Welcome to the Invelos forums. Please read the forum rules before posting.

Read access to our public forums is open to everyone. To post messages, a free registration is required.

If you have an Invelos account, sign in to post.

    Invelos Forums->General: General Discussion Page: 1 2 3 4  Previous   Next
PlayStation Network Compromised
Author Message
DVD Profiler Desktop and Mobile RegistrantDr. Killpatient
Here's my card
Registered: May 19, 2007
Reputation: Highest Rating
United States Posts: 5,917
Posted:
PM this userView this user's DVD collectionDirect link to this postReply with quote
Also, just about every news story on the breach said that passwords were compromised. I believe I read that Sony has encouraged it's members to change the password on other sites if they used the same password on the PSN.

This tells me that the passwords are in plain-text format without any encryption.
DVD Profiler Desktop and Mobile RegistrantStar ContributorTaro
Registered: February 23, 2009
Reputation: High Rating
Belgium Posts: 1,580
Posted:
PM this userView this user's DVD collectionDirect link to this postReply with quote
Quoting Dr. Killpatient:
Quote:
This tells me that the passwords are in plain-text format without any encryption.

They explicited said so in their first press release: all data, excluding credit card info, is in a non-encrypted table (non-encrypted I believe doesn't necessarily mean plain text but chances are it is).
CC info was in a seperate table that has 128-bit encryption.

Some people are now saying that the non-encrypted table was hashed and not in plain text, but I can't find an official source (Sony source) to confirm this.
Blu-ray collection
DVD collection
My Games
My Trophies
 Last edited: by Taro
DVD Profiler Unlimited RegistrantStar Contributorpaulb_99
PSN-ID: Magnolia-Fan
Registered: March 14, 2007
Netherlands Posts: 868
Posted:
PM this userView this user's DVD collectionDirect link to this postReply with quote
Saw this today, your passwords were not in plain text.

I also spoke to my CC company and they advised that, while of course be very vigilant, there was no reason to cancel my card. If anything suspicious happens they will cancel the card at no cost and fully refund those payments,

Paul
DVD Profiler Desktop and Mobile RegistrantDr. Killpatient
Here's my card
Registered: May 19, 2007
Reputation: Highest Rating
United States Posts: 5,917
Posted:
PM this userView this user's DVD collectionDirect link to this postReply with quote
Keep in mind that your CC company may want to mitigate the potential costs of sending out millions of new CC cards on a gamble that the CC info won't be decrypted.

I'm glad that the passwords were hashed. While not infallible in preventing against figuring out potential matches, the workload would be immense - they would have to create a hash table for every possible password combination to break it.  Using characters available on the US keyboard, the number of iterations increases by a power of 94 every time you add a character.
 Last edited: by Dr. Killpatient
DVD Profiler Desktop and Mobile RegistrantStar ContributorTaro
Registered: February 23, 2009
Reputation: High Rating
Belgium Posts: 1,580
Posted:
PM this userView this user's DVD collectionDirect link to this postReply with quote
Ah, that's the proof of the hashing I was looking for. So far all I had was indirect hearsay.

It does somewhat reassure me.
Blu-ray collection
DVD collection
My Games
My Trophies
DVD Profiler Unlimited RegistrantStar Contributorpaulb_99
PSN-ID: Magnolia-Fan
Registered: March 14, 2007
Netherlands Posts: 868
Posted:
PM this userView this user's DVD collectionDirect link to this postReply with quote
PSN is starting back up again starting right now, you'll be required to download firmware 3.61 and reset your password, after that you may already be able on go online (US & Canada) or later today (rest of the world)


Paul
DVD Profiler Desktop and Mobile RegistrantStar ContributorBad Father
Registered: July 23, 2001
Registered: March 13, 2007
Posts: 4,596
Posted:
PM this userView this user's DVD collectionDirect link to this postReply with quote
The update took about 10 minutes from start to password change.
My WebGenDVD online Collection
    Invelos Forums->General: General Discussion Page: 1 2 3 4  Previous   Next