Xbox account can be easily stolen
When using "External" as File Storage Location, authentication tokens are made available to any application with access to external storage (games/com.mojang/xal folder).
Thus, the user himself gets access to them. An unsuspecting victim, at the request of third person, can send data from this folder (or just whole game data folder), so third person can log into the servers on behalf of the stolen account.
At the moment, several such cases are known. It also remains unclear how to deal with this. Changing the account password or logging out does not help, the account remains active on the third person's device. If you know a way to log out of your Xbox account remotely, let me know.
2022-12-17, 10:23 AM
2024-01-04, 08:52 PM
2024-01-04, 08:52 PM
0
2
976035
-