PlayStation Network Security Update

443 1

On Tuesday, April 26 we shared that some information that was compromised in connection with an illegal and unauthorized intrusion into our network. Once again, we’d like to apologize to the many users who were inconvenienced and worried about this situation.

We want to state this again given the increase in speculation about credit card information being used fraudulently. One report indicated that a group tried to sell millions of credit card numbers back to Sony. To my knowledge there is no truth to this report of a list, or that Sony was offered an opportunity to purchase the list.

One other point to clarify is from this weekend’s press conference. While the passwords that were stored were not “encrypted,” they were transformed using a cryptographic hash function. There is a difference between these two types of security measures which is why we said the passwords had not been encrypted. But I want to be very clear that the passwords were not stored in our database in cleartext form. For a description of the difference between encryption and hashing, follow this link.

To reiterate a few other security measures for your information: Sony will not contact you in any way, including by email, asking for your credit card number, social security number or other personally identifiable information. If you are asked for this information, you can be confident Sony is not the entity asking. When the PlayStation Network and Qriocity services are fully restored, we strongly recommend that you log on and change your password. Additionally, if you use your PlayStation Network or Qriocity user name or password for other unrelated services or accounts, we strongly recommend that you change them, as well. To protect against possible identity theft or other financial loss, we encourage you to remain vigilant, to review your account statements and to monitor your credit reports.

We continue to work with law enforcement and forensic experts to identify the criminals behind the attack. Once again, we apologize for causing users concern over this matter.

Our objective is to increase security so our customers can safely and confidently play games and use our network and media services. We will continue to provide updates as we have them.

Comments are closed.

443 Comments

1 Author Reply

  • @SGAShepp the link is awaiting for approval. With regards to hashing.
    and as far as the proof with the reason why the Ohter OS was removed, well that reared its ugly head in a lawsuit with regards to the Other OS, Some here the truth could run em over like an 18 wheeler and they still won’t accept it lol.

  • Stop giving us useless update that we read countless time and get the psn up already.

  • datastorm…seriously, don’t you have anything better to do? Your posts are just annoying at this point.

  • No, Sony wouldn’t give out false dates, that would be entrapment anyways. Not to mention pros aren’t that dumb.
    This Group probably have thought of all that already. And they are probably Long gone by now. Heck there probably not even based here in the US.

  • I have been a large supporter of Sony for a very long time and I am eagerly awaiting the reintroduction of PSN. However, in our current digital age, information is worth more than just about any tangible object. With this in mind, Sony’s “Welcome Back” program is not just a joke, but an insult to it’s consumers. Now the people who still live at home with mom and dad can jump on these blogs and bash people like me for being upset because they have no idea the implications of this breach. I on the other hand I am trying to purchase a house and any blemish on my credit history could make that impossible. IMO, 30 free days of PS+ (which never has anything decent anyway) and some crappy free game is not a proper apology. I think that Sony should float the bill so that I can hire an outside company to protect my data and credit since it is solely their responsibility that it is now out in the open. Considering an information breach like this can potentially follow me around and continue to destroy me for the rest of my life, I am more than just upset. Sony, your “Welcome Back” program does nothing but mock the victims and undermind the severity of the crime.

  • While I have the deepest sympathy for the problems that Sony is experience, I can’t help but feel that their lackadaisical approach to their network and customer relations in the primary reason that this happened. Sony has the ability to change the electronics market worldwide (Walkman’s, 3-D tv’s, Blur-Ray, DVD’s, etc.) but they are unable to provide proper security infrastructure and procedures?! This seems highly unlikely to me that a company with so many resources was simply unable to prevent, contain, and control this. So, the only other logical assumption was that Sony didn’t care enough to protect their consumers. As long as the money rolls in who cares?
    People also want to call Sony liars but I don’t agree. Sure they may announce a new piece of hardware or software and then never release it, but thats business. This is entirely different. Security should have been in place to protect consumers, not the company, and it was not. I feel that this is a clear indicator of how Sony feels about their consumers. Actions speak louder than blog entries. So no, I do not feel that Sony is a company of liars. Lazy truth stretchers? I can side with that.

  • I do not blame the hackers, I blame Sony. If a prisoner escapes from prison, do you blame the prisoner? No you blame the institution who’s job it is to contain them. Sony has a moral and ethical responsibility to protect the data of the very people who helped to make the company what it is. I’m insulted that Sony implies that my personal and private information is worth no more than a free month of PS+ and some DLC. So basically Sony is telling me that their possibly life changing mistakes is worth no more than 10 bucks.

  • PlaystationNOTwork

  • You don’t blame the hackers? Really? I think they share a small, tiny bit of responsibility in this.

    Also, nobody twisted your arm to give Sony your information. They asked for it and you obliged. You could have said no. Yes, Sony’s serverse were breeched and you trusted them with your information. Problem is, data theft is a common thing in this day and age and it DOES happen.

    Maybe next time you should keep your personal information to yourself.

  • Sony said it expected online services to be fully restored >>>>by the end of May,<<>>partial restoration occurring in phases around the world beginning this week<<<.

    Google it!

  • did you hear that a hacker got into Xbox live…but, didn’t steal nothing nor changed anything but, just showed them that it is hackable. UGH, nothing is safe.

  • @Rustbucket80 Agreed 100% on Comment #345

  • @Rustbucket80, I do agree with you on all accounts.

  • @datastorm 347 they said that last tuesday >:\ sony is a bunch of lying bigots

  • As one person puts it, the Welcome back thing, is a Wolf in Sheep clothing.”
    It is Not only a slap in the face and an insult, but it is taking advantage of users. Sony, Is hoping to offer services to make a quick buck off this tragedy. it would have been best if Sony had not made the offer. it would have been far better had the offer been a letter of apology from the president of Sony, like what my mother received back in o when her camera had a bad lens . She got a better camera out of the deal along with that letter of apology HAND WRITTEN AND HAND SIGNED by the then president of Sony.. That is what made me Chose Sony.But Sony has changed greatly since that time.

    They changed for the worse.

  • Datastorm,You sound like a tool..like almost every post I see from you isn’t anything people care about. All you do is complain. We get enough of that elsewhere thanks.

  • @352 So stop supporting them and stop complaining to us. Go play 360 or Wii or something.

  • Spidey817,

    Your response to me not giving Sony my information is like saying I should never leave the house because a plane might fall out of the sky and crush me. I want to use their services, and as a contigency, I had to release some of my information. So your argument is that I should never use any service or product which inquires about my personal information? That is completely unrealistic for anyone, especially when you consider the range of services and companies that require this information. Hackers are going to hack, bad people do bad things. That is why we have police, FBI, etc. Sony should have predicted this inevitability and put proper deterrent’s in place. If this was the case, we would be talking about another company that got hacked which didn’t take the necessary steps to protect itself or its customers.
    So you can call me stupid or niave or whatever, but the fact of the matter is I am normal; I am the majority. I purchase things online like everyone else does and I go to extensive lengths to protect my information. Your “suggestion” is not realistic and you know it and I bet you do not abide by it.

  • google:
    Pachter Interview on Sony Security Breach (video)
    Carr Interview About Possible Sony Security Breach (video)

    You might want to re-think cloud data base.

  • From the looks of it Sony will get on-line gaming just in time for the PS4!

  • @354 Stop t-t-t-ta;likn that Blah blah blah

  • @354 or maybe when resistance 4 comes out

  • First of all, no, the odds of being hit by a falling plane are not the same as the odds of your data being stolen online. Go google those odds.

    Next up, you should know when you release your personal information that there’s a chance it’s going to be stolen. Period. No matter the security features put in place if a good enough hacker wants that information they’re going to get it.

    My point was, you said you were trying to buy a house and your personal information is important because of that. In knowing how often data thefts happen you should have stopped and declined to willingly hand your data over. When you willingly handed it over, you opened yourself up to having it fall into the wrong hands.

    What’s realistic and what’s not isn’t for me to decide, it’s for everyone to decide for themselves. Obviously this impacted you in a big way, so apparently it was a little more realistic for you than you seem to realize.

  • Seriously, shut up. No one cares about anything you have to say.

    The only thing we want to know is when the network is back up. If anything’s making me impatient, it’s YOU, because instead of getting an update on the situation, all I see when I come here is you being a troll! Go play your 360 is you’re so discontent. NONE OF US CARE!

    And seriously? Michael Pachter? Like he’s someone I’d ever listen to.

  • That post was at datastorm, not anyone else.

  • @Spidey817
    Are you afraid that your going to lose your gaming? if Sony Gets a little heat for what they did wrong? The majority of us are saying, Sony has a serious problem and that they need to fix it. The majority are saying this “peace Offering” of the PSN stuff is bated to entice people in midst of a tragedy. it takes advantage of people. The problem with Kids is you have not Experienced in these things and we adults have seen much in our life time.

    Take the time to stop and think. the parents have the ultimate Control. and I see a great deal of “Fit Throwing” because Kids are not getting there way.
    Comments like “Hurry the hell up”, and Sony You Better get you but into higher gear” severs no purpose what so ever. .

  • @344
    You seem to be under the misguided impression that an online (nationwide) network is completely impenetrable.

    “Honda reported a data breach on Dec. 28 affecting 2.2 million customers but didn’t disclose the total number of records compromised. Thieves stole customer names, e-mail addresses and vehicle identification numbers from an e-mail marketing provider Honda partnered with, but the full magnitude of the breach is still unknown at this point.”

    Source: http://www.eweek.com/c/a/Security/662-Major-Data-Breaches-in-2010-More-Go-Undisclosed-Report-787068/

    Major companies usually don’t even publicize the breach or even disclose the full extent of the damage at all. So really, get off your high horse, and if you actually wanna be self righteous about an issue like this, try it when the company at hand (Sony) is actually violating the rules (as in NOT ANNOUNCING A MAJOR BREACH TO THE PUBLIC) and also try blaming those that actually STOLE YOUR INFORMATION…really, NOT blaming the hackers? You’re an [DELETED] and deserve to have your personal information exploited.

  • At least most of us level headed people are cramming data that is good and important and if you thinks its bad well ” to bad so sad.” Personally if some of us irritate you wish some cold hard facts, it is hopes it will snap you out of your psychosis and get you to see some reality. But then Kids can’t handle that kind of stuff.All you care about is games, games, games.. Well we adults care about having the monies to give you a roof over your head. and if that means getting rid of a service that is not safe then we adults will do that.
    And if you don’t like that then so be it even if you are young person just out of Mom’s and dad’s home, How will you feel when all your money is snatched away leaving you with nothing? and the Land Lord comes a knocking with Pay rent or vacate? This is precisely the reason why We adults make the decisions and not the kids. We have to weigh everything in the decisions we make. Be we rich or poor. Every parents duty is to keep the family safe. irregardless of what we will need to sacrifice to do that. And if you don’t care, then you have no respect for your parents, I challenge you on this one thing Spidey817 Go out and volunteer for something. See how you feel afterwards.

  • Anyone else bored??!?!?

    Stuck on DH:A on a boss battle in legend mode for my lvl 48 mage……stuck in COD on Veteran in a hallway/office/hallway and can’t seem to get to the next checkpoint (tried at least 25 times *sigh* so not used to playing military FPS on console)….Hamsterball is harder than most people would think it is (and a fun game)….can’t play Battlefield 1943….stuck on quest(s) in Borderlands DLC…..don’t want to play some games I have a lot of trophies in due to 2 of my games ‘erasing’ their already collected trophy list once I got a new trophy (Madden ’10 and Flower) so that eliminates more than 1/2 my disc based games….already finished Stacking & DLC (which I got just before the system went down it seems)….not ready for 2nd playthrough in Mini Ninjas….

    Guess I could play Assassins Creed since that has no trophies anyways and different from what I’ve been playing. Then again I have Bayonetta and Dead Space sitting at 1% each so nothing really to lose…and I’ve been waiting to play DS but wanted to finish Fallout 3 first (but not playing due to poss. trophy issue).

  • no offence bt if your so worried bout money issues and all this shouldn’t even concern you what so ever and stop owning any kind of system so you won’t buy any games… so get off this blog and make that money then you would think an “adult” like you datastorm could’ve figured this out by now…

  • And for everyone sanity, can we quit going round and round saying the same things 1000 different ways?!?!?! We’ve covered it. We’re all just waiting. We know how everyone feels about this (esp those that have been posting since the first blog post about system down).

    Can’t we just talk about games and such, since we don’t have any other blog posts to look at besides the same “update” over and over again?!?!?

    LETS TALK ABOUT GAMING! :)

  • true so who’s looking forward to E3?! Anyone?!

  • Im looking forward for nitendos e3 cause it looks like there new system will be online before sonys

  • it better not be a HD Wii…

  • Anyone have MotorStorm: Apocalypse? I’m waiting for Dirt 3 myself but wondered how MotorStorm was; as an alternative to a traditional racing game.

    Why did EA give 1943 for free with the new Battlefield: BC2 disc (ultimate pack)?!? I see lots of people have already downloaded it and I already have it! lol Wonder if I can sell the code somehow. Wish it was a free DLC mappack instead, though you get onslaught with it it seems. Thinking I might want to get this as I miss it on my PC and am curious to how it is on the console.

    Anyone planning on getting Brink? Looks like a mix of Borderlands with Battlefield (graphics/gameplay and squad based w/ rewards for doing so). Debating on what to get for my next FPS….

    And a suggestion for a game like Oblivion: Elder Scrolls, but without the game freezes and with trophies…. :)

  • no its supposedly not a wii but is HD they call it Project Caffe? (I guess they like coffee) But i hope its better than the wii. And i wonder how microsoft will make fun of sony lol

  • they lied may 4th on the east side….

  • E3 always has something interesting. Wonder what it’ll be this year.

    (and if everyone at Sony is working around the clock, guess they won’t have anyone there….. heh)

  • I was planning on getting brink but then it reminded me too much of killzone with the classes and how you can be revived (which is rubbish). I just wish they would make an updated version of cod4 with those maps and mw2 maps in one game id be set for 2 years lol

  • I don’t care if it’s reiterating the current projections for when the network will be up, or revisiting frequently asked questions, but I’d appreciate at the very least a daily update. Waiting patiently has taken its toll on me, and quite frankly, I’m losing my patience. Waiting – without a courtesy update? That’s when I’m just about fed up and barely holding onto showing civility.

  • i guess… hope they don’t disappoint dat goes for everyone else as well

  • I was hoping that by 11:00 they would at least have had an update saying when they think the psn will be coming back up. Because I don’t think its gonna be today anymore….

  • Playstation only cares about re-gaining money by giving us all a seet taste of ps+ for a month. Its just like a dealer gives a customer a taste of that new new

  • I can’t believe they would say that it should be up by now, fail at putting PSN back up AND leave us hanging with no update. That kind of act loses them customers and money for good.

  • I think that 3d technology is getting impressing regardless at who makes it. I like the Idea of 3d glassless games. What I think aught to be done is true flight simulation. the PS3 has the power and ability, Throttle back on the shooters and create more creative games. but then again, I have always wanted to hop in an aircraft and go visiting other places. You know gaming can be more then just guns, RPGS and such. Heck the Japanese have games that we Americans will never see. I say , make the console equal for all. Give all the consoles the ability to use devices like play tv, and such. If Sony wants to really apologize to us consumers, then give us features we can use. Like an updated printer directory so we can print out Pictures..The dang thing does a better job then any PC I have seen.
    Should have seen kids eyes light up when I used the PS3 to pint there Pics with Santa lol. Printed using the PS3s native system then went to the Other OS for other things like making signs and such for Sana’s Booth. . People were impressed that the PS3 did that. See there are those of us that did use the Other OS for things other then Hacking.

  • stop complaining for other OS that POS stuff got us here in the first place

  • Maybe everyone at Sony passed out as they are or were “working around the clock”

  • sony is slack-a-lackin

  • Playstation It only does nothing what xbox can (connect online) :)

  • @ Lopez….that’s my problem with COD…you stop and you heal automatically from bullet wounds? Pfft. Much prefer squad based combat….where a med can assist those not mortally wounded, and both people benefit. Though if it’s a revive like it Borderlands (where multiplayer is totally co-op), then I’m good with it. If it’s PvP, then people should die if it’s a killshot (or at the very least the person that shot them should get credit for a kill)…

    Just watched Brink videos (looks cool btw) and you can respawn or wait for medic….Love the smart move thing…I hate jumping and doin all that crap with a controller so im very interested to see how that flows in game. Has very good reviews it seems, though I’ll likely wait for a price drop since Dirt 3 is already $59.99 and I hate paying anything more than $30 for a disc game (esp. ones I know have limited replay interest after 1 play thru) .

Please enter your date of birth.

Date of birth fields