Random Homebrew: Monkey 64
Nintendo 64 emulator
Friends: Coding 'n Cracking - Nymphaea - PS3 Forum - darkforestgroup - daxhordes.org - Tgames - coldbird - gopsp.it - pspstation.org - prometheus - hgoel.info - MakeSmartTV - ps vita

Sony keeps username & password in plain text format

Post crashes / information about (potential) security issues over here! Sensitive information might be deleted without notice.

Re: Sony keeps username & password in plain text format

Postby Coldbird » Mon Oct 03, 2011 9:49 pm

Damn... now I REALLY beg users NOT TO use non PRO builds of PROCFW...
This could be exploited in so many bad ways by building a manipulated PROCFW which logs this...
Image
PSP N-1000 ✔ / 6.20 PRO NIGHTLY ✔ / PRO ONLINE ✔

READ THE TRUTH ABOUT THE VITA KERNEL EXPLOIT
User avatar
Coldbird
Guru
 
Posts: 460
Joined: Sun Nov 14, 2010 12:33 am

Re: Sony keeps username & password in plain text format

Postby bpeterson » Mon Oct 03, 2011 9:51 pm

Good find. I wouldn't be surprised, if it worked the same way on the PS3.
Follow me on Twitter: http://twitter.com/bpetersondev
bpeterson
 
Posts: 63
Joined: Wed May 18, 2011 7:17 pm

Re: Sony keeps username & password in plain text format

Postby ViP3R » Tue Nov 29, 2011 11:05 am

Next time it's uncle sam's redeem codes in there. Why can't they store in it in generally, the "Sony-type-of-encryption" a.k.a. keeping them in .prx *oh God it's even worst than that... Or some sort they can figure out.

bpeterson wrote:Good find. I wouldn't be surprised, if it worked the same way on the PS3.

Meh, i dont know but, who knows if they're lazy as hell to store them in the HDD :roll:
Goodbye, Captain John "Soap" Mactavish
And Goodbye, Joe Frazier - thanks for encouraging me to have my own PSP
User avatar
ViP3R
 
Posts: 1331
Joined: Fri Dec 31, 2010 8:55 am
Location: Flash0:/Philippines

Re: Sony keeps username & password in plain text format

Postby Casavult » Tue Nov 29, 2011 2:29 pm

Hmmm, I could use this to get my brothers PSN details from his PSP. :lol:

But seriously, this sort of stuff should be heavily encrypted, but hey this is Sony...
PSP 1000 32GB PRO-HG Duo TA-082 6.60 CFW ME 1.8 and (L)CFW PRO-C fix3 + TM and DDC v8/v9 Mod
PSP 1000 8GB PRO-HG Duo TA-079 5.00 CFW M33-6 + Fix, TM and DDC v8/v9 Mod
PS Vita 32GB 3g + Wi-fi PCH-1103 2.02 OFW ARK eCFW

Forum Rules. Read them first!
User avatar
Casavult
Moderator
 
Posts: 2564
Joined: Wed Jun 08, 2011 4:22 pm
Location: London, UK.

Re: Sony keeps username & password in plain text format

Postby Kaliki » Fri Dec 02, 2011 1:22 pm

Casavult wrote:But seriously, this sort of stuff should be heavily encrypted, but hey this is Sony...

I agree, there should indeed be a lot more secure protection on this. But you can't really blame Sony because the risk only exists if you are using CFW, which is not supported by Sony's tech people. Otherwise, practically everyone can put TCFW on other peoples PSP's in seconds nowadays... :?
Security guy of Sony says: "I lost my keys.... some one found my keys?" (as found on Hellcat's twitter)
Kaliki
 
Posts: 87
Joined: Tue Jan 11, 2011 12:30 am

Re: Sony keeps username & password in plain text format

Postby m0skit0 » Mon Dec 05, 2011 8:47 am

Kaliki wrote:But you can't really blame Sony because the risk only exists if you are using CFW, which is not supported by Sony's tech people.

I'm sorry but... WHAT? What about Sony reading your pass and stuff? And IIRC, Sony's servers also kept your personal data in plain text, so yeah, Sony is to blame, definitely. And even if not, any decent technology company will store your personal data encrypted. Even on a portable device. Shame on Sony.

And to everybody: please stop lickin' corporations' a**, you don't owe them anything.
I wanna lots of mov al,0xb
Image
"just not into this RA stuffz"
User avatar
m0skit0
Guru
 
Posts: 4787
Joined: Mon Sep 27, 2010 6:01 pm

Re: Sony keeps username & password in plain text format

Postby FrEdDy » Mon Dec 05, 2011 8:15 pm

m0skit0 wrote:
Kaliki wrote:But you can't really blame Sony because the risk only exists if you are using CFW, which is not supported by Sony's tech people.

I'm sorry but... WHAT? What about Sony reading your pass and stuff? And IIRC, Sony's servers also kept your personal data in plain text, so yeah, Sony is to blame, definitely. And even if not, any decent technology company will store your personal data encrypted. Even on a portable device. Shame on Sony.

And to everybody: please stop lickin' corporations' a**, you don't owe them anything.

Yes, Sony stored sensitive PSN information in plaintext. No matter where they store your information, it should be always protected.
https://github.com/freddy-156
<@n00b81> FREDDY CUTTIES
User avatar
FrEdDy
HBL Collaborator
 
Posts: 349
Joined: Mon Sep 27, 2010 7:08 pm

Re: Sony keeps username & password in plain text format

Postby ViKtory » Tue Dec 06, 2011 6:56 pm

I guess this is why PSN got hacked so easily.
User avatar
ViKtory
 
Posts: 1103
Joined: Wed Aug 17, 2011 8:07 pm
Location: India

Re: Sony keeps username & password in plain text format

Postby Kaliki » Tue Dec 06, 2011 11:06 pm

m0skit0 wrote:And even if not, any decent technology company will store your personal data encrypted.

That got me thinking. It's obviously right. I still wonder why many consumers don't care more often about giving away their personal data. But that's a different story.
Security guy of Sony says: "I lost my keys.... some one found my keys?" (as found on Hellcat's twitter)
Kaliki
 
Posts: 87
Joined: Tue Jan 11, 2011 12:30 am

Re: Sony keeps username & password in plain text format

Postby toBsucht » Sun Mar 18, 2012 7:33 pm

So if anyone share his nan dump with login data people can get it easy?! btw i think you know that thiere is a hb to get those data
viewtopic.php?f=2&t=2624 HomeBrews working with 6.xxhen/cfw
viewtopic.php?f=2&t=1879 signed HomeBrew list \ close to all files @ mediafire.com/toBsucht

PsP-cfw-online url
User avatar
toBsucht
VIP
 
Posts: 1691
Joined: Wed Dec 29, 2010 8:15 am

Previous

Return to Security

Who is online

Users browsing this forum: No registered users and 1 guest