Live data from Hacker News

Sony: All personal data stolen from PSN

blog.us.playstation.com

151–160 of 292 posts

Re: Sony: All personal data stolen from PSN

#151
post #6

Payback for GeoHot or what? Haven't heard anything about the source of the attack since the DDoS that Anonymous took credit for...

I think given the severity and potential criminal lawsuits for this nobody will step out right away, however I'm pretty sure the geohot story pissed off some good hackers who found something to do in their spare time...

Re: Sony: All personal data stolen from PSN

#152
Frankly I'm in shock. That a company as large and experienced as Sony would allow this to happen, well it beggars belief. The contempt shown to customers, not just by Sony but by other large tech companies (I'm looking at you Apple) is disgusting.

I choose not to be part of Facebook because I'd rather they didn't know every detail of my life. Now I have to consider if I want to use products from Sony because of concerns that they can't even protect my private data, which they force me to give them in order to use their services.

Unbafuckinglievable.

Re: Sony: All personal data stolen from PSN

#154

This is a much much bigger deal than the Gawker security breach. Sony had substantially more information on its users than Gawker could ever hope to dream of. Specifically information on real names, addresses, and potentially credit cards. This is a big F'N deal and I wouldn't be surprised if it cost Sony more than Microsoft's infamous 1 billion dollar write-down with the Xbox 360's Red Ring of Death. I don't think t…

"I wouldn't be surprised if it cost Sony more than Microsoft's infamous 1 billion dollar write-down with the Xbox 360's Red Ring of Death." Banks, colleges, hospitals, and credit card processors do this all the time, and it doesn't cost them anywhere near a billion dollars despite the fact that they have vastly more personal information. Sure they usually only have a few hundred thousand records and not a few million…

Numbers I've heard floated for leaks on the smaller scale are around $15-20 per person for post-leak mitigation and damages, which could push near $1b if the same per-person cost held with this size leak (which it might not). When my university had some data stolen, their lawyers advised them to buy everyone a year of some identity-theft insurance/monitoring package, which I believe cost them around $10 per person just for that.

Re: Sony: All personal data stolen from PSN

#156
http://psx-scene.com/forums/f177/sony-has-been-bad-boy-ridic...

"A well known hacker i don’t want to reveal here had all the Sony PlayStation Network functions 100% decrypted as well as providing some nice info about how Sony dealing with PSN members privacy in their online servers.

Apparently, Sony server gathered everything they can from the PSN connected PS3 console. When i said everything, i meant it. Here, i make all the list of what they squeezed from the IRC chat logs conversation between the hackers.

Sony monitors all messages over PSN. All connected devices return values sent to Sony server returns TV, Firmware version, Firmware type, Console model They also collects data in your USB attached device. Credit card sent as plain text, example: creditCard.paymentMethodId=VISA&creditCard.holderN ame=Max&creditCard.cardNumber=4558254723658741&cre ditCard.expireYear=2012&creditCard.expireMonth=2&c reditCard.securityCode=214&creditCard.address.addr ess1=example street%2024%20&creditCard.address.city=city1%20&cr editCard.address.province=abc%20&creditCard.addres s.postalCode=12345%20 *The best part of all, the list is stored online and updated when u login PSN and random.

But, that’s not all, with the PSN functions fully decrypted, this hacker can use the function to get all games, DLC, you name it, from PSN store without paying anything."

Re: Sony: All personal data stolen from PSN

#157
post #138

Earlier quoted context omitted.

It may be that the attackers pwned the servers and skimmed the numbers (including CVV) as they were HTTP POSTed in plain text.

That wouldn't work over SSL, as there is no plain text in the HTTP Verb. And I recall a "paper" coming up some months ago that was mentioning the protocols the PS3 goes through, which does confirm that the data is transmitted over SSL.[0] [0] http://arstechnica.com/gaming/news/2011/02/report-psn-hacked...

The SSL gets decrypted inside the web server process memory, at the latest. Sometimes it's stripped off by an SSL offload accelerator device before even entering the web server.

The numbers probably also cross the wire in plain text between the web server and the database too.

Re: Sony: All personal data stolen from PSN

#158

Earlier quoted context omitted.

It may be that the attackers pwned the servers and skimmed the numbers (including CVV) as they were HTTP POSTed in plain text.

"as they were HTTP POSTed in plain text." Why on earth would you ever do that?

See my other response above http://news.ycombinator.com/item?id=2487412

Re: Sony: All personal data stolen from PSN

#159

This seems like a really big argument for never allowing your data to be stored by a 3rd party. Does anyone see any reason why these companies should do anything other than store the data locally on your system, encrypted/obfuscated, and then only ever send once, via encrypted connection, and then immediately delete the info remotely? I mean, if someone breaks in to my house and steals my PS3, they already have acces…

Much of ecommerce would go down the drain, if they got rid of remote storage of your details. No recurring billing, no "One-Click", no address books, etc...

Re: Sony: All personal data stolen from PSN

#160
post #84
post #55

Earlier quoted context omitted.

The article says there is no evidence credit card information was accessed.

When credit cards are involved you really need to prepare for the worst case scenario.

Thankfully that's what's great about credit cards (and let's not forget that) - you just ask the bank to deactivate the old one and no more transactions can go through. Also, you should in general not be liable for any fraudulent use of the number. Just dispute it. (my contract said I could be held liable for up to $50 of fraudulent use only in the case where the CARD was stolen and used prior to my reporting it.)
Post reply on HN