The Official PS3 thread - Aaaaannnnnnddddd we're back!

Subscribe
12  62  102  110  111  112  113  114  122  162 
Page 112 of 189
Go to
Re: The Official PS3 thread - Encryption? We don't need no stinkin' encryption.
Not the Facebook games!
Reply
Re: The Official PS3 thread - Encryption? We don't need no stinkin' encryption.
lol. sony. i'd just give up at this point.
Reply
Re: The Official PS3 thread - Encryption? We don't need no stinkin' encryption.
Quote: The smart move would be to just drop $10-15 in everyone's wallets.
I hear that's the plan. There will be an option to enter your bank account info when PSN comes back online in order to receive a direct deposit of the compensatory funds.
Reply
Re: The Official PS3 thread - Encryption? We don't need no stinkin' encryption.
Quote: Sony can't win:

http://www.joystiq.com/2011/05/02/so...ring-an-issue/
Oh, it got worse.

Quote:
Following up on this morning's news that Sony Online Entertainment servers were offline across the board, Sony Online Entertainment announced that it has lost 12,700 customer credit card numbers as the result of an attack, and roughly 24.6 million accounts may have been breached.

The company took SOE servers offline after learning of the attack last evening, and today detailed the unfortunate results: "approximately 12,700 non-US credit or debit card numbers and expiration dates (but not credit card security codes), and about 10,700 direct debit records of certain customers in Austria, Germany, the Netherlands, and Spain" were lost, apparently from "an outdated database from 2007." Of the 12,700 total, 4,300 are alleged to be from Japan, while the remainder come from the aforementioned four European countries.

Furthermore, Sony ties today's announcement directly to the recent attacks on PlayStation Network and Qriocity, with Sony saying SOE customer information was stolen on either April 16 or April 17. Sony has repeatedly stated that its PSN servers and SOE servers are not part of the same network, so it remains unclear just how these two attacks are tied together. Head past the break for the full statement from Sony.
http://www.joystiq.com/2011/05/02/so...redit-card-nu/


Reply
Re: The Official PS3 thread - Encryption? We don't need no stinkin' encryption.
We can get bin Laden, but can't catch these douchbags?
Reply
Re: The Official PS3 thread - Encryption? We don't need no stinkin' encryption.
Quote: We can get bin Laden, but can't catch these douchbags?
We will in ten years.
Reply
Re: The Official PS3 thread - Encryption? We don't need no stinkin' encryption.
Quote: Oh, it got worse.



http://www.joystiq.com/2011/05/02/so...redit-card-nu/


Yikes. Now I'm really glad I cancelled my Debit Card last week.
Reply
Re: The Official PS3 thread - Encryption? We don't need no stinkin' encryption.
Quote: Yikes. Now I'm really glad I cancelled my Debit Card last week.
Well, also keep in mind that this is S.O.E. the developers behind several MMO games, like DC Universe Online. It's separate from PSN, so if you never subscribed to one of their games, they won't have your info.

Still though, 2 branches of Sony infiltrated within a month, one may have credit card info stolen, the other definitely has CC info stolen. Both have personal info of users stolen.

Not a good month for Sony.
Reply
Re: The Official PS3 thread - Encryption? We don't need no stinkin' encryption.
This is going to hurt sony pretty bad. I think the ps3 may make it out, but those mmo's are going to lose a lot of people because of this, monthly subs are their only way to make money after they have sold the product.
Reply
Re: The Official PS3 thread - Encryption? We don't need no stinkin' encryption.
Quote: We can get bin Laden, but can't catch these douchbags?
We only got him because all his personal information was stolen off the PSN.
Reply
Re: The Official PS3 thread - Encryption? We don't need no stinkin' encryption.
Quote: We only got him because all his personal information was stolen off the PSN.
I thought it was Apple tracking him on his iPhone 4 (White)
Reply
Re: The Official PS3 thread - Encryption? We don't need no stinkin' encryption.
Let's see that douche ad guy make a sarcastic commercial about this. What a colossal fuck up and the way they handled it is even worse. I wish I had gotten MK for the 360.
Reply
Re: The Official PS3 thread - Encryption? We don't need no stinkin' encryption.
Quote: I thought it was Apple tracking him on his iPhone 4 (White)
He must not have read the user agreement.
Reply
Re: The Official PS3 thread - Encryption? We don't need no stinkin' encryption.
Quote: He must not have read the user agreement.
Who agrees to something they didn't read!?
Reply
Re: The Official PS3 thread - Encryption? We don't need no stinkin' encryption.
To the point addressed in our new thread title:

Quote: PlayStation Network Security Update

+ Posted by Patrick Seybold // Sr. Director, Corporate Communications & Social Media

On Tuesday, April 26 we shared that some information that was compromised in connection with an illegal and unauthorized intrusion into our network. Once again, we’d like to apologize to the many users who were inconvenienced and worried about this situation.

We want to state this again given the increase in speculation about credit card information being used fraudulently. One report indicated that a group tried to sell millions of credit card numbers back to Sony. To my knowledge there is no truth to this report of a list, or that Sony was offered an opportunity to purchase the list.

One other point to clarify is from this weekend’s press conference. While the passwords that were stored were not “encrypted,” they were transformed using a cryptographic hash function. There is a difference between these two types of security measures which is why we said the passwords had not been encrypted. But I want to be very clear that the passwords were not stored in our database in cleartext form. For a description of the difference between encryption and hashing, follow this link.
I'm certainly not up on this sort of thing at all, but it seems like maybe security wasn't as lax as we all are lead to believe.
Reply
Re: The Official PS3 thread - Encryption? We don't need no stinkin' encryption.
That is the point that confused me. I couldn't imagine store passwords in plain text. In some of the systems I support you can get to the passwd file but they look like: $1$mam19$4tEbpV6TPNAqeBdFKJkXi1$-1. I probably would have called that encrypted, but I'm guessing encrypted means its stored non-ascii perhaps.
Reply
Re: The Official PS3 thread - Encryption? We don't need no stinkin' encryption.
Yeah, hashing is more heavily used now. Encryption is good if you want to be able to decrypt. With a hash key, a good one, you won't be able to decipher the data.
Reply
Re: The Official PS3 thread - Encryption? We don't need no stinkin' encryption.
Yeah, you don't want to decrypt. You want to see that the hashes match.
Reply
Re: The Official PS3 thread - Encryption? We don't need no stinkin' encryption.
So if our personal data was actually well-protected, do we think that the info is actually still safe? Why isn't this a bigger story? I only found it in the Playstation Blog. Why isn't it being reported in Joystiq, Kotaku, etc?

Instead we get articles like this Canadian one that repeatedly criticizes Sony's practices, then briefly acknowledges that the data was hashed and that might have been adequate protection. Is encryption always safe? It seems disingenuous to rail on them if they might have actually been as diligent as we could have expected.
Reply
Re: The Official PS3 thread - Encryption? We don't need no stinkin' encryption.
Woke up this morning to find my bank account was in the negative. Three charges to some international company all for the same amount went through and according to the bank more were pending. So they're re-issuing me new cards and reversing the transactions. Didn't think Sony had my cc info but then I remembered I've used it to purchase several games on the PSN store over the past few months.
Reply
Re: The Official PS3 thread - Encryption? We don't need no stinkin' encryption.
Quote: Woke up this morning to find my bank account was in the negative. Three charges to some international company all for the same amount went through and according to the bank more were pending. So they're re-issuing me new cards and reversing the transactions. Didn't think Sony had my cc info but then I remembered I've used it to purchase several games on the PSN store over the past few months.
Man that sucks.

So the card you used on PSN, you kept active? Up until the bank cancelling it of course.

I'm still waiting for my new card to show up in the mail. Cancelled my old card last week.
Reply
Re: The Official PS3 thread - Encryption? We don't need no stinkin' encryption.
Quote: Woke up this morning to find my bank account was in the negative. Three charges to some international company all for the same amount went through and according to the bank more were pending. So they're re-issuing me new cards and reversing the transactions. Didn't think Sony had my cc info but then I remembered I've used it to purchase several games on the PSN store over the past few months.
That sucks. Sorry. Did you play any SOE games or were you only PSN purchases?
Reply
Re: The Official PS3 thread - Encryption? We don't need no stinkin' encryption.
Quote: That sucks. Sorry. Did you play any SOE games or were you only PSN purchases?
It was only PSN purchases. I did have an SOE account long time ago when I played games like Everquest and Star Wars Galaxies but the card I used then is long gone.
Reply
Re: The Official PS3 thread - Encryption? We don't need no stinkin' encryption.
Quote: Man that sucks.

So the card you used on PSN, you kept active? Up until the bank cancelling it of course.

I'm still waiting for my new card to show up in the mail. Cancelled my old card last week.
Yeah, I kept my card active and it was the same one I used to make PSN purchases. I probably should have canceled it last week but like I said I forgot about the games I purchased.
Reply
Re: The Official PS3 thread - Encryption? We don't need no stinkin' encryption.
Well one good thing about a new card for me is that I can use all those Redbox 1 use per card free rental codes again :P
Reply
12  62  102  110  111  112  113  114  122  162 
Page 112 of 189
Go to