Not So Fast: Sony's PlayStation Network Hacked Again(thenextweb.com)
thenextweb.com
Not So Fast: Sony's PlayStation Network Hacked Again
http://thenextweb.com/industry/2011/05/18/not-so-fast-sonys-playstation-network-hacked-again/
6 comments
I think, at this point you either have to be insanely loyal or pretty clueless to still use PSN. Yet, Sony was saying yesterday that only a small percentage of users are deleting their accounts. What gives?
I think a lot of the inertia is due to the fear that deleting an account could invalidate your purchases with that account. I've bought a few games and DLC packs myself--there's a lot of content I own* that I'd suddenly lose out on. It may be chump change, but I'm not about to walk away from money I've spent in good faith.
I think at this point if Sony would give us a cut-and-run solution to let us kill our accounts but keep our purchases--they won't--we'd see a surge in account deletions, especially after today's news.
Probably worth mentioning that I don't play many online games, so most of the time when I sign on it's to buy single-player content.
I think at this point if Sony would give us a cut-and-run solution to let us kill our accounts but keep our purchases--they won't--we'd see a surge in account deletions, especially after today's news.
Probably worth mentioning that I don't play many online games, so most of the time when I sign on it's to buy single-player content.
Exactly right. If you delete your account, all your purchases disappear. For some of us, that's hundreds of dollars.
I won't ever hand Sony a credit card again, and I'm limiting my purchases to exclusives... And even then, I'll think long and hard before I give them the money for those.
I won't ever hand Sony a credit card again, and I'm limiting my purchases to exclusives... And even then, I'll think long and hard before I give them the money for those.
It sounds so strange to say that your "purchases dissapear". It's as if Sony steals them from you.
Not that I'm saying they are stealing it, it just sounds surreal.
Not that I'm saying they are stealing it, it just sounds surreal.
If it weren't my own action causing it, it would be exactly like Sony stealing them.
That's why I spelled it 'own*'.
I own a PS3, I definitely won't delete my PSN account yet.
All there is to steal is already stolen, I'm going to remove my credit card info from my account (if that's even possible...) and make sure never to buy anything from sony ever again (on the psn or elsewhere). But I already paid for the console, so I won't punish myself by banning myself for online play.
All there is to steal is already stolen, I'm going to remove my credit card info from my account (if that's even possible...) and make sure never to buy anything from sony ever again (on the psn or elsewhere). But I already paid for the console, so I won't punish myself by banning myself for online play.
Here's what gives:
1) The only really valuable information [1] you have on PSN is your credit card information.
2) While Sony said that the credit card information might have been stolen too, so far it appears that it hasn't been compromised.
3) The primary use most people have for PSN is playing games online with other people. Security isn't such a big deal there. [2]
4) Those who purchase games and DLC using PlayStation Store can always choose not to use their credit card for that.
Bottom line? As long as the user's credit card info isn't compromised, he or she will probably care about their PSN security as much as, for example, having their Goodreads account hacked: it would be an annoyance, but not the end of the world.
[1] Trophies and stuff like that have their own value, but most people value their money a lot more than their PSN trophies.
[2] Again, it's not a big deal compared to, for example, having your wallet stolen.
1) The only really valuable information [1] you have on PSN is your credit card information.
2) While Sony said that the credit card information might have been stolen too, so far it appears that it hasn't been compromised.
3) The primary use most people have for PSN is playing games online with other people. Security isn't such a big deal there. [2]
4) Those who purchase games and DLC using PlayStation Store can always choose not to use their credit card for that.
Bottom line? As long as the user's credit card info isn't compromised, he or she will probably care about their PSN security as much as, for example, having their Goodreads account hacked: it would be an annoyance, but not the end of the world.
[1] Trophies and stuff like that have their own value, but most people value their money a lot more than their PSN trophies.
[2] Again, it's not a big deal compared to, for example, having your wallet stolen.
From an informal survey amongst my friends, most of us really don't care. We give dozens of companies this information, and there's kind of an understanding that there's a decent chance of hacking/disgruntled employee rage/what have you at any company. Shit happens.
I am in this camp, as stated in the other HN thread on today's front page: http://news.ycombinator.com/item?id=2560599
Yes, Sony has bad security. Yes, some kid hacked and released his hack to the public, and Sony had that reaction coming what with the linux shenanigans. But I just want to play online games. I do not care that much who is at fault, right, wrong, whatever; everyone has their little crusade. Just let me play with what I paid for.
Q. Who actually stopped me from being able to do that? Who interfered with my fun time?
A. The thieves and the people ruining games with hacks outside of sandboxes with friends.
I blame the ones who shot the gun.
Yes, Sony has bad security. Yes, some kid hacked and released his hack to the public, and Sony had that reaction coming what with the linux shenanigans. But I just want to play online games. I do not care that much who is at fault, right, wrong, whatever; everyone has their little crusade. Just let me play with what I paid for.
Q. Who actually stopped me from being able to do that? Who interfered with my fun time?
A. The thieves and the people ruining games with hacks outside of sandboxes with friends.
I blame the ones who shot the gun.
Xbox Live is still working.
I can't speak of the psychological reasons, but I am not surprised at all. Recall the brouhaha when Call of Duty: Modern Warfare 2 would not come with dedicated servers in the PC version:
http://i.imgur.com/9wKiV.jpg
http://i.imgur.com/9wKiV.jpg
Also recall the difference in tone between these forums and the PSN forums when Geohot was under attack by Sony. Some people simply do not understand the consequences of what has happened and only care about playing their games again.
I couldn't figure out how to delete my account from the PSN website. I don't own a PS3 anymore but I still have an account, which is a bummer.
As a tangent to the article itself, is "THENEXTWEB" a scraper site or content farm?
Who the hell ends an article with this sentence?
Who the hell ends an article with this sentence?
If a multi-billion dollar company like Sony can have the
Do they not have editors? Do they not check what they post after it's posted?Maybe they got confused since most of the income/valuation figures for Sony are in Yen.
Reseting passwords using email addresses and birthdays.
Admittedly, given the information that Sony knows about you, what else could they use to reset passwords that the bad guys don't have?
Edit: Wait, reading more of the articles, this exploit doesn't send a password reset email, or similar, to the users; and just allows them to enter a new password? That's ... convenient, but at an enormous cost. I retract my confusion.
Admittedly, given the information that Sony knows about you, what else could they use to reset passwords that the bad guys don't have?
Edit: Wait, reading more of the articles, this exploit doesn't send a password reset email, or similar, to the users; and just allows them to enter a new password? That's ... convenient, but at an enormous cost. I retract my confusion.
Somewhat ironic: PSN HQ is in Redwood Shores, also home to a few high-profile security companies like Qualys, Imperva, and Checkpoint.
You'd think that after two successful hacking incidents, the execs would have brought in top-notch security people to get the house in order. (Maybe they thought they did.)
You'd think that after two successful hacking incidents, the execs would have brought in top-notch security people to get the house in order. (Maybe they thought they did.)
Even if they did, PSN is a fairly big piece of IT and considering what we've seen so far I'd expect the issues to run deep into the system. It's not like a month is sufficient to completely reimplement everything from the ground up, especially when SCE first spent a week saying everything was fine and nothing had happened.
:(
Will someone pull these assholes aside, slap them a couple of times and remind them that they're messing stuff up for the rest of us? Call of Duty multiplayer be damned, every time this happens they're giving those knee-jerk, reactionary geniuses in Washington more rope to hang us all with when it comes to the Internet.
Which "assholes" are you talking about? The Sony developers who left a huge glaring security hole wide open on their website, the third-party security consultants whom Sony hired to catch these kinds of mistakes before going live or the person who spotted the obvious security flaw and did the reasonable thing to alert Sony about their mistake.
Is the "reasonable" thing here "hacking the sony site"? If it is, you are wrong. That isn't reasonable.
Hacking the site? They found an obvious security vulnerability, tested it, and alerted the company. What should they have done? Sit back and wait for a bad actor to exploit it?
Okay did you read the article? It points directly to a link that explains how someone found yet another vulnerability in PSN and that individuals were already exploiting it.
http://sony.nyleveia.com/2011/05/17/warning-all-psn-users-yo...
http://sony.nyleveia.com/2011/05/17/warning-all-psn-users-yo...
I think I misunderstood who you were talking about in the grandparent post: It seemed like you were railing against the people who wrote the article for testing the exploit and describing it online.
So what do you think someone should do when they find a major security hole in a web site?