Live data from Hacker News

Blizzard Network Breached; Change Your Battle.Net Passwords

kotaku.com

11–20 of 164 posts

Re: Blizzard Network Breached; Change Your Battle.Net Passwords

#11
post #4

"Some data was illegally accessed, including a list of email addresses for global Battle.net users, outside of China. For players on North American servers (which generally includes players from North America, Latin America, Australia, New Zealand, and Southeast Asia) the answer to the personal security question, and information relating to Mobile and Dial-In Authenticators were also accessed. Based on what we curren…

Reset your password via your original email...

Re: Blizzard Network Breached; Change Your Battle.Net Passwords

#12
post #4

"Some data was illegally accessed, including a list of email addresses for global Battle.net users, outside of China. For players on North American servers (which generally includes players from North America, Latin America, Australia, New Zealand, and Southeast Asia) the answer to the personal security question, and information relating to Mobile and Dial-In Authenticators were also accessed. Based on what we curren…

Do these have to be human-confirmable? Wondering why they're stored in plaintext.. I've been curious about this before. Do you-folks store your challenge-question-answers in plaintext?

I've called before to recover an account and the tech support guy asked for the answer to my security question.

Re: Blizzard Network Breached; Change Your Battle.Net Passwords

#13
post #4

"Some data was illegally accessed, including a list of email addresses for global Battle.net users, outside of China. For players on North American servers (which generally includes players from North America, Latin America, Australia, New Zealand, and Southeast Asia) the answer to the personal security question, and information relating to Mobile and Dial-In Authenticators were also accessed. Based on what we curren…

Do these have to be human-confirmable? Wondering why they're stored in plaintext.. I've been curious about this before. Do you-folks store your challenge-question-answers in plaintext?

> Do these have to be human-confirmable? Wondering why they're stored in plaintext.. I've been curious about this before. Do you-folks store your challenge-question-answers in plaintext?

I would hazard a guess that most sites store "Secret Questions/Answers" in plain text, or a two-way hash (that their support app reverses), as they are used to confirm identity along with the basics (DOB, address, email, etc).

Re: Blizzard Network Breached; Change Your Battle.Net Passwords

#14

I'm concerned that this is happening so often that it is no longer raising eyebrows. It's becoming one of those "just how things work on the Internet, get used to it".

isn't it inevitable? Rogue employees, dumb mistakes, passwords will always be stolen: what's important is they're stored securely enough that when (not if) they are stolen they are worthless to the people that now hold the passwords.

Re: Blizzard Network Breached; Change Your Battle.Net Passwords

#15
post #4

"Some data was illegally accessed, including a list of email addresses for global Battle.net users, outside of China. For players on North American servers (which generally includes players from North America, Latin America, Australia, New Zealand, and Southeast Asia) the answer to the personal security question, and information relating to Mobile and Dial-In Authenticators were also accessed. Based on what we curren…

Do these have to be human-confirmable? Wondering why they're stored in plaintext.. I've been curious about this before. Do you-folks store your challenge-question-answers in plaintext?

Possibly. I've been on phone support with companies that require me to tell them answers to my security questions. Also, automatic security question checking would require support for soft matches like capitalization or punctuation. You could simplify the data before hashing (strip special chars and convert to lower case), or store multiple hashes to each variant.

I really wish a lot more work went in to security question penetration testing. It's relatively easy for a determined attacker to come up with the correct answers to these questions (or convince a human that they know the answers). The recent iCloud breach makes me believe that in many cases the "security questions" practice is by far the weakest link in modern web authentication.

Re: Blizzard Network Breached; Change Your Battle.Net Passwords

#17

Earlier quoted context omitted.

Do these have to be human-confirmable? Wondering why they're stored in plaintext.. I've been curious about this before. Do you-folks store your challenge-question-answers in plaintext?

> Do these have to be human-confirmable? Wondering why they're stored in plaintext.. I've been curious about this before. Do you-folks store your challenge-question-answers in plaintext? I would hazard a guess that most sites store "Secret Questions/Answers" in plain text, or a two-way hash (that their support app reverses), as they are used to confirm identity along with the basics (DOB, address, email, etc).

They can confirm identity with a one-way hash - the only reason I could think of not supporting this would be fuzzy matching.

Re: Blizzard Network Breached; Change Your Battle.Net Passwords

#19
This is ridiculous. Maybe the world is ending, because it feels like every major website/provider of some popular service is getting hacked these days. A company of Blizzard's stature and wallet size has no excuse for this kind of thing happening, no excuse at all. If you're charging people exorbitant amounts of cash to buy your games and then charging some of your customers a fee for the privilege of using your so-called "secure" servers every month then you should be providing a certain level of security in return, it's not rocket science - employ someone who knows how to secure a server.

This is certainly not limited to Blizzard, it seems like everyday there is a new story about some kind of security breach and then we're told to change our passwords and some details may have been stolen. As an owner of both Starcraft 2 and Diablo III and I am heavily disappointed especially considering how much I paid for both of those games here in Australia (bought digitally as well).

Re: Blizzard Network Breached; Change Your Battle.Net Passwords

#20
post #4

"Some data was illegally accessed, including a list of email addresses for global Battle.net users, outside of China. For players on North American servers (which generally includes players from North America, Latin America, Australia, New Zealand, and Southeast Asia) the answer to the personal security question, and information relating to Mobile and Dial-In Authenticators were also accessed. Based on what we curren…

I believe Blizzard makes you supply a scanned copy of your state issued identification in order to get a password reset.
Post reply on HN