Sony: All personal data stolen from PSN
71–80 of 292 posts
Re: Sony: All personal data stolen from PSN
#72Earlier quoted context omitted.
Frankly I'm more concerned with their words about changing credit cards if you've made a purchase through PSN. This seems to be an admission that they were storing CC#'s in plain text.
How do you use stored credit card info if the cc# is not stored? Unlike passwords, the encryption for the cc#s has to be reversible. That's part of the reason why they introduced CVCs, right?
While only marginally better depending on the type of attack and permissions gained by the attacker, if all they got was static data on disk, then it would be secure.
Re: Sony: All personal data stolen from PSN
#73I haven't really been following this but there have been rumblings all week that a hacked firmware was released that allowed anyone who installed it, and twiddled with some other things, access to the PSN development and testing network. Anyone know more?
Re: Sony: All personal data stolen from PSN
#74Thanks for waiting a week to tell me my credit card info has been stolen Sony. I am not a big fan of MSFT usually, but the next time I am buying a console I'm not buying a PS4.
The article says there is no evidence credit card information was accessed.
Re: Sony: All personal data stolen from PSN
#75Wow this sounds really really bad. As much as I dislike sony's actions in the Geohot case, and as much as "this is what you get for failing at security", I feel pretty bad for them right now (and even worse for all of their customers) >To protect against possible identity theft or other financial loss, we encourage you to remain vigilant, to review your account statements and to monitor your credit reports. >We have…
I fail to see why Sony should be pitied, unless the details of the attack are laid out, and Sony shows that it was following good security practice. I see neither disclosure happening any time soon.
I hate sony, but I still feel bad for them.
Re: Sony: All personal data stolen from PSN
#76Re: Sony: All personal data stolen from PSN
#77Earlier quoted context omitted.
Frankly I'm more concerned with their words about changing credit cards if you've made a purchase through PSN. This seems to be an admission that they were storing CC#'s in plain text.
Because Sony would need to send your unencrypted CC# to your CC company when you make a purchase is it even possible to not store it in plain text?
Re: Sony: All personal data stolen from PSN
#78Thanks for waiting a week to tell me my credit card info has been stolen Sony. I am not a big fan of MSFT usually, but the next time I am buying a console I'm not buying a PS4.
The article says there is no evidence credit card information was accessed.
Re: Sony: All personal data stolen from PSN
#79FTA: we believe that an unauthorized person has obtained the following information that you provided: ...PlayStation Network/Qriocity password and login... I'm curious if this means they store everyone's password in plain-text, or if by "password" they really mean a hash of some sort.
Frankly I'm more concerned with their words about changing credit cards if you've made a purchase through PSN. This seems to be an admission that they were storing CC#'s in plain text.
And I have better password practices than most. Credit cards might be an immediate thought, but how many other physical and intangible assets does your password give a hacker access to?
Re: Sony: All personal data stolen from PSN
#80I'm disappointed but not surprised. When I had to change my password a few months ago on the Sony developer's network site I was told that my new password was too similar to the last ones. I was wondering how they knew that, aside from storing the passwords in plain-text, something I'd assume they'd be too smart to do. I guess I gave them too much credit.
Genuine Question: They let you change your password without having you supply the old one?