The Sony Affair
Weeks have passed since Sony brought down the Playstation Network after a hacker attack and the longer it takes for it to come back online, the more questions have to be asked...
When Sony brought down the Playstation Network back in April, there was a lot of blame going around - against Sony, for not having enough security, and against the hackers for doing the intrusion in the first place. But more than two weeks later, with the PSN still down and the Sony Online Entertainment-servers being brough down a week ago, the situation is becoming more and more embarrassing for Sony.
For many companies, Internet security is reactive in the sense that certain holes are only discovered after outside forces have found them and exploited them. As the whole affair started to roll out, and the extent of the breach became known, many were quick to point to other companies - including Google and Apple - that had been hacked in the past. That's all fair, if we don't count that two wrongs hardly make a right, but as time goes on and PSN still isn't available new questions start to pop up.
The most important one, of course, is what did Sony's PSN security actually look like?
At the time of writing, it's said that they are on the last leg of internal testing. We've also been told that the whole network probably won't be available until May 31, with features that directly relates to customer data (as the Playstation Store) coming online last. Meanwhile, SOE isn't talking at all, and the players of Everquest II and DC Universe Online are left fumbling in the dark for any hints on when their games will be available again.
Which begs two follow-up questions to the one above. What is taking so long? would be the first. We know that the FBI is involved, is it because of their investigation that things got delayed? No answer from Sony on that one, which I guess is to be expected. But without that information it's hard not to ask the second one - shouldn't this have been done years ago?
Bad things happens. Bad people will be bad people. It's a sad fact of life. Bringing PSN online with the introduction of the Playstation 3 should have happened in light of this. There's simply no excuse to not do all the testing possible. A hole might still have been found. The hackers might still have been able to get in. But the longer Sony take to bring their network back online, the bigger we have to assume the hole was. Security holes are constantly found in Flash, in Mac OS X and in Windows. They are often quickly patched. Two weeks of what we are told are "around the clock" work point to a much bigger issue with the network.
PSN was initially though to come online last week, then another hole was found and it was delayed again. The longer it takes, and the more it is delayed, PSN looks more and more like a patchwork of security issues. Sony are taking the time needed to make it as secure as possible, that's understandable. But what isn't acceptable is that this should have been done before the Playstaton 3's launch. It should have been patched up during all the firmware updates we've been downloading over the years. It should certainly have been fixed when Sony became aware that they risked being the target of hackers. We knew they were, with Anonymous pointing the way when they brought down PSN through a Denial of Service attack. So why didn't anything happen?
It is important to give Sony the benifit of the doubt when you don't have all the information at hand, but we are looking at the E3 press conference with bated breaths. They need to tell us, their customers, something spectacular to gain our trust again. A month of PSN+ and some free downloadable titles might be nice compensation for the downtime itself. It's not a way to gain back our full trust.
One thing that should be said is that over time, Sony have become better and better at communicating with us. From the initial silence, which several of us were quite upset about, they have gone to great length to posting regular updates to the Playstation Blog, even publishing a letter from the Sony Corporation CEO. That's impressive and as we wait for PSN to be brought back up, I hope they keep doing that.
At the same time, SOE stay true to their form of pissing off their customers and give infrequent updates that lack any form of information about what is actually going on behind the scenes. The intrusion into the SOE servers wasn't discovered until quite late, and you'd expect them to try their utmost to sate their angry customers. Instead their company culture seem to be one of total arrogance and, except for promises of free game-time and a Batman-inspired mask for players of DC Universe Online, they seem dead set on keeping that up. SOE has an incredibly bad reputation amongst MMO gamers already and one has to wonder if the upper echelons of the company - together with their PR side of things - have any connection with the dark reality of this.
No matter what happens at Sony or SOE, it's quite clear that the players and consumers already lost. We got the short end of the stick. While Microsoft rushed out the Xbox 360 and got us stuck with the infamous Red Ring of Death as a result, it looks as if Sony's rush to create a competitor to Xbox Live ended up with around 100 million accounts' personal information got stolen. I can live without online gaming for a few weeks, I'd like to think that I'm a rather forgiving person, but the actual timeframe is only the tip of the iceberg - the PSN rabbit hole goes a lot deeper.