PSN Network Hacked

SentrySteveSentrySteve .txt Join Date: 2002-03-09 Member: 290Members, Constellation
<div class="IPBDescription">Incase any PS3 user has not heard</div><a href="http://blog.us.playstation.com/2011/04/26/update-on-playstation-network-and-qriocity/" target="_blank">http://blog.us.playstation.com/2011/04/26/...k-and-qriocity/</a>

The fun parts:

<!--quoteo--><div class='quotetop'>QUOTE </div><div class='quotemain'><!--quotec-->we believe that an unauthorized person has obtained the following information that you provided: name, address (city, state, zip), country, email address, birthdate, PlayStation Network/Qriocity password and login, and handle/PSN online ID. It is also possible that your profile data, including purchase history and billing address (city, state, zip), and your PlayStation Network/Qriocity password security answers may have been obtained. If you have authorized a sub-account for your dependent, the same data with respect to your dependent may have been obtained. While there is no evidence at this time that credit card data was taken, we cannot rule out the possibility. If you have provided your credit card data through PlayStation Network or Qriocity, out of an abundance of caution we are advising you that your credit card number (excluding security code) and expiration date may have been obtained.<!--QuoteEnd--></div><!--QuoteEEnd-->

<!--quoteo--><div class='quotetop'>QUOTE </div><div class='quotemain'><!--quotec-->When the PlayStation Network and Qriocity services are fully restored, we strongly recommend that you log on and change your password. Additionally, if you use your PlayStation Network or Qriocity user name or password for other unrelated services or accounts, we strongly recommend that you change them, as well.<!--QuoteEnd--></div><!--QuoteEEnd-->
«1

Comments

  • Kouji_SanKouji_San Sr. Hινε Uρкεερεг - EUPT Deputy The Netherlands Join Date: 2003-05-13 Member: 16271Members, NS2 Playtester, Squad Five Blue
    Some of the comments on that article are pretty hilarious as well!
  • nightshadowznightshadowz Join Date: 2009-07-08 Member: 68086Members
    This is old new to me good thing i don't have a psn acc or the other account go PC :D!
  • ThiefThief Ownage Join Date: 2003-08-09 Member: 19214Members, Constellation
    For the 814th time in my life, I wish I could afford microsoft stock. They are probably flipping their ###### delighted right now.
  • SwiftspearSwiftspear Custim tital Join Date: 2003-10-29 Member: 22097Members
    Hacked by Bill Gates >:)
  • lolfighterlolfighter Snark, Dire Join Date: 2003-04-20 Member: 15693Members
    *I* would never even store the password in a database as entered by the user. You're encrypting it before transmission anyway - might as well LEAVE it encrypted and store that in the database. That way, if anyone looks in your database, all they see is the encrypted password, which will be of no use to them.
  • TalesinTalesin Our own little well of hate Join Date: 2002-11-08 Member: 7710NS1 Playtester, Forum Moderators
    Just loving the PS3 sales that cropped up. 'For Offline Play Only'.
  • ANeMANeM Join Date: 2003-05-13 Member: 16267Members, Constellation
    <!--quoteo(post=1842592:date=Apr 26 2011, 06:51 PM:name=Thief)--><div class='quotetop'>QUOTE (Thief @ Apr 26 2011, 06:51 PM) <a href="index.php?act=findpost&pid=1842592"><{POST_SNAPBACK}></a></div><div class='quotemain'><!--quotec-->For the 814th time in my life, I wish I could afford microsoft stock. They are probably flipping their ###### delighted right now.<!--QuoteEnd--></div><!--QuoteEEnd-->

    It is a rather nice coincidence that PSN was down during a free gold weekend for Xbox Live.
  • TykjenTykjen Join Date: 2003-01-21 Member: 12552Members, Reinforced - Shadow
    Its only been down a week. Still a week to go if its gonna beat the xbox live record downtime :P
    And the 360 still has the 52% failrate.
    This is all but forgotten in the wake of this big blow to Sony. They cant fight the free crowd being so uptight. A sure blow to capitalism for Sony.
    Im a ps3 owner and couldnt care less cause most games I do play on console are for single playing..while the PC is for anything else. I was hoping for something like this to happen to them. Well deserved and I hope they are as happy as I am.
  • RobRob Unknown Enemy Join Date: 2002-01-24 Member: 25Members, NS1 Playtester
    <!--quoteo(post=1842639:date=Apr 27 2011, 01:54 AM:name=lolfighter)--><div class='quotetop'>QUOTE (lolfighter @ Apr 27 2011, 01:54 AM) <a href="index.php?act=findpost&pid=1842639"><{POST_SNAPBACK}></a></div><div class='quotemain'><!--quotec-->*I* would never even store the password in a database as entered by the user. You're encrypting it before transmission anyway - might as well LEAVE it encrypted and store that in the database. That way, if anyone looks in your database, all they see is the encrypted password, which will be of no use to them.<!--QuoteEnd--></div><!--QuoteEEnd-->

    I'm sure they did this. Unfortunately, these days what you do is get the encrypted password, even one that can't be unencrypted, and run it through a so called 'rainbow table' which is a massive look up of encrypted passwords from known inputs. It's why you shouldn't use dictionary words in your passwords. These are likely guesses, so it's easy to put together permutations of them, encrypt them the same way applications do, and store both the raw password and the encrypted password.

    When you find an encrypted password, you got em!
  • ThaldarinThaldarin Alonzi&#33; Join Date: 2003-07-15 Member: 18173Members, Constellation
    I have a friend who bought Portal 2 on the PS3 so he could play it on the PC and PS3. So far, he hasn't been able to play it on either, as it requires Steam linking and must be done on the PS3 Network xD
  • CrispyCrispy Jaded GD Join Date: 2004-08-22 Member: 30793Members, Constellation
    edited April 2011
    It's... a bit frustrating.
  • TalesinTalesin Our own little well of hate Join Date: 2002-11-08 Member: 7710NS1 Playtester, Forum Moderators
    edited April 2011
    <!--quoteo(post=1842696:date=Apr 27 2011, 07:00 AM:name=Tykjen)--><div class='quotetop'>QUOTE (Tykjen @ Apr 27 2011, 07:00 AM) <a href="index.php?act=findpost&pid=1842696"><{POST_SNAPBACK}></a></div><div class='quotemain'><!--quotec-->And the 360 still has the 52% failrate.<!--QuoteEnd--></div><!--QuoteEEnd-->
    Where do you get that statistic from? That debunked GameInformer article? (Was a reader survey, not actual fail-rate numbers) Still have yet to have one RROD on me (I own three, they work great as cheap media extenders if you run TVersity), and last I'd heard the actual fail-rate was closer to 30%, and even then only applied to the early-run systems.

    <!--quoteo(post=1842705:date=Apr 27 2011, 08:17 AM:name=Rob)--><div class='quotetop'>QUOTE (Rob @ Apr 27 2011, 08:17 AM) <a href="index.php?act=findpost&pid=1842705"><{POST_SNAPBACK}></a></div><div class='quotemain'><!--quotec-->I'm sure they did this. Unfortunately, these days what you do is get the encrypted password, even one that can't be unencrypted, and run it through a so called 'rainbow table' which is a massive look up of encrypted passwords from known inputs. It's why you shouldn't use dictionary words in your passwords. These are likely guesses, so it's easy to put together permutations of them, encrypt them the same way applications do, and store both the raw password and the encrypted password.

    When you find an encrypted password, you got em!<!--QuoteEnd--></div><!--QuoteEEnd-->
    This is what MD5 salting is for; have to create rainbow tables for the specific salt used, which effectively just turns it into a massive dictionary attack instead.
    Though I'm truly surprised at the number of 'secure' systems that don't even bother with a basic salt, much less a per-database secondary salt.
  • ThaldarinThaldarin Alonzi&#33; Join Date: 2003-07-15 Member: 18173Members, Constellation
    I can't take credit for this, but, well, here it is..
    <img src="http://img.photobucket.com/albums/v247/DrForester/SonyIsntGoodWithComputers.gif" border="0" class="linked-image" />
  • DrfuzzyDrfuzzy FEW... MORE.... INCHES... Join Date: 2003-09-21 Member: 21094Members
    <img src="http://fc03.deviantart.net/fs44/f/2009/140/2/2/PC_Gaming_Master_Race_by_Claidheam_Righ.jpg" border="0" class="linked-image" />
  • lolfighterlolfighter Snark, Dire Join Date: 2003-04-20 Member: 15693Members
    edited April 2011
    <!--quoteo(post=1842788:date=Apr 27 2011, 11:55 PM:name=Drfuzzy)--><div class='quotetop'>QUOTE (Drfuzzy @ Apr 27 2011, 11:55 PM) <a href="index.php?act=findpost&pid=1842788"><{POST_SNAPBACK}></a></div><div class='quotemain'><!--quotec--><img src="http://fc03.deviantart.net/fs44/f/2009/140/2/2/PC_Gaming_Master_Race_by_Claidheam_Righ.jpg" border="0" class="linked-image" /><!--QuoteEnd--></div><!--QuoteEEnd-->
    ... now imagine if this happened to Valve. Steam down, can't play most of your games, and all the info you entered when making purchases in the hands of the hackers. I don't think gloating is in order, it could be us next time.
  • Kouji_SanKouji_San Sr. Hινε Uρкεερεг - EUPT Deputy The Netherlands Join Date: 2003-05-13 Member: 16271Members, NS2 Playtester, Squad Five Blue
    Steam account hijacking is something odd indeed... I don't have much faith in their security...
  • spellman23spellman23 NS1 Theorycraft Expert Join Date: 2007-05-17 Member: 60920Members
    <!--quoteo(post=1842830:date=Apr 27 2011, 05:57 PM:name=lolfighter)--><div class='quotetop'>QUOTE (lolfighter @ Apr 27 2011, 05:57 PM) <a href="index.php?act=findpost&pid=1842830"><{POST_SNAPBACK}></a></div><div class='quotemain'><!--quotec-->... now imagine if this happened to Valve. Steam down, can't play most of your games, and all the info you entered when making purchases in the hands of the hackers. I don't think gloating is in order, it could be us next time.<!--QuoteEnd--></div><!--QuoteEEnd-->

    yup.

    More proof you shouldn't let people have your personal info on file when possible. Manual entry ftw.
  • TykjenTykjen Join Date: 2003-01-21 Member: 12552Members, Reinforced - Shadow
    <!--quoteo(post=1842754:date=Apr 27 2011, 07:53 PM:name=Talesin)--><div class='quotetop'>QUOTE (Talesin @ Apr 27 2011, 07:53 PM) <a href="index.php?act=findpost&pid=1842754"><{POST_SNAPBACK}></a></div><div class='quotemain'><!--quotec-->Where do you get that statistic from? That debunked GameInformer article? (Was a reader survey, not actual fail-rate numbers) Still have yet to have one RROD on me (I own three, they work great as cheap media extenders if you run TVersity), and last I'd heard the actual fail-rate was closer to 30%, and even then only applied to the early-run systems.<!--QuoteEnd--></div><!--QuoteEEnd-->

    While the failrate was nearer 40% perhaps, Microsoft provided EXCELLENT customer service for everyone affected. I had one RROD, shipped it from Norway to England..got a new one delivered on my door 2 weeks later. +3 free Gold months. MS got a big thumbs up for that one..quite a pleasant surprise :)
  • JediYoshiJediYoshi The Cupcake Boss Join Date: 2002-05-27 Member: 674Members
    <!--quoteo(post=1842831:date=Apr 27 2011, 06:02 PM:name=Kouji_San)--><div class='quotetop'>QUOTE (Kouji_San @ Apr 27 2011, 06:02 PM) <a href="index.php?act=findpost&pid=1842831"><{POST_SNAPBACK}></a></div><div class='quotemain'><!--quotec-->Steam account hijacking is something odd indeed... I don't have much faith in their security...<!--QuoteEnd--></div><!--QuoteEEnd-->

    Perhaps you missed the presentation where Gabe gave out his username and password to showcase Steam Guard.
  • Konohas Perverted HermitKonohas Perverted Hermit Join Date: 2008-09-26 Member: 65075Members
    <!--quoteo(post=1842894:date=Apr 28 2011, 01:04 AM:name=JediYoshi)--><div class='quotetop'>QUOTE (JediYoshi @ Apr 28 2011, 01:04 AM) <a href="index.php?act=findpost&pid=1842894"><{POST_SNAPBACK}></a></div><div class='quotemain'><!--quotec-->Perhaps you missed the presentation where Gabe gave out his username and password to showcase Steam Guard.<!--QuoteEnd--></div><!--QuoteEEnd-->

    But Gabe's password and username were easy to begin with.
  • CrispyCrispy Jaded GD Join Date: 2004-08-22 Member: 30793Members, Constellation
    <!--quoteo(post=1842839:date=Apr 28 2011, 02:12 AM:name=Tykjen)--><div class='quotetop'>QUOTE (Tykjen @ Apr 28 2011, 02:12 AM) <a href="index.php?act=findpost&pid=1842839"><{POST_SNAPBACK}></a></div><div class='quotemain'><!--quotec-->While the failrate was nearer 40% perhaps, Microsoft provided EXCELLENT customer service for everyone affected. I had one RROD, shipped it from Norway to England..got a new one delivered on my door 2 weeks later. +3 free Gold months. MS got a big thumbs up for that one..quite a pleasant surprise :)<!--QuoteEnd--></div><!--QuoteEEnd-->Flatmate got 2 replacements, the second of which was only supplied with a 1 month warranty, after which it entered a state in which it only reads discs 80% of the time. He's not best pleased.

    Look at it this way: Sony have more experience manufacturing electronics hardware, Microsoft have more experience manufacturing system software.
  • lazylazy Join Date: 2005-07-23 Member: 56631Members
    Is it still gaben or what
  • ThaldarinThaldarin Alonzi&#33; Join Date: 2003-07-15 Member: 18173Members, Constellation
    <!--quoteo(post=1842948:date=Apr 28 2011, 02:52 PM:name=lazy)--><div class='quotetop'>QUOTE (lazy @ Apr 28 2011, 02:52 PM) <a href="index.php?act=findpost&pid=1842948"><{POST_SNAPBACK}></a></div><div class='quotemain'><!--quotec-->Is it still gaben or what<!--QuoteEnd--></div><!--QuoteEEnd-->

    user: gaben
    password: ilikecake
  • DrfuzzyDrfuzzy FEW... MORE.... INCHES... Join Date: 2003-09-21 Member: 21094Members
    <!--quoteo(post=1842993:date=Apr 28 2011, 01:44 PM:name=Thaldarin)--><div class='quotetop'>QUOTE (Thaldarin @ Apr 28 2011, 01:44 PM) <a href="index.php?act=findpost&pid=1842993"><{POST_SNAPBACK}></a></div><div class='quotemain'><!--quotec-->password: ilikecake<!--QuoteEnd--></div><!--QuoteEEnd-->

    I lol'd
  • Kouji_SanKouji_San Sr. Hινε Uρкεερεг - EUPT Deputy The Netherlands Join Date: 2003-05-13 Member: 16271Members, NS2 Playtester, Squad Five Blue
    <!--quoteo(post=1842998:date=Apr 28 2011, 07:03 PM:name=Drfuzzy)--><div class='quotetop'>QUOTE (Drfuzzy @ Apr 28 2011, 07:03 PM) <a href="index.php?act=findpost&pid=1842998"><{POST_SNAPBACK}></a></div><div class='quotemain'><!--quotec-->I lol'd<!--QuoteEnd--></div><!--QuoteEEnd-->
    You're kind of obligated to :D
  • AlignAlign Remain Calm Join Date: 2002-11-02 Member: 5216Forum Moderators, Constellation
    Every time you make a "gabe is fat lol" joke Episode 3 is delayed another week.
  • Kouji_SanKouji_San Sr. Hινε Uρкεερεг - EUPT Deputy The Netherlands Join Date: 2003-05-13 Member: 16271Members, NS2 Playtester, Squad Five Blue
    <!--quoteo(post=1843013:date=Apr 28 2011, 08:26 PM:name=Align)--><div class='quotetop'>QUOTE (Align @ Apr 28 2011, 08:26 PM) <a href="index.php?act=findpost&pid=1843013"><{POST_SNAPBACK}></a></div><div class='quotemain'><!--quotec-->Every time you make a "gabe is fat lol" joke Episode 3 is delayed another week.<!--QuoteEnd--></div><!--QuoteEEnd-->
    Aight, but this was a cookies joke... which... ehm... AH nevermind!
  • ThaldarinThaldarin Alonzi&#33; Join Date: 2003-07-15 Member: 18173Members, Constellation
    On a more serious note to this thread, for you guys that did have your card data on the PS Network, DO cancel your bank cards immedietely. I have heard several instances of fraudulent cases through work already, which they believe has been a direct result of the network hack.
  • SentrySteveSentrySteve .txt Join Date: 2002-03-09 Member: 290Members, Constellation
    edited April 2011
    <!--quoteo(post=1843033:date=Apr 28 2011, 06:28 PM:name=Thaldarin)--><div class='quotetop'>QUOTE (Thaldarin @ Apr 28 2011, 06:28 PM) <a href="index.php?act=findpost&pid=1843033"><{POST_SNAPBACK}></a></div><div class='quotemain'><!--quotec-->On a more serious note to this thread, for you guys that did have your card data on the PS Network, DO cancel your bank cards immedietely. I have heard several instances of fraudulent cases through work already, which they believe has been a direct result of the network hack.<!--QuoteEnd--></div><!--QuoteEEnd-->

    Damn...

    That's crazy. A group/someone has data on peoples' credit cards from around the globe.

    I did hear in an update that they didnt get the security / CVV numbers. Without those numbers the cards <i>should</i> be worthless.

    I only wish I remembered the password I used on my PSN account and I don't even have a way to check until they bring it back online...
  • ThaldarinThaldarin Alonzi&#33; Join Date: 2003-07-15 Member: 18173Members, Constellation
    <!--quoteo(post=1843049:date=Apr 28 2011, 11:42 PM:name=SentrySteve)--><div class='quotetop'>QUOTE (SentrySteve @ Apr 28 2011, 11:42 PM) <a href="index.php?act=findpost&pid=1843049"><{POST_SNAPBACK}></a></div><div class='quotemain'><!--quotec-->I did hear in an update that they didnt get the security / CVV numbers. Without those numbers the cards <i>should</i> be worthless.<!--QuoteEnd--></div><!--QuoteEEnd-->

    In the UK, it is physically possible to push transactions through without them. I'm not entirely sure how, but I know enough from talking to agents at VISA and Mastercard to know it can be done. It's probably because some places like post offices and supermarkets still have systems online that allow you to sign for a card; so if you can make a duplicate card from a card number, with no one checking any information, a simple swipe, fake signature.. easy done.
Sign In or Register to comment.