Thursday, April 28, 2011

Sony PlayStation netWork hacKing eXplained

SONY now says that PlayStation user credit card info was encrypted (at some level) - but they continue to suggest that the relevant tables may have been accessed.
The personal data table, which is a separate data set, was not encrypted, but was, of course, behind a very sophisticated security system that was breached in a malicious attack.
Very sophisticated indeed.

SONY has posted this FAQ. It includes this paternalistic gem:
For your security, we encourage you to be especially aware of email, telephone, and postal mail scams that ask for personal or sensitive information
Mind you, SONY did not take much care with that user personal information.  "We will not give out your information."  We will not do much to protect it, either.

No comments: