Live data from Hacker News

Sony: All personal data stolen from PSN

blog.us.playstation.com

61–70 of 292 posts

Re: Sony: All personal data stolen from PSN

#61
post #14
post #8

FTA: we believe that an unauthorized person has obtained the following information that you provided: ...PlayStation Network/Qriocity password and login... I'm curious if this means they store everyone's password in plain-text, or if by "password" they really mean a hash of some sort.

Frankly I'm more concerned with their words about changing credit cards if you've made a purchase through PSN. This seems to be an admission that they were storing CC#'s in plain text.

I don't know much about online credit card transactions, but how are you supposed to do it? Don't you need the number to transfer to Visa or whoever in order to get money out of someone's account?

Re: Sony: All personal data stolen from PSN

#62

I can't even begin to fathom the magnitude of this considering how many people likely use the same login credentials for all of their sites. The problem you run into is that communicating both the nature of the breach and convincing people to respond accordingly is incredibly hard. This will continue to happen across many sites. I think after enough of these breaches, though, people will start to think about the prot…

This is a good time to purchase a password-vault app - AND USE IT!

Re: Sony: All personal data stolen from PSN

#63
post #26

What the hell Sony? I just tried logging into http://us.playstation.com/psn/playstation-home/ the SSL connection to https://store.playstation.com gave Error code: sec_error_unknown_issuer. It's like you're actively trying to make me never trust you again.

Looks OK in my Firefox, says it's signed by Comodo UTN-USERFirst-Hardware.

I am not making this up.

Re: Sony: All personal data stolen from PSN

#64

This is a much much bigger deal than the Gawker security breach. Sony had substantially more information on its users than Gawker could ever hope to dream of. Specifically information on real names, addresses, and potentially credit cards. This is a big F'N deal and I wouldn't be surprised if it cost Sony more than Microsoft's infamous 1 billion dollar write-down with the Xbox 360's Red Ring of Death. I don't think t…

Microsoft had millions of pieces of defective hardware out there which they were warranting free replacement on for several years. Unless Sony's going to replace all the PS3's in the wild, the direct costs for dealing with this PR nightmare shouldn't come close to what Microsoft set aside.

Re: Sony: All personal data stolen from PSN

#65
post #14
post #8

FTA: we believe that an unauthorized person has obtained the following information that you provided: ...PlayStation Network/Qriocity password and login... I'm curious if this means they store everyone's password in plain-text, or if by "password" they really mean a hash of some sort.

Frankly I'm more concerned with their words about changing credit cards if you've made a purchase through PSN. This seems to be an admission that they were storing CC#'s in plain text.

Because Sony would need to send your unencrypted CC# to your CC company when you make a purchase is it even possible to not store it in plain text?

Re: Sony: All personal data stolen from PSN

#66
post #8

FTA: we believe that an unauthorized person has obtained the following information that you provided: ...PlayStation Network/Qriocity password and login... I'm curious if this means they store everyone's password in plain-text, or if by "password" they really mean a hash of some sort.

Even if the passwords were stored in a hashed format, people might have sent their credentials to a compromised system.

Re: Sony: All personal data stolen from PSN

#67
post #5

This is a much much bigger deal than the Gawker security breach. Sony had substantially more information on its users than Gawker could ever hope to dream of. Specifically information on real names, addresses, and potentially credit cards. This is a big F'N deal and I wouldn't be surprised if it cost Sony more than Microsoft's infamous 1 billion dollar write-down with the Xbox 360's Red Ring of Death. I don't think t…

You can diss your competitor for poor security practices only if you have some confidence in your own.

All big companies claim total confidence in their own security... right up to the moment they're proved wrong. (and sometimes beyond)

Re: Sony: All personal data stolen from PSN

#68
post #25

I haven't really been following this but there have been rumblings all week that a hacked firmware was released that allowed anyone who installed it, and twiddled with some other things, access to the PSN development and testing network. Anyone know more?

you might be looking for rebug: http://rebug.me/

Re: Sony: All personal data stolen from PSN

#69
post #25

I haven't really been following this but there have been rumblings all week that a hacked firmware was released that allowed anyone who installed it, and twiddled with some other things, access to the PSN development and testing network. Anyone know more?

I personally don't know any more, but this might be a good starting point if you're interested: http://news.ycombinator.com/item?id=2482679 is a link to a post on reddit from a moderator of a forum that deals in ps3 modding. He outlines the situation, and his forum probably has some more information.

Re: Sony: All personal data stolen from PSN

#70
post #14
post #8

FTA: we believe that an unauthorized person has obtained the following information that you provided: ...PlayStation Network/Qriocity password and login... I'm curious if this means they store everyone's password in plain-text, or if by "password" they really mean a hash of some sort.

Frankly I'm more concerned with their words about changing credit cards if you've made a purchase through PSN. This seems to be an admission that they were storing CC#'s in plain text.

PCI requires that CC#'s are stored encrypted in the database. A service this big has had a full PCI compliance overview, and they wouldn't miss a basic requirement like that (I hope).
Post reply on HN