Live data from Hacker News

Sony: All personal data stolen from PSN

blog.us.playstation.com

251–260 of 292 posts

Re: Sony: All personal data stolen from PSN

#251

There were sixty million[0] PSN accounts. This is impressive, and amounts to (judging by a quick search) the largest-scale ID (and possibly credit-card) theft ever [Not so, see child comment]. Not even factoring in credit card details, the usernames, emails, addresses, ages, passwords, mother's maiden names, favourite pets, of sixty million people is worth a hell of a lot. I have to wonder how much data that is, in t…

20 characters is quite generous. 123-reg (semi-popular domain reseller) insists on eight. Not seven. Not nine. Eight exactly.

Re: Sony: All personal data stolen from PSN

#252

Earlier quoted context omitted.

Somewhat untrue. You could still use linux, but just not in combination with continued (free) PSN access.

That was the theory anyway. Now we don't have PSN access either. We kept the family PS3 patched-up in good faith. Is there now a reasonable way for me to install Linux? Seriously, the kids are probably moving to Xbox and I have some supercomputing I'd like to do.

I'd like to know this too... I assume that now the keys have been discovered, PS3 should be fully retaskable?

Re: Sony: All personal data stolen from PSN

#253

Earlier quoted context omitted.

every act of incompetence under the Sony name tarnishes that name, and in the marketplace, that's ultimately all that matters As it should. When these companies merge, buy other companies out, or execute reverse takeovers, there's always talk of "brand synergies" and all of the business advantages of having one set of products associated with another. There's absolutely no reason why that particular sword shouldn't h…

This is precisely my view. I haven't knowingly given Sony any of my money since Lik-Sang.

What a great store.

Re: Sony: All personal data stolen from PSN

#254

This seems like a really big argument for never allowing your data to be stored by a 3rd party. Does anyone see any reason why these companies should do anything other than store the data locally on your system, encrypted/obfuscated, and then only ever send once, via encrypted connection, and then immediately delete the info remotely? I mean, if someone breaks in to my house and steals my PS3, they already have acces…

While I think I agree with you, but rule #1 when doing client-server development is: Never, ever, trust the client. And, ironically, something which I think Sony forgot here. :)

The entire security model for consoles has always relied on trusting the client. It has never worked, and yet they keep doing it time and time again. It doesn't surprise me a bit that they did their network the same exact way.

Re: Sony: All personal data stolen from PSN

#255
While it's a big deal, let's be reasonable with our expectations of privacy.

I know my street addresses, home and work, my e-mail addresses, significant URLs, credit cards, expired credit cards, buying habits, posts, messages, family relationships (mother, wife, ex-wife, kids, ex-girlfriends) etc are stored in a lot (probably more than a hundred) places. I have no expectation all that data will be kept secret for any length of time. I seriously doubt much of that data could be kept form a dedicated googler with lots of free time, much less from a determined criminal who wanted that data.

Re: Sony: All personal data stolen from PSN

#256
post #3

Holy Cow! This has to be one of the most serious breaches I remember in recent times. While I dont work in security and my security foo is weak it appears that they did not have a strong layered security apparatus in place? Is it just a coincidence that this breach and geohotz exploit happened around the same time?

It really looks like the PSN architecture assumed that the clients were trustworthy. If so, that's an epic Security 101 fail.

That would explain why they were so nervous about PS3 jailbreaking.

Re: Sony: All personal data stolen from PSN

#257
post #173

Earlier quoted context omitted.

Salted hashes are better than unsalted hashes.

Against a GPU that can calculate five million hashes per second your salt isn't worth the paper it's printed on.

So we should just store the password in plain text then!! Or we could use the honor system, with no password!!

Re: Sony: All personal data stolen from PSN

#258

Earlier quoted context omitted.

The Japanese announcement is full of apology: "2011年4月21日よりPlayStation®NetworkおよびQriocity™の障害が継続しており、お客様および関係各位に多大なるご迷惑をおかけしておりますことを深くお詫び申しあげます。" Which is a polite and flowery way of apologizing for the ongoing interruption of service. http://cdn.jp.playstation.com/msg/sp_20110427_psn.html

True, they are different probably because this (the Japanese announcement) is from Sony Corporation, and the link in English is probably from Sony Corporation of America.

In Japan lawsuits are less common, and an apology is expected even if it's not your fault, so it shouldn't hurt their legal defense if they apologize. I think it won't be interpreted as an admission of guilt like it could be in America.

Re: Sony: All personal data stolen from PSN

#259

Earlier quoted context omitted.

"I wouldn't be surprised if it cost Sony more than Microsoft's infamous 1 billion dollar write-down with the Xbox 360's Red Ring of Death." Banks, colleges, hospitals, and credit card processors do this all the time, and it doesn't cost them anywhere near a billion dollars despite the fact that they have vastly more personal information. Sure they usually only have a few hundred thousand records and not a few million…

Numbers I've heard floated for leaks on the smaller scale are around $15-20 per person for post-leak mitigation and damages, which could push near $1b if the same per-person cost held with this size leak (which it might not). When my university had some data stolen, their lawyers advised them to buy everyone a year of some identity-theft insurance/monitoring package, which I believe cost them around $10 per person ju…

Monoprice did the same thing when they were hacked last year. Two months after it happened, I got a letter from them with a few papers describing the identity theft monitoring service I would receive for a year.

Re: Sony: All personal data stolen from PSN

#260

"Although we are still investigating the details of this incident, we believe that an unauthorized person has obtained the following information that you provided: ... PlayStation Network/Qriocity password and login," Seriously? Even Sony is keeping passwords in plaintext? There wasn't a single competent person involved in the design of PSN who might have mentioned that was a terrible idea?

Sometimes, you explain why storing a password in plaintext is a terrible idea, but the business executives simply do not care, or think it's better to keep them available, in case somebody forgets it...
Post reply on HN