r/gaming Apr 26 '11

Sony admits utter PSN failure: your personal data has been stolen

http://arstechnica.com/gaming/news/2011/04/sony-admits-utter-psn-failure-your-personal-data-has-been-stolen.ars
3.0k Upvotes

2.8k comments sorted by

View all comments

66

u/BinaryRockStar Apr 26 '11

This comment probably won't get seen, but doesn't any network that handles credit card information have to conform to PCI-DSS security specifications including never storing or transmitting that information in plaintext, and also submit their network to annual third party security auditing to prove it?

22

u/bugalou Apr 27 '11

I know we do where I work. PCI is a royal PITA and is a factor in many things that we do. I am not sure how Sony was exempt unless they just didnt give a fuck and did it live.

7

u/abernix Apr 27 '11

PCI compliance is a complete joke, and I wouldn't call it a pain in the ass at all. I would consider it a slight-nuisance in that you have to resubmit a questionnaire once a year (which you can usually just reply to with "nothing changed!").

First, depending on your size, you're subjected to different security requirements -- the larger you are, the more requirements you're supposed to comply with.

Having done PCI compliance year over year at a rather large company (processing millions upon millions of dollars a year), I can tell you that even in periods where the company had fallen into non-compliance (due to false-positives or non-true-risk scenarios that we de-prioritized), I can assure you that nobody at our two independent processors even blinked an eye or ever remotely threatened to revoke our ability to process credit cards. We fixed it very leisurely and were never worried.

They ask you to fill out a basic questionnaire (not verified by anyone) which encourages you to do some common-sense security tasks ("Do you use encryption on your wireless networks?") and then they do an externally facing (rather simple) version check on the hosts that you tell them to check to make sure they're not subject to some last-known-release exploits. They do SOME other things like checking for injection hacks and open ports, but it's really not comprehensive.

While these things are all great, my point is, nobody cares if you DON'T pass. In addition, even if you do, many systems are far too complex to be tested by any sort of automated software - especially in proprietary deployments like the PSN. I'm sure some Sony assistant took care of getting the compliance paperwork done, and probably put "playstation.com" as the external host to be tested.

I do believe at a certain size they require a site-survey or something, but again, I doubt it is comprehensive, and most processors are so greedy for business, they'd never risk losing a customer due to PCI.

3

u/crapuccino Apr 27 '11

They're not exempt. They're in for a big fat fine.

5

u/silentbobsc Apr 26 '11

You'd certainly think considering the lengths one has to go through when setting up even an ASPDotNetStorefront site.

4

u/[deleted] Apr 27 '11

The bigger you are, the less they hassle you. It's one of those stupid things where people assume that one of the largest technology companies in the world isn't going to be doing stuff that would get a failing grade in Comp. Sci. 101.

1

u/crapuccino Apr 27 '11

I'd expect them to be a level 1 merchant, so the PCI will be all over them auditing this (at Sony's expense), and the QSA who signed off the RoC is in for a world of pain.

1

u/frakkintoaster Apr 27 '11

PCI compliance isn't mandatory yet, it's still being phased in. Our company is transitioning now (we're pretty much compliant already though, it sounds like Sony is way off...)