Live data from Hacker News

Sony: All personal data stolen from PSN

blog.us.playstation.com

291–292 of 292 posts

Re: Sony: All personal data stolen from PSN

#291
post #287

Earlier quoted context omitted.

That's not practical. Password hashes should be slow, to stop dictionary attacks; and it's easy to imagine a couple thousand "similar" passwords (flip case of some characters? 256 possibilities for an 8-character password. Add year of birth? 20-50 possibilities. And so on.)

Presumably the ratio between the rate of normal logins (each of which requires a single execution of the password hash) and the rate of password changes is at least a few thousand.

Sure, but if you run through a few thousand hashes to check for similarity, an attacker can check for the couple thousand most popular passwords in the same amount of time. It is possible to throw enough money at it to make an attack uneconomical, but that's expensive.

(Also, DoS. Note that you can't stop people from changing passwords when the system is under load, as that sets you up for a combined compromise-password-hashes-then-DoS attack...)

Re: Sony: All personal data stolen from PSN

#292
post #11

I wonder how many times a company can install trojans on your computer, destroy your OS's security, secretly watch all your actions, then proceed to not properly protect your data when you voluntarily give it to them...before going out of business. Sony's size and momentum must be pretty crazy. Or maybe it's our society. I just can't imagine a small record store in the 1960s, after being caught spying through the bed…

Happens to lots of organisations. Look at the Catholic Church. They are pretty big, still popular and have had their share of 'incidents' (to put it very mildly) recently.
Post reply on HN