Live data from Hacker News

Sony: All personal data stolen from PSN

blog.us.playstation.com

281–290 of 292 posts

Re: Sony: All personal data stolen from PSN

#281

Earlier quoted context omitted.

Right, the key here is that goodwill is measurable. Opportunity costs are not.

Opportunity costs are measurable. It all depends on your assumptions whether the measurements are reasonable or not. Ex. If I make $2000 a week as a contractor on a steady contract, I know that the opportunity cost of taking a week of unpaid vacation time is $2000. That's a reasonable, measurable assumption. However, I could also say that the opportunity cost of that week of vacation will be $12000, because there mig…

You're estimating an opportunity cost here, not measuring it.

Goodwill can be measured in the sense that goodwill = purchase price - book value. No assumptions are involved in its calculations--goodwill is calculated based on two fixed values.

Opportunity costs are not as concrete. In your example above you state your opportunity cost is $2000...but what if that rush project comes through? What if your steady contract scales back for that week? There are assumptions involved; ideally your opportunity cost would be the expected value of all probable incomes during that week. Identifying those probabilities a priori is impossible.

My point is: opportunity costs are based on assumptions. They cannot be measured--only estimated.

Re: Sony: All personal data stolen from PSN

#283

Earlier quoted context omitted.

Sony Music's meddling is the reason Sony failed to make a successful Mp3 player, all the more remarkable because Sony created the individual portable music market and dominated it with the Walkman.

Not only that, but they're responsible for the Minidisc's failure. That could have been a really nice format, but they had to slap a bunch of restrictions on it.

Not only the DRM restrictions, but that they limited manufacturing licenses to other companies. MinkDiscs are the perfect size and a little more durable (scratch resistent) imo. It's a shame CD's won out.

Re: Sony: All personal data stolen from PSN

#284

There were sixty million[0] PSN accounts. This is impressive, and amounts to (judging by a quick search) the largest-scale ID (and possibly credit-card) theft ever [Not so, see child comment]. Not even factoring in credit card details, the usernames, emails, addresses, ages, passwords, mother's maiden names, favourite pets, of sixty million people is worth a hell of a lot. I have to wonder how much data that is, in t…

While I detest PayPal, and it makes me livid that any company places upper-bound (and/or character) restrictions on passwords, I did want to mention that Yubico provides a two-factor authentication key which works with PayPal: http://yubico.com/VIP

I don't have any stake in either company, but I was glad when Google rolled out 2-factor and I am especially glad to be able to finally use 2-factor for safeguarding my money.

Re: Sony: All personal data stolen from PSN

#285

Earlier quoted context omitted.

You could at least have them encrypted on disk with a key only stored in memory, i.e.: when the system is turned on. Alternatively a dedicated crypo device where you feed it cipher text and it gives you plain text would also help as the attack wouldn't be able to get the key (even if they have the physical box (for good crypto devices)) While only marginally better depending on the type of attack and permissions gain…

And what if that server needs to be rebooted some day? What if there's a hardware failure and it has to be powered off? Something as big as PSN has multiple servers reading the same DB and must be able to tolerate failures without forcing everyone to re-enter their CC #. The keys must be stored persistently somewhere.

As tzs said, you basically have to have someone(s) restart the system and re-enter they key.

Re: Sony: All personal data stolen from PSN

#286

Earlier quoted context omitted.

It should at least be an option for me not to store it, if I prefer not to use "one-click" and similar features. I understand why stores prefer to save the information without giving me a choice (reduces friction for future purchases), but I'm not sure that's a good enough reason given the prevailing security track records. Either that, or perhaps there could be statutory penalties for data breaches. For example, if…

Online retailers who handle their own CC processing tend to keep credit card information around if only for fraud/chargeback tracking in the future - being online opens you up to massive abuse if you don't keep it in check. A big player like sony should have been complying with PCI standards - but from what I've seen, that's not so difficult to pass and then forget about - people take shortcuts - and how many compani…

From my experience, PCI compliance does not require that you have everything perfect, as long as you have a plan to fix your deficiencies.

And as an employee at a couple of PCI compliant shops, I can attest that even full PCI compliance still leaves a lot of holes (enough that some organizations have formed their own compliance exams above and beyond PCI).

Re: Sony: All personal data stolen from PSN

#287
post #203

Earlier quoted context omitted.

Well, they could try permuting your new password in a few different ways and seeing if any of those permutations match the old hash.

That's not practical. Password hashes should be slow, to stop dictionary attacks; and it's easy to imagine a couple thousand "similar" passwords (flip case of some characters? 256 possibilities for an 8-character password. Add year of birth? 20-50 possibilities. And so on.)

Presumably the ratio between the rate of normal logins (each of which requires a single execution of the password hash) and the rate of password changes is at least a few thousand.

Re: Sony: All personal data stolen from PSN

#288
post #225

Earlier quoted context omitted.

You sigh too quickly. The CDs said "Sony BMG." The merger with BMG was in March of 2004 and the rootkit was in 2005. The reason you associate it with Sony corporate and not Bertelsmann (of Bertelsmann Music Group) is because reporters are lazy and shorten the name of the company to just Sony. Maybe Germans were boycotting magazines because that was the part of the name familiar to them. I don't recall that. Its fair…

The executive in charge at the time of the fiasco came over to Sony BMG from Bertelsmann. What actually happened to him? I don't think I ever heard.

Nothing much. In his defense, he's also been in charge as the industry has moved away from DRM. The music labels view computer technology as just a hammer in the toolbox. If they have a better option, they go to that.

http://www.npr.org/templates/story/story.php?storyId=4989260 (even here when they were interviewing him, the headline is just "Sony" but throughout it is "Sony BMG") http://en.wikipedia.org/wiki/Thomas_Hesse (last few paragraphs)

Re: Sony: All personal data stolen from PSN

#289

Earlier quoted context omitted.

The Japanese announcement is full of apology: "2011年4月21日よりPlayStation®NetworkおよびQriocity™の障害が継続しており、お客様および関係各位に多大なるご迷惑をおかけしておりますことを深くお詫び申しあげます。" Which is a polite and flowery way of apologizing for the ongoing interruption of service. http://cdn.jp.playstation.com/msg/sp_20110427_psn.html

Would you mind giving a rough translation of that? Google Translate is doing a terrible job, and I speak absolutely no Japanese.

We sincerely apologize to our customers and other parties who are affected by the continuing service impairment of the Playstation Network since April 21st.

Re: Sony: All personal data stolen from PSN

#290
post #273

http://psx-scene.com/forums/f177/sony-has-been-bad-boy-ridic... "A well known hacker i don’t want to reveal here had all the Sony PlayStation Network functions 100% decrypted as well as providing some nice info about how Sony dealing with PSN members privacy in their online servers. Apparently, Sony server gathered everything they can from the PSN connected PS3 console. When i said everything, i meant it. Here, i mak…

This is interesting. I remember hearing a story about Apple and the record labels. Basically, it took a long time for the labels to trust Apple with their entire catalogues DRM on Apple's servers (DRM was added at time of purchase). It required lots of work on Apple's side to gain that trust so that the labels felt comfortable with Apple essentially housing all of their prized assets. If Sony was trusting all transac…

Sony is a member of the RIAA and MPAA and I imagine one of the heavyweights, if not the heavyweight. So nothing will come of this from that angle.
Post reply on HN