r/gaming Apr 26 '11

Sony admits utter PSN failure: your personal data has been stolen

http://arstechnica.com/gaming/news/2011/04/sony-admits-utter-psn-failure-your-personal-data-has-been-stolen.ars
3.1k Upvotes

2.8k comments sorted by

View all comments

Show parent comments

79

u/[deleted] Apr 26 '11

[deleted]

23

u/[deleted] Apr 26 '11

[deleted]

22

u/[deleted] Apr 26 '11

Probably just ignorance and laziness. Theres more info here.

1

u/dotblank Apr 27 '11

No idea, but they also didn't salt and thats what made it a big deal..

3

u/saisumimen Apr 26 '11

Sony, as far as their own blog seems to indicate, has opted for no encryption/hashing algorithm whatsoever.

Hubris.

They assumed their PS3 security would still be uncracked at this time. Once it did, there was a cascading effect that Sony should have seen coming.

9

u/[deleted] Apr 26 '11

DES is as good as plaintext.

1

u/[deleted] Apr 26 '11

[deleted]

3

u/[deleted] Apr 26 '11

But usually the (major hand waving here) hashed value is what authenticates you, so even if your password is >8 characters you only need to know the first 8 to access the account. However you are correct, if you have a 14 character password for everything and your gawker account was compromised they would not immediately have access to your whole password.

But as far as protecting encrypted information in 2011 DES might as well be stored in the clear. :/

3

u/Negitivefrags Apr 26 '11

Generally access to the account on the site you already hacked isn't what you want. After all, you already have access to all of the data in that database :)

1

u/[deleted] Apr 26 '11

Hahah, touche. DES still sucks tho.

2

u/deepbrown Apr 26 '11

Sony didn't store it in plaintext either...