Thursday, March 22, 2007

More on Xbox Live

So it appears that the Xbox Live "hacking" story is actually a story about social engineering. There are informative updates from Steven Davis here and here, and he also links to an excellent article by Robert Lemos here.

So when Microsoft says that they have no evidence that Xbox Live has been hacked, they are telling the truth, apparently. What they're not saying is that appears to be significant anecdotal evidence that there are procedural issues with how Microsoft employees provide support to Xbox Live customers that makes them vulnerable to social engineering ruses.

