Report: Sony’s PSN password website suffers from an exploit
A report over on Eurogamer states that Sony’s PSN password reset system contains an exploit which could potentially allow someone to change a customer’s PSN password using the accounts stored email and the user’s date of birth.
Due to the exploit, Sony has made PSN sign-in unavailable on some of its websites, including: PlayStation.com, the PlayStation forums, PlayStation Blog, Qriocity.com, Music Unlimited via the web client, and all PlayStation game title websites.
“Unfortunately this also means that those who are still trying to change their password via Playstation.com or Qriocity.com will be unable to do so for the time being,” Sony said on the EU forums. “This is due to essential maintenance and at present it is unclear how long this will take.
“In the meantime you will still be able to sign into PSN via your PlayStation 3 and PSP devices to connect to game services and view Trophy/Friends information. Clarification: this maintenance doesn’t affect PSN on consoles, only the website you click through to from the password change email.”
Nyleveia.com, which first found the exploit, suggested folks secure their accounts by creating a new email that would not be used anywhere else other than through PSN.
The site also suggested users switch their current PSN accounts over to a newly created email address.
“You risk having your account stolen, when this hack becomes more public, if you do not make sure that your PSN account’s email is one that cannot be affiliated with or otherwise traced to you,” said the site.
The site contracted Sony on the matter, and noted that the system “went down approximately 15 minutes,” after it received a respoce from SCEE.
Sony has since pulled the password reset website in the hopes of fixing the issue. Hopefully all will be straightened out soon, and the site will be back up.
http://www.vg247.com/2011/05/18/repo..._content=games