Live data from Hacker News

Sony: All personal data stolen from PSN

blog.us.playstation.com

11–20 of 292 posts

Re: Sony: All personal data stolen from PSN

#11
I wonder how many times a company can install trojans on your computer, destroy your OS's security, secretly watch all your actions, then proceed to not properly protect your data when you voluntarily give it to them...before going out of business.

Sony's size and momentum must be pretty crazy. Or maybe it's our society. I just can't imagine a small record store in the 1960s, after being caught spying through the bedroom windows of its customers, ever staying in business.

I feel terrible for anyone caught in this. But maybe, just maybe, Sony isn't the company to do business with anymore?

Re: Sony: All personal data stolen from PSN

#14
post #8

FTA: we believe that an unauthorized person has obtained the following information that you provided: ...PlayStation Network/Qriocity password and login... I'm curious if this means they store everyone's password in plain-text, or if by "password" they really mean a hash of some sort.

Frankly I'm more concerned with their words about changing credit cards if you've made a purchase through PSN. This seems to be an admission that they were storing CC#'s in plain text.

Re: Sony: All personal data stolen from PSN

#15
post #5

This is a much much bigger deal than the Gawker security breach. Sony had substantially more information on its users than Gawker could ever hope to dream of. Specifically information on real names, addresses, and potentially credit cards. This is a big F'N deal and I wouldn't be surprised if it cost Sony more than Microsoft's infamous 1 billion dollar write-down with the Xbox 360's Red Ring of Death. I don't think t…

You can diss your competitor for poor security practices only if you have some confidence in your own.

[deleted]

Re: Sony: All personal data stolen from PSN

#16
post #6

Payback for GeoHot or what? Haven't heard anything about the source of the attack since the DDoS that Anonymous took credit for...

Anon actually didn't do the DDoS attack. From the press release-"For once we didn't do it" http://anonnews.org/?p=press&a=item&i=848

I thought Anonymous apologized to PSN users for the collateral damage? Makes me wonder if they're just trying to save face after realizing the users were turning against them too...

"We realize that targeting the PSN is not a good idea. We have therefore temporarily suspended our action, until a method is found that will not severely impact Sony customers." -- Anonymous

Then they went on to say something about how Anonymous is a diverse group and they can't control everyone, blah blah blah.

Re: Sony: All personal data stolen from PSN

#17
post #4

So it is as bad as we feared. The only silver lining I can see is that Sony made the difficult business decision to turn off the network until they were sure it was secure. While that doesn't make me feel better as a PSN user I do respect their honesty and commitment to fixing it. Time to get a new identity! =)

I doubt turning off the PSN was a "difficult business decision". More like their lawyers said "KILL IT NOW" and pointed out the ramifications of not actively preventing such wholesale personal information theft.

There will already be a lawsuit of some sort. Imagine how bad it would be for them if they hadn't shut it down.

Re: Sony: All personal data stolen from PSN

#18
How could they have gained access to passwords? Do they mean, rather, gained access to your secure password hash, or did they simply store passwords in an unencrypted format? Being a member of PSN, this has me concerned. I'm making it a point to change all of my security questions and passwords all throughout all websites I use.

Re: Sony: All personal data stolen from PSN

#19
There were sixty million[0] PSN accounts. This is impressive, and amounts to (judging by a quick search) the largest-scale ID (and possibly credit-card) theft ever [Not so, see child comment]. Not even factoring in credit card details, the usernames, emails, addresses, ages, passwords, mother's maiden names, favourite pets, of sixty million people is worth a hell of a lot.

I have to wonder how much data that is, in terms of storage. How could you even take that without someone noticing?

Hats off to whoever it was. Now, I'm off to change my passwords. Thank Christ I had the sense not to use a credit card to buy from PSN.

[0] http://www.derangedshaman.com/2011/01/06/sonys-60-million-ps...

[edit] On a related note, paypal refuses to let my change my password to something longer than 20 characters - or have spaces in my password. Why is this the case? Surely the only thing that an upper limit on the length of a password does is help the attacker.

Re: Sony: All personal data stolen from PSN

#20
post #13

Funnily enough the stock doesnt seem to have moved at all as a result of this news - http://www.google.com/finance?q=sne

They're down about 10% relative to the rest of the market since the PSN outage, and pretty significantly in after hours trading (stock market closed about 25 minutes ago, news broke a few minutes ago).
Post reply on HN