Live data from Hacker News

Sony: All personal data stolen from PSN

blog.us.playstation.com

31–40 of 292 posts

Re: Sony: All personal data stolen from PSN

#32
post #4

So it is as bad as we feared. The only silver lining I can see is that Sony made the difficult business decision to turn off the network until they were sure it was secure. While that doesn't make me feel better as a PSN user I do respect their honesty and commitment to fixing it. Time to get a new identity! =)

Time to get a new identity! =) That's what I was thinking: in most cases of user accounts being compromised, the solution is "change your passwords on this and other sites". Here you need to change your birthday, cancel your credit card, move out, change your name… kind of a hassle.

no problem!

http://www.fakenamegenerator.com/

Re: Sony: All personal data stolen from PSN

#33
post #4

So it is as bad as we feared. The only silver lining I can see is that Sony made the difficult business decision to turn off the network until they were sure it was secure. While that doesn't make me feel better as a PSN user I do respect their honesty and commitment to fixing it. Time to get a new identity! =)

Time to get a new identity! =) That's what I was thinking: in most cases of user accounts being compromised, the solution is "change your passwords on this and other sites". Here you need to change your birthday, cancel your credit card, move out, change your name… kind of a hassle.

>Here you need to change your birthday

And, you know, your mom probably won't be too happy when you pop out of your time machine, a week before your birth, and tell her she needs to induce labor.

Re: Sony: All personal data stolen from PSN

#34

This is a much much bigger deal than the Gawker security breach. Sony had substantially more information on its users than Gawker could ever hope to dream of. Specifically information on real names, addresses, and potentially credit cards. This is a big F'N deal and I wouldn't be surprised if it cost Sony more than Microsoft's infamous 1 billion dollar write-down with the Xbox 360's Red Ring of Death. I don't think t…

"I wouldn't be surprised if it cost Sony more than Microsoft's infamous 1 billion dollar write-down with the Xbox 360's Red Ring of Death."

Banks, colleges, hospitals, and credit card processors do this all the time, and it doesn't cost them anywhere near a billion dollars despite the fact that they have vastly more personal information. Sure they usually only have a few hundred thousand records and not a few million, but even still the idea that this is going to cost them a billion dollars is absurd.

Re: Sony: All personal data stolen from PSN

#35

If someone has had their data stolen, are there any steps that they can take to ensure that they are not fleeced or does this mean that it's only a matter of time (or perhaps luck)?

Change your credit card number and password; everything else is information that is already known.

Re: Sony: All personal data stolen from PSN

#36
post #11

I wonder how many times a company can install trojans on your computer, destroy your OS's security, secretly watch all your actions, then proceed to not properly protect your data when you voluntarily give it to them...before going out of business. Sony's size and momentum must be pretty crazy. Or maybe it's our society. I just can't imagine a small record store in the 1960s, after being caught spying through the bed…

People want to play God of War, Little Big Planet and Gran Turismo. I think Sony could do just about anything and stay in business. As sad as that is, it's probably true.

Re: Sony: All personal data stolen from PSN

#37
post #5

This is a much much bigger deal than the Gawker security breach. Sony had substantially more information on its users than Gawker could ever hope to dream of. Specifically information on real names, addresses, and potentially credit cards. This is a big F'N deal and I wouldn't be surprised if it cost Sony more than Microsoft's infamous 1 billion dollar write-down with the Xbox 360's Red Ring of Death. I don't think t…

You can diss your competitor for poor security practices only if you have some confidence in your own.

>You can diss your competitor for poor security practices only if you have some confidence in your own.

Nope, companies usually don't leave any chance to point to the competition's faults and laugh, even if they themselves are worse in that regard.

Re: Sony: All personal data stolen from PSN

#38
post #11

I wonder how many times a company can install trojans on your computer, destroy your OS's security, secretly watch all your actions, then proceed to not properly protect your data when you voluntarily give it to them...before going out of business. Sony's size and momentum must be pretty crazy. Or maybe it's our society. I just can't imagine a small record store in the 1960s, after being caught spying through the bed…

Momentum and hydra-esque qualities. Sony manufactures parts for a lot of tech companies, who would suffer if Sony ceased to exist. So it's in their best interest to keep them alive, especially in the short-term as it would be crippling to have to change suppliers suddenly.

Re: Sony: All personal data stolen from PSN

#39
I'm disappointed but not surprised. When I had to change my password a few months ago on the Sony developer's network site I was told that my new password was too similar to the last ones. I was wondering how they knew that, aside from storing the passwords in plain-text, something I'd assume they'd be too smart to do.

I guess I gave them too much credit.

Re: Sony: All personal data stolen from PSN

#40
post #8

FTA: we believe that an unauthorized person has obtained the following information that you provided: ...PlayStation Network/Qriocity password and login... I'm curious if this means they store everyone's password in plain-text, or if by "password" they really mean a hash of some sort.

This would be such an incredibly stupid security failure.

Passwords should always be salted and hashed.

Credit card info should always be HSM-protected so that it is irretrievable except through a hardware API.

What was Sony thinking!?

Post reply on HN