http://arstechnica.com/gaming/news/2011/04/sony-admits-utter-psn-failure-your-personal-data-has-been-stolen.ars

SONY 確認 PSN 用戶個人資料被盜,目前不清楚信用卡資料有沒有災情.
越來越慘,我想信用卡資料大概也被盜,SONY不敢認吧.沒準備好,就跟Hacker宣戰,唉.
Sony admits utter PSN failure: your personal data has been stolen
By Ben Kuchera | Last updated about 4 hours ago (April 26, 2011 15:24PST)

Sony承認PSN徹底失敗: 你的個人資料已經被幹走了(?)

Sony has finally come clean about the "external intrusion" that has caused
the company to take down the PlayStation Network service, and the news is
almost as bad as it can possibly get. The hackers have all your personal
information, although Sony is still unsure about whether your credit card
data is safe. Everything else on file when it comes to your account is in the
hands of the hackers.

Sony終於承認所謂的「外部入侵」造成PSN服務當機,其實比想像中的還要嚴重,雖然
Sony目前還不確定信用卡資料是不是有被盜,但黑客已經取得玩家們的部份個人資料,
所有有關玩家帳號的資料都已經在黑客手中。

In other words, Sony's security has failed in a spectacular fashion, and
we're just now finding out about it. In both practical and PR terms, this is
a worst-case scenario.

換句話說,對於practical和PR方面來說,這是情況很糟糕。Sony的安全系統已經出現嚴
重的漏洞,只是我們現在才知道。
(這段翻得怪怪的Sorry...orz)

What did they get?

他們拿到了什麼?

Here is the data that Sony is sure has been compromised if you have a
PlayStation Network Account:

這裡是Sony已經確定被盜的PSN帳號資料:

Your name 你的名字
Your address (city, state, and zip) 你的住址(縣市,郵遞區號)
Country 國家
E-mail address Email帳號
Birthday 生日
PSN password and login name PSN的登入帳號和密碼

"It is also possible that your profile data, including purchase history and
billing address (city, state, zip), and your PlayStation Network/Qriocity
password security answers may have been obtained. If you have authorized a
sub-account for your dependent, the same data with respect to your dependent
may have been obtained," Sony announced. While the company claims that there
is "no evidence" that credit card information has been compromised, it won't
rule out the possibility.

Sony表示:「關於你的個人資料,包括購買紀錄、付款地址(縣市、郵遞區號)、以及你的
PSN/Qriocity密碼的安全問題,很有可能已經被盜了。如果你曾經有連結子帳號
(Authorized Sub-Account),子帳號的相關資料可能也被盜了。」雖然Sony目前宣稱「沒
有相關證據」證明信用卡資料有被盜,但是並不排除這個可能性。

Their advice is to be safe, rather than sorry. "If you have provided your
credit card data through PlayStation Network or Qriocity, out of an abundance
of caution we are advising you that your credit card number (excluding
security code) and expiration date may have been obtained."

其實Sony應該去加強安全系統而不是在道歉。「如果你曾經有透過PSN或Qriocity輸入你
的信用卡資料,我們現在通知你你的信用卡號碼(包括安全號碼)還有有效期限可能已經
被盜了」
(啊...就只有「通知」而已喔?...)

What can you do?

你可以做什麼?

You are warned to keep watch over your accounts, and to be aware of your
heightened risk of fraud due to the security breach. "For your security, we
encourage you to be especially aware of e-mail, telephone, and postal mail
scams that ask for personal or sensitive information," the company said.
"Sony will not contact you in any way, including by email, asking for your
credit card number, social security number or other personally identifiable
information."

由於安全系統出現漏洞,建議你常常注意你的帳號狀況,並且提高警覺防範詐騙(這是
要騙啥啊不是都盜光了嗎?...)。「為了你的安全,我們建議你特別要小心透過Email
、電話、傳統郵件等等管道洩漏個人資料或敏感資訊。」Sony表示「Sony不會用任何方式
(包括Email)詢問你信用卡號碼、身份證字號或其他個人私密資訊。」
(他們不會問但是好像蠻會洩漏的...)

Sony has also provided a wealth of sources for data and protection against
identity theft.

Sony也投入了大量的資源來保護個人資料防範他人偷竊。
(呃...)

You may wish to visit the web site of the U.S. Federal Trade Commission at
www.consumer.gov/idtheft or reach the FTC at 1-877-382-4357 or 600
Pennsylvania Avenue, NW, Washington, DC 20580 for further information about
how to protect yourself from identity theft. Your state Attorney General may
also have advice on preventing identity theft, and you should report
instances of known or suspected identity theft to law enforcement, your State
Attorney General, and the FTC. For North Carolina residents, the Attorney
General can be contacted at 9001 Mail Service Center, Raleigh, NC 27699-9001;
telephone (877) 566-7226; or www.ncdoj.gov. For Maryland residents, the
Attorney General can be contacted at 200 St. Paul Place, 16th Floor,
Baltimore, MD 21202; telephone: (888) 743-0023; or www.oag.state.md.us.

(上面這串是美國聯邦貿易局等等的相關聯絡資料,不翻譯:P)

To be fair, Sony does apologize for the inconvenience. There is still no
update on when service will be restored, but that is the least of your
concerns if you have a PlayStation Network account. It's time to change your
passwords, at the very least, and if you're like to be completely safe it's
not a bad idea to cancel your credit or debit cards and request replacements.

Sony對於造成的不便感到抱歉,不過PSN修復上線後還是沒有更新,身為PSN使用者的你
建議最少要去更換密碼,如果想要更進一步的確保安全,建議去註銷信用卡或申請更換


We'll continue to follow this story as it develops.

我們會持續追蹤相關報導與開發團隊的消息。

==

所以PSN到底怎麼了囧...

一下說被Cracker入侵,一下又說要修復Rebug...?
howar31.com

howar31 wrote:
所以PSN到底怎麼了囧...恕刪)


這篇新聞稿的主要內容與用意,只是在昭告天下:

我,SONY,知道這次PSN被駭是個嚴重問題,
而且越深入調查發現安全漏洞破很大,大到公司找不到從何修起.......

這算討饒文+求救文+取暖文嗎?
忠實PS資深玩家的悲哀......
哇咧。。。

真的是如此那索尼要如何賠呀。。。
商譽的損傷真是大呀。。。

那PSP GO 。。以後不就只敢買點卡了。。
有一群強盜進入一家商家,把人殺了,把東西搶了,把商店砸了,
大家都在怪商店門禁沒做好,危機意識太低,商店受愴嚴重無法營業,
大部份的人都怪商店,但譴責強盜的人卻很少.
sgconduty wrote:
有一群強盜進入一家商...(恕刪)


你是在暗喻美國老大的行事作風嗎? 哈哈 真逗.

P.S 假如你是世界超強,沒錯你就是橫行天下 不受法律約束.

sgconduty wrote:
有一群強盜進入一家商...(恕刪)


PS STORE才是商店
PSN的電子錢包或是信用卡資料像是銀行
銀行被搶
而且是非常輕易的被搶
我們會譴責搶匪
同時也要質疑銀行是否沒有盡到保管客戶財產的職責

AlgerChen wrote:
你是在暗喻美國老大的行事作風嗎? 哈哈 真逗.

P.S 假如你是世界超強,沒錯你就是橫行天下 不受法律約束....


你這樣講也沒錯,美國的行徑和駭客也沒啥兩樣,
先警告你,你不聽話我就攻擊你,你真的不聽話?我就真的打你,
以前看終極警探4都是笑一笑哪有可能這樣,
現在看到PSN被攻擊,7500萬人突然間沒PSN,你看看有多少人沒PSN後PS3就跟廢物一樣,
那萬一駭客攻擊的是銀行體系,突然間,你多年存款就不見了,別說這不可能,這是很有可能的,
成也網路,敗也網路.
其實在幾個月前,早就有駭客提出警告,PSN的客戶資料結構格式而且取得非常的容易,也取笑SONY的小學生網路程度,後來SONY好像不當作一回事,繼續跟那些駭客玩貓抓老鼠的遊戲,找FBI來抓人上法院,無形中又樹立許多敵人,也試著拿著高薪找一些知名的駭客到SONY上班,但沒有一個肯賞臉,完全沒把心思放在強化PSN上,前陣子好不容易把Geohot大神摸頭成功,好像事情會這樣結束了,但潑出去的水(金鑰)難收回啊…

只能說SONY在這件事上需要付出最大的責任,或許可以請微軟當顧問也不錯…

對了,快去把PSN上註冊的信用卡停掉吧…
emule2006 wrote:
其實在幾個月前,早就...(恕刪)

SONY 的 PSN 在這次事件後, 應該全面採用付費制度了.
SONY 當初八成是因為網路服務是免費的,
所以不想燒太多錢在網路這邊.

現在出這麼大的包, 希望 SONY 能有所警惕.
文章分享
評分
評分
複製連結

今日熱門文章 網友點擊推薦!