Author Topic: PlayStation Network hacked, personal information of 77 million accounts compromised  (Read 6809 times)

0 Members and 1 Guest are viewing this topic.

Offline BucklingSpring

  • Thread Starter
  • Posts: 1613
Explicit subject...

This is probably a Guinness World Record's grade for the biggest breach in history.

Apparently Android and other PDA/SmartPhone OS' are not much stronger than Sony's

So what do you think… Is it the end of the world as we know it?
In memory of smallfry 1996-2013
Boards I own, click ->
More
Ducky x2 (9008G2 Pro PBT/MX Green and Mini MX Red), Matias x2 (QP and Mini QP Dampened ALPS), Topre RealForce x4 (87U 55g/Digilog case, 103U-UW & 104UG High-Profile x2), Filco Majestouch x2 (TKL MX Blue & V2 AI 104 MX Blue), IBM-M x2 (BS & RD), Unicomp-M x5 (BS black on black x2, BS Ivory x2, QT Ultra-Classic), Deck x4 (Legend MX Black & MX Clear, Hassium & Francium w/ MX Brown), DAS III (MX Blue), KBT Pure Pro 60% (MX Red), NMB-RT8256CW+ x2 (black space invader), XArmor U9BL-S (MX Brown) given for free to someone I hate, CM X2 (Trigger/MX Green + Storm TKL/NovaTouch), TVS GOLD (MX Blue) and a many many more (NMB, DELL, MS, ATT, KeyTronic, Etc...)

Offline BucklingSpring

  • Thread Starter
  • Posts: 1613
Quote from: ripster;338381
Maybe THAT'S where my Credit Card info got stolen.

Visa didn't particularly seem interested in catching the culprit when I talked to them


They don't make a big deal of it on the phone. But they do their homework...
It really depends what went wrong with your card.

There are so many scenarios – Here's a couple just to name a couple
  • Dumpster diving to retrieve and steal data for carbon paper (small breach, low interest)
  • Card cloned while swiped in a compromised sales point. All cards known to have been swiped during the suspected compromised window will be deactivated (still small-medium breach, low interest)
  • Transactional Internet site compromised, gazillion cards stolen (major breach, high profile – They'll work day and night to track the hack. But the wise ones are often in Russia or China where US have very little reach.


Good old Wikipedia for CC fraud 101
In memory of smallfry 1996-2013
Boards I own, click ->
More
Ducky x2 (9008G2 Pro PBT/MX Green and Mini MX Red), Matias x2 (QP and Mini QP Dampened ALPS), Topre RealForce x4 (87U 55g/Digilog case, 103U-UW & 104UG High-Profile x2), Filco Majestouch x2 (TKL MX Blue & V2 AI 104 MX Blue), IBM-M x2 (BS & RD), Unicomp-M x5 (BS black on black x2, BS Ivory x2, QT Ultra-Classic), Deck x4 (Legend MX Black & MX Clear, Hassium & Francium w/ MX Brown), DAS III (MX Blue), KBT Pure Pro 60% (MX Red), NMB-RT8256CW+ x2 (black space invader), XArmor U9BL-S (MX Brown) given for free to someone I hate, CM X2 (Trigger/MX Green + Storm TKL/NovaTouch), TVS GOLD (MX Blue) and a many many more (NMB, DELL, MS, ATT, KeyTronic, Etc...)

Offline BucklingSpring

  • Thread Starter
  • Posts: 1613
Quote from: ripster;338417
Main thing with the PSN attack is you better not be using the same password as your bank accounts or you can be royally screwed.


Why not? It is so easyier to remember :-)

Credit card companies are so paranoid... I wouldn't be surprised if they cancell all the cards used to purchase a Play Station.
In memory of smallfry 1996-2013
Boards I own, click ->
More
Ducky x2 (9008G2 Pro PBT/MX Green and Mini MX Red), Matias x2 (QP and Mini QP Dampened ALPS), Topre RealForce x4 (87U 55g/Digilog case, 103U-UW & 104UG High-Profile x2), Filco Majestouch x2 (TKL MX Blue & V2 AI 104 MX Blue), IBM-M x2 (BS & RD), Unicomp-M x5 (BS black on black x2, BS Ivory x2, QT Ultra-Classic), Deck x4 (Legend MX Black & MX Clear, Hassium & Francium w/ MX Brown), DAS III (MX Blue), KBT Pure Pro 60% (MX Red), NMB-RT8256CW+ x2 (black space invader), XArmor U9BL-S (MX Brown) given for free to someone I hate, CM X2 (Trigger/MX Green + Storm TKL/NovaTouch), TVS GOLD (MX Blue) and a many many more (NMB, DELL, MS, ATT, KeyTronic, Etc...)

Offline Ekaros

  • Posts: 942
Quote from: ripster;338417
Main thing with the PSN attack is you better not be using the same password as your bank accounts or you can be royally screwed.

 
Or they could over do it like here in Finland. My bank requires 8 number indetifier+4 number Pin...

And one time usable pin. Still, CCs are less protected, if they don't force using this same system...

Still, CCs are somewhat unsafe, for the services which keep info around...

77Million, it hasn't yet been on web, so I guess it's "professional" job. Quite nice penny for info it has, even if CCs are not usable...
So I should add something useless here yes? Ok, ok...
Filco 105-key NKRO MX Browns Sw/Fi-layout|IBM Model M 1394545 Lexmark 102-key Finnish-layout 1994-03-22|Cherry G80-3000LQCDE-2 with MX CLEAR
[SIGPIC][/SIGPIC]
Dell AT102W(105-key SF) (Black ALPS)|Steelseries Steelkeys 6G(MX Black) ISO-FI-layout|Cherry G84-4400 G84-4700 Cherry MLs

Offline sndstrm

  • Posts: 56
Whats funny is that every Xbox360 user is sitting back snickering.

Quote from: Ekaros;339047
77Million, it hasn't yet been on web, so I guess it's "professional" job. Quite nice penny for info it has, even if CCs are not usable...


You mean it hasn't posted on Wikileaks?
rm -Rf /*

Offline Ekaros

  • Posts: 942
Quote from: sndstrm;339048
Whats funny is that every Xbox360 user is sitting back snickering.



You mean it hasn't posted on Wikileaks?

Or to piratebay ;D
So I should add something useless here yes? Ok, ok...
Filco 105-key NKRO MX Browns Sw/Fi-layout|IBM Model M 1394545 Lexmark 102-key Finnish-layout 1994-03-22|Cherry G80-3000LQCDE-2 with MX CLEAR
[SIGPIC][/SIGPIC]
Dell AT102W(105-key SF) (Black ALPS)|Steelseries Steelkeys 6G(MX Black) ISO-FI-layout|Cherry G84-4400 G84-4700 Cherry MLs

Offline sndstrm

  • Posts: 56
Quote from: Ekaros;339050
Or to piratebay ;D

Eww, that would be ugly.  I pretty sure piratebay has been shutdown though.
rm -Rf /*

Offline Ekaros

  • Posts: 942
Quote from: sndstrm;339072
Eww, that would be ugly.  I pretty sure piratebay has been shutdown though.

It would, but style of Anonymous and some for fame hackers... When did you last check on thepiratebay?
So I should add something useless here yes? Ok, ok...
Filco 105-key NKRO MX Browns Sw/Fi-layout|IBM Model M 1394545 Lexmark 102-key Finnish-layout 1994-03-22|Cherry G80-3000LQCDE-2 with MX CLEAR
[SIGPIC][/SIGPIC]
Dell AT102W(105-key SF) (Black ALPS)|Steelseries Steelkeys 6G(MX Black) ISO-FI-layout|Cherry G84-4400 G84-4700 Cherry MLs

Offline sndstrm

  • Posts: 56
Quote from: Ekaros;339075
It would, but style of Anonymous and some for fame hackers... When did you last check on thepiratebay?

Well I know they have been in some pretty heavy legal trouble and heard they were being shut down.  When you mentioned it I tried going to it and I get this.
« Last Edit: Fri, 29 April 2011, 07:51:58 by sndstrm »
rm -Rf /*

Offline sndstrm

  • Posts: 56
Not that I was trying to look up 77,000,000 credit card numbers >=]
rm -Rf /*

Offline Ekaros

  • Posts: 942
Quote from: sndstrm;339077
Well I know they have been in some pretty heavy legal trouble and heard they were being shut down.  When you mentioned it I tried going to it and I get this.

You got an evil ISP, works perfectly fine here... Certain ISPs and countries block it, free internet, no cencorship...


Only, 2,2M "lost"... Still, I heard the other info might be good...
So I should add something useless here yes? Ok, ok...
Filco 105-key NKRO MX Browns Sw/Fi-layout|IBM Model M 1394545 Lexmark 102-key Finnish-layout 1994-03-22|Cherry G80-3000LQCDE-2 with MX CLEAR
[SIGPIC][/SIGPIC]
Dell AT102W(105-key SF) (Black ALPS)|Steelseries Steelkeys 6G(MX Black) ISO-FI-layout|Cherry G84-4400 G84-4700 Cherry MLs

Offline sndstrm

  • Posts: 56
Quote from: Ekaros;339086
You got an evil ISP, works perfectly fine here... Certain ISPs and countries block it, free internet, no cencorship...

I kinda had a feeling that was the problem.  I wish I wouldn't have seen that because now it's going to eat at me.  I'm an isohunt evangelist anyways!
rm -Rf /*

Offline reaper

  • ** Moderator Emeritus
  • Posts: 3067
I don't know if any of you guys have accounts over at DSL Reports web site but they were attacked via SQL injection method just a few days ago.  Emails & passwords were stolen.

http://news.cnet.com/8301-27080_3-20058471-245.html

Theres's a link in the article that takes you directly to discussion on their forum.
« Last Edit: Fri, 29 April 2011, 18:00:48 by reaper »
Att fly är livet, att dröja, döden.
Din Eli

Offline reaper

  • ** Moderator Emeritus
  • Posts: 3067
And then we have this guy selling CC & CCV dumps, skimmers, etc. on this very forum. lol
Att fly är livet, att dröja, döden.
Din Eli

Offline audioave10

  • Posts: 498
This is not the first time that Sony has screwed-up.
DECK Legend "Toxic" - SOLD
96 IBM Model M 82G2383- 95 IBM Model M 92G7453 - SOLD
Cherry G80-3000/Blues
new: MechanicalEagle Z77 RGB/Blues

Offline Voixdelion

  • Posts: 338
sony is royally pissing me off lately.   Now i got email re the xfactor audition registrations at fox - apparently they have also gotten hit too, though the amazing thing is thney didn't hsve much more than email and name anyway.  What really irks me about the psn thing is the amount of info that was available for them to steal - name phone address email login pass age dob ... why did sony even need all that for their little game network anyway?
"The more you tolerate each other, the less enforcement will happen."-iMav

Offline sndstrm

  • Posts: 56
Quote from: Voixdelion;339446
... why did sony even need all that for their little game network anyway?

Very good question.  They would say something like, "that is the required info for billing purposes".  Too bad you cant link the payment to paypal so you wouldnt have your billing info spread to the four winds.  But the psn network is supposed to free anyways.  Well their basic subscription anyways.
rm -Rf /*

Offline sndstrm

  • Posts: 56
Quote from: ripster;339502
My dob is always Jan 1.  Gung Hay Fat Choy is my city of birth.

Gung Hay Fat Choy, Alabama
rm -Rf /*

Offline godly_music

  • Posts: 255
eBay and Amazon are equally prone to screw up big, so this is not a Sony problem. This is a problem of massive data graves. Since nobody really likes Sony, well, hooray to us.

Offline instantkamera

  • Posts: 617
Quote from: BucklingSpring;338379

Apparently Android and other PDA/SmartPhone OS' are not much stronger than Sony's


?
Realforce 86UB - Razer Blackwidow - Dell AT101W - IBM model MCST  LtracX - Kensington Orbit - Logitech Trackman wheel opticalAMD PhenomII x6 - 16GB RAM - SSD - RAIDDell U2211H - Spyder3 - Eye One Display 2

Offline BucklingSpring

  • Thread Starter
  • Posts: 1613
Quote from: ripster;339318
Time to open up yet another email account for Forum use!


That's the way to go... I love unlimited aliases on paying webmail services.
It takes a split second to create and is live as soon as you click OK.

Then if I ever receive spam at MyGeekhack@whatever.com. I know where something went wrong… :-)
In memory of smallfry 1996-2013
Boards I own, click ->
More
Ducky x2 (9008G2 Pro PBT/MX Green and Mini MX Red), Matias x2 (QP and Mini QP Dampened ALPS), Topre RealForce x4 (87U 55g/Digilog case, 103U-UW & 104UG High-Profile x2), Filco Majestouch x2 (TKL MX Blue & V2 AI 104 MX Blue), IBM-M x2 (BS & RD), Unicomp-M x5 (BS black on black x2, BS Ivory x2, QT Ultra-Classic), Deck x4 (Legend MX Black & MX Clear, Hassium & Francium w/ MX Brown), DAS III (MX Blue), KBT Pure Pro 60% (MX Red), NMB-RT8256CW+ x2 (black space invader), XArmor U9BL-S (MX Brown) given for free to someone I hate, CM X2 (Trigger/MX Green + Storm TKL/NovaTouch), TVS GOLD (MX Blue) and a many many more (NMB, DELL, MS, ATT, KeyTronic, Etc...)

Offline BucklingSpring

  • Thread Starter
  • Posts: 1613
Quote from: instantkamera;340025
?

Just a matter of time before a major leak makes it to the news.
In memory of smallfry 1996-2013
Boards I own, click ->
More
Ducky x2 (9008G2 Pro PBT/MX Green and Mini MX Red), Matias x2 (QP and Mini QP Dampened ALPS), Topre RealForce x4 (87U 55g/Digilog case, 103U-UW & 104UG High-Profile x2), Filco Majestouch x2 (TKL MX Blue & V2 AI 104 MX Blue), IBM-M x2 (BS & RD), Unicomp-M x5 (BS black on black x2, BS Ivory x2, QT Ultra-Classic), Deck x4 (Legend MX Black & MX Clear, Hassium & Francium w/ MX Brown), DAS III (MX Blue), KBT Pure Pro 60% (MX Red), NMB-RT8256CW+ x2 (black space invader), XArmor U9BL-S (MX Brown) given for free to someone I hate, CM X2 (Trigger/MX Green + Storm TKL/NovaTouch), TVS GOLD (MX Blue) and a many many more (NMB, DELL, MS, ATT, KeyTronic, Etc...)

Offline instantkamera

  • Posts: 617
Where is the "apparent" weakness? If you are talking about "tracking data", that isn't really in the same scope, plain-text or otherwise.
Realforce 86UB - Razer Blackwidow - Dell AT101W - IBM model MCST  LtracX - Kensington Orbit - Logitech Trackman wheel opticalAMD PhenomII x6 - 16GB RAM - SSD - RAIDDell U2211H - Spyder3 - Eye One Display 2

Offline BucklingSpring

  • Thread Starter
  • Posts: 1613
Quote from: instantkamera;340669
Where is the "apparent" weakness? If you are talking about "tracking data", that isn't really in the same scope, plain-text or otherwise.


On the end user side, most phones are not encrypted vaults (Unless hardened). On the Network side, I don't know how Wireless phone companies are managing their central databases.
In memory of smallfry 1996-2013
Boards I own, click ->
More
Ducky x2 (9008G2 Pro PBT/MX Green and Mini MX Red), Matias x2 (QP and Mini QP Dampened ALPS), Topre RealForce x4 (87U 55g/Digilog case, 103U-UW & 104UG High-Profile x2), Filco Majestouch x2 (TKL MX Blue & V2 AI 104 MX Blue), IBM-M x2 (BS & RD), Unicomp-M x5 (BS black on black x2, BS Ivory x2, QT Ultra-Classic), Deck x4 (Legend MX Black & MX Clear, Hassium & Francium w/ MX Brown), DAS III (MX Blue), KBT Pure Pro 60% (MX Red), NMB-RT8256CW+ x2 (black space invader), XArmor U9BL-S (MX Brown) given for free to someone I hate, CM X2 (Trigger/MX Green + Storm TKL/NovaTouch), TVS GOLD (MX Blue) and a many many more (NMB, DELL, MS, ATT, KeyTronic, Etc...)

Offline Ekaros

  • Posts: 942
BTW, my PC still works online? How is that consoles "it just works"? ;D

Ease of gaming...
So I should add something useless here yes? Ok, ok...
Filco 105-key NKRO MX Browns Sw/Fi-layout|IBM Model M 1394545 Lexmark 102-key Finnish-layout 1994-03-22|Cherry G80-3000LQCDE-2 with MX CLEAR
[SIGPIC][/SIGPIC]
Dell AT102W(105-key SF) (Black ALPS)|Steelseries Steelkeys 6G(MX Black) ISO-FI-layout|Cherry G84-4400 G84-4700 Cherry MLs


Offline Voixdelion

  • Posts: 338
Re: NEW security hole/exploit:

Well, duh.

What kind of security fix lets you reset your stolen password with the same information that was already confirmed as being stolen?!   0_o  

My nomination  for the epic fail/Darwin award goes to Sony this year.  Cripes!
"The more you tolerate each other, the less enforcement will happen."-iMav

Offline audioave10

  • Posts: 498
That video lags like crazy. I'm not crazy about controller movement either. Mafia II on PC looks better (I don't care about AA). Ripster, please, check other PC forums about PC games and hardware. OCN is not the best place to hang out. I only use one video card too.
DECK Legend "Toxic" - SOLD
96 IBM Model M 82G2383- 95 IBM Model M 92G7453 - SOLD
Cherry G80-3000/Blues
new: MechanicalEagle Z77 RGB/Blues

Offline Voixdelion

  • Posts: 338
So it wasn't really a "hack", but it WAS a "hole"... only if you reset the pass through the website instead of from the ps3 directly apparently.  But still, I missed the logic train in using personal data which is known to be exposed  as criteria for proving your identity.  That just seems like a no-brainer to me.  I still think this is the fault of trying to mine and store so much information (particularly when it isn't even warranted for those specific purposes.)  Sony is a complete cluster **** lately.  What happened over there?
"The more you tolerate each other, the less enforcement will happen."-iMav

Offline audioave10

  • Posts: 498
They are currently busy trying to put 80 year old grandmothers in jail because their grandson downloaded a movie.
DECK Legend "Toxic" - SOLD
96 IBM Model M 82G2383- 95 IBM Model M 92G7453 - SOLD
Cherry G80-3000/Blues
new: MechanicalEagle Z77 RGB/Blues

Offline BucklingSpring

  • Thread Starter
  • Posts: 1613
Quote from: Voixdelion;348373
So it wasn't really a "hack", but it WAS a "hole"... only if you reset the pass through the website instead of from the ps3 directly apparently.  But still, I missed the logic train in using personal data which is known to be exposed  as criteria for proving your identity.  That just seems like a no-brainer to me.  I still think this is the fault of trying to mine and store so much information (particularly when it isn't even warranted for those specific purposes.)  Sony is a complete cluster **** lately.  What happened over there?


Technically, you don't need to break or force anything to be considered a hack.
You are "hacking" as soon as you exploit or abuse the system for anything beyond your written rights and privileges.

No matter what, the hacker is exposed to serious legal retributions from the system owner. If a crime was committed, the hacker will also have the law on his back.

If the system owner was negligent at protecting personally identifiable information (PII) or financial data such as credit card information. Then he is also exposed to some major problems such as user class actions and even Federal/States lawsuits.

On the long run, this is going to be an interresting Sony story.
But they have so much money... They can afford to be dumb.
In memory of smallfry 1996-2013
Boards I own, click ->
More
Ducky x2 (9008G2 Pro PBT/MX Green and Mini MX Red), Matias x2 (QP and Mini QP Dampened ALPS), Topre RealForce x4 (87U 55g/Digilog case, 103U-UW & 104UG High-Profile x2), Filco Majestouch x2 (TKL MX Blue & V2 AI 104 MX Blue), IBM-M x2 (BS & RD), Unicomp-M x5 (BS black on black x2, BS Ivory x2, QT Ultra-Classic), Deck x4 (Legend MX Black & MX Clear, Hassium & Francium w/ MX Brown), DAS III (MX Blue), KBT Pure Pro 60% (MX Red), NMB-RT8256CW+ x2 (black space invader), XArmor U9BL-S (MX Brown) given for free to someone I hate, CM X2 (Trigger/MX Green + Storm TKL/NovaTouch), TVS GOLD (MX Blue) and a many many more (NMB, DELL, MS, ATT, KeyTronic, Etc...)

Offline BucklingSpring

  • Thread Starter
  • Posts: 1613
Quote from: ripster;349802
I laugh at ethical corporate concerns. That's why I own AAPL.
(Attachment Link) 18410[/ATTACH]

 
ROFL - Did Panda-R hit again? She looks like she might be his daughter.
In memory of smallfry 1996-2013
Boards I own, click ->
More
Ducky x2 (9008G2 Pro PBT/MX Green and Mini MX Red), Matias x2 (QP and Mini QP Dampened ALPS), Topre RealForce x4 (87U 55g/Digilog case, 103U-UW & 104UG High-Profile x2), Filco Majestouch x2 (TKL MX Blue & V2 AI 104 MX Blue), IBM-M x2 (BS & RD), Unicomp-M x5 (BS black on black x2, BS Ivory x2, QT Ultra-Classic), Deck x4 (Legend MX Black & MX Clear, Hassium & Francium w/ MX Brown), DAS III (MX Blue), KBT Pure Pro 60% (MX Red), NMB-RT8256CW+ x2 (black space invader), XArmor U9BL-S (MX Brown) given for free to someone I hate, CM X2 (Trigger/MX Green + Storm TKL/NovaTouch), TVS GOLD (MX Blue) and a many many more (NMB, DELL, MS, ATT, KeyTronic, Etc...)