Blizzard got Hacked!

This topic is locked from further discussion.

Avatar image for madman683
madman683

483

Forum Posts

0

Wiki Points

0

Followers

Reviews: 13

User Lists: 1

#1 madman683
Member since 2005 • 483 Posts

http://us.blizzard.com/en-us/securityupdate.html

Players and Friends,

Even when you are in the business of fun, not every week ends up being fun. This week, our security team found an unauthorized and illegal access into our internal network here at Blizzard. We quickly took steps to close off this access and began working with law enforcement and security experts to investigate what happened.

At this time, weve found no evidence that financial information such as credit cards, billing addresses, or real names were compromised. Our investigation is ongoing, but so far nothing suggests that these pieces of information have been accessed.

Some data was illegally accessed, including a list of email addresses for global Battle.net users, outside of China. For players on North American servers (which generally includes players from North America, Latin America, Australia, New Zealand, and Southeast Asia) the answer to the personal security question, and information relating to Mobile and Dial-In Authenticators were also accessed. Based on what we currently know, this information alone is NOT enough for anyone to gain access to Battle.net accounts.

We also know that cryptographically scrambled versions of Battle.net passwords (not actual passwords) for players on North American servers were taken. We use Secure Remote Password protocol (SRP) to protect these passwords, which is designed to make it extremely difficult to extract the actual password, and also means that each password would have to be deciphered individually. As a precaution, however, we recommend that players on North American servers change their password. Please click this link to change your password. Moreover, if you have used the same or similar passwords for other purposes, you may want to consider changing those passwords as well.

In the coming days, we'll be prompting players on North American servers to change their secret questions and answers through an automated process. Additionally, we'll prompt mobile authenticator users to update their authenticator software. As a reminder, phishing emails will ask you for password or login information. Blizzard Entertainment emails will never ask for your password. We deeply regret the inconvenience to all of you and understand you may have questions. Please find additional information here.

We take the security of your personal information very seriously, and we are truly sorry that this has happened.

Sincerely,
Mike Morhaime

Avatar image for James00715
James00715

2484

Forum Posts

0

Wiki Points

0

Followers

Reviews: 1

User Lists: 0

#2 James00715
Member since 2003 • 2484 Posts

Here is the actual link if you don't trust the OP: http://us.blizzard.com/en-us/securityupdate.html

Thanks, just changed my password.

Avatar image for deactivated-64b76bd048860
deactivated-64b76bd048860

4363

Forum Posts

0

Wiki Points

0

Followers

Reviews: 13

User Lists: 0

#3 deactivated-64b76bd048860
Member since 2007 • 4363 Posts
Password changed. Should I change authenticators? (on mobile)
Avatar image for RoccoHout
RoccoHout

1086

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

#4 RoccoHout
Member since 2011 • 1086 Posts

Changed my password, hope I can use my old password soon enough trough.

Avatar image for ssvegeta555
ssvegeta555

2448

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

#5 ssvegeta555
Member since 2003 • 2448 Posts

Thanks for the headsup. Info changed.

Avatar image for bahamutzzzz
bahamutzzzz

185

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

#6 bahamutzzzz
Member since 2007 • 185 Posts

So, now its actually blizzard fault? A lot of accounts got hacked in the past and now they admit it?

Avatar image for Amigro
Amigro

737

Forum Posts

0

Wiki Points

0

Followers

Reviews: 3

User Lists: 0

#7 Amigro
Member since 2003 • 737 Posts
This is just proof that authenticators, mobile apps, thingamijigs, and cryptographic stenogrofiers don't protect us from anything!
Avatar image for jakes456
jakes456

1398

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

#8 jakes456
Member since 2011 • 1398 Posts

Blizzard is pathetic.

Avatar image for Ravenshout
Ravenshout

1265

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

#9 Ravenshout
Member since 2012 • 1265 Posts

Blizzard is pathetic.

jakes456

Any company's online service can be hacked depending on the hacker's desire and motive.

You have been throwing utter hatred towards big companies.

Avatar image for Legendaryscmt
Legendaryscmt

12532

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

#10 Legendaryscmt
Member since 2005 • 12532 Posts

With all these companies getting hacked, looks like I picked a good job market. :D

In all seriousness though, this does suck. Hopefully the security will be increased and that Blizzard takes this as a serious warning.

Avatar image for IxX3xil3d0n3XxI
IxX3xil3d0n3XxI

1508

Forum Posts

0

Wiki Points

0

Followers

Reviews: 18

User Lists: 0

#11 IxX3xil3d0n3XxI
Member since 2006 • 1508 Posts

Blizzard is pathetic.

jakes456

Every single company is more than capable of getting hacked. Blizzard if very popular and therefore a bigger target. Glad your game company isnt having issues though.

Avatar image for Temporius
Temporius

502

Forum Posts

0

Wiki Points

0

Followers

Reviews: 2

User Lists: 0

#12 Temporius
Member since 2008 • 502 Posts
If the attackers also attained the salts for the passwords (blizzard did not state that they did) AND have reverse engineered any of the clients to the degree of being able to determine other cryptographic information(I do not believe any of their game have been reverse engineered to this extent), the attackers can attain passwords. As a precaution after a potential breach, assume that your password is or will be compromised until it can be proven that it was not. The attackers already had the algorithm for the authenticators, if you have one, it has been compromised.
Avatar image for Sleepyz
Sleepyz

3805

Forum Posts

0

Wiki Points

0

Followers

Reviews: 1

User Lists: 0

#13 Sleepyz
Member since 2003 • 3805 Posts

A while back got email saying my main character in wow was transfered to another server (Hadn't played in like a year) so reported and now account is banned not sure if lost my stuff. Then stupid me pays 60 dollars plus tax for Diablo 3 play for 2-3 weeks and get bored and a month later i try to play again and says I'm banned i go to web site and can't even log on there since my password is not working.

I finally get account password working after 5 days! and I'm still banned from Diablo 3. Never even played D3 online. I don't use external programs on games and i scan for malware and viruses on regular basis so its not me. Just got reply to ticket about banned account and replied with a form letter that said nothing.

Blizzard is never getting another penny from me.

Avatar image for Sword-Demon
Sword-Demon

7007

Forum Posts

0

Wiki Points

0

Followers

Reviews: 1

User Lists: 0

#14 Sword-Demon
Member since 2008 • 7007 Posts
Never even played D3 online. Sleepyz
isn't it always online? :?
Avatar image for th3warr1or
th3warr1or

20637

Forum Posts

0

Wiki Points

0

Followers

Reviews: 8

User Lists: 0

#15 th3warr1or
Member since 2007 • 20637 Posts
Thanks. Password changed.
Avatar image for ChubbyGuy40
ChubbyGuy40

26442

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

#16 ChubbyGuy40
Member since 2007 • 26442 Posts

This is just proof that authenticators, mobile apps, thingamijigs, and cryptographic stenogrofiers don't protect us from anything!Amigro

I'm sorry but did anyone read this at all or are you all just that stupid? They stole encryped passwords. They did not steal encryption keys or crack the way authenticators work. They have absolutely no access to any of our accounts.

So, now its actually blizzard fault? A lot of accounts got hacked in the past and now they admit it?

bahamutzzzz

It's always been the player's fault for getting their account stolen.

Avatar image for the_ChEeSe_mAn2
the_ChEeSe_mAn2

8463

Forum Posts

0

Wiki Points

0

Followers

Reviews: 1

User Lists: 0

#17 the_ChEeSe_mAn2
Member since 2003 • 8463 Posts
Changed my password, thanks for the posting :)
Avatar image for Temporius
Temporius

502

Forum Posts

0

Wiki Points

0

Followers

Reviews: 2

User Lists: 0

#18 Temporius
Member since 2008 • 502 Posts

[QUOTE="Amigro"]

I'm sorry but did anyone read this at all or are you all just that stupid? They stole encryped passwords. They did not steal encryption keys or crack the way authenticators work. They have absolutely no access to any of our accounts.

ChubbyGuy40

The authenticator algorithm has been out for a while now, the bad guys were already able to copy authenticators with just a serial number. Your authenticator will not protect you until your change it.

[QUOTE="bahamutzzzz"]

So, now its actually blizzard fault? A lot of accounts got hacked in the past and now they admit it?

ChubbyGuy40

It's always been the player's fault for getting their account stolen.

Diablo 3 had a session hijacking vulnerability. Hackers could completely bypass any security you had on your account by joining a game with you and tinkering with some of the game's files.
Avatar image for ChubbyGuy40
ChubbyGuy40

26442

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

#19 ChubbyGuy40
Member since 2007 • 26442 Posts

The authenticator algorithm has been out for a while now, the bad guys were already able to copy authenticators with just a serial number. Your authenticator will not protect you until your change it.

Diablo 3 had a session hijacking vulnerability. Hackers could completely bypass any security you had on your account by joining a game with you and tinkering with some of the game's files.Temporius

That's false. RSA's security token was cracked, but Blizzard uses Vasco. If it was cracked, do you really think Blizzard and the community would've kept silent all this time?

That was also proven false. You could view the session ID for the persons in your game, but you could never spoof it to gain control. Several threads on d2jsp and Blizzhackers proved this. Even Blizzard said there were no instances of spoofing or hijacking being the cause of people getting hacked. If I remember right, some people saying they were hacked with auths were caught lying by some Blues.

Avatar image for DanielDust
DanielDust

15402

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

#20 DanielDust
Member since 2007 • 15402 Posts
[QUOTE="ChubbyGuy40"]

[QUOTE="Amigro"]Temporius

The authenticator algorithm has been out for a while now, the bad guys were already able to copy authenticators with just a serial number. Your authenticator will not protect you until your change it.

[QUOTE="bahamutzzzz"]

So, now its actually blizzard fault? A lot of accounts got hacked in the past and now they admit it?

ChubbyGuy40

It's always been the player's fault for getting their account stolen.

Diablo 3 had a session hijacking vulnerability. Hackers could completely bypass any security you had on your account by joining a game with you and tinkering with some of the game's files.

You read too much internet drama from idiots that give out their account info then whine on the internet by inventing some random stories to hide their idiocy.
Avatar image for Gladestone1
Gladestone1

5695

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

#21 Gladestone1
Member since 2004 • 5695 Posts

Love how its always the players fault for being hacked..Thats the most laughable excuse ive heard to often bye gamers..Its not our fault..In reality its blizzards with these damn spammers in diablo games.Most of the hackers are them guys..Got my account hacked once..They turned me back a few hours got all my things back..Blizzard lets these fools spam the chat room an have a way with spamming every five min..Instead of keeping a person there an booting them..Dont tell me its cost effective either..They can ask one of the fans to do it also..Just like everquest back in the day used to use fans to be kind of a eye for them..Lets face it these spammers stay because blizzard wants them to stay..If they wanted them gone they can do it..Its stupid that they are there day after day..These are your folks who are hacking people..Its no ones fault but blizzard alone..Dont tell me other wise either..

Avatar image for DanielDust
DanielDust

15402

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

#22 DanielDust
Member since 2007 • 15402 Posts
I love how every random clueless person stars saying random stupid stuff. This is obviously a case where Blizzard is to blame for their security, but individuals getting hacked is strictly their own fault, they are idiots plain and simple, yes I say you are one too, because you not only got hacked for spyware or w/e stupid thing you did to have your data take, but you're also saying some stupid irrelevant stuff about spammers that have tens of accounts and will just move to the next one, try to ignore those spammer, you'll see that you receive just as many messages even if you block a lot of them, spammers don't get your account data for spamming messages. You're pathetic people, saying you're laughable for writing such stupid things is...laughable. I have absolutely no respect for people that get hacked and instead of acting humble and trying to see what went wrong, to permanently fix the problem, they start to act like idiots and blame other people for their problems.
Avatar image for HyperWarlock
HyperWarlock

3295

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

#23 HyperWarlock
Member since 2011 • 3295 Posts

it's happening to most companys, Twitter, Facebook, PSN, Steam, Battle.net, Xbox Live, Amazon...They have all been hacked in the past couple of years.

Avatar image for superclocked
superclocked

5864

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

#24 superclocked
Member since 2009 • 5864 Posts
There are 2 types of companies in the world. Those that know they've been hacked, and those that don't...
Avatar image for Miroku32
Miroku32

8666

Forum Posts

0

Wiki Points

0

Followers

Reviews: 43

User Lists: 0

#25 Miroku32
Member since 2006 • 8666 Posts
Thanks for posting this. Changed my pass.
Avatar image for PcGamingRig
PcGamingRig

7386

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

#26 PcGamingRig
Member since 2009 • 7386 Posts

anything can be hacked into if the person is good enough.

Avatar image for deactivated-59d151f079814
deactivated-59d151f079814

47239

Forum Posts

0

Wiki Points

0

Followers

Reviews: 2

User Lists: 0

#27 deactivated-59d151f079814
Member since 2003 • 47239 Posts
.... Battle.net probably has some 20 million unique users between SC, Diablo, Warcraft and WoW.. Of course its going to get hacked sooner or later.... Like every service has from Steam, Microsoft, PSN, etc etc..
Avatar image for SKaREO
SKaREO

3161

Forum Posts

0

Wiki Points

0

Followers

Reviews: 2

User Lists: 0

#28 SKaREO
Member since 2006 • 3161 Posts
Wasn't the first time and most certainly won't be the last time.
Avatar image for True_Sounds
True_Sounds

2915

Forum Posts

0

Wiki Points

0

Followers

Reviews: 72

User Lists: 0

#29 True_Sounds
Member since 2009 • 2915 Posts

I had to change the security question on my email, because our blizzard usernames are our emails and the security questiosn for both were the same. Having unencypted security questions is pretty low for blizzard. :/

Avatar image for Amigro
Amigro

737

Forum Posts

0

Wiki Points

0

Followers

Reviews: 3

User Lists: 0

#30 Amigro
Member since 2003 • 737 Posts

[QUOTE="Amigro"]This is just proof that authenticators, mobile apps, thingamijigs, and cryptographic stenogrofiers don't protect us from anything!ChubbyGuy40

I'm sorry but did anyone read this at all or are you all just that stupid? They stole encryped passwords. They did not steal encryption keys or crack the way authenticators work. They have absolutely no access to any of our accounts.

M sarcasm goes over at least one person's head. I figured using the words stenogrofier and thingamijigs would have made that very apparent (both are not real words btw), but I guess I have to be a bit clearer in the future =P

Avatar image for TheFatPerson
TheFatPerson

1806

Forum Posts

0

Wiki Points

0

Followers

Reviews: 3

User Lists: 0

#31 TheFatPerson
Member since 2011 • 1806 Posts

Thanks for the info, have my password changed. I'm also working on getting my e-mail changed but the site is having some difficulties ith that. Have a ticket opened as I'm typing this.

Avatar image for HyperWarlock
HyperWarlock

3295

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

#32 HyperWarlock
Member since 2011 • 3295 Posts

[QUOTE="ChubbyGuy40"]

[QUOTE="Amigro"]This is just proof that authenticators, mobile apps, thingamijigs, and cryptographic stenogrofiers don't protect us from anything!Amigro

I'm sorry but did anyone read this at all or are you all just that stupid? They stole encryped passwords. They did not steal encryption keys or crack the way authenticators work. They have absolutely no access to any of our accounts.

M sarcasm goes over at least one person's head. I figured using the words stenogrofier and thingamijigs would have made that very apparent (both are not real words btw), but I guess I have to be a bit clearer in the future =P

Just remember you're typing, not speaking.

Avatar image for commander1122
commander1122

1165

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

#33 commander1122
Member since 2005 • 1165 Posts

greedy company should get hacked!...they deserve it

Avatar image for HyperWarlock
HyperWarlock

3295

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

#34 HyperWarlock
Member since 2011 • 3295 Posts

greedy company should get hacked!...they deserve it

commander1122

In most cases it's the players who get affected the most, there personal information is out there. I don't think the players deserve that...

Avatar image for DanielDust
DanielDust

15402

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

#35 DanielDust
Member since 2007 • 15402 Posts

[QUOTE="commander1122"]

greedy company should get hacked!...they deserve it

HyperWarlock

In most cases it's the players who get affected the most, there personal information is out there. I don't think the players deserve that...

Yep, just another mindless ignorant thinking this serves "X company" right, the only people that are really affected are the users, just like the Sony hack, Ubisoft, Relic, Sega, Square Enix, Codemasters, Steam, etc (there were a lot of big name game developers hacked in the last year and there will be many more in the future, only we were really affected and most of us were affected more than once since many of us around here have accounts for most of the companies hacked).

Avatar image for SKaREO
SKaREO

3161

Forum Posts

0

Wiki Points

0

Followers

Reviews: 2

User Lists: 0

#36 SKaREO
Member since 2006 • 3161 Posts
I love how people think their "personal information" is so valuable. And they totally miss the point where Blizzard has lost the trust that their customers once had in them. It damages their brand image a lot worsee than your super secret personal information (woooo so secret) Like, as if you thought submitting any info on the web is safe to begin with. No database or web site connected to the internet is 100% secured. If you think the customers we're affected by this, then why weren't any accounts stolen? Does anyone remember how many accounts got hijacked at the laaunch of D3? Like thousands. Yes, several people reported Blizzard to the FBI because of the account hacking in June. And Blizzard denied that their database had been cracked (which of course it was, how could this happen otherwise?) and now ... OOPS looks like they got hacked again but this time they have to admit it because hell, it could be the FBI testing their security response.
Avatar image for Temporius
Temporius

502

Forum Posts

0

Wiki Points

0

Followers

Reviews: 2

User Lists: 0

#37 Temporius
Member since 2008 • 502 Posts
Looks like the hackers actually do have enough information to breach accounts. See here for a discussion of several mathematicians stating that the modulus used by blizzard could have discrete logs computed relative to it in computationally feasible time. Of note is that the person asking the question was quite blatantly trying to break a battle.net scrambled password. On top of that, mobile authenticators have been confirmed compromised by blizzard, and attackers have access to the phone numbers used for mobile authenticators. Also, given their aversion to state what happened, I suspect this was not an advanced attack.