Kaz Hirai Holds PSN Outage Press Conference
With the PSN outage now entering a 11th day, Kaz Hirai is taking the unpresidented measure of holding a press conference tonight at 10PM PDT/2PM Sunday JST. As for the details of the conference. Well, we don’t know much at this time, but we are going to post up additions to this article as we get more news from the livestream of the press event. One assumes that we might get some details as to what happened, how they are remedying the issue, and most likely, if and what will be the compensation to the end users.
Stay tuned, as the conference is suppose to start in 3 minutes.
BTW, our graphic comes from the PSNStores.com website.
9:59 PM PDT – Not much happening yet. We have some classical music playing as reporters funnel into the press room at Sony’s corporate headquarters in Japan.
10:02 PM – We are introducing attendees. All are bowing as they are introduced.
10:03 PM – Kaz extends apologies to PSN users for the outage and exposure of data, followed by a long bow.
10:05 PM – Starting to address facts about the outage. Servers are located in San Diego at ATT facilites. Established on April 1, 2010. Sony rents the space and manages the servers.
10:06 PM – Noted infiltration to network on April 18-19th. Shut down network on April 20th. Also engaged outside security firm to mirror servers and examine network. Highly sophisticated intrusion, and hackers covered tracks well.
10:07 PM – On April 27th, emailed users to let them know that Sony did not know if users had been jeopardized. However it was confirmed that user data had been taken. Data obtained – Names, address, email address, gender, login ID, password, b-day. No known credit card data has been compromised or taken, but have been advised to monitor credit.
10:09 PM – contacted FBI to assist in investigating the infiltration.
10:10 PM – Displaying chart that is unfortunately in Japanese but diagrams the server structure of PSN and Qrocity network. Possibly infiltrated via Web Application server via a user created tool. From there the infiltrator ended up gaining access to the database server via this tool. Only suggested, but not confirmed mode of compromised access.
10:12 PM – 10 million accounts that have active credit cards attached to them. Other accounts may have other means of payment attached to them, including PSN cards, etc.
10:12 PM – excellerating a data server plan to a new data center with more advanced security. Looking to use more protection on customer data. Automated monitoring and encryption. Enhanced ability to watch for unauthorzed access to network. Created a position of Chief Software Officer to monitor network in SCNA. A new firmware will release with PSN restoration which will require password update.
10:15 PM – Password can only be changed on original PS3 that the account was created, or by verification email.
10:16 PM – need to check purchase history when the service comes back up. Recommends changing passwords on other accounts if you used the same password for any other account outside of PSN.
10:17 PM – Sounds like they are going to offer some sort of credit monitoring in each country. 30 day free membership in playstation Plus, and some other premium free download content.
10:18 PM – Services will be brought up slowly, in a controlled manner. Free items mentioned above will be put together in a Welcome Back offer of some sort.
10:19 PM – Looking to restore all services within this month, starting with PSN access, VOD, Qrocity, and PSN Store purchases
10:20 PM – Bringing up Anonymous hack and how they publicized info about Sony execs and their family members.
10:22 PM – And with that we go to questions from the floor.
10:23 PM – Question from Nikkei – about credit card numbers and how will this outage affect the bottom line of Sony. Kaz responds that while they do not think any credit card data has been compromised, they cannot guarantee it. Sony will reimburse credit card owners for the cost of reissuing a card as well as credit monitoring services.
10:27 PM – While several pieces of data have been leaked, cannot address exact amount or number of data that was stolen.
10:30 PM – Question about cooperation with law enforcement. Will Sony file lawsuits against individuals or companies involved. Answer – still investigating the break-in, so exact data is still in flux. Feel that it is less than 78 million people, but the theft involves 78 million accounts. FBI is leading investigation as the data center is located in the US. Legal avenues have not been discussed as the investigation has only just started.
10:33 PM – Again, another question about the amount, or type of data taken. Again the response discusses the points mentioned above.
10:35 PM – Stream is going a little wacky between live audio and translator. Really getting irritated by this
10:36 PM – nothing that shows that the intruders actually access the credit card section of the data store.
10:37 PM – Was the web application server affected by a known vunerablilty. Answer – Yes, but Sony was not aware of the vunerability. Will not mention the type of server or application server that was vunerable.
10:39 PM – Credit card fees will be paid by Sony if compromised. Credit card monitoring will be made available to those that have credit cards used illegally, but it will not be granted to all users carte blanche from the start.
10:41PM – Asking question about disclosure policy. Talking about complaints that have arrised due to extended quiet period from Sony. Kaz mentions complete timeline, and mentions that they did not know the extent of the data issue until the 27th of April and then notified users of data compromise at that point in time. Stopping the system had to happen gradually. Did Sony know about intrusion when Sony Tablet was announced. Yes, but did not know the extent of the issue at that time.
10:44 PM – What do you think the reason was for hacking. Over the past month, Sony has experience attacks on its systems, but cannot link this attack to the same groups. At this point in time, the reason for intrusion, it cannot be disclosed at this time.
10:47PM – Why was password not encrypted. There are security measures at the server level, but not on the actual data itself.
10:49 PM – Sony Tablet, NGP and PSN deployment to new regions are all affected by this outage. Some more than others.
10:52 PM – Will Sony use password history features to make sure that passwords are not reused. Will make notice that password for PSN should be different from other passwords and that it should be changed on a regular basis.
10:55 PM – Why was their no contingency plan for this kind of event. How are you going to take on pirates. Sony has to provide services that protect its rights as well as those that develop for the platform.
11:02 PM – Many of these questions continue to revolve around the data that was taken.
11:03 PM – Why was release of information quicker in US over Europe and/or Japan. Also, does the cracking of the Root Key cause issues for Sony in the future. We like to use regional blogs to convey this kind of information, but we do not have them in all regions. As for the cracking of the root key, we do not want to discuss this due to the legal matters surrounding this.
11:08 PM – What will the cost of the 30 days of PS Plus for Sony as well as the cost of any credit monitoring software. Costs are not the concern, instead it is about reinstalling the confidence of the customer in Sony products and security
11:12 PM – Discussing the various security attacks on Sony over the last 30 Days. Specifically mention the attack by Anonymous and how it affected Sony. Does not implicity indicate that Anonymous is involved with this attack.
11:14 PM – Funny that when all of this started, account numbers were at 70 million. 11 days later it is 78 million. How did 8 million people register when the services hav been turned off for 11 days?
11:16 PM – Kaz states that most calls to support center are about restoration of service
11:18 PM – Basic package of free rewards – cannot define exact cost, as packages will be different per region. Sounds like it will be a decent package. As Wombat said earlier this week – FREE MAG for All! Just kidding!
11:21 PM – Will enhance the robustness of the network system and data center.
11:24 PM – Why was press conference not held on April 27th. wanted to have timing of resumption, consumer rewards and more in place before we held press conference.
11:30 PM – 50 million PS3 devices in the environment, 80% or 37 million consoles are connected to the network.
11:35 PM – No confirmation of credit card data leakage.
Tags: kaz hirai, outage, psn, Sony
-
http://twitter.com/HybridMisfit Jordan Thomas
-
shidlern











