Earlier quoted context omitted.
They also restrict it to EDIT: That doesn't even make sense, unless they're storing plain-text passwords.
If you're at the point of needing a 50 character passcode for your blizzard game maybe you should just download the free authenticator .
Diablo 3 bug report: "Passwords not case-sensitive."
151–156 of 156 posts
Re: Diablo 3 bug report: "Passwords not case-sensitive."
#152Earlier quoted context omitted.
OK, where can I download that free authenticator for my Nokia S60?
Run java? http://arenabooster.marisil.org/bma.htm
The Java-based (J2ME) versions of the Battle.net Mobile Authenticator previously
available through this website have been discontinued.
http://eu.blizzard.com/en-gb/mobile/Re: Diablo 3 bug report: "Passwords not case-sensitive."
#153Earlier quoted context omitted.
Well, in the same forum there's also this: http://us.battle.net/d3/en/forum/topic/5149150816 I don't understand why there is a 16 character limit on user passwords.
It's not technically a limit, as much as a truncation. I still would be happy if they lengthened that.
Re: Diablo 3 bug report: "Passwords not case-sensitive."
#154Earlier quoted context omitted.
OK, where can I download that free authenticator for my Nokia S60?
Well, they do offer http://us.battle.net/support/en/article/battlenet-sms-protec... which provides an extra (but different) layer of security.
Re: Diablo 3 bug report: "Passwords not case-sensitive."
#155Earlier quoted context omitted.
If you're at the point of needing a 50 character passcode for your blizzard game maybe you should just download the free authenticator .
OK, where can I download that free authenticator for my Nokia S60?
Re: Diablo 3 bug report: "Passwords not case-sensitive."
#156Earlier quoted context omitted.
Hi, interested in the above comment. Can you explain how a timing attack would work here?
An interesting demo: [1] By not doing all 3 hashes, an attacker might realise that the password they sent passed, say, 2 checks, but not the third. This discloses information about the relationship between the password the attacker just tried and the correct password. [1] http://carlos.bueno.org/2011/10/timing.html