PlayStation Network Security Update

443 1

On Tuesday, April 26 we shared that some information that was compromised in connection with an illegal and unauthorized intrusion into our network. Once again, we’d like to apologize to the many users who were inconvenienced and worried about this situation.

We want to state this again given the increase in speculation about credit card information being used fraudulently. One report indicated that a group tried to sell millions of credit card numbers back to Sony. To my knowledge there is no truth to this report of a list, or that Sony was offered an opportunity to purchase the list.

One other point to clarify is from this weekend’s press conference. While the passwords that were stored were not “encrypted,” they were transformed using a cryptographic hash function. There is a difference between these two types of security measures which is why we said the passwords had not been encrypted. But I want to be very clear that the passwords were not stored in our database in cleartext form. For a description of the difference between encryption and hashing, follow this link.

To reiterate a few other security measures for your information: Sony will not contact you in any way, including by email, asking for your credit card number, social security number or other personally identifiable information. If you are asked for this information, you can be confident Sony is not the entity asking. When the PlayStation Network and Qriocity services are fully restored, we strongly recommend that you log on and change your password. Additionally, if you use your PlayStation Network or Qriocity user name or password for other unrelated services or accounts, we strongly recommend that you change them, as well. To protect against possible identity theft or other financial loss, we encourage you to remain vigilant, to review your account statements and to monitor your credit reports.

We continue to work with law enforcement and forensic experts to identify the criminals behind the attack. Once again, we apologize for causing users concern over this matter.

Our objective is to increase security so our customers can safely and confidently play games and use our network and media services. We will continue to provide updates as we have them.

Comments are closed.

443 Comments

1 Author Reply

  • @Szamal
    We don’t know for sure. It could or it might not.

    It’s about 11:10 AM in California so give them some time I guess. I mean they gotta go on their lunch breaks right (even though they’re “working around the clock”….ROFL LULZ)

    @mcbuttz78
    We needed results pronto a few days ago.

    >_>

  • Get mean and nasty with these site forums owners have them arrested for harboring criminal activity . . Get them to talk and get these scum bag’s arrested. They didnt have any mercy for the 77 million of us. Why should you. Take them back to old scholl guilty until proven innocent.

    They didnt care when they where still the working devs games and content.. Why should the legion os playstation gamers have any mercy on them. We work hard to buy your content and relax with your services of movies and games and entertainment you provide for our families. This is attack on your family sony . Show them no mercy!!! Go after these forums sites like ps hax and nex generation have them shut down by the goverment and have the govt shut down all how to hack site or forums, deem them illegal.

    Put a good hurting on them Asap!!

    mcbuttz78
    vp-psn legionarre group

  • It never ceases to amaze me the impatience of people. You chastise them for not protecting your info “well enough”…then whine that they are taking their time to protect your info?

    Understand that the using the service right now, simply isn’t a priority. If Sony put it up a week ago and they were breached again, Sony would do more damage to them as a company then would likely be able to recover from.

    Stop asking for a magical date, it will be up when it’s ready to be up. Sony has to do what’s best for it’s business, not what lets you waste your evening in the most enjoyable way possible. Crying for a date accomplishes nothing but shows just how immature you are and how little you grasp of how things work in the world.

  • SOny please remember on thing which the law of the internet. The internet is not a right within Common laws of freedom of speech are not ment for the internet>therefore you can have the government take control of these sites and etc .if there are talking about your product and service’s of your product in a illegal fashion of manipultion of product. As in “how to hack” which is versus the terms and conditoning of your product. you can also sue these sites along with developers of the product in which there talking about.
    .
    Internet is privalage not a right..

    mcbuttz78
    vp-legionaire commitee

  • @i_like_toast
    You’re sounding like a passive consumer that feels you have no control over your product/services that you pay good money for.

    “It never ceases to amaze me the impatience of people”
    That would be relevant if the PSN was down for like 4 or 5 days at most. Today is now over 14 days since it’s been down.

    That’s kind of lame.

    “If Sony put it up a week ago and they were breached again, Sony would do more damage to them as a company then would likely be able to recover from.”

    And you’re saying that the time they’ve shut down the PSN (over 2 weeks now) hasn’t damaged Sony? Really? They’ve now missed 2 PS Store update, people can’t buy DLC, avatars, themes, TV shows, movies, and games off of the PS Store, people are getting fed up with them, Sony is being mocked and ridiculed by many from the gaming industry, government agencies are demanding answers from Sony, people are filing lawsuits.

    PS3 game sales aren’t really moving (relative to X360). A lot of gamers have supposedly sold all their PS3 stuff and got an X360 instead.

    Hey buddy.. I think Sony has lots lots of profits, potential profits, and lots of clients over the past few weeks.

  • @mcbuttz78
    You do realize that once something gets posted on the Internet, you can’t really erase it off of the Internet right? So even if Sony somehow manages to get these supposed hacker sites you speak me, I’m sure there will be someone else who will post the hacks and stuff on another blog, site, etc.

    So trying to get these sites to shut down would be a waste of time & money, which should be used towards finding the guys who hacked the PSN, suing them, and getting their asses in jail.

  • @nike. I really dont care if ever put the psn back up to play online becuase theres a government investigation going on. What they need to do is get rid of theses cells and site harboring these hackers. Start arresting site owners for harboring criminals who do criminal activity or plot it towards games and dev’s of games . There not doing console any good promoting how crack a xbox or ps3 or how to hack a game and etc. these sites sell products to do illegal harm to games and console for profit advertisments of the site. Which is same as taking money for those products.

    They should be asking the Us government to shut these sites/forums down .

  • i just want a release date that is going to be true.

  • okay people i dont really care about security just keep my account info secure screw the rest i just wanna play if they take someones credit card good just get a new one. Reminder I said ACCOUNT INFO like email and password so i can play the rest who cares i dont even care if they have jail broken ps3s and all that who cares I wanna play get it over with much rather it be the same problems but me play okay!

  • @ nike
    Its not a waste of time or money . You have to go after the house of where they sleep. If you arrest one. you’ve let 100 get away. Doing it one at a time is waste of money and time, they need to go after where they do there dirty scheming and it on these hacking sites and arrest them all.. And then sony should to appeal to the us government to have site’s like ps hax and next gen deemed illegal for the internet. It hurting devs, and consoles money at the end of the day.

    It also hurting us gamers even more becuase devs of games will charge more to us to buy. Becuase they need more money for sercurity of the product. Sony/xbox/wii cant do it all for the dev’s .. they willstart charging us the money. ANd some of us dont have that money.

  • BRING PSN BACK ONLINE!! DON’T LET ME DOWN SONY.. COME ON… A LOT OF MY XBOX FRIENDS ARE TALKING [DELETED] ABOUT YOU GUYS AND ITS GETTING HARD TO DEFEND YOU GUYS….. =[
    COME ON… I SAW THAT YOUR STOCK HAS BEEN GOING DOWN SIGNIFICANTLY.. THIS ISN’T RIGHT FOR YOUR OWN COMPANY AND THE SAKE OF YOUR LOYAL MEMBERS.. ILL NEVER PLAY XBOX BUT PLEASE JUST HURRY IT UP..

  • BRING PSN BACK ONLINE!! DON’T LET ME DOWN SONY.. COME ON… A LOT OF MY XBOX FRIENDS ARE TALKING ABOUT YOU GUYS AND ITS GETTING HARD TO DEFEND YOU GUYS….. =[

    COME ON… I SAW THAT YOUR STOCK HAS BEEN GOING DOWN SIGNIFICANTLY.. THIS ISN’T RIGHT FOR YOUR OWN COMPANY AND THE SAKE OF YOUR LOYAL MEMBERS.. ILL NEVER PLAY XBOX BUT PLEASE JUST HURRY IT UP..

  • Blah Blah Blah….

    Simple question, what is the date where the PSN will be back on line.
    DATE. Not range of dates, or a guess, an actual date. For example:

    “Thank you for your patience.PSN services will be back on line May 3rd 2011.”

    It is not that hard.

  • Yea sony just put it up man, and to all those people saying let them take forever as long as they protect us… yea well guess what they already have our info so what does it matter?

  • @212 Exactly, at first it was 1-2 days 5 a week later they said within a week (from last tuesday), Sunday in Yapan, They said the exact same thing twice “within a week” whats up sony? cat got your tongue?

  • here it is & still nothing…

  • 216 comments, 1 stinking reply by Playstation, losing our personal details – priceless.

  • good one :)

  • So Amazon drops the price of Portal 2 to $35 and I don’t have a credit card at the moment because I had to cancel it.

    Even if I did, is it wise at this point to continue to purchase PS3 products? We still have no idea what’s going on with PSN, especially after this SOE thing, I’m hearing more and more how much heat Sony has on them from practically everyone and I’m starting to wonder what the aftermath of this whole thing will mean to Sony’s gaming division. Is it going to be able to survive this?

    Is this a dying console or is Sony committed to the Playstation for the long run?

  • Hope that u will get PSN back soon. Keep up the good work! :D

  • all i want is to get to the psn store & sync my trophies…

  • oh ya. and use my codes for mortal kombat & motorstorm.

  • Yea sorry grim but they havent even mentioned the psn store being up in any of the updates so you’re gonna be waiting till mid-late may on that man. Your trophies will be up when we can sign in

  • the longer its down. the longer its gonna take for me to sync my trophies.

  • THEY PUT AN UPDATE ON THE EUROPE BLOG!! BUT IT JUST TALKS ABOUT THE RECENT HACKING AND DOESNT MENTION ANYTHING ABOUT PSN… DANG THESE PPL!! THEY NEED TO HURRY UP! YOU PROMISED BY TODAY!!!

  • within a week. Within another week. We will say anything to keep u guys from selling ur ps3 and getting a xbox 360. When will it be up. Quit stringing us along. All ur doing in these blogs now is repeating urself. Come on man.

  • FYI: You can purchase the PSN cards and downloadable codes for PSN cards from amazon.com For those of you who like the instant gratification of shopping on PSN at any time and not having to run out and purchase a card each time you want to d/l something – just use this method. You can still get items from PSN any time of day without having to give them your debit/credit card info or having to run out and purchase a physical PSN card with a code on it. Amazon.com will just email you the code right after purchasing.

    Looking forward to some online gaming when PSN back up. If we get to pick our download I might go for Zen Pinball or Castle Crashers. I’ve already got Dead Nation and GoW 1&2 collection, otherwise those would be on the top of the list.

  • WHY ARE YOU LEAVING US HANGING? You clearly stated that you would have some PSN services up by TODAY and yet you insist on not updating us all day. Your incompetence makes me sick.

  • come on sony… this is a good way to get people to switch to either the wii/360.

  • SOOPERGOOMAN187

    @ ki773r37f I retract what I said earlier. I’m still not afraid of these hackers, as I have moved since that address originally used for my psn deets and plan to change everything once back online. Also I post from hotspots and skewl so No sense for they to try to rack me through them. I also employ a traceroute ip scanner on my home network. If you come knocking on my network, I will know who and where from. I use nettools5 amongst other programs to keep my home and family safe from intrusions. I’ve been at IT since 96′. I will heed your advice and call the FBI, but again I tried today with a csr at sony tech and he hung up on me. I wonder if that is standard protocol now at sony tech support ( I dont know the answer to your question, click!), this is a technical issue…
    Cont…..

  • SOOPERGOOMAN187

    inued……

    So here it is the 3rd of May, a day later than previously stated in your past posts. If sony had of even just posted here saying: Thanks for the Info, or on twitter about all that info I did send em then I’d quit talking about it. They did say anonymous had nothing to do with it at the press conference or something. These psn so called hacker peeps are not really of that smart. In one video, the hacker’s mac address of his ps3 is clearly shown(I sent that to sony). I highly doubt they have that much skill to really hack and from what I’ve read it was a very simple redirection that they used and that’s all Im going to say on this subject, ever again….

  • @226 – While I can’t speak on behalf of other PSN users out there, I can say for myself that getting physical PSN cards isn’t so much a problem. Typically speaking *@ least prior to the PSN outage), I regularly go to a local Blockbuster Video several times a month to get PSN cards, so that aspect isn’t so much an issue.

    What factors into all this mess is that, regardless if one is just a casual PSN user or hardcore user, a good many people’s faith in Sony is on shaky ground at best. While most of the blame for this issue can be laid @ the feet of the hackers, Sony did have a role to play in this mess in as far as how they handled PSN security & how they disseminated info early on. With that being said, any people are, @ a minimum, reconsidering their continued use of PSN & it’s store. Who’s to say that there won’t be another major breach again & we won’t be in this prediciment? This is, at best, a major turn-off y’know?

  • this is why im glad i own all 3 consoles. i bet if sony didnt remove other os feature. this probably would of never happened.

  • @Nike

    yes it is indeed kinda lame it’s been down for over two weeks. Like most gamers PS3 I would like to use the service. However there are things far more important then getting to use a service, which is what Sony’s focus on.

    And if you can’t grasp the difference between short term and long term damage, there is no hope in having an adult conversation with you. Losing two weeks of the PSN is nothing compared to the loss of prematurely putting the system back up and being breached again.

    Most of us are willing to forgive Sony and give them another chance. As the old saying goes, Fool me once, shame on you. Fool me twice, shame on me. If it happens twice Sony loses customers, possibly enough to jeopardize it’s long term profitability as a company. I’ll take 2 weeks, 3 week, 4 weeks, or whatever period it takes for Sony to get it right, then to risk losing a company who has made a product I enjoy for the past decade and I believe can continue making products I enjoy for many years to follow.

    Sony is doing what any long term minded company would do

  • I am guessing we will get a status update around midnight est saying something like we need a couple of more days, but we have been working really hard.

    With that being said I want them to take their time. I really do not want a rush job with this. It can take a very long time to rebuild any aspect of the psn and realistically I dont think it could be done in 1 or 2 weeks. I even believe it could take them months to rebuild and transfer everything .

  • @CapsLockLunatic sony didn’t promise anything today, congrats on getting false hopes based on speculation and resounding failure to read. Though what can be expected from the lunatic screaming in every post.

    Not to mention why do you defend sony to your so called xbox friends? Sony screwed up, there is no defense of it. Does this screw up mean the games I’m playing are any less enjoyable? No. I’m still playing and enjoying games. Perhaps you should try that. Just a suggestion.

  • @232 – To the best of my knowlege, the reasoning behind removing OtherOS was, in short, for security reasons.I can understand the reasoning behand the decision w/ that being said. However, in hindsight, it looks like removing OtherOS only delayed the inevitable. Perhaps if they insituited other measures as well, we may or may not be in this situation now. Who’s to say?

  • @234 – I kind of agree with what you’re saying, but if that’s in fact the case. Why would they lie to the customers, yet again? This is a company people WANT to trust, no one goes around and points the finger at Sony. They doing it to themselves by giving out dates. Like they did with the whole “within a week” thing. Now they’re doing it again by saying “within this week”. Most of us wanna trust this company, but the patience is growing thin day by day, and lie by lie.

  • They removed OtherOS because people were determined to get at the parts of the hardware that Sony didn’t want to allow access to. Which eventually lead to the now infamous hacking lawsuit once the ps3 hardware was fully cracked.

    It wasn’t so much for security as it was to prevent the ps3 becoming the rampant piracy machine that the psp is.

  • Not coming out “within a week” isn’t a lie, it’s missing an arbitrary deadline. It means things they didn’t expect became issues and they are taking their time to do it right.

    Would you honestly rather them say, “hey well it’s not really ready…but we did say within a week so here ya go!”

    Would it be nice if Sony could give a little more details? Of course it would. But given how twisted everything they say as it makes its way around gaming new sites, I can’t say I don’t understand the desire to minimize what they are sharing.

  • @238 – Well, the way I look at it, stuff like piracy, etc. falls under the whole blanket topic of security, – not just stuff like what happenned to PSN.

  • Sony betrayed us

  • @239 – I get what you’re saying, & to a degree I can say that I agree, but consider this: Which is worse – putting out a statement & having it twisted around, or saying nothing at all & having that lead to rampant speculation? Personally speaking, I think that the later is more damaging to Sony.

  • @239 – No, but I rather them not give a date out, period. They got peoples hopes up for nothing, a lot of people including myself expected it to come up today. I have a day off today, so it would have been nice for it to be up, but like you said not everything goes as planned. Nonetheless if I was Sony, I would at least update my consumers on the fact that its not gonna be up today and giving out a proper date as to when its gonna be up. Instead of leaving us in the dark, yet again.

  • + KingLazy93 on May 3rd, 2011 at 2:14 pm said:
    “Sony betrayed us.”

    Hardly. SCEA and SOE (Sony) were both made victims of a viscous attack by a group of hackers. Along with that, those of us who use the PSN and/or SOE have also been made to suffer.

    SCEA and SOE are doing their best to make repairs, upgrades and to bring us all back online. What are the hackers doing? And look at our Community. Many have not understood what has been posted and others are attacking and insulting fellow posters. Why not pull together and show support for each other?

    Things will work out. Understanding that planned events can be delayed and that acts of God cannot be avoided will help. Explain the issue to your friends and strangers. Inform them.If people want answers, ask them not to rely on the “sky is falling” crowd. Look to the officials for answers. Understand that they can’t post everyday, but they do post when they have something concrete to share.

    Help yourself. Help the Community.

  • I would say seeing a Headline, as i saw, “SONY CONFIRMS CREDIT DATA STOLEN”(an actual headline i read on gamespot). To go on to read the actual article and find that confirms means, unlikely but possible, I’d say having your words twisted if far more damaging since most people aren’t going to take the time to actually read the article as I did. As you can see comments on this blog being reflecting of.

    Sony hasn’t said nothing, they’ve given multiple updates a week. Which is a lot more then nothing and far less then what many of us who actually will take the time to read it would like.

    At this point, Sony for as far as i’m concerned can be locked in a proverbial bubble ignorant to the world around them as they work on getting this fixed for the long term continuation of the company. The extent of which they can do is say the obvious. We’re still working on, we’re sorry, and thank you for your patience.

    @king

    if you expected it up today, you have no one to blame but yourself. Anything outside of Sony saying, “it’s up” is simply a hopeful guess.

    Also I enjoy the irony of you starting with don’t give us a date and end with give us date :)

  • A personal message to the head of sony sercurity team. You need to start spitting some names out/or arrested hackers criminals to the media and and you need to start arresting guys asap. Becuase congressmen are getting very un rested about all of this. Start getting brutal becuase come friday . The government is going to be very loud if its already not loud enough..

    You should not care if its the biggest fish or the guy that done it. It could a minor player in this . We dont care how you do this just get it done becuase it really getting out of hand. And shut down the ps2 servers as well or re do them as well.

    Your job is not easy but hear me out . You dont have to pull in a whale to be the best fisherman. A bass will do.. As long you pulling in something to keep the masses at bay.

    mcbuttz78
    vp-psn legioniree comittee

  • Cmon really why wasnt the PSN secure on higu security if sony was on top of their network this wouldnt be happening.(>*_*)>

  • @244 – There isn’t any irony in that, if you read my other comments, I simply keep stating stop giving us false dates and give us an official one. As for my own fault, so I guess its everyone’s fault but Sony, am I right? Patrick simply stated that it’ll be up in a week from last week which is today[May 3rd]. That’s not hopeful thinking, that’s believing what Patrick has said. If you’re gonna literally sit there and tell me “Hey, I didn’t believe him from the moment he said it”, that would be a load, you and I both know that.

    On another note, I have patience, but like I said its growing thin, and I’m like everyone else I’m simply asking for an official date. Not “within a week”, not “within two weeks”, an official date.

  • @244 – with regards to your response to king, Sony *DID* say 3 (@ least) times already when PSN would be up. Initially, they said 2 to 3 days. Then on last Thursday’s post, they said “one week from yesterday [last wednesday]”. A week from last wednesday would be today. Then they most recently said “within a week.

Please enter your date of birth.

Date of birth fields