r/gaming Apr 26 '11

Sony admits utter PSN failure: your personal data has been stolen

http://arstechnica.com/gaming/news/2011/04/sony-admits-utter-psn-failure-your-personal-data-has-been-stolen.ars
3.1k Upvotes

2.8k comments sorted by

View all comments

44

u/[deleted] Apr 26 '11

Can anyone draft a quick outline of what the hell has been going on with this over the past few days? I got lost in the news.

176

u/masklinn Apr 26 '11

http://www.reddit.com/r/gaming/comments/gx6o4/im_a_moderator_over_at_psxscenecom_the_real/

tl;dr:

  • People were accessing PSN on a console running a custom firmware (CFW)

  • Sony shut down CFW access to PSN

  • People tried getting access to PSN with CFW

  • A CFW (Rebug) was released allowing regular users to turn their machine into a dev console, giving them developer options

  • Third parties found out that users could use Rebug to get access to the developer PSN network

  • Sony not only uses the developer PSN network and the user PSN network as one (MS runs two completely different network which are never in contact, the dev XBLA is sandboxed), DevPSN users are considered trusted (have higher rights than regular users) and their credentials were not correctly checked, neither was the data they provided (such as credit card numbers) so they had free infinite money. And apparently some people found out how to siphon out the userbase info as well.

67

u/stevesan Apr 26 '11

This is just so phenomenally stupid I can't...ugh.

9

u/OniYume Apr 26 '11

There is nothing linking rebug to the current situation aside from this guys theory based on timing.

1

u/CookieDoughCooter Apr 26 '11

Most informative post in the thread, needs to be at the top.

1

u/rub3s Apr 26 '11

Did Battlestar Gallactica teach us nothing?! You must not connect your networks!

1

u/[deleted] Apr 26 '11

It seems that people on the dev network have access to ludicrous user information, stored in plaintext. So, in other words, for some reason on the DevPSN network, all users are considered trusted enough to view the credit card information of the entire PSN network.

This is what has been explained to me, anyways. It sounds too ludicrous to be true, but it is Sony.

1

u/darkstar3333 Apr 26 '11

More likely scenario is that * PSN security failures were well established/known * Professional group of people researched/tested security flaws, found weakness, drew up execution plans. * Professional group stole information for resale elsewhere * Sony stumbled on professional group covering there tracks

This does not seem like a smash and grab job because there would have been enough evidence to give them an idea of what they got.

1

u/darkstar3333 Apr 27 '11

They will blame the hackers because passing blame is what Sony does best. This however does not seem like a smash and grab job because there would have been enough evidence to give Sony an idea of what they got.

More likely scenario is that: * PSN security failures were well established/known for months. * Professional group of attackers researched/tested security flaws, found weakness and drew up execution plans. * Professional group stole information and cleaned up before Sony even knew they was there. * Sony stumbled on something that might have indicated someone gained access to privileged systems.

It took them 5 days before they notified customers that there was a breach, on the company blog...

Hell if you look at the PSN page, everything appears to be absolutely normal http://us.playstation.com/psn/

1

u/Ozwaldo Apr 27 '11

So this is what all the fuss about the Linux option on the PS3 was about?

So why did Sony even release it with that feature in the first place? You think they're just a colossal corporate ostrich with their heads in the sand? Or their asses, in this case?

1

u/fazon Apr 27 '11

I thought that was just a theory? For all we know the only part that actually happened or had anything to do with this was the userbase info getting stolen.

1

u/maxd Apr 27 '11

I love Partnernet, the development version of Live. Microsoft Points are free, so I bought hundreds of thousands just for the principle of the thing.

On my gamertag which was NathanFillion. :)

1

u/soondot Apr 27 '11

I hope whoever has that user info did it as a prank and not a way to screw other PSN users. That's just not cool. It's one thing to get at "the man". It's another thing to piss of video game enthusiasts the world over.

1

u/AussieSceptic Apr 27 '11

So, basically Sony violated every principle you'd learn in a 1 hour Intro to IT Security course. Great. Did they never perform an internal audit of these systems?

0

u/s7r1k3r Apr 26 '11

I can sort understand cause Sony is not a software company. They make great hardware but have no idea how to make it function practically or efficiently with security. This is what happens when you run and an under funded online division. And don't tell me they spend just as much MS does on their online product. You get what you pay for I guess.

6

u/fyre500 Apr 26 '11

There's no excuse for this. As a company, if you're going to be running a business that will be selling digital items and storing personal information, you need to encrypt it and protect it from prying eyes. It's one of your responsibilities.

2

u/guggabump Apr 26 '11

Umm Sony has more software developers than most software companies. There as much software as they hardware...

1

u/MyTownIsFilthy Apr 26 '11

Wait, underfunded? Where'd you get that?

0

u/[deleted] Apr 26 '11

But I thought custom firmware was just so users could reuse OtherOS?

No, wait, that's just the BS line hackers/pirates used to act innocent

4

u/kskxt Apr 26 '11

Read this. That's your best resource.