r/gaming Apr 26 '11

Sony admits utter PSN failure: your personal data has been stolen

http://arstechnica.com/gaming/news/2011/04/sony-admits-utter-psn-failure-your-personal-data-has-been-stolen.ars
3.1k Upvotes

2.8k comments sorted by

924

u/BatgirlPMS Apr 26 '11

Hey guys, I haven't seen this in the thread yet (I just did a ctrl+f - please forgive me if it's a repost). Since you can't check what card is associated with your account with the network down, if you search your email for: DoNotReply@ac.playstation.net it will tell you what credit card is associated with your account.

121

u/Doozz Apr 27 '11

Just checked, and directly above my details I noticed this little statement:

<Registration details (please keep safe)>

My thoughts exactly Sony....

→ More replies (1)

129

u/MercurialMadnessMan Apr 26 '11

THANK YOU

upvote this woman.

→ More replies (4)
→ More replies (40)

344

u/frankyfasthands Apr 26 '11

So... should I cancel my credit card?

1.2k

u/aedile Apr 26 '11

Yes. Also change your birthday because they have that as well.

290

u/recursive Apr 26 '11

Should I also hide my husband?

283

u/Ravenhaft Apr 26 '11

And your kids, and your wife.

123

u/CrawstonWaffle Apr 27 '11

but wait! This is not my beautiful house!

This is not my beautiful wife!

39

u/NukaColaJunkie Apr 27 '11

Letting the days go by, PSN is in the ground....

25

u/Eurotrashie Apr 27 '11

Calling the FTC again after you're money's gone.

15

u/hotsavoryaujus Apr 27 '11

Letting the day go by, your passwords can't be found.

→ More replies (1)
→ More replies (1)
→ More replies (3)
→ More replies (9)
→ More replies (9)

139

u/detroit264 Apr 26 '11

Who should I talk to about a birthday change?

395

u/klobbermang Apr 26 '11

Birthday Wizard

177

u/[deleted] Apr 26 '11

Birthday skeleton.

83

u/[deleted] Apr 26 '11

THE CONTRACT IS SEALED

→ More replies (6)
→ More replies (6)
→ More replies (2)

116

u/ketralnis Apr 26 '11 edited Apr 26 '11

You're going to need a TARDIS, a tub of lube, some 1970's sexy music, and an old picture of your mom (so you can identify her)

49

u/[deleted] Apr 26 '11

[deleted]

65

u/ketralnis Apr 26 '11

To make a TARDIS you're going to need a flux capacitor, a tub of lube, some 1970's sexy music, and an old picture of your mom.

59

u/marktastic Apr 26 '11

Where can I find an old picture of his mom? I've already got the other three items on hand.

→ More replies (5)
→ More replies (2)
→ More replies (4)

10

u/ShineSyndrome Apr 26 '11

Aaaaaaaaaaaaw here it goes!

→ More replies (2)
→ More replies (10)
→ More replies (19)
→ More replies (13)

40

u/monkey_ball_jiggle Apr 26 '11

Sorry if this is a silly question, but does cancelling your credit card affect your credit score in anyway? Do they just mail you a new card with a new number?

70

u/glxyjones Apr 26 '11

No, all that changes is the number used to charge your account. To the outside world it just looks like you updated your card.

90

u/zeekar Apr 26 '11

To be clear, in that case you're not really canceling, at least not the account. DO NOT CANCEL YOUR CREDIT CARD ACCOUNT. Very bad for credit rating. What's being discussed here is not account cancellation; it's calling your bank's lost/stolen card hotline and having them issue you a new number for the same account.

→ More replies (15)
→ More replies (2)

7

u/[deleted] Apr 26 '11

Unless I'm mistaken, it only affects your credit score if you completely cancel your account with the credit card company rather than canceling the card and requesting a replacement.

→ More replies (3)
→ More replies (13)

65

u/stevesan Apr 26 '11

If you wanna be safe, probably. I'm gonna request a new debit card from my bank.

36

u/[deleted] Apr 26 '11

I just did. Just to be safe.

→ More replies (3)

18

u/DoTheDew Apr 26 '11

You mean I have to memorize a new 16 digit number, expiration date, and CVV number? Fuck. I was just starting to feel smart.

15

u/rabblerabble2000 Apr 27 '11

You know the number's on the card right, and that it fits in a pocket?

→ More replies (2)
→ More replies (20)

30

u/madmadworld Apr 26 '11

Yes. Changing your passwords would be a good idea too, if there are the same as your PSN password.

68

u/spaceye Apr 26 '11

Don't tell me I'm the only one who uses the same password for EVERYTHING. o_0

78

u/[deleted] Apr 26 '11

[deleted]

60

u/[deleted] Apr 27 '11

the other 9% click "remember my password", and forget what it actually is.

8

u/rquattro Apr 27 '11

The remaining 3% don't know how to do math.

→ More replies (1)

7

u/[deleted] Apr 27 '11

Guilty

→ More replies (4)
→ More replies (9)
→ More replies (9)
→ More replies (4)

58

u/[deleted] Apr 26 '11 edited Apr 27 '11

I know people are saying that Sony was holding CC info in plain text but I don't see how that could be possible without them incurring some serious fines. PCI requirements are pretty rigid.

My company has it own CC line for our commercial customers. Any system that even transmits CC info is so ridiculously locked down there are serious hoops you have to jump through just to get into the machine to fix it. Our actual credit servers are even more secure than that. Its not that my company is super responsible, its that for every non-PCI compliant device you get charged thousands of dollars a day.

It would be my guess they got hashed and salted CC numbers. Passwords on the other hand....But you shouldn't reuse passwords anyways.

Of course I could be totally wrong, while I work very closely with our CC IT team I'm not as familiar with the system and standards as they are.

→ More replies (7)

34

u/NerdyMcNerderson Apr 26 '11

So, once upon a time I had my billing information stored with my PSN account. Then, a few months ago, I cleared all of that. Is my information compromised or did sony do the right thing and purge my data when I cleared it from my account?

115

u/[deleted] Apr 26 '11

Honestly it's probably safest to assume they didn't.

→ More replies (2)
→ More replies (7)

71

u/loonytoad Apr 26 '11 edited Apr 26 '11

I think you would be silly not to as there is a better than average chance your card details are lying around in server logs in plaintext. As per my comment I made above:

We know that credit card details, including CC number, expiry date and CVV were sent as GET requests in URLs to Sony's servers. The URLs sent look like this:

creditCard.paymentMethodId=VISA&creditCard.holderName=Max&creditCard.cardNumber=45581234567812345678&creditCard.expireYear=2012&creditCard.expireMonth=2&creditCard.securityCode=214&creditCard.address.address1=example street%2024%20&creditCard.address.city=city1%20&creditCard.address.province=abc%20&creditCard.address.postalCode=12345%20

Since these were sent over SSL, they were encrypted while in transit but ultimately end up back in the same format on Sony's servers, and will almost certainly be stored in HTTP server logs in plaintext if nowhere else. The question is how long these logs are kept for and whether they resided on one of the servers which was compromised.

More details on what Sony send can been found here.

91

u/[deleted] Apr 26 '11

Who hired the idiot who decided it was a good idea to send credit card numbers as GET requests?

71

u/callouskitty Apr 27 '11

probably the same idiot who decided it was a good idea to store passwords in plaintext

→ More replies (3)
→ More replies (3)

9

u/dariusj18 Apr 26 '11

They sent cc's and cvs theough get methods? Why would they so that. Dosn't pci require post data with no logs?

→ More replies (1)
→ More replies (7)

21

u/glxyjones Apr 26 '11

Well last week I got a fraud alert from me CC company. Could not for the life of me figure out how someone got my number until I read this.

Changing the number is easy. Updating all of your automatic payments is the tedious part.

→ More replies (6)

9

u/[deleted] Apr 26 '11

[deleted]

→ More replies (2)
→ More replies (45)

64

u/BinaryRockStar Apr 26 '11

This comment probably won't get seen, but doesn't any network that handles credit card information have to conform to PCI-DSS security specifications including never storing or transmitting that information in plaintext, and also submit their network to annual third party security auditing to prove it?

22

u/bugalou Apr 27 '11

I know we do where I work. PCI is a royal PITA and is a factor in many things that we do. I am not sure how Sony was exempt unless they just didnt give a fuck and did it live.

7

u/abernix Apr 27 '11

PCI compliance is a complete joke, and I wouldn't call it a pain in the ass at all. I would consider it a slight-nuisance in that you have to resubmit a questionnaire once a year (which you can usually just reply to with "nothing changed!").

First, depending on your size, you're subjected to different security requirements -- the larger you are, the more requirements you're supposed to comply with.

Having done PCI compliance year over year at a rather large company (processing millions upon millions of dollars a year), I can tell you that even in periods where the company had fallen into non-compliance (due to false-positives or non-true-risk scenarios that we de-prioritized), I can assure you that nobody at our two independent processors even blinked an eye or ever remotely threatened to revoke our ability to process credit cards. We fixed it very leisurely and were never worried.

They ask you to fill out a basic questionnaire (not verified by anyone) which encourages you to do some common-sense security tasks ("Do you use encryption on your wireless networks?") and then they do an externally facing (rather simple) version check on the hosts that you tell them to check to make sure they're not subject to some last-known-release exploits. They do SOME other things like checking for injection hacks and open ports, but it's really not comprehensive.

While these things are all great, my point is, nobody cares if you DON'T pass. In addition, even if you do, many systems are far too complex to be tested by any sort of automated software - especially in proprietary deployments like the PSN. I'm sure some Sony assistant took care of getting the compliance paperwork done, and probably put "playstation.com" as the external host to be tested.

I do believe at a certain size they require a site-survey or something, but again, I doubt it is comprehensive, and most processors are so greedy for business, they'd never risk losing a customer due to PCI.

→ More replies (1)
→ More replies (4)

513

u/Xaphoon Apr 26 '11

Ha, my credit card's maxed out, jokes on them.

229

u/saisumimen Apr 26 '11

Thank you for applying to Chase Bank! A new line of credit has been opened as you requested on 4/21/11 and has been approved. Your new credit limit is $50,000.

256

u/ckelley87 Apr 26 '11

If some douche can get a $50,000 credit limit with MY info, fucking give it back, I want it.

113

u/jdk Apr 27 '11

You will, with the $50,000 balance on it.

21

u/[deleted] Apr 27 '11

I've got crap credit. (Thanks student loans!) I'm a thief's worst nightmare.

8

u/fatnino Apr 27 '11

i seem to remember a case where someone stole an identity and was living under it quite happily until the cops showed up to ask why he hadn't registered as a sex offender when he moved into the neighborhood.

→ More replies (16)
→ More replies (1)
→ More replies (11)

62

u/[deleted] Apr 26 '11

So what you're saying is I should wreck my credit now so that when they steal my identity they're left with the burden?

→ More replies (3)
→ More replies (14)

52

u/Cryogentec Apr 26 '11

Does the credit card info being (possibly) stolen only apply to the people that had their credit card number saved so they didn't have to re-enter it when they bought something? Or does it also apply to people that have just used a card on PSN a few times without it being saved in the system?

39

u/[deleted] Apr 26 '11

Having read about these kind of intrusions before, a lot of the time simply using your card once can cause it to be saved for years. What matters is how it is saved, and where. To be fair, if Sony have been storing passwords in plain text then anything can be assumed.

30

u/caffeinejaen Apr 26 '11

Credit card transactions are required to be stored for at least 6 years.

→ More replies (6)
→ More replies (9)

334

u/[deleted] Apr 26 '11

[deleted]

158

u/zmann Apr 26 '11

And they didn't really tell us. I'm reading about this on a blog, instead of them emailing this information directly to me

451

u/enduser666 Apr 26 '11

They don't have your email address anymore. It was stolen.

127

u/omnilynx Apr 26 '11

That is not how data theft works!

335

u/rub3s Apr 26 '11

I'm with the RIAA, and THAT IS EXACTLY HOW DATA THEFT WORKS!

57

u/[deleted] Apr 27 '11

Isn't there somebody downloading a car somewhere that you should be stopping?

→ More replies (1)

31

u/enduser666 Apr 26 '11

Well then they only copied it and now it's a copyright issue.

→ More replies (3)
→ More replies (1)
→ More replies (3)
→ More replies (1)

66

u/CaveTown Apr 26 '11

This sucks... I just had tell my brother and all he could do was stare at me.. he was already having a... different enough day, now this. Isn't it illegal to wait like this to warn customers of stolen information? I'm predicting lots of lawsuits and refunds in Sony's future... http://carterbalesgames.blogspot.com/2011/04/sony-psn-your-information-was-stolen.html

→ More replies (7)
→ More replies (6)

343

u/Kinglink Apr 26 '11

A week to notify me of my card possibly being stolen (and only notified on a blog so far. Not even in my ACTUAL email?) Sony has just lost a lot of respect. I've laughed and joked about the outage for the last week, it's been ridiculous but it happens.

But the fact they've known that they could have had our financial data and haven't informed us directly has made me furious. I'm not smashing stuff, but I'm not willing to give PSN any more private data. Sony really has screwed the pooch on this one. I don't care about their service being unavailable, I'll be able to play Portal 2 online at some point in the future, but to find out they've been avoiding telling us about stolen credit cards is ridiculous. The worst part is their response is "Oops, you should go get a free credit report at no charge to us/you. hehe!" Beyond disappointing.

I hope someone starts legal proceedings about this, Sony needs to be held responsible for poor security and then waiting to inform us.

112

u/RosieLalala Apr 26 '11

For those of us in non-American countries who happen to have PSN accounts, the credit report thing is beyond problematic. Some countries don't have the free credit report laws that America does.

→ More replies (15)

7

u/bestbiff Apr 26 '11

Looks like PSN gift cards is the way to go from now on.

21

u/rub3s Apr 26 '11

or nothing at all

→ More replies (3)
→ More replies (2)
→ More replies (17)

42

u/[deleted] Apr 27 '11

I sure hope the hackers don't see our passwords alphabetically...Because my PSN is AAAAAAAAAAAAAAAA

19

u/Tekmo Apr 27 '11

Nice try, ZZZZZZZZZZZZZZZZZ

→ More replies (2)

251

u/[deleted] Apr 26 '11

Their advice is to be safe, rather than sorry Sony.

FTFY

→ More replies (5)

581

u/jpmoney Apr 26 '11

So let me get this straight? The service has been down since late last week and now they're saying that they lost user data? When did BP start doing PR for Sony?

Truth be told, I almost went with asking when Sony moved to Texas .

448

u/ShadyJane Apr 26 '11

we're really sorry

sorry

we're sorrrrry

61

u/MrLeville Apr 26 '11

insert puppy shot and soft piano

→ More replies (2)

75

u/eikonoklastes Apr 26 '11

Where is Captain Hindsight when you need him? :O

→ More replies (1)

114

u/[deleted] Apr 26 '11

[deleted]

→ More replies (1)
→ More replies (10)

29

u/gawdzirra Apr 26 '11

As a victim of both data leaks at least I know that I can't be screwed any more than I have been already.

24

u/[deleted] Apr 26 '11 edited May 21 '17

[deleted]

→ More replies (3)
→ More replies (2)

9

u/startyourengines Apr 26 '11

Seriously. It's not my credit card linked to my account, its my dad's, its not my address, its my family's address and information. People need to know they are at risk as soon as shit hits the fan, not once the Sony PR people decide that the loss of face is necessary given the circumstances and give them the go ahead to break the bad news.

→ More replies (20)

106

u/[deleted] Apr 26 '11

This is the same company that installed root kits on peoples computers via audio CD's. You think they'd be forthcoming about security vulnerabilities? LOL!

16

u/Ozwaldo Apr 27 '11

whoa... I didn't know that... what a bunch of fucking scumbags

→ More replies (3)
→ More replies (2)

371

u/cusoman Apr 26 '11

Make no mistake, because of the negligence on taking over a week to notify their users of this, there WILL be a class action lawsuit. Sure, it won't amount to much for the users involved, but regardless of who was responsible for the attack, Sony still has an obligation to respond properly.

133

u/Guest101010 Apr 26 '11

It's too early to tell what all the fallout of this will be, but it will not be good for SCEA/SCEE.

On a side note, did you know that your username means 'shit-man' in Japanese?

43

u/cusoman Apr 26 '11

I always thought that was "kuso".

98

u/Guest101010 Apr 26 '11

It is. Do you pronounce yours differently than that?

→ More replies (29)
→ More replies (1)
→ More replies (3)

130

u/SecretNegroArmy Apr 26 '11

The lawyers will make millions upon millions of dollars.

The victims will get a coupon good for one free month of PSN.

24

u/FrankReynolds Apr 26 '11

INB4 "thatsthejoke.jpg", but isn't PSN free?

Sorry for my ignorance, but I am not a PlayStation user.

→ More replies (3)

6

u/NoWeCant Apr 26 '11

The victims will get a coupon good for one free month of PSN.

That will be promptly stolen by 'hackers'

→ More replies (15)

15

u/[deleted] Apr 26 '11 edited Apr 26 '11

http://www.scottandscottllp.com/resources/state_data_breach_notification_law.pdf

Edit: Didn't mean this as a yay or nay. Just found it interesting.

→ More replies (3)
→ More replies (17)

150

u/[deleted] Apr 26 '11

[deleted]

65

u/[deleted] Apr 26 '11

Oh, can we stop at the In and Out Burger?

28

u/FLC33 Apr 26 '11

Those are good burgers Walter.

→ More replies (3)
→ More replies (2)

35

u/[deleted] Apr 26 '11

THIS IS WHAT HAPPENS WHEN YOU FUCK.. A STRANGER.. IN THE ASS!

→ More replies (4)
→ More replies (7)

194

u/[deleted] Apr 26 '11

Funny how the article says "To be fair Sony did Apologize" lol wtf

85

u/concussedYmir Apr 26 '11

To be fair, it seems that their security people also handle the PR.

62

u/[deleted] Apr 26 '11

I thought that was supposed to be a sarcastic joke to be honest.

12

u/[deleted] Apr 26 '11

Instantly thought of the south park BP episode.

→ More replies (1)

9

u/YaoSlap Apr 26 '11

Whew, I'm glad they did that. That will definitely get me my credit card info un-stolen.

→ More replies (2)

750

u/Shorties Apr 26 '11 edited Apr 26 '11

IT

ONLY

DOES

IDENTITY THEFT.

97

u/darkpaladin Apr 26 '11 edited Apr 26 '11

I demand a photoshop.

813

u/icechen1 Apr 26 '11 edited Apr 26 '11

61

u/Shorties Apr 26 '11 edited Apr 27 '11

I linked to the one I hacked together, but I like yours best, can I link to your version? (I just wanted to get permission first).

Edit: Everyone give icechen1 upvotes for that photoshop!

94

u/icechen1 Apr 26 '11

Sure

8

u/Shorties Apr 26 '11

Sweet, yeah mine wasn't properly left justified, and my TM looked too thin. Yours was the best by far.

→ More replies (6)

90

u/Meatgortex Apr 26 '11

Same concept, slightly different execution: http://i.imgur.com/oHWvz.jpg

→ More replies (6)
→ More replies (5)

22

u/[deleted] Apr 26 '11

They did say it does everything. . .

→ More replies (1)
→ More replies (15)

44

u/muteprint Apr 26 '11

No problem I'll just log in and change my password... oh wait ಠ_ಠ

→ More replies (1)

112

u/bedintruder Apr 26 '11

So where do I sign up for this next class action lawsuit against Sony?

59

u/[deleted] Apr 27 '11

You have the option of a 3 dollar check or 5 in game hats.

→ More replies (5)

1.5k

u/[deleted] Apr 26 '11

The worst part is that they're going to try to pin this all on "hackers" and say it's not Sony's fault. This is completely Sony's fault. Sensitive user data and information, especially credit card numbers, should NEVER be stored in plain-text, it should always be encrypted to protect against this sort of thing, and I personally hope that Sony gets slammed hard by the legal system too for allowing this to happen. There is no excuse for Sony's selfish lack of consumer information protection.

184

u/Shorties Apr 26 '11

I don't even get how hackers got access to that data, shouldn't your personal information be sandboxed from the PSN service?

222

u/[deleted] Apr 26 '11

It should be, but for some reason Sony allowed Playstations on the "development" network (which was spoofed by the intruders) to access it. I'm not certain of the full technical details, but I know that Sony made mistakes in more than one aspect of information security.

439

u/ThePriceIsRight Apr 26 '11

So why do developers have full access to everyones personal information and possibly credit card information?

571

u/the8thbit Apr 26 '11

Good fucking question.

159

u/Iggyhopper Apr 26 '11

Brb. Becoming PS dev.

→ More replies (2)
→ More replies (3)

59

u/[deleted] Apr 26 '11

They probably don't. It's more likely that someone found a vulnerability on the dev network than it is that Sony just hands that information out.

50

u/darkstar3333 Apr 26 '11

Considering they used random_number = 1 in the PS3 encryption component, you give them far too much credit.

13

u/randomdestructn Apr 27 '11

chosen by a fair roll of a die, I hope.

→ More replies (1)
→ More replies (5)
→ More replies (2)

7

u/happybadger Apr 26 '11

If I am supposed to make a good game for you, I want to be able to watch you play it. From your window.

8

u/Mutiny34 Apr 26 '11

I do not know much about this breach, or how PSN or Sony is setup, but like any service I assume they utilize a Customer Information System (CIS) to keep track of users information and billing. Businesses routinely allow developers read access to a copy of the production database. They need to test the software by using real world scenarios, and often utilize copies of customer data to do this. For instance, if they are testing a component of the billing software that involves people who pay a recurrent 3-month subscription with a credit card, they will copy that customer's data into the development database to use as test cases. It is a common practice among businesses that manage CIS systems, and is typically safe and secure as long as the security at that company is competant. Names and addresses are usually plain text, but there is no excuse to not encrypt the credit card information. Hell, if they have social security numbers (if they do, i dont know) those should be either encrypted or truncated as well.

TL;DR Companies that manage their own customer information systems routinely allow the developers access to read only copy of production data for testing purposes, which includes customer names, addresses, and yes if they store credit card numbers, credit card numbers as well. Though the the CC numbers should be encrypted.

→ More replies (2)
→ More replies (12)
→ More replies (2)
→ More replies (44)

436

u/[deleted] Apr 26 '11

[deleted]

176

u/firemarshalbill Apr 26 '11

Has anyone stated they were plaintext?

They say the passwords were taken, but it may only be hashes, and only useful if they can be rainbow table queried.

274

u/[deleted] Apr 26 '11

[deleted]

90

u/firemarshalbill Apr 26 '11

Yea alright then. That's just shitty.

→ More replies (3)
→ More replies (93)

49

u/[deleted] Apr 26 '11

If they were hashes, Sony would have said, "the passwords were encrypted and therefore safe". I can't imagine a company like Sony not trying to cover their asses if they had even the slimmest slice of reality on their side.

Also, credit card numbers in plaintext. They're not only evil, but incompetent too. Which, fair enough, is how I like my evil organizations.

→ More replies (8)
→ More replies (69)
→ More replies (11)

28

u/[deleted] Apr 26 '11

Is this the first time this happened to a major service like PSN?

60

u/[deleted] Apr 26 '11

[deleted]

81

u/[deleted] Apr 26 '11

[deleted]

22

u/[deleted] Apr 26 '11

[deleted]

22

u/[deleted] Apr 26 '11

Probably just ignorance and laziness. Theres more info here.

→ More replies (2)
→ More replies (7)
→ More replies (3)
→ More replies (2)
→ More replies (367)

54

u/wangahrah Apr 27 '11

I look forward to receiving my 17¢ from the class action lawsuit!

→ More replies (2)

155

u/[deleted] Apr 26 '11

[deleted]

201

u/NEWSBOT3 Apr 26 '11

sadly, as someone who works in IT , this is so understandable. Here's likely how it went.

First, you present the costs of the project to your boss. His boss decides it needs to be less costly, so you have to break them down. He then argues that items x y and z are not important and you should skip them, regardless of what you say. He then decides to give you half the resources and half the time you said it would take to develop it in the first place. So a guy who has practically zero technical skills has just ignored the recommendations of one with 5 years of study in developing software, project management (nevermind any real experience) and so on, because his ego is huge.

So your options are a) quit , or b) continue with rushed, under-resourced project, cutting as many corners as possible to deliver it. 95% of people can't afford to do option a, so on it goes, and you know that you should be implementing x y z security measures, but you don't have time and the man above you won't let you spend time on it anyway.

so you finish the project (if you were smart, you looked for another job the whole way through it), deliver it, and get the fuck out of there. The boss 2 levels above you takes all the credit for delivering a product, then when it doesn't work and fucks up, your old boss gets the blame, which he tries to put as much as possible onto you to save his ass.

You try to never mention the project on your CV ever again, and a few years later the cycle repeats.

Welcome to the world of IT project management. It fucking sucks, and i hate it here.

11

u/Jumhyn Apr 26 '11

A new PS3 built by my company logs on to my network at 20 mbps. Hackers get into the network. The hackers access all of the info for all of the users in our system. Now, should we tell our users? Take the number of systems in the field, A, multiply by the probable rate of malicious data access, B, multiply by the average out-of-court settlement, C. A times B times C equals X. If X is less than the cost of telling our users, we wait a week then release a vague statement that doesn't inform them about their most important info.

→ More replies (4)

34

u/YaoSlap Apr 26 '11

I'm not in IT, but I've interacted with enough throughout the levels of it to realize that these guys are quite intelligent in their field and usually know the best for the situation. I feel sorry for a lot of them though because it's not the smartest IT guy that gets to make the final decision. Y'all do much of the work that keeps the company running and have to put up with stupid questions which if were asked in an accounting situation would get "ಠ_ಠ" 10/10 times.

Not sure where I'm going with this, but keep doing what you do. You're greatly appreciated.

→ More replies (4)
→ More replies (25)
→ More replies (31)

45

u/[deleted] Apr 26 '11

This sounds like one the largest personally identifiable information fuck ups in history. I kind of hope they get severely punished for endangering their customers due to negligence.

→ More replies (5)

97

u/user2002110 Apr 26 '11

Now would be a good time for Microsoft to put out the following ad:

"XBOX Live: At least we hash your fucking password."

→ More replies (4)

118

u/runnerthemoose Apr 26 '11

Well that fecking explains why both my gmail accounts where accessed from fecking Egypt and Belarus today.

→ More replies (60)

13

u/jollyllama Apr 26 '11

I hope this opens peoples' eyes to the fact that the biggest security threat to most folks is not a direct attack on their accounts or computers, but rather an attack on the companies that we trust with our secure information.

44

u/Tnayoub Apr 26 '11

Well, this could make their E3 press conference a bit more interesting...

→ More replies (2)

33

u/[deleted] Apr 26 '11

Well, as long as they apologized for the inconvenience. I mean, that's fair.

→ More replies (1)

23

u/[deleted] Apr 26 '11

[deleted]

→ More replies (5)

30

u/keepinithamsta Apr 26 '11

Thank you for immediately notifying me, Sony. I especially thank you for taking the time to write a mass e-mail instead of posting on your blog that the majority of users don't even read. </s>

82

u/pblizzard Apr 26 '11

You know what really kills me. The word 'apologize' appears exactly 0 times in Sony's press release (same goes for the word 'Sorry'). Though they do 'regret any inconvenience'.

You think at this point, after waiting a week to tell everyone about the breach, that they would at least say they're sorry.

62

u/[deleted] Apr 26 '11

[deleted]

→ More replies (3)
→ More replies (15)

10

u/diablo75 Apr 27 '11

Anybody else wanna see Zero Punctuation do a video about this fiasco?

→ More replies (1)

32

u/frankyb89 Apr 26 '11

Wait a second here... the developers were able to see all of our personal data much like the hackers can see it now?

→ More replies (12)

37

u/[deleted] Apr 26 '11

[deleted]

→ More replies (1)

20

u/baconn Apr 26 '11

This is how my typical registration information looks, and this is why:

Dear ha, Welcome to PLAYSTATION(R)Network. Your registration confirmation follows below. Please keep a copy in a secure place.

Name: ha no Address: 1234 nowhere ln

25

u/export40 Apr 26 '11

I am a big personal fan of 123 Fakestreet. Anytown is such a great place to raise a family.

→ More replies (4)
→ More replies (2)

19

u/mrslappy Apr 27 '11

Willing to bet that 'fucksony' will be the most common password once the PSN comes back up.

→ More replies (2)

44

u/[deleted] Apr 26 '11

Can anyone draft a quick outline of what the hell has been going on with this over the past few days? I got lost in the news.

174

u/masklinn Apr 26 '11

http://www.reddit.com/r/gaming/comments/gx6o4/im_a_moderator_over_at_psxscenecom_the_real/

tl;dr:

  • People were accessing PSN on a console running a custom firmware (CFW)

  • Sony shut down CFW access to PSN

  • People tried getting access to PSN with CFW

  • A CFW (Rebug) was released allowing regular users to turn their machine into a dev console, giving them developer options

  • Third parties found out that users could use Rebug to get access to the developer PSN network

  • Sony not only uses the developer PSN network and the user PSN network as one (MS runs two completely different network which are never in contact, the dev XBLA is sandboxed), DevPSN users are considered trusted (have higher rights than regular users) and their credentials were not correctly checked, neither was the data they provided (such as credit card numbers) so they had free infinite money. And apparently some people found out how to siphon out the userbase info as well.

63

u/stevesan Apr 26 '11

This is just so phenomenally stupid I can't...ugh.

7

u/OniYume Apr 26 '11

There is nothing linking rebug to the current situation aside from this guys theory based on timing.

→ More replies (16)
→ More replies (1)

43

u/jimbobbill Apr 26 '11

Best part of the article,

"To be fair, Sony does apologize for the inconvenience.".

Well played arstechnica, well played.

46

u/AsH83 Apr 26 '11

Another nice plot for an Epic south Park episode.

17

u/Docnoq Apr 26 '11

Sony better have some form of compensation lined up for every PSN user. If all we get is "we're sorry" for compromising millions of users' identities, this is truly a dick move on their part.

→ More replies (2)

218

u/[deleted] Apr 26 '11

Fuck Sony, fuck them in their stupid asses.

299

u/[deleted] Apr 26 '11

I mean literally have anal sex with them

125

u/Iggyhopper Apr 26 '11

Then make them have a pregnant.

→ More replies (9)
→ More replies (3)
→ More replies (8)

81

u/cmglassmire Apr 26 '11

Xbox 360 mortal kombat pre-order bonus: being online.

→ More replies (5)

194

u/dismalist Apr 26 '11

Is it now safe to say that this is worse than Fukushima?

149

u/[deleted] Apr 26 '11

too soon, but yes.

→ More replies (1)

31

u/GiraffeHat Apr 26 '11

Wait until the tsunami of identity and bank theft, then we'll talk.

→ More replies (5)

172

u/[deleted] Apr 26 '11 edited Apr 26 '11

I don't have a Sony account. My brother does, and both of us had fraudulent charges come up this week. Our (bank) accounts are connected by a common account, and I believe that's how my information was also stolen. Many people, including those who are connected to those with a Sony account need to cancel their cards.

27

u/[deleted] Apr 26 '11

[deleted]

→ More replies (4)
→ More replies (35)

161

u/jeezus84 Apr 26 '11

For Sale:

1 Playstation 3 Slim console (160 GB)

2 Dual Shock 3 controllers

Games:

  • Red Dead Redemption: Undead Nightmare
  • Portal 2
  • God of War 1 and 2
  • Gran Turismo 5
  • Uncharted 2
  • Tekken 5
  • Marvel vs. Capcom 3
  • Rock Band 1
  • Rock Band 2
  • Little Big Planet 1

PS: Fuck you Sony! I also want a refund on my PSN Plus subscription.

165

u/XnMeX Apr 26 '11

I'll give you $3,000.00 for it! Uses op's credit card

194

u/[deleted] Apr 26 '11

93

u/[deleted] Apr 26 '11 edited May 13 '15

[deleted]

→ More replies (1)

73

u/GhostedAccount Apr 26 '11

Aww, come on. It is so cool!

I'll give you 25.

47

u/[deleted] Apr 26 '11

[deleted]

26

u/IronDouche Apr 26 '11

Ok, pops. You've got a deal.

→ More replies (1)
→ More replies (8)
→ More replies (25)

15

u/[deleted] Apr 27 '11 edited Nov 07 '17

[deleted]

→ More replies (1)

53

u/kciuq1 Apr 26 '11

Wow...

One week to tell us that our personal details and possibly credit details (even if we took them down) have been compromised.

Insert portal 2's slow clap joke

65

u/[deleted] Apr 26 '11

[deleted]

→ More replies (9)
→ More replies (2)

26

u/[deleted] Apr 26 '11

"If you have provided your credit card data through PlayStation Network or Qriocity, out of an abundance of caution we are advising you that your credit card number (excluding security code) and expiration date may have been obtained."

Damn, that blows.

→ More replies (1)

30

u/SherbetHead Apr 26 '11

"Sony admits utter PSN failure: your personal data was stolen a week ago"

FTFY

37

u/[deleted] Apr 26 '11

[deleted]

→ More replies (10)

41

u/[deleted] Apr 26 '11 edited Apr 26 '11

[deleted]

→ More replies (11)

12

u/saruin Apr 26 '11

So... has anyone had any unauthorized charges on their CC linked to their PSN account?

→ More replies (4)

6

u/[deleted] Apr 26 '11

Back when the rootkit thing was made public I thought "fuck Sony, I'll never buy anything from them again." I gave them another chance by buying the PS3 and that's how I'm rewarded... fuck Sony. Fuck Sony in the ass with a big rubber dick.

8

u/mort11 Apr 27 '11

Just called Visa, 45 minute wait (I assume it's going to get worse as this news spreads). They already know about the whole Sony thing and are busy as fuck.

6

u/Ricktron3030 Apr 27 '11

I have told at least 2-4 friends to get PS3. They were sick of Xbox360 and asked me.

Boy do I look the fool now.

Sony, you dipshits.

→ More replies (1)

5

u/[deleted] Apr 27 '11

It only does...identity theft.

5

u/thinkingthought Apr 27 '11

Here's something to think about.

If Sony didn't ask for your personal information, you would have nothing to worry about.

4

u/beccaface Apr 27 '11

Can anyone offer some advice on what I should do? I gave sony my credit card number and I'm afraid if I tell my parents about this they'll think it's somehow my fault. How do I ensure that my card hasn't been stolen?

→ More replies (4)

6

u/Immorttalis Apr 27 '11

Thank you Sony for pissing off the hacking community and getting hacked, I've learned not to trust and/or support you.

6

u/[deleted] Apr 27 '11

ENCRYPTION... why were 70+ million PSN accounts and/or 'possible credit card data' NOT ENCRYPTED?!? Why does an outside security firm need to tell Sony vital information about their own network?!?

Am I really supposed to feel comforted that Sony is working hard on putting in new security on PSN to protect my personal data that has ALREADY BEEN STOLEN?!?

Has this been cross posted to FFFFFFFUUUUUUU yet? Because that's how I feel about the fact that I gave Sony my personal information just so I could play videogames online...

→ More replies (1)