Live data from Hacker News

Sony: All personal data stolen from PSN

blog.us.playstation.com

71–80 of 292 posts

Re: Sony: All personal data stolen from PSN

#72
post #48
post #14

Earlier quoted context omitted.

Frankly I'm more concerned with their words about changing credit cards if you've made a purchase through PSN. This seems to be an admission that they were storing CC#'s in plain text.

How do you use stored credit card info if the cc# is not stored? Unlike passwords, the encryption for the cc#s has to be reversible. That's part of the reason why they introduced CVCs, right?

You could at least have them encrypted on disk with a key only stored in memory, i.e.: when the system is turned on. Alternatively a dedicated crypo device where you feed it cipher text and it gives you plain text would also help as the attack wouldn't be able to get the key (even if they have the physical box (for good crypto devices))

While only marginally better depending on the type of attack and permissions gained by the attacker, if all they got was static data on disk, then it would be secure.

Re: Sony: All personal data stolen from PSN

#73
post #25

I haven't really been following this but there have been rumblings all week that a hacked firmware was released that allowed anyone who installed it, and twiddled with some other things, access to the PSN development and testing network. Anyone know more?

There was a reddit thread on this that explains the gist of it: http://news.ycombinator.com/item?id=2482679.

Re: Sony: All personal data stolen from PSN

#74
post #55

Thanks for waiting a week to tell me my credit card info has been stolen Sony. I am not a big fan of MSFT usually, but the next time I am buying a console I'm not buying a PS4.

The article says there is no evidence credit card information was accessed.

And it also says "we cannot rule out the possibility."

Re: Sony: All personal data stolen from PSN

#75
post #51
post #47

Wow this sounds really really bad. As much as I dislike sony's actions in the Geohot case, and as much as "this is what you get for failing at security", I feel pretty bad for them right now (and even worse for all of their customers) >To protect against possible identity theft or other financial loss, we encourage you to remain vigilant, to review your account statements and to monitor your credit reports. >We have…

I fail to see why Sony should be pitied, unless the details of the attack are laid out, and Sony shows that it was following good security practice. I see neither disclosure happening any time soon.

It's probably too much of my mother and not enough of my father, but I can't stand watching people fail, no matter how much I hate them.

I hate sony, but I still feel bad for them.

Re: Sony: All personal data stolen from PSN

#77
post #65
post #14

Earlier quoted context omitted.

Frankly I'm more concerned with their words about changing credit cards if you've made a purchase through PSN. This seems to be an admission that they were storing CC#'s in plain text.

Because Sony would need to send your unencrypted CC# to your CC company when you make a purchase is it even possible to not store it in plain text?

It could be encrypted, but maybe the attackers got the key/salt as well.

Re: Sony: All personal data stolen from PSN

#78
post #55

Thanks for waiting a week to tell me my credit card info has been stolen Sony. I am not a big fan of MSFT usually, but the next time I am buying a console I'm not buying a PS4.

The article says there is no evidence credit card information was accessed.

I absolutely do not trust them at this point. Why would I?

Re: Sony: All personal data stolen from PSN

#79
post #14
post #8

FTA: we believe that an unauthorized person has obtained the following information that you provided: ...PlayStation Network/Qriocity password and login... I'm curious if this means they store everyone's password in plain-text, or if by "password" they really mean a hash of some sort.

Frankly I'm more concerned with their words about changing credit cards if you've made a purchase through PSN. This seems to be an admission that they were storing CC#'s in plain text.

Having access to a few of my passwords online has effects that range from my current to future employment, relationships with friends, partners, s.o's, future employers, all of my bank accounts, etc.

And I have better password practices than most. Credit cards might be an immediate thought, but how many other physical and intangible assets does your password give a hacker access to?

Re: Sony: All personal data stolen from PSN

#80
post #49

I'm disappointed but not surprised. When I had to change my password a few months ago on the Sony developer's network site I was told that my new password was too similar to the last ones. I was wondering how they knew that, aside from storing the passwords in plain-text, something I'd assume they'd be too smart to do. I guess I gave them too much credit.

Genuine Question: They let you change your password without having you supply the old one?

Password reset link?
Post reply on HN