{"id":875,"date":"2011-06-03T11:06:33","date_gmt":"2011-06-03T16:06:33","guid":{"rendered":"http:\/\/www.ict-pulse.com\/?p=875"},"modified":"2011-06-03T11:06:33","modified_gmt":"2011-06-03T16:06:33","slug":"game-over-lessons-from-the-sony-playstation-network-fiasco","status":"publish","type":"post","link":"https:\/\/ict-pulse.com\/2011\/06\/game-over-lessons-from-the-sony-playstation-network-fiasco\/","title":{"rendered":"Game over! Lessons from the Sony PlayStation Network Fiasco"},"content":{"rendered":"
For those of you who are not online gamers, you might not be aware of the major hacking of the Sony PlayStation Network that occurred in April, which caused the company to shut down that service. Recalling an earlier post, 10 things to consider before you migrate to cloud services<\/a><\/strong>, there are some lessons to learn from the Sony experience…<\/em><\/p>\n In mid- to late-April, reports began to circulate in the media that one of Sony’s networks had been hacked. The only sign of trouble was that there had been a major outage of the online service for Sony’s PlayStation 3 and portable consoles, the PlayStation Network. However, as the outage continued and frustration among gamers grew, on 22 April Sony reported on its blog that its PlayStation Network and Qriocity services had been affected by an \u201cexternal intrusion\u201d<\/em>. The company suspended the two services until further notice, and explained that its efforts \u201c<\/em>to resolve this matter involve re-building our system to further strengthen our network infrastructure<\/a><\/em>\u201d<\/em>.<\/p>\n What eventually became clear was that details for PlayStation Network’s members, which number 70+ million,\u00a0had been stolen. The stolen information included names, addresses, and possibly credit card numbers (TechCrunch<\/a>). As expected, Sony has been working assiduously to rebuild its network. Additionally, it has established a free identity theft insurance protection programme for each of its PlayStation Network and Qriocity members who sign up for the protection. The programme includes up to USD 1 million in coverage per person to cover costs associated with an identity theft incident linked to its hacked network. However, while Sony tries to extricate itself from this mess, there are a number of lesson we can learn.<\/p>\n 1. Do not underestimate the commitment of hackers.<\/strong> Sony is a huge and reputable company, hence there is an expectation of top-notch online security. However, there are cyber-criminals who have dedicated themselves to breaching cloud security. For example, on top of all of Sony’s problems with its PlayStation Network, on 22 May, news began to trickle out that Sony BMG in Greece had been hacked and user data had been exposed (Sophos<\/a>). The stolen information included the names, email addresses and usernames of registered site members. On 24 May, it was reported that the website for Sony Music Japan was hacked. Although data from the site was exposed, it appeared not to include personal user information. However, the attackers left some evidence of their infiltration and highlighted additional weaknesses of the site (Sophos<\/a>). Then on 25 May, Geek<\/a> reported that Sony Canada has been hacked and the personal details for 2,000 members had been stolen.<\/p>\n 2. Businesses are not as vigilant as they should be<\/strong>.\u00a0 Cloud providers and businesses that are operating or involved in cloud-like services are often aware of the type of threats and ways they could be vulnerable online. However, over the last few years, experts have been of the view that cloud operators and providers in particular have not been vigilant enough to try to keep one step ahead of the criminals.<\/p>\n