Something went wrong. Try again later

Giant Bomb News

265 Comments

Well, Crap... Sony's Password Reset System Has Been Compromised [UPDATED]

Sony takes down its web-based login/password access points to fix an exploit--console-based systems currently unaffected.

No Caption Provided

UPDATE: Sony claims the exploit has been fixed and pushed back on reports of an additional hack.

"We temporarily took down the PSN and Qriocity password reset page," said senior director of corporate communications and social media Patrick Seybold on the PlayStation Blog. "Contrary to some reports, there was no hack involved. In the process of resetting of passwords there was a URL exploit that we have subsequently fixed. Consumers who haven’t reset their passwords for PSN are still encouraged to do so directly on their PS3. Otherwise, they can continue to do so via the website as soon as we bring that site back up."

--

In case you were betting on how long it was going to take for something to go wrong on the PSN after it began to come back online last weekend, those of you who bet on "five days or less" win the door prize. Congratulations: you get a free copy of inFamous, and your password stolen again.

== TEASER == Late last night, Nyleveia discovered--and users on NeoGAF have verified--that Sony's online password reset system--specifically, the web-based version on sites such as PlayStation.com and Qriocity.com--has a rather nasty exploit in it that allows any would-be hacker to simply reset your account password provided they know your PSN account email and your date of birth. That's it. Entering that info apparently lets anyone who knows the exploit reset your password and access your account. On the plus side, you'll get an email sent to you notifying you that your password has been reset. So that's awesome.

Not long after this was reported, Sony took all of its web-based login systems down, and as of this writing, there is no specific update as to how long this fix will take to put into place. The official SCEE Twitter account noted this morning that "this maintenance doesn't affect PSN on consoles, only the website you click through to from the password change email." So, to clarify, you can still log in on your console and play games online via PSN. You just can't use any of the web-based login sites until Sony fixes this exploit.

Nyleveia suggested that users create an entirely new email address for their PSN accounts, one not associated with any other online accounts in order to be absolutely safe. Because that's where we're at now. We're creating all new accounts just to be able to safely log into the PlayStation Network. I really hate the Internet sometimes.

Alex Navarro on Google+

265 Comments

Avatar image for napalm
napalm

9227

Forum Posts

162

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

Edited By napalm
@REDRUN said:
I just heard the roaring sound of the "million-man-face-palm" just now.
I've been told it's one of the loudest sounds from space.
Avatar image for thomasonfa
thomasonfa

398

Forum Posts

82

Wiki Points

0

Followers

Reviews: 0

User Lists: 4

Edited By thomasonfa

        

   Patrick, don't hate the internet, hate the game. - Ice-T
   Patrick, don't hate the internet, hate the game. - Ice-T
Avatar image for dezvous
dezvous

690

Forum Posts

4

Wiki Points

0

Followers

Reviews: 2

User Lists: 15

Edited By dezvous

It's interesting how all over the internet some websites refer to accounts being compromised and such but have there actually been any definitive instances where people lost their accounts or had their credit cards used? I mean so far it's been nothing but hearsay, account information definitely seemed to be accessible (and that's not good) but that's about it. So far this whole thing seems like it could have been a hell of a lot worse. 

Avatar image for xsheps
Xsheps

123

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 1

Edited By Xsheps

Anyone who signs up for PSN at this point DESERVES to have their identities stolen.

Avatar image for kyle
Kyle

2383

Forum Posts

6307

Wiki Points

0

Followers

Reviews: 0

User Lists: 12

Edited By Kyle
@clstirens said: 
Except the last update made it so if PSN determined that your ps3 wasn't the one you originally used with that PSN ID, you MUST do it online. (unless this issue somehow doesn't affect the e-mails going out?)I had no trouble, but a friend of mine has only ever used one ps3, and it forced him to change it via the web, not his console.
Oh yeah, forgot about that.
Avatar image for deactivated-5c7ea8553cb72
deactivated-5c7ea8553cb72

4753

Forum Posts

0

Wiki Points

0

Followers

Reviews: 5

User Lists: 0

lol.

Avatar image for jjweatherman
JJWeatherman

15144

Forum Posts

5249

Wiki Points

0

Followers

Reviews: 10

User Lists: 18

Edited By JJWeatherman

Oh, goodness.

Avatar image for keavy_rain
Keavy_Rain

135

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

Edited By Keavy_Rain

I'm a little peeved because I just replaced my PS3 that died back in September and now can't login to PSN or redeem my LA Noire DLC codes, but from the sound of it I'd only be able to log into PSN if I could reset my password, so hopefully they get this fixed by the time the store is up.

Sony, if it helps, I have a $50 PSN card and I wanna spend it. Granted, you have my $50 already, but you COULD be totally cool and let me redeem it.

Avatar image for onemanx
OneManX

1728

Forum Posts

50

Wiki Points

0

Followers

Reviews: 4

User Lists: 6

Edited By OneManX
@Fattony12000: The games are yours forever
Avatar image for hitmanagent47
HitmanAgent47

8553

Forum Posts

25

Wiki Points

0

Followers

Reviews: 0

User Lists: 2

Edited By HitmanAgent47

This is confusing, so I already changed the password when it was offered to me, but sony is saying that it's fixed for consoles? but not webpages? Yeah right, I don't trust them anymore.

I hope there isn't some exploit if I don't change my password again or create some fake email.

Avatar image for seriouslynow
SeriouslyNow

8504

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 1

Edited By SeriouslyNow

Sony : giving a shit about your information.  Professionally like.

Avatar image for swomar
swomar

66

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 1

Edited By swomar
@WrathOfBanja said:
@swomar said:

@NL_Buddha said:

@captain_clayman: Gooder?? You have the nerve to crap on them and not even use proper english!! Please, the 360 had a 46% failure rate and no one has even cried this much about that. All they did was give you an extra warranty which doesn't cost them a cent. Sony is giving away free games and movies!! That costs much more then an extra warranty.  Just saying.  
Not to be a dick here, but you really shouldn't make fun of someone's English if you can't tell the difference between "then" and "than". And how exactly does extending warranties on faulty hardware doesn't cost money?
"And how exactly does extending warranties on faulty hardware doesn'tcost money?"Grammar mistakes everywhere!
Yeah, that was pretty stupid. I guess that makes me a dick then :p
Avatar image for saga
Saga

190

Forum Posts

2

Wiki Points

0

Followers

Reviews: 5

User Lists: 1

Edited By Saga

"Nyleveia suggested that users create an entirely new email address for their PSN accounts, one not associated with any other online accounts in order to be absolutely safe. " 


I just created mine....sony_executives_are_morons@gmail.com 
Avatar image for lordandrew
LordAndrew

14609

Forum Posts

98305

Wiki Points

0

Followers

Reviews: 0

User Lists: 36

Edited By LordAndrew

A URL exploit? A freaking URL exploit? Does Sony have register_globals enabled or something?

Avatar image for wrathofbanja
WrathOfBanja

370

Forum Posts

67

Wiki Points

0

Followers

Reviews: 1

User Lists: 3

Edited By WrathOfBanja
@swomar said:
@WrathOfBanja said:
@swomar said:

@NL_Buddha said:

@captain_clayman: Gooder?? You have the nerve to crap on them and not even use proper english!! Please, the 360 had a 46% failure rate and no one has even cried this much about that. All they did was give you an extra warranty which doesn't cost them a cent. Sony is giving away free games and movies!! That costs much more then an extra warranty.  Just saying.  
Not to be a dick here, but you really shouldn't make fun of someone's English if you can't tell the difference between "then" and "than". And how exactly does extending warranties on faulty hardware doesn't cost money?
"And how exactly does extending warranties on faulty hardware doesn'tcost money?"Grammar mistakes everywhere!
Yeah, that was pretty stupid. I guess that makes me a dick then :p
Ahh its okay. Nobody have well grammar in the internet anyways.