Threat of the month: PlayStation breach

Randy Abrams, ESET
Randy Abrams, ESET
What is it?
The Sony PlayStation Network/Qriocity service breach of 77 million records contained a twist that makes it dangerous.

How does it work?
Not only were names, email addresses, billing addresses and passwords leaked, but the answers to security reset questions were leaked as well. This means that simply changing a password on the Sony network isn't going to protect other accounts that use challenge questions.

How can I prevent it?
If you are/were a user of the service, then you need to check all of your other accounts to see if you have password reset or security questions and change them if they are the same questions as used by Sony. I have long advocated using incorrect answers because the right answers are often easy to guess or learn. In this case, if you used the same wrong answer in other places in addition to Sony, you'll need to change those too.

More in Features

Behind the scenes: Privacy and data-mining

Behind the scenes: Privacy and data-mining

With data-mining firms harvesting personal information from online activity, privacy advocates, if not yet consumers, are alarmed, reports James Hale.

The great divide: Reforming the CFAA

The great divide: Reforming the CFAA

Aaron Swartz's death inspired Rep. Zoe Lofgren to want to reform the federal anti-hacking law, but some security pros worry this would sterilize a potent enforcement weapon, reports Dan Kaplan.

Suspect everything: Advanced threats in the network

Suspect everything: Advanced threats in the network

Are there ways to catch sophisticated malware that hides in trusted processes and services? Deb Radcliff finds out.