<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Sony: We wuz robbed.&#160;Again.</title>
	<atom:link href="http://boingboing.net/2011/05/02/sony-we-wuz-breached.html/feed" rel="self" type="application/rss+xml" />
	<link>http://boingboing.net/2011/05/02/sony-we-wuz-breached.html</link>
	<description>Brain candy for Happy Mutants</description>
	<lastBuildDate>Sat, 18 May 2013 15:32:00 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.4.1</generator>
	<item>
		<title>By: deckard68</title>
		<link>http://boingboing.net/2011/05/02/sony-we-wuz-breached.html#comment-1099310</link>
		<dc:creator>deckard68</dc:creator>
		<pubDate>Wed, 30 Nov -0001 00:00:00 +0000</pubDate>
		<guid isPermaLink="false">#comment-1099310</guid>
		<description>Personalized spam, and personalized attempts to deceive. That is what this breach is about, so far as we know. It is a data set of people names connected to their email addresses. So instead of &quot;Dear Bank Customer, you need to reset your password by visiting bank.crimesrus.com&quot;, it will say &quot;Dear Joe Smith of 123 Happy Lane, you need to reset your banking password...&quot;.

And some people, senior citizens especially, may be tricked.

But unless there turns out to be credit card info stolen, this is basically the theft of an up-to-date mailing list. A HUGE one. The password to the PSN network? Worthless. The history of what games you played? No one cares. But boy, even non-criminals would love an up-to-date mailing list. 501c3s would kill for that kind of info so they could personalize their fundraising emails.</description>
		<content:encoded><![CDATA[<p>Personalized spam, and personalized attempts to deceive. That is what this breach is about, so far as we know. It is a data set of people names connected to their email addresses. So instead of &#8220;Dear Bank Customer, you need to reset your password by visiting bank.crimesrus.com&#8221;, it will say &#8220;Dear Joe Smith of 123 Happy Lane, you need to reset your banking password&#8230;&#8221;.</p>
<p>And some people, senior citizens especially, may be tricked.</p>
<p>But unless there turns out to be credit card info stolen, this is basically the theft of an up-to-date mailing list. A HUGE one. The password to the PSN network? Worthless. The history of what games you played? No one cares. But boy, even non-criminals would love an up-to-date mailing list. 501c3s would kill for that kind of info so they could personalize their fundraising emails.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: DWittSF</title>
		<link>http://boingboing.net/2011/05/02/sony-we-wuz-breached.html#comment-1099577</link>
		<dc:creator>DWittSF</dc:creator>
		<pubDate>Wed, 30 Nov -0001 00:00:00 +0000</pubDate>
		<guid isPermaLink="false">#comment-1099577</guid>
		<description>Geohot has a great blog post up about this, and he&#039;s 100% spot on:

Now until more information is revealed on the technicals, I can only speculate, but I bet Sony&#039;s arrogance and misunderstanding of ownership put them in this position. Sony execs probably haughtily chuckled at the idea of threat modeling. Traditionally the trust boundary for a web service exists between the server and the client. But Sony believes they own the client too, so if they just put a trust boundary between the consumer and the client(can&#039;t trust those pesky consumers), everything is good. Since everyone knows the PS3 is unhackable, why waste money adding pointless security between the client and the server? This arrogance undermines a basic security principle, never trust the client.



http://geohotgotsued.blogspot.com/</description>
		<content:encoded><![CDATA[<p>Geohot has a great blog post up about this, and he&#8217;s 100% spot on:</p>
<p>Now until more information is revealed on the technicals, I can only speculate, but I bet Sony&#8217;s arrogance and misunderstanding of ownership put them in this position. Sony execs probably haughtily chuckled at the idea of threat modeling. Traditionally the trust boundary for a web service exists between the server and the client. But Sony believes they own the client too, so if they just put a trust boundary between the consumer and the client(can&#8217;t trust those pesky consumers), everything is good. Since everyone knows the PS3 is unhackable, why waste money adding pointless security between the client and the server? This arrogance undermines a basic security principle, never trust the client.</p>
<p><a href="http://geohotgotsued.blogspot.com/" rel="nofollow">http://geohotgotsued.blogspot.com/</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Anonymous</title>
		<link>http://boingboing.net/2011/05/02/sony-we-wuz-breached.html#comment-1100114</link>
		<dc:creator>Anonymous</dc:creator>
		<pubDate>Wed, 30 Nov -0001 00:00:00 +0000</pubDate>
		<guid isPermaLink="false">#comment-1100114</guid>
		<description>Sony aren&#039;t to blame. As long as some one can create security some one out there can bypass it. Check how many major websites have been hacked in the last few months. Listen to sarcastic gamer playstation podcast for a proper perspective. </description>
		<content:encoded><![CDATA[<p>Sony aren&#8217;t to blame. As long as some one can create security some one out there can bypass it. Check how many major websites have been hacked in the last few months. Listen to sarcastic gamer playstation podcast for a proper perspective. </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: grs</title>
		<link>http://boingboing.net/2011/05/02/sony-we-wuz-breached.html#comment-1099124</link>
		<dc:creator>grs</dc:creator>
		<pubDate>Wed, 30 Nov -0001 00:00:00 +0000</pubDate>
		<guid isPermaLink="false">#comment-1099124</guid>
		<description>I heard Osama bin Laden was caught because he called Sony customer service to see if his Playstation account had been hacked.</description>
		<content:encoded><![CDATA[<p>I heard Osama bin Laden was caught because he called Sony customer service to see if his Playstation account had been hacked.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: deckard68</title>
		<link>http://boingboing.net/2011/05/02/sony-we-wuz-breached.html#comment-1099125</link>
		<dc:creator>deckard68</dc:creator>
		<pubDate>Wed, 30 Nov -0001 00:00:00 +0000</pubDate>
		<guid isPermaLink="false">#comment-1099125</guid>
		<description>I heard there&#039;s a mansion opening up to buyers shortly.</description>
		<content:encoded><![CDATA[<p>I heard there&#8217;s a mansion opening up to buyers shortly.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jack</title>
		<link>http://boingboing.net/2011/05/02/sony-we-wuz-breached.html#comment-1099126</link>
		<dc:creator>Jack</dc:creator>
		<pubDate>Wed, 30 Nov -0001 00:00:00 +0000</pubDate>
		<guid isPermaLink="false">#comment-1099126</guid>
		<description>I hear Abbottabad has a nice empty place ripe for a datacenter...

*chirps* *chirps* *chirps* *howl* *chirps* *chirps* 

Okay, seriously, Sony.  HOW!?!?!?!? Something this massive.  HOW?!?!?!?!?</description>
		<content:encoded><![CDATA[<p>I hear Abbottabad has a nice empty place ripe for a datacenter&#8230;</p>
<p>*chirps* *chirps* *chirps* *howl* *chirps* *chirps* </p>
<p>Okay, seriously, Sony.  HOW!?!?!?!? Something this massive.  HOW?!?!?!?!?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Anonymous</title>
		<link>http://boingboing.net/2011/05/02/sony-we-wuz-breached.html#comment-1099387</link>
		<dc:creator>Anonymous</dc:creator>
		<pubDate>Wed, 30 Nov -0001 00:00:00 +0000</pubDate>
		<guid isPermaLink="false">#comment-1099387</guid>
		<description>The password to the PSN network may be worthless but in a lot of cases it will be the same as the email, paypal, wow, etc. one.</description>
		<content:encoded><![CDATA[<p>The password to the PSN network may be worthless but in a lot of cases it will be the same as the email, paypal, wow, etc. one.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: JM</title>
		<link>http://boingboing.net/2011/05/02/sony-we-wuz-breached.html#comment-1099404</link>
		<dc:creator>JM</dc:creator>
		<pubDate>Wed, 30 Nov -0001 00:00:00 +0000</pubDate>
		<guid isPermaLink="false">#comment-1099404</guid>
		<description>You know&#039;s laughing hardest?

Nintendo.</description>
		<content:encoded><![CDATA[<p>You know&#8217;s laughing hardest?</p>
<p>Nintendo.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Blackbird</title>
		<link>http://boingboing.net/2011/05/02/sony-we-wuz-breached.html#comment-1099149</link>
		<dc:creator>Blackbird</dc:creator>
		<pubDate>Wed, 30 Nov -0001 00:00:00 +0000</pubDate>
		<guid isPermaLink="false">#comment-1099149</guid>
		<description>So...is this all of the data yet?</description>
		<content:encoded><![CDATA[<p>So&#8230;is this all of the data yet?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: technogeek</title>
		<link>http://boingboing.net/2011/05/02/sony-we-wuz-breached.html#comment-1099152</link>
		<dc:creator>technogeek</dc:creator>
		<pubDate>Wed, 30 Nov -0001 00:00:00 +0000</pubDate>
		<guid isPermaLink="false">#comment-1099152</guid>
		<description>This is _almost_ enough to make me sympathize with Sony&#039;s decision to kill the OtherOS feature (removing the PS3&#039;s ability to run Linux). On the other hand, that was _almost_ enough to make me feel Sony&#039;s security people clearly had their eye on the wrong ball.

Grumph. Either way.

</description>
		<content:encoded><![CDATA[<p>This is _almost_ enough to make me sympathize with Sony&#8217;s decision to kill the OtherOS feature (removing the PS3&#8242;s ability to run Linux). On the other hand, that was _almost_ enough to make me feel Sony&#8217;s security people clearly had their eye on the wrong ball.</p>
<p>Grumph. Either way.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: edgore</title>
		<link>http://boingboing.net/2011/05/02/sony-we-wuz-breached.html#comment-1099158</link>
		<dc:creator>edgore</dc:creator>
		<pubDate>Wed, 30 Nov -0001 00:00:00 +0000</pubDate>
		<guid isPermaLink="false">#comment-1099158</guid>
		<description>If the LOCATION of their data center has anything to do with their problems they should probably just give up right now.</description>
		<content:encoded><![CDATA[<p>If the LOCATION of their data center has anything to do with their problems they should probably just give up right now.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: cratermoon</title>
		<link>http://boingboing.net/2011/05/02/sony-we-wuz-breached.html#comment-1099168</link>
		<dc:creator>cratermoon</dc:creator>
		<pubDate>Wed, 30 Nov -0001 00:00:00 +0000</pubDate>
		<guid isPermaLink="false">#comment-1099168</guid>
		<description>That&#039;s just what I was thinking, edgore. Isn&#039;t the fundamental problem really that either the sensitive personal/credit card information is either stored on the same system as the game servers or on a system that is somehow trusted or too easily compromised once the game servers are hacked? Sony is doing something seriously wrong if they expect the user hardware to be secure to enough to be their main line of defense against intrusions. First rule of computer security: never trust the hardware in the hands of an untrusted third party.</description>
		<content:encoded><![CDATA[<p>That&#8217;s just what I was thinking, edgore. Isn&#8217;t the fundamental problem really that either the sensitive personal/credit card information is either stored on the same system as the game servers or on a system that is somehow trusted or too easily compromised once the game servers are hacked? Sony is doing something seriously wrong if they expect the user hardware to be secure to enough to be their main line of defense against intrusions. First rule of computer security: never trust the hardware in the hands of an untrusted third party.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: oldtaku</title>
		<link>http://boingboing.net/2011/05/02/sony-we-wuz-breached.html#comment-1099169</link>
		<dc:creator>oldtaku</dc:creator>
		<pubDate>Wed, 30 Nov -0001 00:00:00 +0000</pubDate>
		<guid isPermaLink="false">#comment-1099169</guid>
		<description>FFS Sony. If the physical location of your data center is an issue then you&#039;re even stupider than we were giving you credit for. Maybe you can use Tor to hide teh eye-pees?
</description>
		<content:encoded><![CDATA[<p>FFS Sony. If the physical location of your data center is an issue then you&#8217;re even stupider than we were giving you credit for. Maybe you can use Tor to hide teh eye-pees?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Anonymous</title>
		<link>http://boingboing.net/2011/05/02/sony-we-wuz-breached.html#comment-1099186</link>
		<dc:creator>Anonymous</dc:creator>
		<pubDate>Wed, 30 Nov -0001 00:00:00 +0000</pubDate>
		<guid isPermaLink="false">#comment-1099186</guid>
		<description>I read that prior to the hacking, Sony was already building a new Server installation in a new location - these events have brought the move date forward...I guess changing location to the new installation adds more security due to the hardware that is in place &amp; moving now means less disruption for us in the long term.</description>
		<content:encoded><![CDATA[<p>I read that prior to the hacking, Sony was already building a new Server installation in a new location &#8211; these events have brought the move date forward&#8230;I guess changing location to the new installation adds more security due to the hardware that is in place &#038; moving now means less disruption for us in the long term.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jack</title>
		<link>http://boingboing.net/2011/05/02/sony-we-wuz-breached.html#comment-1099195</link>
		<dc:creator>Jack</dc:creator>
		<pubDate>Wed, 30 Nov -0001 00:00:00 +0000</pubDate>
		<guid isPermaLink="false">#comment-1099195</guid>
		<description>What about this magical â€œcloudâ€ I keep on hearing about?  Amazonâ€™s â€œcloudâ€ goes down and brings slews of sites down. Sonyâ€™s â€œcloudâ€ is hacked and 1,000,000,000+ users have their data compromised.

Iâ€™m keeping my landline.</description>
		<content:encoded><![CDATA[<p>What about this magical â€œcloudâ€ I keep on hearing about?  Amazonâ€™s â€œcloudâ€ goes down and brings slews of sites down. Sonyâ€™s â€œcloudâ€ is hacked and 1,000,000,000+ users have their data compromised.</p>
<p>Iâ€™m keeping my landline.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Rob</title>
		<link>http://boingboing.net/2011/05/02/sony-we-wuz-breached.html#comment-1099707</link>
		<dc:creator>Rob</dc:creator>
		<pubDate>Wed, 30 Nov -0001 00:00:00 +0000</pubDate>
		<guid isPermaLink="false">#comment-1099707</guid>
		<description>Call it a hunch, but I don&#039;t think there&#039;s many senior citizens on Everquest or PSN
</description>
		<content:encoded><![CDATA[<p>Call it a hunch, but I don&#8217;t think there&#8217;s many senior citizens on Everquest or PSN</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: kibbee</title>
		<link>http://boingboing.net/2011/05/02/sony-we-wuz-breached.html#comment-1099463</link>
		<dc:creator>kibbee</dc:creator>
		<pubDate>Wed, 30 Nov -0001 00:00:00 +0000</pubDate>
		<guid isPermaLink="false">#comment-1099463</guid>
		<description>How were passwords stolen?  Shouldn&#039;t they be salted and hashed?  Seriously how can Sony be so stupid about this stuff?  However, after owning a MiniDisk player and having to put up with SonicStage, it doesn&#039;t surprise me.  For anybody who complains about iTunes, you&#039;ve never used SonicStage.  I also can&#039;t believe they are so insecure that all accounts and credit cards can be accessed by hacking into the game network.  </description>
		<content:encoded><![CDATA[<p>How were passwords stolen?  Shouldn&#8217;t they be salted and hashed?  Seriously how can Sony be so stupid about this stuff?  However, after owning a MiniDisk player and having to put up with SonicStage, it doesn&#8217;t surprise me.  For anybody who complains about iTunes, you&#8217;ve never used SonicStage.  I also can&#8217;t believe they are so insecure that all accounts and credit cards can be accessed by hacking into the game network.  </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ibbers</title>
		<link>http://boingboing.net/2011/05/02/sony-we-wuz-breached.html#comment-1099213</link>
		<dc:creator>ibbers</dc:creator>
		<pubDate>Wed, 30 Nov -0001 00:00:00 +0000</pubDate>
		<guid isPermaLink="false">#comment-1099213</guid>
		<description>on an unrelated matter - boingboing have you increased the amount of adverts on the site?

hell of a lot more advertising clutter nowdays it seems.</description>
		<content:encoded><![CDATA[<p>on an unrelated matter &#8211; boingboing have you increased the amount of adverts on the site?</p>
<p>hell of a lot more advertising clutter nowdays it seems.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: EH</title>
		<link>http://boingboing.net/2011/05/02/sony-we-wuz-breached.html#comment-1099214</link>
		<dc:creator>EH</dc:creator>
		<pubDate>Wed, 30 Nov -0001 00:00:00 +0000</pubDate>
		<guid isPermaLink="false">#comment-1099214</guid>
		<description>Sony should not be allowed to take credit cards.</description>
		<content:encoded><![CDATA[<p>Sony should not be allowed to take credit cards.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: brianary</title>
		<link>http://boingboing.net/2011/05/02/sony-we-wuz-breached.html#comment-1099727</link>
		<dc:creator>brianary</dc:creator>
		<pubDate>Wed, 30 Nov -0001 00:00:00 +0000</pubDate>
		<guid isPermaLink="false">#comment-1099727</guid>
		<description>I think SonyStyle.com is still pending.</description>
		<content:encoded><![CDATA[<p>I think SonyStyle.com is still pending.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: morcheeba</title>
		<link>http://boingboing.net/2011/05/02/sony-we-wuz-breached.html#comment-1099226</link>
		<dc:creator>morcheeba</dc:creator>
		<pubDate>Wed, 30 Nov -0001 00:00:00 +0000</pubDate>
		<guid isPermaLink="false">#comment-1099226</guid>
		<description>too late... Sony Bank is issuing their own credit cards.
http://www.asahi.com/english/TKY201103310375.html</description>
		<content:encoded><![CDATA[<p>too late&#8230; Sony Bank is issuing their own credit cards.<br />
<a href="http://www.asahi.com/english/TKY201103310375.html" rel="nofollow">http://www.asahi.com/english/TKY201103310375.html</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Steiny</title>
		<link>http://boingboing.net/2011/05/02/sony-we-wuz-breached.html#comment-1099230</link>
		<dc:creator>Steiny</dc:creator>
		<pubDate>Wed, 30 Nov -0001 00:00:00 +0000</pubDate>
		<guid isPermaLink="false">#comment-1099230</guid>
		<description>&lt;a href=&quot;http://www.youtube.com/watch?v=kzs9L9HDdp0&quot;&gt;Sailor Mars has the answers to all Sony&#039;s problems.&lt;/a&gt;</description>
		<content:encoded><![CDATA[<p><a href="http://www.youtube.com/watch?v=kzs9L9HDdp0">Sailor Mars has the answers to all Sony&#8217;s problems.</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Anonymous</title>
		<link>http://boingboing.net/2011/05/02/sony-we-wuz-breached.html#comment-1099253</link>
		<dc:creator>Anonymous</dc:creator>
		<pubDate>Wed, 30 Nov -0001 00:00:00 +0000</pubDate>
		<guid isPermaLink="false">#comment-1099253</guid>
		<description>I guess http://ispsnupyet.com may be wrong..</description>
		<content:encoded><![CDATA[<p>I guess <a href="http://ispsnupyet.com" rel="nofollow">http://ispsnupyet.com</a> may be wrong..</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: petsounds</title>
		<link>http://boingboing.net/2011/05/02/sony-we-wuz-breached.html#comment-1099256</link>
		<dc:creator>petsounds</dc:creator>
		<pubDate>Wed, 30 Nov -0001 00:00:00 +0000</pubDate>
		<guid isPermaLink="false">#comment-1099256</guid>
		<description>This summary is a bit sparse on details. The 25 million additional users were from the Sony Online Entertainment network, completely separate from PSN. This network handles their (shitty) MMORPGs like Everquest and Star Wars: Galaxies.

100 million users. That&#039;s roughly one third of the entire population of the USA.

This kind of systemic, gargantuan negligence of people&#039;s trusted data needs to be criminalized.</description>
		<content:encoded><![CDATA[<p>This summary is a bit sparse on details. The 25 million additional users were from the Sony Online Entertainment network, completely separate from PSN. This network handles their (shitty) MMORPGs like Everquest and Star Wars: Galaxies.</p>
<p>100 million users. That&#8217;s roughly one third of the entire population of the USA.</p>
<p>This kind of systemic, gargantuan negligence of people&#8217;s trusted data needs to be criminalized.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
