|
(05-18-2011, 12:25 PM)
|
Sony had an exploit on their PSN password recovery page and is now fixed
#1
This is a continuation on this story:
http://www.neogaf.com/forum/showthread.php?t=430519 First, to avoid unnecessary panic, let me just say that Sony already took the page down, and are most likely fixing it, and if you were a victim of this, you would get an email warning someone had changed your password, so if you didn't, you're safe. Now to the whole story: This guy on twitter ( http://twitter.com/#!/Nyleveia ) was claiming there was an exploit on the password recovery page that allowed anyone with a matching PSN login address and Date of Birth could change your password without you confirming it. Personally I didn't believe him so I gave him my login and dob. He didn't reply for a long time so I went to sleep. This morning however I got these 2 emails. ![]() ![]() ![]() Sender details
Quote:
And where the story gets even more interesting is that Sony are just lying about it. This is their latest tweets.
Quote:
Quote:
And now they're fixing the problem. Honestly, I was never bothered by the original hack, no network is secure and I think Sony wasn't to blame and that they handled the entire thing by the book and quite well. This however... this is 100% on them, and what bothers me the most is that they're lying about it.
Last edited by Metalmurphy; 05-18-2011 at 12:52 PM.
Reason: typos
|
|
|
|
place a shoe on my head
to reduce lag compensation (05-18-2011, 12:28 PM)
|
#2
Lol so do you even know the password to your own account?
|
|
Kratos can kill Zeus
but not Pam Anderson? (05-18-2011, 12:28 PM)
|
#3
Sony just keeps on surprising us!
|
|
is the terrorists' lawblob
(05-18-2011, 12:29 PM)
|
#4
Here we go again!
Buckle up! |
|
Member
(05-18-2011, 12:30 PM)
|
#5
just a DOB is not secure enough, everyone knows my DOB
thats it, i want facial recognitions and fingerprint scans in ps4 |
|
Member
(05-18-2011, 12:30 PM)
|
#6
Surprising and annoying that this hole a) existed b) was not discovered in their post-fall security review.
Kudos to Nyleveia though, for finding it and informing Sony. |
|
(05-18-2011, 12:30 PM)
|
#7
Originally Posted by Jarmel:
|
|
This sh!t needs to stop?
(05-18-2011, 12:30 PM)
|
#8
Finding it rather hard to respect Sony these days :/
|
|
bish gets all the credit :)
(05-18-2011, 12:30 PM)
|
#9
un-fucking-believable
|
|
Member
(05-18-2011, 12:31 PM)
|
#10
When will the national nightmare end???????
|
|
Member
(05-18-2011, 12:31 PM)
|
#11
Of course they're going to lie about it. The PSN hack has already hurt them in terms of PR.
|
|
Member
(05-18-2011, 12:32 PM)
|
#12
Originally Posted by Metalmurphy:
|
|
Member
(05-18-2011, 12:32 PM)
|
#13
Yikes, one mess after another. So what are the chances of all those that changed their PSN Passwords, having to re-do it again?
|
|
Member
(05-18-2011, 12:34 PM)
|
#14
wow...
|
|
MrArseFace
(05-18-2011, 12:34 PM)
|
#15
Originally Posted by TheBranca18:
I think they post it on their twitter feed so you can be notified easily. |
|
(05-18-2011, 12:34 PM)
|
#16
Originally Posted by TheBranca18:
|
|
Member
(05-18-2011, 12:34 PM)
|
#17
unbelievable. there is literally nothing they could do to make me trust them again at this point.
|
|
Member
(05-18-2011, 12:35 PM)
|
#18
Originally Posted by panda21:
|
|
MrArseFace
(05-18-2011, 12:35 PM)
|
#19
Originally Posted by Metalmurphy:
|
|
Member
(05-18-2011, 12:36 PM)
|
#20
This can't be that easy, can it? Thats unbelievable.
|
|
Member
(05-18-2011, 12:37 PM)
|
#21
edit: nvm, done with psn threads :P
Last edited by daffy; 05-18-2011 at 12:41 PM.
|
|
Combovers don't work when there is no hair
(05-18-2011, 12:37 PM)
|
#22
Sony's network security - the gift that keeps on giving away your personal information
|
|
Banned
(05-18-2011, 12:37 PM)
|
#23
thread needs some corporate love.
|
|
Member
(05-18-2011, 12:38 PM)
|
#24
Originally Posted by CadetMahoney:
|
|
(05-18-2011, 12:39 PM)
|
#25
Originally Posted by Metalmurphy:
|
|
Member
(05-18-2011, 12:40 PM)
|
#26
I don't know the details but I guess that the confirmation url is embedded in the webpage somehow. Just URL manipulation to 'force' the confirmation?
|
|
Banned
(05-18-2011, 12:40 PM)
|
#27
So the OP can't access his account now?
|
|
Member
(05-18-2011, 12:40 PM)
|
#28
Originally Posted by CadetMahoney:
|
|
is the terrorists' lawblob
(05-18-2011, 12:41 PM)
|
#29
Originally Posted by panda21:
Ehhhh?? |
|
Member
(05-18-2011, 12:42 PM)
|
#30
Originally Posted by toythatkills:
As for proving it wasn't a massive wind-up, don't you think Metal Murphy would have tried to log into his PSN account afterwards to check? |
|
(05-18-2011, 12:42 PM)
|
#31
Originally Posted by TheBranca18:
|
|
hide your water-based mammals
(05-18-2011, 12:42 PM)
|
#32
Hmmmmm....
Bakc to the Witcher 2 then :P |
|
(05-18-2011, 12:42 PM)
|
#33
Australian and Japan's gov were right.
|
|
(05-18-2011, 12:43 PM)
|
#34
Originally Posted by toythatkills:
And no the emails aren't spoofed.
Quote:
|
|
Banned
(05-18-2011, 12:44 PM)
|
#35
Originally Posted by Tntnnbltn:
|
|
(05-18-2011, 12:44 PM)
|
#36
Originally Posted by Tntnnbltn:
I'm certainly dubious if the hacker had his email, though. |
|
MrArseFace
(05-18-2011, 12:44 PM)
|
#37
don't really give a shit about passwords being lost/compromised as long as I get on there and wipe off any credit card info. PSN cards only
|
|
Member
(05-18-2011, 12:45 PM)
|
#38
For.Fucks.Sake.
How embarrassing. |
|
Member
(05-18-2011, 12:45 PM)
|
#39
Originally Posted by toythatkills:
|
|
Member
(05-18-2011, 12:46 PM)
|
#40
Lets see how Stringer defend this!
|
|
(05-18-2011, 12:46 PM)
|
#41
Originally Posted by Akkad:
|
|
Banned
(05-18-2011, 12:47 PM)
|
#42
Originally Posted by Defuser:
|
|
Junior Member
(05-18-2011, 12:47 PM)
|
#43
News at ten: Sony notify PSN users that their date of birth information has been breached. PSN taken down immediately - ETA "in a couple of days" - when it's back up, upon logging in, sony will require all users to change their date of birth before accessing PSN.
Also - due to "security reasons" the "feature" of having a choice of input will be removed, as this was never explicitly promised when users purchased the ps3. Instead, everyone will share one big PSN account which will consist of two buttons, one that can be clicked to download Little Big Planet and another that can be clicked to listen to a selected Sony/BMG artist*. *Artists subject to change and rootkit installation. Limited to one play on one machine for the lifetime of offer. |
|
Member
(05-18-2011, 12:47 PM)
|
#44
Hohohohoooly shit! This is funny.
|
|
(05-18-2011, 12:48 PM)
|
#45
Originally Posted by gcubed:
Originally Posted by kurtrussell:
|
|
(05-18-2011, 12:50 PM)
|
#46
Originally Posted by Metalmurphy:
|
|
Member
(05-18-2011, 12:50 PM)
|
#47
At least they fixed it before it started getting out of hand...
Still shit though. |
|
Licorice-flavoured booze?
(05-18-2011, 12:50 PM)
|
#48
Originally Posted by toythatkills:
|
|
Member
(05-18-2011, 12:51 PM)
|
#49
But I didn't get my password mailed to me in text in the confirmation emails. Is there something different in the Japanese and North American password change systems?
|
|
(05-18-2011, 12:51 PM)
|
#50
Originally Posted by toythatkills:
And Sony took the password recovery page down afterwards. |