Announcement

Collapse
No announcement yet.

Sony's Playstation Network hacked. Down 6 days and counting. And to ice the cake...

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

  • #31
    Your welcome sir.

    More news:

    "Sony has confirmed that the credit card details possibly stolen in a breach of its PlayStation Network were encrypted"

    One day Canada will rule the world, and then we'll all be sorry.

    Comment


    • #32
      ... encrypted in pig latin

      Comment


      • #33
        Originally posted by Dauphin View Post
        Your welcome sir.

        More news:

        "Sony has confirmed that the credit card details possibly stolen in a breach of its PlayStation Network were encrypted"

        http://www.zdnet.co.uk/news/security...data-40092628/
        Sony encrypts lots of things. They just don't know how to do it properly.

        I wouldn't be shocked if they stored the encryption keys on the same server that was breached.

        PSN was breached. PSN needs access to the "encrypted" credit card table (this heavily implies it's a simple DB table that stores the individually encrypted numbers, which is epic-fail in and of itself). PSN has some mechanism (code) to access that table. It's not at all out of the realm of possibility for the hackers to look into that and find out how PSN itself accesses the numbers, then do so itself. There's certainly tremendous financial incentive for them to figure it out.
        "The issue is there are still many people out there that use religion as a crutch for bigotry and hate. Like Ben."
        Ben Kenobi: "That means I'm doing something right. "

        Comment


        • #34
          Rumor...



          Is Sony user database for sale in online bazaar?
          That's among the rumors still swirling in wake of massive security breach

          Eight days after Sony took the PlayStation Network offline, rumors and misinformation continue to swirl around the unprecedented shutdown and massive data breach that affected an estimated 77 million users.

          Security expert Kevin Stevens of TrendMicro tweeted today (April 28) that low-level cybercriminals using "carder" online forums were offering to sell a database of 2.2 million credit-card numbers taken during the PlayStation Network breach.

          Independent security blogger Brian Krebs then posted screenshots of four hackers discussing the purported database in a chat room.

          "xxx: format is: fname, lnams, address, zipcode, country, phone, email, email password, dob, ccnum, cvv2, exp date," wrote user "Sutekh" in one of the screenshots.

          In plain English, that's the first name, last name, address, postal code, country, telephone number, email address, email password, date of birth, credit-card number, credit-card security code and credit-card expiration date attached to each of 2.2 million accounts — including "150k german ones," as Sutekh said in a different posting.

          "Sony was supposedly offered a chance to buy the DB (database) back but didn't," tweeted Stevens.

          Neither Stevens nor Krebs claimed to have seen the actual database being offered, and it almost sounds too good to be true. Why, for example, would Sony have the passwords to users' third-party email accounts, such as Yahoo or Gmail accounts?

          Sony: Your credit card information is safe
          For its part, Sony dribbled out a bit more information today.

          In an FAQ posted on various PlayStation websites worldwide, the company said that "your credit card security code (sometimes called a CVC or CSC number) has not been obtained because we never requested it from anyone who has joined the PlayStation Network or Qriocity, and is therefore not stored anywhere in our system."

          (Qriocity is a separate entertainment-delivery network owned and run by Sony, which was also affected by the PlayStation Network breach.)

          Sony also stated that, "The entire credit card table was encrypted and we have no evidence that credit card data was taken."

          So either the hackers selling the database are lying about having credit card security codes, or Sony is not telling the truth about having them in the first place.

          The latter scenario seems far less likely, as Sony would open itself to enormous lawsuits if it were found to be less than truthful about the breach — except that, as was reported yesterday, unencrypted credit card numbers with security codes are exactly what amateur hackers claimed to have found in PlayStation Network development channels two months ago.

          Anecdotal evidence of credit card fraud against PlayStation Network users has been showing up on several websites.

          "My bank called me to notify me of a suspicious transaction and they confirmed it was indeed a fraudulent withdrawal," a man calling himself Josh Webb emailed to the gaming site VGN365. "I’ve had to cancel my card and order a new one which the bank will transfer my previous account’s money into."

          "The number of Ars Technica readers who have had issues with their credit cards in the past few days, and have commented, e-mailed, or Tweeted about the issue, is alarming," wrote Ben Kuchera on the tech blog Ars Technica. "We may be dealing with a coincidence in timing, but when your inbox is heavy with people saying they're fighting fraudulent credit card charges, it may be the first signs of fire somewhere in the smoke."

          The first lawsuit
          Kristopher Johns of Alabama filed a federal class-action suit against Sony on behalf of all PlayStation Network users on Wednesday in the Northern District of California.

          The suit claims that Sony "failed to encrypt data and establish adequate firewalls to handle a server intrusion contingency, failed to provide prompt and adequate warnings of security breaches, and unreasonably delayed in bringing the PSN service back on line." (The PlayStation Network service is still offline.)

          It might be hard for Sony to refute those allegations. In its own FAQ today, the company admitted that "The personal data table … was not encrypted, but was, of course, behind a very sophisticated security system that was breached in a malicious attack."

          In other words, once someone got into the restricted part of the network, all user data except credit card numbers was easily obtainable — more than enough information to set up identity thefts and spear-phishing scams en masse.

          George Hotz, the 23-year-old New Jersey hacker sued by Sony for hacking the PlayStation 3, pointed out the inherent flaw in the PlayStation Network's security in a blog posting today. (He disavowed any connection to the data breach.)

          "Traditionally the trust boundary for a web service exists between the server and the client. But Sony believes they own the client too," he wrote, referring to the PlayStation 3 console as the client. "So if they just put a trust boundary between the consumer and the client (can't trust those pesky consumers), everything is good. Since everyone knows the PS3 is unhackable, why waste money adding pointless security between the client and the server?"

          In other words, user authentication was done at the console level during routine logins. Consoles accessing the PlayStation Network were not individually verified, since Sony believed that retail consoles could not be modified to access the behind-the-scenes development channels of the PlayStation Network.

          But the fact is that PlayStation 3 consoles could indeed be modified to do just that, which led February's amateurs to allegedly find the unencrypted user data — and which may have opened the way for the data breach.
          "The issue is there are still many people out there that use religion as a crutch for bigotry and hate. Like Ben."
          Ben Kenobi: "That means I'm doing something right. "

          Comment


          • #35
            But wait, there's more!
            NEW YORK (AP) -- Sony Corp. says that hackers may have taken personal information from an additional 24.6 million user accounts after a review of the recent PlayStation Network breach found an earlier intrusion at its online entertainment division.

            The data loss comes on top of the 77 million PlayStation accounts it has already said were jeopardized by a malicious intrusion.

            The breach occurred April 16 and 17 -- before the PlayStation break-in. About 10,700 direct debit records of customers in Austria, Germany, the Netherlands and Spain may have been stolen.

            A further 12,700 credit or debit card numbers elsewhere outside the U.S. may also have been stolen, it said.

            Sony says it shut service to Sony Online Entertainment games such as "DC Universe Online" early Monday morning.
            Pool Manager - Lombardi Handicappers League - An NFL Pick 'Em Pool

            https://youtu.be/HLNhPMQnWu4

            Comment


            • #36
              I use to play FFXI years ago.

              Am I in trouble?/

              JM
              Jon Miller-
              I AM.CANADIAN
              GENERATION 35: The first time you see this, copy it into your sig on any forum and add 1 to the generation. Social experiment.

              Comment


              • #37
                You're not liable for fraudulent purchases as long as you report them in a reasonable amount of time. Just be sure you look over your credit card statements more carefully over the next six or twelve months.

                I changed all of my passwords to make sure that my PSN password is no longer in use anywhere else.
                <p style="font-size:1024px">HTML is disabled in signatures </p>

                Comment


                • #38
                  77m users, a few anecdotally getting credit card fraud doesn't necessarily mean it's linked. I had some dodgy transactions requested last year, my bank cancelled the card and notified me, could just be coincidence. This stuff is very common.
                  Jon Miller: MikeH speaks the truth
                  Jon Miller: MikeH is a shockingly revolting dolt and a masturbatory urine-reeking sideshow freak whose word is as valuable as an aging cow paddy.
                  We've got both kinds

                  Comment


                  • #39
                    Recompense (and details about it coming back)



                    So coming it's back and this is the sweetner:

                    Complimentary Offering and "Welcome Back" Appreciation Programme

                    While there is no evidence at this time that credit card data was taken, the company is committed to helping its customers protect their personal data and will provide a complimentary offering to assist users in enrolling in identity theft protection services and/or similar programmes. The implementation will be at a local level and further details will be made available shortly in each region.

                    The company will also roll out the PlayStation Network and Qriocity "Welcome Back" programme, to be offered worldwide, which will be tailored to specific markets to provide our consumers with a selection of service options and premium content as an expression of the company's appreciation for their patience, support and continued loyalty.

                    Central components of the "Welcome Back" programme will include:

                    Each territory will be offering selected PlayStation entertainment content for free download. Specific details of this content will be announced in each region soon.
                    All existing PlayStation Network customers will be provided with 30 days free membership in the PlayStation Plus premium service. Current members of PlayStation Plus will receive 30 days free service.
                    Q Music Unlimited subscribers (in countries where the service is available) will receive 30 days free service.
                    Additional "Welcome Back" entertainment and service offerings will be rolled out over the coming weeks as the company returns the PlayStation Network and Qriocity services to the quality standard users have grown to enjoy and strive to exceed those exceptions.
                    Jon Miller: MikeH speaks the truth
                    Jon Miller: MikeH is a shockingly revolting dolt and a masturbatory urine-reeking sideshow freak whose word is as valuable as an aging cow paddy.
                    We've got both kinds

                    Comment


                    • #40
                      as I am not one of the 77 million, how sweet is the sweetener?
                      Socrates: "Good is That at which all things aim, If one knows what the good is, one will always do what is good." Brian: "Romanes eunt domus"
                      GW 2013: "and juistin bieber is gay with me and we have 10 kids we live in u.s.a in the white house with obama"

                      Comment


                      • #41
                        Depends what

                        provide a complimentary offering to assist users in enrolling in identity theft protection services and/or similar programmes. The implementation will be at a local level and further details will be made available shortly in each region.
                        and

                        Each territory will be offering selected PlayStation entertainment content for free download. Specific details of this content will be announced in each region soon.
                        Actually amounts to.

                        The free Playstation Plus was widely talked about, and I don't think that counts as much since it's actually quite a good advert for them, free trial to get more people subscribing (if anyone would!)
                        Jon Miller: MikeH speaks the truth
                        Jon Miller: MikeH is a shockingly revolting dolt and a masturbatory urine-reeking sideshow freak whose word is as valuable as an aging cow paddy.
                        We've got both kinds

                        Comment


                        • #42
                          hah... they will have to be offering some extra sweeteners it seems:

                          Sony attacked again, 12,700 non-US CC numbers feared stolen

                          Socrates: "Good is That at which all things aim, If one knows what the good is, one will always do what is good." Brian: "Romanes eunt domus"
                          GW 2013: "and juistin bieber is gay with me and we have 10 kids we live in u.s.a in the white house with obama"

                          Comment


                          • #43
                            This easily could have happened to Microsoft or Nintendo and the only reason Sony was targeted is because they publicly tried to piss off the hackers. That's really the only reason Sony was targeted instead of one of the others.
                            Try http://wordforge.net/index.php for discussion and debate.

                            Comment


                            • #44
                              Originally posted by Oerdin View Post
                              This easily could have happened to Microsoft or Nintendo and the only reason Sony was targeted is because they publicly tried to piss off the hackers. That's really the only reason Sony was targeted instead of one of the others.
                              I doubt this would happen to Microsoft. MS has been exceptionally competent with security since ~2004 or so.

                              Sony made a lot of basic errors.
                              "The issue is there are still many people out there that use religion as a crutch for bigotry and hate. Like Ben."
                              Ben Kenobi: "That means I'm doing something right. "

                              Comment


                              • #45
                                I don't disagree that MS or Nintendo might have alerted customers faster or that it might have been slightly harder for hackers to break in but any security system can be defeated and the harder it is the more some college kid will want to hack it just to show how LEET he is.
                                Try http://wordforge.net/index.php for discussion and debate.

                                Comment

                                Working...
                                X