Security expert testifies Sony servers went unpatched
Summary: Sony used outdated software on its PlayStation Network servers, according to the testimony of a security expert sitting before a congressional subcommittee.As reported by The Consumerist, Dr.
Sony used outdated software on its PlayStation Network servers, according to the testimony of a security expert sitting before a congressional subcommittee.
As reported by The Consumerist, Dr. Gene Spafford, computer science professor at Purdue University, testified that Sony used versions of the open source Apache Web server software that went "unpatched and had no firewall installed."
In recent weeks Sony's seen its PlayStation Network, Qriocity and Sony Online Entertainment services compromised, leading to the exposure of more than 100 million user accounts. Some credit card accounts have been taken along the way.
Sony declined to participate in the subcommittee hearing. Instead, Sony Computer Entertainment America chairman Kazuo Hirai sent a letter outlining the company's efforts and implicated someone associated with the the "hacktivist" collective known as Anonymous as the possible culprit.
- Sony implicates ‘Anonymous’ in PlayStation Network attack
- Sony security hole exposes another 24.6 million accounts
- A look at what Sony’s doing to fix the PlayStation Network mess
- Hey Sony: Give gamers straight answers if you want our business
- Sony encrypted credit card data, but not user account info
- PSN debacle illustrates stark differences between Apple and Sony
- Sony’s PlayStation Network data breach: Game networks an irresistible hacker honey pot
- Sony confirms PlayStation Network hack exposed user info
- PlayStation Network intrusion hackers grabbed customer details
Kick off your day with ZDNet's daily email newsletter. It's the freshest tech news and opinion, served hot. Get it.
Talkback
It coulda been mesothelioma
They took people's credit card data, stuffed it onto a server, and didn't even keep the software up to date with the security patches?
Agree, it is .....
the height of arrogance and reckless irresponsibility, but this is Sony, so maybe it is not surprising.
RE: Security expert testifies Sony servers went unpatched
<a href="http://www.iresourcer.com">advertise jobs</a>
RE: Security expert testifies Sony servers went unpatched
<h3><a href="http://www.maurisource.com">creation web</a></h3>
Doesn't really matter that they weren't patched, the latest version still
RE: Security expert testifies Sony servers went unpatched
LOL Do you really believe all that FUD you spew?
How do you know it'll still get hacked? Because it doesn't have a Microsoft logo on it?
more LOL...
RE: Security expert testifies Sony servers went unpatched
Sony let your baby play in the middle of a busy road! Is it then a surprise that this happened? <a href="http://bodas.banquetesinnova.com">Banquetes</a>
RE: Security expert testifies Sony servers went unpatched
What I really want to know is when does PSN will be working again. I remember Sony saying that it will be working this week???
RE: Security expert testifies Sony servers went unpatched
corporate governance?
Message has been deleted.
RE: Security expert testifies Sony servers went unpatched
Remember the DRM rootkit? Sony isn't dumb, just arrogant.
RE: Security expert testifies Sony servers went unpatched
Apache auto update wasn't installed?
What IF
House analogy is bad
I blame it on us
we let these people get off once caught because nobody was physicaly hurt, no property was physically taken, it's just money. And for those that do get jail time, and not a suspended setence (or a job at a security form) they just go back and do it again
When my card data was stolen and used to purchase crap online I got the money back in 2 weeks, but that was two weeks I couldn't use my own money! Imagine if that was my only account, I would have been late on payments and stuff, or my credit ruined.
We're the blame here because we don't treat it like something that could affect our lives moving forward (for many it does hinder or destroy their lives down the road.
Well, I say "catch and kill" so they're no longer around to do it again, maybe the next guyt would like the thought of living more then the thought of getting caught and counting the hours to his death.
RE: Security expert testifies Sony servers went unpatched
RE: Security expert testifies Sony servers went unpatched
And yes, if someone broke into my friends house and stole a bunch of stuff I was letting him borrow, and I learned he left the windows and doors wide open, I'd punch him. Sure, I'd realize that its not completely his fault, but he could have gone through simple measures to prevent it from happening.
RE: Security expert testifies Sony servers went unpatched
A friend asked to borrow my truck At the time he didn't have a valid driver's license. I told him my insurance probably wouldn't pay if i let an unlicensed driver drive the truck and he had an accident.
He said "I've never had an accident."
And i replied: "Bill, there's a reason they don't call them 'purposes."
Contributory negligence is a very real legal concept.
RE: Security expert testifies Sony servers went unpatched
Sorry, but US laws are very clear on requirements for ANYONE to house credit card data and Sony breached these laws by not having proper protections in place. Not only that, this is commone sense IT kinda stuff, so Sony is absolutely to blame here.