Xbox password flaw exposed by five-year-old boy

4.6
A five-year-old boy who worked out a security vulnerability on Microsoft's Xbox Live service has been officially thanked by the company.

Kristoffer Von Hassel, from San Diego, figured out how to log in to his dad's account without the right password.
Microsoft has fixed the flaw, and added Kristoffer to its list of recognised security researchers.
In an interview with local news station KGTV, Kristoffer said: "I was like yea!"

The boy worked out that entering the wrong password into the log-in screen would bring up a second password verification screen.
Kristoffer discovered that if he simply pressed the space bar to fill up the password field, the system would let him in to his dad's account.

Kristoffer's name now appears on a page set up to thank people who have discovered problems with Microsoft products.
The company also gave him four free games, $50 (£30), and a year-long subscription to Xbox Live.

Posted:
Related Forum: Xbox Forum

Source: http://www.bbc.co.uk/news/technology-26879185

Comments

"Xbox password flaw exposed by five-year-old boy" :: Login/Create an Account :: 115 comments

If you would like to post a comment please signin to your account or register for an account.

XenoChristPosted:

I hope that kid enjoys his little kinect games.

ResortPosted:

Wow thats kinda weird that the kid new to report this problem to xbox. Good for him

aMixcrashPosted:

"I was like yea!" - We shall remember his quote

VacPosted:

LOL this is really funny

MRMURK4G3Posted:

You think with all of the money they have they would have given him more than that, if this was someone else then this could have been a threat to a lot of peoples accounts. But still glad its sorted now :D

LAUGHING_TAC0Posted:

people dont get it do they lol like someone else stated you really think a 5 year tried to find a "loop Hole" no complete accident prolly was trying to sign into his dads account couldnt see he just tried random things, as i see it, it ALL had to do with luck, and thats one lucky kid there, and it would of been a matter of time b4 someone else found. Hate on me all you want just stating what i believe to be true.

FamousPosted:

Wow just wow a five year old found that, that is insane.

Tesla_FanPosted:

tattooedsins I still wonder why people keep supporting this money hungry company and xbox 360/xbox one.. wake up people


You playstation fanboys just never let up do you? always criticizing and taking shots at xbox whenever you possibly can, why? does it make you feel good? criticizing a console just shows how jealous you are of it clearly, if the playstation is so superior then why do you keep mentioning anything about xboxs? just enjoy your superior console to yourself. LOL

And your entire network was hacked so you cant even talk ROFL

FluffyisEpikPosted:

-CP They owe that kid a hell of a lot more.


Not really it wasn't a major flaw or something that people were taking advantage of.

Evo8Posted:

-CP
tattooedsins I still wonder why people keep supporting this money hungry company and xbox 360/xbox one.. wake up people


You are the one who needs to "wake up". The whole point of a business is to make money, not lose it. I hate communists like you who put down others for chasing the money.


Yeah I will never understand people like this. "That business needs to stop trying to make money."