Something went wrong. Try again later

Giant Bomb News

265 Comments

Well, Crap... Sony's Password Reset System Has Been Compromised [UPDATED]

Sony takes down its web-based login/password access points to fix an exploit--console-based systems currently unaffected.

No Caption Provided

UPDATE: Sony claims the exploit has been fixed and pushed back on reports of an additional hack.

"We temporarily took down the PSN and Qriocity password reset page," said senior director of corporate communications and social media Patrick Seybold on the PlayStation Blog. "Contrary to some reports, there was no hack involved. In the process of resetting of passwords there was a URL exploit that we have subsequently fixed. Consumers who haven’t reset their passwords for PSN are still encouraged to do so directly on their PS3. Otherwise, they can continue to do so via the website as soon as we bring that site back up."

--

In case you were betting on how long it was going to take for something to go wrong on the PSN after it began to come back online last weekend, those of you who bet on "five days or less" win the door prize. Congratulations: you get a free copy of inFamous, and your password stolen again.

== TEASER == Late last night, Nyleveia discovered--and users on NeoGAF have verified--that Sony's online password reset system--specifically, the web-based version on sites such as PlayStation.com and Qriocity.com--has a rather nasty exploit in it that allows any would-be hacker to simply reset your account password provided they know your PSN account email and your date of birth. That's it. Entering that info apparently lets anyone who knows the exploit reset your password and access your account. On the plus side, you'll get an email sent to you notifying you that your password has been reset. So that's awesome.

Not long after this was reported, Sony took all of its web-based login systems down, and as of this writing, there is no specific update as to how long this fix will take to put into place. The official SCEE Twitter account noted this morning that "this maintenance doesn't affect PSN on consoles, only the website you click through to from the password change email." So, to clarify, you can still log in on your console and play games online via PSN. You just can't use any of the web-based login sites until Sony fixes this exploit.

Nyleveia suggested that users create an entirely new email address for their PSN accounts, one not associated with any other online accounts in order to be absolutely safe. Because that's where we're at now. We're creating all new accounts just to be able to safely log into the PlayStation Network. I really hate the Internet sometimes.

Alex Navarro on Google+

265 Comments

Avatar image for louiedog
louiedog

2391

Forum Posts

227

Wiki Points

0

Followers

Reviews: 0

User Lists: 2

Edited By louiedog

I saw the headline and expected the article to just be a facepalm picture. Seriously, Sony? Weeks of talking to security experts and getting your stuff back online and this? Why should I trust you with any of my information ever again?

Avatar image for cylemoore
CyleMoore

571

Forum Posts

1210

Wiki Points

0

Followers

Reviews: 18

User Lists: 7

Edited By CyleMoore

Well at least I changed my password on PSN.

Avatar image for wacomole
Wacomole

1194

Forum Posts

681

Wiki Points

0

Followers

Reviews: 0

User Lists: 2

Edited By Wacomole
" So, to clarify, you can still log in on your console and play games online via PSN. You just can't use any of the web-based login sites until Sony fixes this exploit. "

just to add...
If you've finally received the extremely delayed email that Sony sent out to allow you to change your password via your PC (usually needed with secondary accounts) it will include a link to click.  
That link is supposed to take you to the PSN login to change your password.  But that too is affected by this problem.
Therefore there are probably still many people who can still not log in and play online.
Avatar image for dezvous
dezvous

690

Forum Posts

4

Wiki Points

0

Followers

Reviews: 2

User Lists: 15

Edited By dezvous

This doesn't sound like an exploit so much as it just not requiring more secretive data for a password reset. Hackers aren't doing any hacking here. 


This is effectively the same as any other website where all you have to do is put in your email and then only answer a security question or something. 

I believe the problem Sony is faced with is that they want people to be able to recover their accounts easily, in case they say forget a security question or something but that also leaves the accounts open to a relatively easy way to be compromised if someone has your date of birth. 
Avatar image for scrumdidlyumptious
Scrumdidlyumptious

1679

Forum Posts

4386

Wiki Points

0

Followers

Reviews: 0

User Lists: 5

Doesn't sound too serious.

Avatar image for lord_canti
lord_canti

1689

Forum Posts

2173

Wiki Points

0

Followers

Reviews: 1

User Lists: 6

Edited By lord_canti
@boylie said:
OH FOR FUCK'S SAKE
Avatar image for nihilius
Nihilius

174

Forum Posts

1

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

Edited By Nihilius

This is getting ridiculous.

Avatar image for dallydoll
DallyDoll

237

Forum Posts

1

Wiki Points

0

Followers

Reviews: 0

User Lists: 5

Edited By DallyDoll

Well, this is beyond fucked.

Avatar image for white_silhouette
White_Silhouette

527

Forum Posts

308

Wiki Points

0

Followers

Reviews: 0

User Lists: 4

Edited By White_Silhouette

Ah I love Sony some times. True Sony fans will get a second job to buy this console, and you'll need a second email account to for the chance that your info will be taken... again.

Avatar image for s-a-n-jr
s-a-n-JR

3256

Forum Posts

2993

Wiki Points

0

Followers

Reviews: 1

User Lists: 15

Edited By s-a-n-JR

There seems to be some confusion surrounding this news.

This exploit does not allow people to take the new password you put in after the PSN came back up. If you can still log into your PSN then obviously your password wasn't reset and you have nothing to worry about regarding this particular exploit.    


Avatar image for oldmanlight
OldManLight

1328

Forum Posts

177

Wiki Points

0

Followers

Reviews: 7

User Lists: 9

Edited By OldManLight

I'm never using a credit card on any sony network ever again.

Avatar image for commando
Commando

1999

Forum Posts

249

Wiki Points

0

Followers

Reviews: 0

User Lists: 2

Edited By Commando

Wow. That blows. Might as well just start rebuilding it from the ground up.

Avatar image for proggykins
proggykins

151

Forum Posts

46

Wiki Points

0

Followers

Reviews: 0

User Lists: 2

Edited By proggykins

What? I don't... what? What the hell are they doing at Sony?

Avatar image for dingofighter
Dingofighter

1888

Forum Posts

251

Wiki Points

0

Followers

Reviews: 0

User Lists: 3

Edited By Dingofighter
@JohnPaulVann said:
Stop race-hating on Sony! This could happen to anybody. The only reason any one is talking about it is because Sony is Japanese. The RROD was infinitely worse than the PSN failure but nobody made even one tenth as much noise. 
You saying that the japanese are a different race makes you even more racist...
Avatar image for mideonnviscera
MideonNViscera

2269

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

Edited By MideonNViscera

Oh Sony!

Avatar image for deactivated-64ba3d2213a4d
deactivated-64ba3d2213a4d

549

Forum Posts

1

Wiki Points

0

Followers

Reviews: 3

User Lists: 0

@Sanj said:
There seems to be some confusion surrounding this news.

This exploit does not allow people to take the new password you put in after the PSN came back up. If you can still log into your PSN then obviously your password wasn't reset and you have nothing to worry about regarding this particular exploit.    

This.
Hell, this isn't even an exploit. You guys have no idea how many websites let you change someone's password with that little info.
Hell, with Facebook all you need to know is one of their OLD passwords.
Avatar image for devoid
Devoid

438

Forum Posts

7

Wiki Points

0

Followers

Reviews: 0

User Lists: 12

Edited By Devoid

What. So Sony puts up this website, and then is just like, "Oh wait, the hackers woulda taken your date of birth when they got your email, right? WHOOPS".

That's so stupid. Did they really not think of that?

Avatar image for perilator666
perilator666

524

Forum Posts

41

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

Edited By perilator666

oh god, im laughing so hard i'm crying. this is motherfucking hilarious.

Avatar image for legalbagel
LegalBagel

1955

Forum Posts

1590

Wiki Points

0

Followers

Reviews: 7

User Lists: 7

Edited By LegalBagel

Well, at least I reset it last night and hopefully am now done with this whole mess.


I thought they were going to force you to reset via your registered Playstation or something?  That's how I activated my initial reset.
Avatar image for cirdain
Cirdain

3796

Forum Posts

1645

Wiki Points

0

Followers

Reviews: -1

User Lists: 6

Edited By Cirdain

dude... what

Avatar image for frankxiv
frankxiv

2600

Forum Posts

8534

Wiki Points

0

Followers

Reviews: 1

User Lists: 11

Edited By frankxiv

for once i'm glad sony's web based services are a joke so i'd have no reason to ever use them

Avatar image for tesla
Tesla

2299

Forum Posts

1

Wiki Points

0

Followers

Reviews: 0

User Lists: 4

Edited By Tesla

Cue the Price is Right fail music.

Avatar image for gla55jaw
gla55jAw

2834

Forum Posts

6584

Wiki Points

0

Followers

Reviews: 6

User Lists: 31

Edited By gla55jAw

Geez, I don't want to make another email account that I never check just for Sony. This shit is getting really annoying now.

Avatar image for ignisphaseone
IgnisPhaseOne

80

Forum Posts

1351

Wiki Points

0

Followers

Reviews: 2

User Lists: 4

Edited By IgnisPhaseOne
@DedBeet said:
Sony's attempt at 2 factor authentication:  birth date + email address.
LOLOLOLOLOLOL

Only because I took computer security. When you look at it this way, this is even more retarded since it's the same protected info they leaked.
Avatar image for man_flannel
MAN_FLANNEL

2472

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

Edited By MAN_FLANNEL

Sony thought it was a good idea for passwords to be reset with a birth date and e-mail address?  Are they trying to look like complete idiots?

Avatar image for atary77
Atary77

580

Forum Posts

18

Wiki Points

0

Followers

Reviews: 2

User Lists: 0

Edited By Atary77

You gotta be kidding me! XD

Avatar image for s-a-n-jr
s-a-n-JR

3256

Forum Posts

2993

Wiki Points

0

Followers

Reviews: 1

User Lists: 15

Edited By s-a-n-JR
@Protome said:

@Sanj said:

There seems to be some confusion surrounding this news.

This exploit does not allow people to take the new password you put in after the PSN came back up. If you can still log into your PSN then obviously your password wasn't reset and you have nothing to worry about regarding this particular exploit.    

This. Hell, this isn't even an exploit. You guys have no idea how many websites let you change someone's password with that little info.
Hell, with Facebook all you need to know is one of their OLD passwords.
Exactly. I swear people just read what they want to read in an article. They see, "Sony" and "compromised" and think that the PSN has been hacked again and your passwords have been stolen.

READ THE ARTICLE PEOPLE (except Alex needs to change the part about passwords being stolen again. That is untrue).
Avatar image for uncledisco
UncleDisco

885

Forum Posts

646

Wiki Points

0

Followers

Reviews: 0

User Lists: 10

Edited By UncleDisco
@alex: I think you need to change this:

  "and your password stolen again"

Since you're password really isn't getting stolen.. only reset 
Avatar image for xenonick
XenoNick

1584

Forum Posts

4

Wiki Points

0

Followers

Reviews: 0

User Lists: 10

Edited By XenoNick
@JohnPaulVann said:
Stop race-hating on Sony! This could happen to anybody. The only reason any one is talking about it is because Sony is Japanese. The RROD was infinitely worse than the PSN failure but nobody made even one tenth as much noise. 
Sony fanboy defense activate!
Avatar image for unsolvedparadox
unsolvedparadox

2298

Forum Posts

31

Wiki Points

0

Followers

Reviews: 1

User Lists: 2

Edited By unsolvedparadox
@Blunt said:
You know what I liked about game consoles 20 odd years ago? If shit was broke you just blew in the cartridge.
QFT
Avatar image for stupot
Stupot

182

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

Edited By Stupot

Hahahahaha

Avatar image for authenticm
AuthenticM

4404

Forum Posts

12323

Wiki Points

0

Followers

Reviews: 1

User Lists: 2

Edited By AuthenticM

now this is getting ridiculous.

Avatar image for zero3
zero3

30

Forum Posts

6

Wiki Points

0

Followers

Reviews: 0

User Lists: 16

Edited By zero3

Just for curiosity I translated the article into a foreign language and this came up:

WE'RE GIVING YOU 4 FREE GAMES AND BROADENING THE SELECTION
Avatar image for donos
Donos

1245

Forum Posts

22

Wiki Points

0

Followers

Reviews: 0

User Lists: 1

Edited By Donos

Isn't this how password reset works for just about anything? You enter your login username, and an email is sent to whatever email account is associated with that username. It just so happens that for PSN, your username is your email account.

They could just make it so the password isn't reset until you hit a password reset link in that email, though that would be more open to phishing scams.

I don't see much reason to be mad at Sony for doing the exact same thing as every other account-based online service.

Edit: Hell, the Giant Bomb password reset works the same way. Breaking news, Giant Bomb's password reset system has been compromised!!!

Avatar image for themailtoad
TheMailToad

19

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

Edited By TheMailToad

Jack Trenton now has every possible sleeve rolled up.

Avatar image for teekomeeko
teekomeeko

793

Forum Posts

1557

Wiki Points

0

Followers

Reviews: 0

User Lists: 6

Edited By teekomeeko

It took likely years to build the network to begin with, and they had no choice but to build it again in like a month. Whoever didn't see a weird exploit coming is out of their minds. 


The simplicity of the password reset was necessary because the interwebs confuses too many people, but coincidentally that type of thing is what MOST password resets I've ever had to do use (I think Amazon has it fairly simple, too, and my credit card info is all over that bitch), so pretty much most of the internet is vulnerable to this type of account theft.
Avatar image for springfart
Springfart

572

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 12

Edited By Springfart

oh wow

Avatar image for mr_skeleton
Mr_Skeleton

5195

Forum Posts

7918

Wiki Points

0

Followers

Reviews: 0

User Lists: 15

Edited By Mr_Skeleton

Shit is still broke.

Avatar image for matiaz_tapia
matiaz_tapia

718

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

Edited By matiaz_tapia

READ THE ARTICLE PEOPLE!!!!!



Avatar image for legalbagel
LegalBagel

1955

Forum Posts

1590

Wiki Points

0

Followers

Reviews: 7

User Lists: 7

Edited By LegalBagel
@Sanj said:
@Protome said:

@Sanj said:

There seems to be some confusion surrounding this news.

This exploit does not allow people to take the new password you put in after the PSN came back up. If you can still log into your PSN then obviously your password wasn't reset and you have nothing to worry about regarding this particular exploit.    

This.
Hell, this isn't even an exploit. You guys have no idea how many websites let you change someone's password with that little info.
Hell, with Facebook all you need to know is one of their OLD passwords.
Exactly. I swear people just read what they want to read in an article. They see, "Sony" and "compromised" and think that the PSN has been hacked again and your passwords have been stolen. READ THE ARTICLE PEOPLE.     
Well, your password hasn't been stolen, but given that Sony already leaked your DOB and PSN name, I'm guessing that this stupid way of resetting passwords makes it easy picking for the hackers to take over your account again at a later date if people hadn't complained.  Not as bad as taking your new password, but still pretty bad.

Which makes me question the new "security measures" that Sony put in place.  I mean, honestly, they knew they had already leaked info and this is their way of resetting passwords?
Avatar image for djghostmare
djghostmare

94

Forum Posts

6692

Wiki Points

0

Followers

Reviews: 0

User Lists: 1

Edited By djghostmare

Yeah, I'm sorry but this is the same as answering "Mother's maiden name" in the place of birthdate. It's a stupid system that a lot of sites use, but it's not the biggest news. Moving on.


By the way, you should never publish your full complete birthdate anywhere (like on Facebook), because it is the most common security question ever. Do you know who else uses your birthdate as a security question? Your fucking bank! Your phone company will ask for your address, some will only require your postal code! A birthdate is not a security question! Every single institution in the world has to stop using addresses, birthdates, and mother's maiden names as their security question. I live in Québec and most women keep their maiden names after marriage. 

These are dumb questions. People who publicise this information on the internet are dumber.
Avatar image for spiritof
Spiritof

2471

Forum Posts

28754

Wiki Points

0

Followers

Reviews: 25

User Lists: 27

Edited By Spiritof

  

  The internet is dead. Long live the CB radio.
Avatar image for louiedog
louiedog

2391

Forum Posts

227

Wiki Points

0

Followers

Reviews: 0

User Lists: 2

Edited By louiedog
@Devoid said:
What. So Sony puts up this website, and then is just like, "Oh wait, the hackers woulda taken your date of birth when they got your email, right? WHOOPS".That's so stupid. Did they really not think of that?
It doesn't even need to be the hackers. If you have a public Facebook account or you're a more public figure (and bigger target), like a podcast host, who has mentioned their birthday to all, there is half the info. Many people have a pretty visible email address. Even if it's not the one used for PSN, googling for other email addresses for people is usually not that hard. I've done it a number of times to try and contact someone.

I bet the guy in charge of security at Sony puts one of those fake rock key hiders under his welcome mat.
Avatar image for valkyr
Valkyr

746

Forum Posts

1196

Wiki Points

0

Followers

Reviews: 0

User Lists: 37

Edited By Valkyr

Ok, this is stupid, I'm not going to enjoy an online service ever again if I have to be such a paranoid to be 'secure', you now what hackers, you want my data, take it, it's useless, I don't care just stop screwing up the matchmaking fun.

Avatar image for ch13696
ch13696

4760

Forum Posts

204

Wiki Points

0

Followers

Reviews: 0

User Lists: 11

Edited By ch13696
@ptc said:
@JohnPaulVann said:
Stop race-hating on Sony! This could happen to anybody. The only reason any one is talking about it is because Sony is Japanese. The RROD was infinitely worse than the PSN failure but nobody made even one tenth as much noise. 
Sony Defense Force - ENGAGE!
Microsoft fanboys - ENGAGE!
Avatar image for xpgamer7
xpgamer7

2488

Forum Posts

148

Wiki Points

0

Followers

Reviews: 12

User Lists: 5

Edited By xpgamer7

More Free games?

Avatar image for louiedog
louiedog

2391

Forum Posts

227

Wiki Points

0

Followers

Reviews: 0

User Lists: 2

Edited By louiedog
@Andvari said:
Yeah, I'm sorry but this is the same as answering "Mother's maiden name" in the place of birthdate. It's a stupid system that a lot of sites use, but it's not the biggest news. Moving on.

By the way, you should never publish your full complete birthdate anywhere (like on Facebook), because it is the most common security question ever. Do you know who else uses your birthdate as a security question? Your fucking bank! Your phone company will ask for your address, some will only require your postal code! A birthdate is not a security question! Every single institution in the world has to stop using addresses, birthdates, and mother's maiden names as their security question. I live in Québec and most women keep their maiden names after marriage. 

These are dumb questions. People who publicise this information on the internet are dumber.
Some of us don't use real answers for those security questions because they are so easy to find out. I guess I'll have to start using fake birth dates as well. And no, I never make mine visible anywhere.

I actually got into an argument with someone yesterday about online security. He thought I was a paranoid loon because I wasn't willing to give a website my name, address, phone number, birth date, and last 4 digits of my social security for a free lighter. He was willing to and used the argument that "i can come up with a random 4 digits and it's someone last 4...". I suppose he can also randomly come up with the person's name, address, birth date, etc. Some people are really stupid when it comes to online security and will sell themselves out to take part in a facebook quiz or for a free damn lighter.
Avatar image for deactivated-5d7bd9e4bef30
deactivated-5d7bd9e4bef30

4741

Forum Posts

128

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

I love how the truly stupid people are blaming the "hackers" for this.

It's about as close to hacking as social engineering over the phone.
You ignorami can suck my taint.
Also, Sony can suck my taint, I haven't been too inconvenienced by PSN's dowtime due to using my 360 for online and wasn't up in arms about how utter underwhelming the "Welcome Back" package was even though I owned most of the good stuff there for having the gall to support them.
I am however miffed about the stupendously new pinnacle of ineptitude they have shown here.
Mostly I'm disappointed in myself for being surprised by this.
Avatar image for coloursheep
coloursheep

70

Forum Posts

2

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

Edited By coloursheep
@JohnPaulVann: racism or no racism you are right that this could happen to anyone i cant believe so many gamers are up in arms about this but instead of being angry at the hackers all they care about is bitching about sony