Xbox live certificate accidentally published.

Discussion in 'Xbox One Development' started by ASSEMbler, Dec 9, 2015.

  1. ASSEMbler

    ASSEMbler Administrator

    Joined:
    Mar 13, 2004
    Messages:
    19,272
    Likes Received:
    496
  2. XboxSurgeon

    XboxSurgeon Site Supporter Since 2013

    Joined:
    Nov 18, 2013
    Messages:
    1,524
    Likes Received:
    388
    Interesting...
     
  3. rso

    rso Familiar Face

    Joined:
    Mar 26, 2010
    Messages:
    1,161
    Likes Received:
    39
    In b4 eejits going all "omg live's borken!1!". That cert seems to be "only" for the website's https connection, no online (as in game) services are likely to be affected at all. Also note there's no Xboxen listed amongst the affected software.
     
    CodeAsm and Bad_Ad84 like this.
  4. ddxcb

    ddxcb Gota J.T.A.G. That Xbone Yo.

    Joined:
    Apr 17, 2008
    Messages:
    312
    Likes Received:
    12
    the xbox one will probably auto update the Cert and that be the end of the attack.
     
  5. doulomb

    doulomb Robust Member

    Joined:
    Apr 26, 2013
    Messages:
    212
    Likes Received:
    37
    LMAO, while its obviously not a big deal in terms of the potential damage, this is a key management failure on par with sony's ECDSA rng goof.
    how the hell do you accidentally release the private keys for a certificate like that lmao

    -doulomb
     
  6. rso

    rso Familiar Face

    Joined:
    Mar 26, 2010
    Messages:
    1,161
    Likes Received:
    39
    > auto update on xbone
    Well, that's also true for the Windowses, and they did list those.

    > how do you even...
    Stupidity, plain and simple. Just look at all the private info on github. SSL keys, user credentials in versioned config files, hardcoded credentials in source code...
     
    CodeAsm likes this.
  7. Lukew

    Lukew Rapidly Rising Member

    Joined:
    Sep 18, 2015
    Messages:
    77
    Likes Received:
    41
    [​IMG]
     
    CodeAsm and XboxSurgeon like this.

Share This Page