Unconfigured Ad Widget

Collapse

D3

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • #91
    JDay
    I need a LIFE!!
    • Nov 2008
    • 19393

    Originally posted by dem0critus
    Wait a minute, so Blizz doesn't even guarantee the security WITH the authenticator, as stated in this article.... SO about that multi million dollar lawsuit.
    No, they said that having an authenticator is not a 100% guarantee. RSA SecureID is pretty much (is?) they same thing they're using, and that was compromised for a while last year.

    Originally posted by Nose Nuggets
    Thanks. Still find it hard to believe. i was prety bored one day during the height of that and was pretty active on the forums. there where a LOT of people saying they had authenticators and always have to type their code and still got hacked.

    dunno.
    Trolls, every game launch gets them.
    Oppressors can tyrannize only when they achieve a standing army, an enslaved press, and a disarmed populace. -- James Madison

    The Constitution shall never be construed to authorize Congress to prevent the people of the United States, who are peaceable citizens, from keeping their own arms. -- Samuel Adams, Debates and Proceedings in the Convention of the Commonwealth of Massachusetts, 86-87 (Pearce and Hale, eds., Boston, 1850)

    Comment

    • #92
      Merc1138
      I need a LIFE!!
      • Feb 2009
      • 19742

      There is one version of the authenticator that doesn't work with diablo 3(or starcraft 2).



      And Blizzard did have to point out on their forums a few times that it didn't work with diablo 3, so it's possible that idiots were using that service(without bothering to notice it wasn't actually working with diablo 3), and then got their d3 accounts phished like normal.

      Comment

      • #93
        Nose Nuggets
        Calguns Addict
        • Apr 2008
        • 6801

        Originally posted by JDay
        No, they said that having an authenticator is not a 100% guarantee. RSA SecureID is pretty much (is?) they same thing they're using, and that was compromised for a while last year.
        It IS the same thing.

        But secureID was compromised because someone grabbed the seed information off a secureID server. its not that someone actually found away around an unknown authenticator.

        You would think SecureID would have 2 factor auth to get to the seeds but never mind...


        Originally posted by JDay
        Trolls, every game launch gets them.
        Fair enough.


        "It is to secure our rights that we resort to government at all." -Thomas Jefferson

        Comment

        • #94
          dem0critus
          Senior Member
          • Mar 2012
          • 619

          Originally posted by Merc1138
          There is one version of the authenticator that doesn't work with diablo 3(or starcraft 2).



          And Blizzard did have to point out on their forums a few times that it didn't work with diablo 3, so it's possible that idiots were using that service(without bothering to notice it wasn't actually working with diablo 3), and then got their d3 accounts phished like normal.
          Good point. I'm new to this whole authenticator thing, but from what I understand someone could still get phished if they're using an authenticator by suckering someone into telling them the extra random code they need? Just food for thought.

          Also, I'm really not familiar with that device at all, so I could certainly be wrong about that depending on how that authenticator specifically works.

          Comment

          • #95
            Merc1138
            I need a LIFE!!
            • Feb 2009
            • 19742

            Originally posted by dem0critus
            Good point. I'm new to this whole authenticator thing, but from what I understand someone could still get phished if they're using an authenticator by suckering someone into telling them the extra random code they need? Just food for thought.

            Also, I'm really not familiar with that device at all, so I could certainly be wrong about that depending on how that authenticator specifically works.
            No...

            There are multiple "authenticators".

            The basic one is a small little device that goes on your keychain. You press a button, it displays a number. The number changes every 60 seconds. Even if someone phished your login info, and the number you typed in, 60 seconds later they wouldn't be able to connect.

            The next type of authenticator is a mobile phone application that does the same thing as the physical keychain device. Both of these methods work using encryption based off of a serial number, a seed from a clock, and a database of private keys. Unless the hacker got access to the private key database(which probably isn't even held by Blizzard anyway), even if they got the serial number from the back of your physical device or from your cellphone app(meaning they'd physically need your phone, or this thing hanging off of your keys), they couldn't do anything with it because they'd still need the device itself(or your phone).

            The dial-in method requires you to call in to a 1-800 number from your phone that's registered to your account and enter in a number displayed on the WoW login screen plus your PIN.

            If someone knew your phone number, and wow login info, they'd need your PIN(which you aren't typing on your computer so they'd need a keylogger on your phone to get it), in addition to spoofing your phone number on caller ID, and knowing your username and password. But, as Blizzard clearly points out, this specific authenticator service doesn't work with D3 or SC2 anyway.

            In addition to the authenticators, Blizzard has yet another service called "SMS protect" which will send you an SMS message on your cellphone when there are changes to passwords, changes to registered authenticator settings, or "suspicious login activity" and it's kind of obvious to blizzard when your account that is normally logged in from comcast, suddenly gets a login from Signapore.



            It's not like Blizzard hasn't gone out of their way to try and protect users from malware and their typical idiot user selves.

            Comment

            • #96
              dem0critus
              Senior Member
              • Mar 2012
              • 619

              Originally posted by Merc1138
              No...

              There are multiple "authenticators".

              The basic one is a small little device that goes on your keychain. You press a button, it displays a number. The number changes every 60 seconds. Even if someone phished your login info, and the number you typed in, 60 seconds later they wouldn't be able to connect.

              The next type of authenticator is a mobile phone application that does the same thing as the physical keychain device. Both of these methods work using encryption based off of a serial number, a seed from a clock, and a database of private keys. Unless the hacker got access to the private key database(which probably isn't even held by Blizzard anyway), even if they got the serial number from the back of your physical device or from your cellphone app(meaning they'd physically need your phone, or this thing hanging off of your keys), they couldn't do anything with it because they'd still need the device itself(or your phone).

              The dial-in method requires you to call in to a 1-800 number from your phone that's registered to your account and enter in a number displayed on the WoW login screen plus your PIN.

              If someone knew your phone number, and wow login info, they'd need your PIN(which you aren't typing on your computer so they'd need a keylogger on your phone to get it), in addition to spoofing your phone number on caller ID, and knowing your username and password. But, as Blizzard clearly points out, this specific authenticator service doesn't work with D3 or SC2 anyway.

              In addition to the authenticators, Blizzard has yet another service called "SMS protect" which will send you an SMS message on your cellphone when there are changes to passwords, changes to registered authenticator settings, or "suspicious login activity" and it's kind of obvious to blizzard when your account that is normally logged in from comcast, suddenly gets a login from Signapore.



              It's not like Blizzard hasn't gone out of their way to try and protect users from malware and their typical idiot user selves.
              Right, so if I'm bob the hacker and I'm emailing you telling you to respond with a fresh code off the authenticator along with your password, then I'm in as long as I use it in time, no?

              So a motivated scammer CAN still phish someone dumb enough to give them their login info AND a fresh auth code, but they will most likely only be able to get in once for 60 seconds.

              Again, just food for thought.

              Comment

              • #97
                JDay
                I need a LIFE!!
                • Nov 2008
                • 19393

                Originally posted by dem0critus
                Right, so if I'm bob the hacker and I'm emailing you telling you to respond with a fresh code off the authenticator along with your password, then I'm in as long as I use it in time, no?

                So a motivated scammer CAN still phish someone dumb enough to give them their login info AND a fresh auth code, but they will most likely only be able to get in once for 60 seconds.

                Again, just food for thought.
                I seriously doubt they'd bother trying to get a rolling code that will likely be expired before they get to the prompt for it. These accounts are keylogged by trojans that send the logs back to a command and control server. And if you're dumb enough to give out that information you deserve what you get.
                Oppressors can tyrannize only when they achieve a standing army, an enslaved press, and a disarmed populace. -- James Madison

                The Constitution shall never be construed to authorize Congress to prevent the people of the United States, who are peaceable citizens, from keeping their own arms. -- Samuel Adams, Debates and Proceedings in the Convention of the Commonwealth of Massachusetts, 86-87 (Pearce and Hale, eds., Boston, 1850)

                Comment

                • #98
                  dem0critus
                  Senior Member
                  • Mar 2012
                  • 619

                  Originally posted by JDay
                  I seriously doubt they'd bother trying to get a rolling code that will likely be expired before they get to the prompt for it. These accounts are keylogged by trojans that send the logs back to a command and control server. And if you're dumb enough to give out that information you deserve what you get.
                  Yeah, I know. But, you know that there are some really stupid people out there. I was just pointing out that an authenticator doesn't cure dumb haha.

                  Comment

                  • #99
                    Merc1138
                    I need a LIFE!!
                    • Feb 2009
                    • 19742

                    Originally posted by dem0critus
                    Right, so if I'm bob the hacker and I'm emailing you telling you to respond with a fresh code off the authenticator along with your password, then I'm in as long as I use it in time, no?

                    So a motivated scammer CAN still phish someone dumb enough to give them their login info AND a fresh auth code, but they will most likely only be able to get in once for 60 seconds.

                    Again, just food for thought.
                    Yes, but realistically there's no way they could even guarantee that they'd be able to do it in 60 seconds.

                    Typically these work(just like any other phishing scheme, unless someone is actively doing it) by logging the info of idiots into a database and then someone loads up the list and goes through it. The reason why you likely wouldn't be able to do it in 60 seconds, is because of the 500 other morons that got the email at the same time pounding their login info into your phishing site that doesn't require dealing with the authenticator.

                    Comment

                    • JDay
                      I need a LIFE!!
                      • Nov 2008
                      • 19393

                      Originally posted by dem0critus
                      Yeah, I know. But, you know that there are some really stupid people out there. I was just pointing out that an authenticator doesn't cure dumb haha.
                      We need to get rid of laws that protect stupid people and let nature take its course, but that's a topic for another thread.
                      Oppressors can tyrannize only when they achieve a standing army, an enslaved press, and a disarmed populace. -- James Madison

                      The Constitution shall never be construed to authorize Congress to prevent the people of the United States, who are peaceable citizens, from keeping their own arms. -- Samuel Adams, Debates and Proceedings in the Convention of the Commonwealth of Massachusetts, 86-87 (Pearce and Hale, eds., Boston, 1850)

                      Comment

                      • dem0critus
                        Senior Member
                        • Mar 2012
                        • 619

                        Originally posted by JDay
                        We need to get rid of laws that protect stupid people and let nature take its course, but that's a topic for another thread.
                        Booyah.

                        Comment

                        • JDay
                          I need a LIFE!!
                          • Nov 2008
                          • 19393



                          Oppressors can tyrannize only when they achieve a standing army, an enslaved press, and a disarmed populace. -- James Madison

                          The Constitution shall never be construed to authorize Congress to prevent the people of the United States, who are peaceable citizens, from keeping their own arms. -- Samuel Adams, Debates and Proceedings in the Convention of the Commonwealth of Massachusetts, 86-87 (Pearce and Hale, eds., Boston, 1850)

                          Comment

                          • JDay
                            I need a LIFE!!
                            • Nov 2008
                            • 19393

                            Blizzard really botched this update, servers are down
                            Oppressors can tyrannize only when they achieve a standing army, an enslaved press, and a disarmed populace. -- James Madison

                            The Constitution shall never be construed to authorize Congress to prevent the people of the United States, who are peaceable citizens, from keeping their own arms. -- Samuel Adams, Debates and Proceedings in the Convention of the Commonwealth of Massachusetts, 86-87 (Pearce and Hale, eds., Boston, 1850)

                            Comment

                            • Brianguy
                              Veteran Member
                              • Sep 2009
                              • 3836

                              don't nerf my monk! damn you blizzard

                              Comment

                              • Nose Nuggets
                                Calguns Addict
                                • Apr 2008
                                • 6801

                                haha!


                                "It is to secure our rights that we resort to government at all." -Thomas Jefferson

                                Comment

                                Working...
                                UA-8071174-1