Live data from Hacker News

Sony: All personal data stolen from PSN

blog.us.playstation.com

201–210 of 292 posts

Re: Sony: All personal data stolen from PSN

#201

This seems like a really big argument for never allowing your data to be stored by a 3rd party. Does anyone see any reason why these companies should do anything other than store the data locally on your system, encrypted/obfuscated, and then only ever send once, via encrypted connection, and then immediately delete the info remotely? I mean, if someone breaks in to my house and steals my PS3, they already have acces…

Much of ecommerce would go down the drain, if they got rid of remote storage of your details. No recurring billing, no "One-Click", no address books, etc...

It should at least be an option for me not to store it, if I prefer not to use "one-click" and similar features. I understand why stores prefer to save the information without giving me a choice (reduces friction for future purchases), but I'm not sure that's a good enough reason given the prevailing security track records.

Either that, or perhaps there could be statutory penalties for data breaches. For example, if there was mandatory compensation of, say, $100/person for a data breach, companies might be incentivized to better think about whether they really need to store this data, and whether they're storing it safely.

Re: Sony: All personal data stolen from PSN

#202
post #48
post #14

Earlier quoted context omitted.

Frankly I'm more concerned with their words about changing credit cards if you've made a purchase through PSN. This seems to be an admission that they were storing CC#'s in plain text.

How do you use stored credit card info if the cc# is not stored? Unlike passwords, the encryption for the cc#s has to be reversible. That's part of the reason why they introduced CVCs, right?

> How do you use stored credit card info if the cc# is not stored?

Simplifying just a bit -- The one time you pass the # along to the bank, they give you back a transaction ID you can use to do future things with that card. The bank knows the number, looks it up by that ID.

Re: Sony: All personal data stolen from PSN

#203

I'm disappointed but not surprised. When I had to change my password a few months ago on the Sony developer's network site I was told that my new password was too similar to the last ones. I was wondering how they knew that, aside from storing the passwords in plain-text, something I'd assume they'd be too smart to do. I guess I gave them too much credit.

Well, they could try permuting your new password in a few different ways and seeing if any of those permutations match the old hash.

Re: Sony: All personal data stolen from PSN

#204

This seems like a really big argument for never allowing your data to be stored by a 3rd party. Does anyone see any reason why these companies should do anything other than store the data locally on your system, encrypted/obfuscated, and then only ever send once, via encrypted connection, and then immediately delete the info remotely? I mean, if someone breaks in to my house and steals my PS3, they already have acces…

Much of ecommerce would go down the drain, if they got rid of remote storage of your details. No recurring billing, no "One-Click", no address books, etc...

I can imagine a couple of good one-click solutions involving public keys.

Re: Sony: All personal data stolen from PSN

#205

There were sixty million[0] PSN accounts. This is impressive, and amounts to (judging by a quick search) the largest-scale ID (and possibly credit-card) theft ever [Not so, see child comment]. Not even factoring in credit card details, the usernames, emails, addresses, ages, passwords, mother's maiden names, favourite pets, of sixty million people is worth a hell of a lot. I have to wonder how much data that is, in t…

Overestimating 100k per user, it would only be 6 terabytes. And all those low-entropy passwords etc should compress quite well.

Re: Sony: All personal data stolen from PSN

#206
post #149

Earlier quoted context omitted.

I've been seeing the notion of accounting for the loss of sales due to "reputation" come up on HN recently and I wish to dispute it. First, most of the time when we're talking about business and we talk about costs we're clearly talking about accounting costs. This applies to startups, too. When you're talking about accounting costs, you don't get to include economic costs (e.g., opportunity cost.) Second, isn't tryi…

"Goodwill" is the difference between the book value of a company (value of tangible assets) and what it can be sold for. A manufacturer with tooling, machines and inventory might not have much, but a software company's book value is near zero. People are asked to put value on intangibles all the time. You might want to write them all down to zero, but the rest of us value Wordsworth more than the dead trees his words…

No. Goodwill is the difference between the price paid to acquire a company and the book value of the acquired company. To put goodwill on the books, you must buy a company.

Re: Sony: All personal data stolen from PSN

#207

Earlier quoted context omitted.

Much of ecommerce would go down the drain, if they got rid of remote storage of your details. No recurring billing, no "One-Click", no address books, etc...

It should at least be an option for me not to store it, if I prefer not to use "one-click" and similar features. I understand why stores prefer to save the information without giving me a choice (reduces friction for future purchases), but I'm not sure that's a good enough reason given the prevailing security track records. Either that, or perhaps there could be statutory penalties for data breaches. For example, if…

Online retailers who handle their own CC processing tend to keep credit card information around if only for fraud/chargeback tracking in the future - being online opens you up to massive abuse if you don't keep it in check.

A big player like sony should have been complying with PCI standards - but from what I've seen, that's not so difficult to pass and then forget about - people take shortcuts - and how many companies out there have ever had their processing revoked for NOT complying with PCI? That would be an interesting statistic.

Re: Sony: All personal data stolen from PSN

#208

How could they have gained access to passwords? Do they mean, rather, gained access to your secure password hash, or did they simply store passwords in an unencrypted format? Being a member of PSN, this has me concerned. I'm making it a point to change all of my security questions and passwords all throughout all websites I use.

Not as easy as it sounds. You wouldn't believe the reaction I got from Mom when I asked her to change her maiden name.

Makes me wonder how many people just punch in "Maiden".

Of course those security questions are nearly useless anyway.

Re: Sony: All personal data stolen from PSN

#209
post #11

I wonder how many times a company can install trojans on your computer, destroy your OS's security, secretly watch all your actions, then proceed to not properly protect your data when you voluntarily give it to them...before going out of business. Sony's size and momentum must be pretty crazy. Or maybe it's our society. I just can't imagine a small record store in the 1960s, after being caught spying through the bed…

Don't read this as a defense of the company, but there hasn't really been a single, monolithic Sony for decades. Sony Music Entertainment, perpetrators of 2005's rootkit debacle, is pretty far removed from Sony Computer Entertainment, the division responsible for Playstation. Sony Electronics, makers of TVs, home theater systems, and Walkmans, is another silo, as is Sony Pictures. Of course, every act of incompetence…

every act of incompetence under the Sony name tarnishes that name, and in the marketplace, that's ultimately all that matters

As it should. When these companies merge, buy other companies out, or execute reverse takeovers, there's always talk of "brand synergies" and all of the business advantages of having one set of products associated with another. There's absolutely no reason why that particular sword shouldn't have two edges to it.

Re: Sony: All personal data stolen from PSN

#210

Thanks for waiting a week to tell me my credit card info has been stolen Sony. I am not a big fan of MSFT usually, but the next time I am buying a console I'm not buying a PS4.

Do what you will, I'm not going to defend Sony exactly but you'd be stunned to know how much this kind of thing happens and goes unreported. Stunned. Sony deserves a pile of credit for manning up and saying what they've said. Unfortunately they're also admitting that they have no idea how bad it really is. A remarkable number of companies wouldn't disclose this much. A remarkable number of them will interpret and spi…

It took them a week to release a non-statement, which they only issued after Congresspeople started complaining about why the service was down for so long. This is not a victory for transparency.
Post reply on HN