• Ever wanted an RSS feed of all your favorite gaming news sites? Go check out our new Gaming Headlines feed! Read more about it here.

Cranster

Prophet of Truth
Banned
Oct 25, 2017
9,788
We'll file this one under the "major screw up" category, as it seems Sony has been left vulnerable for years now there has been an exploit that has potentially been costing consumers and allowing thieves to profit. Due to the nature of this PlayStation Security exploit, we won't disclose how to actually do it since, y'know, it's illegal. However we do hope this stirs up awareness for Sony, which according to a user who's filed a claim, that the exploit is still not being acknowledged.

Basically, how the exploit operates is that typically, PSN requires all credit cards to supply them with their CVV security number. When you normally operate PSN this isn't something the system typically requests, but when you log in from a different console it will ask you for this CVV number before you can proceed to log-in. However due to a very easy exploit, if a thief was to get their hands on another PlayStation user's account, they could potentially rack up victim's credit cards without even knowing their CVV number as the bug bypasses the requirement, allowing users to buy content from another account.


"It isn't an exploit with the consoles, it's an exploit with the network" one modder told us in a private message. When we asked a particular user why this exploit is only coming out today in the form of a YouTube video, their response was rather shocking in stating that Sony simply did not care unless it was made public. This exploit has allegedly been around roughly for five full years. The user had claimed that they had sent Sony the exploit in the past, via their own hacking disclosure program, hackerone. The user eventually ended up getting a response that informed them that the exploit served no security risk and was simply fraud. This email was from just today as you can read below.

psn-exploit-l.jpg



If this is true then Sony really needs to get this exploit fixed.
 

entremet

You wouldn't toast a NES cartridge
Member
Oct 26, 2017
59,970
I wonder if people remember the 2011 PSN security breach.

Sony and security man lol.
 

Maximus

Member
Oct 27, 2017
3,586
Jeez that crazy, super important to monitor your purchase history or turn off purchase notifications...
 

Kolx

Member
Oct 25, 2017
8,505
The exploit was there for 5 years and Sony ignored it? Either this's complete BS, or Sony have some serious explanation to do.
 

BasilZero

Banned
Oct 25, 2017
36,343
Omni
Good thing I've never used credit card or anything tied to my account for PSN purchases.


This is why I love buying PSN Wallet credit from store lol.
 
Oct 27, 2017
2,471
But if somebody has access to your PSN account, then don't you have bigger issues to worry about anyway? Not sure I'm following this correctly.
 

Rowsdower

Prophet of Truth - The Wise Ones
Avenger
Oct 27, 2017
16,549
Canada
So this can only be done if someone gets your PSN account info?

Well, time to make a super long random character password.

Also never save credit card info on PSN, that's asking for trouble.
 

BrickArts295

GOTY Tracking Thread Master
Member
Oct 26, 2017
13,728
Friendly reminder that everyone should double check that they have two factor authorization and remove their CC from their account.

*Sigh* Time to make another tongue twister password.
 

Shoot

Member
Oct 25, 2017
4,528
I wonder if people remember the 2011 PSN security breach.

Sony and security man lol.
I remember it quite well. That is why I am not surprised by this in the slightest. Anyone who uses the PS store for any amount of time can also tell that its software is held together by duct tape. The sad fact is that Sony is raking in money through PSN with minimal effort they do not care.
I don't leave anything connected. I use and delete.
I have doing the exact same thing as well.
 

Eggman

Banned
Apr 16, 2018
557
The amount of people aren't going to actually read or comprehend this is already too big. This is only an issue if your account is already compromised, this isn't a way for someone to "hack" your account.
 
Oct 25, 2017
4,426
Silicon Valley
So the exploit is... if someone gets hold of your account, and you have a card on the account, they can make purchases?

Um, duh? Isn't this why you enable 2FA and monitor your purchases?

Wat
 
Oct 30, 2017
5,006
You'd think Sony would take Network and financial security very seriously considering, you know, the month long fuck up back in 2011 because they were too stupid to actually secure their fucking network.
 

nolifebr

Banned
Sep 1, 2018
11,465
Curitiba/BR
Does PSN ever required the credit card security code for every purchase?

As far as I can remember, they only ask for the PSN account password before finalizing a purchase. The security code is only requested once when the card is added.
 

Jahranimo

Community Resettler
Member
Oct 25, 2017
9,002
I hope no one actually keeps a payment method stored on their console...right????
 

Rowsdower

Prophet of Truth - The Wise Ones
Avenger
Oct 27, 2017
16,549
Canada
Does PSN ever required the credit card security code for every purchase?

As far as I can remember, they only ask for the PSN account password before finalizing a purchase. The security code is only requested once when the card is added.

Any time I make a purchase on the web store it asks me for the security code. On the console itself, it only asks for the password when buying something.
 
Oct 25, 2017
16,738
Just turn on 2FA. That's exactly what it's for. They can only do this if your account is already compromised. So either delete your payment method or enable 2FA
 

Cronogear

â–˛ Legend â–˛
Member
Oct 27, 2017
3,978
So they need to already have access to your account to do this?

This seems like a whole lot of nothing.
 

TripaSeca

Member
Oct 27, 2017
2,762
SĂŁo Paulo
Nintendo's eshop never asks for CVV too, but I don't think that's the problem. Thing is on PSN they use the card to buy content for OTHER accounts.
 

Deleted member 52823

User requested account closure
Banned
Jan 29, 2019
342
I've always had to enter my CVV to confirm purchases. Sounds bogus to me. Unless you know your CVV by heart, I mean. The story sounds dumb.

Game sharing between two different accounts is as simple as one user has PS+, the other doesn't, and you go from there. If you are starting off fresh, no trophies etc, it's a simple matter of spending an equal amount of money so you can both play online etc,

Game sharing is useful when two people want the same $60 game, but want to split costs. It's a trade off. One way or the other, someone should be helping you out, or else it's just you trying to make everyone happy.
 

Nanashrew

Banned
Oct 25, 2017
6,328
PSN is just full of holes, isn't it? After the 2011 hack, I never keep any of my stuff on their servers, and I never will.
 

Keyouta

The Wise Ones
Member
Oct 25, 2017
4,193
Canada
I never tie my credit card to any of this shit. Steam, PSN, Nintendo, etc. I can take a few seconds and enter in the information needed when I'm buying.