What's new
Off Topix: Embrace the Unexpected in Every Discussion

Off Topix is a well established general discussion forum that originally opened to the public way back in 2009! We provide a laid back atmosphere and our members are down to earth. We have a ton of content and fresh stuff is constantly being added. We cover all sorts of topics, so there's bound to be something inside to pique your interest. We welcome anyone and everyone to register & become a member of our awesome community.

Xbox password flaw exposed by five-year-old boy

Jazzy

Waiting....
Member
Joined
Jan 27, 2010
Posts
71,573
Reaction score
1,221
Points
2,125
A five-year-old boy who worked out a security vulnerability on Microsoft's Xbox Live service has been officially thanked by the company.

Kristoffer Von Hassel, from San Diego, figured out how to log in to his dad's account without the right password.

Microsoft has fixed the flaw, and added Kristoffer to its list of recognised security researchers.

In an interview with local news station KGTV, Kristoffer said: "I was like yea!"

The boy worked out that entering the wrong password into the log-in screen would bring up a second password verification screen.

Kristoffer discovered that if he simply pressed the space bar to fill up the password field, the system would let him in to his dad's account.

"I got nervous. I thought he was going to find out," Kristoffer told television station, KGTV.

"I thought someone was going to steal the Xbox."

Dad Robert - who works in security - sent details of the flaw to Microsoft.

In a statement, the company said: "We're always listening to our customers and thank them for bringing issues to our attention.

"We take security seriously at Xbox and fixed the issue as soon as we learned about it."

Kristoffer's name now appears on a page set up to thank people who have discovered problems with Microsoft products.

The company also gave him four free games, $50 (£30), and a year-long subscription to Xbox Live.

Source

Wow, smart five year old. Glad Microsoft gave him recognition and rewarded him.
 
Heh, great security there!
 

Create an account or login to post a reply

You must be a member in order to post a reply

Create an account

Create an account here on Off Topix. It's quick & easy!

Log in

Already have an account? Log in here.

Back
Top Bottom