Go Back  DVD Talk Forum > Entertainment Discussions > Video Game Talk
Reload this Page >

The Official PS3 thread - Aaaaannnnnnddddd we're back!

Community
Search
Video Game Talk The Place to talk about and trade Video & PC Games

The Official PS3 thread - Aaaaannnnnnddddd we're back!

Thread Tools
 
Search this Thread
 
Old 04-26-11 | 08:50 PM
  #2601  
DVD Talk Limited Edition
 
Joined: Oct 2001
Posts: 6,097
Likes: 0
Received 3 Likes on 3 Posts
Re: The Official PS3 thread - Software bugs? We don't need no software bugs

Originally Posted by Ravenous
If I was MS I would totally but the xbox on sale for $100 off each version and do some kind of media blitz and totally over hype Live... shit Id get 4gb 360 for $100
and you still wouldn't be able to play Sony exclusive titles ... so who cares
Old 04-26-11 | 08:56 PM
  #2602  
Drexl's Avatar
DVD Talk Legend
 
Joined: Feb 2001
Posts: 16,077
Likes: 0
Received 16 Likes on 14 Posts
From: St. Louis, MO
Re: The Official PS3 thread - Software bugs? We don't need no software bugs

Originally Posted by dino88
I'm curious what game you tried to play that didn't work, because the updates are working just fine.
And which games won't work without updates anyway? It has to go online to know there's an update available.
Old 04-26-11 | 08:58 PM
  #2603  
pinata242's Avatar
DVD Talk Hero
 
Joined: Jun 2003
Posts: 30,155
Likes: 0
Received 3 Likes on 3 Posts
From: Owasso, OK
Re: The Official PS3 thread - Software bugs? We don't need no software bugs

Originally Posted by Fandango
You guys need to calm down, apparently they didn't know this until yesterday.
This statement confuses me. Are we supposed to calm down because they don't know how to monitor their own systems for intrusion? It sounds like you're saying ignorance is a valid defense.

What if they still didn't know? Would we be safe then?
Old 04-26-11 | 09:00 PM
  #2604  
DVD Talk Legend
 
Joined: May 2007
Posts: 12,298
Received 81 Likes on 70 Posts
Re: The Official PS3 thread - Software bugs? We don't need no software bugs

I'd be happy if psn stayed offline for a month or even more as long as it takes to fix everything and get it all back up and running.
Old 04-26-11 | 09:03 PM
  #2605  
dsa_shea's Avatar
DVD Talk Legend
 
Joined: Jan 2005
Posts: 22,295
Received 356 Likes on 256 Posts
From: Tulsa, Oklahoma
Re: The Official PS3 thread - Software bugs? We don't need no software bugs

How do they even know that customer information was taken? What lets them know this?
Old 04-26-11 | 09:45 PM
  #2606  
DVD Talk Hall of Fame
 
Joined: Jun 2002
Posts: 8,487
Likes: 0
Received 0 Likes on 0 Posts
Re: The Official PS3 thread - Software bugs? We don't need no software bugs

Originally Posted by glassdragon
I don't know if this is something sony could have avoided.
I'm pretty sure it is, actually.

Originally Posted by Fandango
You guys need to calm down, apparently they didn't know this until yesterday.
Oh, ok then. Sorry, Sony!
Old 04-26-11 | 09:46 PM
  #2607  
LorenzoL's Avatar
DVD Talk Legend
 
Joined: Apr 2004
Posts: 23,722
Received 462 Likes on 374 Posts
From: Ontario, Canada
Re: The Official PS3 thread - Software bugs? We don't need no software bugs

Originally Posted by dsa_shea
How do they even know that customer information was taken? What lets them know this?
One of the article indicated that when Sony called a 3rd party to investigate the intrusion, that they were informed of the breach.
Old 04-26-11 | 09:55 PM
  #2608  
DVD Talk Hall of Fame
 
Joined: Jun 2002
Posts: 8,487
Likes: 0
Received 0 Likes on 0 Posts
Re: The Official PS3 thread - Software bugs? We don't need no software bugs

Just got the official email at 10:18 PM, by the way. I won't repost it since it's essentially exactly the same thing that pinata posted earlier.
Old 04-26-11 | 10:10 PM
  #2609  
DVD Talk Limited Edition
 
Joined: Aug 2005
Posts: 5,512
Likes: 0
Received 0 Likes on 0 Posts
Re: The Official PS3 thread - Software bugs? We don't need no software bugs

Would be kind of funny if Microsoft ended up being the 3rd party investigating the breach...
Old 04-26-11 | 10:35 PM
  #2610  
Senior Member
 
Joined: Sep 2005
Posts: 292
Likes: 0
Received 0 Likes on 0 Posts
Re: The Official PS3 thread - Software bugs? We don't need no software bugs

Originally Posted by slop101
If people's card info was stolen and being fraudulently used, we'd be hearing about it by now.
I was thinking the same thing.

Not sure what to do right now. I sold my PS3 last year, but my PSN account is still around. Can't remember if I had a card on file or not. Of course I can't login and check either...
Old 04-26-11 | 10:42 PM
  #2611  
sauce07's Avatar
DVD Talk Limited Edition
 
Joined: Nov 2003
Posts: 6,549
Received 26 Likes on 18 Posts
From: Centreville, VA
Re: The Official PS3 thread - Software bugs? We don't need no software bugs

this sucks, and it will suck for a couple more weeks till everything gets straightened out but in no way is this going to get me to buy another Microsoft product.
Old 04-26-11 | 10:54 PM
  #2612  
DVD Talk Gold Edition
 
Joined: Aug 2001
Posts: 2,394
Likes: 0
Received 1 Like on 1 Post
Re: The Official PS3 thread - Software bugs? We don't need no software bugs

Originally Posted by pinata242
This statement confuses me. Are we supposed to calm down because they don't know how to monitor their own systems for intrusion? It sounds like you're saying ignorance is a valid defense.

What if they still didn't know? Would we be safe then?
No, what I'm saying is people are implying they knew about it days ago and didn't report it until now. If they pre-emptively told people their information might have been stolen and people had to cancel their cards, change passwords etc and it turned out nothing had been stolen they would have gotten backlash too. So either way Sony was screwed.
Old 04-26-11 | 11:00 PM
  #2613  
DVD Talk Godfather
 
Joined: Aug 1999
Posts: 51,148
Received 2,980 Likes on 2,275 Posts
Re: The Official PS3 thread - Software bugs? We don't need no software bugs

Originally Posted by Fandango
No, what I'm saying is people are implying they knew about it days ago and didn't report it until now. If they pre-emptively told people their information might have been stolen and people had to cancel their cards, change passwords etc and it turned out nothing had been stolen they would have gotten backlash too. So either way Sony was screwed.
Sony actually doesn't believe that credit card info was stolen, at least not at this point, but they don't know for sure either way. I'd still like to know if they screwed up in encrypting out passwords...
Old 04-26-11 | 11:14 PM
  #2614  
pinata242's Avatar
DVD Talk Hero
 
Joined: Jun 2003
Posts: 30,155
Likes: 0
Received 3 Likes on 3 Posts
From: Owasso, OK
Re: The Official PS3 thread - Software bugs? We don't need no software bugs

Originally Posted by Fandango
No, what I'm saying is people are implying they knew about it days ago and didn't report it until now. If they pre-emptively told people their information might have been stolen and people had to cancel their cards, change passwords etc and it turned out nothing had been stolen they would have gotten backlash too. So either way Sony was screwed.
Fair enough but, really, Sony deserves to be screwed either way for this. Whether or not any info was stolen. Whether or not any stolen info will be used for ill. Whether or not they knew about it. The fact that this exploit existed is enough to justify the piling on.

I'm not saying anyone else is impregnable, but I am sure they're all going through a new round of testing and simulations to find any heretofore unknown holes.
Old 04-26-11 | 11:32 PM
  #2615  
Senior Member
 
Joined: Sep 2005
Posts: 292
Likes: 0
Received 0 Likes on 0 Posts
Re: The Official PS3 thread - Software bugs? We don't need no software bugs

Are they sending out emails to all PSN accounts, or just ones they think are compromised? So far I haven't received anything from Sony.
Old 04-26-11 | 11:55 PM
  #2616  
DVD Talk Gold Edition
 
Joined: Aug 2001
Posts: 2,394
Likes: 0
Received 1 Like on 1 Post
Re: The Official PS3 thread - Software bugs? We don't need no software bugs

http://lo-ping.org/2011/04/26/psn-hackers-chat-logs/
Old 04-26-11 | 11:59 PM
  #2617  
pinata242's Avatar
DVD Talk Hero
 
Joined: Jun 2003
Posts: 30,155
Likes: 0
Received 3 Likes on 3 Posts
From: Owasso, OK
Re: The Official PS3 thread - Software bugs? We don't need no software bugs

[user2] cuz its way too easy todo scamming at this point

[user2] for example:

[user2] creditCard.paymentMethodId=VISA&creditCard.holderName=Max&creditCard.cardNumber=4558254723658741&creditCard.expireYear=2012&creditCard.expireMonth=2&creditCard.securityCode=214&creditCard.address.address1=example street%2024%20&creditCard.address.city=city1%20&creditCard.address.province=abc%20&creditCard.address.postalCode=12345%20

[user2] sent as plaintext

[user3] uh

[user3] did you censor that card?

[user2] ya its fake

[user3] good

[user1] wow, plaintext :S

[user5] plaintext wow

[user3] im never putting in my details like that
Attack or not, this is (if true) is more infuriating than anything! Seriously, Sony!? PLAIN FUCKING TEXT OVER THE INTERNET!?
Old 04-27-11 | 12:00 AM
  #2618  
DVD Talk Limited Edition
 
Joined: Jul 2008
Posts: 7,127
Received 32 Likes on 27 Posts
From: STL
Re: The Official PS3 thread - Software bugs? We don't need no software bugs

Originally Posted by DarthPrime
Are they sending out emails to all PSN accounts, or just ones they think are compromised? So far I haven't received anything from Sony.
That just means that all of your information was stolen and wiped clean from Sony's records. Your credit card is probably being used to fund an Al-Qaeda training camp or Donald Trump's presidential campaign.
Old 04-27-11 | 12:16 AM
  #2619  
DVD Talk Special Edition
 
Joined: Apr 2002
Posts: 1,501
Likes: 0
Received 0 Likes on 0 Posts
From: OKC, OK
Re: The Official PS3 thread - Software bugs? We don't need no software bugs

I am not so concerned about my CC number getting stolen. That is an easy fix. If someone starts charging on that account, my CC company will take care of me, especially with the knowledge of this extensive breach.

Much more frightening to me is the thought of identity theft. With names, addresses, birthdates, emails and all the other shit they mentioned, I am concerned about someone setting up NEW credit accounts in your name. They can go crazy and by the time it is found out, your credit is toast.

This is god damn ridiculous.
Old 04-27-11 | 12:19 AM
  #2620  
DVD Talk Legend
 
Joined: Apr 2002
Posts: 20,767
Likes: 0
Received 15 Likes on 8 Posts
Re: The Official PS3 thread - Software bugs? We don't need no software bugs

I don't have a PSN account but am following the story since this could be the biggest data breach in history. I was just surprised with how long the outage was but now the possibility of CC info being stolen is pretty bad. So Sony says there's no evidence CC info was stolen but that can't be ruled out and says to check your card statements...

Any groups taking credit for the hack?
Old 04-27-11 | 12:22 AM
  #2621  
DVD Talk Legend
 
Joined: Apr 2002
Posts: 20,767
Likes: 0
Received 15 Likes on 8 Posts
Re: The Official PS3 thread - Software bugs? We don't need no software bugs

Originally Posted by SoonerDoc
I am not so concerned about my CC number getting stolen. That is an easy fix. If someone starts charging on that account, my CC company will take care of me, especially with the knowledge of this extensive breach.

Much more frightening to me is the thought of identity theft. With names, addresses, birthdates, emails and all the other shit they mentioned, I am concerned about someone setting up NEW credit accounts in your name. They can go crazy and by the time it is found out, your credit is toast.

This is god damn ridiculous.
You think that'd be bad - what about the people who used debit cards and have their bank account wiped out?
Old 04-27-11 | 12:25 AM
  #2622  
pinata242's Avatar
DVD Talk Hero
 
Joined: Jun 2003
Posts: 30,155
Likes: 0
Received 3 Likes on 3 Posts
From: Owasso, OK
Re: The Official PS3 thread - Software bugs? We don't need no software bugs

Originally Posted by Ranger
You think that'd be bad - what about the people who used debit cards and have their bank account wiped out?
Debit card? That's as much on them
Old 04-27-11 | 12:50 AM
  #2623  
DVD Talk Hall of Fame
 
Joined: Jun 2002
Posts: 8,487
Likes: 0
Received 0 Likes on 0 Posts
Re: The Official PS3 thread - Software bugs? We don't need no software bugs

Some funnies from Twitter, as reported by Kotaku (and some others):

"Hey folks, they told Playstation Plus subscribers about this credit card thing last Thursday."
- Bookscout

"If Sony had required firmware updates hourly instead of daily, this never would've happened."
- MTV Multiplayer's Russ Frushtick

"PSN's down for a week, my credit card info might be stolen, but the most irritating thing about Sony's service is still the name 'Qriocity.'"
- Casey Malone

"PS3 Mortal Kombat exclusive: Kratos. Xbox 360 Mortal Kombat exclusive: being online."
-Andre Black Nerd

"BREAKING NEWS: Nintendo takes WiiWare/Virtual Console offline, just to see If anyone will even notice"
-GeorgeBray
Old 04-27-11 | 01:17 AM
  #2624  
bunkaroo's Avatar
DVD Talk Legend
 
Joined: Oct 2002
Posts: 16,400
Received 206 Likes on 139 Posts
From: Chicago West Suburbs
Re: The Official PS3 thread - Software bugs? We don't need no software bugs

This is from the comments section of the latest PSN story at Kotaku. I have familiarity with PCI compliance and it sounds like Sony was indeed negligent. Class action time...

For all of you Sony apologists, here is why this is a big deal.

Lets put everything into perspective.

December 2010: failOverflow/George Hotz hack the PS3.
January 2011: Sony files a lawsuit against failOverflow and George Hotz.
February 2011: PSN's network traffic is detailed. Personal information is stored locally and sent unencrypted to Sony via PSN.
April 2011: PSN is breached.

As a credit card merchant, Sony has some obligations. As defined in the Payment Card Industry Data Security Standard (PCI DSS) Sony is supposed to do the following:

1) Build and Maintain a Secure Network
2) Protect Card holder Data
3) Maintain a Vulnerability Management Program
4) Implement Strong Access Control Measures
5) Regularly Monitor and Test Networks
6) Maintain an Information Security Policy

[en.wikipedia.org]

They failed to do this.

The biggest weakness is Sony assumed that PSN was a private network. A network between a secure PS3 and PSN. How do we know this is Sony's assumption? Because in a detailed analysis of the network transmissions between a PS3 and PSN a hacker discovered that user credit card data was transmitted to PSN unencrypted.

[pastie.org] (See line 66)

Once the PS3 was hacked, PSN became an open/public network. With credit card information being sent unencrypted, it was only a matter of time before, on a limited basis, private data would be stolen. But the fact that Sony didn't encrypt the data was in violation of the PCI DSS agreement with credit card companies.

Sony knew in January what was at stake, we know this because when they filed the lawsuit against failOverflow and George Hotz, Sony invoked the Computer Fraud and Abuse Act. The act is exclusively used by financial institutions and the government to protect against hacking of banks, atms, credit card merchants and transaction processors, or government systems. It further defined the relationship between the PS3 and PSN in such a way by implying specific provisions of the law that George Hotz broke.

I know it's easy to sit there and say every network is hackable. While that's true to some degree, some networks are more difficult to breach than others. The fact that Twitter or Gawker got hacked is meaningless compared to a company that does financial transactions. Again, the whole idea of a company that follows the PCI DSS properly is that they won't get breached. In fact, since the release of the PCI DSS no company found in compliance with the PCI DSS has been breached.

Sony knew since January that user data was at risk, but it did little to nothing to secure that data. It knew that it couldn't close the hole that was created by failOverflow and George Hotz, that cat was let out of the bag despite "assurances" from hackers that it was secure with FW 3.56. The changes Sony is making to PSN today are changes Sony should have made to PSN months ago. The fact that they didn't was either negligence or wishful thinking on their part.

If the breach was only a breach of personal information, then Sony got lucky. However, if this was a breach of financial information and Sony clearly understood what was at stake back in January, then they have to explain why for three months they did nothing to secure their customers personal and private data.
Old 04-27-11 | 01:30 AM
  #2625  
Supermallet's Avatar
Banned by request
 
Joined: Jun 2000
Posts: 54,150
Likes: 0
Received 11 Likes on 11 Posts
From: Termite Terrace
Re: The Official PS3 thread - Software bugs? We don't need no software bugs

Originally Posted by redbill
if you keep your emails, look for a receipt for adding funds to your wallet. it tells you the last 4 digits.
Found it, thanks. I was smart enough to put that on the card with a $300 credit limit. Phew.

Edit: Bunkaroo, can we get a link to that comment? I want to forward it to a friend.


Archive - Advertising - Cookie Policy - Privacy Statement - Terms of Service -

Copyright © 2026 MH Sub I, LLC dba Internet Brands. All rights reserved. Use of this site indicates your consent to the Terms of Use.