Page 1 of 2 1 2 LastLast
Results 1 to 20 of 35

Thread: Battle.net compromised     submit to reddit submit to twitter

  1. #1
    blax n gunz
    Join Date
    May 2005
    Posts
    11,141
    BG Level
    9

    Battle.net compromised

    Press Release

    F.A.Q.

    Change your passwords immediately.
    You can't change your security question/answer yet.
    Mobile authenticator data was grabbed (i.e. phone numbers). Keychain authenticators should still be fine.
    Now would be a good time to check out services like keepass to store your passwords/secret answers.
    Don't forget this easy primer on how to pick a secure password, even though battle.net stops you at 16 characters.

  2. #2
    Nikkei's Hoe
    Worse than her at uno

    Join Date
    Dec 2006
    Posts
    6,236
    BG Level
    8
    FFXIV Character
    Eanae Hikari
    FFXIV Server
    Gilgamesh
    FFXI Server
    Cerberus
    WoW Realm
    Hyjal

    All passwords were salted/hashed so no big deal there. Nothing stolen is enough to steal an account straight up, but the list of emails grabbed has to be absolutely massive.

  3. #3
    Ridill
    Join Date
    Feb 2007
    Posts
    15,537
    BG Level
    9

    *snickers*

  4. #4
    The Defense is ready, Your Honor
    Join Date
    Sep 2007
    Posts
    20,630
    BG Level
    10
    FFXIV Character
    Lord Longhaft
    FFXIV Server
    Gilgamesh
    FFXI Server
    Cerberus
    WoW Realm
    Mug'thol

    Is this the future of online gaming? Ugh. Every major game. Every time. I can't even take 3 months off of a MMO without coming back to a hacked-and-stolen character.

  5. #5
    Nikkei's Hoe
    Worse than her at uno

    Join Date
    Dec 2006
    Posts
    6,236
    BG Level
    8
    FFXIV Character
    Eanae Hikari
    FFXIV Server
    Gilgamesh
    FFXI Server
    Cerberus
    WoW Realm
    Hyjal

    Nothing was taken that should lead to a stolen account. Passwords were luckily properly encrypted as they should have been (eyes on you Sony). Authenticator stuff may be a mess to clean up for sure. The major thing taken here is your email address. Incoming 100x more phishing emails. Really have to keep an eye on any correspondence from Blizzard for secure links for quite a while now...

  6. #6
    Ridill
    Join Date
    Aug 2005
    Posts
    22,165
    BG Level
    10

    Quote Originally Posted by arus2001 View Post
    *snickers*
    THIS IS IMPOSSIBLE THEY WOULD NEVER ACTUALLY ADMIT GETTING HACKED OMG WE'RE ALL HALLUCINATING AND THIS REALLY HAPPENED A FEW MONTHS AGO AND THEY'RE NOT ACTUALLY ADMITTING IT!

  7. #7
    Resident Moogle
    Join Date
    Mar 2007
    Posts
    13,173
    BG Level
    9
    FFXI Server
    Asura

    Quote Originally Posted by Eanae View Post
    Incoming 100x more phishing emails.
    I still get BNet phising e-mails to my old ISP-tied e-mail account even though I've not had it associated with BNet in over 5 years. Thankfully Gmail seems pretty on top on what's obvious phising and what isn't, so it shouldn't affect my current address too much.

    At least they were on top of shit.

  8. #8
    I'm almost as bad as Mazmaz
    Sweaty Dick Punching Enthusiast

    Join Date
    Jul 2008
    Posts
    25,978
    BG Level
    10

    Luckily I send everything I get from Blizzard straight to junk already.

    Actually as I say this I've got 10 new emails in my junk folder right now from "Blizz" and "Diablo".

  9. #9
    The Defense is ready, Your Honor
    Join Date
    Sep 2007
    Posts
    20,630
    BG Level
    10
    FFXIV Character
    Lord Longhaft
    FFXIV Server
    Gilgamesh
    FFXI Server
    Cerberus
    WoW Realm
    Mug'thol

    Been getting a bunch of new spam email. Why am I not surprised. Blizzard is just too big a target.

  10. #10
    Ridill
    Join Date
    Aug 2005
    Posts
    22,165
    BG Level
    10

    Not sure if I'm getting anything new or not, but the same amount as usual of the ones that are cloning my own email (i.e. it says it's from "Blizzard Services, myemail@address") are leaking through into the shit I actually look at.

  11. #11
    Certified Enhancement Shaman
    Join Date
    May 2008
    Posts
    1,871
    BG Level
    6
    FFXIV Character
    Meph Taru
    FFXIV Server
    Diabolos

    is it only NA that got h4x0r3d? I dont wanna change my pass again :/

  12. #12
    wotg torrent kitty :3
    Join Date
    Jun 2007
    Posts
    1,624
    BG Level
    6

    Quote Originally Posted by Meph View Post
    is it only NA that got h4x0r3d? I dont wanna change my pass again :/
    don't have to fear anything else than more spam if your account isn't on NA servers:

    North American-based accounts, including players from Latin America, Australia, New Zealand, and Southeast Asia

    - Email addresses
    - Answers to secret security questions
    - Cryptographically scrambled versions of passwords (not actual passwords)
    - Information associated with the Mobile Authenticator
    - Information associated with the Dial-in Authenticator
    - Information associated with Phone Lock, a security system associated with Taiwan accounts only

    Accounts from all global regions outside of China (including Europe and Russia)

    - Email addresses

    China-based accounts

    - Unaffected

  13. #13
    blax n gunz
    Join Date
    May 2005
    Posts
    11,141
    BG Level
    9

    Quote Originally Posted by Eanae View Post
    Nothing was taken that should lead to a stolen account. Passwords were luckily properly encrypted as they should have been (eyes on you Sony). Authenticator stuff may be a mess to clean up for sure. The major thing taken here is your email address. Incoming 100x more phishing emails. Really have to keep an eye on any correspondence from Blizzard for secure links for quite a while now...
    The secret question/answer pairs are also problematic as it makes it easier for someone to phone blizzard and provide those for access. Blizzard can guard against this with stronger phone support policies, but I'm willing to bet a lot of bnet users also use identical question/answer pairs on more important online accounts like banking.

  14. #14
    Nikkei's Hoe
    Worse than her at uno

    Join Date
    Dec 2006
    Posts
    6,236
    BG Level
    8
    FFXIV Character
    Eanae Hikari
    FFXIV Server
    Gilgamesh
    FFXI Server
    Cerberus
    WoW Realm
    Hyjal

    I'm going to go out on a limb and say they won't allow that information to reset passwords until they have everyone change theirs (speculation obviously). They also ask for a cd key that's tied to your account to do anything regarding password/authenticator resets so it really doesn't effect anything within battle.net anyways.

  15. #15
    Brown Recluse
    Sweaty Dick Punching Enthusiast

    Join Date
    May 2006
    Posts
    28,080
    BG Level
    10
    FFXI Server
    Unicorn

    But I use an authenticator! I can't be hacked. It's the players fault not blizzard.

  16. #16
    Nikkei's Hoe
    Worse than her at uno

    Join Date
    Dec 2006
    Posts
    6,236
    BG Level
    8
    FFXIV Character
    Eanae Hikari
    FFXIV Server
    Gilgamesh
    FFXI Server
    Cerberus
    WoW Realm
    Hyjal

    Quote Originally Posted by Dimmauk View Post
    But I use an authenticator! I can't be hacked. It's the players fault not blizzard.
    Sony, EA, Riot, Valve, Trion, Dropbox, LinkedIn, and countless other organizations hacked within the last year. If someone wants into a database bad enough they'll get into it. All the information that really matters was protected. Go circle jerk somewhere else.

  17. #17
    Eli Manning is my Lord and Savior
    Join Date
    Dec 2007
    Posts
    6,097
    BG Level
    8
    FFXI Server
    Cerberus
    WoW Realm
    Greymane

    The Sony info actually wasn't that protected.

  18. #18
    Nikkei's Hoe
    Worse than her at uno

    Join Date
    Dec 2006
    Posts
    6,236
    BG Level
    8
    FFXIV Character
    Eanae Hikari
    FFXIV Server
    Gilgamesh
    FFXI Server
    Cerberus
    WoW Realm
    Hyjal

    Yeah I know. Mentioned that in an above post. I meant blizzards info is protected. From their blog post it looks like all passwords are uniquely salted so even of you happened to crack one password (which won't happen), you'll have to individually crack them all.

  19. #19
    Brown Recluse
    Sweaty Dick Punching Enthusiast

    Join Date
    May 2006
    Posts
    28,080
    BG Level
    10
    FFXI Server
    Unicorn

    But YOU said it was the players fault. Do I need to go back and quote? Blizzard fucked up. Story end. I'm still playing btw.

  20. #20
    Nikkei's Hoe
    Worse than her at uno

    Join Date
    Dec 2006
    Posts
    6,236
    BG Level
    8
    FFXIV Character
    Eanae Hikari
    FFXIV Server
    Gilgamesh
    FFXI Server
    Cerberus
    WoW Realm
    Hyjal

    If the players are having their accounts stolen it still is their fault. How dense are you to realize nothing stolen here will lead to hacked battle.net accounts?

Page 1 of 2 1 2 LastLast

Similar Threads

  1. Battle.net World Championship 2012
    By 6souls in forum Gaming Discussion
    Replies: 0
    Last Post: 2012-01-25, 22:04
  2. Replies: 308
    Last Post: 2010-07-17, 15:37
  3. Returning to WoW; Trouble with Merger into Battle.net
    By ChooChooTrain in forum Gaming Discussion
    Replies: 16
    Last Post: 2010-04-27, 09:39
  4. Uh, wtf Battle.net?
    By Eanae in forum Gaming Discussion
    Replies: 12
    Last Post: 2010-03-05, 21:04
  5. Battle.net mobile authenicator now available!!
    By Misterjingles in forum Gaming Discussion
    Replies: 2
    Last Post: 2009-04-02, 08:04
  6. Battle.net Update (beta opt-in?)
    By geno in forum Gaming Discussion
    Replies: 0
    Last Post: 2009-03-19, 18:32