Live data from Hacker News

Sony: All personal data stolen from PSN

blog.us.playstation.com

111–120 of 292 posts

Re: Sony: All personal data stolen from PSN

#111
post #14
post #8

FTA: we believe that an unauthorized person has obtained the following information that you provided: ...PlayStation Network/Qriocity password and login... I'm curious if this means they store everyone's password in plain-text, or if by "password" they really mean a hash of some sort.

Frankly I'm more concerned with their words about changing credit cards if you've made a purchase through PSN. This seems to be an admission that they were storing CC#'s in plain text.

It may be that the attackers pwned the servers and skimmed the numbers (including CVV) as they were HTTP POSTed in plain text.

Re: Sony: All personal data stolen from PSN

#112
post #76

Giant Bomb is reporting that passwords are supposedly secure (of course, "no way" is clearly false), so I'm guessing there's at least a decent salted hash: http://www.giantbomb.com/news/good-news-psn-back-maybe-withi...

I don't think he's reporting passwords are secure. He's just saying for people (like me) who forgot what their PSN password was have no way of figuring out.

Re: Sony: All personal data stolen from PSN

#113
post #13

Funnily enough the stock doesnt seem to have moved at all as a result of this news - http://www.google.com/finance?q=sne

The market seems to have taken this into account over the past few days: http://finance.yahoo.com/echarts?s=SNE#chart5:symbol=sne;ran...

Re: Sony: All personal data stolen from PSN

#114
post #95

We've seen several examples recently of Japanese corporate culture's secrecy and lack of candor. Toyota, TEPCO nuclear plant and now Sony same pattern of not wanting to admit to the problem. I wouldn't bet on their long term competitiveness.

I think corporate ass-covering is pretty pan-cultural. See RSA's recent "we're answering every question other than the one that everyone is asking" PR about the SecurID thing.

Re: Sony: All personal data stolen from PSN

#115

This seems like a really big argument for never allowing your data to be stored by a 3rd party. Does anyone see any reason why these companies should do anything other than store the data locally on your system, encrypted/obfuscated, and then only ever send once, via encrypted connection, and then immediately delete the info remotely? I mean, if someone breaks in to my house and steals my PS3, they already have acces…

>"This seems like a really big argument for never allowing your data to be stored by a 3rd party."

iTunes comes to mind:

http://isc.sans.edu/diary.html?storyid=9136

http://news.ycombinator.com/item?id=1488956

http://news.ycombinator.com/item?id=948757

Re: Sony: All personal data stolen from PSN

#116
post #90

Earlier quoted context omitted.

Linux installation is easy piece of cake to HN audience, but nightmare to normal people.

Sony yanked linux support from PS3s after thousands of users had already paid for it. Tally that in the "Reasons to no longer support Sony" column.

Somewhat untrue. You could still use linux, but just not in combination with continued (free) PSN access.

Re: Sony: All personal data stolen from PSN

#119

Earlier quoted context omitted.

And they used the same servers for development as for production. Isn't that non-PCI-compliant?

What is the source for the claim in your first question? I don't see this mentioned in the linked post.

I got this link from Slashdot:

http://www.reddit.com/comments/gx6o4/im_a_moderator_over_at_...

But don't hold that against me. :-)

I clicked around a bit in the linked psx-scene forums and it looked like there was a decent basis for it.

Re: Sony: All personal data stolen from PSN

#120
post #55

Thanks for waiting a week to tell me my credit card info has been stolen Sony. I am not a big fan of MSFT usually, but the next time I am buying a console I'm not buying a PS4.

The article says there is no evidence credit card information was accessed.

Not to be trite, but as they say, absence of evidence is not evidence of absence.

Especially considering the sentences immediately after the "there is no evidence..." statement, I'd be wary. I might just be jaded and they're really just trying to be forthcoming and helpful, but all that CYA-type-speak after that line makes me at least a little bit dubious that they're revealing all the details just yet.

Post reply on HN