Live data from Hacker News

Blizzard Network Breached; Change Your Battle.Net Passwords

kotaku.com

1–10 of 164 posts

Re: Blizzard Network Breached; Change Your Battle.Net Passwords

#3

I'm concerned that this is happening so often that it is no longer raising eyebrows. It's becoming one of those "just how things work on the Internet, get used to it".

Either that or 2-factor authentication will catch on and stealing passwords won't be worth anything.

Re: Blizzard Network Breached; Change Your Battle.Net Passwords

#4
"Some data was illegally accessed, including a list of email addresses for global Battle.net users, outside of China. For players on North American servers (which generally includes players from North America, Latin America, Australia, New Zealand, and Southeast Asia) the answer to the personal security question, and information relating to Mobile and Dial-In Authenticators were also accessed. Based on what we currently know, this information alone is NOT enough for anyone to gain access to Battle.net accounts."

The part where it says, "answer to the personal security question" were accessed should be EXTREMELY ALARMING. This combined with an email addresses is usually enough to get your password reset on lots of sites. I believe this will reset your password on Google (assuming you're not using 2 factor).

Re: Blizzard Network Breached; Change Your Battle.Net Passwords

#5

I'm concerned that this is happening so often that it is no longer raising eyebrows. It's becoming one of those "just how things work on the Internet, get used to it".

I suspect the quality of Pen-Testing being carried out or lack of is certianly an area of concern given the frequency.

Re: Blizzard Network Breached; Change Your Battle.Net Passwords

#6
post #3

I'm concerned that this is happening so often that it is no longer raising eyebrows. It's becoming one of those "just how things work on the Internet, get used to it".

Either that or 2-factor authentication will catch on and stealing passwords won't be worth anything.

Two-factor makes more sense. Relying on your database never getting hacked is nonsense. Is not a matter of are you getting hacked but when are you going to get hacked... expect getting hacked.

(disclaimer: I am the founder of Authy.com a two-factor auth API)

Re: Blizzard Network Breached; Change Your Battle.Net Passwords

#7

I'm concerned that this is happening so often that it is no longer raising eyebrows. It's becoming one of those "just how things work on the Internet, get used to it".

One of the many reasons using a password manager and having different, random passwords for each site is a good idea.

Re: Blizzard Network Breached; Change Your Battle.Net Passwords

#8
post #4

"Some data was illegally accessed, including a list of email addresses for global Battle.net users, outside of China. For players on North American servers (which generally includes players from North America, Latin America, Australia, New Zealand, and Southeast Asia) the answer to the personal security question, and information relating to Mobile and Dial-In Authenticators were also accessed. Based on what we curren…

This is why you never use the actual answer to that question, but actually a separate password for those.

Re: Blizzard Network Breached; Change Your Battle.Net Passwords

#9
post #4

"Some data was illegally accessed, including a list of email addresses for global Battle.net users, outside of China. For players on North American servers (which generally includes players from North America, Latin America, Australia, New Zealand, and Southeast Asia) the answer to the personal security question, and information relating to Mobile and Dial-In Authenticators were also accessed. Based on what we curren…

Do these have to be human-confirmable? Wondering why they're stored in plaintext.. I've been curious about this before. Do you-folks store your challenge-question-answers in plaintext?

Re: Blizzard Network Breached; Change Your Battle.Net Passwords

#10

I'm concerned that this is happening so often that it is no longer raising eyebrows. It's becoming one of those "just how things work on the Internet, get used to it".

One of the many reasons using a password manager and having different, random passwords for each site is a good idea.

I agree. As long as the password authentication mechanism is in place, unique, random, and complex passwords are the best way to secure yourself. Unless you can memorize each of these unique passwords yourself, the next best thing is to use a secure password manager program to take care of this for you.
Post reply on HN