Live data from Hacker News

IRC chat log of PSN hackers

pastebin.com

11–20 of 45 posts

Re: IRC chat log of PSN hackers

#11

They seemed to be concerned about the lack of security they were witnessing, and they also alluded to "this could be bad in the hands of a spammer". If this log is real, is it truly the conversation of those that took the data?

I'm with you on all points; however, what I find interesting is that these guys talk explicitly about the credit card data being available via the path they took. If these are the same people--or if perhaps it was someone lurking in the channel--the suggestion is that the technique used would have exposed the credit card data of these users--despite Sony claiming that they felt it was unlikely.

I'm not sure there's a lot of "news" to this post; my feeling is that if Sony, "isn't ruling out the possibility" that my credit card information was stolen, I'm working under the assumption that it was. I'd encourage everyone else who was subscribed to PSN to do the same.

Re: IRC chat log of PSN hackers

#12
This is old. Here is the same pastie, but posted on February 16, 2011 http://pastie.org/private/97oth9v5tspkiztwwdmnga

They aren't talking about the PSN Hack that brought down the network this time, they are going back and forth about how PSN stores the user's CC information in plain text on the console and that a shady/grey custom firmware has the potential to skim that information off the hardware and onto a bad guy's server.

The only slightly frightening thing about this is how they allude to the idea that this plain text CC information and security codes are transmitted over plain text, but that information is false. All transactions done between your PS3 console and the PSN network were done over SSL.

Re: IRC chat log of PSN hackers

#16
post #14

[deleted]

Anyone in the channel could have posted it from their own IRC logs - most IRC programs will allow you to log everything you see. That they've censored the nicknames of the people talking before posting gives me the feeling that it was probably one of the people talking in the channel that posted it.

Re: IRC chat log of PSN hackers

#17

They seemed to be concerned about the lack of security they were witnessing, and they also alluded to "this could be bad in the hands of a spammer". If this log is real, is it truly the conversation of those that took the data?

Looks to me like guys trying to get banned PS3s back on the game network, not steal user info and credit card numbers.

[user12] know this, sony in realtime, monitors all messages over psn [user12] I verified that, its part of my privacy threats thing I am doing [user5] ok too bad id like the psn messenger on pc [user12] the realtime monitoring is a bit bothersome to me

It seems plausible though that people were using this info to do things which violated Sony's security model and that their security model also didn't effectively separate credit card info from the game data.

For example, there were claims a few weeks ago (Wired or ARS I think) that they were all mixed together in the same SSL stream.

Re: IRC chat log of PSN hackers

#18
post #4

Could someone please provide a précis?

Please there is no reason to use words that most people here don't know. Plenty of people who frequent HN are non native speakers of English. To save others the trouble, calpaterson asked for a resume .

Actually, neither précis nor résumé is native English. They are French, and in French they mean "summary".

Re: IRC chat log of PSN hackers

#19
post #4

Could someone please provide a précis?

Please there is no reason to use words that most people here don't know. Plenty of people who frequent HN are non native speakers of English. To save others the trouble, calpaterson asked for a resume .

"Précis" is a French word, so wouldn't the fact that many people who frequent HN are non-native speakers of English mean that using a French word increases the number of people who understand?

Of course, I would have gone for tl;dr.

Re: IRC chat log of PSN hackers

#20
post #12

This is old. Here is the same pastie, but posted on February 16, 2011 http://pastie.org/private/97oth9v5tspkiztwwdmnga They aren't talking about the PSN Hack that brought down the network this time, they are going back and forth about how PSN stores the user's CC information in plain text on the console and that a shady/grey custom firmware has the potential to skim that information off the hardware and onto a bad gu…

I don't think "user2" is claiming that the credit card information was sent in plaintext:

normally you ATLEAST enccrypt the securtity code, even if its ssl

That seems to refer to encrypting the CC security code before sending it over SSL using public key encryption, which is good practice if you subscribe to defence in depth. But it's nothing I'd get upset about.

Post reply on HN