![]() |
|
|
#1 |
|
Editor & Senior Moderator
Join Date: Oct 2007
Location: Hyderabad, India
Posts: 15,031 (7.23/day)
Thanks: 790
Thanked 13,027 Times in 5,718 Posts
|
Blizzard Servers Hacked, User Data Compromised
Online gaming giant Blizzard Entertainment reported unauthorized access to its servers. The security breach was detected earlier this week, and the company claims that the hackers may have accessed user data such as e-mail addresses of Battle.net users, their personal security questions, and information related to mobile and dial-in authentications.
Blizzard claims that the information compromised is not enough for anyone to gain access to the Battle.net accounts, and that there was no evidence to suggest that more vital bits of user data, such as real names, credit card information, or billing addresses were accessed. Users' Battle.net passwords, which are cryptographically-scrambled, may have been accessed. Since SRP (secure remote protocol) is used to protect the passwords, it is extremely difficult to unscramble them. Blizzard strongly recommends users to change their passwords as investigations into the security breach are on. Source: Shack News |
|
|
|
| The Following User Says Thank You to btarunr For This Useful Post: |
|
|
#2 |
![]() Join Date: Jul 2007
Location: Plymouth, UK
Posts: 4,813 (2.24/day)
Thanks: 532
Thanked 859 Times in 684 Posts
|
Can someone please tell me why this information is being so readily hacked into? There seemingly has been a handful of companies now that have had this happen to them.
__________________
![]() “Sorry but I cannot respond now, I am running a full virus scan on the internet.” -brandonwh64
|
|
|
|
|
|
#3 |
![]() Join Date: Sep 2008
Location: Weedopia
Posts: 1,169 (0.67/day)
Thanks: 114
Thanked 187 Times in 143 Posts
|
Because their security employees don't know what they are doing. They don't keep it up to date like they should which makes it easy to exploit.
__________________
|
|
|
|
|
|
#4 |
![]() Join Date: Jul 2007
Location: Plymouth, UK
Posts: 4,813 (2.24/day)
Thanks: 532
Thanked 859 Times in 684 Posts
|
Fools. Well here's to the inevitable "they might have taken some card details" line that is bound to come up.
__________________
![]() “Sorry but I cannot respond now, I am running a full virus scan on the internet.” -brandonwh64
|
|
|
|
|
|
#5 |
![]() Join Date: Dec 2008
Location: Central Illinois
Posts: 1,300 (0.79/day)
Thanks: 286
Thanked 244 Times in 164 Posts
|
Blame flash mysql and java
|
|
|
|
|
|
#6 |
|
"I go fast!1!11!1!"
Join Date: Oct 2008
Location: IA, USA
Posts: 10,642 (6.23/day)
Thanks: 1,784
Thanked 2,630 Times in 1,984 Posts
|
Or generally bad programming behaviors (like not checking inputs).
__________________
Golden Rule of Programming: Never assume. try { SteamDownload(); } catch (Steamception ex) { RageQuit(); } |
|
|
|
|
|
#7 | |
![]() Join Date: Sep 2008
Location: Weedopia
Posts: 1,169 (0.67/day)
Thanks: 114
Thanked 187 Times in 143 Posts
|
Quote:
I would hope their programmers know this, but that's like saying "I would hope they know to keep their programs updated" Someone somewhere in the company needs some security training or know how to use Google to check for known exploits. Bad Blizzard, BAD!
__________________
|
|
|
|
|
|
|
#8 |
![]() Join Date: Jan 2011
Posts: 96 (0.11/day)
Thanks: 0
Thanked 8 Times in 7 Posts
|
eh no skin off my back changed password, security question and email, benefits of holding several different accounts that just get forwarded to one account that has no job but to get forwarded mail. Only thing that ticked me off was that i couldn't copy paste my password when i change password apparently they hate keepass users.
|
|
|
|
|
|
#9 |
|
Linux Advocate
Join Date: Nov 2006
Posts: 10,281 (4.27/day)
Thanks: 1,219
Thanked 2,788 Times in 1,800 Posts
|
generally it is not the IT staff that is in the wrong. phishing is still in this day and age a great way to get user credentials. corporations need to train employees to not give out their credentials to ANYONE.
|
|
|
|
|
|
#10 |
![]() Join Date: May 2012
Location: Northern NJ, USA
Posts: 263 (0.64/day)
Thanks: 52
Thanked 32 Times in 24 Posts
|
Just want to know, did Blizzard use an authenticator? Cause if not,...
__________________
![]() Gigabyte GTX 670 OC WindForce 3X @ 1345 mhz/ 7010 mhz. |
|
|
|
|
|
#11 |
|
Banstick Dummy
Join Date: Jun 2007
Location: Crystal River, FL
Posts: 15,142 (6.86/day)
Thanks: 1,337
Thanked 6,860 Times in 3,752 Posts
|
I changed my password last night just to be safe. I also have an authenticator so I'm really not worried.
|
|
|
|
|
|
#12 |
![]() |
I laughed so hard and said myself:
In the whole forums i register, they get the one i dont!
|
|
|
|
|
|
#13 |
![]() Join Date: May 2008
Location: Iowa, USA
Posts: 3,358 (1.81/day)
Thanks: 569
Thanked 616 Times in 451 Posts
|
Changed password to be safe much harder now should take over 60,000 years to get it a a rate of 100,000 passwords a sec.
But I also use a authenticator.
__________________
|
|
|
|
|
|
#14 |
![]() |
Oh no, someone might steal my Diablo 3 account that I never use and my long-canceled WOW subscription. What ever will I do?
__________________
|
|
|
|
| The Following User Says Thank You to NinkobEi For This Useful Post: |
|
|
#15 |
![]() Join Date: Jan 2012
Location: South Africa
Posts: 94 (0.18/day)
Thanks: 45
Thanked 54 Times in 25 Posts
|
|
|
|
|
| The Following 5 Users Say Thank You to [XC] Oj101 For This Useful Post: |
|
|
#16 |
![]() Join Date: Apr 2008
Location: Sydney
Posts: 3,424 (1.83/day)
Thanks: 2,492
Thanked 745 Times in 530 Posts
|
God damnit Blizzard, now I'm gonna feel worried every time I play SC2
__________________
A STATE OF TRANCE ![]() |
|
|
|
|
|
#17 |
![]() |
I think it is the web programmers fault. They use the old mysql_escape_string instead of mysqli_real_escape_string($connect, $fetch($query))
|
|
|
|
|
|
#18 |
![]() Join Date: Nov 2011
Location: Hamilton, Ohio
Posts: 53 (0.09/day)
Thanks: 11
Thanked 16 Times in 9 Posts
|
This is the first I've heard of them ever being hacked, I been playing WoW on and off since 05'.
Having an authenticator and using pre-paid game cards, I'm personally not worried about anything. Out of roughly 10 million people who play wow, plus other blizzard games, also inactive accounts created over the years... Odds are pretty slim anything happened to you. |
|
|
|
|
|
#19 |
![]() Join Date: Apr 2012
Location: Givatayim
Posts: 35 (0.08/day)
Thanks: 4
Thanked 6 Times in 4 Posts
|
Just like Sony, they have more than enough money and more than enough riding on their online integrity to let something like happen.
I would say it is either something unavoidable or they're really trying to skim the bottom line.. |
|
|
|
|
|
#20 |
|
Linux Advocate
Join Date: Nov 2006
Posts: 10,281 (4.27/day)
Thanks: 1,219
Thanked 2,788 Times in 1,800 Posts
|
|
|
|
|
|
|
#21 |
![]() Join Date: Feb 2011
Posts: 682 (0.80/day)
Thanks: 431
Thanked 137 Times in 98 Posts
|
Ok, let's imagine I work as the head of internet security at Blizzard and I see all those ****-ups at Sony, Nvidia, etc... So guess what I do? I pick up my huge salary and go home to take some rest what I truly deserve.... for months after months .......... obviously
|
|
|
|
|
|
#22 |
|
Hardcore Monkey Moderator
Join Date: Feb 2007
Location: Cheeseland (Wisconsin, USA)
Posts: 12,254 (5.27/day)
Thanks: 591
Thanked 5,510 Times in 2,948 Posts
|
Seems to me that a lot of people here have little knowledge concerning internet security.
There is no such thing as 100% secure, as the "guards at the gates" will always have some inherent weakness which sooner or later someone will find and exploit. Training and updating is, of course, paramount but that will not stop a hacker who finds a way in that no one knew existed. As protection gets better so do the hackers, and it's a constant battle to keep networks secure. And Easy Rhino is right ... one disgruntled employee with server access, and a bone to pick, will foil your best efforts at intrusion prevention.
__________________
Cloud (noun, singular): A dynamic arrangement of multiple potential single points of failure, with a user at one end and their data at the other. Get more tech news on a wide variety of topics at NextPowerUp
|
|
|
|
|
|
#23 |
![]() Join Date: Dec 2009
Location: Iran
Posts: 39 (0.03/day)
Thanks: 10
Thanked 9 Times in 7 Posts
|
And those suckers still force you to use your real name for accounts! There's no privacy anymore
![]() Even if they didn't get the credit cards and other info, the emails and names are enough for spamming. Name + Email + some other personal info = Spam (scam) that really looks like an actual email! |
|
|
|
|
|
#24 | |
![]() Join Date: Feb 2011
Posts: 682 (0.80/day)
Thanks: 431
Thanked 137 Times in 98 Posts
|
Quote:
I have to admit that it was more than 15 years ago when I had to touch security related stuffz, (so I pretty much have no clue how it's going nowadays), but these massive user data leaks are happening all over the globe, and somehow I feel that there must be a way to prevent it happening this large scale, even if it's impossible to avoid it entirely . These kind of news telling stories that the hackers are getting the whole user databases, and the only question is that if they can "decode" it or not in that particular case. (I hope all of this doesn't sounds like that I want to be a smart*** here, because (honestly) I'm not...:B) |
|
|
|
|
|
|
#25 | ||||
|
Hardcore Monkey Moderator
Join Date: Feb 2007
Location: Cheeseland (Wisconsin, USA)
Posts: 12,254 (5.27/day)
Thanks: 591
Thanked 5,510 Times in 2,948 Posts
|
Quote:
When you open a window to let the air in, it can be very difficult to keep the dust out despite your best attempts. Quote:
Even the best minds in the security fields fight this kind of thing daily. It is no trivial task. Add to that the fact that even the best admins are human and may make mistakes ... Quote:
Quote:
Just kidding, your post was fine and brings up good discussion.
__________________
Cloud (noun, singular): A dynamic arrangement of multiple potential single points of failure, with a user at one end and their data at the other. Get more tech news on a wide variety of topics at NextPowerUp
|
||||
|
|
|
![]() |
| Currently Active Users Viewing This Thread: 1 (0 members and 1 guests) | |
| Thread Tools | |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| I-O Data Unveils USB 3.0 Host Card for Servers | btarunr | News | 1 | Apr 11, 2012 02:36 PM |
| Sony confirms personal PSN data compromised. | CDdude55 | Games | 146 | May 22, 2011 12:43 AM |
| Steam Idea: Get your account back when compromised. | AphexDreamer | General Software | 9 | Apr 20, 2011 01:42 PM |
| nVidia's GeForce.com subsite compromised! | Red_Machine | NVIDIA | 15 | Apr 1, 2011 06:28 PM |
| Intel Atom-based Servers: Sufficient for Dedicated Servers | btarunr | News | 18 | Jul 22, 2008 07:34 PM |