Unconfigured Ad Widget
Collapse
|
|
|
|
|
|
|
|
D3
Collapse
X
-
Oppressors can tyrannize only when they achieve a standing army, an enslaved press, and a disarmed populace. -- James Madison
The Constitution shall never be construed to authorize Congress to prevent the people of the United States, who are peaceable citizens, from keeping their own arms. -- Samuel Adams, Debates and Proceedings in the Convention of the Commonwealth of Massachusetts, 86-87 (Pearce and Hale, eds., Boston, 1850) -
There is one version of the authenticator that doesn't work with diablo 3(or starcraft 2).
And Blizzard did have to point out on their forums a few times that it didn't work with diablo 3, so it's possible that idiots were using that service(without bothering to notice it wasn't actually working with diablo 3), and then got their d3 accounts phished like normal.Comment
-
It IS the same thing.
But secureID was compromised because someone grabbed the seed information off a secureID server. its not that someone actually found away around an unknown authenticator.
You would think SecureID would have 2 factor auth to get to the seeds but never mind...
Fair enough.
"It is to secure our rights that we resort to government at all." -Thomas JeffersonComment
-
Good point. I'm new to this whole authenticator thing, but from what I understand someone could still get phished if they're using an authenticator by suckering someone into telling them the extra random code they need? Just food for thought.There is one version of the authenticator that doesn't work with diablo 3(or starcraft 2).
And Blizzard did have to point out on their forums a few times that it didn't work with diablo 3, so it's possible that idiots were using that service(without bothering to notice it wasn't actually working with diablo 3), and then got their d3 accounts phished like normal.
Also, I'm really not familiar with that device at all, so I could certainly be wrong about that depending on how that authenticator specifically works.Comment
-
No...Good point. I'm new to this whole authenticator thing, but from what I understand someone could still get phished if they're using an authenticator by suckering someone into telling them the extra random code they need? Just food for thought.
Also, I'm really not familiar with that device at all, so I could certainly be wrong about that depending on how that authenticator specifically works.
There are multiple "authenticators".
The basic one is a small little device that goes on your keychain. You press a button, it displays a number. The number changes every 60 seconds. Even if someone phished your login info, and the number you typed in, 60 seconds later they wouldn't be able to connect.
The next type of authenticator is a mobile phone application that does the same thing as the physical keychain device. Both of these methods work using encryption based off of a serial number, a seed from a clock, and a database of private keys. Unless the hacker got access to the private key database(which probably isn't even held by Blizzard anyway), even if they got the serial number from the back of your physical device or from your cellphone app(meaning they'd physically need your phone, or this thing hanging off of your keys), they couldn't do anything with it because they'd still need the device itself(or your phone).
The dial-in method requires you to call in to a 1-800 number from your phone that's registered to your account and enter in a number displayed on the WoW login screen plus your PIN.
If someone knew your phone number, and wow login info, they'd need your PIN(which you aren't typing on your computer so they'd need a keylogger on your phone to get it), in addition to spoofing your phone number on caller ID, and knowing your username and password. But, as Blizzard clearly points out, this specific authenticator service doesn't work with D3 or SC2 anyway.
In addition to the authenticators, Blizzard has yet another service called "SMS protect" which will send you an SMS message on your cellphone when there are changes to passwords, changes to registered authenticator settings, or "suspicious login activity" and it's kind of obvious to blizzard when your account that is normally logged in from comcast, suddenly gets a login from Signapore.
It's not like Blizzard hasn't gone out of their way to try and protect users from malware and their typical idiot user selves.Comment
-
Right, so if I'm bob the hacker and I'm emailing you telling you to respond with a fresh code off the authenticator along with your password, then I'm in as long as I use it in time, no?No...
There are multiple "authenticators".
The basic one is a small little device that goes on your keychain. You press a button, it displays a number. The number changes every 60 seconds. Even if someone phished your login info, and the number you typed in, 60 seconds later they wouldn't be able to connect.
The next type of authenticator is a mobile phone application that does the same thing as the physical keychain device. Both of these methods work using encryption based off of a serial number, a seed from a clock, and a database of private keys. Unless the hacker got access to the private key database(which probably isn't even held by Blizzard anyway), even if they got the serial number from the back of your physical device or from your cellphone app(meaning they'd physically need your phone, or this thing hanging off of your keys), they couldn't do anything with it because they'd still need the device itself(or your phone).
The dial-in method requires you to call in to a 1-800 number from your phone that's registered to your account and enter in a number displayed on the WoW login screen plus your PIN.
If someone knew your phone number, and wow login info, they'd need your PIN(which you aren't typing on your computer so they'd need a keylogger on your phone to get it), in addition to spoofing your phone number on caller ID, and knowing your username and password. But, as Blizzard clearly points out, this specific authenticator service doesn't work with D3 or SC2 anyway.
In addition to the authenticators, Blizzard has yet another service called "SMS protect" which will send you an SMS message on your cellphone when there are changes to passwords, changes to registered authenticator settings, or "suspicious login activity" and it's kind of obvious to blizzard when your account that is normally logged in from comcast, suddenly gets a login from Signapore.
It's not like Blizzard hasn't gone out of their way to try and protect users from malware and their typical idiot user selves.
So a motivated scammer CAN still phish someone dumb enough to give them their login info AND a fresh auth code, but they will most likely only be able to get in once for 60 seconds.
Again, just food for thought.Comment
-
I seriously doubt they'd bother trying to get a rolling code that will likely be expired before they get to the prompt for it. These accounts are keylogged by trojans that send the logs back to a command and control server. And if you're dumb enough to give out that information you deserve what you get.Right, so if I'm bob the hacker and I'm emailing you telling you to respond with a fresh code off the authenticator along with your password, then I'm in as long as I use it in time, no?
So a motivated scammer CAN still phish someone dumb enough to give them their login info AND a fresh auth code, but they will most likely only be able to get in once for 60 seconds.
Again, just food for thought.Oppressors can tyrannize only when they achieve a standing army, an enslaved press, and a disarmed populace. -- James Madison
The Constitution shall never be construed to authorize Congress to prevent the people of the United States, who are peaceable citizens, from keeping their own arms. -- Samuel Adams, Debates and Proceedings in the Convention of the Commonwealth of Massachusetts, 86-87 (Pearce and Hale, eds., Boston, 1850)Comment
-
Yeah, I know. But, you know that there are some really stupid people out there. I was just pointing out that an authenticator doesn't cure dumb haha.I seriously doubt they'd bother trying to get a rolling code that will likely be expired before they get to the prompt for it. These accounts are keylogged by trojans that send the logs back to a command and control server. And if you're dumb enough to give out that information you deserve what you get.Comment
-
Yes, but realistically there's no way they could even guarantee that they'd be able to do it in 60 seconds.Right, so if I'm bob the hacker and I'm emailing you telling you to respond with a fresh code off the authenticator along with your password, then I'm in as long as I use it in time, no?
So a motivated scammer CAN still phish someone dumb enough to give them their login info AND a fresh auth code, but they will most likely only be able to get in once for 60 seconds.
Again, just food for thought.
Typically these work(just like any other phishing scheme, unless someone is actively doing it) by logging the info of idiots into a database and then someone loads up the list and goes through it. The reason why you likely wouldn't be able to do it in 60 seconds, is because of the 500 other morons that got the email at the same time pounding their login info into your phishing site that doesn't require dealing with the authenticator.Comment
-
We need to get rid of laws that protect stupid people and let nature take its course, but that's a topic for another thread.Oppressors can tyrannize only when they achieve a standing army, an enslaved press, and a disarmed populace. -- James Madison
The Constitution shall never be construed to authorize Congress to prevent the people of the United States, who are peaceable citizens, from keeping their own arms. -- Samuel Adams, Debates and Proceedings in the Convention of the Commonwealth of Massachusetts, 86-87 (Pearce and Hale, eds., Boston, 1850)Comment
-
-
Oppressors can tyrannize only when they achieve a standing army, an enslaved press, and a disarmed populace. -- James Madison
The Constitution shall never be construed to authorize Congress to prevent the people of the United States, who are peaceable citizens, from keeping their own arms. -- Samuel Adams, Debates and Proceedings in the Convention of the Commonwealth of Massachusetts, 86-87 (Pearce and Hale, eds., Boston, 1850)Comment
-
Blizzard really botched this update, servers are down
Oppressors can tyrannize only when they achieve a standing army, an enslaved press, and a disarmed populace. -- James Madison
The Constitution shall never be construed to authorize Congress to prevent the people of the United States, who are peaceable citizens, from keeping their own arms. -- Samuel Adams, Debates and Proceedings in the Convention of the Commonwealth of Massachusetts, 86-87 (Pearce and Hale, eds., Boston, 1850)Comment
-
haha!
"It is to secure our rights that we resort to government at all." -Thomas JeffersonComment
Calguns.net Statistics
Collapse
Topics: 1,869,467
Posts: 25,184,231
Members: 357,644
Active Members: 5,238
Welcome to our newest member, Ty160805.
What's Going On
Collapse
There are currently 40259 users online. 35 members and 40224 guests.
Most users ever online was 239,041 at 10:39 PM on 02-14-2026.

Comment