Live data from Hacker News

Diablo 3 bug report: "Passwords not case-sensitive."

us.battle.net

11–20 of 156 posts

Re: Diablo 3 bug report: "Passwords not case-sensitive."

#11
post #3

Facebook does sort of the same thing: http://www.zdnet.com/blog/facebook/facebook-passwords-are-no... Yes, it's possibly less secure. But for both Facebook and all of the Blizzard games there are other options if you are concerned.

Related, but different in an important way.

If your password is aBc, you can log in to Facebook using aBc (original), AbC (windows caps lock), and ABc (first cap) only. For a regular password, this is just slightly less secure.

Being case insensitive entirely is quite a bit less secure (abc, abC, aBc, aBC, Abc, AbC, ABc, ABC).

Re: Diablo 3 bug report: "Passwords not case-sensitive."

#12

They don't (or didn't, I haven't checked in the last few months) allow special characters, either. Seriously - what? (Then again, my bank does the same thing.)

So use a long password without them: password strength is what counts, not funny rules about special characters and minimum characters.

Re: Diablo 3 bug report: "Passwords not case-sensitive."

#13
post #12

They don't (or didn't, I haven't checked in the last few months) allow special characters, either. Seriously - what? (Then again, my bank does the same thing.)

So use a long password without them: password strength is what counts, not funny rules about special characters and minimum characters.

This is not the point.

Users are put at risk because Blizzard fails to adequately impose security. Tech savvy users can just use a stronger password, but the others are put at risk by what I can only call negligence.

Re: Diablo 3 bug report: "Passwords not case-sensitive."

#14

They don't (or didn't, I haven't checked in the last few months) allow special characters, either. Seriously - what? (Then again, my bank does the same thing.)

> They don't (or didn't, I haven't checked in the last few months) allow special characters, either. Seriously - what? (Then again, my bank does the same thing.)

This is not entirely correct. They do allow some types of punctuation, and have done for a very long while. I haven't tested characters like #, @, & (etc) though, but periods and the like have worked.

Re: Diablo 3 bug report: "Passwords not case-sensitive."

#16
post #3

Facebook does sort of the same thing: http://www.zdnet.com/blog/facebook/facebook-passwords-are-no... Yes, it's possibly less secure. But for both Facebook and all of the Blizzard games there are other options if you are concerned.

Facebook's is a little better - you can't disregard case entirely. Blizzard just cut the search space by a lot. Then again, it would be pretty difficult to brute force a password in Battle.net, to be honest. I'm assuming they'd lock out the account after just a handful of tries.

> Then again, it would be pretty difficult to brute force a password in Battle.net, to be honest. I'm assuming they'd lock out the account after just a handful of tries.

Correct. ~5 failed attempts forces you to use your authenticator code, and if you don't have one, you need to use their reset form and a captcha.

Re: Diablo 3 bug report: "Passwords not case-sensitive."

#17
post #3

Facebook does sort of the same thing: http://www.zdnet.com/blog/facebook/facebook-passwords-are-no... Yes, it's possibly less secure. But for both Facebook and all of the Blizzard games there are other options if you are concerned.

Facebook's is a little better - you can't disregard case entirely. Blizzard just cut the search space by a lot. Then again, it would be pretty difficult to brute force a password in Battle.net, to be honest. I'm assuming they'd lock out the account after just a handful of tries.

The game clients will lock an account out after ~20 or 30 attempts and I assume the website will do the same. No one is going to brute force an account.

Re: Diablo 3 bug report: "Passwords not case-sensitive."

#18
post #12

They don't (or didn't, I haven't checked in the last few months) allow special characters, either. Seriously - what? (Then again, my bank does the same thing.)

So use a long password without them: password strength is what counts, not funny rules about special characters and minimum characters.

They also restrict it to EDIT: That doesn't even make sense, unless they're storing plain-text passwords.

Re: Diablo 3 bug report: "Passwords not case-sensitive."

#19
post #3

Facebook does sort of the same thing: http://www.zdnet.com/blog/facebook/facebook-passwords-are-no... Yes, it's possibly less secure. But for both Facebook and all of the Blizzard games there are other options if you are concerned.

Facebook's is a little better - you can't disregard case entirely. Blizzard just cut the search space by a lot. Then again, it would be pretty difficult to brute force a password in Battle.net, to be honest. I'm assuming they'd lock out the account after just a handful of tries.

Yea, until someone steals their hashes.

Re: Diablo 3 bug report: "Passwords not case-sensitive."

#20
post #9

Although this is a really silly bug, I did already know about it (it's the same in WoW), so frankly at the moment, I'm more concerned about the Diablo 3 bug which is causing a lot of us to not be able to successfully login and play, at all. Really not good.

> Although this is a really silly bug,

Personally, I don't believe it is a bug at all. They have obviously made the decision to not enforce case in an effort to reduce customer service load/player frustration.

Yes, it reduces the time needed to brute force your password if someone got hold of their user DB. But 1) we are still talking an excessively long time (their min. password length is 8) and 2) once they have that, you may have bigger problems.

Whilst this is only anecdotal (over several years of WoW/SC2), the majority of compromised Battle.net accounts are through keyloggers/malware and phishing scams. In those cases, you can have a 40 character password with all the case sensitivity you like and it won't matter at all.

Post reply on HN