Xbox Live was not hacked. It had been conned. |
Ó
This is an update to Major Nelson's head hitting the roof after hearing reports of fraud over Xbox Live and fearing that the network had been hacked. Xbox Live staff had gotten back to him and reconfirmed it: Xbox Live was not hacked, period (oh, thank goodness). The bad news was that Xbox Live was the victim of a commonplace e-commerce and computer security crime: social engineering.Or, put more simply, they've just been had. (Oh, holy...)
Let's make this quick: social engineering "is a collection of techniques used to manipulate people into performing actions or divulging confidential information." In this case, it's con artistry over a fiber-optic cable.
It seems that Xbox Live's support staff had been conned into revealing account information they would not have done so otherwise. The Major mentions some "painful-to-listen-to audio files": probably the full voice evidence of their own people getting hit by a truck and not even knowing it. It happens to the best of us, really (try visiting a convention for hackers or computer security, and ask about it).
As renowned (and reformed) former black hat hacker Kevin Mitnick so casually remarks (but not with these words), it's a hell of a lot easier to dupe, lube, or seduce the password out of your victim than to hack into his or her PC.
Currently, Xbox Live engineers are training the customer support staff and partners to reduce their vulnerability to social engineering-type attacks. And it would be wise to repeat the earlier warning he gave: don't just give your personal information out to anyone, although in this case it's the support staff who have learned this lesson the hard way.
We're not one to believe that there's a sucker born every minute. Sometimes, it's more like the devil inside is way more powerful than the better angels of our nature, whether up close and personal, or reaching out to touch someone.
Contact Us:
The QJ.net Network |
|
| Site | Feed |
| QJ.NET | RSS |
| Nintendo DS | RSS |
| PlayStation 3 | RSS |
| PSP Updates | RSS |
| Wii | RSS |
| Xbox 360 | RSS |
| MMORPG | RSS |
| Personal Computer Games | RSS |
| iPhone - iPod Touch | RSS |
| QJ.NET Forums | RSS |
User Favorites - December
User Favorites - December
| Top Jumps | |
| Custom Firmware 5.50GEN-D3.. | (2708) |
| Custom Firmware 5.50GEN-D3.. | (1014) |
| Custom Firmware 5.50GEN-D3.. | (516) |
| Tiger Woods Wife Outrun Fl.. | (504) |
| MaGiXieN: 6.xxGEN is not w.. | (410) |
| MaGiXieN explains release.. | (358) |
| Custom Firmware 5.03GEN-C.. | (302) |
| PSP Homebrew: CFW 5.03 GEN.. | (209) |
| Custom firmware 5.50GEN-D.. | (171) |
| Wii homebrew - Custom IOS3.. | (109) |
| PSP Revolution v0.3 | (96) |
| Naruto Shippuden: Ultimate.. | (92) |
| PS3 optional update 3.15 d.. | (85) |
| No plans for custom firmwa.. | (85) |
| PSP homebrew - DaedalusX64.. | (84) |
| PSP Homebrew - PSPDisp v0... | (82) |
| Resident Evil 5 patch 1.03.. | (82) |
| PSP homebrew game: PSP Mar.. | (74) |
| Sony starts talking about.. | (73) |
| gpSP v0.9 for the PSP | (71) |
| PS3 is year's best platfor.. | (70) |
| Sony files curious new tra.. | (66) |
| Sony sells 440,000 PS3 uni.. | (66) |
| PSP homebrew - DaedalusX6.. | (66) |
| PSPlayerMT For PSP - Direc.. | (66) |
Categories
Archives
December 2009
November 2009
October 2009
September 2009
August 2009
July 2009
June 2009
May 2009
April 2009
March 2009
February 2009
January 2009
December 2008
November 2008
October 2008
September 2008
August 2008
July 2008
June 2008
May 2008
April 2008
March 2008
February 2008
January 2008
December 2007
November 2007
October 2007
September 2007
August 2007
July 2007
June 2007
May 2007
April 2007
March 2007
February 2007
January 2007
December 2006
November 2006
October 2006
September 2006
August 2006
July 2006
June 2006
May 2006
April 2006
March 2006
February 2006
January 2006
Comments
isnt that still hacking? sort of like saying, i wasnt drunk because i can still drive.
Using Social Engineering to compromise accounts is still a form of hacking. It taught in basic network security. Some of the best hackers in the world dont steal accounts, people give it to them willingly. Microsoft messed up and they dont want to admit it. So they call it a con. I guess they just dont want to admit that they got hacked and peoples accounts got compromised. An isolated incidence would mean maybe a dozen accounts. But when your talking about more then a dozen, then its a flaw, anymore and its been compromised.
Yeah, um.. people giving out personal account information from a company is terrible. It is far worse than simply having a server or whatever taken over. If I was anyone that had their account seize or anything, I would find out exactly what happened immediately. Better safe than sorry. You have no idea what information they might have given out.
those mother*****ers beter not give out my account information mother*****ers with a company like microsoft couldn't they have hired non retarded operators?
i believe "microsoft" and "retarded" go hand in hand.
so true
Add New Comment