| Mail |
You might also like: WoW Insider, Massively, and more

Reader Comments (13)

Posted: Mar 23rd 2007 10:31PM (Unverified) said

  • 2 hearts
  • Report
The person on the end of 18004MYXBOX is not her.
Reply

Posted: Mar 23rd 2007 10:45PM aStagnantSleep said

  • 2 hearts
  • Report
WEAK.
Reply

Posted: Mar 23rd 2007 10:50PM LaughingTarget said

  • 2 hearts
  • Report
Not surprising. The #1 method "hackers" use to get into secure systems is to call as an IT person and ask. You'd be amazed how many people just up and give away user names and passwords when you say "Code Red Computer Emergency".
Reply

Posted: Mar 24th 2007 10:58AM (Unverified) said

  • 2 hearts
  • Report
I wonder whether they were as unsuccessful at this as Microsoft says. I got a Citigroup call earlier today indicating that someone stole my credit card information and used it to make purchases in England yesterday... the information is no doubt in other places besides my Live account, but the timing makes me wonder...

-Geoff
http://www.alinktothefuture.com
Reply

Posted: Mar 23rd 2007 11:14PM (Unverified) said

  • 2 hearts
  • Report
Actually laughingtarget they would call the end users first to extract data from them... People who know nothing about it are more likely to believe that you are telling the truth. Most IT people know something about social engineering.
Reply

Posted: Mar 23rd 2007 11:20PM (Unverified) said

  • 2 hearts
  • Report
its quite simple. they call give them their gamertag and say they forgot what their .net email address is. the untrained service cneter operators would give them that info.

the policy should be to bad you forgot your e-mail. and thats how it will be. basicaly this wa sa loophole in security. any other service you calla nd say you forgot private info they usualy ahve a security question or just refuse you the info.

With that said i had all the info for my wife and the cable company would not help me cause my name wa snot on the account. why i dunno but she set it up when we moved. I had to ahve ehr call them from work and put me on the account. i than stated to the lady i could ahve ahd any one call and say they was my wife and she got quiet.

so there are loop holes every where specially if you know some of the info already. but thats just life. this case should not have happened because ms should not be giving out any info. if you forgot your .net email and password your out 50 bucks 2 bad.

Reply

Posted: Mar 23rd 2007 11:35PM acceptablerisk said

  • 2 hearts
  • Report
Social engineering is hacking. It's the most effective and reliable method for gaining access to restricted systems. That's what hacking is all about.
Reply

Posted: Mar 23rd 2007 11:44PM (Unverified) said

  • 2 hearts
  • Report
Actually, the CSR that you talk to really has no respect for you, because you are bitching that your video games don't work to a person who is trying to make a living listening to your complaints.
Face it, you are pissed off even before your call and you want heads to roll (cause you think you are the center of the universe).
So they will buy any excuse to get your piece of crap attitude off the phone.

Sounds pretty easy to me to impersonate a 15 year old.
Reply

Posted: Mar 24th 2007 12:17AM (Unverified) said

  • 2 hearts
  • Report
That's why.......I say..........@#$% it!
Reply

Posted: Mar 24th 2007 12:23AM LaughingTarget said

  • 2 hearts
  • Report
That is why I said call *AS* one, not call an IT person. Being IT and using those words are magic.
Reply

Posted: Mar 24th 2007 2:38AM (Unverified) said

  • 2 hearts
  • Report
Goldang, she's a hottie!
Reply

Posted: Mar 24th 2007 8:06AM SSUK said

  • 2 hearts
  • Report
10: She's a model, so yeah... Illustrating a 'glamourous' side of this industry. Unfortunatly, call centres have ME to deal with, lord help them.
Reply

Posted: Mar 24th 2007 5:13PM (Unverified) said

  • 2 hearts
  • Report
Or of course, it wasn't your bank phoning but someone pretending to be them to extract personal information from you ;)

Social Engineering is commonplace and it's the biggest organisations that are the most vulnerable. To be honest it's good to see Microsoft (or at least parts of it) be open and honest about this, it shows they're likely to actually do something about it.

http://gamenian.blogspot.com/
Reply
Sorry, you must be logged in to leave a comment.

Featured Stories

Rhythm Heaven Fever review: Crazy into you

Posted on Feb 9th 2012 12:00PM

Remedy not done with Alan Wake

Posted on Feb 9th 2012 10:30AM

Engadget

TUAW

Massively

WoW