iTnews
  • Home
  • News
  • Technology
  • Networking

Sony: PSN credit card details were encrypted

By Liam Tung
Apr 29 2011 5:54AM
Follow google news

Passwords still a gold mine, says former black hat.

Sony has claimed that the credit details of its PlayStation Network customers were encrypted, a key fact it omitted in its initial disclosure about being hacked. 

Sony: PSN credit card details were encrypted

“The entire credit card table was encrypted and we have no evidence that credit card data was taken,” Patrick Seybold, Sony’s senior director of corporate communications said in a blog post Wednesday. 

He added that CVV2 data, the three digit code to verify an online purchaser has the card being used in an online transaction, was not stolen. 

While encryption did not cancel the risk of fraud posed to as many as 77 million PlayStation Network customers, it reduced it, and should have been revealed during the first admission, according to Graham Cluley, senior technology consultant at security vendor Sophos.

“Sony has once again missed an opportunity to reassure its customers,” he wrote.

“They should have said in the first announcement of the data loss that the credit card data was encrypted, and they should - in this latest communication - have provided details of the nature of the encryption that was used.”

Still, identity theft and secondary hacking of PlayStation Network users’ other accounts remained a risk. 

Seybold pointed out that the “personal data table”, which included names, passwords, birth dates, buying history, and billing addresses were not encrypted. 

“For your security, we encourage you to be especially aware of email, telephone, and postal mail scams that ask for personal or sensitive information,” Seybold wrote. 

Sony also revealed that besides rebuilding its server infrastructure -- one of the reasons it gave last week for shutting down its network -- it had already begun moving network infrastructure to a “more secure” data centre.

“We are initiating several measures that will significantly enhance all aspects of PlayStation Network’s security and your personal data, including moving our network infrastructure and data center to a new, more secure location, which is already underway,” according to Seybold. 

Sony was also working on a new firmware update, which “will require all users to change their password once PlayStation Network is restored", expected to occur within a week.  

The company promised to find the culprits behind the alleged hack “no matter where in the world they might be located”. 

The most likely place to find those responsible would be somewhere in or near Russia, according to former black hat hacker and Wired security editor Kevin Poulson, who ruled out other usual suspects such as hacking collective Anonymous, Chinese hackers and recreational hackers. 

Poulson ruled the “For-Profit Cybertheif”, largely concentrated in Ukraine and Russia, as “probably guilty”. 

“These guys ... know databases like the backs of their hands — they dream in SQL.”

“Credit cards without the mag[netic] stripe data or CVV2 are among the least valuable commodities. But combined with the other data, the database is valuable indeed,” he wrote in a blog post on Thursday. 

“The passwords (which Sony evidently didn’t bother to hash)  could be a gold mine, because people have a tendency to use the same password everywhere; you can bet a big chunk of those 77 million PlayStation Network passwords will unlock everything from Facebook accounts to online banking.”

Add iTnews as your trusted source

Add iTnews As Your Trusted Source Add iTnews As Your Trusted Source
Got a news tip for our journalists? Share it with us anonymously here.
Copyright © iTnews.com.au . All rights reserved.
Tags:
breachcardscreditencryptionhacknetworkingplaystationsecuritysony

Related Articles

  • Anthropic pulls Mythos-class models globally Anthropic pulls Mythos-class models globally
  • AudiA6 crypto launderers arrested, network taken down by police AudiA6 crypto launderers arrested, network taken down by police
  • US charges suspected Russian hacker with facilitating cyber campaign US charges suspected Russian hacker with facilitating cyber campaign
  • Gov looks for upstream threat blocking by telcos, cloud operators Gov looks for upstream threat blocking by telcos, cloud operators
Join our WhatsApp Channel

Partner Content

Scalable AI solutions: secure delivery
Scalable AI solutions: secure delivery
AI is delivering business value today
Partner Content AI is delivering business value today
Thomas Peer Solutions unveils data cloud platform and executive leadership forum for 2026
Partner Content Thomas Peer Solutions unveils data cloud platform and executive leadership forum for 2026
Agile isn’t the problem: why projects still fail, and what’s missing
Partner Content Agile isn’t the problem: why projects still fail, and what’s missing

Sponsored Whitepapers

Are Australian organisations as cyber-ready as they think?
Are Australian organisations as cyber-ready as they think?
Are New Zealand organisations as cyber-ready as they think?
Are New Zealand organisations as cyber-ready as they think?
From visibility to execution:  Fixing the SaaS management gap
From visibility to execution: Fixing the SaaS management gap
When cyber risk has no clear owner: A practical guide for senior Australian business leaders
When cyber risk has no clear owner: A practical guide for senior Australian business leaders
Agile in the AI Era: why projects still fail
Agile in the AI Era: why projects still fail

Events

  • iTnews State of Security Breakfast iTnews State of Security Breakfast
  • iTnews State of Data & AI Breakfast iTnews State of Data & AI Breakfast
  • Forrester's AI Forum Sydney Forrester's AI Forum Sydney
  • The 2026 iAwards The 2026 iAwards
  • Integrate 2026 Integrate 2026
Share on Facebook Share on LinkedIn Share on Whatsapp Email A Friend

Most Read Articles

Kmart Group to expand RFID tagging to more products and to Target

Kmart Group to expand RFID tagging to more products and to Target

Federal Parliamentary Computer Network set for its "most significant" upgrade

Federal Parliamentary Computer Network set for its "most significant" upgrade

WA man jailed for at least five years for evil twin attack

WA man jailed for at least five years for evil twin attack

Optus fast-tracks network operations insourcing from Nokia

Optus fast-tracks network operations insourcing from Nokia

techpartner.news logo
Sydney-based AI-cloud waste startup raises $3m
Sydney-based AI-cloud waste startup raises $3m
Brennan uses NiCE to modernise its contact centre
Brennan uses NiCE to modernise its contact centre
Impact Awards: Tecala slashes customer response times for fintech IQumulate
Impact Awards: Tecala slashes customer response times for fintech IQumulate
Interactive introduces private cloud platform
Interactive introduces private cloud platform
Digital61 expands cybersecurity portfolio
Digital61 expands cybersecurity portfolio
All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website constitutes acceptance of nextmedia's Privacy Policy and Terms & Conditions.