Feeds

PlayStation Network credit cards protected by encryption

User passwords? Not so much

Boost IT visibility and business value

All credit card information stored on Sony's PlayStation Network was encrypted, the company said one day after warning users their user names, passwords, birth dates and home addresses were stolen in a security breach.

“The entire credit card table was encrypted and we have no evidence that credit card data was taken,” Sony representatives wrote in the update, which was posted late on Wednesday. “The personal data table, which is a separate data set, was not encrypted, but was, of course, behind a very sophisticated security system that was breached in a malicious attack.”

The update clarifies statements Sony made on Tuesday that the stolen information may have included payment-card data, purchase history, billing addresses, and security answers used to change passwords. It didn't provide details about the encryption used to protect card data, but assuming it followed standard industry practices, it was likely enough to prevent the information from being used by the hackers behind the break in.

Wednesday's update follows multiple news reports that recounted PSN users who reported credit card fraud that seemed to coincide with the breach.

Noticeably absent from Sony's update was the status of passwords used to log in to the PlayStation Network. Industry practices dictate they should never be stored in clear text, but rather should be run through a one-way cryptographic hash algorithm, which converts each string in plaintext to a unique set of characters that can never be reversed.

As we've learned from last year's mammoth website hack at Gawker and numerous other security breaches, users frequently employ the same credentials for numerous accounts, making all of them vulnerable when a single one is compromised. Sony's update strongly urged PlayStation Network users who use the same account name and password for unrelated services to change them.

The update said that Sony has sent the majority of its 77 million users an email informing them of the breach and the steps they should take to protect themselves in its aftermath. The company also said it is working to track down the perpetrators.

“We are currently conducting a thorough investigation of the situation and are working closely with a recognized technology security firm and law enforcement in order to find those responsible for this criminal act no matter where in the world they might be located,” Sony representatives wrote.

They said they expect some online PlayStation services to resume this Tuesday. The network has been inaccessible since April 20, when Sony took it offline. ®

The essential guide to IT transformation

More from The Register

next story
Top Gun display for your CAR: Heads-up fighter pilot tech
Sadly Navdy kit doesn't include Sidewinder missile to blast traffic
FEAST YOUR EYES: Samsung's Galaxy Alpha has an 'entirely new appearance'
Wow, it looks like nothing else on the market, for sure
iPhone 6 flip tip slips in Aussie's clip: Apple's 'reversible USB' leaks
New plug not compatible with official Type-C, according to fresh rumors
TV transport tech, part 1: From server to sofa at the touch of a button
You won't believe how much goes into today's telly tech
YES YES YES! Apple patents mousy, pressure-sensing iVibrator
Fanbois prepare to experience the great Cupertin-O
Apple takes blade to 13-inch MacBook Pro with Retina display
Shaves price, not screen on mid-2014 model
NVIDIA claims first 64-bit ARMv8 SoC for Androids
Mile-High 'Denver' Tegra K1 successor said to rival PC performance
XBOX One will learn to play media from USB and DLNA sources
Hang on? Aren't those file formats you hardly ever see outside torrents?
prev story

Whitepapers

Endpoint data privacy in the cloud is easier than you think
Innovations in encryption and storage resolve issues of data privacy and key requirements for companies to look for in a solution.
Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Top 8 considerations to enable and simplify mobility
In this whitepaper learn how to successfully add mobile capabilities simply and cost effectively.
Solving today's distributed Big Data backup challenges
Enable IT efficiency and allow a firm to access and reuse corporate information for competitive advantage, ultimately changing business outcomes.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.