1. Forums
  2. Discord
  3. About Mapcore
  4. Patreon Supporters
  • Login
  • Register
  • Search
This Thread
  • Everywhere
  • This Thread
  • This Forum
  • Articles
  • Pages
  • Forum
  • More Options
  1. Mapcore
  2. Discussions
  3. Off-Topic

PSN down

  • Izuno
  • April 25, 2011 at 11:09 PM
  • -HP-
    • May 2, 2011 at 10:34 AM
    • #41

    [Blocked Image: http://img.photobucket.com/albums/v247/DrForester/SonyIsntGoodWithComputers.gif]

  • sarge mat
    • May 2, 2011 at 3:15 PM
    • #42

    http://www.gamepro.com/article/news/219 ... nt=Twitter

    Looks like Sony Online has also been attacked and taken down.

  • Serenius
    • May 2, 2011 at 4:12 PM
    • #43

    Anyone else lose faith in humanity a little more after reading the story about gamers being more outraged at possibly losing their trophies than having their personal data stolen?

  • Sentura
    • May 2, 2011 at 6:34 PM
    • #44
    Quote from Serenius

    Anyone else lose faith in humanity a little more after reading the story about gamers being more outraged at possibly losing their trophies than having their personal data stolen?

    it kinda leads to the question, "are gamers people?"

  • BaRRaKID
    • May 2, 2011 at 7:34 PM
    • #45
    Quote from Jetsetlemming

    It is, in fact, possible to make a service strong enough to be reasonably secure from outside intrusions.

    PSN was reasonably protected, actually comparing to most online services it was really well protected since it could only be accessed trough a black box (the PS3) which had many hardware and software security blocks in place that where really hard to bypass. Of course they should had anticipated that the PS3 would eventually be hacked, but this doesn't seem like it was an ordinary attack, it was something more sophisticated, so it was kind of hard for their security team to predict it would happen.

    Also how many web services do you know that are "reasonably protected"? You talked about Valve but there's Non-Steam which bypasses the encryption and protection that Steam uses, and people cheat and hack steam games all the time (although to be fair not as much as in other games/plataforms). Not to mention Amazon, Facebook, Twitter, Google, and even Visa, they all had their own security problems/breaches in the past.

    Even if your application implements all of the security best practices, hackers can still get inside using social engineering, in fact most of the big security breaches we've seen lately are due to social engineering, so reasonably secure, its probably not secure enough these days.

    Images

    • seams.webp
      • 40.1 kB
      • 914 × 588
    • seams2.webp
      • 39.54 kB
      • 1,249 × 680
  • Jetsetlemming
    • May 2, 2011 at 8:05 PM
    • #46
    Quote from barrakid

    it was really well protected since it could only be accessed trough a black box (the PS3)

    This isn't true. All web services have an IP that can be accessed through a computer at least, and PSN has a website anyway. There's also the Media Go service for downloading Playstation/PSP things on a PC for people who don't have their systems set up to connect to the internet.

    And there's a really big difference between an external exploit, like cracking offline copyright protection, or flooding a server's bandwidth with a million connection attempts, and getting internal access to a website's server and its easily readable data. Nobody has ever stolen credit card numbers from Steam, Amazon, or Visa.

    News has already come out that PSN did not have any dedicated security staff or really knowledgeable IT guys and they had to hire external security to investigate this issue. I can guarantee you that they had some super weak shit going on that the hacker(s) exploited.

  • Sentura
    • May 2, 2011 at 8:06 PM
    • #47
    Quote from Jetsetlemming

    It is, in fact, possible to make a service strong enough to be reasonably secure from outside intrusions.

    lol this is bullshit. no system is 100% secure, and you always need to assume this. security 101

  • Jetsetlemming
    • May 2, 2011 at 8:42 PM
    • #48
    Quote from Sentura

    lol this is bullshit. no system is 100% secure, and you always need to assume this. security 101

    I said reasonably secure. It is quite possible to make a website secure enough from the internet side that it's probably not going to be broken into. Nobody has ever gotten into Amazon, Visa, or Paypal, and these would be way higher value targets than PSN. And yes, you always need to plan for "but what if", which is why the personal information should've never been saved in a readable format. Sony had to hire an external security team to "investigate" this issue. When the PS3 was hacked it was discovered that a single malformed encryption key was used for everything on the entire platform and it turned out to be trivially easy to get around every layer of copyright protection and code signing. Do you really think that this was some act of internet nature, unpredictable, and unpreventable? Is that a more reasonable opinion than "Sony's completely incompetent with security and this shouldn't have been able to happen"?

  • Mazy
    • May 2, 2011 at 10:54 PM
    • #49

    http://www.joystiq.com/2011/05/02/sony- ... t-card-nu/

    Hmmm, guess they should've kept their mouth shut about being all safe n' shit.

  • sarge mat
    • May 2, 2011 at 10:59 PM
    • #50

    Isn't Sony Online separate from Playstation though even now. Not that people will see the difference or care (nor should they).

  • -HP-
    • May 2, 2011 at 11:09 PM
    • #51

    [Blocked Image: http://forums.pvkii.com/style_emoticons/default/Thumb_MichealJacksonPopcorn.gif]

  • Izuno
    • May 3, 2011 at 1:03 AM
    • #52
    Quote from Mazy

    http://www.joystiq.com/2011/05/02/son…it-card-nu/Hmmm, guess they should've kept their mouth shut about being all safe n' shit.

    Mazy hacked my brain and stole the idea to post this before I could get to it. I contacted the FBI to see if I have a case in going after Mazy for theft, but they said "He posted that hours before you did. Get better internet skills, a**hole."

  • Sentura
    • May 3, 2011 at 1:44 AM
    • #53

    well hopefully that'll amount to another free game title. i would like that.

  • twiz
    • May 3, 2011 at 2:38 AM
    • #54

    I'd gladly give up my credit card information for a random free game.

  • Mazy
    • May 3, 2011 at 7:26 AM
    • #55
    Quote from Izuno

    Mazy hacked my brain and stole the idea to post this before I could get to it. I contacted the FBI to see if I have a case in going after Mazy for theft, but they said "He posted that hours before you did. Get better internet skills, a**hole."

    I stole your megahurtz, deal with it!

    It is interesting that they claim that this is part of the same attack that happened two weeks back. I mean you can't really spin this in a positive way, but if it had been a new attack they would've looked bad since they didn't grasp how unsecure some of their stuff online still is, but being that it was part of the first attack, then it just looks like they have no idea what's going on. Neither paint them in a good light.

  • Sentura
    • May 3, 2011 at 1:36 PM
    • #56
    Quote from twiz

    I'd gladly give up my credit card information for a random free game.

    eh the card i used for psn was shut down months ago, so i'm not really fussed.

  • Izuno
    • May 3, 2011 at 5:38 PM
    • #57

    So if one uses prepaid PSN card such as what you can buy at Best Buy or other retailers you'd be 100% in the clear of at least your credit card info being at risk...assuming you otherwise never input a CCN into PSN?

    ie...what's pictured at this link.

  • Thrik
    • May 3, 2011 at 7:02 PM
    • #58

    That's right, but it's not really a concern anyway as it's not PSN that's had credit card numbers compromised, but Sony Online Entertainment — an entirely different beast.

  • BaRRaKID
    • May 3, 2011 at 7:08 PM
    • #59
    Quote from Jetsetlemming

    This isn't true. All web services have an IP that can be accessed through a computer at least, and PSN has a website anyway. There's also the Media Go service for downloading Playstation/PSP things on a PC for people who don't have their systems set up to connect to the internet.

    And there's a really big difference between an external exploit, like cracking offline copyright protection, or flooding a server's bandwidth with a million connection attempts, and getting internal access to a website's server and its easily readable data. Nobody has ever stolen credit card numbers from Steam, Amazon, or Visa.

    News has already come out that PSN did not have any dedicated security staff or really knowledgeable IT guys and they had to hire external security to investigate this issue. I can guarantee you that they had some super weak shit going on that the hacker(s) exploited.

    Sorry, i don't own a PS3 so i was under the impression that the PSN was only accessible using the console.

    And I don't want to keep pushing this subject since Sony failed again, but, just because a service has an IP address (PSN probably has more than one, but whatever) it doesn't mean you can access it through a computer. That's only true if it allows connections trough a known protocol, which is probably not the case here, since almost any domestic router firewall can block traffic from protocols that can be exploited. Even if you could use one of those protocols to access the server you would need to have a zero-day exploit (considering that all the servers are patched) that allowed privilege escalation (since you usually need administrator privileges to access a database), and those are rare and hard to find, and if the hacker did have one there's nothing that a security expert could due since you can't protect yourself against something that you don't even know exists.

    Second if they had a PSN website, i really doubt that it was on the same server as the rest of the PSN content. You usually use a server dedicated to storing all the website files, and then have several other servers to handle the more heavy services (like for example databases) behind a load balancer.

    Finally I never said that people stole CC numbers from Steam, what i said was that non steam shows that Steam isn't a "reasonably secure" service, and Visa did have data stolen a couple of years ago by a known hacker who used a type of man in the middle attack where he could listen to all transactions made between a know retail chain and the Visa servers, and using that data he managed to steal millions of dollars by creating fake CC. He was later caught and hired by the FBI as a security expert, but double crossed them and ended up in jail, it'«s a great story actually

  • Jetsetlemming
    • May 3, 2011 at 7:32 PM
    • #60

    You don't seem to be seeing the difference between defacing a store, robbing the mailman, and actually breaking into the store and having free reign in it. The latter is what happened to Sony. It's also what happened to Gizmodo recently. It's not what No-Steam does. It's not what spying on a retailer is.

    Edit: Imagine Fort Knox. Ok? Super well guarded fortress and US military base, at which the US gold reserves are kept. Famous for high security. No-Steam is like if you put on a Clinton mask, went up to the front gate, and went "Hey I'm totes a legit member of the US government, gimme gold plz" and the dumb guard goes "Well ok, if you say so" and hands you a gold bar. The Visa thing is like if you ambushed a truck full of gold on its way to Fort Knox and robbed it. What happened to Sony is like if you pried up the wood covering a big gaping hole in their outer wall, walked right in, found the safes unlocked, and stole all the gold.

    edit 2: And it took fort knox a week to notice the robbery, at first they just told everyone they were investigating a local gold shortage.

Participate now!

Don’t have an account yet? Register yourself now and be a part of our community!

Register Yourself Login
Discord

The Mapcore Discord is our lively IRC channel of the 2000s reborn. Chat about level design, gaming, and more.

Latest Posts

  1. How to Use a Free Kundali Maker for Accurate Future Predictions

    astr09
    July 23, 2026 at 6:35 AM
  2. Tangerine

    Harry Poster
    July 18, 2026 at 11:10 AM
  3. Any of the old guard still around? D:

    Warby
    July 12, 2026 at 8:23 PM
  4. About our archived forums

    Thrik
    June 30, 2026 at 2:12 PM
  5. Mapcore Discord

    mason_fan123
    June 24, 2026 at 8:52 PM
  6. [CS2] Valley

    Serialmapper
    June 22, 2026 at 11:56 AM
  7. Free Music / SFX Resource - Over 2500 Tracks

    Eric Matyas
    June 18, 2026 at 12:32 PM
  8. Pango [WIP]

    Elowen
    June 11, 2026 at 10:13 AM
  9. [CS2] Dvina

    Jeremy Rivera
    June 11, 2026 at 10:03 AM
  10. Bridges 2.0 by NEXSIDE, MAP SHOWCASE. ( Steam Workshop )

    MrTrane18
    June 1, 2026 at 7:46 PM
  1. Privacy Policy
  2. Contact
Powered by WoltLab Suite™