Home

Sony Locks Accounts After Data Breach

Comments | Mathew J. Schwartz, InformationWeek | October 12, 2011 02:12 PM


10 Massive Security Breaches
(click image for larger view)
Slideshow: 10 Massive Security Breaches
Sony has suffered a data breach involving the usernames and passwords of about 93,000 customers. But the exploit appeared to involve a massive number of credentials stolen from third-party sites, only some of which attackers were able to reuse to logon to people's PlayStation Network (PSN), or Sony Online Entertainment (SOE), or Sony Entertainment Network (SEN) accounts.

"These attempts appear to include a large amount of data obtained from one or more compromised lists from other companies, sites, or other sources," said Philip Reitinger, the chief information security officer (CISO) of Sony Group, in a blog post announcing the breach.

More Insights

Webcasts

More >>

White Papers

More >>

Reports

More >>

In other words, the unauthorized access of people's Sony accounts resulted from their reusing their usernames and passwords across multiple sites. "Given that the data tested against our network consisted of sign-in ID-password pairs, and that the overwhelming majority of the pairs resulted in failed matching attempts, it is likely the data came from another source and not from our networks," he said. "We have taken steps to mitigate the activity."

[Apple's products continue to highlight what relatively secure environments look like. What can we learn from Steve Jobs And Tech Security?]

Sony has locked the affected accounts, and said it's reviewing how accounts may have been accessed, and whether any unauthorized purchases were made. It said it would refund those purchases, but also that no credit card numbers were at risk.

For context, Reitinger said that the breach appeared to involve less than 0.1% of Sony's PSN, SEN, and SOE customer base. Sony is now reaching out to the 93,000 people whose external usernames and passwords attackers were able to match with their Sony accounts, and requiring them to reset their passwords. "We encourage you to choose unique, hard-to-guess passwords and always look for unusual activity in your account," he said.

Of course, Sony's security image is still reeling after its websites were compromised more than a dozen times earlier this year. In the most severe breach, which resulted in at least one class action lawsuit being filed, attackers stole information on more than 77 million PSN users, and the Sony gaming network was offline for more than a month.

In this case, Sony seems to be placing the blame for the attack on password reuse. But should Sony--especially given its status as the most exploited attack target of 2011--have done more to prevent such an attack from succeeding, not least by supplementing a system based solely on usernames and passwords?

"The fact that people reuse passwords is a known issue. Sony should be requiring more than using a username and password. And in their situation, in which people are coming in from hardware that they know, there's no excuse," said Joseph Steinberg, CEO of Green Armor Solutions, which sells identity verification software.

For example, he said, many financial services firms and healthcare companies are demonstrating identity verification state of the art, including extensive behind-the-scenes logic to help detect unusual behavior on the part of someone using otherwise acceptable username and password access credentials. For example, is a user based in New York City suddenly trying to log in from London? Or is a login attempt coming from a PC that's never been used before? In either case, identity verification systems can escalate the authentication, requiring more than just usernames and passwords to log in.

In the case of PSN, furthermore, Sony could even be using a PlayStation as part of a multi-factor authentication mechanism. "They control the hardware on the PlayStation, they should be doing strong authentication from that hardware," Steinberg said. "They really need to start thinking of their system as a financial system, rather than a gaming system."



Related Reading




Currently we allow the following HTML tags in comments:

Single tags

These tags can be used alone and don't need an ending tag.

<br> Defines a single line break

<hr> Defines a horizontal line

Matching tags

These require an ending tag - e.g. <i>italic text</i>

<a> Defines an anchor

<b> Defines bold text

<big> Defines big text

<blockquote> Defines a long quotation

<caption> Defines a table caption

<cite> Defines a citation

<code> Defines computer code text

<em> Defines emphasized text

<fieldset> Defines a border around elements in a form

<h1> This is heading 1

<h2> This is heading 2

<h3> This is heading 3

<h4> This is heading 4

<h5> This is heading 5

<h6> This is heading 6

<i> Defines italic text

<p> Defines a paragraph

<pre> Defines preformatted text

<q> Defines a short quotation

<samp> Defines sample computer code text

<small> Defines small text

<span> Defines a section in a document

<s> Defines strikethrough text

<strike> Defines strikethrough text

<strong> Defines strong text

<sub> Defines subscripted text

<sup> Defines superscripted text

<u> Defines underlined text

BYTE encourages readers to engage in spirited, healthy debate, including taking us to task. However, BYTE moderates all comments posted to our site, and reserves the right to modify or remove any content that it determines to be derogatory, offensive, inflammatory, vulgar, irrelevant/off-topic, racist or obvious marketing/SPAM. BYTE further reserves the right to disable the profile of any commenter participating in said activities.

COMMENTS

Tune In to BYTE
Facebook Twitter LinkedIn Newsletter RSS
Whitepapers
whitepaper
In this paper you will learn the five trends shaping the future of enterprise mobility. Learn how the rise of social media as a business application, the lurring between work and home, the emergence of new mobile devices, the demand for tech savvy employees and changing expectations of corporate IT will fundamentally change the workplace.
whitepaper
In a survey of more than 1,700 information workers (iWorkers) in North America, notebooks, desktops, and smartphones were found to be “must-have” devices, while tablets, slates, and netbooks were relegated to “nice-to-have” status, according to a commissioned study conducted by Forrester Consulting on behalf of Dell and Intel.
Sponsored by: Dell
Upcoming Events