Something went wrong. Try again later
    Follow

    PlayStation Network (PS3)

    Platform »

    The PlayStation Network is the online service by Sony Computer Entertainment, providing downloads of games, trailers, themes and much more. The service is free, but also offers a paid version for various benefits.

    Well, Crap... Sony's Password Reset System Has Been Compromised [UPDATED]

    Avatar image for fireburger
    FireBurger

    1612

    Forum Posts

    2836

    Wiki Points

    0

    Followers

    Reviews: 4

    User Lists: 11

    #151  Edited By FireBurger

    I think Kaz is beheading people right now. Now that video makes him look like an idiot.

    Avatar image for jagenheim
    jagenheim

    227

    Forum Posts

    89

    Wiki Points

    0

    Followers

    Reviews: 1

    User Lists: 3

    #152  Edited By jagenheim

    There is one thing I'm not clear about, as I have not used this Sony Reset Password functionality; what happens when you do reset the password?


    What is it reset to? It doesn't seem to be sent to the user via email? Most sites sends you a randomized password that you can login with, but here it seems to be the hacker that selects the password and thus can access the account freely after logging in again?!?

    If so; I don't understand everyone who defends this is a no-issue. Because if the above it true, and I don't know if it is, then ALL accounts are unsafe; even those with 'secure' (i.e. impossible to brute-force) passwords.
    Avatar image for afroman269
    Afroman269

    7440

    Forum Posts

    103

    Wiki Points

    0

    Followers

    Reviews: 0

    User Lists: 6

    #153  Edited By Afroman269

    Silly Sony.

    Avatar image for meteora
    meteora

    5844

    Forum Posts

    17

    Wiki Points

    0

    Followers

    Reviews: 1

    User Lists: 3

    #154  Edited By meteora

    Surely they must have thought this over first before implementing it...

    Avatar image for beforet
    beforet

    3534

    Forum Posts

    47

    Wiki Points

    0

    Followers

    Reviews: 1

    User Lists: 2

    #155  Edited By beforet

    It's like everything is crumbling around Sony, an weare the ones getting the shit. Well, I have a few other emails. I'll just switch to those. Pain in the ass, it is.

    Avatar image for tepidshark
    TepidShark

    1493

    Forum Posts

    16438

    Wiki Points

    0

    Followers

    Reviews: 1

    User Lists: 14

    #156  Edited By TepidShark

    I was about to say I didn't know what the big deal was because I logged in just fine, but then I read that it was the web version.

    Avatar image for swick
    Swick

    266

    Forum Posts

    699

    Wiki Points

    0

    Followers

    Reviews: 2

    User Lists: 6

    #157  Edited By Swick

    Until hackers back off a bit... bye bye Sony.

    Avatar image for benjaebe
    benjaebe

    2868

    Forum Posts

    7204

    Wiki Points

    0

    Followers

    Reviews: 1

    User Lists: 6

    #158  Edited By benjaebe

    For anyone interested in how the exploit was done, here it is:

    The prodecure is as follows:
    1) Navigate to : https://store.playstation.com/accounts/reset/resetPassword.action?token (this is normally, via email, https://store.playstation.com/accounts/reset/resetPassword.action?token=YYYYYYYYYYYYYYYYYYYYYYYY with the y's being a unique token) - do not enter the code at this point.
    2) Open a new tab in firefox, and go to fr.playstation.com (other pages will work too most likely), and click Login (Connexion)
    3) Click Recover password
    4) Enter the email and date of birth of the target account
    5) Click continue, then on the confirmation page, click "Reset using E-mail"
    6) Switch back to the original tab, and enter the code, then click continue
    7) You will now be asked to enter a new password for the target account
    Avatar image for machofantastico
    MachoFantastico

    6762

    Forum Posts

    24

    Wiki Points

    0

    Followers

    Reviews: 73

    User Lists: 4

    #159  Edited By MachoFantastico

    Seriously... what the hell Sony? Insane!

    Avatar image for rafaelmei
    RafaelMei

    368

    Forum Posts

    416

    Wiki Points

    0

    Followers

    Reviews: 0

    User Lists: 5

    #160  Edited By RafaelMei

    Un-fucking-believable

    Avatar image for cronoxtream
    CronoXtream

    133

    Forum Posts

    3

    Wiki Points

    0

    Followers

    Reviews: 0

    User Lists: 0

    #161  Edited By CronoXtream

    lol dam, sony is just fucking up by the numbers.

    Avatar image for dropabombonit
    dropabombonit

    1543

    Forum Posts

    0

    Wiki Points

    0

    Followers

    Reviews: 0

    User Lists: 0

    #162  Edited By dropabombonit

    Not that bad, at least the console stuff is fine

    Avatar image for chickdigger802
    chickdigger802

    575

    Forum Posts

    38

    Wiki Points

    0

    Followers

    Reviews: 5

    User Lists: 2

    #163  Edited By chickdigger802

    god with all this bad shit going down. I really do hope  Sony got some super good stuff to reveal during E3.

    ngp for $100 WOOWEOWOWOWOO!

    Avatar image for bones8677
    Bones8677

    3539

    Forum Posts

    567

    Wiki Points

    0

    Followers

    Reviews: 1

    User Lists: 11

    #164  Edited By Bones8677

    Can't they fix this by implementing a secret question kind of security?

    Avatar image for deactivated-6157afb2b3c07
    deactivated-6157afb2b3c07

    1026

    Forum Posts

    2483

    Wiki Points

    0

    Followers

    Reviews: 2

    User Lists: 4

    I don't even have words for this.

    Avatar image for buccura
    Buccura

    255

    Forum Posts

    88

    Wiki Points

    0

    Followers

    Reviews: 0

    User Lists: 12

    #166  Edited By Buccura

    Goddommot Sono

    Avatar image for kyle
    Kyle

    2383

    Forum Posts

    6307

    Wiki Points

    0

    Followers

    Reviews: 0

    User Lists: 12

    #167  Edited By Kyle

    Are you fucking kidding me? 
    Are you fucking kidding me? 
    Avatar image for shadowdogg
    ShadowDoGG

    152

    Forum Posts

    299

    Wiki Points

    0

    Followers

    Reviews: 3

    User Lists: 0

    #168  Edited By ShadowDoGG

    Misleading title...

    Avatar image for joeybagad0nutz
    joeybagad0nutz

    1500

    Forum Posts

    0

    Wiki Points

    0

    Followers

    Reviews: 0

    User Lists: 0

    #169  Edited By joeybagad0nutz

    And I was thinking of buying my own ps3. Looks like I'm gonna wait.
    Avatar image for theinsider
    TheInsider

    55

    Forum Posts

    0

    Wiki Points

    0

    Followers

    Reviews: 0

    User Lists: 0

    #170  Edited By TheInsider

     Yea, on the 1 to 10 oh crap scale this is a 1

    Avatar image for chan05
    chan05

    382

    Forum Posts

    4408

    Wiki Points

    0

    Followers

    Reviews: 0

    User Lists: 14

    #171  Edited By chan05

    i thought they were heavily "testing" there new security systems before coming back online...seriously...how unprepared are these people?

    Avatar image for nl_buddha
    NL_Buddha

    64

    Forum Posts

    8

    Wiki Points

    0

    Followers

    Reviews: 0

    User Lists: 0

    #172  Edited By NL_Buddha
    @captain_clayman: Gooder?? You have the nerve to crap on them and not even use proper english!! Please, the 360 had a 46% failure rate and no one has even cried this much about that. All they did was give you an extra warranty which doesn't cost them a cent. Sony is giving away free games and movies!! That costs much more then an extra warranty.  Just saying.  
    Avatar image for clstirens
    clstirens

    854

    Forum Posts

    15

    Wiki Points

    0

    Followers

    Reviews: 0

    User Lists: 0

    #173  Edited By clstirens
    @Kyle said:
    Are you fucking kidding me? 
    Are you fucking kidding me? 
    Though really, who the hell was doing this online? Just use your console the next time you turn it on, it takes two seconds.
    Except the last update made it so if PSN determined that your ps3 wasn't the one you originally used with that PSN ID, you MUST do it online. (unless this issue somehow doesn't affect the e-mails going out?)

    I had no trouble, but a friend of mine has only ever used one ps3, and it forced him to change it via the web, not his console.
    Avatar image for unsolvedparadox
    unsolvedparadox

    2298

    Forum Posts

    31

    Wiki Points

    0

    Followers

    Reviews: 1

    User Lists: 2

    #174  Edited By unsolvedparadox
    @NL_Buddha said:

    @captain_clayman: Gooder?? You have the nerve to crap on them and not even use proper english!! Please, the 360 had a 46% failure rate and no one has even cried this much about that. All they did was give you an extra warranty which doesn't cost them a cent. Sony is giving away free games and movies!! That costs much more then an extra warranty.  Just saying.  

    I'm not going to defend the less than stellar quality of the Xbox 360 launch hardware. That said, how do you figure an extra warranty on hardware with what you state was a 46% failure rate would be cheaper than a selection of downloadable games that many affected users already own?

    No physical parts to replace or transport, no repair labour required for the Sony offering. You may be going a little far in your harsh assessment of the RROD problem.
    Avatar image for theht
    TheHT

    15998

    Forum Posts

    1562

    Wiki Points

    0

    Followers

    Reviews: 1

    User Lists: 9

    #175  Edited By TheHT
    No Caption Provided
    Avatar image for dprabon
    dprabon

    344

    Forum Posts

    10676

    Wiki Points

    0

    Followers

    Reviews: 0

    User Lists: 7

    #176  Edited By dprabon
    @Tuffgong said:
    @warmonked said:
    "...  to simply reset your account password provided they know your PSN account email and your date of birth. 

    so what? Password reset by submitting email is on every web site login ever.
    @Donos said:
    Isn't this how password reset works for just about anything? You enter your login username, and an email is sent to whatever email account is associated with that username. It just so happens that for PSN, your username is your email account.They could just make it so the password isn't reset until you hit a password reset link in that email, though that would be more open to phishing scams.I don't see much reason to be mad at Sony for doing the exact same thing as every other account-based online service.Edit: Hell, the Giant Bomb password reset works the same way. Breaking news, Giant Bomb's password reset system has been compromised!!!
    @teekomeeko said:
    It took likely years to build the network to begin with, and they had no choice but to build it again in like a month. Whoever didn't see a weird exploit coming is out of their minds. 

    The simplicity of the password reset was necessary because the interwebs confuses too many people, but coincidentally that type of thing is what MOST password resets I've ever had to do use (I think Amazon has it fairly simple, too, and my credit card info is all over that bitch), so pretty much most of the internet is vulnerable to this type of account theft.
    Man I love it when other people do my work for me.
    @Zero_Dude said:
    @Microshock said:
    Hackers are real pieces of shit, aren't they. No-life basement dwelling losers that have nothing to do but to fuck peoples shit up.
    They didn't even gain anything out of this! They're just deliberately being dicks to millions of people for no reason. The only reason I could think of is that they're upset with the GeoHotz thing, so they did this hoping that people wouldn't read into it and would just get mad at Sony. And you know what? It's fucking working! Yes, Sony deserved what was coming to them, they needed to fix their security issues, but the innocent PS3 owners should not have been involved in any way.I'm really rooting for Sony this E3. This was supposed to be their year and it still can be.
    True, true.
    I think I have to laugh, so not to cry. / :
    Avatar image for justinaquarius
    JustinAquarius

    319

    Forum Posts

    2

    Wiki Points

    0

    Followers

    Reviews: 1

    User Lists: 0

    #178  Edited By JustinAquarius

    Guess you get what you pay for with PSN (which is nothing)

    Avatar image for fuzzylemon
    FuzzYLemoN

    1609

    Forum Posts

    2558

    Wiki Points

    0

    Followers

    Reviews: 0

    User Lists: 1

    #179  Edited By FuzzYLemoN

    E3 is going to be hella awkward.

    Avatar image for dj_lae
    DJ_Lae

    672

    Forum Posts

    6448

    Wiki Points

    0

    Followers

    Reviews: 11

    User Lists: 10

    #180  Edited By DJ_Lae


    I love how they're not using a simple password reset system via e-mail (where you request a reset and then click a generated link that's sent to you), but simply allowing you to verify yourself via personal information.

     

    Because, you know, it's not as if anyone just stole everyone's fucking personal information a month ago.

    Avatar image for ahmadmetallic
    AhmadMetallic

    19300

    Forum Posts

    -1

    Wiki Points

    0

    Followers

    Reviews: 1

    User Lists: 11

    #181  Edited By AhmadMetallic
    @Microshock said: 

    Hackers are real pieces of shit, aren't they. No-life basement dwelling losers that have nothing to do but to fuck peoples shit up.

    how do you know they don't have successful lives where they dwell in real houses, with lots to do in their lives?
    just because they hack and damage other people's online property, you stereotype them ?

    way to go, gamer.  
    Avatar image for jackel2072
    Jackel2072

    2510

    Forum Posts

    370

    Wiki Points

    0

    Followers

    Reviews: 0

    User Lists: 11

    #182  Edited By Jackel2072
    @TheHT said:
    No Caption Provided
    pretty much...
    Avatar image for pibo47
    Pibo47

    3238

    Forum Posts

    8

    Wiki Points

    0

    Followers

    Reviews: 0

    User Lists: 3

    #183  Edited By Pibo47

    Jesus fucking christ sony, are you seriously serious?

    Avatar image for 1p
    1p

    798

    Forum Posts

    42

    Wiki Points

    0

    Followers

    Reviews: 0

    User Lists: 3

    #184  Edited By 1p

    PSN security breach - It's the gift that keeps on giving!

    Avatar image for aarny91
    Aarny91

    3962

    Forum Posts

    2309

    Wiki Points

    0

    Followers

    Reviews: 6

    User Lists: 14

    #185  Edited By Aarny91
    @Ahmad_Metallic said:
    @Microshock said: 

    Hackers are real pieces of shit, aren't they. No-life basement dwelling losers that have nothing to do but to fuck peoples shit up.

    how do you know they don't have successful lives where they dwell in real houses, with lots to do in their lives?
    just because they hack and damage other people's online property, you stereotype them ?

    way to go, gamer.  
    Do they really deserve respect, though?
    Avatar image for nasar7
    Nasar7

    3236

    Forum Posts

    647

    Wiki Points

    0

    Followers

    Reviews: 0

    User Lists: 5

    #186  Edited By Nasar7
    @Aarny said:
    @Ahmad_Metallic said:
    @Microshock said: 

    Hackers are real pieces of shit, aren't they. No-life basement dwelling losers that have nothing to do but to fuck peoples shit up.

    how do you know they don't have successful lives where they dwell in real houses, with lots to do in their lives?
    just because they hack and damage other people's online property, you stereotype them ?

    way to go, gamer.  
    Do they really deserve respect, though?
    No, they don't. Fuck them.
    Avatar image for xanavi
    xanavi

    216

    Forum Posts

    2317

    Wiki Points

    0

    Followers

    Reviews: 0

    User Lists: 11

    #187  Edited By xanavi
    @Aarny: Remember that the first game was Tennis for Two hacked together on a oscilloscope, so we probably wouldn't even have video games if there were never any hackers.
    Avatar image for swomar
    swomar

    66

    Forum Posts

    0

    Wiki Points

    0

    Followers

    Reviews: 0

    User Lists: 1

    #188  Edited By swomar
    @NL_Buddha said:
    @captain_clayman: Gooder?? You have the nerve to crap on them and not even use proper english!! Please, the 360 had a 46% failure rate and no one has even cried this much about that. All they did was give you an extra warranty which doesn't cost them a cent. Sony is giving away free games and movies!! That costs much more then an extra warranty.  Just saying.  
    Not to be a dick here, but you really shouldn't make fun of someone's English if you can't tell the difference between "then" and "than". And how exactly does extending warranties on faulty hardware doesn't cost money?
    Avatar image for wrathofbanja
    WrathOfBanja

    370

    Forum Posts

    67

    Wiki Points

    0

    Followers

    Reviews: 1

    User Lists: 3

    #189  Edited By WrathOfBanja
    @swomar said:

    @NL_Buddha said:

    @captain_clayman: Gooder?? You have the nerve to crap on them and not even use proper english!! Please, the 360 had a 46% failure rate and no one has even cried this much about that. All they did was give you an extra warranty which doesn't cost them a cent. Sony is giving away free games and movies!! That costs much more then an extra warranty.  Just saying.  
    Not to be a dick here, but you really shouldn't make fun of someone's English if you can't tell the difference between "then" and "than". And how exactly does extending warranties on faulty hardware doesn't cost money?
    "And how exactly does extending warranties on faulty hardware doesn'tcost money?"
    Grammar mistakes everywhere!
    Avatar image for twoonefive
    TwoOneFive

    9793

    Forum Posts

    203

    Wiki Points

    0

    Followers

    Reviews: 0

    User Lists: 1

    #190  Edited By TwoOneFive
    @Aarny said:
    @Ahmad_Metallic said:
    @Microshock said: 

    Hackers are real pieces of shit, aren't they. No-life basement dwelling losers that have nothing to do but to fuck peoples shit up.

    how do you know they don't have successful lives where they dwell in real houses, with lots to do in their lives?
    just because they hack and damage other people's online property, you stereotype them ?

    way to go, gamer.  
    Do they really deserve respect, though?
    yea man, way to go! .... wtf?! are you serious, they derserve to be stereotyped because what they do is wrong so fuck em
    Avatar image for woodenplatypus
    WoodenPlatypus

    1389

    Forum Posts

    3983

    Wiki Points

    0

    Followers

    Reviews: 2

    User Lists: 0

    #191  Edited By WoodenPlatypus

    Oh god.

    Avatar image for ryanwho
    ryanwho

    12011

    Forum Posts

    -1

    Wiki Points

    0

    Followers

    Reviews: 0

    User Lists: 0

    #192  Edited By ryanwho

    Fool me 13 times...

    Avatar image for aarny91
    Aarny91

    3962

    Forum Posts

    2309

    Wiki Points

    0

    Followers

    Reviews: 6

    User Lists: 14

    #193  Edited By Aarny91
    @xanavi said:
    @Aarny: Remember that the first game was Tennis for Two hacked together on a oscilloscope, so we probably wouldn't even have video games if there were never any hackers.
    But that's hacking something together that doesn't have any bad effects for other people. What the PSN hackers are doing annoy thousands of people.
    Avatar image for hitmanagent47
    HitmanAgent47

    8553

    Forum Posts

    25

    Wiki Points

    0

    Followers

    Reviews: 0

    User Lists: 2

    #194  Edited By HitmanAgent47

    Wow, maybe it's time I sell the ps3 and get a blu ray player with a xbox 360 instead. If they can't figure this out, then I can't trust them.

    Avatar image for sayishere
    Sayishere

    1854

    Forum Posts

    4422

    Wiki Points

    0

    Followers

    Reviews: 1

    User Lists: 5

    #195  Edited By Sayishere

    Chill out people

    Avatar image for hizang
    Hizang

    9475

    Forum Posts

    8249

    Wiki Points

    0

    Followers

    Reviews: 22

    User Lists: 15

    #196  Edited By Hizang

    Giant Bomb's Top Men should be running Sony!

    Avatar image for thefreeman
    TheFreeMan

    2712

    Forum Posts

    1120

    Wiki Points

    0

    Followers

    Reviews: 0

    User Lists: 1

    #197  Edited By TheFreeMan

    Fuck.

    Avatar image for jeust
    Jeust

    11739

    Forum Posts

    15085

    Wiki Points

    0

    Followers

    Reviews: 8

    User Lists: 15

    #198  Edited By Jeust

    Well, that's not unheard of... 


    A lot of systems have similar exploits. Facebook, with some quicksteps can reveal the email a person has his/her facebook account connected to, revealing part of the combination email / password needed to have access to the account. ^^

    We live in an insecure world.
    Avatar image for vodun
    Vodun

    2403

    Forum Posts

    220

    Wiki Points

    0

    Followers

    Reviews: 0

    User Lists: 0

    #199  Edited By Vodun

    Eeeh...I fail to see where the hacking is involved here? Just sounds like they can reset your password? Or is there some way to intercept the newly generated password?


    Either way this just sounds like a dumb design, not a security breach as such. You know, a dumb design made under intense pressure to get something out, anything, for the love of god get something out there....
    Avatar image for zombiejames
    ZombieJames

    41

    Forum Posts

    0

    Wiki Points

    0

    Followers

    Reviews: 0

    User Lists: 0

    #200  Edited By ZombieJames

    The issue's been fixed: 
    http://blog.us.playstation.com/2011/05/18/update-on-psn-password-reset-process/

    This edit will also create new pages on Giant Bomb for:

    Beware, you are proposing to add brand new pages to the wiki along with your edits. Make sure this is what you intended. This will likely increase the time it takes for your changes to go live.

    Comment and Save

    Until you earn 1000 points all your submissions need to be vetted by other Giant Bomb users. This process takes no more than a few hours and we'll send you an email once approved.