Letter from Howard Stringer to Playstation Customers.

Post » Wed Aug 18, 2010 7:37 pm

I actually blogged about this earlier today (won't post a link due to advertising, but it's in my profile...).

It's a good apology, but too little too late I think :shrug:
User avatar
Nikki Hype
 
Posts: 3429
Joined: Mon Jan 01, 2007 12:38 pm

Post » Wed Aug 18, 2010 9:20 pm

http://www.tgdaily.com/games-and-entertainment-brief/55623-sony-admits-some-psn-data-was-unencrypted. The only thing encrypted was the credit card info, which I wouldn't be surprised if it wasn't salted...
If you are encrypting something, I don't think salting it makes to much difference given that the idea of a salt is to prevent the use of rainbow tables for reversing hashes.
User avatar
Kim Bradley
 
Posts: 3427
Joined: Sat Aug 18, 2007 6:00 am

Post » Wed Aug 18, 2010 11:22 am

Rumors of a third attack planned by hackers this weekend.

http://news.cnet.com/8301-31021_3-20060227-260.html

A group of hackers says it is planning another wave of cyberattacks against Sony in retaliation for its handling of the PlayStation Network breach.

An observer of the Internet Relay Chat channel used by the hackers told CNET today that a third major attack is planned this weekend against Sony's Web site. The people involved plan to publicize all or some of the information they are able to copy from Sony's servers, which could include customer names, credit card numbers, and addresses, according to the source. The hackers claim they currently have access to some of Sony's servers.

Should the planned attack succeed, it would be the latest blow in a series of devastating security breaches of Sony's servers over the past month. The failure of Sony's server security has ignited investigations by the FBI, the Department of Justice, Congress, and the New York State Attorney General, a well as data security and privacy authorities in the U.K., Canada, and Taiwan.

Read more: http://news.cnet.com/8301-31021_3-20060227-260.html#ixzz1LaNUaDmL
User avatar
celebrity
 
Posts: 3522
Joined: Mon Jul 02, 2007 12:53 pm

Post » Wed Aug 18, 2010 12:18 pm

If you are encrypting something, I don't think salting it makes to much difference given that the idea of a salt is to prevent the use of rainbow tables for reversing hashes.

Quite, however, by "encrypt" I expect it to be just hashing of a database field. It seems unlikely (to me) that Sony kept a table just for credit card info completely separate from the rest of the user's info. I could easily be wrong in that assumption and they are two separate tables with the credit card info properly encrypted, but if it is just hashed as I expect at this point, I wouldn't be surprised if it was not salted. Right now I don't have a very favorable looking on Sony's security policies.
User avatar
Niisha
 
Posts: 3393
Joined: Fri Sep 15, 2006 2:54 am

Post » Wed Aug 18, 2010 9:20 pm

Quite, however, by "encrypt" I expect it to be just hashing of a database field. It seems unlikely (to me) that Sony kept a table just for credit card info completely separate from the rest of the user's info. I could easily be wrong in that assumption and they are two separate tables with the credit card info properly encrypted, but if it is just hashed as I expect at this point, I wouldn't be surprised if it was not salted. Right now I don't have a very favorable looking on Sony's security policies.

What would be the point of hashing credit card data? You couldn't ever retrieve the data.
User avatar
WTW
 
Posts: 3313
Joined: Wed May 30, 2007 7:48 pm

Post » Thu Aug 19, 2010 3:37 am

I still can't believe they were running stuff on unpatched, no-firewall servers. What a STUPID mistake. :shakehead:
User avatar
Eoh
 
Posts: 3378
Joined: Sun Mar 18, 2007 6:03 pm

Post » Wed Aug 18, 2010 11:51 am

What would be the point of hashing credit card data?

Keeping casual copying of the info, I'd assume :shrug: Like I said right now I don't have high expectations for Sony's security policies, so maybe I'm just looking too down on them right now. After this mess is all cleared, I hope they do do a good job at encrypting the personal info of their customers.

You couldn't ever retrieve the data.

I'm talking about the credit card numbers, and them being just hashed, not encrypted. When I said "assumption" I was talking about my assumption that Sony only hashed the credit card numbers rather than actually encrypting them.
User avatar
Laura Hicks
 
Posts: 3395
Joined: Wed Jun 06, 2007 9:21 am

Post » Wed Aug 18, 2010 1:06 pm

Keeping casual copying of the info, I'd assume
A hash function has no inverse though. Where as a function to encrypt data does.
User avatar
Project
 
Posts: 3490
Joined: Fri May 04, 2007 7:58 am

Post » Wed Aug 18, 2010 12:07 pm

A hash function has no inverse though. Where as a function to encrypt data does.

I was not aware of this, that makes me feel a little better about Sony's practices then, since the credit card info was then most likely properly encrypted.
User avatar
Taylah Illies
 
Posts: 3369
Joined: Fri Feb 09, 2007 7:13 am

Post » Wed Aug 18, 2010 2:37 pm

Rumors of a third attack planned by hackers this weekend.

http://news.cnet.com/8301-31021_3-20060227-260.html

A group of hackers says it is planning another wave of cyberattacks against Sony in retaliation for its handling of the PlayStation Network breach.



Huh. I guess we'll just have to wait and see then...

Is it just me, or has anyone else noticed it seems to take a slightly longer amount of time for the maintenance message to come up when signing in? Compared to when they first shut it down. It came up almost right away, and now it takes a few seconds. For me, anyway.
User avatar
Kayleigh Williams
 
Posts: 3397
Joined: Wed Aug 23, 2006 10:41 am

Post » Wed Aug 18, 2010 5:59 pm

Huh. I guess we'll just have to wait and see then...

Is it just me, or has anyone else noticed it seems to take a slightly longer amount of time for the maintenance message to come up when signing in? Compared to when they first shut it down. It came up almost right away, and now it takes a few seconds. For me, anyway.


Your losing it bro.
User avatar
Alexander Horton
 
Posts: 3318
Joined: Thu Oct 11, 2007 9:19 pm

Post » Wed Aug 18, 2010 11:18 am

Wow, no encryption and unpatched servers; that is novice level mistakes. I have limited knowledge of Apache and databases and that even amazes me.

How on earth does a huge company like Sony make such silly mistakes??
User avatar
Taylor Tifany
 
Posts: 3555
Joined: Sun Jun 25, 2006 7:22 am

Post » Thu Aug 19, 2010 1:17 am

that "welcome back" package compensation is a gimmick. Oh, yeah, a free month of PSN+ - and I have to keep paying if I want to retain access to my freebies. I'd rather they just let us dl one or two old PS1 games off of PSN, it's not like the old games are really worth anything anyway - but at least it'd be something I can keep.

EDIT: And I bet they're gonna pay more for investigator services than what they would've had to spend to update their security system!
User avatar
Bones47
 
Posts: 3399
Joined: Fri Nov 09, 2007 11:15 pm

Post » Wed Aug 18, 2010 3:41 pm

that "welcome back" package compensation is a gimmick. Oh, yeah, a free month of PSN+ - and I have to keep paying if I want to retain access to my freebies. I'd rather they just let us dl one or two old PS1 games off of PSN, it's not like the old games are really worth anything anyway - but at least it'd be something I can keep.

EDIT: And I bet they're gonna pay more for investigator services than what they would've had to spend to update their security system!


They are also giving free stuff which you will be able to keep forever.
User avatar
Rude_Bitch_420
 
Posts: 3429
Joined: Wed Aug 08, 2007 2:26 pm

Post » Wed Aug 18, 2010 1:12 pm

They are also giving free stuff which you will be able to keep forever.

But its still owned and trademarked by the Sony corporation.

So your just borrowing it, in its eyes.
User avatar
Facebook me
 
Posts: 3442
Joined: Wed Nov 08, 2006 8:05 am

Post » Wed Aug 18, 2010 11:34 pm

They are also giving free stuff which you will be able to keep forever.


which is...? I've only heard about the PS+ thing, and extensions on subscriptions to things like DCUO and their Qriocity music thing or whatever. And they've made vague passings to offering "other" stuff, but haven't officially announced it yet.
User avatar
Mason Nevitt
 
Posts: 3346
Joined: Fri May 11, 2007 8:49 pm

Post » Thu Aug 19, 2010 3:32 am

which is...? I've only heard about the PS+ thing, and extensions on subscriptions to things like DCUO and their Qriocity music thing or whatever. And they've made vague passings to offering "other" stuff, but haven't officially announced it yet.


We don't know the exact games but Sony Europe will be offering you 2 games out of a total of 5. Its about a $10 value.. :shrug:
User avatar
CArlos BArrera
 
Posts: 3470
Joined: Wed Nov 21, 2007 3:26 am

Post » Wed Aug 18, 2010 2:08 pm

We don't know the exact games but Sony Europe will be offering you 2 games out of a total of 5. Its about a $10 value.. :shrug:


huh. is this for European folks only? even if that were the case, I imagine them having something similar for other regions. otherwise you'd have people pointing fingers and yelling "racist!" all over the web at Sony.
User avatar
Kristian Perez
 
Posts: 3365
Joined: Thu Aug 23, 2007 3:03 am

Post » Wed Aug 18, 2010 2:08 pm

Still down?
User avatar
мistrєss
 
Posts: 3168
Joined: Thu Dec 14, 2006 3:13 am

Post » Wed Aug 18, 2010 4:34 pm

Still down?


AFAIK...unfortunately :sadvaultboy:

there isn't confirmed reports of it going back up in japan, is there?

I read on the PS blog there in the "final stages" of making sure it's secure and what-not. I can't imagine it taking more than another few days. hopefully.
User avatar
Madeleine Rose Walsh
 
Posts: 3425
Joined: Wed Oct 04, 2006 2:07 am

Post » Wed Aug 18, 2010 6:50 pm

AFAIK...unfortunately :sadvaultboy:

there isn't confirmed reports of it going back up in japan, is there?

I read on the PS blog there in the "final stages" of making sure it's secure and what-not. I can't imagine it taking more than another few days. hopefully.


This, I hope.

Anyways yah, you have to continue to pay for PS+ to keep your freebies, unless they are actually giving stuff away.

If not, I guess Infamous will keep me happy until online returns. I hope I can get Killzone 3 as a freebie too, :biggrin:, but that is just wishful, very wishful thinking :violin:
User avatar
Angela
 
Posts: 3492
Joined: Mon Mar 05, 2007 8:33 am

Post » Thu Aug 19, 2010 2:40 am

well hopefully in a few days I will have the parts too hook up the PS3 to my monitor. Once it is all hooked up, Psn extravaganza!

http://www.youtube.com/watch?v=JYsKDaQIX54
User avatar
Harry Hearing
 
Posts: 3366
Joined: Sun Jul 22, 2007 6:19 am

Post » Wed Aug 18, 2010 8:48 pm

This is like a really good horror movie. I honestly hope Sony can catch the criminals and put them behind bars! :mad:
Also have you guys noticed that no other game company has gotten involved? Why do you guys think about that? Is it just that they trust Sony?
User avatar
Samantha hulme
 
Posts: 3373
Joined: Wed Jun 21, 2006 4:22 pm

Post » Wed Aug 18, 2010 11:37 pm

Also have you guys noticed that no other game company has gotten involved? Why do you guys think about that? Is it just that they trust Sony?


What do you mean "involved"? I'm confused...

and horror movie? lol, who died? I thought this was all technology-oriented...

hope I can get Killzone 3 as a freebie too, :biggrin:, but that is just wishful, very wishful thinking :violin:


I hope you don't mean digitally? KZ3 is one of the most massive games in terms of the size of all the data. it would take a very, very long time to download.
User avatar
Beth Belcher
 
Posts: 3393
Joined: Tue Jun 13, 2006 1:39 pm

Post » Wed Aug 18, 2010 3:52 pm

What do you mean "involved"? I'm confused...

and horror movie? lol, who died? I thought this was all technology-oriented...


They haven't said anything. For example: they haven't mentioned how this can affect them, etc.. When i said movie: I meant hackers, identity theft, conspiracies..
User avatar
Dan Endacott
 
Posts: 3419
Joined: Fri Jul 06, 2007 9:12 am

PreviousNext

Return to Othor Games