Go back to school with your Mac, iPhone and TUAW
Posts with tag account-security

Authenticator failure revisited, Blizzard responds

We created a lot of waves with this post about Blizzard's Authenticator key allegedly failing -- as you know if you've been listening to the podcast, lots of people have emailed us with their own input on the situation, alternately thanking us for making it known that the Authenticator wasn't 100% secure, and lambasting us for being "ignorant" about how Blizzard's security token works. At the base of the story, there are two things we know are true: that someone was using the Authenticator on their account, and then was subsequently hacked. For that reason, we've stood by the "Authenticator fails" story -- while having an Authenticator on your account is a helpful line of defense, it, like all other computer security measures, isn't a 100% guarantee against getting hacked.

Most people agree on that. Where opinions differ are in how the account was hacked -- originally, we and a few other sources speculated that the Authenticator had been somehow removed from the account in question. But now Belfaire has responded (we believe to the incident in question, though a link to our story was removed from the original post), and says that as far as he can tell, the Authenticator was not removed from the account. In fact, after the password was changed back, the Authenticator's serial key was asked for and given, so the Authenticator remained attached to the account the whole time.

Of course, that just leaves the most important question: how did the account get hacked? We've heard all kinds of various insights as to how the Authenticator works (it only lasts for 60 seconds, supposedly each key can only be used once, so there's no way a keylogger could nab the Authenticator code and reuse it), but the fact remains that the person we're talking about was using the key, and still got hacked. One hack out of all the Authenticators sold so far is a terrific record, and could prove that, statistically, an Authenticator is good as 100% security. But the fact remains that this person got hacked while using the key (however it was done), and if security can be broken once, it will be broken again.

Authenticator fails, removed from account without user's permission

Think a Blizzard Authenticator will keep your account from being hacked? Think again -- we've got our first known report of someone who was protecting their account with one of Blizzard's keys, and still got their character hacked down to their undies. Someone in this forum thread apparently logged out one night and logged on the next morning to find her account stripped of everything but PvP gear, and her Authenticator no longer connected to her account.

Supposedly, to deactivate an Authenticator from an account, you need to get in touch with Billing services, and reportedly they'll then ask for a notarized statement with a picture, like a driver's license, just to remove the Authenticator. But obviously, this one was removed even without that, and we're being told that all you might need to remove the Authenticator is the answer to the user's secret question and a CD key (or even less). In other words, the fault isn't with the technology, it seems to be with the support reps on Blizzard's side of the phone line -- if they can be convinced to remove the Authenticator, the account can then be hacked.

The little keys have been selling like hotcakes since they were released -- almost everyone has figured that $6.50 was cheap for peace of mind. But while an Authenticator still does provide an extra step in security, the sad truth is that it hardly makes an account impermeable.

[Via BRK]

Update: Married IRL has more analysis, including a comment that confirms all you really need to get past the Authenticator is the user's secret question answer, usual address information, and the original CD key. If the standard for getting an Authenticator removed really is a Photo ID, it's fairly clear that Blizzard's reps aren't doing their jobs right.

More after the break.

Continue reading Authenticator fails, removed from account without user's permission

Authenticators are going out, via USPS

We had heard that there were problems with the Blizzard Authenticator (a few people who'd ordered them had gotten their money refunded by Blizzard), but apparently there are at least a few going out. Mania got hers -- she says that it works great, that she has already associated it with her accounts, and that she's thrilled with her purchase.

Not everybody is so lucky -- reader Tweaky emailed us to say that his order was supposed to go out UPS Next Day Air, but after it didn't show up and he had a tussle with Customer Support, he then found out it was actually going through the USPS and that it would show up late. No word on whether he's seen his yet or not. A few people commented on our last post that they actually had shipping returned to them, so maybe Blizzard originally planned to send some UPS, and then had to switch to a cheaper mailing method.

At this point, Blizzard has the keyfob sold out on their website, and there's no indication when we'll see any more (soon, probably). It appears that not only did they vastly underestimate demand for the Authenticator, but that people are seriously concerned about the security of their World of Warcraft account. No other game company has ever offered anything like this before, but given the response, it could soon become a standard.

Avast! update causing issues with WoW

Avast! anti-virus, which is used by millions of people around the world, recently upgraded to version 4.8. Unfortunately, it seems that this upgrade has caused many WoW players to have a drastically lower play experience.

The most common symptom is severe keystroke lag while playing the World of Warcraft. Mouse actions also seem to be affected by this. Delays as low as a second and as high as five seconds between keystroke and the game receiving that action have been reported. Supposedly, running WoW in windowed mode fixes this, but your mileage may vary.

Continue reading Avast! update causing issues with WoW

WoW Rookie: Account Security Basics

Recently we've had several posts about being hacked, guild banks assaulted, and Blizzard's typical response. The Customer Service Forum is filled with threads started by desperate World of Warcraft players seeking the return of their accounts and belongings as a gesture of goodwill. It is our responsibility to keep our accounts safe from hackers.

I speak from experience when I say that being hacked is just dreadful. Although it is usually possible to have your account returned, there is usually significant damage done in the process. In the past, even Blizzard employees have had their accounts compromised. This post is designed to help you do the best you can to protect your World of Warcraft investment.

Continue reading WoW Rookie: Account Security Basics

Bank declines Blizzard charges

It seems that keyloggers and phishers are not the only fraudsters infiltrating World of Warcraft. Halifax, a bank in the United Kingdom has ceased processing most transactions with Blizzard Entertainment. This measure was taken in response to increasing numbers of reports fraudulent transactions for WoW services. I had a similar issue with another bank based in the United States. That institution saw my recurring Blizzard charge as suspicious. Once I contacted them to verify my subscriptions my credit card was quickly returned to an active status.

In this case, the only fault on Blizzard's is making an astoundingly popular, subscription-based RPG. Do be on the lookout for unexpected transactions from Blizzard Entertainment and be sure to report them to your bank as soon as possible. Representatives from Blizzard Entertainment declined interviews with the Register, which investigated this phenomenon.

Do not be surprised if the transaction for your WoW subscription is refused in the near future. Halifax customers can use their credit cards to pay for their WoW subscriptions by making special arrangements with their account services department. If you would like to continue to use your Halifx Visa or Master card, be sure to contact customer support for authentication.


RESOURCES

Blizzard Events
BlizzCon (225)
Worldwide Invitational (116)
Class Columns
(Death Knight) Lichborne (4)
(Druid) Shifting Perspectives (51)
(Hunter) Big Red Kitty (45)
(Hunter) Scattered Shots (28)
(Mage) Arcane Brilliance (50)
(Paladin) The Light and How to Swing It (56)
(Priest) Spiritual Guidance (32)
(Rogue) Encrypted Text (38)
(Shaman) Totem Talk (59)
(Warlock) Blood Pact (34)
(Warrior) The Care and Feeding of Warriors (62)
Gameplay
(Arena PvP) Blood Sport (30)
(BG PvP) The Art of War(craft) (31)
(Casual) WoW, Casually (22)
(Guild Leadership) Officers' Quarters (69)
(Professions) Insider Trader (69)
(Raid Healing) Raid Rx (20)
(Raiding) Raiding 101 (2)
(Raiding) Ready Check (31)
(Roleplaying) All the World's a Stage (50)
Hybrid Theory (25)
New Players' Guide (4)
Tank Talk (9)
AddOns and UI
AddOn Spotlight (96)
Macro Anatomy (15)
Reader UI of the Week (28)
Reader WoWspace of the week (31)
The Creamy GUI Center (18)
Lore and Stories
Around Azeroth (576)
Ask A Lore Nerd (15)
Barrens Chat (17)
Know your Lore (65)
Tales from the Lion's Pride Inn (14)
WoW Moviewatch (567)
Features
15 Minutes of Fame (31)
About the Bloggers (29)
Ask WoW Insider (67)
Azeroth Security Advisor (4)
Breakfast topics (777)
Build Shop (37)
Forum Post of the Day (51)
Gamers on the Street (25)
Guildwatch (88)
He Said She Said (5)
Illusionary Tactics (3)
It came from the Blog (29)
Phat Loot Phriday (98)
The Colosseum (4)
Two Bosses Enter (61)
Well Fed Buff (30)
World of WarCrafts (33)
WoW Crossword (7)
WoW Insider Show (82)
WoW Rookie (42)
[1.Local] (18)
Classes
Death Knight (164)
Druid (358)
Hunter (349)
Mage (206)
Paladin (346)
Priest (281)
Rogue (200)
Shaman (317)
Warlock (216)
Warrior (254)
News
Account Security (33)
AddOns (274)
Analysis / Opinion (3621)
Blizzard (1835)
Bugs (227)
Burning Crusade (393)
Contests (260)
Economy (199)
Events (500)
Expansions (832)
Fan stuff (1029)
Features (714)
Forums (325)
Guilds (527)
Hardware (53)
Humor (886)
Interviews (186)
Lore (361)
Mounts (161)
News items (1776)
NPCs (244)
Odds and ends (1809)
Patches (1202)
Podcasting (87)
Ranking (56)
Realm News (314)
Realm Status (258)
RP (187)
Rumors (74)
Virtual selves (744)
WoW Insider Business (330)
WoW Social Conventions (178)
WoW TCG (63)
Wrath of the Lich King (818)
Strategy
Achievements (27)
Alts (135)
Arena (301)
Battlegrounds (184)
Bosses (393)
Buffs (149)
Cheats (80)
Classes (374)
Enchants (38)
Factions (185)
Guides (436)
How-tos (442)
Instances (741)
Items (955)
Leveling (353)
Making money (215)
PvP (842)
Quests (404)
Raiding (837)
Talents (205)
Tips (619)
Tricks (238)
Walkthroughs (97)
Media
Comics (98)
Fan art (59)
Galleries (262)
Machinima (655)
Podcasts (54)
Polls (74)
Screenshots (735)
Races
Alliance (128)
Draenei (68)
Dwarves (24)
Gnomes (51)
Human (24)
Night Elves (55)
Horde (135)
Blood Elves (75)
Orcs (35)
Tauren (59)
Trolls (28)
Undead (32)
Professions
Alchemy (94)
Blacksmithing (75)
Cooking (83)
Enchanting (88)
Engineering (124)
First Aid (20)
Fishing (67)
Herbalism (57)
Inscription (35)
Jewelcrafting (98)
Leatherworking (75)
Mining (54)
Skinning (35)
Tailoring (82)
Retired
Pimp My Profile (1)
(Engineering) Hoof and Horn Research and Development (17)
Azeroth Interrupted (24)
Back In The Day (3)
World Wide WoW (8)
/silly (14)

RSS NEWSFEEDS

Powered by Blogsmith

    Featured Galleries

    World of WarCrafts: Ghoul doll
    World of WarCrafts: Murloc fail shirt
    Wrath of the Lich King: Utgarde Keep Walkthrough
    Wrath of the Lich King: Loading screens
    New Death Knight skins
    Wrath of the Lich King: Jewelcrafting
    Wrath of the Lich King: Blacksmithing
    Cro Threadstrong selling apples
    World of WarCrafts: Loop of Cursed Bones

     

    Most Commented On (30 days)

    Recent Comments

    Other Weblogs Inc. Network blogs you might be interested in: