• Hey, guest user. Hope you're enjoying NeoGAF! Have you considered registering for an account? Come join us and add your take to the daily discourse.

PSN thread: PSN up in all areas except HK/Korea (Store is not up yet)

Status
Not open for further replies.

Darkangus

Member
Luckyman said:
http://www.reuters.com/article/2011/05/13/us-sony-idUSTRE74C70420110513

UH OH

(Reuters) - Sony Corp's computer networks remain vulnerable to attack three weeks after the company learned that it had been victim of one of the biggest data breaches in history, according to an Internet security expert.

The expert found a handful of security flaws in Sony's networks while remotely studying its systems via the Internet to see how difficult it would be to penetrate the electronics giant's systems in the wake of the attacks.

Security researcher John Bumgarner discovered a potential bonanza for hackers by using little more than a web browser, Google's search engine and a basic understanding of Internet security systems.

"Sony still has several external security issues that need to be addressed," said Bumgarner, chief technology officer for the U.S. Cyber Consequences Unit, a research group funded by government and private sector grants that monitors Internet threats.

How the f*** did he test a service that isn't online?
 

jonabbey

Member
I wonder if it's Sony corporate policy not to pay systems and network personnel a competitive wage? That might explain why they seem to have a network designed by monkeys.

banana site:.sony.com
 

navanman

Crown Prince of Custom Firmware
Darkangus said:
How the f*** did he test a service that isn't online?

He didn't. He says there are security flaws on other Sony affiliated sites like Sony Music, movie, Sony Store, etc..
 

alr1ght

bish gets all the credit :)
Luckyman said:

0118_kpid.gif
 

TheSeks

Blinded by the luminous glory that is David Bowie's physical manifestation.
Brannon said:
http://3.bp.blogspot.com/_y07JL2xxcTI/TJxAUj3LDUI/AAAAAAAABxo/DyL92dDAB9w/s400/PBF044ADMovingBirthday.jpg

:lol x 5 at that PBF. I haven't seen that before.

Also who cares about the rest of the Sony sites. Just let me get PSN up for a day so I can trophy whore Portal 2. Trophy whore Portal 2. Trophy whore Portal 2.

Goddamn it. :|
 
chubigans said:
None of those flaws relate to the Playstation Network- just random Sony sites and other companies that aren't SCEA/E/I/N.
To be honest, I'm still amazed how fast the whole world of big business became totally internet-enabled. Fuck-ups like this are going to happen more and more as more hackers are emboldened. It'll take at least a decade until proper security is universally implemented.
 
Luckyman said:
Security researcher John Bumgarner discovered a potential bonanza for hackers by using little more than a web browser, Google's search engine and a basic understanding of Internet security systems./QUOTE]


That cuts most deep.
 

Darkangus

Member
SolidSnakex said:
He's not talking about PSN. He's talking about Sony websites in general.

I know... =)

The question was for the people that are going all nuts saying that now we are getting a new delay in the PSN... =P

But thanks for the quick replay... =)
 

DiZ_O

Banned
TheSeks said:
:lol x 5 at that PBF. I haven't seen that before.

Also who cares about the rest of the Sony sites. Just let me get PSN up for a day so I can trophy whore Portal 2. Trophy whore Portal 2. Trophy whore Portal 2.

Goddamn it. :|

Dude, relax. It's just trophies...You'll live.
 

test_account

XP-39C²
I just read through the whole Reuters article and it seems that it is not referring to PSN indeed, but other Sony related websites.

I also found this quote interesting:


"Security experts have said they believe the hackers initially gained access to Sony's network through a "spear-phishing" attack that targeted a systems administrator who had broad privileges to access data on Sony's networks.

In "spear-phishing" campaigns, hackers craft e-mails with personalized messages so that the recipients let their guard down and click on links or download attachments that launch malicious software programs that take over their computers.

Once one PC is corrupted, hackers can use that machine as a base from which to launch sophisticated operations, such as the attacks on Sony's networks.
"


If this is true, then it really didnt have much to do with the security itself on the PSN servers, but rather that one (or several) employee got fooled thinking that a phishing mail was a real mail. I also wonder what type of malicious software they think about, and wouldnt some anti-virus etc. software detect this?

But regardless, this claim does kinda collide with the statement that one of Sony's representatives said during the May 1st press conference, where it was mentioned that the hackers used a "known to the world" vulnerability. I assume that he wasnt referring to a phishing attack at least.

I also wonder if Sony runs all their webistes internally or if there are 3rd parties that are in charge of some of the sites. But anyway, they need to improve their security for sure.
 

Luckyman

Banned
HaRyu said:
And many will unfortunately think he was talking about PSN anyway. *sigh*

If you can get emails of people that potentially have admin rights to PSN via Google there is a problem. They will get attacked by unique malicious email that cannot be detected by software protection
 

ElRenoRaven

Member
Luckyman said:
If you can get emails of people that potentially have admin rights to PSN via Google there is a problem. They will get attacked by unique malicious email that cannot be detected by software protection

It's not PSN really. This article just shows how Sony in general lacks any security sense at all among all their networks. It shows a fundamental flaw within the entire company.
 

test_account

XP-39C²
PsychoRaven said:
It's not PSN really. This article just shows how Sony in general lacks any security sense at all among all their networks. It shows a fundamental flaw within the entire company.
"Lacks any security sense at all" is a bit exaggerated in my opinion, but i do agree that Sony needs to have more focus on the security. Hopefully Sony has learned a valuable lesson from all of this and will have a big "clean up" on their servers as soon as possible, not just the PSN servers, but every single server that they have.
 

TheSeks

Blinded by the luminous glory that is David Bowie's physical manifestation.
DiZ_O said:
Dude, relax. It's just trophies...You'll live.

I can't play the game until the service is back up because of it. It's been two weeks. I'm antsy.
 

pvpness

Member
meppi said:
Jesus Christ at this pace I see myself playing Battlefield 3 SP over and over again, wondering how awesome it would be to play the game the way it's meant to be played. :-/
It would suck to have to breakdown and build a pc to play it the way it was meant to be played but it would be 10x the gloriousness.

The Bumgarner thing could be irritating for Sony as a global company but doesn't seem to have any direct relation to PSN other than general incompetence. Makes the powers that be look stupid too I guess.
 

Fugu

Member
test_account said:
"Security experts have said they believe the hackers initially gained access to Sony's network through a "spear-phishing" attack that targeted a systems administrator who had broad privileges to access data on Sony's networks.

In "spear-phishing" campaigns, hackers craft e-mails with personalized messages so that the recipients let their guard down and click on links or download attachments that launch malicious software programs that take over their computers.

Once one PC is corrupted, hackers can use that machine as a base from which to launch sophisticated operations, such as the attacks on Sony's networks.
"
If this is true, it is unbelievable that Sony is using the word "sophisticated" to describe anything that has happened afterwards.
 

iFootball

Member
H_Prestige said:
LMAO at the comments.

"The Playstation Blog guys are jerks. I just asked them what they were doing for lunch and they replied "We have no updates concerning lunch""
I don't know, it must the 3 week delay, Late Friday still in the office, etc., but this made me lol....
 

test_account

XP-39C²
Fugu said:
If this is true, it is unbelievable that Sony is using the word "sophisticated" to describe anything that has happened afterwards.
Yeah. I dont really know what to belive. If the hackers had to rely on a phishing attack, it shows, or at least it seems, that the main security on the PSN servers was good enough. But if it was a phishing attack, then this doesnt really add up to being a sophisticated attack as you mentioned (it could have been an extremely well done phishing attack though, so that it looked very authentic, but still, it doesnt seem to be too sophisticated on a technical level), and it also kinda rule out the statement about that a "known to the world" exploit was used. I wouldnt directly define a phishing attack as an exploit at least.

EDIT: And if it was a phishing attack, does Sony really need over 3 week to rebuild the PSN security because of this? I dont know that much about server security, but that sounds a bit wierd to me at least, that it would take this long to fix something if only a phishing attack was done. But i dont know.
 

EagleEyes

Member
Does Sony realistically have a shot at PSN being at full capacity by E3? If they don't then they will definitely have to take some time out of their conference to talk about it. Which would suck because people don't want to hear about security issues at an E3 conference.
 

DrForester

Kills Photobucket
EagleEyes said:
Does Sony realistically have a shot at PSN being at full capacity by E3? If they don't then they will definitely have to take some time out of their conference to talk about it. Which would suck because people don't want to hear about security issues at an E3 conference.

I still think full functioning PSN will be an E3 announcement. If the online play is up and running well soon and goes till E3 without a hitch, it would be a nice time to return the store, and announce the freebies people are getting.
 

Used-ID

Member
EagleEyes said:
Does Sony realistically have a shot at PSN being at full capacity by E3? If they don't then they will definitely have to take some time out of their conference to talk about it. Which would suck because people don't want to hear about security issues at an E3 conference.

Urk. I can see the entire Sony keynote being about the PSN outage - with 3-5 minutes of "We're launching new hardware in Japan later this year, and we have some games that are coming out in a few months that you can play demos of on the show floor."

I can also see Microsoft spending 10-15 minutes on how Live is secure, etc, etc. While Nintendo just tries to remind everyone that they have a way to play games across the internet.
 

Used-ID

Member
DrForester said:
I still think full functioning PSN will be an E3 announcement. If the online play is up and running well soon and goes till E3 without a hitch, it would be a nice time to return the store, and announce the freebies people are getting.

Until Grace Chen unsurprisingly fails to update the store until 2 weeks after E3.
 
Air Zombie Meat said:
Wow, I really thought it would be up by this weekend. Can't be much longer surely.
it's being released in stages. "A few days" per stage right up to E3 where multiplayer will go up live on stage and fans can proclaim "Sony won E3! PSN is back up!" Makes sense really/
 

jackdoe

Member
CadetMahoney said:
it's being released in stages. "A few days" per stage right up to E3 where multiplayer will go up live on stage and fans can proclaim "Sony won E3! PSN is back up!" Makes sense really/
Haha. The only way Nintendo could trump that is if they actually announce Project Cafe with a decent network solution.
 
Used-ID said:
I can also see Microsoft spending 10-15 minutes on how Live is secure, etc, etc. While Nintendo just tries to remind everyone that they have a way to play games across the internet.

[unless I have been missing it] It seems that the other two heavyweights
have taken the high road regarding this ordeal for the most part, so far.
Impressive, considering how cutthroat the industry can be under normal circumstances.
E3 hysteria may be a much less pleasant beast...
 

Zoibie

Member
Used-ID said:
Urk. I can see the entire Sony keynote being about the PSN outage - with 3-5 minutes of "We're launching new hardware in Japan later this year, and we have some games that are coming out in a few months that you can play demos of on the show floor."

What, two hours of 'no new updates'?

Nah, it'll be business as usual, maybe with a quick aside when PSN releases comes up to reassure us that they're taking this seriously and whatnot.
 
Status
Not open for further replies.
Top Bottom