Sony Reports Massive Hack Attempt On Networks: 93,000 Accounts Affected Globally
blog.us.playstation.com
blog.us.playstation.com
On the positives, at least they're being open about it now and they detected it.
I'd love to know from someone in the business whether bruteforce attempts like this typically come from a single IP, multiple IPs or a unique IP per account break-in attempt. If it's anything but the latter, one would really hope a company as high-profile and as targeted as Sony would be checking more thoroughly for this kind of stuff.
Any guesses as to where the original list of usernames and passwords may have come from?
On issue that JoachimSchipper points out [1] is that Sony probably isn't rate limiting, or throttling login attempts, which is a security issue, as it opens up the possibility of brute force attacks
Thankfully, I originally used a throwaway password and don't have a valid credit card on that account anymore, so I honestly don't care at this point what happens to it.
As an aside, I would point out that XBL hack reports (with purchased/stolen points) have been running rampant for the last year[4], with Microsoft working hard to bury the reports. One of the editors at VE3D was hit by it and had a few thousand Points purchased against their account.
There have been on-again/off-again rumors that the iTunes store has been compromised for the last year with people reporting apps purchased against their accounts and Apple saying that no hack has occurred (oddly enough this all took place after the iTunes store ratings shenanigans in 2010[1][2]).
As a customer I'd rather places disclosed hack attempts to me and what they were doing to combat it than cover it up, deny it, say it never happens and everything is safe and then wait for the other shoe to drop.
This reminds me of the LastPass announcement[3] when they detected an irregularity in the form of a few extra bytes transferred from a source to destination server where the bytes that arrived were less than were sent, so they went to defcon3, posted the issue on the block and set forth on rebuilding and locking the systems down without every actually confirming a hack... just being safe.
There were a fair share of people irate at the news; I wonder how much of it was anger at the team (you couldn't really claim they didn't know what they were doing) or just anger at the fact that something they had set-and-forget(ed) was now suddenly they had to worry about.
No one ever wants to hear the bad news, but bad news delivered along side "how we are fixing it" is always a good way to tell if your data is in good hands.
[1] http://www.engadget.com/2010/07/04/inexplicable-rise-in-ipho... [2] http://www.thebuzzmedia.com/itunes-app-store-hacked-again-us... [3] http://blog.lastpass.com/2011/05/lastpass-security-notificat... [4] http://www.joystiq.com/2011/06/17/report-lulzsec-hacking-gro...