"Some data was illegally accessed, including a list of email addresses for global Battle.net users, outside of China. For players on North American servers (which generally includes players from North America, Latin America, Australia, New Zealand, and Southeast Asia) the answer to the personal security question, and information relating to Mobile and Dial-In Authenticators were also accessed. Based on what we curren…
Blizzard Network Breached; Change Your Battle.Net Passwords
11–20 of 164 posts
Re: Blizzard Network Breached; Change Your Battle.Net Passwords
#12"Some data was illegally accessed, including a list of email addresses for global Battle.net users, outside of China. For players on North American servers (which generally includes players from North America, Latin America, Australia, New Zealand, and Southeast Asia) the answer to the personal security question, and information relating to Mobile and Dial-In Authenticators were also accessed. Based on what we curren…
Do these have to be human-confirmable? Wondering why they're stored in plaintext.. I've been curious about this before. Do you-folks store your challenge-question-answers in plaintext?
Re: Blizzard Network Breached; Change Your Battle.Net Passwords
#13"Some data was illegally accessed, including a list of email addresses for global Battle.net users, outside of China. For players on North American servers (which generally includes players from North America, Latin America, Australia, New Zealand, and Southeast Asia) the answer to the personal security question, and information relating to Mobile and Dial-In Authenticators were also accessed. Based on what we curren…
Do these have to be human-confirmable? Wondering why they're stored in plaintext.. I've been curious about this before. Do you-folks store your challenge-question-answers in plaintext?
I would hazard a guess that most sites store "Secret Questions/Answers" in plain text, or a two-way hash (that their support app reverses), as they are used to confirm identity along with the basics (DOB, address, email, etc).
Re: Blizzard Network Breached; Change Your Battle.Net Passwords
#14I'm concerned that this is happening so often that it is no longer raising eyebrows. It's becoming one of those "just how things work on the Internet, get used to it".
Re: Blizzard Network Breached; Change Your Battle.Net Passwords
#15"Some data was illegally accessed, including a list of email addresses for global Battle.net users, outside of China. For players on North American servers (which generally includes players from North America, Latin America, Australia, New Zealand, and Southeast Asia) the answer to the personal security question, and information relating to Mobile and Dial-In Authenticators were also accessed. Based on what we curren…
Do these have to be human-confirmable? Wondering why they're stored in plaintext.. I've been curious about this before. Do you-folks store your challenge-question-answers in plaintext?
I really wish a lot more work went in to security question penetration testing. It's relatively easy for a determined attacker to come up with the correct answers to these questions (or convince a human that they know the answers). The recent iCloud breach makes me believe that in many cases the "security questions" practice is by far the weakest link in modern web authentication.
Re: Blizzard Network Breached; Change Your Battle.Net Passwords
#16Re: Blizzard Network Breached; Change Your Battle.Net Passwords
#17Earlier quoted context omitted.
Do these have to be human-confirmable? Wondering why they're stored in plaintext.. I've been curious about this before. Do you-folks store your challenge-question-answers in plaintext?
> Do these have to be human-confirmable? Wondering why they're stored in plaintext.. I've been curious about this before. Do you-folks store your challenge-question-answers in plaintext? I would hazard a guess that most sites store "Secret Questions/Answers" in plain text, or a two-way hash (that their support app reverses), as they are used to confirm identity along with the basics (DOB, address, email, etc).
Re: Blizzard Network Breached; Change Your Battle.Net Passwords
#18Re: Blizzard Network Breached; Change Your Battle.Net Passwords
#19This is certainly not limited to Blizzard, it seems like everyday there is a new story about some kind of security breach and then we're told to change our passwords and some details may have been stolen. As an owner of both Starcraft 2 and Diablo III and I am heavily disappointed especially considering how much I paid for both of those games here in Australia (bought digitally as well).
Re: Blizzard Network Breached; Change Your Battle.Net Passwords
#20"Some data was illegally accessed, including a list of email addresses for global Battle.net users, outside of China. For players on North American servers (which generally includes players from North America, Latin America, Australia, New Zealand, and Southeast Asia) the answer to the personal security question, and information relating to Mobile and Dial-In Authenticators were also accessed. Based on what we curren…