Feeds

After hack nightmare, Sony bars lawsuits with new TOS

Class actions verboten

SANS - Survey on application security programs

After getting the pants sued off it for security breaches that exposed personal information connected to more than 100 million online accounts, Sony is requiring subscribers to waive their right to wage class-action lawsuits for almost any reason.

Sony dropped the bombshell in an updated terms of service and user agreement (PDF) on one of its websites. It requires people with accounts on Sony's PlayStation Network or other online services to seek binding arbitration with an arbitrator of the company's choosing instead of exercising their right to have a judge or jury hear their case. Legal claims can only be filed if the dispute isn't resolved through arbitration in a timely manner.

The terms go on to state:

ANY DISPUTE RESOLUTION PROCEEDINGS, WHETHER IN ARBITRATION OR COURT, WILL BE CONDUCTED ONLY ON AN INDIVIDUAL BASIS AND NOT IN A CLASS OR REPRESENTATIVE ACTION OR AS A NAMED OR UNNAMED MEMBER IN A CLASS, CONSOLIDATED, REPRESENTATIVE OR PRIVATE ATTORNEY GENERAL LEGALACTION, UNLESS BOTH YOU AND THE SONY ENTITY WITH WHICH YOU HAVE A DISPUTE SPECIFICALLY AGREE TO DO SO IN WRITING FOLLOWING INITIATION OF THE ARBITRATION.

Sony subscribers will be required to agree to the terms the next time they sign into their accounts - effective Thursday - if they want to continue using the online services.

The changes come five months after an attack on the PlayStation Network exposed names, addresses, email addresses, passwords, and other sensitive data for 77 million accounts. Sony shuttered the service for 40 days while it cleaned up the mess. In the weeks following, attacks were found to hit Sony Online Entertainment, the company's computer games service, and the Sony Pictures website, exposing personal information for 25 million more accounts.

In July Sony's insurance company filed a lawsuit that argued its policy didn't apply to a raft of class-action lawsuits filed in response to the high-profile security breaches.

The terms of service give subscribers the ability of opt out of the class action require, but it will require them to do something many probably haven't done in years, if ever – write a letter on paper and send it to an address using the postal service.

The instructions:

YOUR WRITTEN NOTIFICATION MUST BE MAILED TO 6080 CENTER DRIVE, 10TH FLOOR, LOS ANGELES, CA 90045, ATTN: LEGAL DEPARTMENT/ARBITRATION AND MUST INCLUDE: (1) YOUR NAME, (2) YOUR ADDRESS, (3) YOUR PSN ACCOUNT NUMBER, IF YOU HAVE ONE, AND (4) A CLEAR STATEMENT THAT YOU DO NOT WISH TO RESOLVE DISPUTES WITH ANY SONY ENTITY THROUGH ARBITRATION.

Anyone got a stamp? ®

High performance access to file storage

More from The Register

next story
Obama allows NSA to exploit 0-days: report
If the spooks say they need it, they get it
Putin tells Snowden: Russia conducts no US-style mass surveillance
Gov't is too broke for that, Russian prez says
Snowden-inspired crypto-email service Lavaboom launches
German service pays tribute to Lavabit
Mounties always get their man: Heartbleed 'hacker', 19, CUFFED
Canadian teen accused of raiding tax computers using OpenSSL bug
Heartbleed exploit, inoculation, both released
File under 'this is going to hurt you more than it hurts me'
Arts and crafts store Michaels says 3 million credit cards exposed in breach
Meanwhile, Target investigators prepare for long process in nabbing hackers
Canadian taxman says hundreds pierced by Heartbleed SSL skewer
900 social insurance numbers nicked, says revenue watchman
prev story

Whitepapers

SANS - Survey on application security programs
In this whitepaper learn about the state of application security programs and practices of 488 surveyed respondents, and discover how mature and effective these programs are.
Combat fraud and increase customer satisfaction
Based on their experience using HP ArcSight Enterprise Security Manager for IT security operations, Finansbank moved to HP ArcSight ESM for fraud management.
The benefits of software based PBX
Why you should break free from your proprietary PBX and how to leverage your existing server hardware.
Top three mobile application threats
Learn about three of the top mobile application security threats facing businesses today and recommendations on how to mitigate the risk.
3 Big data security analytics techniques
Applying these Big Data security analytics techniques can help you make your business safer by detecting attacks early, before significant damage is done.