Quantcast
Destructoid Japanator Tomopop Flixist
Dtoid Forums now support TapATalk and ForumRunner on your iOS/Android devices. Whoot.

Reports on Sony server security lack accuracy (Update) photo

Sony responded to the questions from the U.S. House of Representatives' Subcommittee on Commerce, Manufacturing and Trade with an open letter yesterday. But Dr. Gene Spafford, professor at the department of Computer Science at Purdue University, noted something interesting when speaking at the hearing.

Apparently, the Apache Web server software that Sony used was an outdated version and it also didn't have a firewall installed. Oooops.

Even better, that issue seems to have been "reported in an open forum monitored by Sony employees" about 2-3 months before the Anonymous attacks and subsequent other hacks happened. I think it's safe to say that if Anonymous knew about this, its attacks would've been more successful.

Actually, page 7 of this PDF that was inaccessible at the time of writing (maybe it hated foreigners) only said:

"Presumably, both companies are large enough that they could have afforded to spend an appropriate amount on security and privacy protections of their data; I have no information about what protections they had in place, although some news reports indicate that Sony was running software that was badly out of date, and had been warned about that risk."

Awesome. Thanks to the commenters for pointing out my failing though! It was deserved and I love you all. Community member KwikPwn also found the YouTube video of the hearing (the official webcast still gives 404 error) that shows Dr. Stafford's comments on the outdated Apache software and the lack of a firewall. Take a look for yourself!

Sony Was Using Outdated Software Prior to PSN Breach [GamePro] [Image]








More gaming stories around the web. Got news? Submit yours to tips@destructoid.com

Maurice Tan Maurice Tan does his Associate Editing from The Netherlands in a reality-shattering time zone. After working as a university lecturer in Psychology and Communications teaching game studies and the merits of Keyboard Cat, he now spends most of his time posting news, previews, reviews, and features about industry stuff or all things PC and strategy. He is also a connoisseur of licensed games, as long as they have achievements. Likes Deus Ex, Colonization, Mass Effect, TIE Fighter, and his iPod Touch. Meet the rest of the team



Post a comment! You can also post a photo below:

Comment with Facebook





Click connect and comment instantly!

Comment with Dtoid





New? SIGN UP - it takes 5 seconds

160 comments | showing # 1 to 50
prev
next 50 comments

Mr Andy Dixon's Avatar - Comment posted on 05/05/2011 14:21
Mr Andy Dixon
Boners.
CLFresh's Avatar - Comment posted on 05/05/2011 14:23
CLFresh
lol at the stupidity of SONY throughout this fiasco. Just more and more bad press.
Imdavid's Avatar - Comment posted on 05/05/2011 14:25
Imdavid
Wow...fantastic. They got after people who fiddle with their firmware and give two shits about their own server security? Fuck you, Sony. Good luck on PS4.
EternalDeathSlayer's Avatar - Comment posted on 05/05/2011 14:26
EternalDeathSlayer
So, can we stop with the Sony Defense Force around here now? Is this not enough proof for you that Sony was lazy, arrogant, and worst of all doesn't give a shit about it's customers?

Anybody who comes in here and comments with a defense of Sony is officially a fucking asshole loser with a misguided sense of loyalty to a multinational corporation that makes black boxes filled with computer components. You need to get a life and get over it.
Imdavid's Avatar - Comment posted on 05/05/2011 14:26
Imdavid
*err, go after..
Isay Isay's Avatar - Comment posted on 05/05/2011 14:26
Isay Isay
I'm sure Sony consulted a different type of boilermaker after this report
Jack8274's Avatar - Comment posted on 05/05/2011 14:26
Jack8274
This just keeps getting better and better. I need to make some popcorn.
EternalDeathSlayer's Avatar - Comment posted on 05/05/2011 14:26
EternalDeathSlayer
Also, I'm never going on PSN again.
Lord Death of Murder Mountain's Avatar - Comment posted on 05/05/2011 14:27
Lord Death of Murder Mountain
Kaz Hirai: will do corporate stuff for food.
Bakewell's Avatar - Comment posted on 05/05/2011 14:29
Bakewell
Whilst no company can guarantee that the data they keep is safe there can be no excuse for "protecting" data on out-dated software with no firewall.

This can't be good for Sony. A billion dollar company that fails to protect customer data to the greatest possible standards is negligence of the highest degree. It might not have stopped them from getting hacked but at least the could have said they had tried.
EternalDeathSlayer's Avatar - Comment posted on 05/05/2011 14:29
EternalDeathSlayer
The worst part for me is that I always tell people Sony is the lesser of evils in the competition between them and MS. Their online platform is more open and they sometimes appear to actually care about consumers, at least more than Microsoft.

Now I know how "open" they really are. Fucking morons.
Wolfy-Boey's Avatar - Comment posted on 05/05/2011 14:32
Wolfy-Boey
Riiiiiiidge Racer!!

No one?
llort het's Avatar - Comment posted on 05/05/2011 14:33
llort het
Definitely starting to agree with Geohotz's "they spent more money hiring lawyers than security people." quote. Good going Sony, once again I feel zero sympathy for any lawsuits that come your way.
caramelzappa's Avatar - Comment posted on 05/05/2011 14:34
caramelzappa
This is unacceptable. THey were negligent to secure their network, and then lied to us when it was attacked.

Companies don't care about us. I get that. Microsoft and Nintendo don't care about consumers either. But every company should know that if you are this careless, lots of people will not buy your products.

I'm still going to get Uncharted 3, because it will probably be my GOTY. But other than that I'm done with Playstation.
tylerstravis's Avatar - Comment posted on 05/05/2011 14:35
tylerstravis
Expect amazon to have an influx of people purchasing dlc through them.
wildcatfan87's Avatar - Comment posted on 05/05/2011 14:40
wildcatfan87
makes me wonder what the wii has
KwikPwn's Avatar - Comment posted on 05/05/2011 14:40
KwikPwn
Since Sony refused to participate in the Congressional Subcommittee, they're now being subpoenaed by New York's Attorney General.

The truth will come out!
jondier's Avatar - Comment posted on 05/05/2011 14:40
jondier
@Jack8274 get that new popcorn pop up bowl ive been hearing about. it looks cool lol
Tietsu's Avatar - Comment posted on 05/05/2011 14:40
Tietsu
Is it sad that my first thought after reading the headlines, "Hey, lions!"?
Woopman's Avatar - Comment posted on 05/05/2011 14:41
Woopman
And the palm meets the face yet again.

Yeah, no way I'm getting a PS4.
Gorescream's Avatar - Comment posted on 05/05/2011 14:42
Gorescream
Fuck your apology sony.
Aaron Mxy Yost's Avatar - Comment posted on 05/05/2011 14:43
Aaron Mxy Yost
I am Jack's complete lack of surprise.
kid23455's Avatar - Comment posted on 05/05/2011 14:43
kid23455
This hole that Sony is in is now the equivilent of a Cold War nuke, which is roughly a thousand times stronger than the ones dropped in Japan.
RoverTHX's Avatar - Comment posted on 05/05/2011 14:44
RoverTHX
@wildcatfan87
I would hope that if people tried to hack the Nintendo wifi all the numbers they would get are friend codes that used credit cards.

But for all we know, no one never thought of hacking their wii and destroying Nintendo's 70millionz? Community from the inside out.
SkullLeader's Avatar - Comment posted on 05/05/2011 14:44
SkullLeader
So Sony is allowed to use Apache but we aren't allowed to put Linux on our PS3s which we paid for?
Trev's Avatar - Comment posted on 05/05/2011 14:44
Trev
As noted in the comments of the last article by pokota, the actual quote from Stappford is "I have no information about what protections they had in place, although some news reports indicate that Sony was running software that was badly out of date, and had been warned about that risk." and that he cites no sources.

I want to know more, and I want it to be real information instead of this "I read it somewhere, maybe" thing.
ZRB's Avatar - Comment posted on 05/05/2011 14:45
ZRB
I can't wait to see what sony's response to this is. "Anonymous came and uninstalled our firewalls and rolled back our server software! Honest, guys!"

My heart goes out to all of you who unknowingly fed your information to this monstrosity of a network setup.
myosan8bit's Avatar - Comment posted on 05/05/2011 14:46
myosan8bit
forgot my password (again) should have just asked a hacker.....Sony love ff and disgaea and sweet psp nut come on you don't give a monkey's nut's about us...no ps3 4 me Sony suck this.....
Ilostmycookie's Avatar - Comment posted on 05/05/2011 14:46
Ilostmycookie
*Sigh*

My sympathies sony for the shitkicking you are going to continue receiving. You deserve it.
AklashPahk's Avatar - Comment posted on 05/05/2011 14:46
AklashPahk
I told you that would be good for us to know what happened. Sony (and others) will take better care with this kind thing in the future, with all of the bad publicity.
ManWithNoName's Avatar - Comment posted on 05/05/2011 14:47
ManWithNoName
Wait, have the author of the article said 'Apparently, the Apache Web server software that Sony used was an outdated version and it also didn't have a firewall installed.'? Sorry, but if you are not sure should you really speak this as certainty? But, yeah, if it is like this, then Sony fucked it big. Not only have did a bad job on PR, but also fucked with their network security.
CO Jakyl's Avatar - Comment posted on 05/05/2011 14:48
CO Jakyl
I didnt back annonymous, I just wanted to play my shit online...Sony as a whole is pretty fucked on the next playstation. They better just work on their TV and Audio departments. I for one will never buy another playstation console. At the same token Im sure that sony has learned its leason....too little too late one would assume.
brainderailment's Avatar - Comment posted on 05/05/2011 14:48
brainderailment
Shouldn't have ignored those pop-ups.
MinusO1's Avatar - Comment posted on 05/05/2011 14:48
MinusO1
@E.D.S I'm with you on defending Sony. After all this bullshit to come around and be like, "It's okay guys, Sony still cares about it's customers. Look, we get free stuff.", will just make you look like a fucking tool and a dumbass.

Sony knew about their lame security and did nothing, spent all this money on protecting it's property through litigation, and gave everyone the run around about everything.

tl;dr Fuck you if you defend Sony.
dtomek's Avatar - Comment posted on 05/05/2011 14:49
dtomek
@EDS
Their online suuuuuuure is more open. Hah, j/k, except seriously.
cbarrentos's Avatar - Comment posted on 05/05/2011 14:50
cbarrentos
@caramelzappa :
way to tell 'em.
"up yours sony! i mean... i'm still buying your stuff for a little while... but then! UP YOURS SONY"
Scuffles's Avatar - Comment posted on 05/05/2011 14:51
Scuffles
........... Wow ..... wow ......

So arguably my home computer has tighter security than their corporate systems... I find that somehow less than reassuring.
pokota's Avatar - Comment posted on 05/05/2011 14:51
pokota
This is what Spafford said: "I have no information about what protections they had in place, although some news reports indicate that Sony was running software that was badly out of date, and had been warned about that risk."

As far as I know, he cited no sources, and had zero first-hand information. It's likely he was talking about the same forum posts everyone else has mentioned, which is amazing that he would bring up in a real situation. If we're using forum posts as proof, then I can prove the existence of El Chupacabra really fast.

If it's true, then it certainly deserves attention, and there definitely needs to be an inquiry, but people taking what Spafford said as anything close to being fact are either jumping the gun or being willfully mislead.

http://republicans.energycommerce.house.gov/Media/file/Hearings/CTCP/050411/Spafford.pdf
mix's Avatar - Comment posted on 05/05/2011 14:54
mix
Oh Jim you so crazy...not Jim? Whaaaaa?

@EDS
You mad bro?

I'm not defending Sony, I just got a new CreditCard and moved on with my life, maybe it's because I sit upstairs in a Credit Union all day and know shit gets stolen all the time, who knows. If Sony was aware of old firmware and did nothing, than that is shitty of them, doesn't mean I won't turn my PS3 on and play online.

They need to make a Kevin Butler commercial or something around this.
Enzi's Avatar - Comment posted on 05/05/2011 14:55
Enzi
That's pretty consistent with the chat log that was floating around a while ago.

Fucking epic fail.

At least we know now that Sony really doesn't give a shit about users security. I guess it's pretty easy now to sue Sony. Having no firewall is pretty much the real life analogy of having no door.
jawshoeuh's Avatar - Comment posted on 05/05/2011 14:56
jawshoeuh
oh my good gravy this is getting tired. wtf, sony. even after being targeted by hackers you didn't beef up security? ...and by 'beef up' i mean 'bring up to a basic standard'.
M47R1X's Avatar - Comment posted on 05/05/2011 14:57
M47R1X


Damnit Sony, I tried to defend you, I really did, but you fucked up. HARD. Inexcusable if true.
pokota's Avatar - Comment posted on 05/05/2011 14:58
pokota
Reading any kind of news on an of the gaming blogs is pretty much worthless. They just repeat one another, with no effort at research or even the faintest concern over truth. And to think, sometimes Destructoid makes fun of Kotetsu, when they are basically the same.

The GamePro article does not mesh with the transcripts at all, and comes close to being an outright lie.
tahmidk's Avatar - Comment posted on 05/05/2011 14:58
tahmidk
lol this is why i dont have PSN on my PS3
Everyday Legend's Avatar - Comment posted on 05/05/2011 15:00
Everyday Legend
I bet they wish they were anonymous right about now.

DIDJA SEE WHUT I DID DERE
Jay Me's Avatar - Comment posted on 05/05/2011 15:00
Jay Me
Don't worry Sony, release the NGP for £150 & all will be forgiven.
D00mM4r1n3's Avatar - Comment posted on 05/05/2011 15:03
D00mM4r1n3
I'm surprised no one at Sony has committed Seppuku yet. Just goes to show their arrogance.
Black Nexus's Avatar - Comment posted on 05/05/2011 15:04
Black Nexus
Everyone really needs to read the article. As trev pointed out he hasn't seen Sonys security. They could be using military grade firewalls for all this guy knows.

This guy may be an expert in the field, but if he has never seen the system in question his opinions worth nothing.

Can everyone wait for actual facts to surface before you pull an eternaldeathslayer and say something that stupid.

There's a CSI team going over this, wait for them to come with the official report theeeeeen state an opinion.
quantumcatphd's Avatar - Comment posted on 05/05/2011 15:04
quantumcatphd
@Pokota that's true of the MSM as well, so they're like real journalists!
Also, did you mean Kotaku, or am I missing a gaming blog? :)
prev next 50 comments

Comment with Facebook





Click connect and comment instantly!

Comment with Dtoid





New? SIGN UP - it takes 5 seconds

Comments policy

Destructoid is an open discussion community. You don't need to "audition" to post a comment - just speak your mind. We respect differing opinions on the site, so have at it. Be smart, funny, insightful, clueless, or cute -- but back it up with substance. Keep your cool, keep it fun. We only ask that you act respectfully and above all: don't be a troll and ruin it for everyone else. Don't bring down gamers or we'll, you know, gently shoot you in the face and stuff you into a flaming mailbox. Each comment is your opportuntity to make this community awesomer. Is that even a word?

Avoiding the banhammer only requires common sense: spamming, trolling, racism, NSFW stuff, and other forms of sucking will not be tolerated. If anyone is griefing please report abuse. Be good. Don't suck!