4 ms·
I think you read the article wrong. Sony is stating that they detected a large number of sign in attempts, which many failed, but 93,000 succeeded. The attemp
by phsr 15y ago
I think you read the article wrong. Sony is stating that they detected a large number of sign in attempts, which many failed, but 93,000 succeeded. The attempts were made using the data (they assume) obtained from the prior hacks on the various Sony sites. This is not a new breach, but a follow through with the data from prior breaches, probably due to the affected users not updating their credentials from the prior hack.
On issue that JoachimSchipper points out [1] is that Sony probably isn't rate limiting, or throttling login attempts, which is a security issue, as it opens up the possibility of brute force attacks
[1] http://news.ycombinator.com/item?id=3102489 http://news.ycombinator.com/item?id=3102489
- tibbon 15y agoMaybe this doesn't work on something the scale of Sony, but if I detected a breach, I'd identify all effected users, and automatically force change of all their passwords (Google does this), making old authentication data stale.
- elliottcarlson 15y agoAfter the prior breach every had to update their password. The real question is if checks were in place to prevent reusing old passwords.
- cube13 15y agoI haven't had a chance to change my password yet. The website that allowed you to do so had some security issue that forced it to be taken down. Thankfully, I originally used a throwaway password and don't have a valid credit card on that account anymore, so I honestly don't care at this point what happens to it.