Want to read Slashdot from your mobile device? Point it at m.slashdot.org and keep reading!

 



Forgot your password?
typodupeerror
×
Crime Microsoft Privacy Security XBox (Games) Games

Microsoft: 'Unlikely' Credit Card Details Lifted From Xbox 360s 105

An anonymous reader writes with this excerpt from ZDNet: "Security researchers from two universities say they found how hackers can retrieve credit card data and other personal information from used Microsoft Xbox 360s, even if the console is restored back to factory settings and its hard drive is wiped. Microsoft is now looking into their story of buying a refurbished Xbox 360 from a Microsoft-authorized retailer, downloading a basic modding tool, gaining access to the console's files and folders, and eventually extracting the original owner's credit card information. Redmond is still investigating, but it's already calling the claims 'unlikely.'"
This discussion has been archived. No new comments can be posted.

Microsoft: 'Unlikely' Credit Card Details Lifted From Xbox 360s

Comments Filter:
  • by crazyjj ( 2598719 ) * on Thursday April 05, 2012 @10:53AM (#39585085)

    IIRC, Sony said something very similar at the beginning of the PSN breach [wikipedia.org]--something along the lines of "This was a minor incident. It was probably only a few accounts. Nothing to see here."

  • by not already in use ( 972294 ) on Thursday April 05, 2012 @11:03AM (#39585269)
    No reasonable person would cache credit card details. It's not exactly the type of data, regardless of its sensitivity, that would need to be cached anyway. Let's face the real issue at hand: There is a *huge* market for anti-Microsoft "journalism." You monkeys will piss pageviews on anything that makes any absurd claim, and you won't think twice about whether or not it's credible.
  • Re:Well they would (Score:3, Interesting)

    by Garybaldy ( 1233166 ) on Thursday April 05, 2012 @11:12AM (#39585399)

    Well at least MS denies it. Apple just covers it up.

  • by Anonymous Coward on Thursday April 05, 2012 @11:24AM (#39585565)

    No reasonable person would cache credit card details.

    OK, let's say MS are 'reasonable' and do not specifically and deliberately cache CC data.
    Are you seriously saying that it's not possible that such data would get cached incidentally as part of a larger chunk of data? Stored in some Xbox equivalent of pagefile.sys or whatever? That despite all sorts of data gets cached all over the place, magically somehow CC data never gets in any cache ever?

  • by Anonymous Coward on Thursday April 05, 2012 @11:45AM (#39585915)

    After seeing the original article I tried finding my own credit card number on my xbox hard disk. Through a search of the entire hard disk not even the first 4 digits of my credit card were found, which is part of the issuer identification number. http://en.wikipedia.org/wiki/List_of_Issuer_Identification_Numbers

    Additionally- the article that put this scare on found a number that matched the issuer identification number for a Discover card issued by Bank of America. Microsoft doesn't even take Discover cards. You can't even give this credit card number to Microsoft's system for storage. I find it very hard to believe that Microsoft is storing the credit card number of a card they can't even process.

  • by s.petry ( 762400 ) on Thursday April 05, 2012 @12:40PM (#39586959)

    Take a common sense view of how this could happen. Xbox kernel sees user input, caches input in case the connection is lost. Cache gets written to drive in case of power failure.

    This is the same mindset we see with other Microsoft products like "Active Installer" for IE. Obviously there are security implications but Microsoft chose to put convenience over security.

    To many of us, the security problems released are not excusable. To Microsoft, it's the best business decision.

    In short, it is not a bad intention that brings something like this out necessarily. It's actually a good intention, but poorly planned from the security perspective.

Living on Earth may be expensive, but it includes an annual free trip around the Sun.

Working...