The Register® — Biting the hand that feeds IT

Feeds

PlayStation Network credit cards protected by encryption

User passwords? Not so much

Agentless Backup is Not a Myth

All credit card information stored on Sony's PlayStation Network was encrypted, the company said one day after warning users their user names, passwords, birth dates and home addresses were stolen in a security breach.

“The entire credit card table was encrypted and we have no evidence that credit card data was taken,” Sony representatives wrote in the update, which was posted late on Wednesday. “The personal data table, which is a separate data set, was not encrypted, but was, of course, behind a very sophisticated security system that was breached in a malicious attack.”

The update clarifies statements Sony made on Tuesday that the stolen information may have included payment-card data, purchase history, billing addresses, and security answers used to change passwords. It didn't provide details about the encryption used to protect card data, but assuming it followed standard industry practices, it was likely enough to prevent the information from being used by the hackers behind the break in.

Wednesday's update follows multiple news reports that recounted PSN users who reported credit card fraud that seemed to coincide with the breach.

Noticeably absent from Sony's update was the status of passwords used to log in to the PlayStation Network. Industry practices dictate they should never be stored in clear text, but rather should be run through a one-way cryptographic hash algorithm, which converts each string in plaintext to a unique set of characters that can never be reversed.

As we've learned from last year's mammoth website hack at Gawker and numerous other security breaches, users frequently employ the same credentials for numerous accounts, making all of them vulnerable when a single one is compromised. Sony's update strongly urged PlayStation Network users who use the same account name and password for unrelated services to change them.

The update said that Sony has sent the majority of its 77 million users an email informing them of the breach and the steps they should take to protect themselves in its aftermath. The company also said it is working to track down the perpetrators.

“We are currently conducting a thorough investigation of the situation and are working closely with a recognized technology security firm and law enforcement in order to find those responsible for this criminal act no matter where in the world they might be located,” Sony representatives wrote.

They said they expect some online PlayStation services to resume this Tuesday. The network has been inaccessible since April 20, when Sony took it offline. ®

Customer Success Testimonial: Recovery is Everything

Anonymous Coward

Sorry, Sony...

...but I still don't believe you.

12
2

ROT13 isn't very secure

That's why I always do it twice on any data I want to encrypt!

9
0

Hmm

Sony never emailed me. I call bullshit on them emailing the majority of their 77 million users.

8
0

More from The Register

Samsung Galaxy Note 8: Proof the pen is mightier?
Sammy’s iPad Mini killer has a stylus to stab other rivals too
Microsoft lures buy-curious vixens, corduroys with a cheap fondle
Surface slab sales latest: Will no one rid Ballmer of these turbulent tabs?
First look: iOS 7 for iPad
No, Apple hasn't released it yet, but that doesn't stop intrepid devs
 breaking news
Curtain drops on Apple Store ahead of WWDC: What lies behind?
Steve Jobs watching from on high. No pressure, lads
 breaking news
Cold, dead hands of Steve Jobs slip from iPhones: The Cult of Ive is upon us
Billionaire biz baron's death clears way for uber-shiny iOS 7
Airbus imagines suitcases that find themselves
Point your mobe at your smalls to track their every move
Surprise! Intel smartphone trounces ARM in power trials
Tests show equal performance while sipping significantly less juice
Samsung plans LTE Advanced version of Galaxy S4
1Gbps download capability could stiffen drooping S4 sales forecasts
Apple said to be 'exploring' 5.7-inch iPhone
Who's the copycat this time, Mr. Cook?
Google Chromebooks now in over 6,600 stores
Major, worldwide retail push begins this summer