joeorc said:
and yet that was not good enough for some hacker's! the problem is Sony is being viewed as the Bad guy here and they are trying to protect consumer's you may not think so but with security professional's stating something like this that Even salted encryption may not be enough : PCIDecember 11, 2007Hashing Credit Card Numbers: Revisited AgainI recently had to revisit the estimates I provided in our white paper on brute forcing credit card hashes since new techniques were published that can speed the brute forcing up by at least a factor of 5 using off-the-shelf video cards. Well, a month later I am having to revise the estimates again. Nick Breese of New Zealand has published a paper at Kiwicon on using a PlayStation 3 to crack hashes. His estimates are about 1.4 billion hashes per second for MD5. Our proof of concept code running at about 2 million hashes per second seems kind of slow now. Probably at least 2 billion hashes per second is feasible in the near future with readily available hardware and source code.
Storing credit cards using a simple single pass of a hash algorithm, even when salted, is fool-hardy. It is just too easy to brute force the credit card numbers if the hashes are compromised. Based on the potential value of the card numbers, there is more than enough financial incentive to buy a $500 PlayStation 3 and develop a little code. When hashing credit card number, the hashing must be carefully designed to protect against brute forcing by using strongest available cryptographic hash functions, large salt values, and multiple iterations. you know it's just not about only the PSN outside of PSN there is a whole lot of other web site's with encryption.
Geohot making his hack know has not only hurt ps3 gamer's and people who use the PS3 but may of infact damage other's on the web. Sony removing the Install Other OS on the ps3 with firmware update 3.21 was a precaution they would not want to be liable for.
|
That's because... Sony IS the bad guy hear.
One of two. Both Sony and the Hackers are bad guys.
The good guys are the innocent people who use Other OS who are being screwed.
I could care less about one guy doing a bad thing to get another bad guy if it leads to the innocent being hurt.
Also you know... you think the people who use the PS3 for credit card hashing are going to update their firmware? They'll just buy a slim with all their money.








