Select your localized edition:

Close ×

More Ways to Connect

Discover one of our 28 local entrepreneurial communities »

Be the first to know as we launch in new countries and markets around the globe.

Interested in bringing MIT Technology Review to your local market?

MIT Technology ReviewMIT Technology Review - logo

 

Unsupported browser: Your browser does not meet modern web standards. See how it scores »

{ action.text }

The damage done by the attack on Sony’s PlayStation Network last month—an event that exposed personal information on 100 million accounts—is still being calculated, but was magnified when Sony offered only delayed and incomplete information to users, some experts say.

Sony faces numerous Congressional requests, including this one made last week—as well as subpoenas from New York’s attorney general—seeking more information about what information was stolen, and the nature of its security defenses.

Howard Stringer, chief executive of Sony, has said the breach is the largest of its kind ever experienced by a company. But the details of the attack are still largely murky. “We have this problem with all such attacks. We never know what happened, how bad it is, what they did, or how they did it. Nothing,” says Bruce Schneier, a renowned security expert. “There is no visibility at all, and Sony is particularly ham-fisted about saying stuff and then retracting it.”

In a response to an earlier letter from Congress, Sony said it faced an “extraordinary” situation in which information about the intrusion “was neither immediately nor easily obtainable,” and it acted prudently in shutting the network down quickly while investigating what had happened.

Sony shut down the PlayStation Network from April 20 until May 15, when the company started getting its networks back online. Sony estimates that the incident cost $171 million.

Although the attack started sometime between April 17 and April 19, it wasn’t until April 26 that Sony announced that massive amounts of personal information had been exposed. For seven days, Sony made only cryptic statements to explain network outages. On April 20, the company published a one-line blog post saying: “We’re aware certain functions of PlayStation Network are down. We will report back here as soon as we can with more information.”

On April 21, Sony said it was still investigating. On April 22, it said there had been an “external intrusion on our system.” On April 23, it said it was “rebuilding our system to further strengthen our network infrastructure” in part to “provide the system with additional security.”

1 comment. Share your thoughts »

Tagged: Computing, security, Amazon, Sony, hack

Reprints and Permissions | Send feedback to the editor

From the Archives

Close

Introducing MIT Technology Review Insider.

Already a Magazine subscriber?

You're automatically an Insider. It's easy to activate or upgrade your account.

Activate Your Account

Become an Insider

It's the new way to subscribe. Get even more of the tech news, research, and discoveries you crave.

Sign Up

Learn More

Find out why MIT Technology Review Insider is for you and explore your options.

Show Me