• Log InLog In
  • Register
Liquid`
Team Liquid Liquipedia
EDT 17:49
CEST 23:49
KST 06:49
  • Home
  • Forum
  • Calendar
  • Streams
  • Liquipedia
  • Features
  • Store
  • EPT
  • TL+
  • StarCraft 2
  • Brood War
  • Smash
  • Heroes
  • Counter-Strike
  • Overwatch
  • Liquibet
  • Fantasy StarCraft
  • TLPD
  • StarCraft 2
  • Brood War
  • Blogs
Forum Sidebar
Events/Features
News
Featured News
Serral wins EWC 202532Tournament Spotlight: FEL Cracow 202510Power Rank - Esports World Cup 202580RSL Season 1 - Final Week9[ASL19] Finals Recap: Standing Tall15
Community News
[BSL 2025] H2 - Team Wars, Weeklies & SB Ladder8EWC 2025 - Replay Pack4Google Play ASL (Season 20) Announced40BSL Team Wars - Bonyth, Dewalt, Hawk & Sziky teams10Weekly Cups (July 14-20): Final Check-up0
StarCraft 2
General
The GOAT ranking of GOAT rankings Tournament Spotlight: FEL Cracow 2025 Classic: "It's a thick wall to break through to become world champ" Firefly given lifetime ban by ESIC following match-fixing investigation Serral wins EWC 2025
Tourneys
Sparkling Tuna Cup - Weekly Open Tournament Sea Duckling Open (Global, Bronze-Diamond) TaeJa vs Creator Bo7 SC Evo Showmatch FEL Cracov 2025 (July 27) - $10,000 live event Esports World Cup 2025
Strategy
How did i lose this ZvP, whats the proper response
Custom Maps
External Content
Mutation # 484 Magnetic Pull Mutation #239 Bad Weather Mutation # 483 Kill Bot Wars Mutation # 482 Wheel of Misfortune
Brood War
General
2025 Season 2 Ladder map pool Which top zerg/toss will fail in qualifiers? Google Play ASL (Season 20) Announced Flash Announces (and Retracts) Hiatus From ASL BGH Auto Balance -> http://bghmmr.eu/
Tourneys
[ASL20] Online Qualifiers Day 1 [Megathread] Daily Proleagues Small VOD Thread 2.0 [BSL] Non-Korean Championship - Final weekend
Strategy
Does 1 second matter in StarCraft? Simple Questions, Simple Answers Muta micro map competition [G] Mineral Boosting
Other Games
General Games
Stormgate/Frost Giant Megathread Nintendo Switch Thread Beyond All Reason Total Annihilation Server - TAForever [MMORPG] Tree of Savior (Successor of Ragnarok)
Dota 2
Official 'what is Dota anymore' discussion
League of Legends
Heroes of the Storm
Simple Questions, Simple Answers Heroes of the Storm 2.0
Hearthstone
Heroes of StarCraft mini-set
TL Mafia
Vanilla Mini Mafia TL Mafia Community Thread
Community
General
US Politics Mega-thread European Politico-economics QA Mega-thread Things Aren’t Peaceful in Palestine Canadian Politics Mega-thread Stop Killing Games - European Citizens Initiative
Fan Clubs
INnoVation Fan Club SKT1 Classic Fan Club!
Media & Entertainment
Anime Discussion Thread [\m/] Heavy Metal Thread Movie Discussion! [Manga] One Piece Korean Music Discussion
Sports
2024 - 2025 Football Thread Formula 1 Discussion TeamLiquid Health and Fitness Initiative For 2023 NBA General Discussion
World Cup 2022
Tech Support
Gtx660 graphics card replacement Installation of Windows 10 suck at "just a moment" Computer Build, Upgrade & Buying Resource Thread
TL Community
TeamLiquid Team Shirt On Sale The Automated Ban List
Blogs
The Link Between Fitness and…
TrAiDoS
momentary artworks from des…
tankgirl
from making sc maps to makin…
Husyelt
StarCraft improvement
iopq
Socialism Anyone?
GreenHorizons
Eight Anniversary as a TL…
Mizenhauer
Customize Sidebar...

Website Feedback

Closed Threads



Active: 554 users

Private PSN and SOE Info Has Been Stolen including CC #s -…

Forum Index > General Forum
Post a Reply
Prev 1 14 15 16 17 18 21 Next All
Johnny Business
Profile Joined August 2010
Sweden1251 Posts
April 28 2011 13:09 GMT
#301
On April 28 2011 12:07 brijan wrote:
How is it possible to do anything with the CC details if they don't have a CVC number? Random guessing?


There are places where you can buy stuff without the ccv.

Also it shouldn't matter if the creditcard numbers where hashed since they are kinda easy to brute force. (0-9, 16 characters and on some cards the first 4 are identical.)
Serious Business
Tschis
Profile Joined November 2010
Brazil1511 Posts
April 28 2011 13:57 GMT
#302
Yeah, because brute forcing hundreds of possibilities won´t call any Banks attention?
"A coward is not someone that runs from a battle knowing he will lose. A coward is someone who challenges a weak knowing he will win."
Scribble
Profile Blog Joined March 2011
2077 Posts
April 28 2011 14:19 GMT
#303
This is honestly a minor pain in the ass at best. It's alarming that Sony stored shit the way they did, but if someone is capable of getting this far, one extra step to get to our personal info isn't going to stop them. In any case, all this means is that we should replace our CCs/Debits and be done with it.
Mista_Masta
Profile Joined January 2009
Netherlands557 Posts
April 28 2011 14:39 GMT
#304
Wow, this news is huge. I'm so glad I don't have a PS3, but I feel very sorry for everyone who does, and also a bit for Sony - although they are idiots for letting this happen in the first place.
CyberPitz
Profile Blog Joined June 2009
United States428 Posts
Last Edited: 2011-04-28 14:55:18
April 28 2011 14:54 GMT
#305
According to a Q&A from Sony, they did encrypt their CC data.
http://blog.us.playstation.com/2011/04/27/qa-1-for-playstation-network-and-qriocity-services/

Was my personal data encrypted?
A: All of the data was protected, and access was restricted both physically and through the perimeter and security of the network. The entire credit card table was encrypted and we have no evidence that credit card data was taken. The personal data table, which is a separate data set, was not encrypted, but was, of course, behind a very sophisticated security system that was breached in a malicious attack.


I went and got my card cancelled and reordered just in case (Now to find a way to buy things...), but I hardly blame Sony for this. It's not like they handed the info to the hackers on a platter. Well, my personal info, but what do I care, they could google search that info.
Zhou
Profile Joined February 2009
United States832 Posts
April 28 2011 14:55 GMT
#306
I wonder if this conflicts with things like Netflix in terms of privacy issues. Just to be the safe side, I had my parents check their accounts just in case as well.

Man, I don't even want to check my own at this rate that this is going downhill...

I'm even more afraid to know what happens when they do figure out all this stuff and how much backlash there is going to be.
Aerakin
Profile Joined January 2011
185 Posts
April 28 2011 16:21 GMT
#307
Wow, some of you people are just... stupid.

Credit Card table was encrypted and the other data doesn't even matter much (I assume passwords were also encrypted)

Somehow it's all Sony's fault? Anything can be hacked. This week, it was Sony, next week it could be anyone else. I can assure you that a lot of people still use md5, something that is now easily broken. It doesn't even matter.


Oh well, the burden *should* fall on Sony, but in no way is it completely their fault.

(also, funny how people use this to justify their choice to buy an Xbox 360 - the console that has had so many hardware failures - with this thread.)
Aerakin
Profile Joined January 2011
185 Posts
Last Edited: 2011-04-28 16:22:36
April 28 2011 16:22 GMT
#308
On April 28 2011 23:54 CyberPitz wrote:
Well, my personal info, but what do I care, they could google search that info.


this.



EDIT: damn... new post instead of editing =(
Crying
Profile Joined February 2011
Bulgaria778 Posts
April 28 2011 16:47 GMT
#309
Hmm,this can be a lesson to all of us to make a different credit card for internet games.Fill it with money just about to buy the things/pay subscriptions.Never set up your main credit card in a website
Determination~ Hard Work Surpass NATURAL GENIUS!
Danjoh
Profile Joined October 2010
Sweden405 Posts
April 28 2011 17:05 GMT
#310
On April 29 2011 01:21 Aerakin wrote:
Wow, some of you people are just... stupid.

Credit Card table was encrypted and the other data doesn't even matter much (I assume passwords were also encrypted)

Somehow it's all Sony's fault? Anything can be hacked. This week, it was Sony, next week it could be anyone else. I can assure you that a lot of people still use md5, something that is now easily broken. It doesn't even matter.


Oh well, the burden *should* fall on Sony, but in no way is it completely their fault.

(also, funny how people use this to justify their choice to buy an Xbox 360 - the console that has had so many hardware failures - with this thread.)

Sony is critizised for the minimum effort they put into security. Credit card info was preatty much the only thing they had encrypted, passwords etc was stored as plain text. And that is going by what Sony says. Sony has been doing some shady things like collecting unrelated data whitout consent and installing rootkits on PCs to spy (with the excuse "it's anti-piracy!").

+ Show Spoiler +
<user2> all connected devices return values sent to sony server
<user2> example:
<user3> user2: Debug models of course
<user2> ><info category="76">32&apos;&apos; TFT-TV</info><info category="77">OEM</info><info category="88">release</info><info category="89">cex</info>


<user2> for example:
<user2> creditCard.paymentMethodId=VISA&creditCard.holderName=Max&creditCard.cardNumber=4558254723658741&creditCard.expireYear=2012&creditCard.expireMonth=2&creditCard.securityCode=214&creditCard.address.address1=example street%2024%20&creditCard.address.city=city1%20&creditCard.address.province=abc%20&creditCard.address.postalCode=12345%20
<user2> sent as plaintext
...
<user2> normally you ATLEAST enccrypt the securtity code, even if its ssl
<user5> id hope sony would do such in a safe manner
<user5> psn cards probably plain text to then
<user2> fake certs are known since years as vuln so companies encrypt such data twice normally
<user2> but hey its sony --> its a feature

<user2> i know a few guys who worked @ sony's psn backend. just when
the ps3 was released we talked bout the first psn, at this time ALL was
http and unencrypted. so you could see userpass etc plain. i asked em
why is it that way. lame answer was "we thought it was adressed." - lol


http://pastie.org/private/erihhjd2ccvj0lkmzbtuw
RoosterSamurai
Profile Blog Joined March 2010
Japan2108 Posts
April 28 2011 17:12 GMT
#311
So now that all of our information is out there, I guess there's no way to get it back. So, what, do we all just get screwed? We have to go and change our credit cards because Sony put virtually no effort into their security? Someone break it down for me, because I'm pretty mad...
Takuah
Profile Blog Joined August 2010
United States76 Posts
April 28 2011 17:15 GMT
#312
How could a giant company leave that sensitive information in plaintext? Weak.
Fates
Profile Joined June 2010
United States91 Posts
Last Edited: 2011-04-28 17:18:46
April 28 2011 17:17 GMT
#313
doublepost >.<
Fates
Profile Joined June 2010
United States91 Posts
Last Edited: 2011-04-28 17:18:09
April 28 2011 17:17 GMT
#314
On April 29 2011 02:12 RoosterSamurai wrote:
So now that all of our information is out there, I guess there's no way to get it back. So, what, do we all just get screwed? We have to go and change our credit cards because Sony put virtually no effort into their security? Someone break it down for me, because I'm pretty mad...


If you wanna really be safe I would.

I was one of those lazy people who has the same password for everything, so I literally changed at least 20 passwords that were important. I never knew about keepass until this all happened, so having 25 digit passwords is cool.

Like Sony said, they aren't sure if the credit card info was taken, but I chose to not risk it and got a new card ordered.

If you remember your PSN password and it's the same as any other password you use, it's very highly recommended that you change those.

I'm kinda upset too, but I was just fortunate that none of my funds had been touched, or my e-mail hadn't been hacked into yet. So I don't have much to be furious about.
Enki
Profile Blog Joined January 2007
United States2548 Posts
April 28 2011 17:24 GMT
#315
So far so good, nothings been touched of mine. I did go ahead and order a new debit card though, I am not taking Sony's word that the card numbers didn't go out, and then possibly get screwed weeks/months from now.
"Practice, practice, practice. And when you're not practicing you should be practicing. It's the only way to get better. The only way." I run the Smix Fanclub!
Kyrth
Profile Joined July 2010
United States101 Posts
April 28 2011 17:30 GMT
#316
"The personal data table, which is a separate data set, was not encrypted"

This really pisses me off. A lot. What the hell, Sony? I mean, it just boggles my mind.
RoosterSamurai
Profile Blog Joined March 2010
Japan2108 Posts
April 28 2011 18:12 GMT
#317
On April 29 2011 02:17 Fates wrote:
Show nested quote +
On April 29 2011 02:12 RoosterSamurai wrote:
So now that all of our information is out there, I guess there's no way to get it back. So, what, do we all just get screwed? We have to go and change our credit cards because Sony put virtually no effort into their security? Someone break it down for me, because I'm pretty mad...


If you wanna really be safe I would.

I was one of those lazy people who has the same password for everything, so I literally changed at least 20 passwords that were important. I never knew about keepass until this all happened, so having 25 digit passwords is cool.

Like Sony said, they aren't sure if the credit card info was taken, but I chose to not risk it and got a new card ordered.

If you remember your PSN password and it's the same as any other password you use, it's very highly recommended that you change those.

I'm kinda upset too, but I was just fortunate that none of my funds had been touched, or my e-mail hadn't been hacked into yet. So I don't have much to be furious about.

Well, I don't really remember my PSN password, as I haven't been online in over 6 months (YLOD)...But I could probably guess it if I had to. I guess I'll need to be ordering a new debit card, too. x.x My faith in Sony has been shaken to the core. I used to debate to the death how far superior Sony was to Microsoft. And now I don't even want to think about it.
Dalguno
Profile Blog Joined January 2011
United States2446 Posts
April 28 2011 18:24 GMT
#318

PlayStation(R)Network

===================================

Valued PlayStation(R)Network/Qriocity Customer:

We have discovered that between April 17 and April 19, 2011,
certain PlayStation Network and Qriocity service user account
information was compromised in connection with an illegal and
unauthorized intrusion into our network. In response to this
intrusion, we have:

1) Temporarily turned off PlayStation Network and Qriocity services;

2) Engaged an outside, recognized security firm to conduct a full
and complete investigation into what happened; and

3) Quickly taken steps to enhance security and strengthen our
network infrastructure by rebuilding our system to provide you
with greater protection of your personal information.

We greatly appreciate your patience, understanding and goodwill
as we do whatever it takes to resolve these issues as quickly and
efficiently as practicable.

Although we are still investigating the details of this incident,
we believe that an unauthorized person has obtained the following
information that you provided: name, address (city, state, zip), country,
email address, birthdate, PlayStation Network/Qriocity password and login,
and handle/PSN online ID. It is also possible that your profile data,
including purchase history and billing address (city, state, zip),
and your PlayStation Network/Qriocity password security answers may
have been obtained. If you have authorized a sub-account for your
dependent, the same data with respect to your dependent may have
been obtained. While there is no evidence at this time that credit
card data was taken, we cannot rule out the possibility. If you have
provided your credit card data through PlayStation Network or Qriocity,
out of an abundance of caution we are advising you that your credit
card number (excluding security code) and expiration date may have
been obtained.

For your security, we encourage you to be especially aware of email,
telephone and postal mail scams that ask for personal or sensitive
information. Sony will not contact you in any way, including by email,
asking for your credit card number, social security number or other
personally identifiable information. If you are asked for this information,
you can be confident Sony is not the entity asking. When the PlayStation
Network and Qriocity services are fully restored, we strongly recommend that
you log on and change your password. Additionally, if you use your PlayStation
Network or Qriocity user name or password for other unrelated services or
accounts, we strongly recommend that you change them as well.

To protect against possible identity theft or other financial loss, we
encourage you to remain vigilant, to review your account statements and
to monitor your credit reports. We are providing the following information
for those who wish to consider it:
- U.S. residents are entitled under U.S. law to one free credit report annually
from each of the three major credit bureaus. To order your free credit report,
visit www.annualcreditreport.com or call toll-free (877) 322-8228 .

- We have also provided names and contact information for the three major U.S.
credit bureaus below. At no charge, U.S. residents can have these credit bureaus
place a "fraud alert" on your file that alerts creditors to take additional steps
to verify your identity prior to granting credit in your name. This service can
make it more difficult for someone to get credit in your name. Note, however,
that because it tells creditors to follow certain procedures to protect you,
it also may delay your ability to obtain credit while the agency verifies your
identity. As soon as one credit bureau confirms your fraud alert, the others
are notified to place fraud alerts on your file. Should you wish to place a
fraud alert, or should you have any questions regarding your credit report,
please contact any one of the agencies listed below:

Experian: 888-397-3742 ; www.experian.com; P.O. Box 9532, Allen, TX 75013
Equifax: 800-525-6285 ; www.equifax.com; P.O. Box 740241, Atlanta, GA 30374-0241
TransUnion: 800-680-7289 ; www.transunion.com; Fraud Victim Assistance Division,
P.O. Box 6790, Fullerton, CA 92834-6790

- You may wish to visit the website of the U.S. Federal Trade Commission at
www.consumer.gov/idtheft or reach the FTC at 1-877-382-4357 or 600 Pennsylvania
Avenue, NW, Washington, DC 20580 for further information about how to protect
yourself from identity theft. Your state Attorney General may also have advice
on preventing identity theft, and you should report instances of known or
suspected identity theft to law enforcement, your State Attorney General,
and the FTC. For North Carolina residents, the Attorney General can be
contacted at 9001 Mail Service Center, Raleigh, NC 27699-9001; telephone
(877) 566-7226 ; or www.ncdoj.gov. For Maryland residents, the Attorney
General can be contacted at 200 St. Paul Place, 16th Floor, Baltimore, MD 21202;
telephone: (888) 743-0023 ; or www.oag.state.md.us.

We thank you for your patience as we complete our investigation of this
incident, and we regret any inconvenience. Our teams are working around the
clock on this, and services will be restored as soon as possible. Sony takes
information protection very seriously and will continue to work to ensure that
additional measures are taken to protect personally identifiable information.
Providing quality and secure entertainment services to our customers is
our utmost priority. Please contact us at 1-800-345-7669 should you have any
additional questions.

Sincerely,

Sony Computer Entertainment and Sony Network Entertainment


Email received from Sony.
"I'm gonna keep making drones cause I'm a baller, and ballers make drones." -Snute
Xeofreestyler
Profile Blog Joined June 2005
Belgium6771 Posts
April 28 2011 18:56 GMT
#319
I am so glad that I got a nintendo 64 instead of a playstation when I was a kid right now
Graphics
furymonkey
Profile Joined December 2008
New Zealand1587 Posts
April 28 2011 19:12 GMT
#320
On April 29 2011 01:21 Aerakin wrote:
Wow, some of you people are just... stupid.

Credit Card table was encrypted and the other data doesn't even matter much (I assume passwords were also encrypted)

Somehow it's all Sony's fault? Anything can be hacked. This week, it was Sony, next week it could be anyone else. I can assure you that a lot of people still use md5, something that is now easily broken. It doesn't even matter.


Oh well, the burden *should* fall on Sony, but in no way is it completely their fault.

(also, funny how people use this to justify their choice to buy an Xbox 360 - the console that has had so many hardware failures - with this thread.)


Blaming Sony for their incompetence does not meant it's all Sony's fault. What else do you expect people to say after their information is stolen? "Good job Sony, at least our virginity is safe"?

This is one of the largest data security breach in history, and it doesn't happen every week, so behave all fanboy like doesn't help anyone.
Leenock the Punisher
Prev 1 14 15 16 17 18 21 Next All
Please log in or register to reply.
Live Events Refresh
BSL
19:00
Team Wars - Round 1
Dewalt vs Hawk
ZZZero.O96
LiquipediaDiscussion
[ Submit Event ]
Live Streams
Refresh
StarCraft 2
UpATreeSC 188
JuggernautJason112
StarCraft: Brood War
Britney 18144
ggaemo 311
firebathero 214
ZZZero.O 90
Aegong 38
Dota 2
syndereN497
monkeys_forever253
capcasts119
NeuroSwarm74
League of Legends
Grubby4677
Counter-Strike
Stewie2K780
flusha514
Heroes of the Storm
Liquid`Hasu605
Other Games
tarik_tv12084
gofns9253
fl0m1733
C9.Mang0116
ZombieGrub39
Sick37
PPMD24
ROOTCatZ9
Organizations
StarCraft 2
angryscii 20
Blizzard YouTube
StarCraft: Brood War
BSLTrovo
sctven
[ Show 25 non-featured ]
StarCraft 2
• kabyraGe 223
• davetesta64
• StrangeGG 64
• sitaska32
• LUISG 20
• Reevou 6
• RyuSc2 1
• Kozan
• LaughNgamezSOOP
• IndyKCrew
• intothetv
• AfreecaTV YouTube
• sooper7s
• Migwel
StarCraft: Brood War
• blackmanpl 32
• HerbMon 27
• Azhi_Dahaki14
• STPLYoutube
• ZZZeroYoutube
• BSLYoutube
Dota 2
• masondota22125
• WagamamaTV632
League of Legends
• TFBlade729
Other Games
• imaqtpie1430
• Shiphtur179
Upcoming Events
Korean StarCraft League
5h 11m
CranKy Ducklings
12h 11m
BSL20 Non-Korean Champi…
14h 11m
Mihu vs QiaoGege
Zhanhun vs Dewalt
Fengzi vs TBD
WardiTV European League
18h 11m
ShoWTimE vs Harstem
Shameless vs MaxPax
HeRoMaRinE vs SKillous
ByuN vs TBD
Sparkling Tuna Cup
1d 12h
BSL20 Non-Korean Champi…
1d 16h
Bonyth vs TBD
WardiTV European League
1d 18h
Wardi Open
2 days
OSC
3 days
uThermal 2v2 Circuit
4 days
[ Show More ]
The PondCast
5 days
uThermal 2v2 Circuit
6 days
Liquipedia Results

Completed

BSL 20 Non-Korean Championship
FEL Cracow 2025
Underdog Cup #2

Ongoing

Copa Latinoamericana 4
Jiahua Invitational
BSL 20 Team Wars
KCM Race Survival 2025 Season 3
BSL 21 Qualifiers
CC Div. A S7
IEM Cologne 2025
FISSURE Playground #1
BLAST.tv Austin Major 2025
ESL Impact League Season 7
IEM Dallas 2025

Upcoming

ASL Season 20: Qualifier #1
ASL Season 20: Qualifier #2
ASL Season 20
CSLPRO Chat StarLAN 3
BSL Season 21
RSL Revival: Season 2
Maestros of the Game
SEL Season 2 Championship
WardiTV Summer 2025
uThermal 2v2 Main Event
HCC Europe
CAC 2025
Roobet Cup 2025
ESL Pro League S22
StarSeries Fall 2025
FISSURE Playground #2
BLAST Open Fall 2025
BLAST Open Fall Qual
Esports World Cup 2025
BLAST Bounty Fall 2025
BLAST Bounty Fall Qual
TLPD

1. ByuN
2. TY
3. Dark
4. Solar
5. Stats
6. Nerchio
7. sOs
8. soO
9. INnoVation
10. Elazer
1. Rain
2. Flash
3. EffOrt
4. Last
5. Bisu
6. Soulkey
7. Mini
8. Sharp
Sidebar Settings...

Advertising | Privacy Policy | Terms Of Use | Contact Us

Original banner artwork: Jim Warren
The contents of this webpage are copyright © 2025 TLnet. All Rights Reserved.