• Log InLog In
  • Register
Liquid`
Team Liquid Liquipedia
EST 11:49
CET 17:49
KST 01:49
  • Home
  • Forum
  • Calendar
  • Streams
  • Liquipedia
  • Features
  • Store
  • EPT
  • TL+
  • StarCraft 2
  • Brood War
  • Smash
  • Heroes
  • Counter-Strike
  • Overwatch
  • Liquibet
  • Fantasy StarCraft
  • TLPD
  • StarCraft 2
  • Brood War
  • Blogs
Forum Sidebar
Events/Features
News
Featured News
TL.net Map Contest #21: Winners11Intel X Team Liquid Seoul event: Showmatches and Meet the Pros10[ASL20] Finals Preview: Arrival13TL.net Map Contest #21: Voting12[ASL20] Ro4 Preview: Descent11
Community News
StarCraft, SC2, HotS, WC3, Returning to Blizzcon!45$5,000+ WardiTV 2025 Championship7[BSL21] RO32 Group Stage4Weekly Cups (Oct 26-Nov 2): Liquid, Clem, Solar win; LAN in Philly2Weekly Cups (Oct 20-26): MaxPax, Clem, Creator win10
StarCraft 2
General
Mech is the composition that needs teleportation t TL.net Map Contest #21: Winners StarCraft, SC2, HotS, WC3, Returning to Blizzcon! RotterdaM "Serral is the GOAT, and it's not close" Weekly Cups (Oct 20-26): MaxPax, Clem, Creator win
Tourneys
Constellation Cup - Main Event - Stellar Fest Sparkling Tuna Cup - Weekly Open Tournament $5,000+ WardiTV 2025 Championship Merivale 8 Open - LAN - Stellar Fest Sea Duckling Open (Global, Bronze-Diamond)
Strategy
Custom Maps
Map Editor closed ?
External Content
Mutation # 499 Chilling Adaptation Mutation # 498 Wheel of Misfortune|Cradle of Death Mutation # 497 Battle Haredened Mutation # 496 Endless Infection
Brood War
General
[ASL20] Ask the mapmakers — Drop your questions FlaSh on: Biggest Problem With SnOw's Playstyle BW General Discussion BGH Auto Balance -> http://bghmmr.eu/ Where's CardinalAllin/Jukado the mapmaker?
Tourneys
[Megathread] Daily Proleagues [ASL20] Grand Finals [BSL21] RO32 Group A - Saturday 21:00 CET [BSL21] RO32 Group B - Sunday 21:00 CET
Strategy
PvZ map balance Current Meta How to stay on top of macro? Soma's 9 hatch build from ASL Game 2
Other Games
General Games
Stormgate/Frost Giant Megathread Should offensive tower rushing be viable in RTS games? Nintendo Switch Thread Path of Exile Dawn of War IV
Dota 2
Official 'what is Dota anymore' discussion
League of Legends
Heroes of the Storm
Simple Questions, Simple Answers Heroes of the Storm 2.0
Hearthstone
Deck construction bug Heroes of StarCraft mini-set
TL Mafia
TL Mafia Community Thread SPIRED by.ASL Mafia {211640}
Community
General
Russo-Ukrainian War Thread Things Aren’t Peaceful in Palestine Canadian Politics Mega-thread US Politics Mega-thread The Games Industry And ATVI
Fan Clubs
White-Ra Fan Club The herO Fan Club!
Media & Entertainment
[Manga] One Piece Anime Discussion Thread Movie Discussion! Korean Music Discussion Series you have seen recently...
Sports
2024 - 2026 Football Thread Formula 1 Discussion NBA General Discussion MLB/Baseball 2023 TeamLiquid Health and Fitness Initiative For 2023
World Cup 2022
Tech Support
SC2 Client Relocalization [Change SC2 Language] Linksys AE2500 USB WIFI keeps disconnecting Computer Build, Upgrade & Buying Resource Thread
TL Community
The Automated Ban List
Blogs
Learning my new SC2 hotkey…
Hildegard
Coffee x Performance in Espo…
TrAiDoS
Saturation point
Uldridge
DnB/metal remix FFO Mick Go…
ImbaTosS
Reality "theory" prov…
perfectspheres
Our Last Hope in th…
KrillinFromwales
Customize Sidebar...

Website Feedback

Closed Threads



Active: 1521 users

Private PSN and SOE Info Has Been Stolen including CC #s -…

Forum Index > General Forum
Post a Reply
Prev 1 14 15 16 17 18 21 Next All
Johnny Business
Profile Joined August 2010
Sweden1251 Posts
April 28 2011 13:09 GMT
#301
On April 28 2011 12:07 brijan wrote:
How is it possible to do anything with the CC details if they don't have a CVC number? Random guessing?


There are places where you can buy stuff without the ccv.

Also it shouldn't matter if the creditcard numbers where hashed since they are kinda easy to brute force. (0-9, 16 characters and on some cards the first 4 are identical.)
Serious Business
Tschis
Profile Joined November 2010
Brazil1511 Posts
April 28 2011 13:57 GMT
#302
Yeah, because brute forcing hundreds of possibilities won´t call any Banks attention?
"A coward is not someone that runs from a battle knowing he will lose. A coward is someone who challenges a weak knowing he will win."
Scribble
Profile Blog Joined March 2011
2077 Posts
April 28 2011 14:19 GMT
#303
This is honestly a minor pain in the ass at best. It's alarming that Sony stored shit the way they did, but if someone is capable of getting this far, one extra step to get to our personal info isn't going to stop them. In any case, all this means is that we should replace our CCs/Debits and be done with it.
Mista_Masta
Profile Joined January 2009
Netherlands557 Posts
April 28 2011 14:39 GMT
#304
Wow, this news is huge. I'm so glad I don't have a PS3, but I feel very sorry for everyone who does, and also a bit for Sony - although they are idiots for letting this happen in the first place.
CyberPitz
Profile Blog Joined June 2009
United States428 Posts
Last Edited: 2011-04-28 14:55:18
April 28 2011 14:54 GMT
#305
According to a Q&A from Sony, they did encrypt their CC data.
http://blog.us.playstation.com/2011/04/27/qa-1-for-playstation-network-and-qriocity-services/

Was my personal data encrypted?
A: All of the data was protected, and access was restricted both physically and through the perimeter and security of the network. The entire credit card table was encrypted and we have no evidence that credit card data was taken. The personal data table, which is a separate data set, was not encrypted, but was, of course, behind a very sophisticated security system that was breached in a malicious attack.


I went and got my card cancelled and reordered just in case (Now to find a way to buy things...), but I hardly blame Sony for this. It's not like they handed the info to the hackers on a platter. Well, my personal info, but what do I care, they could google search that info.
Zhou
Profile Joined February 2009
United States832 Posts
April 28 2011 14:55 GMT
#306
I wonder if this conflicts with things like Netflix in terms of privacy issues. Just to be the safe side, I had my parents check their accounts just in case as well.

Man, I don't even want to check my own at this rate that this is going downhill...

I'm even more afraid to know what happens when they do figure out all this stuff and how much backlash there is going to be.
Aerakin
Profile Joined January 2011
185 Posts
April 28 2011 16:21 GMT
#307
Wow, some of you people are just... stupid.

Credit Card table was encrypted and the other data doesn't even matter much (I assume passwords were also encrypted)

Somehow it's all Sony's fault? Anything can be hacked. This week, it was Sony, next week it could be anyone else. I can assure you that a lot of people still use md5, something that is now easily broken. It doesn't even matter.


Oh well, the burden *should* fall on Sony, but in no way is it completely their fault.

(also, funny how people use this to justify their choice to buy an Xbox 360 - the console that has had so many hardware failures - with this thread.)
Aerakin
Profile Joined January 2011
185 Posts
Last Edited: 2011-04-28 16:22:36
April 28 2011 16:22 GMT
#308
On April 28 2011 23:54 CyberPitz wrote:
Well, my personal info, but what do I care, they could google search that info.


this.



EDIT: damn... new post instead of editing =(
Crying
Profile Joined February 2011
Bulgaria778 Posts
April 28 2011 16:47 GMT
#309
Hmm,this can be a lesson to all of us to make a different credit card for internet games.Fill it with money just about to buy the things/pay subscriptions.Never set up your main credit card in a website
Determination~ Hard Work Surpass NATURAL GENIUS!
Danjoh
Profile Joined October 2010
Sweden405 Posts
April 28 2011 17:05 GMT
#310
On April 29 2011 01:21 Aerakin wrote:
Wow, some of you people are just... stupid.

Credit Card table was encrypted and the other data doesn't even matter much (I assume passwords were also encrypted)

Somehow it's all Sony's fault? Anything can be hacked. This week, it was Sony, next week it could be anyone else. I can assure you that a lot of people still use md5, something that is now easily broken. It doesn't even matter.


Oh well, the burden *should* fall on Sony, but in no way is it completely their fault.

(also, funny how people use this to justify their choice to buy an Xbox 360 - the console that has had so many hardware failures - with this thread.)

Sony is critizised for the minimum effort they put into security. Credit card info was preatty much the only thing they had encrypted, passwords etc was stored as plain text. And that is going by what Sony says. Sony has been doing some shady things like collecting unrelated data whitout consent and installing rootkits on PCs to spy (with the excuse "it's anti-piracy!").

+ Show Spoiler +
<user2> all connected devices return values sent to sony server
<user2> example:
<user3> user2: Debug models of course
<user2> ><info category="76">32&apos;&apos; TFT-TV</info><info category="77">OEM</info><info category="88">release</info><info category="89">cex</info>


<user2> for example:
<user2> creditCard.paymentMethodId=VISA&creditCard.holderName=Max&creditCard.cardNumber=4558254723658741&creditCard.expireYear=2012&creditCard.expireMonth=2&creditCard.securityCode=214&creditCard.address.address1=example street%2024%20&creditCard.address.city=city1%20&creditCard.address.province=abc%20&creditCard.address.postalCode=12345%20
<user2> sent as plaintext
...
<user2> normally you ATLEAST enccrypt the securtity code, even if its ssl
<user5> id hope sony would do such in a safe manner
<user5> psn cards probably plain text to then
<user2> fake certs are known since years as vuln so companies encrypt such data twice normally
<user2> but hey its sony --> its a feature

<user2> i know a few guys who worked @ sony's psn backend. just when
the ps3 was released we talked bout the first psn, at this time ALL was
http and unencrypted. so you could see userpass etc plain. i asked em
why is it that way. lame answer was "we thought it was adressed." - lol


http://pastie.org/private/erihhjd2ccvj0lkmzbtuw
RoosterSamurai
Profile Blog Joined March 2010
Japan2108 Posts
April 28 2011 17:12 GMT
#311
So now that all of our information is out there, I guess there's no way to get it back. So, what, do we all just get screwed? We have to go and change our credit cards because Sony put virtually no effort into their security? Someone break it down for me, because I'm pretty mad...
Takuah
Profile Blog Joined August 2010
United States76 Posts
April 28 2011 17:15 GMT
#312
How could a giant company leave that sensitive information in plaintext? Weak.
Fates
Profile Joined June 2010
United States91 Posts
Last Edited: 2011-04-28 17:18:46
April 28 2011 17:17 GMT
#313
doublepost >.<
Fates
Profile Joined June 2010
United States91 Posts
Last Edited: 2011-04-28 17:18:09
April 28 2011 17:17 GMT
#314
On April 29 2011 02:12 RoosterSamurai wrote:
So now that all of our information is out there, I guess there's no way to get it back. So, what, do we all just get screwed? We have to go and change our credit cards because Sony put virtually no effort into their security? Someone break it down for me, because I'm pretty mad...


If you wanna really be safe I would.

I was one of those lazy people who has the same password for everything, so I literally changed at least 20 passwords that were important. I never knew about keepass until this all happened, so having 25 digit passwords is cool.

Like Sony said, they aren't sure if the credit card info was taken, but I chose to not risk it and got a new card ordered.

If you remember your PSN password and it's the same as any other password you use, it's very highly recommended that you change those.

I'm kinda upset too, but I was just fortunate that none of my funds had been touched, or my e-mail hadn't been hacked into yet. So I don't have much to be furious about.
Enki
Profile Blog Joined January 2007
United States2548 Posts
April 28 2011 17:24 GMT
#315
So far so good, nothings been touched of mine. I did go ahead and order a new debit card though, I am not taking Sony's word that the card numbers didn't go out, and then possibly get screwed weeks/months from now.
"Practice, practice, practice. And when you're not practicing you should be practicing. It's the only way to get better. The only way." I run the Smix Fanclub!
Kyrth
Profile Joined July 2010
United States101 Posts
April 28 2011 17:30 GMT
#316
"The personal data table, which is a separate data set, was not encrypted"

This really pisses me off. A lot. What the hell, Sony? I mean, it just boggles my mind.
RoosterSamurai
Profile Blog Joined March 2010
Japan2108 Posts
April 28 2011 18:12 GMT
#317
On April 29 2011 02:17 Fates wrote:
Show nested quote +
On April 29 2011 02:12 RoosterSamurai wrote:
So now that all of our information is out there, I guess there's no way to get it back. So, what, do we all just get screwed? We have to go and change our credit cards because Sony put virtually no effort into their security? Someone break it down for me, because I'm pretty mad...


If you wanna really be safe I would.

I was one of those lazy people who has the same password for everything, so I literally changed at least 20 passwords that were important. I never knew about keepass until this all happened, so having 25 digit passwords is cool.

Like Sony said, they aren't sure if the credit card info was taken, but I chose to not risk it and got a new card ordered.

If you remember your PSN password and it's the same as any other password you use, it's very highly recommended that you change those.

I'm kinda upset too, but I was just fortunate that none of my funds had been touched, or my e-mail hadn't been hacked into yet. So I don't have much to be furious about.

Well, I don't really remember my PSN password, as I haven't been online in over 6 months (YLOD)...But I could probably guess it if I had to. I guess I'll need to be ordering a new debit card, too. x.x My faith in Sony has been shaken to the core. I used to debate to the death how far superior Sony was to Microsoft. And now I don't even want to think about it.
Dalguno
Profile Blog Joined January 2011
United States2446 Posts
April 28 2011 18:24 GMT
#318

PlayStation(R)Network

===================================

Valued PlayStation(R)Network/Qriocity Customer:

We have discovered that between April 17 and April 19, 2011,
certain PlayStation Network and Qriocity service user account
information was compromised in connection with an illegal and
unauthorized intrusion into our network. In response to this
intrusion, we have:

1) Temporarily turned off PlayStation Network and Qriocity services;

2) Engaged an outside, recognized security firm to conduct a full
and complete investigation into what happened; and

3) Quickly taken steps to enhance security and strengthen our
network infrastructure by rebuilding our system to provide you
with greater protection of your personal information.

We greatly appreciate your patience, understanding and goodwill
as we do whatever it takes to resolve these issues as quickly and
efficiently as practicable.

Although we are still investigating the details of this incident,
we believe that an unauthorized person has obtained the following
information that you provided: name, address (city, state, zip), country,
email address, birthdate, PlayStation Network/Qriocity password and login,
and handle/PSN online ID. It is also possible that your profile data,
including purchase history and billing address (city, state, zip),
and your PlayStation Network/Qriocity password security answers may
have been obtained. If you have authorized a sub-account for your
dependent, the same data with respect to your dependent may have
been obtained. While there is no evidence at this time that credit
card data was taken, we cannot rule out the possibility. If you have
provided your credit card data through PlayStation Network or Qriocity,
out of an abundance of caution we are advising you that your credit
card number (excluding security code) and expiration date may have
been obtained.

For your security, we encourage you to be especially aware of email,
telephone and postal mail scams that ask for personal or sensitive
information. Sony will not contact you in any way, including by email,
asking for your credit card number, social security number or other
personally identifiable information. If you are asked for this information,
you can be confident Sony is not the entity asking. When the PlayStation
Network and Qriocity services are fully restored, we strongly recommend that
you log on and change your password. Additionally, if you use your PlayStation
Network or Qriocity user name or password for other unrelated services or
accounts, we strongly recommend that you change them as well.

To protect against possible identity theft or other financial loss, we
encourage you to remain vigilant, to review your account statements and
to monitor your credit reports. We are providing the following information
for those who wish to consider it:
- U.S. residents are entitled under U.S. law to one free credit report annually
from each of the three major credit bureaus. To order your free credit report,
visit www.annualcreditreport.com or call toll-free (877) 322-8228 .

- We have also provided names and contact information for the three major U.S.
credit bureaus below. At no charge, U.S. residents can have these credit bureaus
place a "fraud alert" on your file that alerts creditors to take additional steps
to verify your identity prior to granting credit in your name. This service can
make it more difficult for someone to get credit in your name. Note, however,
that because it tells creditors to follow certain procedures to protect you,
it also may delay your ability to obtain credit while the agency verifies your
identity. As soon as one credit bureau confirms your fraud alert, the others
are notified to place fraud alerts on your file. Should you wish to place a
fraud alert, or should you have any questions regarding your credit report,
please contact any one of the agencies listed below:

Experian: 888-397-3742 ; www.experian.com; P.O. Box 9532, Allen, TX 75013
Equifax: 800-525-6285 ; www.equifax.com; P.O. Box 740241, Atlanta, GA 30374-0241
TransUnion: 800-680-7289 ; www.transunion.com; Fraud Victim Assistance Division,
P.O. Box 6790, Fullerton, CA 92834-6790

- You may wish to visit the website of the U.S. Federal Trade Commission at
www.consumer.gov/idtheft or reach the FTC at 1-877-382-4357 or 600 Pennsylvania
Avenue, NW, Washington, DC 20580 for further information about how to protect
yourself from identity theft. Your state Attorney General may also have advice
on preventing identity theft, and you should report instances of known or
suspected identity theft to law enforcement, your State Attorney General,
and the FTC. For North Carolina residents, the Attorney General can be
contacted at 9001 Mail Service Center, Raleigh, NC 27699-9001; telephone
(877) 566-7226 ; or www.ncdoj.gov. For Maryland residents, the Attorney
General can be contacted at 200 St. Paul Place, 16th Floor, Baltimore, MD 21202;
telephone: (888) 743-0023 ; or www.oag.state.md.us.

We thank you for your patience as we complete our investigation of this
incident, and we regret any inconvenience. Our teams are working around the
clock on this, and services will be restored as soon as possible. Sony takes
information protection very seriously and will continue to work to ensure that
additional measures are taken to protect personally identifiable information.
Providing quality and secure entertainment services to our customers is
our utmost priority. Please contact us at 1-800-345-7669 should you have any
additional questions.

Sincerely,

Sony Computer Entertainment and Sony Network Entertainment


Email received from Sony.
"I'm gonna keep making drones cause I'm a baller, and ballers make drones." -Snute
Xeofreestyler
Profile Blog Joined June 2005
Belgium6773 Posts
April 28 2011 18:56 GMT
#319
I am so glad that I got a nintendo 64 instead of a playstation when I was a kid right now
Graphics
furymonkey
Profile Joined December 2008
New Zealand1587 Posts
April 28 2011 19:12 GMT
#320
On April 29 2011 01:21 Aerakin wrote:
Wow, some of you people are just... stupid.

Credit Card table was encrypted and the other data doesn't even matter much (I assume passwords were also encrypted)

Somehow it's all Sony's fault? Anything can be hacked. This week, it was Sony, next week it could be anyone else. I can assure you that a lot of people still use md5, something that is now easily broken. It doesn't even matter.


Oh well, the burden *should* fall on Sony, but in no way is it completely their fault.

(also, funny how people use this to justify their choice to buy an Xbox 360 - the console that has had so many hardware failures - with this thread.)


Blaming Sony for their incompetence does not meant it's all Sony's fault. What else do you expect people to say after their information is stolen? "Good job Sony, at least our virginity is safe"?

This is one of the largest data security breach in history, and it doesn't happen every week, so behave all fanboy like doesn't help anyone.
Leenock the Punisher
Prev 1 14 15 16 17 18 21 Next All
Please log in or register to reply.
Live Events Refresh
Wardi Open
12:00
#60
WardiTV2372
IndyStarCraft 189
Rex81
Liquipedia
[ Submit Event ]
Live Streams
Refresh
StarCraft 2
mouzHeroMarine 350
IndyStarCraft 173
Rex 81
StarCraft: Brood War
Rain 4194
Horang2 1899
firebathero 247
Shuttle 198
Mong 44
scan(afreeca) 39
Rock 38
sSak 31
Terrorterran 27
Aegong 24
[ Show more ]
JulyZerg 19
SilentControl 7
ivOry 6
Noble 3
Dota 2
Gorgc5857
qojqva3810
Dendi927
420jenkins286
syndereN264
XcaliburYe223
BananaSlamJamma106
Counter-Strike
byalli419
oskar117
Other Games
Mlord668
hiko638
ceh9536
KnowMe440
Hui .368
crisheroes296
Lowko277
Fuzer 268
Sick187
Liquid`VortiX147
ArmadaUGS70
Mew2King61
QueenE43
Trikslyr39
Organizations
StarCraft 2
Blizzard YouTube
StarCraft: Brood War
BSLTrovo
sctven
[ Show 16 non-featured ]
StarCraft 2
• intothetv
• AfreecaTV YouTube
• Kozan
• IndyKCrew
• LaughNgamezSOOP
• Migwel
• sooper7s
StarCraft: Brood War
• blackmanpl 57
• Michael_bg 6
• HerbMon 2
• BSLYoutube
• STPLYoutube
• ZZZeroYoutube
League of Legends
• Nemesis3614
• TFBlade757
Other Games
• Shiphtur110
Upcoming Events
Replay Cast
6h 11m
WardiTV Korean Royale
19h 11m
OSC
1d
Replay Cast
1d 6h
Replay Cast
1d 16h
Kung Fu Cup
1d 19h
Classic vs Solar
herO vs Cure
Reynor vs GuMiho
ByuN vs ShoWTimE
Tenacious Turtle Tussle
2 days
The PondCast
2 days
RSL Revival
2 days
Solar vs Zoun
MaxPax vs Bunny
Kung Fu Cup
2 days
[ Show More ]
WardiTV Korean Royale
2 days
PiGosaur Monday
3 days
RSL Revival
3 days
Classic vs Creator
Cure vs TriGGeR
Kung Fu Cup
3 days
CranKy Ducklings
4 days
RSL Revival
4 days
herO vs Gerald
ByuN vs SHIN
Kung Fu Cup
4 days
BSL 21
5 days
Tarson vs Julia
Doodle vs OldBoy
eOnzErG vs WolFix
StRyKeR vs Aeternum
Sparkling Tuna Cup
5 days
RSL Revival
5 days
Reynor vs sOs
Maru vs Ryung
Kung Fu Cup
5 days
WardiTV Korean Royale
5 days
BSL 21
6 days
JDConan vs Semih
Dragon vs Dienmax
Tech vs NewOcean
TerrOr vs Artosis
Wardi Open
6 days
Liquipedia Results

Completed

Proleague 2025-11-07
Stellar Fest: Constellation Cup
Eternal Conflict S1

Ongoing

C-Race Season 1
IPSL Winter 2025-26
KCM Race Survival 2025 Season 4
SOOP Univ League 2025
YSL S2
BSL Season 21
IEM Chengdu 2025
PGL Masters Bucharest 2025
Thunderpick World Champ.
CS Asia Championships 2025
ESL Pro League S22
StarSeries Fall 2025
FISSURE Playground #2
BLAST Open Fall 2025
BLAST Open Fall Qual

Upcoming

SLON Tour Season 2
BSL 21 Non-Korean Championship
Acropolis #4
IPSL Spring 2026
HSC XXVIII
RSL Offline Finals
WardiTV 2025
RSL Revival: Season 3
META Madness #9
BLAST Bounty Winter 2026
BLAST Bounty Winter 2026: Closed Qualifier
eXTREMESLAND 2025
ESL Impact League Season 8
SL Budapest Major 2025
BLAST Rivals Fall 2025
TLPD

1. ByuN
2. TY
3. Dark
4. Solar
5. Stats
6. Nerchio
7. sOs
8. soO
9. INnoVation
10. Elazer
1. Rain
2. Flash
3. EffOrt
4. Last
5. Bisu
6. Soulkey
7. Mini
8. Sharp
Sidebar Settings...

Advertising | Privacy Policy | Terms Of Use | Contact Us

Original banner artwork: Jim Warren
The contents of this webpage are copyright © 2025 TLnet. All Rights Reserved.