May 11, 2011

When will PlayStation Network be back up?

Perhaps the question should be: "If I hold my breath waiting for Sony to answer and I die, can someone sue?" Because Sony's continued promises when PSN will be back up are like the kid who incessantly promises to clean his room and never does. Subscribers grow impatient, with the vast majority answering our poll are ready to switch to Xbox 360 and Xbox Live.

Late last month, Sony promised partial PSN restoration -- gaming, music and video services -- on May 4, a pledge repeated on May 1. It's now May 8, and PSN is still down. I checked just before posting.





Best Microsoft MCTS Training – Microsoft MCITP Training at Certkingdom.com




Two days ago, in another "I promise to clean my room soon" blog post, Patrick Seybold, Sony Senior director of Corporate Communications & Social Media, writes: "We know many of you are wanting to play games online, chat with your friends and enjoy all of the services PlayStation Network and Qriocity services have to offer, and trust me when I say we're doing everything we can to make it happen. We will update you with more information as soon as we have it. We apologize for the delay and inconvenience of this network outage."

What's the excuse this time? Simply put, Sony cannot yet guarantee that PSN is secure enough to put back online. "When we held the press conference in Japan last week, based on what we knew, we expected to have the services online within a week," Seybold explains. "We were unaware of the extent of the attack on Sony Online Entertainment servers, and we are taking this opportunity to conduct further testing of the incredibly complex system."

Within hours of the May 1 promise to restore PSN last week, Sony Online Entertainment went down, and the company issued yet another security warning. Hackers had stolen data from SOE, and this time Sony confirmed that credit card information had been taken. At least 12,700 credit or debit card and 10,700 direct debt card numbers (with bank account numbers) were stolen from SOE subscribers in Austria, Germany, Netherlands and Spain. So the initial breach was much greater than Sony understood, and the company took much longer uncovering the problem.

Hackers broke into PlayStation Network between April 17-19 and stole massive amounts of personally-identifying user data. On April 20, Sony voluntarily took down the network, after discovering the hack. The action may have helped prevent further data losses and allowed Sony, third-party security investigators and law enforcement to begin a forensic analysis of the hack. To reiterate: Hackers didn't take down PlayStation Network. Sony did. The same can be said of SOE, which Sony took offline, arguably belatedly, after discovering the hack.

In mid April 2011, Sony took down PlayStation Network after hackers stole subscribers' personal data. PlayStation users, will you switch to Xbox?
Absolutely
Not even if Hell froze over
VoteView Results
Share This
Quantcast

The full extent of the data breach is still unknown. Hackers did steal subscriber account IDs, passwords, addresses and phone numbers, security questions, email addresses and birth dates. Sony has insisted that, despite reports of millions of stolen credit card numbers being up for sale, the data was encrypted. While 77 million stolen credit cards makes great headlines, the other information is far more damaging since it can be used to steal peoples' identities. Not surprisingly, lawsuits are piling up, one and one now, for each the PSN and SOE breaches and Sony's handling of the aftermath.

Last week, Sony accused Anonymous of the security breach. Based on my limited knowledge of the hacker group, stealing user information for profit is out of character. Anonymous denied the accusation.

"When will PSN be back up?" is the still unanswered qustion. "We're still working to confirm the security of the network infrastructure, as well as working with a variety of outside entities to confirm with them of the security of the system," Seybold writes. "Verifying the system security is vital for the process of restoration. Additional comprehensive system checks and testing are still required, and we must complete that process before bringing the systems online. As you've heard us say, our utmost priorities are the security of the network and ensuring your data is safe. We won't restore the services until we can test the system's strength in these respects."

That's perhaps good for PSN subscribers' personal data protection in the future. There are plenty of dissatisfied PlayStation Network users in the here and now. On April 30, I started a poll asking PSN subscribers: "Will you switch to Xbox?" The results aren't so interesting as how they changed the longer the PSN outage went on. In the first few days, the results consistently hung around 54 percent switching. But the number crept up the longer PSN stayed down -- to 60 percent, then 65 percent and as of this morning 72.94 percent based on 3,285 responses.

I'm surprised that someone hasn't started a betting pool for when PSN will be back up.

May 10, 2011

What is Microsoft thinking, paying $8.5B for Skype?

It's hard to envision what Microsoft intends to do with Skype for corporate IT. So what can users expect to get out of Microsoft's $8.5 billion investment?

The people who paid $2.5 billion for Skype two years ago are starting to look very astute.

A week or two ago that wasn't the case. Skype's IPO had been delayed. Google and Facebook were sniffing around Skype, but a buyout didn't seem likely -- too many samolies for Facebook to muster, and all sorts of potential problems for Google, including an antitrust hurdle of Brobdingnagian proportions.




Best Microsoft MCTS Training – Microsoft MCITP Training at Certkingdom.com




But this morning comes the announcement that Microsoft will purchase Skype for $8.5 billion. As a defensive move, Microsoft buying Skype has some merit: a Google Voice-and-Skype combination would prove a formidable challenge to Windows Live Messenger and Lync, both in the consumer market and in the enterprise. The Skype international telephone number inventory -- and Skype's long experience with local telcos all over the world -- would provide an instant presence that Google Voice is still struggling to establish.

But $8.5 billion?

It's hard to envision what Microsoft intends to do with Skype for corporate IT. Skype is widely regarded by network admins as anathema. Five years ago, at the BlackHat conference in Europe, Philippe Biodi and Fabrice Desclaux described Skype's obfuscated code, saying it "looks like /dev/random" and it hasn't gotten any better. Like any P2P program, Skype basically runs a backdoor, with random pings and relays going out even when there's nobody using the phone. Security people love software like that.

So if the software's no good in the corporate environment, what can enterprise IT expect to get out of Microsoft's $8.5 billion investment?

Not much, as far as I can tell. Speculation that Skype will integrate into the Lync or Exchange environment seem completely far-fetched: The architectures are completely different, and the software isn't reusable. Surely, Microsoft isn't expecting to keep many key Skype developers around, even with fat paychecks. Those international phone numbers and telco connections could help extend Lync, at least in theory. Skype has a good-sized user base, with 120 million active users every month, but that's small potatoes compared to Live Messenger.

Some analysts speculate that Microsoft will meld the Kinect (currently Xbox-only, but coming soon to a Windows 8 near you) with Skype, but that doesn't make a very compelling argument. Offering a $100 Kinect as a replacement for a $2.95 webcam makes about as much sense as ... as ... as buying Skype for $8.5 billion, eh?

The only positive note for IT, as best I can tell, is possible integration of P2P VoIP technology with Windows Phone. Microsoft may be playing a long game, with a Skype client for Windows Phone 8. Presumably the client wouldn't send chillls down the spine of Exchange and Lync admins. Having Skype available for free corporate calls worldwide certainly has a nice ring to it.

But $8.5 billion?

May 9, 2011

Dirty IT jobs: Partners in slime

Dirty Job No. 2: The shadow
You probably don't want to know where your coworkers are going on the Web. But sometimes you have no choice. Nancy Hand knows this, well, firsthand.







Best Microsoft MCTS Training – Microsoft MCITP Training at Certkingdom.com




Until three years ago, Hand was a network engineer for a large public utility in the Southwest. When any of that site's 3,000 employees got a malware infection, Hand received an alert via the utility's McAfee software. She was then called in to investigate by remotely combing through the employee's browser cache, looking for the source of the attack.

[ Get a $50 American Express gift cheque if we publish your anonymous experiences from tech's front lines. Send your story of a lesson learned, of dealing with frustrating coworkers/end-users/managers, or a humorous happening to offtherecord@infoworld.com. ]

Along the way, Hand got to see where these employees had been surfing while they were allegedly working. Most of the time what she found was benign -- a lot of sites devoted to cooking, fashion, cars, and day trading. Inevitably, though, she'd encounter the darker side.

Like the employee who swore it was a spam email that caused his browser to visit that members-only bondage site, though how that email also managed to create a member profile for him was less clear. (Hand says the head of IT security jokingly awarded her the "Golden Garter Belt" for uncovering that one.)

Or the company vice president whom Hand discovered had been spending work time visiting TeenageVirginSluts.com. Naturally, he was the VP of IT.

"He was my boss's boss's boss," she says. "After I found this I contacted my manager and said, 'We have a zero-tolerance policy for this kind of thing, so I am officially notifying you of what I found.' To my knowledge nothing was ever done. About a year later that VP got fired for another sexually related infraction."

Some employees ended up being escorted from the facility by armed guards, though Hand never knew whether it was due to something she had found.

"Sometimes it was a little unsettling to be on the machine of someone I'd met in another part of my job who seemed like a very toe-the-line type of person, only to discover it wasn't true," she said. "People aren't as innocent as they seem. And the next time they complained about catching a virus, I'm thinking 'Well, you sort of did this to yourself.'"

Dirty jobs survival tip: Be prepared to go it alone.

"Management didn't seem to take any of it very seriously, even after we got hit with a denial-of-service attack that put us out of business for almost an entire day," she says. "It all becomes political, even though you think it shouldn't be. The VP is given a pass, but the secretary gets fired."
Bookmark and Share