Live data from Hacker News

Sony: All personal data stolen from PSN

blog.us.playstation.com

81–90 of 292 posts

Re: Sony: All personal data stolen from PSN

#81
post #55

Thanks for waiting a week to tell me my credit card info has been stolen Sony. I am not a big fan of MSFT usually, but the next time I am buying a console I'm not buying a PS4.

The article says there is no evidence credit card information was accessed.

It also says it might have been, which is much more worrying to me than the lack of evidence; because before this sony had no evidence that their network was compromised.

This whole thing seems like a great example of incompetence.

Re: Sony: All personal data stolen from PSN

#82

This is a much much bigger deal than the Gawker security breach. Sony had substantially more information on its users than Gawker could ever hope to dream of. Specifically information on real names, addresses, and potentially credit cards. This is a big F'N deal and I wouldn't be surprised if it cost Sony more than Microsoft's infamous 1 billion dollar write-down with the Xbox 360's Red Ring of Death. I don't think t…

Microsoft had millions of pieces of defective hardware out there which they were warranting free replacement on for several years. Unless Sony's going to replace all the PS3's in the wild, the direct costs for dealing with this PR nightmare shouldn't come close to what Microsoft set aside.

if pki alone is at the core of their infrastructure problems, and the key is in the chip, this may well be what they have to do. however i don't know that this is entirely because their public key infrastructure.

Re: Sony: All personal data stolen from PSN

#83

How could they have gained access to passwords? Do they mean, rather, gained access to your secure password hash, or did they simply store passwords in an unencrypted format? Being a member of PSN, this has me concerned. I'm making it a point to change all of my security questions and passwords all throughout all websites I use.

Not as easy as it sounds. You wouldn't believe the reaction I got from Mom when I asked her to change her maiden name.

Re: Sony: All personal data stolen from PSN

#84
post #55

Thanks for waiting a week to tell me my credit card info has been stolen Sony. I am not a big fan of MSFT usually, but the next time I am buying a console I'm not buying a PS4.

The article says there is no evidence credit card information was accessed.

When credit cards are involved you really need to prepare for the worst case scenario.

Re: Sony: All personal data stolen from PSN

#88

This is a much much bigger deal than the Gawker security breach. Sony had substantially more information on its users than Gawker could ever hope to dream of. Specifically information on real names, addresses, and potentially credit cards. This is a big F'N deal and I wouldn't be surprised if it cost Sony more than Microsoft's infamous 1 billion dollar write-down with the Xbox 360's Red Ring of Death. I don't think t…

"I wouldn't be surprised if it cost Sony more than Microsoft's infamous 1 billion dollar write-down with the Xbox 360's Red Ring of Death." Banks, colleges, hospitals, and credit card processors do this all the time, and it doesn't cost them anywhere near a billion dollars despite the fact that they have vastly more personal information. Sure they usually only have a few hundred thousand records and not a few million…

I would argue the cost of the RRoD was a heck of a lot more than $1B because of all the lost sales. People didn't want to invest in hardware that was going to break 5 times over.

The direct damage from this won't be $1B (still tens of millions at least). But what about the impact of the lost sales and customers from the loss in credibility and trust? That is what could be huge.

It was relatively "easy" for Microsoft to replace broken hardware. How easy and how much is it going to cost Sony to replace broken trust?

Re: Sony: All personal data stolen from PSN

#89

I can't even begin to fathom the magnitude of this considering how many people likely use the same login credentials for all of their sites. The problem you run into is that communicating both the nature of the breach and convincing people to respond accordingly is incredibly hard. This will continue to happen across many sites. I think after enough of these breaches, though, people will start to think about the prot…

This is a good time to purchase a password-vault app - AND USE IT!

No need to purchase. Just put the "Password Gorilla"[1] binaries for Windows, Linux and Mac on your Dropbox be done with it.

[1] https://github.com/zdia/gorilla/wiki/

Post reply on HN