Is Blizzard Compromised?

#0 - May 21, 2010, 5:46 p.m.
Blizzard Post
Massive accounts got hacked recently. I have been playing wow for like since start, never got hacked until now.
I have all the protection installed etc, you name it i have it as im aware of all this stuff.

Now hackers are adding authenticators to account? WTF? so you mean they have their own authenticator? Moving accounts to battle.net was a mess.

Its either you have a huge security breach on your end or there is a new trojan out that is not yet detected. I say its the former.
#5 - May 21, 2010, 6:37 p.m.
Blizzard Post
Q u o t e:
Honestly, the biggest danger of all is thinking you're invulnerable. The best we can do is apply as many security means as we can - unique email address, unused anywhere else, password we don't use anywhere else, answer to security question that no one else could learn, our operating system, browser, browser plugins, and virus/malware scanners kept completely up-to-date, scans run regularly, Authenticator applied, and so on. Still doesn't make us 100% invulnerable, but it makes us a tough target comparatively.


I like you.
#25 - May 21, 2010, 7:31 p.m.
Blizzard Post
Q u o t e:
thats kinda why Im here making a stink..


Unfortunately, by doing so you do a disservice to yourself and others by diverting attention away from awareness and personal system security. Were there a breach of our security, frankly, we would have substantially larger issues than compromised accounts. While extremely upsetting and unfortunate, even were something of that nature to occur, it would be correctable. If our systems were breached, there is financial information to consider, and the cost in intellectual property alone would be staggering.

Needless to say, extremely tight security is very much in our best interest. As I stated elsewhere:

http://forums.worldofwarcraft.com/thread.html?topicId=25001940455&pageNo=2&sid=1#30

Q u o t e:
When something like this occurs, it's perfectly natural to look for answers and try to find some causality. That's actually not only reasonable, but by far the best and most preferable course of action. I'm delighted to hear that you make active use of well regarded malware scans, but I also feel compelled to remind you of a couple things.

The unfortunate truth is that it doesn't matter how effective your system security is if:

* You've ever provided your account information to another person.
* You fell prey to a phishing scam.
* You've ever logged in from a potentially unsecured or infected system.

There's more than one method of ingress for malicious account thieves, I'm afraid. Merely because you haven't found a keylogger, is not indicative of a security issue on our end.

As of this moment, I can confidently state that our systems remain secure. I would remind those reading that there is more at stake in our security measures than player accounts (though that information is crucially important). We also have all kinds of our own data and creative properties to protect, that are vital to the existence of Blizzard Entertainment.

Approaching the situation logically and bluntly: those who engage in these practices have a much easier time getting account information directly from our customers - ultimately a cheaper and better course of action for them. Where keyloggers and trojans fail, they fall back on social engineering and phishing. I'm sure that if those measures were no longer as effective, that they'd devise new ways to get at your accounts.

That's one of the reasons why we made the Blizzard Authenticator and Mobile Authenticator available, as well invested effort in helping to educate our players regarding account security:

Account Hacked? Security Issue? Look Here!
http://forums.worldofwarcraft.com/thread.html?topicId=24702231244&sid=1

Moving forward, and within the bounds of appropriate responsibility, we will continue to examine new and better methods to help protect and educate our players.


Q u o t e:
"Unthinking respect for authority is the greatest enemy of truth!"


Agreed! Unthinking defiance of rationality can be disastrous as well though - and has spawned many a conspiracy theory based on plausibilities of molecular thinness.
#39 - May 21, 2010, 7:54 p.m.
Blizzard Post
Q u o t e:


Not that I would hack Blizzard if I could! Malkorix, don't send the blue blizzard security team after me. :/


AFK OMW TO ARAENNA'S HOUSE.
#46 - May 21, 2010, 8:13 p.m.
Blizzard Post
Q u o t e:
ONOEZ. /flee


/purr
#53 - May 21, 2010, 8:37 p.m.
Blizzard Post
Q u o t e:
I love how must threads with Mal tend to be full of win.


If you would like to provide feedback on my posting style, you can send a note to [email protected] =3.
Q u o t e:

maybe.... whos to say account information is stored in the same place or with the same restrictions that bank / cred card information is stored in.

In fact, the reason these hacked accounts dont start losing their finances and or their bank accounts dont become compromised is due to the increased security in regards to this information. go to your own account, and look at your payment information, most of it is listed with ******'s for a good reason.


Did you read my posts? I mean no disrespect - I'm just curious.