16 character max password with no special characters allowed. .. Are you people high or something? This is 2012, when every major provider has been owned at least once. Not AOL circa 1995. Get with the program, Blizzard!
While that is bad, according to my napkin calculations that still gives you 82 bits of entropy for your password (if you randomly generate it, taking into account that they aren't case-sensitive {seriously}).
82 bits is actually "good enough" so, for now, not too big a deal. The bigger deal is the SHA1 + salt hash they're using to store them!
"Some data was illegally accessed, including a list of email addresses for global Battle.net users, outside of China. For players on North American servers (which generally includes players from North America, Latin America, Australia, New Zealand, and Southeast Asia) the answer to the personal security question, and information relating to Mobile and Dial-In Authenticators were also accessed. Based on what we curren…
Agreed. I really dislike the "security question" feature a lot of sites force you to enter. In my opinion they make my account much less secure than it would be without this feature. There are plenty of people around who know my email address and have the means to find out my mother's maiden name, or what car I first had or whatever ridiculous information I'm forced to provide to "secure" my account.
> Do these have to be human-confirmable? Wondering why they're stored in plaintext.. I've been curious about this before. Do you-folks store your challenge-question-answers in plaintext? I would hazard a guess that most sites store "Secret Questions/Answers" in plain text, or a two-way hash (that their support app reverses), as they are used to confirm identity along with the basics (DOB, address, email, etc).
> a two-way hash (that their support app reverses) Isn't that just encryption?
I'm not a security expert, but yes. Hashing is, by definition, a one way process. If it is meant to be encrypted and decrypted it's, well, encryption...
"Some data was illegally accessed, including a list of email addresses for global Battle.net users, outside of China. For players on North American servers (which generally includes players from North America, Latin America, Australia, New Zealand, and Southeast Asia) the answer to the personal security question, and information relating to Mobile and Dial-In Authenticators were also accessed. Based on what we curren…
Agreed. I really dislike the "security question" feature a lot of sites force you to enter. In my opinion they make my account much less secure than it would be without this feature. There are plenty of people around who know my email address and have the means to find out my mother's maiden name, or what car I first had or whatever ridiculous information I'm forced to provide to "secure" my account.
These shouldn't be genuine answers. Put your grandmothers maiden name instead of your mothers, your first car could be Apollo 11.
"Some data was illegally accessed, including a list of email addresses for global Battle.net users, outside of China. For players on North American servers (which generally includes players from North America, Latin America, Australia, New Zealand, and Southeast Asia) the answer to the personal security question, and information relating to Mobile and Dial-In Authenticators were also accessed. Based on what we curren…
Secret questions are extreme bad security practice. They're essentially a way to trade off a large amount of user security for reduced customer support costs. It's the same as telling your users to pick a weak password (one that's very likely to be in a dictionary) and then give the attacker a hint what it is. On top of that, many providers (apparently Blizzard included) do not treat the answer to the security question as carefully as a password, e.g., they store it in plain text.
I still haven't received an email about this. My last email from blizzard was three months ago when I bought D3. I hope they plan on sending out something soon with a good explanation on why hackers having your ASQ is a really bad thing.
I still haven't received an email about this. My last email from blizzard was three months ago when I bought D3. I hope they plan on sending out something soon with a good explanation on why hackers having your ASQ is a really bad thing.
Also a detailed post-mortem would be neat but I'm not holding my breath on that one.
The only problem is that in 5 years you'd have no idea what you answered there. And that's exactly when you'd need it.
Yeah, unless you do it consistently everywhere, which again defeats the purpose. Maybe you could do something like consistently answer the previous question from the dropdown?
Or use a tool like 1password to generate and store the 'answers'.
This sort of thing kind of bothers me. Is Blizzard in the business of verifying state-issued identification? What prevents me from photoshopping my target's name on top of my own ID?
I'm not sure how ID cards work across the globe but usually they have some code on them that is supposed to be unique. So you would have to scan your name _and_ the other data, which you would not trivially know. (Yes, I understand that there are ways to get those too)
> "(Yes, I understand that there are ways to get those too)"
And at the point that someone can get a passable fake ID in your name, you have far bigger problems than their social-hacking an online service account.
As mentioned by other people in other recent threads some good quality password safe programs work with Yubikey, so an attacker needs something you know (your password) and something you have (your Yubikey). I'd be interested in seeing some robust analysis of password safe software. But "Password safe" and "keepass" appear to be reputable. I'd also like a native, and trustworthy, password safe for OS X that can work…
Is Yubikey superior to something like Keepass/Lastpass/1password?
Yubikey would be in addition to the password used on Keepass.
So you need your password and the Yubikey to unlock your password safe.
You could set the Yubikey up to be the password - so you only need the Yubikey to open up Keepass.