5 ms·
FTA: we believe that an unauthorized person has obtained the following information that you provided: ...PlayStation Network/Qriocity password and login... I'm
by norova 15y ago
FTA: we believe that an unauthorized person has obtained the following information that you provided: ...PlayStation Network/Qriocity password and login...
I'm curious if this means they store everyone's password in plain-text, or if by "password" they really mean a hash of some sort.
- rhizome 15y agoFrankly I'm more concerned with their words about changing credit cards if you've made a purchase through PSN. This seems to be an admission that they were storing CC#'s in plain text.
- ak217 15y agoHow do you use stored credit card info if the cc# is not stored? Unlike passwords, the encryption for the cc#s has to be reversible. That's part of the reason why they introduced CVCs, right?
- jimktrains2 15y agoYou could at least have them encrypted on disk with a key only stored in memory, i.e.: when the system is turned on. Alternatively a dedicated crypo device where you feed it cipher text and it gives you plain text would also help as the attack wouldn't be able to get the key (even if they have the physical box (for good crypto devices)) While only marginally better depending on the type of attack and permissions gained by the attacker, if all they got was static data on disk, then it would be secure.
- cookiecaper 15y agoAnd what if that server needs to be rebooted some day? What if there's a hardware failure and it has to be powered off? Something as big as PSN has multiple servers reading the same DB and must be able to tolerate failures without forcing everyone to re-enter their CC #. The keys must be stored persistently somewhere.
- tzs 15y agoWhat we do where I work is take the newly generated key whenever we key or rekey the system, split it into multiple pieces using Shamir's secret sharing algorithm, and those pieces are distributed to several people. Whenever the server needs to be started, two of those people must enter their key shares. That enables the server to reconstruct the key, which is then stored in memory.
- jimktrains2 15y agoAs tzs said, you basically have to have someone(s) restart the system and re-enter they key.
- Terretta 15y ago> How do you use stored credit card info if the cc# is not stored? Simplifying just a bit -- The one time you pass the # along to the bank, they give you back a transaction ID you can use to do future things with that card. The bank knows the number, looks it up by that ID.
- macrael 15y agoI don't know much about online credit card transactions, but how are you supposed to do it? Don't you need the number to transfer to Visa or whoever in order to get money out of someone's account?
- lotu 15y agoBecause Sony would need to send your unencrypted CC# to your CC company when you make a purchase is it even possible to not store it in plain text?
- rhizome 15y agoIt could be encrypted, but maybe the attackers got the key/salt as well.
- loire280 15y agoPCI requires that CC#'s are stored encrypted in the database. A service this big has had a full PCI compliance overview, and they wouldn't miss a basic requirement like that (I hope).
- dspillett 15y agoBut if the keys are also stored somewhere where the hackers managed to gain access, they may be able to make use of the information.
- drivebyacct2 15y agoHaving access to a few of my passwords online has effects that range from my current to future employment, relationships with friends, partners, s.o's, future employers, all of my bank accounts, etc. And I have better password practices than most. Credit cards might be an immediate thought, but how many other physical and intangible assets does your password give a hacker access to?
- marshray 15y agoIt may be that the attackers pwned the servers and skimmed the numbers (including CVV) as they were HTTP POSTed in plain text.
- uxp 15y agoThat wouldn't work over SSL, as there is no plain text in the HTTP Verb. And I recall a "paper" coming up some months ago that was mentioning the protocols the PS3 goes through, which does confirm that the data is transmitted over SSL.[0] [0] http://arstechnica.com/gaming/news/2011/02/report-psn-hacked-showing-stunning-lack-of-credit-card-security.ars http://arstechnica.com/gaming/news/2011/02/report-psn-hacked...
- marshray 15y agoThe SSL gets decrypted inside the web server process memory, at the latest. Sometimes it's stripped off by an SSL offload accelerator device before even entering the web server. The numbers probably also cross the wire in plain text between the web server and the database too.
- rhizome 15y agoAnecdotal, but I'd say stripping SSL at the border is much more common that leaving it intact to the node.
- holdenk 15y agoIf the attacker "0wned" the servers the fact there was encryption between you and the server doesn't really help a whole lot, they can just insert them selves in the stack post encryption (or even use the private key to decrypt the encrypted traffic if they wanted to minimize the number of points they touched).
- redthrowaway 15y ago"as they were HTTP POSTed in plain text." Why on earth would you ever do that?
- jzila 15y agoThis would be such an incredibly stupid security failure. Passwords should always be salted and hashed. Credit card info should always be HSM-protected so that it is irretrievable except through a hardware API. What was Sony thinking!?
- marshray 15y agoCredit card info should always be HSM-protected so that it is irretrievable except through a hardware API. How could you suggest such a thing?! That would have cost Sony thousands of dollars extra!
- phillijw 15y agoPossibly even hundreds!
- dedward 15y agoCredit card storage practices are dictated by the PCI standards - and they don't require that level of encryption.
- rm445 15y agoGood question. When you reset your PSN password, they send you a link, rather than your password in plaintext, which at least hints they were doing the right thing. But who knows.
- phaylon 15y agoEven if the passwords were stored in a hashed format, people might have sent their credentials to a compromised system.