Skip to main content

Sony's Kaz Hirai addresses PlayStation Network hack, we're liveblogging


Sony's PlayStation Network has been down for over a week, and it's a royal mess for all involved -- as you've no doubt heard, an external intrusion by unknown hackers compromised the personal information (supposedly including everything but credit card numbers) of potentially millions of users. This morning, Sony VP Kaz Hirai (formerly of the PlayStation division) will address the world from the company's headquarters in Japan, and our friends at Engadget Japanese are on the scene to bring us first-hand details in just a few minutes. Additionally, there appears to be an official livestream that will begin at 1AM ET, so keep it locked right here and potentially find some video at our source link.

Update: We're hearing that Sony's "goodwill gesture" may not be an incredibly significant one -- affected users can expect a free 30-day subscription to PlayStation Plus and a free software download of some sort, while Qriocity customers will get an extra 30 days of service on the house.

Update 2: As many as 10 million credit card numbers may have been exposed, though Sony says it has no proof that any actually have been compromised, and claims that it's received no reports of credit card fraud thus far. It is, however, working with the FBI to investigate the hack.

2:00 JST: The show's begun -- following a little bit of Mozart, Sony has trotted out three solemn-looking executives. More updates after the break. 


2:02 JST: Kaz Hirai and follow bow deeply, giving apologies. They plan to discuss corporate strategy in five points.

2:05 JST: On April 20, JST, says Sony, they were first alerted to unauthorized access.

2:06 JST: The first experts brought in determined it was a highly skilled intruder, so Sony brought in a second security firm to determine what had happened.

2:06 JST: Then, they emailed customers and published warning information. So far, so good.

2:08 JST: Yeah, lots of information was potentially stolen. "No evidence that credit card numbers, expiration dates or billing addresses" were stolen, though, according to the livestream translation.

2:09 JST: They haven't confirmed any cases of credit card fraud so far, and will let us know when they have more information. Sounds like they just don't know yet.

2:10 JST: There's a diagram up -- attackers accessed a database using a tool of some sort. The Japanese translation here isn't technical enough to tell us what.

2:12 JST: Kaz says there will be new security measures to prevent this sort of hack in future. New data center, moved from San Diego to a new location with "more advanced security." Enhanced detection capabilities, automated software monitoring, enhanced levels of data encryption, enhanced everything. Additional firewalls. Sony's creating an Chief Information Security Officer to handle these preparations in future. Good to know.

2:14 JST: There will be an additional sign-on security measure of some sort, but Sony's also asking customers to be vigilant and check their credit card statements. Sounds like they're worried about fraud after all. They're asking customers to change all their passwords too, and change all passwords used on other websites that happen to be the same as the PSN ones.

2:17 JST: Sony says it will "consider" paying for new credit cards if they have to be re-issued to affected customers.

2:18 JST: Yep, 30 day free PS Plus membership, 30 days of free service for Qriocity and Music Unlimited customers and a free gift of some software. Nice gesture.

2:19 JST: We missed a bit there, but it sounds like they're planning to restore full network functionality within the month. Considering it's May 1st, that could be quite a wait.

2:20 JST: Now Sony's complaining about being targeted by Anonymous, both in the form of direct attacks and protests.

2:21 JST: Another round of apologies.

2:22 JST: Q&A time.

2:25 JST: There have been as many as 10 million credit cards registered, but Sony's not sure how many if any have been compromised.

2:26 JST: "By the end of a week's time, we'd like to restart our services in order," says the translator. Sony expects there may financial impact of re-issuing credit cards, lost sales on PSN and Qriocity items, etc, but don't have concrete information on the impact yet.

2:27 JST: Again, they say they haven't received any reports of actual damages from credit card fraud as of yet.

2:30 JST: Q: How many people have been affected? What kinds of legal action can Sony take? A: We're still investigating the leak, so it's not possible to say with any certainty the extent of the hack, but there are 78 million accounts. Some users register more than one account, but the volume of data is potentially for 78 million accounts.

2:32 JST: Since SNEI (Sony Network Entertainment Inc.) is based in the United States, they're working with the FBI... doesn't sound like they're pursuing any other particular legal action yet, but the translation's a bit spotty.

2:35 JST: Sony's discussing the fine points of data leakage and probabilities. Nothing is for certain, it seems, but they have "no trace" that the intruders went into certain parts of the database.

2:36 JST: Q: Was this hack exploiting a known vulnerability, or a new one? A: The one at this time was a known vulnerability, but SNEI management was not aware of it. We're creating an information security officer to improve that. (Sony declined to discuss details of the exploit... it sounds like protections against it aren't in place yet.)

2:39 JST: Sony plans to deploy credit card monitoring measures region by region.

2:41 JST: Q: Why did it take so long to disclose this in a conference like this? A: We shut down the PSN quickly, and it took time to analyze all the data, so we had to take these actions gradually. Once we became aware of the situation, we moved promptly to warn customers.

2:43 JST: It also took more time than Sony hoped to shut down parts of the PSN and to analyze the data, Kaz says.

2:46 JST: Sony says that there's some speculation, but that it doesn't have any proof that Anonymous is behind the attacks. "It's not that we don't have any infomation at all, but it's still within the realm of speculation," says Sony's translator.

2:48 JST: The company says that some security measures were in place, and that the credit card database was definitely encrypted, but... and something was lost in translation here... it sounds like the other user information may not have been.

2:50 JST: Kaz is talking about how future devices, including the NGP, will rely on PSN in future. "We have to regain the trust and confidence of our users." Sony will try to achieve that by strengthening network services and communicating with users better from now on, he says.

2:52 JST: Kaz suggests that users may be prompted to change PSN passwords more frequently in future.

2:56 JST: Q: What message will you deliver to the hackers and pirates? (The speaker seemingly phrased this in the context that such hacks regularly occur and hardware companies have to coexist with such parties) A: We have to be able to protect the intellectual properties and copyrights, and by providing protection systems, we can provide software for users to enjoy... can maintain the ecosystem. We don't want our platform to be undermined.

2:59 JST: Kaz is stumbling around a bit (or Sony's translator is) but it sounds like he's emphasizing proactive data protection over ongoing legal action. Forgive us if that's not the case.

3:01 JST: Sony decided to correct an earlier statement, saying that PSN passwords were not encrypted but rather hashed.

3:06 JST: Both Kaz and the Japanese reporters are repeating themselves a bit now. Here's hoping there's something concrete left to talk about.

3:07 JST: One asked about compensation for the personal data leakage, in terms of credit card charge refunds, free software and the like, and Kaz insisted that the gifts are not compensation for the leak -- Sony is not presently compensating customers for the data leak because it doesn't have any evidence of credit card fraud, and Kaz says if Sony gets such reports it will deal with them on a case-by-case basis.

3:13 JST: Another reporter asked how many customers have already canceled their PSN accounts, and how Sony will deal with these customers' accumulated funds in their online wallet. It sounds like Kaz dodged the first half of the question -- saying something about how PSN doesn't rely on membership -- but we can't be sure from the translation. He does say, however, that Sony will deal with PlayStation Plus members and the contents of online wallets on a case-by-case basis. Sounds like a hassle.

3:30 JST: Reporters and Sony are debating the finer points of when, exactly, the breach was discovered and how Sony intends to protect users in future. We're beginning to nod off here.

3:38 JST: Sony is presently looking into structured ways to refund customers who wish to cancel their service, but don't presently have such a mechanism in place.

3:41 JST: That's all, folks!

Comments

Popular posts from this blog

Manual for Alienware M11x with Sandy Bridge confirms NVIDIA GT540M graphics

If the previous Alienware M11x R3 spec leak got you all giddy, then we have some good news for you: according to a manual dug up by one of our eagle-eyed readers, it appears that this year's M11x refresh will indeed be coming with second-gen Core i5 ULV and Core i7 ULV options, along with a faster DDR3 bus (1333MHz instead of 800MHz), a higher-res webcam (2MP instead of 1.3MP), an HD TrueLife LCD, and optional 3G / 4G mobile broadband. But of course, the real meat on this laptop is its graphics card, which turns out to be an NVIDIA GeForce GT540M with either 1Gb or 2GB of dedicated memory -- not bad for a laptop of this size. Unsurprisingly, no dates or prices are mentioned here, but given the early start of inventory clearance, it shouldn't be long before Round Rock reveals all.  Dell (ZIP)

IBM shows off Smarter Traveler traffic prediction tool

Traffic alerts on GPS devices may be old hat at this point, but there's obviously still plenty of room for improvement, and IBM now says it's managed to do just that with its new "Smarter Traveler" traffic prediction tool. Developed with the help of UC Berkeley's transportation group and the California Department of Transportation, the tool relies on predictive analytics software, GPS monitoring and sensors already on the roads to not only offer alerts, but build a model of each person's usual commuter route. Once the system is trained a bit, commuters are able to check out what's effectively a forecast of their entire route before they even leave the house, rather than simply be alerted to traffic problems before it's too late to avoid them. Head on past for the complete press release, and a quick video explanation of how it works. IBM, Caltrans and UC Berkeley Aim to Help Commuters Avoid Congested Roadways Before their Trip Begins First-of-a-K...

Sony Ericsson Xperia Neo delayed to Q3, Arc and Play facing limited supply due to Japanese quake

There hasn't been much good news coming out of Japan lately and this sadly keeps up with the unhappy trend. Sony Ericsson has officially bumped the broad launch (it's already available in limited quantities) of its Xperia Neo handset to at least July, explaining the delay as the result of "supply chain disruptions." Additionally, the Xperia Arc and Play devices, two other members of the company's new Android Gingerbread family, will be available in smaller volume than expected, at least for the near term. We guess that might go some way to explaining why the Xperia Play failed to reach some UK carriers in time for its April 1st launch date. Skip past the break for a statement from Sony Ericsson, who promises to be more explicit about the situation when it delivers its latest quarterly results on April 19th. As Sony Ericsson continues to assess the impact of the situation in Japan on its business, we have communicated to our operator customers and dis...