Live data from Hacker News

Blizzard Network Breached; Change Your Battle.Net Passwords

kotaku.com

61–70 of 164 posts

Re: Blizzard Network Breached; Change Your Battle.Net Passwords

#61
post #3

Earlier quoted context omitted.

Either that or 2-factor authentication will catch on and stealing passwords won't be worth anything.

Blizzard has 2 factor; the secrets for the mobile authenticator seem to have been compromised as well as the hashed passwords.

But secrets for the mobile authenticator are much less sensitive than passwords, which are prone to reuse. It does, however, defeat the security advantage of two-factor authentication.

(I always thought the really smart crackers would break in, modify the application code to weaken the password encryption, and then re-encrypt every password when the user logs in. Come back a few weeks later and collect a bunch of working passwords, with nobody the wiser.)

Re: Blizzard Network Breached; Change Your Battle.Net Passwords

#62

This is ridiculous. Maybe the world is ending, because it feels like every major website/provider of some popular service is getting hacked these days. A company of Blizzard's stature and wallet size has no excuse for this kind of thing happening, no excuse at all. If you're charging people exorbitant amounts of cash to buy your games and then charging some of your customers a fee for the privilege of using your so-c…

Blizzard is _literally_ under _constant_ attack and has an incredible security team in place. Obviously the only acceptable result is 100% attack deflection, but the idea that this could be or could have been anything short of an absolute top priority for the company is a ridiculous assertion that I'd expect on any other site, but not HN.

I'm a former Blizzard employee with knowledge of the situation and internal workings. EDIT: I am, of course, not remotely qualified to speak for Blizzard or the security team.

Re: Blizzard Network Breached; Change Your Battle.Net Passwords

#63
post #58
post #42

Earlier quoted context omitted.

Of course, your answer should NEVER match the question. But that's beside the point. "Whose was your favorite high school teacher?" -Pecan pie.

The point still stands, though. There is way, way too much potential variation to hash that stuff.

I think the bigger point is that a ton of signups use this question. Whether you say 'Mr. Smith' or 'Pecan Pie' isn't going to save you if you use it for all of them.

Re: Blizzard Network Breached; Change Your Battle.Net Passwords

#64

Looks like Vivendi should have moved quicker with their plans on selling Activision Blizzard. Poor guys. I wonder how much this sad news will impact the success of the WoW: Mists of Pandaria (launch planned on 09/25).

My guess: almost zero impact, long term.

Re: Blizzard Network Breached; Change Your Battle.Net Passwords

#65
post #4

"Some data was illegally accessed, including a list of email addresses for global Battle.net users, outside of China. For players on North American servers (which generally includes players from North America, Latin America, Australia, New Zealand, and Southeast Asia) the answer to the personal security question, and information relating to Mobile and Dial-In Authenticators were also accessed. Based on what we curren…

Do these have to be human-confirmable? Wondering why they're stored in plaintext.. I've been curious about this before. Do you-folks store your challenge-question-answers in plaintext?

I think a good balance between usability and security is to normalize the answer (discard case, punctuation, etc) and then hash it.

Re: Blizzard Network Breached; Change Your Battle.Net Passwords

#66
So I went to update my password for my World of Warcraft account after I saw this.

And guess what I discovered, my current password is more secure than their current password policy will allow. So I filled out a support ticket with the following question (which all Blizzard account holders should ask them)

I was wondering why even after you discovered a security breach you have not updated your password policy to actually allow secure passwords. Your current password policy only allows password that will take a day or two to brute force crack. see http://xkcd.com/936/

These two rules totally nullify any security of your passwords

"Your password must be between 8–16 characters in length. Your password may only contain alphabetic characters (A–Z), numeric characters (0–9), and punctuation."

In fact my current password is better since I apparently created it before your policy changed to not allow non alpha-numeric characters.

The only reason to have those two rules is because you are storing the password in plain text so anyone who gets access to the database can read them freely. Please update your password policy to

"Your password must be at least 20 characters long."

That is it, let me make a 400 character password if I want, let me use cyrillic, chinese, or whatever other unicode characters I want to use. If you truly care about security you will fix your broken password policy!

Re: Blizzard Network Breached; Change Your Battle.Net Passwords

#67

This is ridiculous. Maybe the world is ending, because it feels like every major website/provider of some popular service is getting hacked these days. A company of Blizzard's stature and wallet size has no excuse for this kind of thing happening, no excuse at all. If you're charging people exorbitant amounts of cash to buy your games and then charging some of your customers a fee for the privilege of using your so-c…

Blizzard is _literally_ under _constant_ attack and has an incredible security team in place. Obviously the only acceptable result is 100% attack deflection, but the idea that this could be or could have been anything short of an absolute top priority for the company is a ridiculous assertion that I'd expect on any other site, but not HN. I'm a former Blizzard employee with knowledge of the situation and internal wor…

Security has nothing to do with preventing the attack, it's more so protecting the data much like a bank protects it's assets. It's pretty easy to break into a bank (they're merely glass and brick after all), but there is no way you're getting into that vault once inside and even so, if you get into the vault there are secondary security procedures in place to ensure that nothing is easily taken.

So regardless of whether or not Blizzard is under constant attack, just because someone can get in doesn't mean they should be able to take anything.. I really do hope Blizzard don't go into the banking industry because everyone will be lining up to steal what they can from the easily penetrable building and vault inside. There is no excuse.

If Blizzard is under constant attack, you'd think they'd be smarter about how data is stored and just what an attacker could see if they gained access to a database of any kind. So once again, my point was not about deflecting attacks because that's impossible, it's about making it almost impossible for the hacker to use any of the information he can access.

Re: Blizzard Network Breached; Change Your Battle.Net Passwords

#69
post #42
post #25

Earlier quoted context omitted.

Well, that would be thhe reason, I think... Example: For: "Who was your favorite high school teacher." - Mr. Berners-Lee - Mr. Berners Lee - Tim Berners-Lee - Mr. Lee Never mind if you had two different teachers who were great, and you switch them interchangeably depending on whether you're in an English mood or a Music mood

Of course, your answer should NEVER match the question. But that's beside the point. "Whose was your favorite high school teacher?" -Pecan pie.

The only problem is that in 5 years you'd have no idea what you answered there. And that's exactly when you'd need it.

Re: Blizzard Network Breached; Change Your Battle.Net Passwords

#70

Earlier quoted context omitted.

Blizzard is _literally_ under _constant_ attack and has an incredible security team in place. Obviously the only acceptable result is 100% attack deflection, but the idea that this could be or could have been anything short of an absolute top priority for the company is a ridiculous assertion that I'd expect on any other site, but not HN. I'm a former Blizzard employee with knowledge of the situation and internal wor…

Security has nothing to do with preventing the attack, it's more so protecting the data much like a bank protects it's assets. It's pretty easy to break into a bank (they're merely glass and brick after all), but there is no way you're getting into that vault once inside and even so, if you get into the vault there are secondary security procedures in place to ensure that nothing is easily taken. So regardless of whe…

Did you really just insinuate that banks never get robbed?
Post reply on HN