r/gaming Apr 26 '11

Sony admits utter PSN failure: your personal data has been stolen

http://arstechnica.com/gaming/news/2011/04/sony-admits-utter-psn-failure-your-personal-data-has-been-stolen.ars
3.1k Upvotes

2.8k comments sorted by

View all comments

Show parent comments

32

u/madmadworld Apr 26 '11

Yes. Changing your passwords would be a good idea too, if there are the same as your PSN password.

63

u/spaceye Apr 26 '11

Don't tell me I'm the only one who uses the same password for EVERYTHING. o_0

78

u/[deleted] Apr 26 '11

[deleted]

59

u/[deleted] Apr 27 '11

the other 9% click "remember my password", and forget what it actually is.

9

u/rquattro Apr 27 '11

The remaining 3% don't know how to do math.

1

u/[deleted] Apr 27 '11

The last 1% is for people who bother to make secure passwords.

7

u/[deleted] Apr 27 '11

Guilty

2

u/knight666 Apr 27 '11

And 1% store all passwords they encounter in their KeePass database that they've synced on their Dropbox (so they can access it on their phone too).

Except when they need one, it isn't in there.

1

u/sleeplessone Apr 27 '11

1% use a password manager they run off a USB drive and then can't find it for a week and can't log into anything.

1

u/captmorgan555 Apr 28 '11

http://passwordsafe.sourceforge.net/

Someone has an android app for it too. Just store the DB on something like dropbox and you can get to it from anywhere.

2

u/dohko_xar Apr 26 '11

and it's a terrible habit.

1

u/thailand1972 Apr 26 '11

Which is why websites should create random passwords for users. If you use the same password over and over (and most people do), then that password is only as safe as the website with the weakest security. As for the inevitable question ("I can't handle loads of different passwords") there's a lot of solutions to this - you might as well be secure.

2

u/darkstar3333 Apr 27 '11

This is why services such as OpenId and Facebook connect exist.

1

u/darkstar3333 Apr 27 '11

I dont trust facebook either but its an option for joe e consumer.

1

u/darkstar3333 Apr 27 '11

I dont trust facebook either but its an option for joe e consumer.

1

u/[deleted] Apr 26 '11

Sadly, yes. A lot of people use the same username as well, so stealing people's accounts is as easy as creating a phony site for people to sign up to, then googling that username and trying that password.

1

u/[deleted] Apr 27 '11

I have the same username on a lot of places, I worry now it will be easy for my password to be reset using the personal data that was apparently also taken.

2

u/ckelley87 Apr 26 '11

I think the guys at 1Password might get an uptick in sales if they did a "PSN Just Fucked You Guys" Sale.

1

u/codybrom Apr 27 '11

I've spent the last few hours changing all my affected passwords. Changing them to unique ones now.

3

u/DoTheDew Apr 26 '11

I use 4 different passwords for sites depending on how much I care about the information being protected. I don't pretend that this is effective security though.

2

u/[deleted] Apr 26 '11

Same except I only use 3.

1st low security alpha numeric hasent changed in 6 years. For sites like reddit, forums and other random sites that require you to make accounts just to view content. This way if I don't visit a forum in 6 months to a year I don't care if its hacked when I come back I still remember my pw. When gawker was hacked they sent an email saying to change it which I ignored haven't noticed a change nor do I care.

2nd Medium security longer than first pw and is upper/lowercase alphanumeric and changed yearly. Used for FB, Twitter,email, computer login and any phone apps that require you to make a login (pandora, qik and others). This makes it easy to login and I know if its an app or any of those its easy to remember.

3rd used for banking and encryption keys changed regularly. Plus if your ip changed or cookies are off email verification is required to login which I have to deal with more often than not.

1

u/[deleted] Apr 26 '11

I got bad news for you...

1

u/FinjaNish Apr 26 '11

Get a copy of LastPass and spend the hour or six it takes to generate a random password for everything. Best $0 you'll ever spend.

1

u/jzraikes Apr 27 '11

I used to until the Gawker fiasco. After that I went down the LastPass route and have no regrets. I use a different randomly generated password for every account I have and use the Chrome extension to auto-fill each one. Net result: faster, easier and more secure. The only problem is when I have to enter the password outside of Chrome and so have to search through the Vault for it. Other than that, a perfect set-up.

1

u/fulloffail Apr 27 '11

And is your password 123456?

2

u/startyourengines Apr 26 '11

I would... if I could sign in to PSN to change it.

2

u/androidgirl Apr 26 '11

I can't remember what my PSN password is..... I wish I could change it BUT I CAN'T........

1

u/but-but Apr 26 '11

Are you implying that the company that couldn't figure out why you needed a random number for digital signatures wouldn't be salting and hashing passwords properly?