Don't use corporate IDs on #XBox

By
Follow google news

Consoles need better management.

Unknown consoles and users are causing fresh headaches for IT staff.

Don't use corporate IDs on #XBox

Speaking at the RSA Conference Europe, Christopher Boyd, senior threat researcher at GFI Software, said current consoles are designed for digital media rather than physical software, and there is evidence of tools that have been built to explore data on them.

Referencing a 2010 survey of 200 IT managers, GFI Software found that 49 per cent had a console in the workplace, and 44 per cent had a connected console. It also found that 80 per cent had no record of who was using a console.

Boyd said: “An Xbox 360 account can be tied to a Windows Live ID, so if you lose one, you could lose a corporate identity. So if someone does steal your account and you use the same password for both your corporate and online gaming accounts, it does pay to keep an attack in mind.”

To create a policy that allows connected consoles to be used in a work environment, Boyd advised putting someone in charge of console management, keep a log of users and ensure passwords are changed regularly. He also advised against using a corporate identity in a username as that could make a user a target, and to keep a low profile "as people will ask questions about you while you are shooting aliens".

This article originally appeared at scmagazineuk.com

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © SC Magazine, US edition
Tags:

Most Read Articles

Popular text editor Notepad++ was hacked to drop malware

Popular text editor Notepad++ was hacked to drop malware

'Moltbook' social media site for AI agents had big security hole

'Moltbook' social media site for AI agents had big security hole

Bunnings facial recognition privacy breach ruling partially reversed

Bunnings facial recognition privacy breach ruling partially reversed

Global proxy operator IPIDEA denies Google's malicious intent allegations

Global proxy operator IPIDEA denies Google's malicious intent allegations

Log In

  |  Forgot your password?