The Playstation 3 is IDENTITY THEFT

Message Bookmarked
Bookmark Removed
Not all messages are displayed: show all messages (2009 of them)

The fun bit is imagining how Gabe Newell must be reacting to all this.

JimD, Tuesday, 26 April 2011 22:37 (thirteen years ago) link

I'll be really curious to see how much of an impact (if any) this debacle has on the NGP since it's going to be PSN-only.

you penis-curling she-devils (jamescobo), Wednesday, 27 April 2011 00:41 (thirteen years ago) link

no hacker would be stupid enough to do anything with CC information now. best would be to wait several months. then little purchases here and there.

gah between this and the gawker thing it's enough to make me paranoid for life.

40% chill and 100% negative (Tracer Hand), Wednesday, 27 April 2011 15:24 (thirteen years ago) link

hoping they don't retain card details from over a year ago

if you wanna gamble, take that shit to vegas (Ste), Wednesday, 27 April 2011 15:31 (thirteen years ago) link

why wouldn't they? if they stored all this shit unencrypted and unhashed, they're liable to do any goddamn thing

40% chill and 100% negative (Tracer Hand), Wednesday, 27 April 2011 15:38 (thirteen years ago) link

I'm trying to remember if the credit card info I used to buy Wipeout 2 years ago is before I changed my card or not. This kind of sucks. And I feel dumb for not having removed the credit card info associated with my PSN account after having made that one purchase.

peter in montreal, Wednesday, 27 April 2011 16:12 (thirteen years ago) link

I've checked my bacnk account like 5 times today but like I said any shenanigans wouldn't happen for awhile if the hax0rs are smart (and if they managed to get CC details in the first place, which hasn't been confirmed yet; though all the other information exposed is damaging enough in itself. I mean, with all that's been exposed, a hacker could probably just apply for a credit card in my name.)

40% chill and 100% negative (Tracer Hand), Wednesday, 27 April 2011 16:15 (thirteen years ago) link

eh, I don't think they have enough to do that; Sony's only confirmed that they got names, physical addresses, phone numbers, mailing addresses, birthday, email addresses/PWs, and possibly password security questions/answers. you definitely need more personal info than that (SS# in particular) to get credit, unless of course you've got the same login/password combo for your bank as for your PSN account (do not do this).

not that I'm excusing Sony in the slightest! I have to go to the bank today and get my card killed then disable all my bill autopayments then set them all up again when the new card comes in thanks to their decision to put the Dr. Nick Riviera of data security in charge of their team. they can also go fuck the sun for waiting a full week to give people a heads-up about their personal data being compromised; surely that's in violation of some consumer-protection laws (Gawker at least had the decency to let me know within a day or two of the weekend when all that shit went down). really hard to imagine that they won't get hit with a massive, massive suit over this.

speaking of Gawker, the one good thing about that whole ordeal was that it led me to pull the trigger on the 1Password suite which is why I'm reasonably copasetic about all this bullshit at the moment. imo it's must-have gear for anyone who uses the internet.

you penis-curling she-devils (jamescobo), Wednesday, 27 April 2011 16:47 (thirteen years ago) link

yeah, i was just looking at 1Password myself. i haven't done it yet though cause like, what if i need to register for a site at work and don't have 1Password? and what about all my existing sites? there's probably 100 sites i've bought something from over the last several years.

40% chill and 100% negative (Tracer Hand), Wednesday, 27 April 2011 17:03 (thirteen years ago) link

I guess I should go to the bank and get a new card, too. God damn it. This has also affected me at work (I work in the industry) as I had a bunch of content scheduled to release this week and it all got pushed out, so I am probably going to have a shitload of paperwork to fill out this week.

rockapads, Wednesday, 27 April 2011 17:13 (thirteen years ago) link

xpost

1password has dropbox sync support for the password list; I just installed both programs on my work computer too and it works great. the iOS 1password apps support it too. I think it's like $40 for the app + the software, which is totally a reasonable amount to pay for peace of mind during a situation like this.

you penis-curling she-devils (jamescobo), Wednesday, 27 April 2011 17:18 (thirteen years ago) link

oh and 1password basically adds logins/passwords to its database in realtime as you browse (it's a browser plugin, not just a standalone program) - to add the 100 sites where you've bought stuff from, just visit them, log in normally, and 1password will ask you if you'd like to add it to your list.

you penis-curling she-devils (jamescobo), Wednesday, 27 April 2011 17:20 (thirteen years ago) link

Hmm... this is actually weighing heavily on my post-E3 purchase decision. Hope Sony explains this screw up adequately and soon.

Nhex, Wednesday, 27 April 2011 17:42 (thirteen years ago) link

1password scares me. Just seems like bad practice to keep passwords "written down" in one place no matter where it is. What if the password for 1password gets hacked, or their service compromised?

rockapads, Wednesday, 27 April 2011 18:13 (thirteen years ago) link

that's why you sign up for 2passwords as well

I just like… I just have to say… (Starts crying) (DJP), Wednesday, 27 April 2011 18:25 (thirteen years ago) link

xpost

it's not a service - the passwords (including the master password for the software) are stored locally in a heavily encrypted file; you have the option of putting it in a Dropbox folder & pointing the 1password program towards that location to sync to your devices/other computers/etc. there's no master database for anyone to hack into - they'd have to get into your actual computer and install a keylogger in order to crack it, and frankly at that point you've got bigger problems to deal with.

sorry if I sound like a 1pass sales rep, this thing is just a lifesaver IMO

you penis-curling she-devils (jamescobo), Wednesday, 27 April 2011 18:28 (thirteen years ago) link

*registers 3passwords.com*

forks (forksclovetofu), Wednesday, 27 April 2011 18:38 (thirteen years ago) link

So what are the minimum number of steps that you guys think people should take in the wake of this security breach? Change of email password? New credit card?

reggaeton for the painfully alone (polyphonic), Wednesday, 27 April 2011 19:08 (thirteen years ago) link

burn everything you own, move to woods

don't judge a book by its jpg (Edward III), Wednesday, 27 April 2011 19:12 (thirteen years ago) link

1. change email password; monitor credit card account (btw, you should already be monitoring your cc account anyway so this shouldn't be an additional burden)

2. if fraudulent charges pop up, contest them immediately and change your card number

I just like… I just have to say… (Starts crying) (DJP), Wednesday, 27 April 2011 19:14 (thirteen years ago) link

yeah, i always monitor my credit card account on a weekly basis

forks (forksclovetofu), Wednesday, 27 April 2011 19:17 (thirteen years ago) link

Sony have my email address. Why haven't they emailed me to at least notify me?

40% chill and 100% negative (Tracer Hand), Wednesday, 27 April 2011 23:57 (thirteen years ago) link

man I feel like a good principle in this new brave age of cyber terrorism is just to take nothing for granted and get your credit card # changed every 3 months

br8080 (dayo), Thursday, 28 April 2011 00:07 (thirteen years ago) link

also change your name, age, and gender every 3 months for maximum protection

br8080 (dayo), Thursday, 28 April 2011 00:07 (thirteen years ago) link

My one trick with some of these kind of sites is not to give my real DOB and certainlynever fill in my real phone # or address. Unless I'm being physically mailed something, they dont need any of that. Make my DOB 01/1/someyear, and my phone number 0312345678. And when I order online things, I get em sent to work.

Concubine Tree (Trayce), Thursday, 28 April 2011 00:09 (thirteen years ago) link

Sony have my email address. Why haven't they emailed me to at least notify me?

They don't have it any more, some guy stole it.

JimD, Thursday, 28 April 2011 07:11 (thirteen years ago) link

blocked, i'd say give me the gist but i can read the url i guess

if you wanna gamble, take that shit to vegas (Ste), Thursday, 28 April 2011 08:46 (thirteen years ago) link

Blocked?

it always seems to have dick smith in it (Autumn Almanac), Thursday, 28 April 2011 08:49 (thirteen years ago) link

Gist: CC tables were encrypted, no evidence those tables were accessed, still a possibility that they were. Check yo self.

every day I'm (onimo), Thursday, 28 April 2011 09:09 (thirteen years ago) link

Also they have confirmed that the usernames, passwords, email addresses, addresses, etc. from the user table was unencrypted and has been taken.

every day I'm (onimo), Thursday, 28 April 2011 09:11 (thirteen years ago) link

Again why am I having to read this in the press? Why haven't I heard from Sony?

40% chill and 100% negative (Tracer Hand), Thursday, 28 April 2011 09:27 (thirteen years ago) link

Though JimD's explanation is admittedly persuasive

40% chill and 100% negative (Tracer Hand), Thursday, 28 April 2011 09:28 (thirteen years ago) link

If Geohot taught us anything, it's how good Sony is at encrypting data. They'll have used the same key for all the encryption, probably, and the credit card data will be open to anyone with a few days to leave a computer decrypting.

One of my friends went to the bank to cancel his cards, and they said the data stolen is enough for someone to apply for credit in his name, but I think that was a ploy to sell him a protection plan at £5/month!

CraigG, Thursday, 28 April 2011 09:40 (thirteen years ago) link

Should be ok if I used paypal on PSN Y/N?

every day I'm (onimo), Thursday, 28 April 2011 09:41 (thirteen years ago) link

¯\(°_°)/¯

here's another take:

http://forums.sarcasticgamer.com/showpost.php?p=645846&postcount=734

40% chill and 100% negative (Tracer Hand), Thursday, 28 April 2011 10:21 (thirteen years ago) link

Sony have my email address. Why haven't they emailed me to at least notify me?

I got an email. Nothing in it that wasn't already on the statements on their sites.

Valued PlayStation Network/Qriocity Customer:

We have discovered that between April 17 and April 19, 2011, certain PlayStation Network and Qriocity service user account information was compromised in connection with an illegal and unauthorized intrusion into our network. In response to this intrusion, we have:

1) Temporarily turned off PlayStation Network and Qriocity services;

2) Engaged an outside, recognized security firm to conduct a full and complete investigation into what happened; and

3) Quickly taken steps to enhance security and strengthen our network infrastructure by re-building our system to provide you with greater protection of your personal information.

We greatly appreciate your patience, understanding and goodwill as we do whatever it takes to resolve these issues as quickly and efficiently as practicable.

Although we are still investigating the details of this incident, we believe that an unauthorized person has obtained the following information that you provided: name, address (city, state/province, zip or postal code), country, email address, birthdate, PlayStation Network/Qriocity password and login, and handle/PSN online ID. It is also possible that your profile data, including purchase history and billing address (city, state, zip), and your PlayStation Network/Qriocity password security answers may have been obtained. If you have authorized a sub-account for your dependent, the same data with respect to your dependent may have been obtained. While there is no evidence that credit card data was taken at this time, we cannot rule out the possibility. If you have provided your credit card data through PlayStation Network or Qriocity, to be on the safe side we are advising you that your credit card number (excluding security code) and expiration date may have been obtained.

For your security, we encourage you to be especially aware of email, telephone, and postal mail scams that ask for personal or sensitive information. Sony will not contact you in any way, including by email, asking for your credit card number, social security, tax identification or similar number or other personally identifiable information. If you are asked for this information, you can be confident Sony is not the entity asking. When the PlayStation Network and Qriocity services are fully restored, we strongly recommend that you log on and change your password. Additionally, if you use your PlayStation Network or Qriocity user name or password for other unrelated services or accounts, we strongly recommend that you change them, as well.

To protect against possible identity theft or other financial loss, we encourage you to remain vigilant to review your account statements and to monitor your credit or similar types of reports.

We thank you for your patience as we complete our investigation of this incident, and we regret any inconvenience. Our teams are working around the clock on this, and services will be restored as soon as possible. Sony takes information protection very seriously and will continue to work to ensure that additional measures are taken to protect personally identifiable information. Providing quality and secure entertainment services to our customers is our utmost priority. Please contact us at www.eu.playstation.com/psnoutage should you have any additional questions.

Sincerely,
Sony Network Entertainment and Sony Computer Entertainment Teams

Sony Network Entertainment Europe Limited

every day I'm (onimo), Thursday, 28 April 2011 10:34 (thirteen years ago) link

http://www.eu.playstation.com/psnoutage

just redirects to http://uk.playstation.com/ for me

I have two PSN accounts and still no email.

40% chill and 100% negative (Tracer Hand), Thursday, 28 April 2011 10:40 (thirteen years ago) link

ah here we go - http://uk.playstation.com/psnoutage

40% chill and 100% negative (Tracer Hand), Thursday, 28 April 2011 10:41 (thirteen years ago) link

p snoutage

it always seems to have dick smith in it (Autumn Almanac), Thursday, 28 April 2011 10:43 (thirteen years ago) link

pretty snoutage imo

40% chill and 100% negative (Tracer Hand), Thursday, 28 April 2011 10:44 (thirteen years ago) link

posting this coz I love the way the guy swears (nsfw swears obv)

https://www.youtube.com/watch?v=YD0lsbVUYe0

every day I'm (onimo), Thursday, 28 April 2011 10:46 (thirteen years ago) link

oh wait, 3 mins in he starts comparing hacking to rape, sorry

every day I'm (onimo), Thursday, 28 April 2011 10:47 (thirteen years ago) link

Well, he's making a hyperbolic analogy for loud sweary effect. I lolled.

standing on the shoulders of pissants (ledge), Thursday, 28 April 2011 10:57 (thirteen years ago) link

grey lady wags its finger disapprovingly
http://www.nytimes.com/2011/04/28/arts/video-games/sony-playstation-security-flaw-tests-consumer-trust.html?ref=video-games

i like scheisel better than the average eukyarote but this kind of serious cat stuff following his slavering fanboy diablo iii preview is nagl

forks (forksclovetofu), Thursday, 28 April 2011 16:26 (thirteen years ago) link

I finally got my email from Sony last night

rockapads, Thursday, 28 April 2011 16:48 (thirteen years ago) link

I just got the email. Thanks I guess.

40% chill and 100% negative (Tracer Hand), Thursday, 28 April 2011 16:51 (thirteen years ago) link

man all this & i still cant play mortal kombat

dearth of the hipster (Lamp), Thursday, 28 April 2011 18:46 (thirteen years ago) link

Got round to checking, and it's so long since there was anything I actually wanted to buy on PSN that the card details they've lost were for a card which has already expired anyway. A year ago.

JimD, Thursday, 28 April 2011 19:39 (thirteen years ago) link

i finally got my email! yay! i feel so grown up

Romford Spring (DG), Thursday, 28 April 2011 21:23 (thirteen years ago) link


You must be logged in to post. Please either login here, or if you are not registered, you may register here.