Xbox Live private keys mistakenly disclosed, says Microsoft
Microsoft statement did not list the source of the leaks but the company said that the leaked keys have so far not been used in any cyber attack.
In the security advisory released Wednesday, Microsoft said it has invalidated the leaked certificate. “To help protect customers from potentially fraudulent use of the SSL/TLS digital certificate, the certificate has been deemed no longer valid and Microsoft is updating the Certificate Trust list (CTL) for all supported releases of Microsoft Windows to remove the trust of the certificate,” reads the advisory. The leaked digital certificate cannot be used to impersonate domains, create new certificates or sign code.
However the biggest concern is that the private keys could be used to mount a in a “man-in-the-middle” attack. Potential hacker could use the leaked Xbox Live private keys to gain access to a secure connection. “Each user in the communication unknowingly sends traffic to and receives traffic from the attacker, all the while thinking they are communicating only with the intended user,” Microsoft explained. A hacker could intercept messages sent between Microsoft and the Xbox Live user. Information or sensitive data could be stolen via this method.
Posted:
Related Forum: Xbox Forum
Source: http://www.techworm.net/2015/12/xbox-live-users-open-to-hack-as-microsoft-accidentally-leaks-private-keys.html
Related Articles
Comments
GT-RPosted:
SakiFaux25 this is why ps4/sony and pc is better gg ms gg shows how protected their stuff is if hackers can access these types of stuff and no im not a fan boy i prefer all systems the same way as most people plus this is mo
lol
Valve has had a scamming and phishing issue for years now and Sony had like 3 major hackings that had customer credit cards and addresses leaked but some SSL certificates become compromised on MS's side and suddenly it's "gg ms"
I really hope you're being a troll.
You couldn't be more wrong. Well you can because every time I see you comment with your post purchase rationalization nonsense you show just how wrong you can be.
KiIIPosted:
Microsoft really need to step their game up, Ive lost so much respect over the last half year. I know it was a mistake but they just keep happening.
LebronIs6Posted:
Sony is so much worse. Throughout the past year Sony have had around 15 outages some going as long as a a couple days. (A.K.A LIZARD SQUAD) Trash Sony
SakiPosted:
Faux25 this is why ps4/sony and pc is better gg ms gg shows how protected their stuff is if hackers can access these types of stuff and no im not a fan boy i prefer all systems the same way as most people plus this is mo
lol
Valve has had a scamming and phishing issue for years now and Sony had like 3 major hackings that had customer credit cards and addresses leaked but some SSL certificates become compromised on MS's side and suddenly it's "gg ms"
I really hope you're being a troll.
CB9Posted:
Faux25 this is why ps4/sony and pc is better gg ms gg shows how protected their stuff is if hackers can access these types of stuff and no im not a fan boy i prefer all systems the same way as most people plus this is mo
Was that sarcasm? I'm pretty sure Sony has had worse leaks lol
Mario350Posted:
this is why ps4/sony and pc is better gg ms gg shows how protected their stuff is if hackers can access these types of stuff and no im not a fan boy i prefer all systems the same way as most people plus this is mo
Latest Downloads
- 01. SnowRunner: SaveGame (all trucks are open) [32.1](1)
- 02. [PS4/EU] Hatsune Miku: Project DIVA Future Tone 100% Trophy Save(1)
- 03. Silent Hill 2 Remake: SaveGame (Motel Jacks, NG+)(0)
- 04. Phasmophobia: SaveGame (XX-2000, $594,965,799, 3 apocalypse skulls + bonus)(2)
- 05. Satisfactory: SaveGame (Observation deck)(1)
- 06. [EU] Sniper Elite 5 - Best Of The Best (CUSA16075)(5)
- 07. Voices Of The Void: SaveGame (All improvements for work + 7 days passed) [0.8.0](1)
- 08. Silent Hill 2 Remake: SaveGame (NG+, ending "Maria")(1)
- 09. Five Nights at Freddy's- Security Breach Save(9)
- 10. Commandos 2 - HD Remaster: SaveGame (All missions are open)(0)
- 11. Black Myth: Wukong - SaveGame (100%, NG++)(3)
- 12. Mindjack save xbox(0)
- 13. mindjack ps3 save(0)
- 14. Lies of P: SaveGame (game completed 6 times, hero level 124)(1)
- 15. Shadow of the Ninja - Reborn: SaveGame(0)
Latest Tutorials
- 01. PS3 HEN - Audio via a USB headset.(296)
- 02. Stumble Guys | Social Butterfly Achievement(196)
- 03. Last Days of Lazarus Achievement Walkthrough (Xbox/PS)(1,454)
- 04. EDENGATE: The Edge of Life - 100% Trophy/Achievement Guide(1,820)
- 05. Sherlock Holmes Chapter One | Walkthrough | No Commentary(1,460)
- 06. Morbid: The Seven Acolytes | Full Game Walkthrough(2,428)
- 07. Adam Wolfe | Full Game Walkthrough | No Commentary(1,570)
- 08. ALFRED HITCHCOCK: VERTIGO - 100% Walkthrough(1,879)
- 09. SHERLOCK HOLMES THE AWAKENED | Walkthrough | No Commentary(1,328)
- 10. Space Roguelike Adventure | Guide - Cheat Code!(1,526)
- 11. DETECTIVE Stella Porta Case | Trophy & Achievement Guide(1,190)
- 12. Tunic 100% Platinum Walkthrough | Trophy & Achievement Guide(1,817)
- 13. Outbreak: The Nightmare Chronicles Achievement Walkthrough(1,455)
- 14. Full Void 100% - Trophy & Achievement Guide(1,438)
- 15. Outbreak: Lost Hope #Xbox Achievement Walkthrough(2,274)
"Xbox Live private keys mistakenly disclosed, says Microsoft" :: Login/Create an Account :: 39 comments