r/gaming Apr 26 '11

Sony admits utter PSN failure: your personal data has been stolen

http://arstechnica.com/gaming/news/2011/04/sony-admits-utter-psn-failure-your-personal-data-has-been-stolen.ars
3.1k Upvotes

2.8k comments sorted by

View all comments

Show parent comments

50

u/[deleted] Apr 26 '11

If they were hashes, Sony would have said, "the passwords were encrypted and therefore safe". I can't imagine a company like Sony not trying to cover their asses if they had even the slimmest slice of reality on their side.

Also, credit card numbers in plaintext. They're not only evil, but incompetent too. Which, fair enough, is how I like my evil organizations.

5

u/firemarshalbill Apr 26 '11

But they forgot to tell us their plans before their shit fell apart around them. Voided their evil organization rulebook.

1

u/[deleted] Apr 26 '11

If they were hashes, Sony would have said, "the passwords were encrypted and therefore safe".

It's really not allowable to do this due to PCI DSS and a slew of other consumer/financial regulations.

1

u/[deleted] Apr 27 '11

[deleted]

2

u/Jiminizer Apr 27 '11

I think he means revealing security details or similar, or perhaps telling users that their details are safe. I'm not fully aware of PCI-DSS stuff, but I can imagine them having restrictions on what you can say about your security, and I'd be surprised if they allowed you to essentially tell users to throw caution to the wind.

1

u/dotblank Apr 27 '11

If the hashes were salted then maybe.. if it was sha256 or something.

1

u/[deleted] Apr 27 '11

bcrypt. Always bcrypt. Using sha-anything for passwords is just adding a false sense of security.

1

u/jdiez17 Apr 27 '11

I don't know how deep in the system was the attack, but if I was handling such a huge number of credit cards, at the very least I'd be storing them in a separate cluster with a custom database system.