Re: PSN Downtime Discussion
In regards to the above video, it is understandable that people would feel angry that their information was lost. That said, you cannot become angry with the CSIRT (Computer Security Incident Response Team) and outside investigators because it took them more than a day to fully analyze a crime scene and evidence to determine what happened, as noted in the blog posted by TerryMasters above. Given the scope of the breach, Sony is actually being quite forthcoming about this, considering what it will do to their reputation and business.
PSN is worldwide, so this affects all subscribers regardless of geographical location. I do not know how PCI compliant (a standard used to toughen IT systems that store, process, or transmit cardholder data) Sony is, but one of the requirements is that CC data must be held several years. If you have had any credit card used on PSN within the last several years, this likely affects you.
What this comes down to now is whether the data was encrypted strongly at rest in the database. An earlier Sony blog mentioned possibly compromised administrator developer accounts. What this means is even if the data were encrypted with the best algorithms in the world, a person with admin privileges (or a stolen admin account, in this case) could have been used to decrypt that data.
So, that said, I'd be keeping a close eye on statements personally. Look for small transactions, not large ones, that is how these organized crime syndicates typically keep under the radar while nickel and diming people out of money so they won't notice.