Live data from Hacker News

Sony: All personal data stolen from PSN

blog.us.playstation.com

131–140 of 292 posts

Re: Sony: All personal data stolen from PSN

#131

Earlier quoted context omitted.

And it also says "we cannot rule out the possibility."

Sounds like lawyer-speak for "yeah, they got it".

To me it sounds like lawyer-speak for "We don't think they do but we're covering our arses"

Re: Sony: All personal data stolen from PSN

#132

Earlier quoted context omitted.

Sony yanked linux support from PS3s after thousands of users had already paid for it. Tally that in the "Reasons to no longer support Sony" column.

Somewhat untrue. You could still use linux, but just not in combination with continued (free) PSN access.

That was the theory anyway. Now we don't have PSN access either.

We kept the family PS3 patched-up in good faith. Is there now a reasonable way for me to install Linux?

Seriously, the kids are probably moving to Xbox and I have some supercomputing I'd like to do.

Re: Sony: All personal data stolen from PSN

#133

Wait, "Password" was stolen? WTF they store unencrypted passwords?!?!?!!?! I sure hope they meant password hashes otherwise upset many people should be.

Even if hashes are stolen, you should consider the original password stolen as well, because it's only a matter of time and effort to brute force the original password from the hash. Even if you use a really good password with a really good hash (like bcrypt), it still doesn't mean that they can't find the password, just that it will take more time to do so.

Re: Sony: All personal data stolen from PSN

#134
post #11

I wonder how many times a company can install trojans on your computer, destroy your OS's security, secretly watch all your actions, then proceed to not properly protect your data when you voluntarily give it to them...before going out of business. Sony's size and momentum must be pretty crazy. Or maybe it's our society. I just can't imagine a small record store in the 1960s, after being caught spying through the bed…

> I just can't imagine a small record store in the 1960s, after being caught spying through the bedroom windows of its customers, ever staying in business.

Sony isn't a small record store.

Re: Sony: All personal data stolen from PSN

#135

Earlier quoted context omitted.

This is a good time to purchase a password-vault app - AND USE IT!

Keepass is great, easy, and free.

<3 <3 <3 keepass. It has clients for Linux, Windows and OS X, not to mention many smartphones (stick to the 1.x version for this.) This, along with dropbox makes for an awesome way to keep track of passwords securely.

Re: Sony: All personal data stolen from PSN

#136

This is unreal. What bothers me the most, is that when this happened to me one time before, that particular company paid for a year of credit monitoring services. In this case, Sony is too cheap to do even that, pointing you towards where you could download your credit report online. Ridiculous.

Lifelock is a scam that you are better off without anyway, but yeah, they definitely should provide some compensation. Unlikely though. They would rather sue people that want to run linux.

Re: Sony: All personal data stolen from PSN

#137
This is case-in-point for centralized log-archival-and-analysis tools like SenSage. No matter how secure you make your infrastructure, in situations like this you want evidence of all activity on your networks, computers, DB's, app servers, apps, etc. Storing log data related to this activity can consume petabytes over a multi-year span.

I don't know what kind of forensic tools Sony's using, hopefully they have something like SenSage.

Re: Sony: All personal data stolen from PSN

#138
post #14

Earlier quoted context omitted.

Frankly I'm more concerned with their words about changing credit cards if you've made a purchase through PSN. This seems to be an admission that they were storing CC#'s in plain text.

It may be that the attackers pwned the servers and skimmed the numbers (including CVV) as they were HTTP POSTed in plain text.

That wouldn't work over SSL, as there is no plain text in the HTTP Verb. And I recall a "paper" coming up some months ago that was mentioning the protocols the PS3 goes through, which does confirm that the data is transmitted over SSL.[0]

[0] http://arstechnica.com/gaming/news/2011/02/report-psn-hacked...

Re: Sony: All personal data stolen from PSN

#139

Earlier quoted context omitted.

This is a good time to purchase a password-vault app - AND USE IT!

Okay, I see KeePass and Password Gorilla recommended here in the other replies. I use KeePass actually, and I've seen PGorilla. But I'd like something that is integrated with the iPhone - and works with Linux and Windows too. There's an app called Strip that looks pretty good. I'm listening to other suggestions.

I've used LastPass since the Gawker breach. It works with iOS and automatically syncs password databases across all browsers and mobile devices. I've been very happy with it thus far.

Re: Sony: All personal data stolen from PSN

#140

Earlier quoted context omitted.

Looks OK in my Firefox, says it's signed by Comodo UTN-USERFirst-Hardware. I am not making this up.

Isn't Comodo the CA that was compromised recently?

Yep, through the usertrust sub-CA even.

https://blog.torproject.org/blog/detecting-certificate-autho...

Post reply on HN