Live data from Hacker News

Sony: All personal data stolen from PSN

blog.us.playstation.com

121–130 of 292 posts

Re: Sony: All personal data stolen from PSN

#122

These malicious actions have also had an impact on your ability to enjoy... Interesting. Is it not fair to also say the negligent actions that made these malicious ones possible had an impact? I'm completely sick of the way these press releases sound.

Reminds me of 9/11 and no one in government taking any responsibility. Except Richard Clarke.

Re: Sony: All personal data stolen from PSN

#123

This is unreal. What bothers me the most, is that when this happened to me one time before, that particular company paid for a year of credit monitoring services. In this case, Sony is too cheap to do even that, pointing you towards where you could download your credit report online. Ridiculous.

I believe they are obligated to by US law.

Re: Sony: All personal data stolen from PSN

#124

Earlier quoted context omitted.

This is a good time to purchase a password-vault app - AND USE IT!

Have you ever entered one of those passwords with a playstation controller?

It doesn't have to use all those funny characters. But the vault at least allows you to use a different password for each site. Which, in this case, might be pretty important.

Re: Sony: All personal data stolen from PSN

#125
For many folk who may not use PSN much or recently, the first concern I imagine would be to recall whether they ever provided Sony with the most sensitive things on that list.

A quick gmail search tells me that they had my mailing address and full name, but I have no idea if I ever gave them my CC or DOB or SSN or Gitmo prisoner bar code or whatever else.

I'm glad I use lastpass because I have a nice list of sites to update password info, but I imagine this process is going to take quite a while. Too bad I repeated that password so many times.

Re: Sony: All personal data stolen from PSN

#126

There were sixty million[0] PSN accounts. This is impressive, and amounts to (judging by a quick search) the largest-scale ID (and possibly credit-card) theft ever [Not so, see child comment]. Not even factoring in credit card details, the usernames, emails, addresses, ages, passwords, mother's maiden names, favourite pets, of sixty million people is worth a hell of a lot. I have to wonder how much data that is, in t…

fwiw the Heartland incident involved 130,000,000 records:

http://datalossdb.org/

Not to lessen the extent of this, but it's not nearly the biggest dataloss incident ever.

Re: Sony: All personal data stolen from PSN

#127
post #81
post #55

Earlier quoted context omitted.

The article says there is no evidence credit card information was accessed.

It also says it might have been, which is much more worrying to me than the lack of evidence; because before this sony had no evidence that their network was compromised. This whole thing seems like a great example of incompetence.

It doesn't mean they either know, or don't know. It means their PR isn't willing to fully disclose the exact nature because if they confirm customer data was nicked, class actions will start off rather promptly, and if they say it certainly wasn't, they're seen as over-reacting.

Re: Sony: All personal data stolen from PSN

#128

I can't even begin to fathom the magnitude of this considering how many people likely use the same login credentials for all of their sites. The problem you run into is that communicating both the nature of the breach and convincing people to respond accordingly is incredibly hard. This will continue to happen across many sites. I think after enough of these breaches, though, people will start to think about the prot…

This is a good time to purchase a password-vault app - AND USE IT!

Okay, I see KeePass and Password Gorilla recommended here in the other replies. I use KeePass actually, and I've seen PGorilla. But I'd like something that is integrated with the iPhone - and works with Linux and Windows too.

There's an app called Strip that looks pretty good. I'm listening to other suggestions.

Re: Sony: All personal data stolen from PSN

#129
post #11

I wonder how many times a company can install trojans on your computer, destroy your OS's security, secretly watch all your actions, then proceed to not properly protect your data when you voluntarily give it to them...before going out of business. Sony's size and momentum must be pretty crazy. Or maybe it's our society. I just can't imagine a small record store in the 1960s, after being caught spying through the bed…

Outstanding use of sarcasm to make fun of the "EBS outage means we should all go back to building our own datacenters" overreaction.

/applauds

Re: Sony: All personal data stolen from PSN

#130
post #26

What the hell Sony? I just tried logging into http://us.playstation.com/psn/playstation-home/ the SSL connection to https://store.playstation.com gave Error code: sec_error_unknown_issuer. It's like you're actively trying to make me never trust you again.

Looks OK in my Firefox, says it's signed by Comodo UTN-USERFirst-Hardware. I am not making this up.

Isn't Comodo the CA that was compromised recently?
Post reply on HN