Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

Sony begins full restoration of its PSN and Qriocity services (update: intermittent issues)

0 comments
Can it be happening? Is Sony's security nightmare finally over? Seems to be. On Tuesday, Sony promised full restoration of its PlayStation Network and Qriocity services in the Americas, Europe, and Asia (excluding Japan, Hong Kong, and South Korea) by the end of the week. Now Sony is proclaiming that today is the day for full restoration with details of its "welcome back" package to be announced from each region. The PlayStation Store is already up with a "huge lineup" of new games, demos, add-ons, themes, avatars, and videos along with an updated Playstation Plus. Hey, look on the bright side Sony, even though you've lost the confidence of millions of your customers, at least now they're aware of your Qriocity service. Full press release after the break.

Update: Working fine for us from London. We signed in to the PlayStation Store and even fired up Black Ops multiplayer just for kicks.

Update 2: We're now seeing error "80710D36" occasionally when trying to access the PlayStation Store, presumably due to congestion. We're seeing this from both London and New York.

Sony says PlayStation Network will return to Asia, starting tomorrow

0 comments
Good news, Asia -- the PlayStation Network is finally coming back. Today, Sony announced that it will restore its gaming network across the continent, more than a month after falling prey to a crippling data breach. The company's PSN services are already up and running across other parts of the world and, beginning tomorrow, will light up once again in Taiwan, Singapore, Malaysia, Indonesia, Thailand and even Japan, which had been harboring serious reservations about the network's security. Gamers in South Korea and Hong Kong, meanwhile, will have to wait a little longer before returning to normalcy, though Sony is hoping to completely resolve the issue by the end of the month. The company certainly seems eager to put this saga to bed, and for understandable reasons. The incident has already cost Sony an estimated $171 million in revenue -- not to mention the untold numbers of suddenly wary consumers.
sourceBloomberg

New CyanogenMod lets you rule Android app permissions with an iron fist

0 comments

We've recently seen Google crack down on rogue apps and patch some server-side security issues, but let's not forget Android does have a small measure of built-in security: app permissions. But as with those pesky EULAs, many users tend to breeze through the permissions screen. And Android forces even the most attentive readers to accept or deny all permissions requested by an app. But the newest nightly builds of the CyanogenMod custom ROM include a clever patch allowing users to grant and revoke permissions individually -- something like the TISSA security manager we're still awaiting. Obviously playing God with permissions can crash your applications: with great power comes great responsibility. But we figure if you're running aftermarket firmware on a rooted phone, you're comfortable experimenting. See how it works in the video after the break, then hit the source link to download.

Androinica
sourceCyanogenMod

Sony BMG Greece hacked, company's security woes continue

0 comments
SonyBMG.gr Hacked
It's the security nightmare that just won't end, and right now there's got to be plenty of Sony executives beginning to wish someone would pinch them already. After taking quite a PR and financial beating over the PSN breach, now the Greek site of Sony BMG has been hacked and the account info of thousands of users has been posted online. According to the Sophos blog Naked Security, the attack does not appear to have been particularly sophisticated and was carried out using an automated SQL injection tool that demands more patience than skill. While the data dump reveals the usernames, real names, and email addresses of registered SonyMusic.gr customers, other fields (including passwords and telephone numbers) are either empty or contain fake data -- suggesting the hack was not entirely successful. Here's hoping Sony takes this as an opportunity to seriously baton down those security hatches.
sourceNaked Security

Sony estimates $3.2b loss this year, $171 million cost for PSN breach

0 comments
Sony estimates $3.2b loss this year, $171 million cost for PSN breach
It has not been a good year for Sony, which was affected both by the massive earthquake in March and the PSN outage that spanned from April into May. There couldn't be any doubt that those things would have a drastic impact on the company's bottom-line, and it's now taking the time to give investors an idea of just how big an impact that could be -- even though the financial issues lie largely elsewhere. Sony is set to announce its full financial report for its fiscal year this Thursday and, to soften the blow, estimates have been revised steeply downward. Previously Sony predicted a ¥70 billion ($855 million) profit, but now thinks a ¥260 billion ($3.14 billion) loss is rather more accurate -- a ¥360 billion non-cash charge taking the wind out of ¥200 billion in operating income.

The earthquake was directly blamed for a loss of ¥22 billion, but that figure could certainly grow as this estimate is only through the end of March. Additionally, Sony has provided a early guess of a ¥14 billion (about $172 million) total cost for the PSN breach. That's less than two bucks per exposed account, but again we wouldn't be surprised if it's a figure that increases through the year. You know, once the lawyers start having their fun.
The Wall Street Journal, gamesindustry.biz
sourceSony [PDF]

Key pattern analysis software times your typing for improved password protection

0 comments

The recent pilfering of PlayStation Network passwords and personal info shows that having a strong passcode doesn't always guarantee your online safety. However, key-pattern analysis (KPA) software from researchers at American University of Beirut may be able to keep our logins secure even if they're stolen. You create a unique profile by entering your password a few times while the code tracks the speed and timing of your keystrokes. The software then associates that data to your password as another means of authentication. Henceforth, should the magic word be entered in a different typing tempo, access is denied. We saw a similar solution last year, but that system was meant to prevent multiple users from accessing subscription databases with a single account. This KPA software allows multiple profiles per password so that your significant other can still read all your email -- assuming you and your mate reside in the trust tree, of course.

Adobe dominates Kaspersky Lab's top ten PC vulnerabilites list

0 comments

Being number one is usually an honor, but not when it comes to Kaspersky Lab's top ten PC vulnerabilities list. Unfortunately for the software giant, Adobe took top dishonors for Q1 this year, pulling in five total spots on the list, including the top three. According to the security firm, all of the vulnerabilities appearing on the list allowed cyber-criminals to control computers at the system level. The number one spot was occupied by a vulnerability in Acrobat Reader that was reportedly detected on 40 percent of machines running the application, while Flash Player flaws took second and third. Other dishonorees included the Java Virtual Machine, coming in at fourth and fifth place, Apple QuickTime, Winamp, and Microsoft Office. That ain't bad, considering Microsoft ruled the vulnerabilities roost in 2010.

Google: Android Security Fix Addresses ClientLogin Data Leak

0 comments
Google's Android team is releasing a platform fix that patches a troubling security breach leaving users' personal information at the mercy of hackers.
"This fix requires no action from users and will roll out globally over the next few days," Google told All Things D in a statement on Wednesday.
Recent research conducted at Germany's University of Ulm found that up to 99% of Android handsets may be leaking users' login information when apps connect to Google's servers via unencrypted WiFi networks. The exploit potentially gives third parties access to users' calendar, contact, photo apps and more.
Most devices vulnerable to this kind of attack are those running Android version 2.3.3 and earlier.
If you're an Android user who hasn't updated (or can't update) to 2.3.4, don't connect your device to unsecured WiFi networks until you've received Google's forthcoming security patch.

SOURCE:  The Huffington Post