PSN has been hacked again
mcvuk.com
mcvuk.com
How does someone even conceive of something like that without realizing the glaring problem with it? How does it pass muster at a major corporation that has hired security consultants? This is utterly flabbergasting.
I could understand that much outrage if Sony deliberately designed the password reset process to require only e-mail address and DOB. However, the article says that the password reset page had an exploit that allowed you to do that. It's still shoddy security, but at least it's not sheer idiocy.
I'm really not into the whole boycotting thing and I never really understood (for example) the people who would flat out not buy Microsoft products because of their at times very questionable business practices (especially when the worst of them happened a while ago).
I'll happily look past a gaffe here or there especially when it comes from the PR department or from the corporate lawyers as long as a company puts out a quality product.
And I quite like a few of Sony's products, too. They seem to put more thought into industrial design than most other companies.
But right now I can only pick up my Sony digital camera and earphones in distaste and it will probably be a long while until I buy anything made by Sony.
This is just way too much incompetence and in too short an order and they won't even stand up straight for it, instead pointing the finger at Anon or geohot.
Yuck.
The whole https://secure.wikimedia.org/wikipedia/en/wiki/Standardizati... thing is quite recent.
Another option would be to send out a new password via mail to the billing address if they had no other way to do it electronically. Out of luck if you moved since then. Make the old password a requirement so mail thieves cannot steal your account.
I was pissed that I needed to change my credit card number because of these clowns. If someone wants to make a cool startup make a credit card number that is a one off that will only work for a certain time frame(extendable), dollar limit, and business name(though this one might be tougher because the business name given to the credit card company might be different than the business name I would enter).
Lots of security conventions ("mother's maiden name" for another example) are very silly.
For having three different security firms working with Sony on the hack a month ago, are they really just pushing out the new PSN without a proper, full security review? I mean, any competent developer would immediately realize that this password reset system is flawed by design, especially with the fact that the user's information requested is the information the hackers already have!
This does not bode well for the near future of PSN as a whole. If something as simple as a password reset feature is still being built without security in mind, then how does the rest of the updated system fare?
At this point I assumed that it had used my PS3 hardware ID + my (static) IP + whatever to correlate that in all likelihood it must have been a legitimate login, which was already a bit weird but I guess they wanted to make it as simple as possible for everybody.
But this is just outstanding. It's really security 101 failure. As others have pointed out, using a regular password reset email with a unique token would have been much more safe, albeit not foolproof (some people would have lost their emails accounts they used to register by now).
Sony deserves everything that's happening (and will probably continue to happen) to them. The sad part is that I'm sure a majority of the gamers sony really targets must still be chanting "xbox sucks go sony lol" and still think geohot or anonymous or santa is to blame.
-- A very unhappy PS3 (and its ancestors) owner.
It's rather strange then, given how secure the reset process was post-hack (and I think they did a really good job of making it secure and convenient) that they left such a gaping and obvious hole!
...
Sony deserves everything that's happening (and will probably continue to happen) to them. The sad part is that I'm sure a majority of the gamers sony really targets must still be chanting "xbox sucks go sony lol"...
The effective collective IQ of Sony has sunk below average at this point, and the company lumbers along on network effects. Maybe there's room now for a gaming platform that's not a physical console?
I hope the collective IQ analogy doesn't also work for the United States!
What do you mean by this?
A resurgence in PC gaming? I hope not. I have absolutely no desire to return to the PC gaming obsolescence cycle.
Steam has been alive and well for at least a few years now.
As a fellow PS3 player, I have an alternate point of view: I do not care about anyone's personal crusades. I just want to play some online games.
I believe multiple sources are at fault. One is at fault for providing the gun to the public, another is at fault for shooting the gun, and the third is at fault for not wearing a bulletproof vest. If I were to speculate on where most of the blame should be placed, I would be hardpressed to blame the victim. I point my finger at the gunmen. I am part of the collateral damage, a civilian caught in the crossfire, caught in friendly fire.
The original analogy though is only accurate depending on where this is taking place. A person living in the suburbs would seem silly for wearing a bullet proof vest. A person walking into a war zone without a vest is an idiot. The question is, which of the two locations best describes the internet.
I won't have to pay a dime for transactions I didn't authorize.
I suppose I could call "victim" for having to watch my statements more closely, but everyone does that anyway, right?
That's not actually the problem here. It's pretty standard practice to only ask for an email address to initiate a password reset. Google, for example, only asks for email address. Asking for additional information, like DOB, isn't really a security measure. It's more of an annoyance prevention measure, to make it slightly harder for random people to initiate password resets in your name.
The problem with what Sony was doing is that you could circumvent the verification that you had access to the email address you gave. The way it is supposed to work is that you initiate a password reset, and the site sends you a link that you have to follow to get to the form where the actual password reset takes place and you enter a new password.
The security comes not from knowing your email address and DOB, but rather from having to actually have access to the email.
The way Sony's site was working, when you initiated the reset request it was possible to figure out what the link was that sent in the email, and hence finish the reset process without having access to the email. Oops.
One conclusion: there is a high prevalence of incompetent programmers at companies like Sony, combined with an unsatisfactory ability of management to ferret them out.
Exception is maybe the credit card number, but that would mean that only a small subset of the original account holders can change their password.
Or you use a PS3 device ID and only allow changing the password on the device, but that is also known by the attackers and I'm sure it could be spoofed.
Not even sending a token to the email address on file would work in all cases because the users might have lost their email accounts to the breach too (by reusing the same weak password).
Well, in that case, it'd be the user's fault for not having unique passwords, or at least for not changing an email password they knew was compromised, not Sony's fault. Sony can't do anything to ensure the users' email accounts are secure, so emailing a token would probably be the best solution.
Also, it's still basically impossible to transfer a land-line number to a cell number, as they are apples and oranges.
Often, every device in a secure network would benefit by having its own asymmetric encryption key. This way, Sony could have easily implemented a challenge-response that only clients could respond to. The hackers would only have gotten the public keys, which wouldn't do them any good outside of some sort of man in the middle exploit, which would require secret control of a part of the PSN network over an extended period of time.
I was thinking about the hacker == kids who DDoS mastercard or steal infos from the PSN. Some of them might be hackers, but that's not what a hacker is. Bruteforcing PSN accounts using a stolen DB is not really the mark of a hacker's job for me.
PSN will need more time to properly recover all previous hacked accounts.
So you enter the target’s email address and date of birth on the reset page. If that clears, then the next URL has a token in the query string that you can apply to the actual password reset page URL to reset the target’s password?
The answer is to rebuild/rebrand the networking for the playstation with a strong partner like Amazon, Google, or Valve/Steam.
A partner like Amazon for example could bring good e-commerce stability to lend confidence to platform.
Google is also an excellent candidate -- they have the experience with scale and could use a strong partner like Sony to help push their home media platforms (GoogleTV, etc.)
Though, I do shudder thinking about having a company as incompetent as Sony joining forces with Valve.
Google and Amazon are actively working towards marketing to televisions screens -- Amazon with Prime/Digital Video media sales and Google with GoogleTV and YouTube. They have more to gain from a potential partnership.
The problem seems to be that the email validation required for resetting the password could be circumvented. There is no detailed information in the posts how, but likely either the validation hash was generated in a insecure fashion, or the email address input was not properly sanitized and allowed piggybacking (CCing) a 2nd email address to receive the confirmation email.
eg. /reset?token=XXXXX
Only the recipient of the email can use it and it will let the person reset their password. It's so standard fare, I'm not sure why Sony needed to go this route.
People will keep using them.
Nobody but us cares.