Putting the 'role' back in role-playing games since 2002.
Donate to Codex
Good Old Games
  • Welcome to rpgcodex.net, a site dedicated to discussing computer based role-playing games in a free and open fashion. We're less strict than other forums, but please refer to the rules.

    "This message is awaiting moderator approval": All new users must pass through our moderation queue before they will be able to post normally. Until your account has "passed" your posts will only be visible to yourself (and moderators) until they are approved. Give us a week to get around to approving / deleting / ignoring your mundane opinion on crap before hassling us about it. Once you have passed the moderation period (think of it as a test), you will be able to post normally, just like all the other retards.

Game News Blizzard hacked: Emails, security questions and answers and encrypted Diablo 3 passwords accessed

Weierstraß

Learned
Joined
Apr 1, 2011
Messages
282
Location
Schwitzerland
Project: Eternity
By "cryptographically scrambled", do they mean they got the hashes or what?
 

Metro

Arcane
Beg Auditor
Joined
Aug 27, 2009
Messages
27,792
At this point I'm sure the damage is done. The objective was probably to grab access to as many accounts as possible, empty them of gold/virtual items, and then sell them via farmers or whatever. Same thing was probably happening with D3 when that was reported.
 

Black

Arcane
Joined
May 8, 2007
Messages
1,872,643
At this point I'm sure the damage is done. The objective was probably to grab access to as many accounts as possible, empty them of gold/virtual items, and then sell them via farmers or whatever. Same thing was probably happening with D3 when that was reported.
If some credit card info was stolen there will be an even more massive shitstorm :bounce:
 
Joined
Jan 7, 2012
Messages
14,241
Thats hilariously retarded, but not all that bad considering that 16 character passwords are fairly secure even without case sensitivity. It's the people who have 8 letter passwords which are actually about the strength of a 5-6 letter case-sensitive password who are fucked, and I'm pretty sure the average person has a password under 8 characters.

Not that the average person isn't already using 12345 as their password, but whatever.
 

Mad Method

Novice
Joined
Jan 6, 2012
Messages
9
That's nothing. I hear this bank called Wells Fargo caps your password at 13 characters.
 

Metro

Arcane
Beg Auditor
Joined
Aug 27, 2009
Messages
27,792
If some credit card info was stolen there will be an even more massive shitstorm :bounce:

Eh, doubtful. That's what everyone said about the Valve hacking. The encryption most major companies use for credit card information is AES 256 which is -- for all practical purposes -- impossible to crack without the key.
 
Joined
Jan 7, 2012
Messages
14,241
If some credit card info was stolen there will be an even more massive shitstorm :bounce:

Eh, doubtful. That's what everyone said about the Valve hacking. The encryption most major companies use for credit card information is AES 256 which is -- for all practical purposes -- impossible to crack without the key.

...you DO realize that they almost certainly have the key now, right?
 

Metro

Arcane
Beg Auditor
Joined
Aug 27, 2009
Messages
27,792
I really don't know either way. I'd say it's speculation. It's certainly possible but I wouldn't say 'almost certainly.' Guess we'll know if we see a rash of credit card fraud going on in the next week or so. It's already been five or six days. If the CC info was the ultimate target then they wouldn't waste much time selling the numbers off/making use of them. Keep in mind I'm sure the CC information doesn't use the same encryption that the passwords do. Unless they're absolute morons.
 

sgc_meltdown

Arcane
Joined
May 8, 2003
Messages
6,000
I for one think that it's wonderful that videogame technology has progressed to the point that you can get personal information stolen from your mandatory online singleplayer game account without the commitment of an paid subscription

it's okay though because just like with action rpg design blizzard is fairly new at this online security thing and will do their best to improve upon their excellent foundation

because blizzard cares about their fans
 

Shannow

Waster of Time
Joined
Sep 15, 2006
Messages
6,386
Location
Finnegan's Wake
Funny, but somewhat related, got two spam mails yesterday informing me that my Diablo 3 account is compromised and I should change my password iby hacker provided link.:roll:
I guess it might come as a shock, but I dont have a Diablo 3 account nor the game. :smug:
My guess is that the hackers also got WoW account information while they had their way with Blizz.
At this time, we’ve found no evidence that financial information such as credit cards, billing addresses, or real names were compromised. Our investigation is ongoing, but so far nothing suggests that these pieces of information have been accessed.
I heard that before:
"There is no mass-hacking of D3 accounts. There is no security hole. Nobody who buys an authenticator will ever be hacked. These are not the droids you are looking for."

As a reminder, phishing emails will ask you for password or login information. Blizzard Entertainment emails will never ask for your password.
As a precaution, however, we recommend that players on North American servers change their password. Please click this link to change your password. Moreover, if you have used the same or similar passwords for other purposes, you may want to consider changing those passwords as well.
"Please follow this link and enter your old password before entering your new password twice."
:bro:

(Yeah, I know... still funny.)
 
Self-Ejected

Ulminati

Kamelåså!
Patron
Joined
Jun 18, 2010
Messages
20,317
Location
DiNMRK
Diablo 3 is the gift that keeps on giving if you didn't purchase it and are content to watch the trainwreck from afar. You think the whole thing is over save for the screams of the injured, then something ignites a chemical tank and you get a whole new set of 'splosions to "ooh!" and "aaah!" at.

Good thing my battle.net password hasn't been touched since I grew tired of Starcraft 2. It's about a dozen password changes behind everything else I use. By all means, chinese hackerbros. Go to town with my battle.net account. There's nothing on it worth stealing anyway :lol:

Waiting for gaudaost to write an elaborate argument that tries to cast the blame onto the people who forgot to buy some additional blizzard email protection service. Or how about you, fizzelopeguss? Still going to maintain that diablo 3 isn't several levels of buttrape the consumer beyond TOR? :smug:
 

fizzelopeguss

Arcane
Joined
Oct 1, 2004
Messages
843
Location
Equality Street.
Already in the MMO forum, it's the whole of battle.net. And i don't think people realise how massive this is yet, blizzard spends millions on security...they're not some little chickenshit outfit. To be busted wipe open the way they have is enormous and opens up serious questions on the amount of personal details we give these companies.

hacking community sites and phishing for usernames/passwords is one thing, assfucking sony, xboxlive and blizzard is another. So err, if you have an origin and steam account...you might wanna remove any CC info pronto.
 
Self-Ejected

Ulminati

Kamelåså!
Patron
Joined
Jun 18, 2010
Messages
20,317
Location
DiNMRK
Who in their right mind saves CC info on sites longer than it takes to perform whatever transaction you're paying for O_o

Probably the same schmucks who don't keep seperate passwords for forums/banking/amazon/steam/whatever.
 

fizzelopeguss

Arcane
Joined
Oct 1, 2004
Messages
843
Location
Equality Street.
Who in their right mind saves CC info on sites longer than it takes to perform whatever transaction you're paying for o_O

you'll be surprised, steam practically relies on it during sales periods (their biggest revenue earner) under a guise of "convenience".

Amazon "buy in 1-click" or whatever they call it.

MMO recurring subscriptions (i usually go for time cards).

it's getting a bit retarded when computer games require as much security input as your bank account.
 

DraQ

Arcane
Joined
Oct 24, 2007
Messages
32,828
Location
Chrząszczyżewoszyce, powiat Łękołody
I don't buy shit through steam and I keep it offline whenever not installing or updating something IN ADDITION TO not storing any sort of sensitive data on it.

I treat it as what it is - a bit more tolerable than normal DRM.
 

fizzelopeguss

Arcane
Joined
Oct 1, 2004
Messages
843
Location
Equality Street.
Piracy is wrong kids. fizzle ensures us he actually meant to say "borrowed from a friend".
Steam are terrible, their UK prices are a joke and the shit that goes on sale i've already probably played/pirated already.

Decent aggregator of F2P shite though, their download servers are blazing fast to download clients from.
 

aris

Arcane
Joined
Apr 27, 2012
Messages
11,613
Diablo 3 is the gift that keeps on giving if you didn't purchase it and are content to watch the trainwreck from afar. You think the whole thing is over save for the screams of the injured, then something ignites a chemical tank and you get a whole new set of 'splosions to "ooh!" and "aaah!" at.

Good thing my battle.net password hasn't been touched since I grew tired of Starcraft 2. It's about a dozen password changes behind everything else I use. By all means, chinese hackerbros. Go to town with my battle.net account. There's nothing on it worth stealing anyway :lol:

Waiting for gaudaost to write an elaborate argument that tries to cast the blame onto the people who forgot to buy some additional blizzard email protection service. Or how about you, fizzelopeguss? Still going to maintain that diablo 3 isn't several levels of buttrape the consumer beyond TOR? :smug:
Holy shit? You're part of codex staff now? Seems like your buttlicking has really payed off, and that this forum really is declining.
 

Metro

Arcane
Beg Auditor
Joined
Aug 27, 2009
Messages
27,792
Who in their right mind saves CC info on sites longer than it takes to perform whatever transaction you're paying for o_O

Probably the same schmucks who don't keep seperate passwords for forums/banking/amazon/steam/whatever.

Sometimes the companies continue to store your information on their servers even if you select delete/opt out or whatever. Not surprisingly they aren't 100% honest about things.
 
Self-Ejected

Ulminati

Kamelåså!
Patron
Joined
Jun 18, 2010
Messages
20,317
Location
DiNMRK
True. But at least it means that if your account gets hijacked, they don't automatically get the CC info to use elsewhere as well. the alternative is not shopping online at all sadly. :/
 

Mother Russia

Andhaira
Andhaira
Dumbfuck Queued
Joined
Jan 6, 2012
Messages
3,876
Codex 2013
Blizzard is fucked.

Are they trying to blame Chyna? I mean, didn't they say all passwords outside of China were hacked...or something like that.
 

As an Amazon Associate, rpgcodex.net earns from qualifying purchases.
Back
Top Bottom