Something went wrong. Try again later

Giant Bomb News

209 Comments

Change Your Battle.net Password

Blizzard's network has been accessed by an outside party, your email addresses and "secret question" answers are out there.

Hey, while we're posting passwords in the open around here...
Hey, while we're posting passwords in the open around here...

This is the world we live in now. A world where some service you've signed up with seems to get penetrated every couple of weeks, sending everyone into a password-changing frenzy. I bet the guys selling password-securing apps are stoked. This month's victim of unauthorized access is Blizzard, which disclosed yesterday that someone got into its network on or around August 4 of this year.

So what'd they take? According to Blizzard's FAQ on the matter, players in the North American region--which includes Australia for reasons that I'm sure would make sense if someone bothered to describe it--have the following items to worry about:

  • Email addresses
  • Answers to secret security questions
  • Cryptographically scrambled versions of passwords (not actual passwords)
  • Information associated with the Mobile Authenticator
  • Information associated with the Dial-in Authenticator
  • Information associated with Phone Lock, a security system associated with Taiwan accounts only
  • In addition to this list of North American information, all users except those with China-based accounts had their email address taken.

So that means, at the minimum, your email address is out there. If you're part of what Blizzard considers its North American region, the answer to your secret security question is out there, too. Considering the number of sites that don't let you choose what your secret question is (if mine is any indication, Blizzard is among them), this may be an actual concern for you. Anyone that doesn't let you create your own custom secret question is a Bad Person. Blizzard says that an automated process to update secret questions and answers will be available in the near future. In the meantime, if you use the same secret question/answer combo on multiple sites, this might be a good time to tear your hair out and yell at the sky for a bit.

The FAQ goes on to say that the company believes that physical Blizzard Authenticators are secure, but app-based authentication will eventually require an update. For more details on how your password was stored and why it's unlikely that this will lead to your actual password getting out in the open, read the rest of Blizzard's FAQ... after you're finished changing your password, that is.

Jeff Gerstmann on Google+

209 Comments

Avatar image for jeff
jeff

6357

Forum Posts

107208

Wiki Points

0

Followers

Reviews: 0

User Lists: 20

Edited By jeff
Hey, while we're posting passwords in the open around here...
Hey, while we're posting passwords in the open around here...

This is the world we live in now. A world where some service you've signed up with seems to get penetrated every couple of weeks, sending everyone into a password-changing frenzy. I bet the guys selling password-securing apps are stoked. This month's victim of unauthorized access is Blizzard, which disclosed yesterday that someone got into its network on or around August 4 of this year.

So what'd they take? According to Blizzard's FAQ on the matter, players in the North American region--which includes Australia for reasons that I'm sure would make sense if someone bothered to describe it--have the following items to worry about:

  • Email addresses
  • Answers to secret security questions
  • Cryptographically scrambled versions of passwords (not actual passwords)
  • Information associated with the Mobile Authenticator
  • Information associated with the Dial-in Authenticator
  • Information associated with Phone Lock, a security system associated with Taiwan accounts only
  • In addition to this list of North American information, all users except those with China-based accounts had their email address taken.

So that means, at the minimum, your email address is out there. If you're part of what Blizzard considers its North American region, the answer to your secret security question is out there, too. Considering the number of sites that don't let you choose what your secret question is (if mine is any indication, Blizzard is among them), this may be an actual concern for you. Anyone that doesn't let you create your own custom secret question is a Bad Person. Blizzard says that an automated process to update secret questions and answers will be available in the near future. In the meantime, if you use the same secret question/answer combo on multiple sites, this might be a good time to tear your hair out and yell at the sky for a bit.

The FAQ goes on to say that the company believes that physical Blizzard Authenticators are secure, but app-based authentication will eventually require an update. For more details on how your password was stored and why it's unlikely that this will lead to your actual password getting out in the open, read the rest of Blizzard's FAQ... after you're finished changing your password, that is.

Avatar image for kindgineer
kindgineer

3102

Forum Posts

969

Wiki Points

0

Followers

Reviews: 0

User Lists: 5

Edited By kindgineer

People are ignorant. I hate hackers :/

Avatar image for aceofspudz
aceofspudz

937

Forum Posts

56

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

Edited By aceofspudz

Done. Thanks, Gerstmann!

Avatar image for undeadpool
Undeadpool

8418

Forum Posts

10761

Wiki Points

0

Followers

Reviews: 20

User Lists: 18

Edited By Undeadpool

UUUUUUUUUUUUUU-you know what? I can't even muster up being shocked or angry anymore.

Edit: Ya know what? Maybe a LITTLE angry over the whole "Use an authenticator for EXTRA PROTE-they stole the authenticator...SORRY!

UUUUUUUUUUGH!!!

Avatar image for banefirelord
BaneFireLord

4035

Forum Posts

638

Wiki Points

0

Followers

Reviews: 0

User Lists: 6

Edited By BaneFireLord

I am so sick of this shit.

Avatar image for hussatron
hussatron

193

Forum Posts

33

Wiki Points

0

Followers

Reviews: 0

User Lists: 1

Avatar image for ruthloose
RuthLoose

909

Forum Posts

5

Wiki Points

0

Followers

Reviews: 0

User Lists: 5

Edited By RuthLoose

I suppose this is a form of "punishment" for releasing Diablo III without PVP or some other hacker bullshit.

Avatar image for bell_end
Bell_End

1234

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

Edited By Bell_End

this is why we need biometrics as security pronto. nobody would be able to hack my face

Avatar image for lunar_aura
Lunar_Aura

2824

Forum Posts

17

Wiki Points

0

Followers

Reviews: 0

User Lists: 4

Edited By Lunar_Aura

That article picture shows a rather strong password. I don't think you can brute force Felix The Cat.

Avatar image for deactivated-6620058d9fa01
deactivated-6620058d9fa01

484

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 4

My Battle.net account is locked behind an authenticator that doesn't exist anymore.

Avatar image for winternet
Winternet

8454

Forum Posts

2255

Wiki Points

0

Followers

Reviews: 0

User Lists: 6

Edited By Winternet

Man, my e-mail address was going through such a good phase right now. I was getting around 10 spam e-mails a week, tops. Guess that will change now. Thanks Blizzard.

Avatar image for bell_end
Bell_End

1234

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

Edited By Bell_End

@Winternet said:

Man, my e-mail address was going through such a good phase right now. I was getting around 10 spam e-mails a week, tops. Guess that will change now. Thanks Blizzard.

why is it blizzards fault. blame the fucking hackers

Avatar image for wickedcobra03
WickedCobra03

2375

Forum Posts

587

Wiki Points

0

Followers

Reviews: 1

User Lists: 8

Edited By WickedCobra03

I am glad that our information is safe in these companies hands. Seriously, Microsoft with their FIFA crap, PSN, even steam... now Blizzard.

Is any of our information even safe anymore? That's why I barely store any credit or phone info online. This stuff is too easy to hack and get ahold of people's personal lives...

Avatar image for somejerk
SomeJerk

4077

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

Edited By SomeJerk
In addition to this list of North American information, all users except those with China-based accounts had their email address taken.
 
Send the marines.
Avatar image for duxa
Duxa

341

Forum Posts

1

Wiki Points

0

Followers

Reviews: 1

User Lists: 0

Edited By Duxa

@Skooky: Call them and ask for it to be removed... you will need to fax them or email them a copy of your ID and then they will remove it.

Avatar image for ravenlight
Ravenlight

8057

Forum Posts

12306

Wiki Points

0

Followers

Reviews: 0

User Lists: 2

Edited By Ravenlight

@Bell_End said:

this is why we need biometrics as security pronto. nobody would be able to hack my face

You say that, but it would only be a matter of time.

Avatar image for goldanas
Goldanas

568

Forum Posts

8

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

Edited By Goldanas

@Bell_End said:

this is why we need biometrics as security pronto. nobody would be able to hack my face

Just got to take a picture, and if it requires blink authentication, just crumple the photo a bit and you're good to go.

Now if you were talking about needles that dig into you and take a chunk of your DNA every time, now that'd be some future shit right there.

Avatar image for themasterds
TheMasterDS

3018

Forum Posts

7716

Wiki Points

0

Followers

Reviews: 1

User Lists: 31

Edited By TheMasterDS

I'm going to trust them and leave the password as it is. I really don't care if someone plays my Diablo 3 or Starcraft II account, there's nothing of value there. Well, I suppose if someone got in and deleted my progress or sold off all my stuff that'd be a bummer, but seeing as I haven't played Diablo 3 in months it wouldn't be that much of one.

Avatar image for joker369
Joker369

1012

Forum Posts

140

Wiki Points

0

Followers

Reviews: 0

User Lists: 2

Edited By Joker369

Changed it, thanks for the heads up

Avatar image for buzz_killington
buzz_killington

3674

Forum Posts

5319

Wiki Points

0

Followers

Reviews: 10

User Lists: 2

Edited By buzz_killington

Fuck! Now people know my favorite high school teacher's name!

Avatar image for xeirus
Xeirus

1729

Forum Posts

418

Wiki Points

0

Followers

Reviews: 1

User Lists: 2

Edited By Xeirus

@TheMasterDS said:

I'm going to trust them and leave the password as it is. I really don't care if someone plays my Diablo 3 or Starcraft II account, there's nothing of value there. Well, I suppose if someone got in and deleted my progress or sold off all my stuff that'd be a bummer, but seeing as I haven't played Diablo 3 in months it wouldn't be that much of one.

I felt the same way, haha. I'm not even mad, because I just don't care.

Avatar image for drayco21
Drayco21

30

Forum Posts

3602

Wiki Points

0

Followers

Reviews: 4

User Lists: 0

Edited By Drayco21

Passwords changed. Man, I can't wait for the day when everything in the industry goes digital so we can't have hard copies of things and must be connected to the system at all times to play so that this can happen all the time.

Avatar image for pyromagnestir
pyromagnestir

4507

Forum Posts

103

Wiki Points

0

Followers

Reviews: 0

User Lists: 23

Edited By pyromagnestir

Well that was easy enough. It will take years for people to hack my new password, 6enisB00Bs!

Avatar image for xymox
xymox

2422

Forum Posts

2520

Wiki Points

0

Followers

Reviews: 7

User Lists: 8

Edited By xymox

Answers to the secret questions you say? That makes one of us.

ugh. Can't copy paste a new password in their password box. Screw this, enjoy my lvl 60. Not worth the effort.

Avatar image for brackynews
Brackynews

4385

Forum Posts

27681

Wiki Points

0

Followers

Reviews: 5

User Lists: 48

Edited By Brackynews

Using a canned security question is less of a thing than choosing an irrelevant security answer you can always remember. What was the first street I lived on? Waffles. First pet? Waffles. Favourite teacher? Waffles. Mother's maiden name? Waffles. One of those might be true, but you see the point. Cracking secret questions are about social engineering, not dictionary attacks.

Also, if you use your birthdate information for anything (like say, a hastily chosen forum name) don't be shocked when people can track it back to find out more about you. Pick a different birthdate on forms you can always remember, without outright lying about your age. ~6 months different is reasonable if you're over 21.

The point being, when (not if) the info gets stolen, the people who get to see it do not have real data they can use when calling your banks, credit cards, government offices, etc. If you think it's only about gold farmers hacking your inventory you're outta yo' goddamn mind. This shit is sold to the highest bidder. Be careful of who knows your DOB, Mother's maiden name, and address history. You will be amazed how much access to other information those things will get you over the phone. (Hopefully I shouldn't even have to say guard your SSN/SIN like gold these days, but I remember old news stories where schools were posting grade printouts on doors using SSN numbers to identify students.)

Avatar image for crosstheatlantic
CrossTheAtlantic

1154

Forum Posts

4

Wiki Points

0

Followers

Reviews: 0

User Lists: 2

Edited By CrossTheAtlantic

@Ravenlight said:

@Bell_End said:

this is why we need biometrics as security pronto. nobody would be able to hack my face

You say that, but it would only be a matter of time.

Clearly, hasn't seen Mission Impossible. It's only a matter of time, people!

Avatar image for sackmanjones
Sackmanjones

5596

Forum Posts

50

Wiki Points

0

Followers

Reviews: 7

User Lists: 5

Edited By Sackmanjones

I keep getting e mails from blizzard saying I'm trying to sell my Warcraft character.... I've never played WOW in my life.

Avatar image for wurmbollie
Wurmbollie

20

Forum Posts

1

Wiki Points

0

Followers

Reviews: 0

User Lists: 1

Edited By Wurmbollie

Will Blizz make the passwords case sensitive now?

Avatar image for jswan13
JSwan13

355

Forum Posts

460

Wiki Points

0

Followers

Reviews: 0

User Lists: 13

Edited By JSwan13

Thanks Jeff!

Avatar image for deactivated-5e49e9175da37
deactivated-5e49e9175da37

10812

Forum Posts

782

Wiki Points

0

Followers

Reviews: 0

User Lists: 14

Fuck, at first I didn't care, but my bnet password is also my email password. Now I have to go on full lockdown.

Avatar image for doobie
doobie

612

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

Edited By doobie

@CrossTheAtlantic said:

@Ravenlight said:

@Bell_End said:

this is why we need biometrics as security pronto. nobody would be able to hack my face

You say that, but it would only be a matter of time.

Clearly, hasn't seen Mission Impossible. It's only a matter of time, people!

maybe bell_end could use his Bell end as a biometric device

Avatar image for deactivated-5abeb9715d7a2
deactivated-5abeb9715d7a2

372

Forum Posts

345

Wiki Points

0

Followers

Reviews: 0

User Lists: 22

@Sackmanjones said:

I keep getting e mails from blizzard saying I'm trying to sell my Warcraft character.... I've never played WOW in my life.

Yeah, that's a known scam. I haven't played WoW in years, but I get them once or twice a year.

Avatar image for sweep
sweep

10887

Forum Posts

3660

Wiki Points

0

Followers

Reviews: 4

User Lists: 14

Edited By sweep  Moderator

I changed my password, but if people have my email and the answers to my secret question(I can't even remember what that is) doesn't that render my password redundant? Although, I guess only if they also have my email password.

I'm trying to figure out how much I should be freaking out right now. At the moment I'm still at "Not at all."

Avatar image for joey_ravn
JoeyRavn

5290

Forum Posts

792

Wiki Points

0

Followers

Reviews: 2

User Lists: 3

Edited By JoeyRavn

@CrossTheAtlantic said:

@Ravenlight said:

@Bell_End said:

this is why we need biometrics as security pronto. nobody would be able to hack my face

You say that, but it would only be a matter of time.

Clearly, hasn't seen Mission Impossible. It's only a matter of time, people!

Nicholas Cage is way ahead of you guys. Waaay ahead.

Avatar image for gamer_152
gamer_152

15033

Forum Posts

74588

Wiki Points

0

Followers

Reviews: 71

User Lists: 6

Edited By gamer_152  Moderator

Hackers suck, glad my account wasn't caught up in this. This is also why your secret question should be something only you know. It could be worse though, I'm sure there are a lot of important databases full of our details that are far worse protected than Blizzard's.

Avatar image for gunslingerpanda
GunslingerPanda

5263

Forum Posts

40

Wiki Points

0

Followers

Reviews: 0

User Lists: 2

Edited By GunslingerPanda

So EU users are safe? Cool.

Avatar image for stinky
stinky

1564

Forum Posts

2

Wiki Points

0

Followers

Reviews: 0

User Lists: 1

Edited By stinky

@Wurmbollie said:

Will Blizz make the passwords case sensitive now?

wouldn't help anything against unauthorized access.

Avatar image for lukeweizer
Lukeweizer

3304

Forum Posts

24753

Wiki Points

0

Followers

Reviews: 1

User Lists: 2

Edited By Lukeweizer

Access to my mobile aunthenticator? What do I even do about that? Delete the app and get a new one? I don't even know what my Blizzard secret question is. I don't even know what sites ask for it so I can go change it. What a pain in the ass.

Avatar image for mrklorox
MrKlorox

11220

Forum Posts

1071

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

Edited By MrKlorox

Fuck you Blizzard. For many many annoyances regarding the password change process on your website. And for requiring to put myself at risk just to play your SINGLEPLAYER game. FUCK YOU!

Avatar image for deactivated-5d056614f191a
deactivated-5d056614f191a

1008

Forum Posts

11123

Wiki Points

0

Followers

Reviews: 5

User Lists: 4

I like how they dont inform people on the front page of battle net nor any of their game pages..

just goes to show blizzard could really give a rats ass about their customers security.

Avatar image for jayjonesjunior
jayjonesjunior

1148

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

Edited By jayjonesjunior

@ck1nd said:

People are ignorant. I hate hackers :/

what? hackers are probably the least ignorant of all people luls.

Avatar image for legendarychopchop
LegendaryChopChop

1387

Forum Posts

150

Wiki Points

0

Followers

Reviews: 0

User Lists: 1

Not surprised. The company needs a damn Mobile Authenticator in order to keep things safe... I didn't use one, but now I will. It'll add an extra inkling of security after I change the PW.

Avatar image for butano
butano

2001

Forum Posts

60

Wiki Points

0

Followers

Reviews: 1

User Lists: 7

Edited By butano

So, the authenticator attached to my keychain is basically useless now? That kinda sucks if that's the case.

Avatar image for delta_ass
delta_ass

3776

Forum Posts

0

Wiki Points

0

Followers

Reviews: 36

User Lists: 7

Edited By delta_ass

Fuck you Blizzard.

Avatar image for meatsim
MeatSim

11201

Forum Posts

150

Wiki Points

0

Followers

Reviews: 0

User Lists: 23

Edited By MeatSim

What a pain but gotta change those passwords.

Avatar image for legalbagel
LegalBagel

1955

Forum Posts

1590

Wiki Points

0

Followers

Reviews: 7

User Lists: 7

Edited By LegalBagel

This goes beyond battle.net - if you use the same password for Blizzard that you do for anything else, time to go on a password changing spree. It'd be extremely easy to extrapolate from your email address to a ton of other accounts and brute force your password/email into them to see if they work.

Avatar image for chuckdenomolos
ChuckDeNomolos

79

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

Edited By ChuckDeNomolos

Is there a way to just cancel my Battle.net account? I was done with Diablo 3 after a few days, and all it's gotten me is Chinese IPs trying to access my email.

Avatar image for iluvmsmarvel
ILuvMsMarvel

143

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

Edited By ILuvMsMarvel

Ok, with the thumbnail used on the front page, I have to say this: Guess Blizzard screwed the pooch once again.

Avatar image for tesla
Tesla

2299

Forum Posts

1

Wiki Points

0

Followers

Reviews: 0

User Lists: 4

Edited By Tesla

You would think Blizzard of all companies would value customer security. I'm glad that none of their products beyond Diablo interest me, it will make it easy to not give them another dime.

Avatar image for tineyoghurt
tineyoghurt

384

Forum Posts

426

Wiki Points

0

Followers

Reviews: 1

User Lists: 11

Edited By tineyoghurt

If I remember correctly, the reason for Australia being in in the "North Americas" is that they originally were lumped in with Asia, which didn't work out since Australians like to: a) chat in English b) not be bested by the Koreans. 
 
Ironically, this is the first time I'm glad that battle.net is split into regions, as us Europeans seem rather unaffected by all this (directly, at least).