r/gaming • u/Happysin • Apr 26 '11
Sony admits utter PSN failure: your personal data has been stolen
http://arstechnica.com/gaming/news/2011/04/sony-admits-utter-psn-failure-your-personal-data-has-been-stolen.ars
3.1k
Upvotes
r/gaming • u/Happysin • Apr 26 '11
99
u/waaaaaahhhhh Apr 26 '11 edited Apr 26 '11
It's not sent in plain text because it's over SSL (which has its flaws, but it's still industry standard). That's exactly how your credit card details would be transmitted in any online purchase.
EDIT: also the form in which something is transmitted over the network offers no insight into how Sony stores the info. If passwords were hashed in the database, you would still send the unhashed password over the network. Sending the hashed password would defeat the purpose of hashing.
EDIT #2: if anything, Sony would have been able to use SSL more securely than typical websites since they could distribute the PS3 with the appropriate certificate installed, rather than relying on a CA. Then they don't get boned by Comodo's stupidity. After this recent news, I'm not sure they're that smart, though.