by SPADEZ Thu Apr 28, 2011 5:45 pm
Sonys recent update FAQ on the PSN outage on their blog has a few problems & contradictions in their answers that I would like to point out. These 2 Q & As here and I highlighted the areas that seem to contradict from one answer to another.
Q: Was my personal data encrypted?
A: All of the data was protected, and access was restricted both physically and through the perimeter and security of the network. The entire credit card table was encrypted and we have no evidence that credit card data was taken. The personal data table, which is a separate data set, was not encrypted, but was, of course, behind a very sophisticated security system that was breached in a malicious attack.
So Sony claims that "ALL" of the data was "protected" and access was "restricted". They then go on to say "Credit card table was encrypted"..."we have NO EVIDENCE that credit card data was taken." Yet they say the personal data table was not encrypted and was breached by a malicious attack? Last time I checked, our credit card information IS part of our personal data. Notice the contradiction? Was our data protected or wasn't it?
Q: Was my credit card data taken?
A: While all credit card information stored in our systems is encrypted and there is no evidence at this time that credit card data was taken, we cannot rule out the possibility. If you have provided your credit card data through PlayStation Network or Qriocity, out of an abundance of caution we are advising you that your credit card number (excluding security code) and expiration date may have been obtained. Keep in mind, however that your credit card security code (sometimes called a CVC or CSC number) has not been obtained because we never requested it from anyone who has joined the PlayStation Network or Qriocity, and is therefore not stored anywhere in our system.
No evidence at this time? Or no evidence you wish to share at this time? Sony seems unsure about if our data was protected or not. Also, correct me if I'm wrong as I cannot log into PSN to confirm this, but I do recall users requiring to input their credit card security code into the PSN bank account information settings, otherwise they would not be able to continue due to lack of information required. Doesn't this mean that the hack could have obtained our security codes as well?