Posted October 13, 2011

Aningan
YNWA
Registered: Dec 2010
From Western Sahara

wodmarach
booooooooooored
Registered: Feb 2010
From United Kingdom
Posted October 13, 2011
What makes it funnier to me is that when the first attack happened I said I'd never trust Sony with security again... My friends and people on-line laughed at me saying it could never happen again... some of them are currently claiming it's a lie and hasn't happened again..

bevinator
Yep.
Registered: Mar 2011
From United States
Posted October 13, 2011
From reading the article, the accounts were compromised in a totally different manner from the previous one. Rather than Sony itself getting hacked, this seems like a set of logins from other websites being bruteforced to see if the user keeps the same username/password in multiple places. It's troubling for sure, but it's not a security issue for Sony as much as it's a security issue for individual accounts. If the actual servers got hacked, there wouldn't be any failed attempts. Never thought I'd be defending Sony, but there it is.

bansama
bansama.com
Registered: Oct 2008
From Japan
Posted October 13, 2011
As bevinator says, this isn't an attack Sony's security as such, they simply got a hold of the account information obtained by hacking other unrelated servers, such as the attack on Codemasters, etc., and using that information to try and gain access to Sony accounts.
And let's face it, if you're using universal passwords and account names, you're going to be the victim of such attacks eventually regardless of how much security the likes of Sony have.
And let's face it, if you're using universal passwords and account names, you're going to be the victim of such attacks eventually regardless of how much security the likes of Sony have.

KOC
Kafkan Ogre Club
Registered: Sep 2008
From Denmark
Posted October 13, 2011
Yep, this is why I changed all my passwords everywhere after the first attack. Just to be sure something like this would not happen to me.

kalmis666
Call me duder
Registered: Sep 2010
From Germany
Posted October 13, 2011
I thought this was just a joke.

DarrkPhoenix
A1 Antagonist
Registered: Nov 2008
From United States
Posted October 13, 2011
This wasn't so much a flaw in Sony's security, but a lesson in why you shouldn't re-use username/password pairs across different sites. The one thing in this that Sony could potentially be faulted on is not detecting and locking out the attacker earlier, although this criticism depends on how distributed the attack was. If it was launched from a large botnet so that each IP address was only launching something like 5-10 login attempts, then there's not much Sony could have done. However, if it was launched from a smaller base of computers, such that Sony's servers were seeing hundreds or thousands of login attempts from each IP address over a fairly short period of time, then Sony should have locked out those IPs much faster than they did.

EndlessKnight
Magic Missile!
Registered: Mar 2010
From Canada
Posted October 13, 2011
Agreed. This has little to do with Sony, and everything to do with people using the same passwords on multiple sites. This is nothing new really, Microsoft has this sort of thing occur as well.
Post edited October 13, 2011 by EndlessKnight

Runehamster
keep it classy!
Registered: Jun 2009
From United States
Posted October 13, 2011
I got 'hit' by this, as one of the people affected, and absolutely nothing happened. I use a different password for every site I'm on.

Immoli
Hello
Registered: Jan 2011
From United States
Posted October 14, 2011

Anyway, I doubt they got into mine. Even if they did, all my information is fake and there is no payment options on my account.

Navagon
Easily Persuaded
Registered: Dec 2008
From United Kingdom
Posted October 14, 2011
Rather than a firewall they may as well put a revolving door in their series of tubes.

orcishgamer
Mad and Green
Registered: Jun 2010
From United States
Posted October 14, 2011
Actually this doesn't seem like a fail for Sony, someone targeted their accounts and managed to get pretty much nothing but a username from the few that were compromised... that is if they're telling the truth (which they may not be).

Runehamster
keep it classy!
Registered: Jun 2009
From United States
Posted October 15, 2011


Anyway, I doubt they got into mine. Even if they did, all my information is fake and there is no payment options on my account.

Immoli
Hello
Registered: Jan 2011
From United States
Posted October 15, 2011
