Xbox password flaw exposed by five-year-old boy

4.6
A five-year-old boy who worked out a security vulnerability on Microsoft's Xbox Live service has been officially thanked by the company.

Kristoffer Von Hassel, from San Diego, figured out how to log in to his dad's account without the right password.
Microsoft has fixed the flaw, and added Kristoffer to its list of recognised security researchers.
In an interview with local news station KGTV, Kristoffer said: "I was like yea!"

The boy worked out that entering the wrong password into the log-in screen would bring up a second password verification screen.
Kristoffer discovered that if he simply pressed the space bar to fill up the password field, the system would let him in to his dad's account.

Kristoffer's name now appears on a page set up to thank people who have discovered problems with Microsoft products.
The company also gave him four free games, $50 (£30), and a year-long subscription to Xbox Live.

Posted:
Related Forum: Xbox Forum

Source: http://www.bbc.co.uk/news/technology-26879185

Comments

"Xbox password flaw exposed by five-year-old boy" :: Login/Create an Account :: 115 comments

If you would like to post a comment please signin to your account or register for an account.

DiscJrPosted:

Well, at least he got something out of it's that's good.

PM-KasperPosted:

Wow. I would have never thought of this lol.

LinxPosted:

Wow i would love to see this kid in 10 years from now. lol Mega HACKER! jk

MrMw209Posted:

Thats cool

At least they gave him something for finding the secruity issue

MajPosted:

They should of said to Microsoft, " We have found a big security issue in your systems and would like $250,000 to discuss how to fix it"

DJMarkyMarkPosted:

It's pretty crazy that this was discovered by a 5 year old but I doubt too many people were trying to find a way around the password.

Microsoft could of given him more than just a few games and a year of Xbox Live though.

InvictusPosted:

This little kids a genius.

DusknoirPosted:

Hearthstone That just goes to show how developed Microsoft's security network is! None the less congratulations to that little kid.


True, but they did fix it right away and at least they know how to fix problems with their network.

12sPosted:

people saying he "hacked" it, yeah a 5 year old boy
did this on purpose, props to him finding this instead
of a real hacker , could of turned out bad

PrimPosted:

"I was like yea" This article is actually pretty funny to me.