• Log InLog In
  • Register
Liquid`
Team Liquid Liquipedia
EDT 15:35
CEST 21:35
KST 04:35
  • Home
  • Forum
  • Calendar
  • Streams
  • Liquipedia
  • Features
  • Store
  • EPT
  • TL+
  • StarCraft 2
  • Brood War
  • Smash
  • Heroes
  • Counter-Strike
  • Overwatch
  • Liquibet
  • Fantasy StarCraft
  • TLPD
  • StarCraft 2
  • Brood War
  • Blogs
Forum Sidebar
Events/Features
News
Featured News
Power Rank - Esports World Cup 202529RSL Season 1 - Final Week8[ASL19] Finals Recap: Standing Tall15HomeStory Cup 27 - Info & Preview18Classic wins Code S Season 2 (2025)16
Community News
Weekly Cups (July 14-20): Final Check-up0Esports World Cup 2025 - Brackets Revealed19Weekly Cups (July 7-13): Classic continues to roll8Team TLMC #5 - Submission re-extension4Firefly given lifetime ban by ESIC following match-fixing investigation17
StarCraft 2
General
The GOAT ranking of GOAT rankings Power Rank - Esports World Cup 2025 RSL Revival patreon money discussion thread Esports World Cup 2025 - Final Player Roster Why doesnt SC2 scene costream tournaments
Tourneys
Esports World Cup 2025 Sparkling Tuna Cup - Weekly Open Tournament Sea Duckling Open (Global, Bronze-Diamond) FEL Cracov 2025 (July 27) - $8000 live event RSL: Revival, a new crowdfunded tournament series
Strategy
How did i lose this ZvP, whats the proper response
Custom Maps
External Content
Mutation # 483 Kill Bot Wars Mutation # 482 Wheel of Misfortune Mutation # 481 Fear and Lava Mutation # 480 Moths to the Flame
Brood War
General
BW General Discussion Flash Announces (and Retracts) Hiatus From ASL BGH Auto Balance -> http://bghmmr.eu/ Corsair Pursuit Micro? Pro gamer house photos
Tourneys
[Megathread] Daily Proleagues [BSL 2v2] ProLeague Season 3 - Friday 21:00 CET The Casual Games of the Week Thread BWCL Season 63 Announcement
Strategy
Simple Questions, Simple Answers I am doing this better than progamers do.
Other Games
General Games
Nintendo Switch Thread Stormgate/Frost Giant Megathread [MMORPG] Tree of Savior (Successor of Ragnarok) Path of Exile CCLP - Command & Conquer League Project
Dota 2
Official 'what is Dota anymore' discussion
League of Legends
Heroes of the Storm
Simple Questions, Simple Answers Heroes of the Storm 2.0
Hearthstone
Heroes of StarCraft mini-set
TL Mafia
TL Mafia Community Thread Vanilla Mini Mafia
Community
General
US Politics Mega-thread Things Aren’t Peaceful in Palestine Russo-Ukrainian War Thread The Games Industry And ATVI Stop Killing Games - European Citizens Initiative
Fan Clubs
SKT1 Classic Fan Club! Maru Fan Club
Media & Entertainment
[\m/] Heavy Metal Thread Anime Discussion Thread Movie Discussion! [Manga] One Piece Korean Music Discussion
Sports
2024 - 2025 Football Thread Formula 1 Discussion TeamLiquid Health and Fitness Initiative For 2023 NBA General Discussion
World Cup 2022
Tech Support
Computer Build, Upgrade & Buying Resource Thread
TL Community
The Automated Ban List
Blogs
Ping To Win? Pings And Their…
TrAiDoS
momentary artworks from des…
tankgirl
from making sc maps to makin…
Husyelt
StarCraft improvement
iopq
Socialism Anyone?
GreenHorizons
Customize Sidebar...

Website Feedback

Closed Threads



Active: 796 users

Private PSN and SOE Info Has Been Stolen including CC #s -…

Forum Index > General Forum
Post a Reply
Prev 1 14 15 16 17 18 21 Next All
Johnny Business
Profile Joined August 2010
Sweden1251 Posts
April 28 2011 13:09 GMT
#301
On April 28 2011 12:07 brijan wrote:
How is it possible to do anything with the CC details if they don't have a CVC number? Random guessing?


There are places where you can buy stuff without the ccv.

Also it shouldn't matter if the creditcard numbers where hashed since they are kinda easy to brute force. (0-9, 16 characters and on some cards the first 4 are identical.)
Serious Business
Tschis
Profile Joined November 2010
Brazil1511 Posts
April 28 2011 13:57 GMT
#302
Yeah, because brute forcing hundreds of possibilities won´t call any Banks attention?
"A coward is not someone that runs from a battle knowing he will lose. A coward is someone who challenges a weak knowing he will win."
Scribble
Profile Blog Joined March 2011
2077 Posts
April 28 2011 14:19 GMT
#303
This is honestly a minor pain in the ass at best. It's alarming that Sony stored shit the way they did, but if someone is capable of getting this far, one extra step to get to our personal info isn't going to stop them. In any case, all this means is that we should replace our CCs/Debits and be done with it.
Mista_Masta
Profile Joined January 2009
Netherlands557 Posts
April 28 2011 14:39 GMT
#304
Wow, this news is huge. I'm so glad I don't have a PS3, but I feel very sorry for everyone who does, and also a bit for Sony - although they are idiots for letting this happen in the first place.
CyberPitz
Profile Blog Joined June 2009
United States428 Posts
Last Edited: 2011-04-28 14:55:18
April 28 2011 14:54 GMT
#305
According to a Q&A from Sony, they did encrypt their CC data.
http://blog.us.playstation.com/2011/04/27/qa-1-for-playstation-network-and-qriocity-services/

Was my personal data encrypted?
A: All of the data was protected, and access was restricted both physically and through the perimeter and security of the network. The entire credit card table was encrypted and we have no evidence that credit card data was taken. The personal data table, which is a separate data set, was not encrypted, but was, of course, behind a very sophisticated security system that was breached in a malicious attack.


I went and got my card cancelled and reordered just in case (Now to find a way to buy things...), but I hardly blame Sony for this. It's not like they handed the info to the hackers on a platter. Well, my personal info, but what do I care, they could google search that info.
Zhou
Profile Joined February 2009
United States832 Posts
April 28 2011 14:55 GMT
#306
I wonder if this conflicts with things like Netflix in terms of privacy issues. Just to be the safe side, I had my parents check their accounts just in case as well.

Man, I don't even want to check my own at this rate that this is going downhill...

I'm even more afraid to know what happens when they do figure out all this stuff and how much backlash there is going to be.
Aerakin
Profile Joined January 2011
185 Posts
April 28 2011 16:21 GMT
#307
Wow, some of you people are just... stupid.

Credit Card table was encrypted and the other data doesn't even matter much (I assume passwords were also encrypted)

Somehow it's all Sony's fault? Anything can be hacked. This week, it was Sony, next week it could be anyone else. I can assure you that a lot of people still use md5, something that is now easily broken. It doesn't even matter.


Oh well, the burden *should* fall on Sony, but in no way is it completely their fault.

(also, funny how people use this to justify their choice to buy an Xbox 360 - the console that has had so many hardware failures - with this thread.)
Aerakin
Profile Joined January 2011
185 Posts
Last Edited: 2011-04-28 16:22:36
April 28 2011 16:22 GMT
#308
On April 28 2011 23:54 CyberPitz wrote:
Well, my personal info, but what do I care, they could google search that info.


this.



EDIT: damn... new post instead of editing =(
Crying
Profile Joined February 2011
Bulgaria778 Posts
April 28 2011 16:47 GMT
#309
Hmm,this can be a lesson to all of us to make a different credit card for internet games.Fill it with money just about to buy the things/pay subscriptions.Never set up your main credit card in a website
Determination~ Hard Work Surpass NATURAL GENIUS!
Danjoh
Profile Joined October 2010
Sweden405 Posts
April 28 2011 17:05 GMT
#310
On April 29 2011 01:21 Aerakin wrote:
Wow, some of you people are just... stupid.

Credit Card table was encrypted and the other data doesn't even matter much (I assume passwords were also encrypted)

Somehow it's all Sony's fault? Anything can be hacked. This week, it was Sony, next week it could be anyone else. I can assure you that a lot of people still use md5, something that is now easily broken. It doesn't even matter.


Oh well, the burden *should* fall on Sony, but in no way is it completely their fault.

(also, funny how people use this to justify their choice to buy an Xbox 360 - the console that has had so many hardware failures - with this thread.)

Sony is critizised for the minimum effort they put into security. Credit card info was preatty much the only thing they had encrypted, passwords etc was stored as plain text. And that is going by what Sony says. Sony has been doing some shady things like collecting unrelated data whitout consent and installing rootkits on PCs to spy (with the excuse "it's anti-piracy!").

+ Show Spoiler +
<user2> all connected devices return values sent to sony server
<user2> example:
<user3> user2: Debug models of course
<user2> ><info category="76">32&apos;&apos; TFT-TV</info><info category="77">OEM</info><info category="88">release</info><info category="89">cex</info>


<user2> for example:
<user2> creditCard.paymentMethodId=VISA&creditCard.holderName=Max&creditCard.cardNumber=4558254723658741&creditCard.expireYear=2012&creditCard.expireMonth=2&creditCard.securityCode=214&creditCard.address.address1=example street%2024%20&creditCard.address.city=city1%20&creditCard.address.province=abc%20&creditCard.address.postalCode=12345%20
<user2> sent as plaintext
...
<user2> normally you ATLEAST enccrypt the securtity code, even if its ssl
<user5> id hope sony would do such in a safe manner
<user5> psn cards probably plain text to then
<user2> fake certs are known since years as vuln so companies encrypt such data twice normally
<user2> but hey its sony --> its a feature

<user2> i know a few guys who worked @ sony's psn backend. just when
the ps3 was released we talked bout the first psn, at this time ALL was
http and unencrypted. so you could see userpass etc plain. i asked em
why is it that way. lame answer was "we thought it was adressed." - lol


http://pastie.org/private/erihhjd2ccvj0lkmzbtuw
RoosterSamurai
Profile Blog Joined March 2010
Japan2108 Posts
April 28 2011 17:12 GMT
#311
So now that all of our information is out there, I guess there's no way to get it back. So, what, do we all just get screwed? We have to go and change our credit cards because Sony put virtually no effort into their security? Someone break it down for me, because I'm pretty mad...
Takuah
Profile Blog Joined August 2010
United States76 Posts
April 28 2011 17:15 GMT
#312
How could a giant company leave that sensitive information in plaintext? Weak.
Fates
Profile Joined June 2010
United States91 Posts
Last Edited: 2011-04-28 17:18:46
April 28 2011 17:17 GMT
#313
doublepost >.<
Fates
Profile Joined June 2010
United States91 Posts
Last Edited: 2011-04-28 17:18:09
April 28 2011 17:17 GMT
#314
On April 29 2011 02:12 RoosterSamurai wrote:
So now that all of our information is out there, I guess there's no way to get it back. So, what, do we all just get screwed? We have to go and change our credit cards because Sony put virtually no effort into their security? Someone break it down for me, because I'm pretty mad...


If you wanna really be safe I would.

I was one of those lazy people who has the same password for everything, so I literally changed at least 20 passwords that were important. I never knew about keepass until this all happened, so having 25 digit passwords is cool.

Like Sony said, they aren't sure if the credit card info was taken, but I chose to not risk it and got a new card ordered.

If you remember your PSN password and it's the same as any other password you use, it's very highly recommended that you change those.

I'm kinda upset too, but I was just fortunate that none of my funds had been touched, or my e-mail hadn't been hacked into yet. So I don't have much to be furious about.
Enki
Profile Blog Joined January 2007
United States2548 Posts
April 28 2011 17:24 GMT
#315
So far so good, nothings been touched of mine. I did go ahead and order a new debit card though, I am not taking Sony's word that the card numbers didn't go out, and then possibly get screwed weeks/months from now.
"Practice, practice, practice. And when you're not practicing you should be practicing. It's the only way to get better. The only way." I run the Smix Fanclub!
Kyrth
Profile Joined July 2010
United States101 Posts
April 28 2011 17:30 GMT
#316
"The personal data table, which is a separate data set, was not encrypted"

This really pisses me off. A lot. What the hell, Sony? I mean, it just boggles my mind.
RoosterSamurai
Profile Blog Joined March 2010
Japan2108 Posts
April 28 2011 18:12 GMT
#317
On April 29 2011 02:17 Fates wrote:
Show nested quote +
On April 29 2011 02:12 RoosterSamurai wrote:
So now that all of our information is out there, I guess there's no way to get it back. So, what, do we all just get screwed? We have to go and change our credit cards because Sony put virtually no effort into their security? Someone break it down for me, because I'm pretty mad...


If you wanna really be safe I would.

I was one of those lazy people who has the same password for everything, so I literally changed at least 20 passwords that were important. I never knew about keepass until this all happened, so having 25 digit passwords is cool.

Like Sony said, they aren't sure if the credit card info was taken, but I chose to not risk it and got a new card ordered.

If you remember your PSN password and it's the same as any other password you use, it's very highly recommended that you change those.

I'm kinda upset too, but I was just fortunate that none of my funds had been touched, or my e-mail hadn't been hacked into yet. So I don't have much to be furious about.

Well, I don't really remember my PSN password, as I haven't been online in over 6 months (YLOD)...But I could probably guess it if I had to. I guess I'll need to be ordering a new debit card, too. x.x My faith in Sony has been shaken to the core. I used to debate to the death how far superior Sony was to Microsoft. And now I don't even want to think about it.
Dalguno
Profile Blog Joined January 2011
United States2446 Posts
April 28 2011 18:24 GMT
#318

PlayStation(R)Network

===================================

Valued PlayStation(R)Network/Qriocity Customer:

We have discovered that between April 17 and April 19, 2011,
certain PlayStation Network and Qriocity service user account
information was compromised in connection with an illegal and
unauthorized intrusion into our network. In response to this
intrusion, we have:

1) Temporarily turned off PlayStation Network and Qriocity services;

2) Engaged an outside, recognized security firm to conduct a full
and complete investigation into what happened; and

3) Quickly taken steps to enhance security and strengthen our
network infrastructure by rebuilding our system to provide you
with greater protection of your personal information.

We greatly appreciate your patience, understanding and goodwill
as we do whatever it takes to resolve these issues as quickly and
efficiently as practicable.

Although we are still investigating the details of this incident,
we believe that an unauthorized person has obtained the following
information that you provided: name, address (city, state, zip), country,
email address, birthdate, PlayStation Network/Qriocity password and login,
and handle/PSN online ID. It is also possible that your profile data,
including purchase history and billing address (city, state, zip),
and your PlayStation Network/Qriocity password security answers may
have been obtained. If you have authorized a sub-account for your
dependent, the same data with respect to your dependent may have
been obtained. While there is no evidence at this time that credit
card data was taken, we cannot rule out the possibility. If you have
provided your credit card data through PlayStation Network or Qriocity,
out of an abundance of caution we are advising you that your credit
card number (excluding security code) and expiration date may have
been obtained.

For your security, we encourage you to be especially aware of email,
telephone and postal mail scams that ask for personal or sensitive
information. Sony will not contact you in any way, including by email,
asking for your credit card number, social security number or other
personally identifiable information. If you are asked for this information,
you can be confident Sony is not the entity asking. When the PlayStation
Network and Qriocity services are fully restored, we strongly recommend that
you log on and change your password. Additionally, if you use your PlayStation
Network or Qriocity user name or password for other unrelated services or
accounts, we strongly recommend that you change them as well.

To protect against possible identity theft or other financial loss, we
encourage you to remain vigilant, to review your account statements and
to monitor your credit reports. We are providing the following information
for those who wish to consider it:
- U.S. residents are entitled under U.S. law to one free credit report annually
from each of the three major credit bureaus. To order your free credit report,
visit www.annualcreditreport.com or call toll-free (877) 322-8228 .

- We have also provided names and contact information for the three major U.S.
credit bureaus below. At no charge, U.S. residents can have these credit bureaus
place a "fraud alert" on your file that alerts creditors to take additional steps
to verify your identity prior to granting credit in your name. This service can
make it more difficult for someone to get credit in your name. Note, however,
that because it tells creditors to follow certain procedures to protect you,
it also may delay your ability to obtain credit while the agency verifies your
identity. As soon as one credit bureau confirms your fraud alert, the others
are notified to place fraud alerts on your file. Should you wish to place a
fraud alert, or should you have any questions regarding your credit report,
please contact any one of the agencies listed below:

Experian: 888-397-3742 ; www.experian.com; P.O. Box 9532, Allen, TX 75013
Equifax: 800-525-6285 ; www.equifax.com; P.O. Box 740241, Atlanta, GA 30374-0241
TransUnion: 800-680-7289 ; www.transunion.com; Fraud Victim Assistance Division,
P.O. Box 6790, Fullerton, CA 92834-6790

- You may wish to visit the website of the U.S. Federal Trade Commission at
www.consumer.gov/idtheft or reach the FTC at 1-877-382-4357 or 600 Pennsylvania
Avenue, NW, Washington, DC 20580 for further information about how to protect
yourself from identity theft. Your state Attorney General may also have advice
on preventing identity theft, and you should report instances of known or
suspected identity theft to law enforcement, your State Attorney General,
and the FTC. For North Carolina residents, the Attorney General can be
contacted at 9001 Mail Service Center, Raleigh, NC 27699-9001; telephone
(877) 566-7226 ; or www.ncdoj.gov. For Maryland residents, the Attorney
General can be contacted at 200 St. Paul Place, 16th Floor, Baltimore, MD 21202;
telephone: (888) 743-0023 ; or www.oag.state.md.us.

We thank you for your patience as we complete our investigation of this
incident, and we regret any inconvenience. Our teams are working around the
clock on this, and services will be restored as soon as possible. Sony takes
information protection very seriously and will continue to work to ensure that
additional measures are taken to protect personally identifiable information.
Providing quality and secure entertainment services to our customers is
our utmost priority. Please contact us at 1-800-345-7669 should you have any
additional questions.

Sincerely,

Sony Computer Entertainment and Sony Network Entertainment


Email received from Sony.
"I'm gonna keep making drones cause I'm a baller, and ballers make drones." -Snute
Xeofreestyler
Profile Blog Joined June 2005
Belgium6771 Posts
April 28 2011 18:56 GMT
#319
I am so glad that I got a nintendo 64 instead of a playstation when I was a kid right now
Graphics
furymonkey
Profile Joined December 2008
New Zealand1587 Posts
April 28 2011 19:12 GMT
#320
On April 29 2011 01:21 Aerakin wrote:
Wow, some of you people are just... stupid.

Credit Card table was encrypted and the other data doesn't even matter much (I assume passwords were also encrypted)

Somehow it's all Sony's fault? Anything can be hacked. This week, it was Sony, next week it could be anyone else. I can assure you that a lot of people still use md5, something that is now easily broken. It doesn't even matter.


Oh well, the burden *should* fall on Sony, but in no way is it completely their fault.

(also, funny how people use this to justify their choice to buy an Xbox 360 - the console that has had so many hardware failures - with this thread.)


Blaming Sony for their incompetence does not meant it's all Sony's fault. What else do you expect people to say after their information is stolen? "Good job Sony, at least our virginity is safe"?

This is one of the largest data security breach in history, and it doesn't happen every week, so behave all fanboy like doesn't help anyone.
Leenock the Punisher
Prev 1 14 15 16 17 18 21 Next All
Please log in or register to reply.
Live Events Refresh
Next event in 14h 25m
[ Submit Event ]
Live Streams
Refresh
StarCraft 2
ForJumy 54
MindelVK 53
StarCraft: Brood War
Barracks 686
Mini 523
Larva 503
Bonyth 78
Aegong 75
scan(afreeca) 28
NaDa 2
League of Legends
Grubby3320
Dendi1078
Counter-Strike
fl0m1856
Foxcn352
byalli349
Stewie2K322
oskar234
flusha146
Heroes of the Storm
Liquid`Hasu553
Khaldor321
Other Games
summit1g6351
FrodaN1934
ceh91111
Hui .255
C9.Mang0175
ToD157
Trikslyr56
Sick2
Organizations
StarCraft 2
Blizzard YouTube
StarCraft: Brood War
BSLTrovo
sctven
[ Show 23 non-featured ]
StarCraft 2
• davetesta127
• LUISG 33
• intothetv
• sooper7s
• Migwel
• AfreecaTV YouTube
• LaughNgamezSOOP
• IndyKCrew
• Kozan
StarCraft: Brood War
• 80smullet 19
• Michael_bg 6
• FirePhoenix2
• STPLYoutube
• ZZZeroYoutube
• BSLYoutube
Dota 2
• C_a_k_e 3324
• masondota21097
• WagamamaTV596
League of Legends
• Nemesis4519
• TFBlade1122
• Doublelift1040
Other Games
• imaqtpie1050
• Shiphtur525
Upcoming Events
Esports World Cup
14h 25m
ByuN vs Zoun
SHIN vs TriGGeR
Cyan vs ShoWTimE
Rogue vs HeRoMaRinE
Clem vs Solar
Reynor vs Maru
herO vs Cure
Serral vs Classic
Esports World Cup
1d 14h
Esports World Cup
2 days
CranKy Ducklings
3 days
BSL20 Non-Korean Champi…
3 days
CSO Cup
3 days
BSL20 Non-Korean Champi…
3 days
Bonyth vs Sziky
Dewalt vs Hawk
Hawk vs QiaoGege
Sziky vs Dewalt
Mihu vs Bonyth
Zhanhun vs QiaoGege
QiaoGege vs Fengzi
FEL
4 days
BSL20 Non-Korean Champi…
4 days
BSL20 Non-Korean Champi…
4 days
Bonyth vs Zhanhun
Dewalt vs Mihu
Hawk vs Sziky
Sziky vs QiaoGege
Mihu vs Hawk
Zhanhun vs Dewalt
Fengzi vs Bonyth
[ Show More ]
Sparkling Tuna Cup
6 days
Online Event
6 days
Liquipedia Results

Completed

CSL Xiamen Invitational
Championship of Russia 2025
Murky Cup #2

Ongoing

Copa Latinoamericana 4
Jiahua Invitational
BSL20 Non-Korean Championship
Esports World Cup 2025
CC Div. A S7
Underdog Cup #2
FISSURE Playground #1
BLAST.tv Austin Major 2025
ESL Impact League Season 7
IEM Dallas 2025
PGL Astana 2025
Asian Champions League '25

Upcoming

CSLPRO Last Chance 2025
CSLPRO Chat StarLAN 3
BSL Season 21
RSL Revival: Season 2
SEL Season 2 Championship
uThermal 2v2 Main Event
FEL Cracov 2025
HCC Europe
ESL Pro League S22
StarSeries Fall 2025
FISSURE Playground #2
BLAST Open Fall 2025
BLAST Open Fall Qual
Esports World Cup 2025
BLAST Bounty Fall 2025
BLAST Bounty Fall Qual
IEM Cologne 2025
TLPD

1. ByuN
2. TY
3. Dark
4. Solar
5. Stats
6. Nerchio
7. sOs
8. soO
9. INnoVation
10. Elazer
1. Rain
2. Flash
3. EffOrt
4. Last
5. Bisu
6. Soulkey
7. Mini
8. Sharp
Sidebar Settings...

Advertising | Privacy Policy | Terms Of Use | Contact Us

Original banner artwork: Jim Warren
The contents of this webpage are copyright © 2025 TLnet. All Rights Reserved.