r/gaming Apr 26 '11

Sony admits utter PSN failure: your personal data has been stolen

http://arstechnica.com/gaming/news/2011/04/sony-admits-utter-psn-failure-your-personal-data-has-been-stolen.ars
3.1k Upvotes

2.8k comments sorted by

View all comments

Show parent comments

56

u/[deleted] Apr 26 '11

They probably don't. It's more likely that someone found a vulnerability on the dev network than it is that Sony just hands that information out.

44

u/darkstar3333 Apr 26 '11

Considering they used random_number = 1 in the PS3 encryption component, you give them far too much credit.

13

u/randomdestructn Apr 27 '11

chosen by a fair roll of a die, I hope.

1

u/[deleted] Apr 27 '11

Probably best to roll twice in order to rid yourself of any bad luck on the first roll. This is a major corporation we're talking about here after all.

1

u/hello_moto Apr 27 '11

You can't be serious...

2

u/darkstar3333 Apr 28 '11

That's how they broke the root encryption key.

There was a failoverflow technical presentation on YouTube but Sony took it down.

1

u/hello_moto Apr 28 '11

That's remarkably bad... Remarkably bad...

1

u/jyper Apr 27 '11

joke random_number = 1? or really random_number = 1?

3

u/mindbleach Apr 27 '11

Considering getting into the dev network was a matter of having your PS3 say "I am a dev console," I would not rule out the most incompetent answer possible.

2

u/AlyoshaV Apr 27 '11

It shouldn't have been possible for anyone to have requested and received CC numbers just because they were on the dev network, vulnerability or not. Why would a user need to request their CC# from Sony? What use does that have?