Live data from Hacker News

Sony: All personal data stolen from PSN

blog.us.playstation.com

231–240 of 292 posts

Re: Sony: All personal data stolen from PSN

#231
post #11

I wonder how many times a company can install trojans on your computer, destroy your OS's security, secretly watch all your actions, then proceed to not properly protect your data when you voluntarily give it to them...before going out of business. Sony's size and momentum must be pretty crazy. Or maybe it's our society. I just can't imagine a small record store in the 1960s, after being caught spying through the bed…

This is one of the reasons its a shame you need to buy a console to play exclusive titles. I was going to buy a ps3, but am hesitant now. A security breach like this is really unacceptable from anyone, under any circumstance. I'll need to be careful about disclosing any of my data if I do get a ps3.

Re: Sony: All personal data stolen from PSN

#232

Earlier quoted context omitted.

"I wouldn't be surprised if it cost Sony more than Microsoft's infamous 1 billion dollar write-down with the Xbox 360's Red Ring of Death." Banks, colleges, hospitals, and credit card processors do this all the time, and it doesn't cost them anywhere near a billion dollars despite the fact that they have vastly more personal information. Sure they usually only have a few hundred thousand records and not a few million…

Numbers I've heard floated for leaks on the smaller scale are around $15-20 per person for post-leak mitigation and damages, which could push near $1b if the same per-person cost held with this size leak (which it might not). When my university had some data stolen, their lawyers advised them to buy everyone a year of some identity-theft insurance/monitoring package, which I believe cost them around $10 per person ju…

Things are cheaper in bulk right?

Re: Sony: All personal data stolen from PSN

#234
post #233
post #13

Funnily enough the stock doesnt seem to have moved at all as a result of this news - http://www.google.com/finance?q=sne

Funny, Jim Cramer's thestreet.com upgraded it from hold to buy on the 25th. http://www.thestreet.com/story/11093134/1/sony-corporation-s...

I suspect Sony's stock is getting hammered tomorrow, and the lack official email to PSN users,makes me think it's gonna be more bad news.

Re: Sony: All personal data stolen from PSN

#235
This appears to also have affected Sony in Japan, as well.

It is interesting how this announcement differs from the Japanese announcement[0]. Japanese people are so paranoid about their identity that this cannot go well for Sony in Japan.

It does not seem like Sony is preparing people for any sort of identity theft in Japan other than calling the card companies. They apologized and remarked at how they are gearing-up to better protect their users when the service reopens.

[0] http://cdn.jp.playstation.com/msg/sp_20110427_psn.html

Re: Sony: All personal data stolen from PSN

#236
post #205

There were sixty million[0] PSN accounts. This is impressive, and amounts to (judging by a quick search) the largest-scale ID (and possibly credit-card) theft ever [Not so, see child comment]. Not even factoring in credit card details, the usernames, emails, addresses, ages, passwords, mother's maiden names, favourite pets, of sixty million people is worth a hell of a lot. I have to wonder how much data that is, in t…

Overestimating 100k per user, it would only be 6 terabytes. And all those low-entropy passwords etc should compress quite well.

They would only compress well if you stored them in plaintext...

Re: Sony: All personal data stolen from PSN

#237
post #223

http://psx-scene.com/forums/f177/sony-has-been-bad-boy-ridic... "A well known hacker i don’t want to reveal here had all the Sony PlayStation Network functions 100% decrypted as well as providing some nice info about how Sony dealing with PSN members privacy in their online servers. Apparently, Sony server gathered everything they can from the PSN connected PS3 console. When i said everything, i meant it. Here, i mak…

> Credit card sent as plain text This was debunked. It's encrypted on the wire.

What's your source on that?

Re: Sony: All personal data stolen from PSN

#239

Notice how they never apologize? The closest thing to apology, but it's not an apology, is: > "We thank you for your patience as we complete our investigation of this incident, and we regret any inconvenience." Sony apologizes only to Chuck Norris.

The Japanese announcement is full of apology:

"2011年4月21日よりPlayStation®NetworkおよびQriocity™の障害が継続しており、お客様および関係各位に多大なるご迷惑をおかけしておりますことを深くお詫び申しあげます。"

Which is a polite and flowery way of apologizing for the ongoing interruption of service.

http://cdn.jp.playstation.com/msg/sp_20110427_psn.html

Re: Sony: All personal data stolen from PSN

#240
post #203

I'm disappointed but not surprised. When I had to change my password a few months ago on the Sony developer's network site I was told that my new password was too similar to the last ones. I was wondering how they knew that, aside from storing the passwords in plain-text, something I'd assume they'd be too smart to do. I guess I gave them too much credit.

Well, they could try permuting your new password in a few different ways and seeing if any of those permutations match the old hash.

That's not practical. Password hashes should be slow, to stop dictionary attacks; and it's easy to imagine a couple thousand "similar" passwords (flip case of some characters? 256 possibilities for an 8-character password. Add year of birth? 20-50 possibilities. And so on.)
Post reply on HN