Wow Tech Support

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Thursday, 9 August 2012

The Great Battle.net Compromise

Posted on 18:26 by Unknown
Blizzard has recently announced that their battle.net database, the database that holds all of their usernames and password for games such as World of Warcraft and Diablo, has been compromised:
Some data was illegally accessed, including a list of email addresses for global Battle.net users, outside of China. For players on North American servers (which generally includes players from North America, Latin America, Australia, New Zealand, and Southeast Asia) the answer to the personal security question, and information relating to Mobile and Dial-In Authenticators were also accessed. Based on what we currently know, this information alone is NOT enough for anyone to gain access to Battle.net accounts. We also know that cryptographically scrambled versions of Battle.net passwords (not actual passwords) for players on North American servers were taken. We use Secure Remote Password protocol (SRP) to protect these passwords, which is designed to make it extremely difficult to extract the actual password, and also means that each password would have to be deciphered individually. As a precaution, however, we recommend that players on North American servers change their password. 

What are the implications of this?


  1. Your battle.net ID/email address are now out there - not only does this put your account at more direct risk from a targeted attack, if the email lists fall into the hands of the bad guys then you are much more likely to receive phishing emails.
  2. Your personal security questions/answers are out there - making a social engineering attack on your account, like the recently published attack on Apple, somewhat easier.  Blizzard have vowed to get us all to enter new security questions and answers shortly - let's hope they also advise their tech support teams to be especially vigilant in the meantime.
  3. It appears that the Mobile Authenticator serial numbers/seeds and account link information has been stolen - if this is the case then it is quite feasible that mobile authenticator codes could be generated and used for users with mobile authenticator accounts.  Authenticators rely on the account link info and serial numbers to be kept secret for them to be effective - the algorithm for such schemes is often available in the public domain.  While this type of attack would require some level of sophistication, it is not out of the realm of possibility for modern-day hackers.

What should you do?


First and foremost, go and change your battle.net password.  Yes, the stolen passwords were hashed, but there are techniques for comparing the frequency of hashed passwords to work out which passwords are more likely to be one of the more commonly used passwords.  A "salted" password helps protect against this but we don't know exactly what form Blizzard stores their passwords in (other than they are "cryptographically scrambled").

Second, go buy a hardware authenticator.  The hardware authenticator serial numbers were reportedly not stolen and the technology is developed by a security vendor (Vasco) as opposed to the mobile authenticator app which was developed by Blizzard.  This is not to say the mobile authenticator is bad - it is certainly better than not having an authenticator at all, but the hardware authenticator is the best.  I certainly have one on my account!

Third, be particularly wary of phishing emails.  If your email is now in the hands of the bad guys then you will certainly get hammered with more of these. 

Lastly - don't stress too much.  Our good friends at Blizzard will restore accounts that have been compromised and given that raiding is currently in a quiet time, I am sure that your guild will forgive you.


Email ThisBlogThis!Share to XShare to FacebookShare to Pinterest
Posted in | No comments
Newer Post Older Post Home

0 comments:

Post a Comment

Subscribe to: Post Comments (Atom)

Popular Posts

  • EVE Character report (with titans)
    Quick note: yesterday I met the worst scammer ever, and made an extra post about it which just hit 10K visitors! My first character repor...
  • Diablo 3 Beta Phishing Season Begins
    The scammers are out in force with the recent Diablo 3 beta opt-in announcement.   Phishing scams are very common around any Blizzard beta ...
  • What would happen if people could trade?
    The question of mirror-ability of strategies often comes up when I post my trading strategy. The 0.01 strategy is clearly mirror-able. If th...
  • Tragedy of commons (and non-TC alliances)
    The tragedy of commons is a well-known economical problem, described by the anecdote: "herders sharing a common parcel of land, on whi...
  • A new approach to fight botting
    Botting is a widespread plague of MMOs. A botter can gain insane amount of game resources since it “farms for free”: the time of the bot cos...
  • The war for Finanar
    Finanar is a 0.5 system in Metropolis with 3 ice anomalies. If you check out my corp killboard you see lot of kills there, about 8B destro...
  • The (total lack of) balance of trade of highsec
    The fact that you can be much more rich in highsec than in the competitive areas of EVE (low, null, WH) is one of my main messages. It can b...
  • Planetary interaction for beginners
    Planetary interaction isn't a really profitable enterprise. However the "newbie-version" is a "printing money" schem...
  • Nullsec-altruism and a free titan
    Imagine that you are an avatar in Diablo 3. You enter New Tristram after defeating some risen dead. The town is clearly in danger. The undea...
  • The myth of the skilled, goodfight-seeking PvP-er
    While no sane man would claim that pilot skill decides large engagement instead of strategic decisions, there is a claim that there are skil...

Categories

  • account
  • account theft
  • adobe
  • alpha
  • arena tournament
  • authenticator
  • authenticators
  • battle.net
  • beta
  • blizzard
  • brute force
  • cataclysm
  • diablo 3 phishing scam
  • dictionary attack
  • drive-by
  • email
  • fake
  • flash
  • game
  • Gold
  • guild
  • gumblar
  • hacked
  • hacking
  • hacks
  • Ideas
  • ISK
  • keylogger
  • march
  • mmo-champion
  • New
  • password
  • password stealing
  • patching
  • phishing
  • raiding
  • Random
  • ranks
  • remote auction house
  • scam
  • scams
  • security
  • security checklist
  • soccer
  • strong password
  • trojan
  • vulnerability
  • warcraft
  • wow
  • wowarmory
  • wowmatrix

Blog Archive

  • ►  2013 (242)
    • ►  November (15)
    • ►  October (25)
    • ►  September (24)
    • ►  August (21)
    • ►  July (24)
    • ►  June (22)
    • ►  May (22)
    • ►  April (22)
    • ►  March (20)
    • ►  February (21)
    • ►  January (26)
  • ▼  2012 (261)
    • ►  December (24)
    • ►  November (21)
    • ►  October (24)
    • ►  September (21)
    • ▼  August (26)
      • How could the RL economy crash?
      • Highsec protects gankers from carebears and not th...
      • New scam: contract margin trade scam! (and a 1B mo...
      • A wannabe nullsec alliance members plight
      • Nerf low/null PvE ganking: remove local channel!
      • Why TEST doesn't produce nanotransistors?
      • EVE server?
      • Moron of the week
      • A little gift to total strangers
      • The FW-LP "goldmine" is highly speculative
      • Titan vs 60 dreadnoughts
      • "War bonds toplist" for alliance PvE?
      • EVE Character report - August
      • The great shitworm scam
      • License, tax, rent
      • After Tech alliance budgets
      • Minimal wage and PLEX price
      • Bubble-camp survival guide
      • Screenshots from all over nullsec
      • The Great Battle.net Compromise
      • Guide to riches for low/null/WH veterans
      • Newbie guide to trading riches in EVE
      • Highsec piracy is practically irrelevant
      • Trade guru and hub-builder
      • "Good fight" and "EVE is real" are mutually exclusive
      • The shocking truth, mate
    • ►  July (25)
    • ►  June (20)
    • ►  May (25)
    • ►  April (23)
    • ►  March (23)
    • ►  February (23)
    • ►  January (6)
  • ►  2011 (4)
    • ►  September (1)
    • ►  April (1)
    • ►  March (1)
    • ►  January (1)
  • ►  2010 (17)
    • ►  November (1)
    • ►  September (2)
    • ►  August (1)
    • ►  July (1)
    • ►  June (2)
    • ►  May (2)
    • ►  April (1)
    • ►  March (2)
    • ►  February (2)
    • ►  January (3)
  • ►  2009 (4)
    • ►  December (1)
    • ►  October (1)
    • ►  September (1)
    • ►  July (1)
Powered by Blogger.

About Me

Unknown
View my complete profile