4 ms·
There were sixty million[0] PSN accounts. This is impressive, and amounts to (judging by a quick search) the largest-scale ID (and possibly credit-card) theft e
by hebejebelus 15y ago
There were sixty million[0] PSN accounts. This is impressive, and amounts to (judging by a quick search) the largest-scale ID (and possibly credit-card) theft ever [Not so, see child comment]. Not even factoring in credit card details, the usernames, emails, addresses, ages, passwords, mother's maiden names, favourite pets, of sixty million people is worth a hell of a lot.
I have to wonder how much data that is, in terms of storage. How could you even take that without someone noticing?
Hats off to whoever it was. Now, I'm off to change my passwords. Thank Christ I had the sense not to use a credit card to buy from PSN.
[0] http://www.derangedshaman.com/2011/01/06/sonys-60-million-psn-users-means-zero-zilch-nada/ http://www.derangedshaman.com/2011/01/06/sonys-60-million-ps...
[edit] On a related note, paypal refuses to let my change my password to something longer than 20 characters - or have spaces in my password. Why is this the case? Surely the only thing that an upper limit on the length of a password does is help the attacker.
- samlevine 15y agofwiw the Heartland incident involved 130,000,000 records: http://datalossdb.org/ http://datalossdb.org/ Not to lessen the extent of this, but it's not nearly the biggest dataloss incident ever.
- c2 15y agoTJ Maxx data theft involved 45 million confirmed credit card/debit card numbers stolen, which I believe was more serious then this: http://www.msnbc.msn.com/id/17853440/ http://www.msnbc.msn.com/id/17853440/ Fact is people put most of that other information on Facebook anyway, so for 500 million people, you can quite easily find someone's age, birthday, pets, and much more just from their FB account.
- joeyh 15y agoOverestimating 100k per user, it would only be 6 terabytes. And all those low-entropy passwords etc should compress quite well.
- fragsworth 15y agoThey would only compress well if you stored them in plaintext...
- ZoFreX 15y ago20 characters is quite generous. 123-reg (semi-popular domain reseller) insists on eight. Not seven. Not nine. Eight exactly.
- mdaniel 15y agoWhile I detest PayPal, and it makes me livid that any company places upper-bound (and/or character) restrictions on passwords, I did want to mention that Yubico provides a two-factor authentication key which works with PayPal: http://yubico.com/VIP http://yubico.com/VIP I don't have any stake in either company, but I was glad when Google rolled out 2-factor and I am especially glad to be able to finally use 2-factor for safeguarding my money.