Something went wrong. Try again later
    Follow

    PlayStation Network (PS3)

    Platform »

    The PlayStation Network is the online service by Sony Computer Entertainment, providing downloads of games, trailers, themes and much more. The service is free, but also offers a paid version for various benefits.

    Well, Crap... Sony's Password Reset System Has Been Compromised [UPDATED]

    Avatar image for warmonked
    warmonked

    679

    Forum Posts

    37

    Wiki Points

    0

    Followers

    Reviews: 1

    User Lists: 1

    #101  Edited By warmonked

    "...  to simply reset your account password provided they know your PSN account email and your date of birth. 


    so what? Password reset by submitting email is on every web site login ever.
    Avatar image for vexxan
    Vexxan

    4642

    Forum Posts

    943

    Wiki Points

    0

    Followers

    Reviews: 0

    User Lists: 3

    #102  Edited By Vexxan

    Unbelievable that the managed to set the remains of PSN on fire...just unbelievable. 

    Avatar image for 234rqsd2323d2
    234r2we232

    3175

    Forum Posts

    2007

    Wiki Points

    0

    Followers

    Reviews: 0

    User Lists: 16

    #103  Edited By 234r2we232
    @TheMailToad said:
    Jack Trenton now has every possible sleeve rolled up.
    I'm sure even he is rolling his eyes at PSN at this point.
    Avatar image for mnzy
    mnzy

    3047

    Forum Posts

    147

    Wiki Points

    0

    Followers

    Reviews: 0

    User Lists: 0

    #104  Edited By mnzy
    @coloursheep said:

    @JohnPaulVann: racism or no racism you are right that this could happen to anyone i cant believe so many gamers are up in arms about this but instead of being angry at the hackers all they care about is bitching about sony

    If you can't make a secure login system in 2011, you are either lazy or stupid.
    This could definately not happen to anyone, and it especially shouldn't to a billion dollar tech company like Sony.
    Avatar image for jeanluc
    jeanluc

    4071

    Forum Posts

    7939

    Wiki Points

    0

    Followers

    Reviews: 11

    User Lists: 13

    #105  Edited By jeanluc  Staff

    God damn it. All I want this year is to play inFamous 2 and Uncharted 3 in peace. Is that really to much to ask for?

    Avatar image for bacongames
    bacongames

    4157

    Forum Posts

    5806

    Wiki Points

    0

    Followers

    Reviews: 2

    User Lists: 8

    #106  Edited By bacongames
    @warmonked said:
    "...  to simply reset your account password provided they know your PSN account email and your date of birth. 

    so what? Password reset by submitting email is on every web site login ever.
    @Donos said:
    Isn't this how password reset works for just about anything? You enter your login username, and an email is sent to whatever email account is associated with that username. It just so happens that for PSN, your username is your email account.They could just make it so the password isn't reset until you hit a password reset link in that email, though that would be more open to phishing scams.I don't see much reason to be mad at Sony for doing the exact same thing as every other account-based online service.Edit: Hell, the Giant Bomb password reset works the same way. Breaking news, Giant Bomb's password reset system has been compromised!!!
    @teekomeeko said:
    It took likely years to build the network to begin with, and they had no choice but to build it again in like a month. Whoever didn't see a weird exploit coming is out of their minds. 

    The simplicity of the password reset was necessary because the interwebs confuses too many people, but coincidentally that type of thing is what MOST password resets I've ever had to do use (I think Amazon has it fairly simple, too, and my credit card info is all over that bitch), so pretty much most of the internet is vulnerable to this type of account theft.
    Man I love it when other people do my work for me.
    Avatar image for elyhaym
    elyhaym

    359

    Forum Posts

    0

    Wiki Points

    0

    Followers

    Reviews: 0

    User Lists: 0

    #107  Edited By elyhaym

    /yawn

    This is getting somewhat boring now.
    Avatar image for alittler
    alittler

    8

    Forum Posts

    0

    Wiki Points

    0

    Followers

    Reviews: 0

    User Lists: 0

    #108  Edited By alittler
    @ptc: Really?  Did not Japan, but a few days ago, outright deny the PSN from coming back online in Japan because it was not secure enough?

    ohai guyz, Japan aint dumb
    Avatar image for iotanon
    iotanon

    170

    Forum Posts

    16

    Wiki Points

    0

    Followers

    Reviews: 1

    User Lists: 11

    #109  Edited By iotanon
    @Microshock said:
    Hackers are real pieces of shit, aren't they. No-life basement dwelling losers that have nothing to do but to fuck peoples shit up.
    They didn't even gain anything out of this! They're just deliberately being dicks to millions of people for no reason. The only reason I could think of is that they're upset with the GeoHotz thing, so they did this hoping that people wouldn't read into it and would just get mad at Sony. And you know what? It's fucking working! Yes, Sony deserved what was coming to them, they needed to fix their security issues, but the innocent PS3 owners should not have been involved in any way.

    I'm really rooting for Sony this E3. This was supposed to be their year and it still can be.
    Avatar image for alittler
    alittler

    8

    Forum Posts

    0

    Wiki Points

    0

    Followers

    Reviews: 0

    User Lists: 0

    #110  Edited By alittler
    @JohnPaulVann: I agree! I had an RROD ages ago and I am STILL working on getting my credit card replaced!
    Avatar image for jbrighty
    JBrighty

    87

    Forum Posts

    120

    Wiki Points

    0

    Followers

    Reviews: 0

    User Lists: 4

    #111  Edited By JBrighty

    i was lucky on this, just before this whole mess happened my  CC validation date went off, and i never touched my PS3 since. guess i made the right move unconsciously hehe.

    Avatar image for deepspacejesus
    DeepSpaceJesus

    103

    Forum Posts

    0

    Wiki Points

    0

    Followers

    Reviews: 0

    User Lists: 0

    #113  Edited By DeepSpaceJesus
    @alittler: I thought it was more that they just wanted to make sure it was secure enough, not that they knew it wasn't secure.
    Avatar image for zeezkos
    zeezkos

    70

    Forum Posts

    0

    Wiki Points

    0

    Followers

    Reviews: 0

    User Lists: 0

    #114  Edited By zeezkos

    hmm so i guess i wasn't being crazy when i thought that perhaps the point was to put something in place to capture all the ppl who reset their passwords.  probably still an oversight and not a plot, but there it is...  glad i waited to use my ps3.

    Avatar image for rjaylee
    rjaylee

    3804

    Forum Posts

    529

    Wiki Points

    0

    Followers

    Reviews: 3

    User Lists: 2

    #115  Edited By rjaylee
    Avatar image for jediknight00719
    jediknight00719

    206

    Forum Posts

    0

    Wiki Points

    0

    Followers

    Reviews: 19

    User Lists: 7

    #116  Edited By jediknight00719

    thats pretty stupid on Sony's part.  All you need is a password reset system in which it asks for you e-mail address it checks if that e-mail address is in the system and then sends you an e-mail with a temporary password.  You use that password to log in, and the first thing it should do after logging in is to change the password.


    This is Security 101.  Come on Sony...
    Avatar image for pkshields
    Pkshields

    827

    Forum Posts

    113

    Wiki Points

    0

    Followers

    Reviews: 0

    User Lists: 8

    #117  Edited By Pkshields

    Bah!

    Avatar image for deactivated-5d7bd9e4bef30
    deactivated-5d7bd9e4bef30

    4741

    Forum Posts

    128

    Wiki Points

    0

    Followers

    Reviews: 0

    User Lists: 0

    @Tuffgong said:
    @warmonked said:
    "...  to simply reset your account password provided they know your PSN account email and your date of birth. 

    so what? Password reset by submitting email is on every web site login ever.
    @Donos said:
    Isn't this how password reset works for just about anything? You enter your login username, and an email is sent to whatever email account is associated with that username. It just so happens that for PSN, your username is your email account.They could just make it so the password isn't reset until you hit a password reset link in that email, though that would be more open to phishing scams.I don't see much reason to be mad at Sony for doing the exact same thing as every other account-based online service.Edit: Hell, the Giant Bomb password reset works the same way. Breaking news, Giant Bomb's password reset system has been compromised!!!
    @teekomeeko said:
    It took likely years to build the network to begin with, and they had no choice but to build it again in like a month. Whoever didn't see a weird exploit coming is out of their minds. 

    The simplicity of the password reset was necessary because the interwebs confuses too many people, but coincidentally that type of thing is what MOST password resets I've ever had to do use (I think Amazon has it fairly simple, too, and my credit card info is all over that bitch), so pretty much most of the internet is vulnerable to this type of account theft.
    Man I love it when other people do my work for me.
    I think the biggest thing is that the info that leaked in the first place was the user base's e-mail addresses and DOBs, something Sony probably should've put into consideration before rolling out PSN again. They should've known they'd be under scrutiny for the slightest crack in the armor.
    It just reeks of bad judgement.
    Avatar image for haziqonfire
    Haziqonfire

    250

    Forum Posts

    0

    Wiki Points

    0

    Followers

    Reviews: 0

    User Lists: 4

    #119  Edited By Haziqonfire

    Sony, get your shit together.


    This is becoming pathetic.
    Avatar image for siphillis
    Siphillis

    1357

    Forum Posts

    6549

    Wiki Points

    0

    Followers

    Reviews: 2

    User Lists: 17

    #120  Edited By Siphillis

    "State-of-the-Art" Security Technology.

    Avatar image for mjhaylett
    MJHAYLETT

    490

    Forum Posts

    0

    Wiki Points

    0

    Followers

    Reviews: 0

    User Lists: 0

    #121  Edited By MJHAYLETT

    yeah I have changed my password and now I have made a single use email address for PS3. Mind seeing as I am not putting any credit card info back on it then hackers have at it you goddamn menaces!

    Avatar image for winternet
    Winternet

    8454

    Forum Posts

    2255

    Wiki Points

    0

    Followers

    Reviews: 0

    User Lists: 6

    #122  Edited By Winternet

    Hahahaha this is hilarious!

    Avatar image for crusader8463
    crusader8463

    14850

    Forum Posts

    4290

    Wiki Points

    0

    Followers

    Reviews: 7

    User Lists: 5

    #123  Edited By crusader8463

    Man. That sign on the door at Sony that says "It has been _ days since we had a hacker incident." seems to be getting a work out lately.

    Avatar image for kahjah
    kahjah

    38

    Forum Posts

    0

    Wiki Points

    0

    Followers

    Reviews: 1

    User Lists: 0

    #124  Edited By kahjah

    I mean seeing as how I'm not putting my CC into the PSN anymore, I don't really care about changing a password. I have to do it all the time at work anyway. Not big news...moving on.

    Avatar image for protonguy
    Protonguy

    309

    Forum Posts

    30

    Wiki Points

    0

    Followers

    Reviews: 0

    User Lists: 1

    #125  Edited By Protonguy

    " We're creating all new accounts just to be able to safely log into the PlayStation Network. I really hate the Internet sometimes. " The internet is beautiful. Hate the people :P

    Also, wtf sony? Really, another issue already?

    Avatar image for deactivated-5d7bd9e4bef30
    deactivated-5d7bd9e4bef30

    4741

    Forum Posts

    128

    Wiki Points

    0

    Followers

    Reviews: 0

    User Lists: 0

    Oh dip! I just realized who the dastardly "hacker" who took down Sony was!


    Wheatley
    Wheatley











    It's obvious now!
    Avatar image for bacongames
    bacongames

    4157

    Forum Posts

    5806

    Wiki Points

    0

    Followers

    Reviews: 2

    User Lists: 8

    #127  Edited By bacongames
    @TeflonBilly: I think the important point is that the password reset compromise is only considered such because PSN went down recently and the indeterminate amounts of user info leaked could be used in this context.  Otherwise it's just as dangerous as literally almost any other account login structure out there.  It's valid to say that the previous compromise pokes a few more holes in the normal way of resetting passwords than normal, but the universal standard (however flawed) is not the problem here.  Therefore direct all hate back to the original issue of PSN's compromise and not the web-based pseudo-compromise.
    Avatar image for themasterds
    TheMasterDS

    3018

    Forum Posts

    7716

    Wiki Points

    0

    Followers

    Reviews: 1

    User Lists: 31

    #128  Edited By TheMasterDS
    Avatar image for omegapirate
    OmegaPirate

    5643

    Forum Posts

    6172

    Wiki Points

    0

    Followers

    Reviews: 0

    User Lists: 5

    #129  Edited By OmegaPirate

    Once again an article proves the theory that 90% of internet users never read the story, just the dramatic headlines.

    Those that have read the story realise this is not a big deal - and that those details are pretty much used in this way by nearly every site on the net (giantbomb included).

    Everyone else continue panicking and screaming to get your internet fanboy e-boner high and proud now that you have something to either rage about - or laugh about -
    which in the latter case just makes you an asshole, because if this WAS a major serious issue, it  would not be a laughing matter for those affected.
    Avatar image for deactivated-5d7bd9e4bef30
    deactivated-5d7bd9e4bef30

    4741

    Forum Posts

    128

    Wiki Points

    0

    Followers

    Reviews: 0

    User Lists: 0

    @Tuffgong: Hey, I totally agree with you. I just feel that not taking extra precautions was a bad call by Sony when you consider what the potential original info leak was.
    And how they've touted that they've been working with the security companies and whatnot before deciding to trot out PSN again.
    The Japanese government were wise to be wary
    Avatar image for deactivated-5865c6a5c9438
    deactivated-5865c6a5c9438

    544

    Forum Posts

    5

    Wiki Points

    0

    Followers

    Reviews: 0

    User Lists: 0

    Great.

    Avatar image for warmonked
    warmonked

    679

    Forum Posts

    37

    Wiki Points

    0

    Followers

    Reviews: 1

    User Lists: 1

    #132  Edited By warmonked
    @OmegaPirate said:
    Once again an article proves the theory that 90% of internet users never read the story, just the dramatic headlines.
    Those that have read the story realise this is not a big deal - and that those details are pretty much used in this way by nearly every site on the net (giantbomb included).

    Everyone else continue panicking and screaming to get your internet fanboy e-boner high and proud now that you have something to either rage about - or laugh about -
    which in the latter case just makes you an asshole, because if this WAS a major serious issue, it  would not be a laughing matter for those affected.
    Engadget is reporting that it's not a password reset, but it actually allowed you to enter a new password as well. If true, that was not obvious in this news post.
    Avatar image for euandewar
    EuanDewar

    5159

    Forum Posts

    136

    Wiki Points

    0

    Followers

    Reviews: 4

    User Lists: 0

    #133  Edited By EuanDewar

    Sorry, but thats fucking hilarious.

    Avatar image for andrewb
    AndrewB

    7816

    Forum Posts

    82

    Wiki Points

    0

    Followers

    Reviews: 1

    User Lists: 16

    #134  Edited By AndrewB

    "Nyleveia suggested that users create an entirely new email address for their PSN accounts, one not associated with any other online accounts in order to be absolutely safe. "  


    That's... just not acceptable.
    Avatar image for deepspacejesus
    DeepSpaceJesus

    103

    Forum Posts

    0

    Wiki Points

    0

    Followers

    Reviews: 0

    User Lists: 0

    #135  Edited By DeepSpaceJesus

    Yeah people are kinda overreacting in the comments here. All that really came of this was a (hopefully) fixed exploit and some downtime on their web-based login stuff. 

    Avatar image for samsaturday
    samsaturday

    119

    Forum Posts

    4319

    Wiki Points

    0

    Followers

    Reviews: 2

    User Lists: 16

    #136  Edited By samsaturday

    This would affect me more if I actually used my PS3 for anything other than movies. I haven't played a game on my PS3 in months! Lucky for me, I guess? A console I never use? Ugh.

    Avatar image for jakelogan
    JakeLogan

    226

    Forum Posts

    288

    Wiki Points

    0

    Followers

    Reviews: 0

    User Lists: 3

    #137  Edited By JakeLogan

    I uh, erm......hmmmmmm :S
    Avatar image for binarydragon
    BinaryDragon

    833

    Forum Posts

    2329

    Wiki Points

    0

    Followers

    Reviews: 5

    User Lists: 6

    #138  Edited By BinaryDragon
    @Stupot said:
    Hahahahaha
    brilliant.
    Avatar image for dtat
    dtat

    1750

    Forum Posts

    546

    Wiki Points

    0

    Followers

    Reviews: 1

    User Lists: 9

    #139  Edited By dtat

    2 Strikes Sony...

    Avatar image for hydraham
    HydraHam

    1380

    Forum Posts

    675

    Wiki Points

    0

    Followers

    Reviews: 0

    User Lists: 6

    #140  Edited By HydraHam

    But your account was only compromised if you got an email right?

    Avatar image for matfei90
    Matfei90

    1279

    Forum Posts

    5

    Wiki Points

    0

    Followers

    Reviews: 0

    User Lists: 6

    #141  Edited By Matfei90
    @JohnPaulVann said:
    Stop race-hating on Sony! This could happen to anybody. The only reason any one is talking about it is because Sony is Japanese. The RROD was infinitely worse than the PSN failure but nobody made even one tenth as much noise. 
    Last I heard, if my Xbox red rings, it doesn't compromise my bank account.
    Avatar image for sithtoast
    SithToast

    193

    Forum Posts

    484

    Wiki Points

    0

    Followers

    Reviews: 0

    User Lists: 2

    #142  Edited By SithToast

    For those saying rrod is "infinitely" worse, it really isn't. At least with that you didn't run the risk of your credit card and identity being stolen.

    Avatar image for deepspacejesus
    DeepSpaceJesus

    103

    Forum Posts

    0

    Wiki Points

    0

    Followers

    Reviews: 0

    User Lists: 0

    #143  Edited By DeepSpaceJesus
    @Matfei90 said:

    @JohnPaulVann said:

    Stop race-hating on Sony! This could happen to anybody. The only reason any one is talking about it is because Sony is Japanese. The RROD was infinitely worse than the PSN failure but nobody made even one tenth as much noise. 
    Last I heard, if my Xbox red rings, it doesn't compromise my bank account.
    Why are you people still replying to that really boring troll?

    VVV seriously how dumb are you VVV
    Avatar image for matfei90
    Matfei90

    1279

    Forum Posts

    5

    Wiki Points

    0

    Followers

    Reviews: 0

    User Lists: 6

    #144  Edited By Matfei90
    @DeepSpaceJesus: Sorry if I don't dig 10 pages deep just to see how many other people have quoted someone, because I don't give a fuck.
    Avatar image for deepspacejesus
    DeepSpaceJesus

    103

    Forum Posts

    0

    Wiki Points

    0

    Followers

    Reviews: 0

    User Lists: 0

    #145  Edited By DeepSpaceJesus
    @Matfei90: apology accepted
    Avatar image for deltadreamer
    DeltaDreamer

    137

    Forum Posts

    413

    Wiki Points

    0

    Followers

    Reviews: 0

    User Lists: 1

    #146  Edited By DeltaDreamer

    Thats it i'am selling my ps3

    Avatar image for zanthox
    Zanthox

    257

    Forum Posts

    220

    Wiki Points

    0

    Followers

    Reviews: 2

    User Lists: 6

    #147  Edited By Zanthox

    who was doing this online anyway? If this doesn't include SOE stuff it seems kinda silly.

    Avatar image for little_socrates
    Little_Socrates

    5847

    Forum Posts

    1570

    Wiki Points

    0

    Followers

    Reviews: 16

    User Lists: 23

    #148  Edited By Little_Socrates

    FUCKING CALLED IT.


    They really need to issue a second apology for this. Really.
    Avatar image for dragonkingf0
    Dragonkingf0

    3

    Forum Posts

    0

    Wiki Points

    0

    Followers

    Reviews: 0

    User Lists: 0

    #149  Edited By Dragonkingf0

    Oh come on people it not that big of a deal...

    Avatar image for benjaebe
    benjaebe

    2868

    Forum Posts

    7204

    Wiki Points

    0

    Followers

    Reviews: 1

    User Lists: 6

    #150  Edited By benjaebe

    Seems like more of an oversight than a real hack. Someone probably should've thought about the fact that hackers had your date of birth and email before that's all they required for a password reset, but since they locked password resets to your original PS3 (not a bad move, really) I'm not sure how they could've solved having a web-based solution. The hackers have access to all the information Sony had access to, other than maybe sending a temporary password through email (provided you weren't stupid enough to leave your email password the same.)

    This edit will also create new pages on Giant Bomb for:

    Beware, you are proposing to add brand new pages to the wiki along with your edits. Make sure this is what you intended. This will likely increase the time it takes for your changes to go live.

    Comment and Save

    Until you earn 1000 points all your submissions need to be vetted by other Giant Bomb users. This process takes no more than a few hours and we'll send you an email once approved.