Tech Mania |
| PSN hacked, CFW on Playstation 3 could reveal info about Credit cards Posted: 21 Feb 2011 06:52 AM PST I have been following news on Playstation network and here is what I found out.Some anonymous PS3 hacker is claiming to have decrypted nearly 100% of the traffic transferred over proxies, http and https to and from the PSN. The decrypted data includes sensitive information like credit card data, PSN credentials, Personal information, etc. Here is the full research:
According to this hacker, even if a connection is SSL encrypted, companies are aware of the big risk behind custom CA files and it's possibilities. SONY seems not to care about those known vulnerabilities. It is a big company and a HUGE network. With huge we mean a magnitude of hundreds and even thousands: For your info the PSN utilizes thousands of servers, handled by a very small group of administrators and quality assurance people. The IP ranges and domains of these servers are retrievable by anyone, cause this is how the Internet works ! It is all public data and information An example is the credit card information and the login authentication itself. Take a look at the traffic:
The credit card information should ALWAYS be encrypted. In ANY case. At least the security code should be encrypted and SONY is just relying on it's https connection. With all those CFWs spreading around, this is not secure anymore. Same goes for the user details:
Such sensitive data can now be captured by anyone who builds his own custom firmware with custom certificates. There are some noobie scripts can phish user data. As many of these people are using a third party DNS, they are a potential victim of phishing. At the beginning of the PS3 launch, this user data was even transferred over http ! The PlayStation Network agreement states that SONY is allowed to collect nearly any data that is connected with your privacy.It is clear, that SONY won't tell you WHAT they are collecting in the TOS etc., as many people would never accept that TOS. A few months ago we noticed the TOS silently beeing updated without a new user agreement request. It was about that you have the right to contact a "Data Protection Officer" at SCEE, who can can give you details about what data is collected. So we phoned SCEE. Beeing forwarded to many people, it turned out that there is no so called "Data Protection Officer". Shortly after this call, the clause was removed from the TOS. SONY itself told us, that they do not know, what we are talking about regarding this Officer. They told us, that there was never such a position inside SONY, neither a phone number. Even the address was non existing ! Still it is an impudence what huge amounts of data they are collecting. One example is an information list which is transfered everytime you login the PSN as well as at some random time. A few short quotes: <info category="76″>TFT-TV</info><info category="77″> This is a string sent to SONY which includes your TV model. The list is long and contains a lot more like information about attached USB devices, your home network, your playtime behaviour, installed games, apps, homebrews or their so called "circumvention devices" and so on. Details about your Home network, statistics etc. "Sony is the biggest spy ever… they collect so much data. All connected devices return values sent to Sony's servers," the hacker said. He claims that Sony knows what controllers you're using, what USB devices are plugged in, what sort of television you're using – everything. Here's another section of the chat log:
That's not all: your credit card information is apparently being sent as an unencrypted text file. This is how the code is being sent to Sony:
This information is allegedly being stored online and is updated every time you turn on your system. We've been receiving reports from various sources that e-mails are being sent to those with hacked firmware even before they log back into the PlayStation Network, which is even more evidence that Sony is grabbing information from your system just from being connected to your wireless network. Generally, the PS3′s connection to PSN is protected by SSL and the identity of the remote server is verified using a list of certificates stored on each PlayStation 3 console. The credit card and other sensitive information is sent over this SSL connection. But, according to hackers, CFW could easily subvert this system. However, he has just claimed and not demonstrated to compromise PSN. In addition to this, he claims to have developed a function which will enable to get all the games, DLC, you name it at the PSN Store for free.You can read all the chat logs where the hacker and other persons named as user1, user2, user3 etc are discussing about circumventing PSN access. Thanks Gadgetsdna PSN hacked, CFW on Playstation 3 could reveal info about Credit cards is a post from: Tech Mania Related Posts : |
| You are subscribed to email updates from Tech Mania To stop receiving these emails, you may unsubscribe now. | Email delivery powered by Google |
| Google Inc., 20 West Kinzie, Chicago IL USA 60610 | |


0 comments:
Post a Comment