I must say I'm baffled. I logged back into my PSN account via my PS3 yesterday, it directly asked me to change my password when I tried to use my previous credentials. No confirmation needed, it just sends you an email afterwards to notify you that your password has been changed.
At this point I assumed that it had used my PS3 hardware ID + my (static) IP + whatever to correlate that in all likelihood it must have been a legitimate login, which was already a bit weird but I guess they wanted to make it as simple as possible for everybody.
But this is just outstanding. It's really security 101 failure. As others have pointed out, using a regular password reset email with a unique token would have been much more safe, albeit not foolproof (some people would have lost their emails accounts they used to register by now).
Sony deserves everything that's happening (and will probably continue to happen) to them. The sad part is that I'm sure a majority of the gamers sony really targets must still be chanting "xbox sucks go sony lol" and still think geohot or anonymous or santa is to blame.
If you are referring to changing your password the first time you logged in after the breach, then what is happening is that PSN knows you created that account on that PlayStation, hence the lack of confirmation. I created my account on a friend's PS3, and when I signed in I got sent an email which contained a password reset link.
It's rather strange then, given how secure the reset process was post-hack (and I think they did a really good job of making it secure and convenient) that they left such a gaping and obvious hole!
Sony deserves everything that's happening (and will probably continue to happen) to them. The sad part is that I'm sure a majority of the gamers sony really targets must still be chanting "xbox sucks go sony lol"...
The effective collective IQ of Sony has sunk below average at this point, and the company lumbers along on network effects. Maybe there's room now for a gaming platform that's not a physical console?
I hope the collective IQ analogy doesn't also work for the United States!
The sad part is that I'm sure a majority of the gamers sony really targets ... still think geohot or anonymous or santa is to blame.
As a fellow PS3 player, I have an alternate point of view: I do not care about anyone's personal crusades. I just want to play some online games.
I believe multiple sources are at fault. One is at fault for providing the gun to the public, another is at fault for shooting the gun, and the third is at fault for not wearing a bulletproof vest. If I were to speculate on where most of the blame should be placed, I would be hardpressed to blame the victim. I point my finger at the gunmen. I am part of the collateral damage, a civilian caught in the crossfire, caught in friendly fire.
If it is your credit card information, you would seem to be the victim. In that case Sony is playing the role similar to the US government and is only offering you a shirt instead of a bullet proof vest.
The original analogy though is only accurate depending on where this is taking place. A person living in the suburbs would seem silly for wearing a bullet proof vest. A person walking into a war zone without a vest is an idiot. The question is, which of the two locations best describes the internet.
If it's my credit card information then all the merchants who end up passing my card fraudulently are the victims, because they are the ones who won't get paid.
I won't have to pay a dime for transactions I didn't authorize.
I suppose I could call "victim" for having to watch my statements more closely, but everyone does that anyway, right?
Every day that went by where they didn't respond drew further outcry in the press and from government. So they rushed something out. Caught between a rock and a hard place.
At this point I assumed that it had used my PS3 hardware ID + my (static) IP + whatever to correlate that in all likelihood it must have been a legitimate login, which was already a bit weird but I guess they wanted to make it as simple as possible for everybody.
But this is just outstanding. It's really security 101 failure. As others have pointed out, using a regular password reset email with a unique token would have been much more safe, albeit not foolproof (some people would have lost their emails accounts they used to register by now).
Sony deserves everything that's happening (and will probably continue to happen) to them. The sad part is that I'm sure a majority of the gamers sony really targets must still be chanting "xbox sucks go sony lol" and still think geohot or anonymous or santa is to blame.
-- A very unhappy PS3 (and its ancestors) owner.