TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

5-year-old Ocean Beach boy exposes Microsoft Xbox vulnerability

143 pointsby dan1234about 11 years ago

22 comments

dredmorbiusabout 11 years ago
NB: what is it about small and local news sites, usually TV stations, but also newspapers and such, which cannot <i></i>* CLEARLY <i></i>* indicate <i>where</i> in the world they are?<p>&quot;Ocean Beach&quot; is a pleasantly anonymous place name (I can think of several neighborhoods matching this, the U.S. Gazetteer of Places identifies it as Ocean Beach, NY), affording very little by way of actual location.<p>In an age before widespread Internet use, I experienced similar frustrations while listening to clear channel AM radio broadcasts in the back country. It wasn&#x27;t uncommon to pull in strong signals from hundreds to a thousand miles away. And while there&#x27;s something delightfully surreal in listening to the mundania of local traffic and news reports, if you happen to be in a wilderness location trying to find a reliable weather forecast, &quot;area conditions&quot; doesn&#x27;t do much for you.
评论 #7531588 未加载
评论 #7532450 未加载
评论 #7532623 未加载
评论 #7531780 未加载
评论 #7531560 未加载
评论 #7532732 未加载
chancedabout 11 years ago
&quot;At age 1, Kristoffer got past the toddler lock screen on a cell phone by holding down the home key.&quot;<p>Not to be &quot;that guy&quot; or anything but I suspect it is pretty normal for a child to hold down a button.<p>First, what kind of lousy lock wouldn&#x27;t safeguard against, what was likely either the only or one of a few buttons, being held down?<p>Second, sounds like proud father has made at least a few false connections. He is a geeky equivalent of a creationist museum tourist.
0xbadcafebeeabout 11 years ago
Wow. This is the mavis beacon typing tutor hack.<p>Years ago (jesus, has it been 15 years?), I was in computer class on the old Macintoshes they had with Mavis Beacon Typing Tutor. We were supposed to type out the sentences we read to increase our typing speed, and learn the home row. I hated home row, and insisted that hunt-and-peck was more comfortable for me. But the teacher was adamant I use home row only, which was annoying. I was also not very fast at either form of typing.<p>I discovered by accident that if I hit the spacebar for each letter in each word, the program interpreted it as a successful spelling. All I had to do was keep typing the spacebar to complete the words. So i&#x27;d put my fingers on the home row, moving my fingers up and down, and pressing the spacebar with my thumb. I got 120 words per minute.
评论 #7532505 未加载
评论 #7531631 未加载
评论 #7532858 未加载
quackerhackerabout 11 years ago
So I told this story to my wife, because at first I was a little envious (wishing my boy did this)...then her being the devil&#x27;s advocate made me realize something...if a 5-year-old can bypass Xbox&#x27;s verification by <i>pressing space keys and enter</i> then it says volumes about Xbox&#x27;s verification checks.<p>Who was sleeping at the wheel when Xbox didn&#x27;t add empty strings to password verification checks?
kmfrkabout 11 years ago
On another note, the whitehat bounty seems ridiculously low, if we&#x27;re to take him as a peer:<p><pre><code> Kristoffer will receive four games, $50 and a year-long subscription to Xbox Live from Microsoft.</code></pre>
评论 #7532980 未加载
评论 #7533385 未加载
quuxabout 11 years ago
As I read the article I kept expecting the part where he was suspended from school for the rest of the semester for breaking the school&#x27;s zero tolerance policy on &quot;cyber attacks&quot; or something.
yincrashabout 11 years ago
It&#x27;s really refreshing to see a family embrace their son&#x27;s inventiveness and tenacity rather than reprimand the kid for breaking past the parental controls
评论 #7532005 未加载
samelawrenceabout 11 years ago
Is it just me, or should they have given him more than $120 for exposing this major flaw?
评论 #7531424 未加载
评论 #7531757 未加载
评论 #7531421 未加载
ilbeabout 11 years ago
Spaces, really? Can someone speculate what might be happening under the hood?
评论 #7531440 未加载
评论 #7531457 未加载
zemoabout 11 years ago
what level of crime is this? Does this count as computer trespass in NY? If so, that&#x27;s a class E felony.<p><pre><code> § 156.10 Computer trespass. A person is guilty of computer trespass when he or she knowingly uses, causes to be used, or accesses a computer, computer service, or computer network without authorization and: 1. he or she does so with an intent to commit or attempt to commit or further the commission of any felony; or 2. he or she thereby knowingly gains access to computer material. Computer trespass is a class E felony. </code></pre> <a href="http://public.leginfo.state.ny.us/LAWSSEAF.cgi?QUERYTYPE=LAWS+&amp;QUERYDATA=$$PEN156.10$$@TXPEN0156.10+&amp;LIST=LAW+&amp;BROWSER=BROWSER+&amp;TOKEN=03545439+&amp;TARGET=VIEW" rel="nofollow">http:&#x2F;&#x2F;public.leginfo.state.ny.us&#x2F;LAWSSEAF.cgi?QUERYTYPE=LAW...</a>
评论 #7533863 未加载
评论 #7534746 未加载
vectorpushabout 11 years ago
Look out homakov. :)
crystalmaceabout 11 years ago
Oh sure. When he bypasses child locks he gets rewarded by his parents and Microsoft. When I bypassed child locks and parental controls when I was younger, I got in trouble and my computer taken away. :D
elwellabout 11 years ago
This is indicative of disorganized program structure. Form validation shouldn&#x27;t be unique to separate forms; they should all be piped through the same place, where validation is done.
Aardwolfabout 11 years ago
When I was 5 years old all I could do was sort Duplo blocks by color, and I don&#x27;t even have a memory of it :(. I get sort of jealous if I see how smart small kids can be.
SwiftCeiptabout 11 years ago
I don&#x27;t think its that surprising, kids have all the time in the world. When I was a kid I worked on cracking the Fridge lock.. Perhaps my time was poorly spent.
Evolvedabout 11 years ago
If you scroll down to the bottom where it says &quot;Trending Now&quot; all of the headlines (including this one) state 10news.com KGTV ABC San Diego.
S4Mabout 11 years ago
Seriously, is this true or a late April&#x27;s fool?
评论 #7531752 未加载
snorkelabout 11 years ago
Sennnsatioonal!!!<p>&gt; At age 1, Kristoffer got past the toddler lock screen on a cell phone by holding down the home key.<p>... uh ... pretty sure because that&#x27;s because he watched his father doing in order to use the phone.
elwellabout 11 years ago
“I was like yea!”
67726eabout 11 years ago
Maybe I&#x27;m just cynical, but given that the father is a security researcher, does anyone else think that he himself found the vulnerability but concocted the story to get some free press?
评论 #7532001 未加载
评论 #7532122 未加载
评论 #7532331 未加载
评论 #7532614 未加载
jdorfmanabout 11 years ago
fucking awesome
gygygyabout 11 years ago
Why do I get the feeling someone is trying to say that a xBox could even be hacked a 5 year old. I smell something fishy. :p