• Welcome
    Sponsors
  • Director
    Members
    Advisory Board
    International Advisory Council
    Research Affiliates
    IPilogue Editors
    Alumni
  • IPilogue
    Events
    Publications
  • JD
    Graduate Program
    Clinical
    Prizes & Awards
  • The IPIGRAM Archive
    Events Archive
    IP in the News
    IP Poll of the Week
    IP Pick of the Week
    Gowlings IPilogue Prize
  • Legislation
    Journals
    Government
  • Contact Us
    Subscribe

Privacy Commissioner and Others Up In Arms about Sony PlayStation Network Hack

May 6, 2011 by Matt Lonsdale (IPilogue Editor)

Matt Lonsdale is a JD candidate at Dalhousie University.

On April 20th, 2011, disappointed gamers discovered they could no longer connect to the PlayStation Network. While Sony initially blamed the outage on technical problems, it was later revealed that the service had been deliberately hacked. The incident has sparked a flurry of activity among government officials, law enforcement, politicians and private citizens.

The PlayStation Network is an online service, which allows owners of Sony’s Playstation 3 game console to play multiplayer games, stream movies and purchase new content. The perpetrators had gained access to a database containing a wealth of personal information on PlayStation Network’s customers. Qriocity, a music and video streaming service owned by Sony, was also affected by the attack.

While the extent of the breach is not known, the database accessed contained the personal information of over 75 million PlayStation Network users. In an email to users dated April 27, 2011, Sony wrote, “we believe that an unauthorized person has obtained the following information that you provided: name, address (city, state/province, zip or postal code), country, email address, birthdate, PlayStation Network/Qriocity password, login, password security answers, and handle/PSN online ID”. Credit card data was encrypted and stored in a separate database. While there is no evidence that this information was accessed, Sony has not ruled out the possibility.

Sony’s customers were understandably angry about the breach. In response to this, the US-based Rothken Law Firm has filed a class action law suit in California, alleging that Sony “failed to take reasonable care to protect, encrypt, and secure the private and sensitive data of its users”. The lawsuit seeks information about the breach and Sony’s data security practices, as well as monetary compensation for affected users.

As might be expected in today’s privacy-conscious world, the breach has also received significant attention from government. The attack itself is being investigated by the FBI’s cybercrimes unit in San Diego. A US House of Representatives subcommittee, as part of a hearing entitled, “The Threat of Data Theft to American Consumers”, submitted written questions to the Chairman of the Board of Directors of Sony Computer Entertainment America. Britain’s Information Commissioner’s Office has also been in contact with Sony and is investigating whether the privacy laws of that county have been violated.

In Canada, the office of the Privacy Commissioner was not notified of the breach by Sony. Office spokeswoman Valerie Lawtwon wrote that “We are currently looking into this matter and are seeking information from Sony… [W]e will determine next steps once we have a full understanding of the incident.” The Personal Information Protection and Electronics Document Act does not place an obligation on organizations to report incidents of this kind to the Office of the Privacy Commissioner. However, Schedule 1 of that Act does contain a number of principles which organizations are expected to adhere to, including the implementation of “procedures to protect personal information”. Sony has stated that all personal information was protected by a sophisticated security system, although unlike credit card data, personal information was not encrypted. On May 4, 2011, just two weeks after the breach, Privacy Commissioner, Jennifer Stoddart, gave a speech at the Canada 3.0 conference calling for Parliament to grant the Office the ability to levy substantial fines against organizations. She expressed dismay that Sony had not notified her office of the breach, saying that “I have come to the conclusion that the only way to get some corporations to pay adequate attention to their privacy obligations is by introducing the potential for large fines that would serve as an incentive for compliance”.

Posted in Electronic Databases, Identity Theft, Internet, Privacy

2 Responses to “Privacy Commissioner and Others Up In Arms about Sony PlayStation Network Hack”

  1. Brent Randall (IPilogue Editor), on May 9, 2011 at 10:37 am Said:

    Here is the CEO of Sony, Howard Stringer’s letter to PlayStation Network customers about the situation:

    http://blog.us.playstation.com/2011/05/05/a-letter-from-howard-stringer/

    I know that anybody can be hacked on the Internet, even a giant like Sony, but it doesn’t seem like the real issue has been addressed: their customers were putting their personal information at risk all along. Maybe that’s something PSN users are consenting to by using the service (recall this previous post here on IPOsgoode: http://www.iposgoode.ca/2011/04/i-agree-internet-research-informed-consent/).

    Sony can offer free services to make up for what has happened, but that is only addressing the inconvenience of having the service shut down for this period of time. It will be interesting to see if the privacy concerns of their customers remain at the forefront, or fade away over time. Convincing consumers that Sony’s service is secure is not something that can be done as easily.

  2. Taylor Vanderhelm (IPilogue Editor), on May 12, 2011 at 4:49 pm Said:

    Although there is a lot of speculation regarding the identity of the hackers and their motives (Sony blames Anonymous but Anonymous denies it), I think this could signify a tipping point for how large corporations handle their customers’ private data.

    Until recently, customers in general have been fairly lax and uninterested in the way their personal data has been utilized by corporations. It is hard to blame them. After all, it is not immediately obvious the harm that can be done (outside of credit card numbers) if basic personal and account behaviour information falls into the wrong hands. Additionally, it is likely that most people assume sophisticated corporations will properly encrypt and protect sensitive data.

    While it is not entirely clear, there is chatlog evidence (from an IRC channel for PS3 owners trying to hack or modify the devices for purposes not approved by Sony) which suggests that much of Sony’s security measures were subpar and outdated. If this turns out to be true, it would give consumers further reason to demand companies implement greater security measures.

    Furthermore, it has also been suggested that stolen data is not the only danger. Given more time, it is possible the hackers could have potentially taken control of millions of PS3 systems, resulting in a network as powerful as many nations’ supercomputers. The potential damage of this type of attack was demonstrated on a smaller scale by researchers in 2008 with 200 PS3 machines.

    Given the significant amount of media attention and number of people affected, it will be interesting to observe the impact on consumers’ and businesses’ interest in protecting personal data.

Leave a Reply

All replies and responses are moderated and will not appear on the site immediately. Please see our response policy.

« Canada Responds to “Emergencies” with Updated Drug Regulations | Collective IP Rights of Indigenous Peoples: The 18th Session of the IGC at WIPO »

Career Opportunities
Osgoode IP Club
Writing Competitions
IP Research Guide

Follow @IPilogue

RSS Follow Comments via RSS
  • Denise Brunsdon on The Living Daylights (…Scents, Tastes, and Sounds): Bill C-56 Forebodes Drastic Trade-mark Reform
  • Denise Brunsdon on Must Every Canadian Patent Application Include the Inventor’s Best Mode of Working the Invention?
  • Matt on Mario Bouchard: Copyright Quintet opus 1. no.1, by McLachlin et al
  • Danny Titolo on The ‘Myriad’ with the Golden ‘Gene’: Australia Upholds Breast Cancer Gene Patents
  • Tracy Ayodele on Exceptions which Circumvent Logic
  • Nancy Situ on Military Tactics and Rock Star Patent Lawyers; the Patent System under Stress
  • Laura on The Rise and Fall [and Rise Again?] of BlackBerry
  • Howard Knopf on How Music Can Help You, And You Can Help Music – An Interview With Graham Henderson
  • Paul Atkinson on Bill C-56 Remedies: Rights Holders Can All Feel a Little Safer
  • Bart Cormier on The Living Daylights (…Scents, Tastes, and Sounds): Bill C-56 Forebodes Drastic Trade-mark Reform
RSS Follow Posts via RSS
  • New Step for the Modernization of Copyright Law in the US – Progress or Regress?
  • Reminder: Canada’s IP Writing Challenge 2013
  • Property in Brands
  • Strike Three, Viacom
  • New Book – The Copyright Pentalogy: How the Supreme Court of Canada Shook the Foundations of Canadian Copyright Law
  • The Curious Case of Fake Beijing Olympics Merchandise
  • About the Boundaries of Fairness in Fair Use
  • Who Inherits Your Likes?
  • Game of Thones – Piracy is Coming
  • AEREO, Cable, What’s The Difference?
  • May 2013
  • April 2013
  • March 2013
  • February 2013
  • January 2013
  • December 2012
  • 2013
  • 2012
  • 2011
  • 2010
  • 2009
  • 2008
  • 2007
  • Advisory Board (9)
  • Announcements (31)
  • Blogs (24)
  • Book Review (5)
  • Broadcasting Regulatory Policy (8)
  • Cloud Services (11)
  • Commercialization (90)
  • Competition (19)
  • Competition Law (14)
  • Contracts (69)
  • copyright reform (158)
  • defamation (19)
  • Design (15)
  • Development (6)
  • European Union (54)
  • events (88)
  • Fashion Industry (22)
  • Feature Post (206)
  • Freedom of Speech (22)
  • Freedom of the Press (17)
  • Gaming (9)
  • General (151)
  • Human Rights (10)
  • Image (6)
  • Innovation (156)
  • Internet (274)
  • IP (1242)
    • Copyright (617)
      • CD Levy (10)
      • Digital Downloads (78)
      • Digital Libraries (7)
      • Digital Locks (34)
      • Fair Dealing (79)
        • Parody (2)
        • Satire (1)
      • Infringement (157)
      • Internet Sharing (96)
      • Literary Works (65)
      • Moral Rights (15)
      • Movies (53)
      • Music Industry (104)
      • Originality (33)
      • Ownership (107)
        • Licensees (39)
      • Secondary (ISP) Liability (18)
      • Subsidiary Rights (5)
    • IP Reform (37)
    • Patents (381)
      • Access to Medicines (21)
      • Cross Border Issues (50)
      • Electronic Processes (20)
      • Infringement (72)
      • Patent Practice (27)
      • Patent Trolls (21)
      • Patentability (109)
      • Pharmaceutical Drugs (75)
    • Trademarks (243)
      • Domain Names (44)
      • Famous Marks (20)
      • Official Marks (11)
      • Parallel Importation (4)
      • Personality Rights (12)
  • IP Course Topic (13)
  • IP Intensive (26)
  • IP Litigation Practice (17)
  • Jurisdiction (176)
    • Canada (80)
    • Indonesia (1)
    • Japan (2)
    • UK (41)
    • US (74)
  • Law & Music Course Topic (21)
  • Links (3)
  • MediaLaws (17)
  • Music Industry (85)
  • Open-Source (18)
  • Osgoode Alumnus (14)
  • Patents Course Topic (28)
  • Privacy (188)
    • Electronic Databases (42)
    • Human Rights Issues (31)
    • Identity Theft (14)
  • Regulatory Policy (64)
  • Reputation Management (4)
  • Smartphones (14)
  • Social Justice (4)
    • United Nations Development Programme (2)
  • Social Media (30)
  • Supreme Court of Canada (34)
  • Tech Transfer (31)
  • Technology (245)
  • Telecommunications (89)
  • Trade Secrets (9)
  • UK (19)
  • Uncategorized (102)
  • US-Canada Relations (4)
  • WIPO (16)
  • Log in

Home   |   Contact Us   |   Feedback  |   Privacy   

© 2008 Osgoode Hall Law School York University
4700 Keele Street Toronto, Canada M3J 1P3
T:416.736.5030   F:416.736.5736