Recommended Posts

Really? Got a link?

Yes I'm pretty sure it has been.

Because companies can't store your CVV2 umbers.

EDIT: ok found it here http://www.neogaf.com/forum/showpost.php?p=27470004&postcount=7754 I looked it up on wikipedia and it says this:

Since the CSC may not be stored by the merchant for any length of time[3] (after the original transaction in which the CSC was quoted and then authorized and completed), a merchant who needs to regularly bill a card for a regular subscription would not be able to provide the code after the initial transaction.

Source: http://en.wikipedia.org/wiki/Card_security_code

"Rules for Visa Merchants" (PDF). p. 8.

Edited by American Ninja

I think Sony have been storing CVV2's against the rules, check this link: http://us.playstation.com/support/answer/index.htm?a_id=346

In particular pay attention to #6.

editbilling6a.jpg

Yeah they ask for it but dont store it though. Whenever I viewed my CC info the CVV2 number was always blank.

They ask for the CV2 on first use but once a purchase goes through the card is 'trusted' and they don't need the CV2 for future purchases. They also charge you a buck the first time you enter your info to verify the card number.

EDIT: News stories reporting this:

CNN BBC CTV CBC

Patrick Seybold updated the first Q&A:

+ Patrick Seybold on April 29th, 2011 at 10:43 am said:

As our friends at Destructoid pointed out, I was incorrect on the last point of the credit card question above. I want to make an important distinction: While we do ask for CCV codes, we do not store them in our database. It is transmitted to our payment processors for verification purposes only. Deep apologies for the confusion.

Source: http://blog.us.playstation.com/2011/04/27/qa-1-for-playstation-network-and-qriocity-services/#comment-549273

Congress questions Sony on hacked PlayStation network

A congressional subcommittee has sent a letter to Sony Corp. seeking information about a security attack on PlayStation?s online network by hackers last week.

Addressed to Sony Chairman Kazuo Hirai, the letter requested answers to a detailed list of questions regarding the breach, which exposed the personal information and possibly credit card data of 77 million customer accounts.

The letter, written by the House Subcommittee on Commerce, Manufacturing and Trading, addresses a number of security concerns, including when the breach occurred, how much data was stolen and why Sony waited a week before it notified customers.

The letter demanded specifics on the kind of information the hackers stole and assurances that no credit card data was swiped.

?Given the amount and nature of the personal information known to have been taken, the potential harm that could be caused if credit card information was also taken would be quite significant,? the letter said.

The subcommittee set a May 6 deadline for a reply.

Sony?s admission has drawn a firestorm of anger from customers and lawmakers alike. Rep. Edward J. Markey (D-Mass.) on Wednesday compared the breach to thieves playing the video game Grand Theft Auto with highly sensitive personal information.

The PlayStation network has been down for almost two weeks and it?s unclear when the service will be fully revived.

Sony could not immediately be reached for comment.

Good, just keep debunking nonsense quickly before it spreads like wildfire.

Good, just keep debunking nonsense quickly before it spreads like wildfire.

I think it's a bit late for that - I do agree, they should've acted sooner but it seems to be a major flaw in every company nowadays, let it be Sony, Google, Apple or Microsoft - they never come with the facts fast enough or only after some considerably shaking.

Sony's Hirai to hold news conference on data theft

(Reuters) - Sony Corp's Executive Deputy President Kazuo Hirai will hold a news conference on Sunday on a massive security breach of its popular PlayStation Network, the Japanese electronics giant said.

Hirai will speak at 2:00 p.m. Japan time (09:00 a.m. ET) about the breach, as well as the firm's information management system and the schedule to resume services, Sony said in a news release on Saturday.

The Japanese electronic giant warned this week that hackers had stolen names, addresses, and possibly credit card details from the 77 million user accounts of its video game online network in one of the largest Internet security break-ins ever.

The firm, which shut down the network on April 19, could face legal actions after it delayed disclosing the security breach information. Its shares fell nearly 5 percent in Tokyo on Thursday.

http://www.reuters.com/article/2011/04/30/us-sony-idUSTRE73R0Q320110430

Edit: the 9am ET time doesn't sound right? 2pm Japan time is 6am UK time...so US time has got to be even earlier that morning on Sunday, or late tonight (Saturday).

genuine?

I'd remove those links off of Neowin, even if not related to PSN/fake, they could be peoples details from elsewhere.

On a related note do passwords on PSN not need to be 8 characters long?

Almost 2 weeks with service?! Why can other free services like steam offer protection against things like this, but sony can't?

Because they weren't targeted by this expert hacker. This is exceptional.

Kazuo Hirai will brief media on Sunday

Hirai, in line to succeed CEO Howard Stringer, will hold a news conference in Tokyo at 2:00 p.m. (1 a.m. EDT) on Sony's investigation of the case, its information management system and the schedule to resume services, the firm said in a news release on Saturday.

Source: http://www.reuters.com/article/2011/04/30/us-sony-idUSTRE73R0Q320110430

Almost 2 weeks with service?! Why can other free services like steam offer protection against things like this, but sony can't?

It's pretty much guaranteed that your details have been exposed somewhere by some hack/intrusion and you haven't been told about it.

The fact that you don't know doesn't mean it hasn't happened.

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • BrowserOS 0.46.0 by Razvan Serea BrowserOS is a free, open-source Chromium-based browser that runs AI agents natively, offering a smarter, more productive browsing experience. It supports Chrome extensions and integrates AI agents to automate tasks, fill forms, and streamline workflows. Your data stays on your computer: you can use your own API keys or run local models via Ollama, making it a privacy-first alternative to tools like Perplexity, Comet, or Dia. With built-in productivity tools and app integrations, BrowserOS boosts efficiency while keeping control firmly in your hands. Being Chromium-based, BrowserOS lets you effortlessly import your bookmarks, passwords, and Chrome extensions in just a few clicks. BrowserOS works with OpenAI GPT models, Anthropic Claude, Google Gemini, and local AI models via Ollama or LMStudio. You can use your own API keys and effortlessly switch between providers. BrowserOS Agent Your AI productivity assistant that organizes and manages your browsing effortlessly Quickly list, group, or close tabs Save and resume browsing sessions Search your history and organize bookmarks Switch instantly to the tab you need BrowserOS Navigator – Automate web tasks with ease Navigate websites and search automatically Interact with pages without manual effort Handle repetitive tasks in seconds What makes BrowserOS special Feels like home - same familiar interface as Google Chrome, works with all your extensions AI agents that run on YOUR browser, not in the cloud Privacy first - bring your own keys or use local models with Ollama. Your browsing history stays on your computer Open source and community driven - see exactly what's happening under the hood MCP store to one-click install popular MCPs and use them directly in the browser bar (coming soon) Built-in AI ad blocker that works across more scenarios! BrowserOS 0.46.0 changelog: Run Claude Code & Codex right in your browser — We've extended the agent harness to bring full coding agents into BrowserOS. Claude Code and Codex now come bundled and plug straight into the assistant, so you can drive your browser with the agent — and the subscription — you already use. A brand new experience — A redesigned new tab, a calmer composer, and a rebuilt command center for switching between agents. The whole assistant is cleaner, faster to reach, and easier to live in. New MCP tools — We rebuilt the browser tool surface from the ground up — a tighter, more reliable set of tools for agents to drive the browser. Plus one-click install of BrowserOS as an MCP server into the agents you already run, with automatic URL sync. Chromium 148 — Updated to the latest Chromium base with all recent upstream fixes and security patches. Streamlined — We've pulled back a few features that weren't getting much use — Skills, Soul, and Memory — so we can focus and ship better versions of them soon. Download: BrowserOS 0.46.0 | 181.0 MB (Open Source) Download: BrowserOS for macOS | 485.0 MB Links: BrowserOS Homepage | Github | Screenshot Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • Microsoft finally admits its default Windows 11 25H2, 24H2 action broke key legacy component by Sayan Sen Microsoft last week released Windows 11 KB5094126 and KB5093998 as the latest Patch Tuesday updates. Following that the company also published the accompanying dynamic updates under KB5094149, KB5095971, and KB5094156. So far the company has acknowledged two known issues that have popped up after the release which include bugged-out Office apps as well as the Recycle Bin; though there could be more at play too. Speaking of bugs and issues, Microsoft seems to have finally acknowledged a problem that probably has been around for close to a year. That's because back in July of 2025 the company made a default change to the latest Windows 11 versions, wherein it switched to JScript9Legacy on Windows 11 24H2 and later releases. Hence following the release of version 25H2 in October 2025, JScript9Legacy also remained default-enabled. As a result there has been a compatibility issue ever since then. For those wondering, by switching to JScript9Legacy Microsoft intended to improve the security of modern Windows PCs by reducing vulnerabilities tied to legacy scripting like cross-site scripting (XSS), among others. XSS exploits can allow cyber-attackers to attach malicious code onto legitimate websites and use them to execute the code when a potential victim loads such a website. Hence the new JScript9Legacy engine enforced stricter execution policies and improved object handling, which should help mitigate such attacks. Microsoft today has published a new support article detailing the problem. Neowin spotted it while browsing. The company says that JScript global definitions and execution context may fail to persist across scripts, potentially breaking older dependent apps and web-based components that relied on this legacy behavior. In the article Microsoft has confirmed that the issue stems from its move away from the older jscript9.dll engine in favor of jscript9legacy.dll. As mentioned above, while the newer engine was designed to address vulnerabilities and strengthen security it also changes how JScript handles execution context. As a result functions and definitions loaded by one script could no longer remain available to subsequent scripts once execution ended. The company notes that some applications worked correctly on earlier Windows versions because the older JScript engine automatically retained global definitions and execution state between scripts. Under the newer model though that behavior is disabled by default causing certain legacy workloads and polyfill-dependent scripts to fail. Microsoft says it addressed the problem via the KB5077241 update though the fix had not been enabled automatically in the following updates. As such admins must explicitly turn on persistent JScript execution context using a Registry setting that the tech giant shared today. The configuration can be applied to individual processes or system-wide through the FEATURE_ENABLE_PERSISTENCE registry key. The steps have been outlined below: Run the following command to create the feature control registry key: reg add "HKLM\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ENABLE_PERSISTENCE" Under this key, create a new DWORD (32-bit) value. Configure the value as follows: To enable persistence for specific processes only: Set the value to 1 for each target process name. To enable persistence for all processes: Add * as the key name and set its value to 1. You can find the official support article here on Microsoft's website.
    • The possibility that milk gathers back into a glass implies that gravity can be 'reversed'.
  • Recent Achievements

    • Week One Done
      Jordan Smith earned a badge
      Week One Done
    • Reacting Well
      BizSAR earned a badge
      Reacting Well
    • First Post
      AndreaB earned a badge
      First Post
    • Week One Done
      Huge Trailer earned a badge
      Week One Done
    • Week One Done
      Classifyskilleducation earned a badge
      Week One Done
  • Popular Contributors

    1. 1
      +primortal
      590
    2. 2
      +Edouard
      186
    3. 3
      PsYcHoKiLLa
      76
    4. 4
      Michael Scrip
      73
    5. 5
      Steven P.
      66
  • Tell a friend

    Love Neowin? Tell a friend!