Sony: PSN credit card details were encrypted

 

Passwords still a gold mine, says former black hat.

Sony has claimed that the credit details of its PlayStation Network customers were encrypted, a key fact it omitted in its initial disclosure about being hacked. 

“The entire credit card table was encrypted and we have no evidence that credit card data was taken,” Patrick Seybold, Sony’s senior director of corporate communications said in a blog post Wednesday

He added that CVV2 data, the three digit code to verify an online purchaser has the card being used in an online transaction, was not stolen. 

While encryption did not cancel the risk of fraud posed to as many as 77 million PlayStation Network customers, it reduced it, and should have been revealed during the first admission, according to Graham Cluley, senior technology consultant at security vendor Sophos.

“Sony has once again missed an opportunity to reassure its customers,” he wrote.

“They should have said in the first announcement of the data loss that the credit card data was encrypted, and they should - in this latest communication - have provided details of the nature of the encryption that was used.”

Still, identity theft and secondary hacking of PlayStation Network users’ other accounts remained a risk. 

Seybold pointed out that the “personal data table”, which included names, passwords, birth dates, buying history, and billing addresses were not encrypted. 

“For your security, we encourage you to be especially aware of email, telephone, and postal mail scams that ask for personal or sensitive information,” Seybold wrote. 

Sony also revealed that besides rebuilding its server infrastructure -- one of the reasons it gave last week for shutting down its network -- it had already begun moving network infrastructure to a “more secure” data centre.

“We are initiating several measures that will significantly enhance all aspects of PlayStation Network’s security and your personal data, including moving our network infrastructure and data center to a new, more secure location, which is already underway,” according to Seybold. 

Sony was also working on a new firmware update, which “will require all users to change their password once PlayStation Network is restored", expected to occur within a week.  

The company promised to find the culprits behind the alleged hack “no matter where in the world they might be located”. 

The most likely place to find those responsible would be somewhere in or near Russia, according to former black hat hacker and Wired security editor Kevin Poulson, who ruled out other usual suspects such as hacking collective Anonymous, Chinese hackers and recreational hackers. 

Poulson ruled the “For-Profit Cybertheif”, largely concentrated in Ukraine and Russia, as “probably guilty”. 

“These guys ... know databases like the backs of their hands — they dream in SQL.”

“Credit cards without the mag[netic] stripe data or CVV2 are among the least valuable commodities. But combined with the other data, the database is valuable indeed,” he wrote in a blog post on Thursday

“The passwords (which Sony evidently didn’t bother to hash)  could be a gold mine, because people have a tendency to use the same password everywhere; you can bet a big chunk of those 77 million PlayStation Network passwords will unlock everything from Facebook accounts to online banking.”

Copyright © iTnews.com.au . All rights reserved.


Sony: PSN credit card details were encrypted
"Okay, so the data is encrypted. How? Where? With What? Saying its encrypted is great, but the specifics would lead to some surety. I for one wouldn't come out claiming encryption if all i was ..."
By Daveh
 
 
 
Comments: 1
Daveh
Apr 29, 2011 9:35 AM
Okay, so the data is encrypted. How? Where? With What?
Saying its encrypted is great, but the specifics would lead to some surety. I for one wouldn't come out claiming encryption if all i was using was a Cesar's shift.

What if its only encrypted database storage with the database not requiring root password authentication? No need for decryption there, just open the DB and copy the plain-text result.

Sony was correct not to come out with this at the outset, especially if the encryption is on the database's file storage and they cant guarantee the table was opened legitimately and contents copied OR if Sony were using a weak or broken encryption algorithm OR if the encryption key was held in a flat file on one of the servers hacked.

Oh and as an additional hurt, the numbers in question are credit card numbers, which all already comply to a fixed standard of generation - this provides a more accurate vector for a known plain-text attack, doubly so if the hackers can pair the an encrypted card number with the plaintext version.
Comments have been disabled for this article.
 
 
 
Top Stories
Australian miners send drones to work
In-depth: Unmanned aerial vehicles in the resources sector.
 
The New Zealand telco problem
Opinion: Could Telstra save Kiwi telcos?
 
IT price probe to 'name and shame' gougers
Industry ducking the issue, committee claims.
 
Sign up to receive iTnews email bulletins
   FOLLOW US...

Latest VideosSee all videos »

Latest Comments
Polls
Should the Government enact new legislation to protect copyright holders in the digital age?

   |   View results
Yes
  19%
 
No
  81%
TOTAL VOTES: 510

Vote