Sony PlayStation Network Security Flaw Unfixed After 6 Months

Sony has not fixed a critical PlayStation Network security flaw allowing account takeovers via transaction numbers, six months after initial reporting.

Sony PlayStation Network Security Flaw Unfixed After 6 Months

Sony has not addressed a critical security vulnerability in the PlayStation Network account ownership verification system, six months after the issue was first reported. The flaw allows attackers to seize control of user accounts by exploiting transaction numbers. This bypasses two-factor authentication and passkeys, leaving user data and digital libraries exposed.

Journalist hacked again proving bug can be re-exploited indefinitely

Journalist Nicolas Lellouche recently had his PlayStation account compromised again. He had previously reported the vulnerability, which went viral globally. Sony temporarily flagged his account as high-risk, but the attacker still managed to take over the account. The new attacker did not change the account ID, proving the bug can be re-exploited indefinitely.

Lellouche stated that the vulnerability makes it easy for hackers to change the account email. Attackers can disable the old email and delete access keys without proper verification. He warned that users can no longer use their games with peace of mind because the digital titles risk disappearing permanently.

The journalist expressed despair over Sony's response to the ongoing crisis. He criticized the company for acting as if there is no problem despite the persistent threat. The ease with which account ownership can be transferred highlights a fundamental failure in the platform's security protocols.

Discussion

0 comments

Log in to join the thread with a thoughtful take, question, or correction.

Add to the discussion