ

    The CSpan picture really threw me. For a second I thought I was reading Indecision Forever.

    Avatar image for mesklinite
    mesklinite

    902

    Forum Posts

    37

    Wiki Points

    0

    Followers

    Reviews: 0

    User Lists: 5

    #30  Edited By mesklinite

    Where there's smoke, there's fire!!!!
    Avatar image for saga
    Saga

    190

    Forum Posts

    2

    Wiki Points

    0

    Followers

    Reviews: 5

    User Lists: 1

    #31  Edited By Saga

    I have to say that I am very disappointed at Sony. They took 150+ hours to let customers know that their information was compromised. They throw $5.99 at customers so they can have access to PSNplus for a month. And now they are accused of using outdated security software (similarly to us using norton antivirus 2002 in our PCs)? I spend 50% of my gaming time playing Xbox and about 40% playing PS3. However, it looks like MS will be getting most of my money going forward. The only way that I can regain my confidence in Sony is if they start firing the executives that made the horrible decision to NOT invest in IT security and the ones that declared war on the hackers.


    Until then, I'll be on Xbox live 75% of the time
    Avatar image for matiaz_tapia
    matiaz_tapia

    718

    Forum Posts

    0

    Wiki Points

    0

    Followers

    Reviews: 0

    User Lists: 0

    #32  Edited By matiaz_tapia
    @N7 said:

    But... Look at how old he is! Life is too short to tell lies! "
    Made my day. Thank you.
    Avatar image for authenticm
    AuthenticM

    4404

    Forum Posts

    12323

    Wiki Points

    0

    Followers

    Reviews: 1

    User Lists: 2

    #33  Edited By AuthenticM

    BOOM

    Avatar image for phatseejay
    PhatSeeJay

    3331

    Forum Posts

    9727

    Wiki Points

    0

    Followers

    Reviews: 5

    User Lists: 17

    #34  Edited By PhatSeeJay

    Of course shit hit the fan because they didn't play the "better be safe than sorry"-card! That's always the reason to a disaster where human engineering is involved. They could have figured that out once the PS3 got hacked, yet they didn't pull the plug on their network because it just "might" happen. That's not a reason strong enough to take such a drastic measure, yet here we are.

    Avatar image for billychu
    Billychu

    33

    Forum Posts

    0

    Wiki Points

    0

    Followers

    Reviews: 0

    User Lists: 2

    #35  Edited By Billychu

    Today I learned my porn cache is hundreds of times more secure than Sony's servers. Frightening.

    Avatar image for goldanas
    Goldanas

    568

    Forum Posts

    8

    Wiki Points

    0

    Followers

    Reviews: 0

    User Lists: 0

    #36  Edited By Goldanas

    @Nadafinga said:

    " Wait, this guy testified that he read something on the internet?Huh? "

     It's worse than that. He's quoting something someone else read on the Internet.

    I'm pretty sure this is hearsay and inadmissible. True or not, this doesn't even qualify as evidence.

    The only things that have been swirling around about this whole mess is a bunch of rumors blasting Sony with no real proof. I know my name is blue, but can we please read the whole article or at least wait til' we have a conclusion before selling off our consoles?
    Avatar image for bolgirk
    Bolgirk

    24

    Forum Posts

    49

    Wiki Points

    0

    Followers

    Reviews: 0

    User Lists: 0

    #37  Edited By Bolgirk

    wired had an article similar with a guy who actually was hacking his ps3, and found out that their apache servers were out of date (he had the revision numbers) determined using packet sniffers on his network, and explained that they do not even attempt a firewall or VPN.

    Avatar image for n7
    N7

    4159

    Forum Posts

    23

    Wiki Points

    0

    Followers

    Reviews: 4

    User Lists: 2

    #38  Edited By N7
    @TOYBOXX said:
    " There is no denying that Sony is boned here. And to protect them like a fanboy won't help anyone's case either so don't bother. I'm not sure if it was incompetence, or sheer arrogance, that prevented Sony from protecting itself and it's customers. I'd like to think that they didn't know what they were doing. But if that was the case then why are they in the online business in the first place? 

    As a gamer I don't care how much free content Sony is willing to throw my way. I simply won't buy into that shit. My credit card information may have been compromised - I don't know. Even if the users personal information hadn't been stolen people still scrambled to protect themselves by any means possible. Knowing that gamers came to PSN for entertainment only to be fucked in the end is unforgivable. This could mess up a lot of gamers lives - or the lack thereof. 

    Sony is going to need to do something to get me back on the Playstation with their next console. As of now with the PS3? I'm done. It's being packed up and sold along with the games.
    "
    Sony is also offering free Identity Theft Protection for all users of the Playstation Network in the United States, and is working right now on trying to get a service that would work in other territories and countries as from what I can tell, this one only works with the United States.

    Link to the full thing: Derp
    Avatar image for fox01313
    fox01313

    5256

    Forum Posts

    2246

    Wiki Points

    0

    Followers

    Reviews: 1

    User Lists: 19

    #39  Edited By fox01313

    0 surprise, strange how a tech giant like Sony would be so inept with the internet in many ways. Doesn't look good for them.

    Avatar image for sevan
    Sevan

    98

    Forum Posts

    25

    Wiki Points

    0

    Followers

    Reviews: 0

    User Lists: 9

    #40  Edited By Sevan
    @SRanker said:

    " I would assume this is not true. Theres no proof. It's not an offical report from a company. "

    ...your not serious are you? Sony took a week to tell us something that could have potentially millions of people. Screw their official reports.
    this is a man with a doctorate speaking officlally at a  Congressional House Subcommittee on Commerce hearing. This aint a discussion forum where any Jack@$$ can say whatever. you have to have some serious cred behind you to be allowed to talk at one of those.
     The proof will be looked into, but it has probably already been tampered with as much as possible by Sony. But technology is not an opinion. If a bunch of tech heads on a forum said "hey, this is old $#ity software... its old $#ity software.
      I figured Sony was cutting corners somwhere simply for economic reasons. They have a more expensive system that they wernt making money from for years, and a free (although not as good) online system with dozens of outside programs having access to it. Where more secure systems like xbox live and apple, there are very few programs that are allowed anything more than a shallow access into their systems, PSN just kinda let anyone do whatever. none of PSN's "Apps" have any of the trademarks of a program stripped down and rebuilt for security and efficiency on the network. IF Psn survives this, we'll start seeing more structure. But pretty much PSN was thrown together like the little rascals second race car... except it didnt win the race.
    Avatar image for krakn3dfx
    Krakn3Dfx

    2746

    Forum Posts

    101

    Wiki Points

    0

    Followers

    Reviews: 4

    User Lists: 3

    #41  Edited By Krakn3Dfx

    I love how people throw around terms like "unforgivable" and phrases like "Sony is fucked".

    Most people at this point just want the system back so they can get back to gaming online. Most, if not all of this was on Sony, yes, but for any company that has to deal with this, and there have been a lot, it's usually "lesson learned" and we're all better off for them having gone through it. You can bet it was a huge wake up call for a lot of other online service providers as well.  Sony likely was targeted because they pissed off hackers, but to believe this couldn't happen to just about any company these days is naive at best. The effectiveness of any security is only as god as the asshole standing outside the door's desire to get in.

    If you're boxing up your PS3 to sell because this happened, please, fucking go.  Regardless of what's currently going on, there are a shit ton of awesome PS3 games coming out this year, and I personally will be playing the shit out of them (and I'll be playing Gears 3 and hopefully some new Zelda and whatever else great games come out on any system this year).

    Also, it's not being a fanboy to be realistic about a situation. It's just common sense.

    Avatar image for euandewar
    EuanDewar

    5159

    Forum Posts

    136

    Wiki Points

    0

    Followers

    Reviews: 4

    User Lists: 0

    #42  Edited By EuanDewar

    I can't wait for E3.

    Avatar image for spiritof
    Spiritof

    2471

    Forum Posts

    28754

    Wiki Points

    0

    Followers

    Reviews: 25

    User Lists: 27

    #43  Edited By Spiritof

    Old guys be oldin'.

    (I've never been prouder of my gray "neutral" status on a website before)

    Avatar image for hexogen
    hexogen

    802

    Forum Posts

    3477

    Wiki Points

    0

    Followers

    Reviews: 1

    User Lists: 7

    #44  Edited By hexogen

    I'm no lawyer-man, but does saying IT'S TRUE CUZ I SAWS IT ON THE INTERWEBS have any legal backing whatsoever?

    Avatar image for tadthuggish
    TadThuggish

    1073

    Forum Posts

    334

    Wiki Points

    0

    Followers

    Reviews: 2

    User Lists: 41

    #45  Edited By TadThuggish

    hahahahaha r.i.p. sony whocares-2011

    Avatar image for zor
    zor

    822

    Forum Posts

    10

    Wiki Points

    0

    Followers

    Reviews: 16

    User Lists: 18

    #46  Edited By zor
    @N7 said:

    Sony is also offering free Identity Theft Protection for all users of the Playstation Network in the United States, and is working right now on trying to get a service that would work in other territories and countries as from what I can tell, this one only works with the United States.


    True, but from my understanding of Debix (the company that Sony has hired) is that they aren't that good. I remember last year when my health care provider got hacked, they offered the same service. So I went online to read up on the company, and a lot of people were posting about how they were ineffective. To the point where they were doing things with their own credit, and Debix didn't notice it (like getting loans, which should have sent up a red flare, but didn't).

    So yeah, nice thought on Sony part, but it isn't going to help (assuming internet comments on the company are true).
    Avatar image for billychu
    Billychu

    33

    Forum Posts

    0

    Wiki Points

    0

    Followers

    Reviews: 0

    User Lists: 2

    #47  Edited By Billychu
    @Hexogen
    I'm no lawyer-man, but does saying IT'S TRUE CUZ I SAWS IT ON THE INTERWEBS have any legal backing whatsoever?
    It does when its a forum populated by security specialists INCLUDING SONY EMPLOYEES
    Avatar image for feser
    Feser

    546

    Forum Posts

    1638

    Wiki Points

    0

    Followers

    Reviews: 0

    User Lists: 1

    #48  Edited By Feser

    @Goldanas:
    You realize that forum discussion is not something that is exclusively on the internet, right? He's citing reports from discussions by those involved by in forum discussions initiated by Sony. There is a signifigant difference between that and some random forum on the internet (You really didn't think he was citing a internet forum, did you?).

    Avatar image for xeiphyer
    Xeiphyer

    5962

    Forum Posts

    1193

    Wiki Points

    0

    Followers

    Reviews: 0

    User Lists: 8

    #49  Edited By Xeiphyer

    Not surprising.

    Well, this is something we already knew, but the fact is that the people in charge of security answer to the people who have the money, and they don't always have a lot of say.

    Spending a bunch of money to upgrade something that they just upgraded a few months ago probably seems insane to the admin/accounting people at Sony who don't understand how security works.


    Also to anyone who is saying this is fake, firstly, why would this be fake? Its a doctor/professor talking to congress, that's pretty legitimate. Plus its been said many times by people who have examined Sony's security that they were using an older version of apache with known security flaws. Its been stated by many people in many places.

    Avatar image for mordeaniischaos
    MordeaniisChaos

    5904

    Forum Posts

    -1

    Wiki Points

    0

    Followers

    Reviews: 5

    User Lists: 5

    #50  Edited By MordeaniisChaos
    @Hexogen said:
    " I'm no lawyer-man, but does saying IT'S TRUE CUZ I SAWS IT ON THE INTERWEBS have any legal backing whatsoever? "
    Yeah..... I dunno, I was about to stop backing Sony until I saw "forum post"

    On top of that, a report of a reported forum by someone who never saw the forum? I don't trust that for a second, call me crazy.

    This edit will also create new pages on Giant Bomb for:

    Beware, you are proposing to add brand new pages to the wiki along with your edits. Make sure this is what you intended. This will likely increase the time it takes for your changes to go live.

    Comment and Save

    Until you earn 1000 points all your submissions need to be vetted by other Giant Bomb users. This process takes no more than a few hours and we'll send you an email once approved.