Sony denies PSN hack, confirms PSN Web exploit
- 19 May, 2011 23:46
- Comments
The PlayStation Network wasn't hacked so much as threatened yesterday when a password exploit accessible through its PSN web page login page came to light, claims Sony.
Sony spokesperson Patrick Seybold confirmed the exploit in an official PlayStation blog dispatch yesterday afternoon.
"We temporarily took down the PSN and Qriocity password reset page," wrote Seybold, quickly adding "Contrary to some reports, there was no hack involved."
The "exploit" involved the PSN web-based password reset page, where whistleblower Nyleveia claimed anyone could change someone else's password using their PSN account email and date of birth--both details possibly (though not confirmedly) obtained by hackers in the original mid-April PSN breach.
Seybold seemed to confirm this as well: "In the process of resetting of passwords there was a URL exploit that we have subsequently fixed."
"Consumers who haven't reset their passwords for PSN are still encouraged to do so directly on their PS3," said Seybold. "Otherwise, they can continue to do so via the website as soon as we bring that site back up."
The login page was still down Thursday morning.
A hack is technically defined as "use [of] a computer to gain unauthorized access to data in a system," where an exploit isn't formally defined in computer terms, but means to "make full use of and derive benefit from (a resource)." It's splitting hairs to call the PSN password reset issue one or the other, but as I noted yesterday, "hacking" usually involves breaking into something, where "exploiting" involves taking advantage of some preexisting deficiency to gain some advantage from a broken or vulnerable process (as opposed to flat out breaking into a system).
So yes, Sony was hacked. Or exploited. Or both, depending on your stance. All that matters to PlayStation gamers, I'm betting, is that the vulnerability was patched quickly: if we go with Nyleveia's version of events, within 15 minutes of notification. That's not such a bad thing as reaction times go, and it's also important to bear in mind Sony's under unprecedented scrutiny levels, so any little slip that might otherwise receive passing notice ends up hyper-magnified.
Interact with Game On: Twitter - Facebook - Get in touch
Join the CIO Australia group on LinkedIn. The group is open to CIOs, IT Directors, COOs, CTOs and senior IT managers.
- Bookmark this page
- Share this article
- Got more on this story? Email CIO
- Follow CIO on twitter
- The Top 5 Server Monitoring Battles—and How You Can Win Them
- Get the Whole Picture Why Most Organizations Miss User Response Monitoring—and What to Do About It
- Case Study: Keeping information on the move: Clearswift protects Maman, the logistics experts
- Mobile Security: Don’t leave employees to their own devices
- Seven Tips for Securing Mobile Workers
-
Google Jumps Into Social Bookmarks Game
-
NBN build gaining momentum daily: Quigley
-
Face Time - Interview with John Brennan and Robert DiStefano
-
Monday Grok: Will Siri crack the walls of GOOG?
-
Face Time - Interview with John Brennan and Robert DiStefano
-
Optimised License Management for the Datacenter
Optimised license management is a necessity for all licenses owned by the enterprise. While organisations are starting to understand their license position for the desktop estate, the reality is that licensing in the datacenter presents a daunting set of challenges that require a robust, automated license management solution. Learn about how to address the unique license management requirements of all enterprise IT environments including the desktop and the datacenter. -
Print security and the mobile workforce
Where, when, and how we work is changing. Whether your employees are working on the road without a dedicated workstation or from a home office, they need a safe way to print. Driving this shift is the accelerating adoption of smartphones, tablets, and other mobile devices. But even with these devices, printing remains a key business function for virtually all employees, and many may already be using them to print. Read more. -
Case Study: HJ Heinz
Heinz has trusted Sophos to protect its desktop users and email systems from malware and spam for many years. As part of its multi-tier approach to IT security, the company needed more robust protection against web-based threats and the use of unauthorised applications.

















Comments
Post new comment