[UPDATE] PSN Password Reset Vulnerable to Exploit

Recommended Videos

ace_of_something

New member
Sep 19, 2008
5,995
0
0
Glad my birthday isn't on my account, nor my name, or any of that stuff.
Pretty sure what's described is pretty typical tools for phishing.
 

snfonseka

New member
Oct 13, 2010
198
0
0
AstylahAthrys said:
...

Really? Can these guys just stop? Sony's been through enough already. That's coming from a PC/360 user, too.
Looks like someone didn't read the article before start commenting.
 

loogie

New member
Mar 2, 2011
44
0
0
gphjr14 said:
Glad I just did it on my PS3. Kind of sad these hackers have nothing better to do, at this point Sony should just give them Linux so they can show people just wanted to get free games not another OS. Then when PS4 comes out and doesn't do shit besides play games, people won't wonder why. "It only does games."
You are right, when they say "It only does games" people will expect that.. Just as when they say "it does other things" they should expect it to do other things, I don't recall them stating "It'll do other things, for awhile anyways... then we're going to stop allowing you to do that"
 

SaintWaldo

Interzone Vagabond
Jun 10, 2008
923
0
0
Just change the password through a console, not a website. It's really that simple. I feel the need to point out that ALMOST EVERY web login will reset your password with only the email addy, so this is a two-part key needed to even start the ploy. Not a very big threat profile AT ALL.
 

loogie

New member
Mar 2, 2011
44
0
0
Honestly what are you expecting... a company that has a billion customers had to completely redesign their entire security system in under a month isn't going to do so carefully, or critically, they are going to get things done as fast as possible, which will also mean they will most likely miss a few things...

I'm not surprized something as simple as this is happening, when you design a system, you get tunnel vision, thats why you get others to look at it and make sure it's been covered by all angles, when your rushing the release, you have less/no time to do so...
 

loogie

New member
Mar 2, 2011
44
0
0
eharriett said:
No, Sony isn't any different than a bunch of other sites. Both Microsoft & Apple's ID's aren't that hard if you just have a few simple pieces of info. This is an overarching problem that isn't going away with Sony making a few adjustments.
Difference is Microsoft and Apple don't hand over everyones personal information making such hacking so much easier... Sony JUST had a huge leak of personal info which is exactly the type of thing they can use to steal your accounts... Even if they call up support and are asked questions on every bit of personal information Sony has on you, they can get them all right... It's just careless to have such a flaw in your system knowing that such information was just leaked.
 

loogie

New member
Mar 2, 2011
44
0
0
SaintWaldo said:
Just change the password through a console, not a website. It's really that simple. I feel the need to point out that ALMOST EVERY web login will reset your password with only the email addy, so this is a two-part key needed to even start the ploy. Not a very big threat profile AT ALL.
You don't really understand do you?
THEY can change your password without your knowledge... so if you fail to change your account before they do, you have lost your account... The difference between this and every other password reset system is that most give you a temporary URL to "authenticate" the change, which is sent to your email address for you to confirm the change... thus if they don't have access to your email, nothing will happen... Sony's doesn't have such verification, and is thus vulnerable... Thats a pretty big hole.
 

Buccura

New member
Aug 13, 2009
813
0
0
As a precaution you should have a seperate email for any online account that would be a target anyway (such as game accounts, bank, insurance, etc)
 

Danzaivar

New member
Jul 13, 2004
1,967
0
0
AstylahAthrys said:
...

Really? Can these guys just stop? Sony's been through enough already. That's coming from a PC/360 user, too.
Yeah they really should have kept quiet for a few weeks and let some people with malice find this out instead. :p
 

kurokotetsu

Proud Master
Sep 17, 2008
428
0
0
Yeah, it may be similar in other sites. But that is no excuse. This is a security flaw and should that shouldn't be forgiven. Yes, Sony had a pretty rough month, but it is not the customers fault that there was vulnerabilities in the system. So Sony is not getting sympathy from me. It is their job to make sure that your information isn't leaked. They failed at it (with this, it can be said that it happened twice), so I'm not saying poor Sony. I'im saying do something about it.
 

Amondren

New member
Oct 15, 2009
826
0
0
Oh goody *clap clap* kick a man while he's down now thats nice. I miss being able to play LBP2 online its annoying that people wont give them a break.
 

mjc0961

YOU'RE a pie chart.
Nov 30, 2009
3,847
0
0
I thought the whole point of the "You have to get the e-mail and use the included link within 24 hours or it expires to change your password from the web" set-up was so that this exact scenario could NOT happen.

At least the people who found it reported it to Sony and Sony acted on the information as soon as possible. Now, whoever found this exploit might not actually be a hacker in the traditional definition, but this is the sort of thing good hackers do: find exploits and report them so that companies can fix them. This is why not all hackers should be shot or launched into the sun or whatever other stupid scenarios people have ranted about doing to hackers because of the person or people who hacked PSN.
 

Reed Spacer

That guy with the thing.
Jan 11, 2011
841
0
0
Now, if Sony hadn't taken away Other OS (and backwards compatibility for that matter (try to find a PS2 if yours craps out; g'wan, I dare you)), this probably wouldn't be happening.
 

erztez

New member
Oct 16, 2009
252
0
0
Amondren said:
Oh goody *clap clap* kick a man while he's down now thats nice. I miss being able to play LBP2 online its annoying that people wont give them a break.
Kicking a man? That's wrong.
Kicking a multi-billion dollar company that gave us such wondrous gifts as SecuROM and the BMG rootkit? That's FUN...
 

gphjr14

New member
Aug 20, 2010
868
0
0
loogie said:
You are right, when they say "It only does games" people will expect that.. Just as when they say "it does other things" they should expect it to do other things, I don't recall them stating "It'll do other things, for awhile anyways... then we're going to stop allowing you to do that"
Read the fine print of the user agreement. They were within their right to remove a featured that was used for piracy. Doesn't matter anyways they've figured it out now so they can't really prevent it.
 

kebab4you

New member
Jan 3, 2010
1,451
0
0
Reed Spacer said:
Now, if Sony hadn't taken away Other OS (and backwards compatibility for that matter (try to find a PS2 if yours craps out; g'wan, I dare you)), this probably wouldn't be happening.
Never say never, but most likely the firmware that started it all wouldn't be out today.
 

Martster

Rated EC-10 Condemned
Mar 17, 2010
119
0
0
Even though I don't own a PS3 myself I'm getting sick of this

Cant the hackers leave Sony alone and let gamers get back to what they love
 

Celinis

New member
Dec 22, 2010
25
0
0
All this hacking kinda makes me wonder what other companies are learning from this whole Sony situation. It would be very unwise for companies like Microsoft and Blizzard to not learn from all this.

Why do people do things like this, "just cause"... "2."

See this is why we can't have nice things on the internet.
 

loogie

New member
Mar 2, 2011
44
0
0
gphjr14 said:
loogie said:
You are right, when they say "It only does games" people will expect that.. Just as when they say "it does other things" they should expect it to do other things, I don't recall them stating "It'll do other things, for awhile anyways... then we're going to stop allowing you to do that"
Read the fine print of the user agreement. They were within their right to remove a featured that was used for piracy. Doesn't matter anyways they've figured it out now so they can't really prevent it.
this isn't a legal issue, they promoted their product to do things other then just games, then they removed that very concept, just because it's legal for them to do so, doesn't mean we shouldn't expect more.