March 28th 2010 10:44 pm PT

PAX East Panel: Enforcement on Xbox LIVE: Tales from the Din Part 2


This is the full audio from Stepto’s panel at PAX East.

Recorded on Sunday, March 28, 2010 at PAX East in Boston, MASS



Email at Major – at Xbox – dot com with comments about the show.

Podcast By Larry Hryb, Xbox LIVE's Major Nelson

    Thank you very much, Major! Since I’ve heard your show live from PAX I wanted to hear this.

    Thanks a lot for posting this. I was at the Enforcement panel in Seattle last year and it was extremely entertaining. Looking forward to listening to part two tomorrow.

    Thanks! It will give me something to listen to while I am finishing up prep for tonight’s recording of our show!

    The helicopter?

    Yeah, The Helicopter is just bad….Great Enforcement show…Thanks

    that was so nice of you Stepto Thanks!

    Good stuff!

    This was great – I bet Stepto & team never have a dull day at the office! Thanks :)

    MN, you need to change your phone number ASAP, some idiot just posted it on youtube it would seem.


    Loved the show, very informative and entertaining. The mind just boggles at what this mysterious helicopter could be !!!

    All in all a really good show, thanks for putting it up major.

    I had no idea that they really looked at the complaints you’ve submitted. I’ve always been told by other gamers that fileing a complaint was useless and a total waste of time, and had no effect other then just making you feel better when some one was a true jerk during a game. I do love the fact that you can completely cut someone off if you want to by subbmitting a negative player review and blocking them from sending you messges, oh and taking the time to mute you them from their profile just in case you come across them again later on.

    Ok, so what about the thing “Don`t give away your email and password, because there is no other way to get an account stolen? I am really looking forward to an official Statement about this.

    “My Account was hacked. Can you help me MS?”
    “No, it was your own fault, don`t give away your email and password”
    THis was the way to handle those problems in the past.

    I bet you (MS) won`t be saying anything about this “issue”. Like always.

    Glad you got your account back so quick major

    This has been something that has worried me for a while now
    as alot of people never get theyr accounts back
    as microsoft are unwilling to help

    but microsoft just presume people have been phished

    how ever you where hacked needs to be closed up asap

    and the guy who did it needs to be arrested and charged
    because if high profile accounts can be hacked with no comebacks
    its a bad sign to other xbox live users

    Glad you got hacked major, too bad you got your account back.

    Bungie forums tell me a certain Major Nelson has been hacked? No idea how in the world they did it.

    @Computerdude103 – is there a need to gloat because he had his account modified(not hacked) by and idiot.

    Glad you got you’re account back hope the guy gets everything he deserves since his Real name is posted over the net he made him self a big bulleye on his back

    ill listen to the shows later

    @L0rN I don’t recall them ever saying it was the ONLY way that an account could get compromised, just that is was far and away the most common method.

    Listened to the panel & very much enjoyed it. If there’s a part 3 at PAX Prime this year, I’ll definitely be there again.

    What an idiot (the hacker). Posting it on YouTube gloating about it? Hopefully Microsoft goes after him HARD.

    I know this isn’t the subject or anything, but I’m glad you got your account back!

    We can argue terminology, but the fact is that he logged onto his account and changed stuff. I’m still LOLing at the “lawrence” name. Good thing he didn’t have his real address on there at least!!

    Glad everything got resolved with ur account Major.

    Stay classy Computerdude103

  • SilentStryk09

    i wish we could get an official statement on this matter. I feel it is owed in this situation since MS has always been so adamant on the “you got phished, it was your fault” thing.

    Stay intelligent shadowed ghost

    Microsoft wouldn’t give a crap if your account got hacked (or maybe they would, but for the average person they wouldn’t)

    This is why I’m glad Majors account got hacked. Maybe they’ll realize that their customers don’t want their personal information compromised, just as Lawrence doesn’t want his personal information compromised.

    I thought my posts made it fairly obvious what I was saying but I guess you really need it spelled out to you.

    Yes, that’s what I’m talking about!! I either want Major Nelson to admit it was his fault that his account got hacked, or I want Microsoft to finally admit they have vulnerabilities. I really don’t care how they got Major’s password, even if it was by brute force, Microsoft can and needs to do things to improve the safety of their users.

    That’s a nice backpedal there, but when you say you’re sorry he got his account back, it’s clear you’re being vindictive.

    Anyway, the information we have about this situation is almost nothing. There’s no definitive proof of the attack vector. Most likely in my ill-informed opinion, the attacker executed the attack at PAX East. It presents opportunity and explains why we haven’t seen this before in the wild with Major or any similarly-notable accounts. MITM over the wireless, 0-day attack on the browser or OS, take your pick.

    Could you ask Stepto what they do about people who ruin older games? You know, the not the MW2s of this world. I am constantly filing reports against the same glitchers in CoD3 who ruin the gameplay for everyone but nothing ever gets done about them.

    Calm your nerd rage Computerdude103!

    Once the investigation is complete, I’ll be sharing what I can. For obvious reasons nothing can be said right now.

    Great job MS, a atupid 14 years old Moron hacked the accountsystem of Xbox live……….

    Wow about that hacked account…

    So impressive, that hope to know details and hope it will increase the user’s security.

    Only thing that I can say is: PLEASE, INCREASE THE PASSWORD LENGHT!

    I want to concrete a longer passwd :(

    See you!

    Hey Major sorry to hear your account got hacked. I’m sure the people involved will be caught. Stepto is the man. I love his attitude and philosophy about enforcement. For those of you that are commenting rude stuff, don’t be a Jerk! Major keep doing what your doing. You are appreciated and thank you. Happy gaming all.

    This is the SHORT version, believe it or not…

    My windows LIVE account was hacked 2 years back some way, some how. He/She/They accessed my XBL information through my windows LIVE account(most likely saw a xbox message in my freakin inbox) and proceeded to hack my XBL account. Things started going very wrong. I called XBL support, told them what was up and to suspend my account so no further damage could be done. He/She/They used my credit card information that was linked to my account to buy not only XBL stuff but erroneous charges starting coming in from everywhere. (reason #1 I NEVER have given MS my credit card info EVER again) So yea, got my account suspended, spent about 1 hour with Windows support letting them know what was up, promptly got a new password for my windows LIVE account – fixed EVERYTHING that had gone wrong, worked with my bank about the charges, closed the credit card, changed all of my information back, created new password/login info… the works. The only speed bump that promptly turned into a pot hole? Trying to UN-suspend my XBL account once I had retrieved everything they(XBL CS) told me I needed. They told me it was my fault, I told them to f*** off, back and forth on and on. It took 2 1/2 weeks to finally get access to my xbl account back after countless hours on the phone and online.

    I can say first hand that they(XBL CS)are a pain in the ASS… no, no, the BIGGEST pain in the ASS EVER and everything will always be the customers fault no matter what. I wanted to smash faces into pavement, and I am a pretty mellow guy.

    My point? Computerdude103 said many stupid, unnecessary things, but he is right about them not giving two hoots about your account being compromised. Their philosophy of customer service is “Your fault, always, end of discussion”. So, Major I really want a thorough explanation of what happened(when you can) and what will change as far as that horrendous customer service philosophy is concerned. It took me almost 3 weeks to rectify my account being hacked, took you about 20 minutes.

    They should change the name of “PAF” to “FAXanadu ELC” and it would work out better because it can and if we believe it can then it will….

    Probably hard to believe, but my posts were indeed more sarcastic than anything else. (as I spelled out above) Sorry it didn’t come across that way. I think I left a letter off the email address (or at least I meant to). You make a good point about the hacks probably taking place at PAX, but that still doesn’t change the fact that Microsoft doesn’t deal with these situations correctly for the average customer. Calling customer service and trying to answer some secret question I make up 5 years ago never goes so well.

    Sorry on double post, delete them (my comments on the first page) if you want…

    This is the first time that I have listened to Stepto and I for one have changed my mind about him. Kudos to you sir. There is a world of information out there of everything that MS/XBox Live does to make things more difficult with the attitude of ‘I paid for it, leave me alone.’ Not so. Thanks for keeping everything real and allowing those gamers who can take the handslap for doing wrong redeem themselves. Wheaton’s Law is in effect folks. Don’t be one and I will do my best as well.

    happy gaming

    Computerdude103 – present a better method of password recovery for a stranger to verify your information than a secret question and answer. I mean I highly doubt Xbox support knows me and if I called and said hello please reset the password to account blah I am glad we lost the days of ok here ya go. It used to be that way, when I first worked for an ISP like 4 or 5 years ago all they needed to do was say what username they wanted the password reset for and boom it was done. You could have gotten all of someones information simply by knowing their name and phone number, I am glad that has changed :P

    In summation – do not complain about a system unless you have a better one in mind.

    @NaturlBrnKlr now wait a min the clue was paypal $100 you dont think that was is way in???? i mean after i heard its been bustin before…. thats one thing i dont like xbox using it you should stop paypal/xbox marketplace link major just in case it may have holes in to live im just saying..

    and i think i said it, it could happen when you announce the partnership…..

    Most awesome pod cast. I love hearing about the ways they are fighting cheaters and people who dont play fair. Please keep up the good work!!!

    What a great listen. Thanks Stepto for the work you & your team do.
    BTW… What about this scam ???
    You are probably already aware of this possible scam but if not I and many of my friends received this several times in messages.

    Hmm well hopefully common sense and the agility of the XBL team can keep most of LIVE safe from stupid hackers?
    But there WILL ALWAYS be SOMEONE that finds a way to get their account taken.
    You can try your hardest but you will never be able to stop an idiot from being “ST00P1D”.