Something went wrong. Try again later

Giant Bomb News

209 Comments

Change Your Battle.net Password

Blizzard's network has been accessed by an outside party, your email addresses and "secret question" answers are out there.

Hey, while we're posting passwords in the open around here...
Hey, while we're posting passwords in the open around here...

This is the world we live in now. A world where some service you've signed up with seems to get penetrated every couple of weeks, sending everyone into a password-changing frenzy. I bet the guys selling password-securing apps are stoked. This month's victim of unauthorized access is Blizzard, which disclosed yesterday that someone got into its network on or around August 4 of this year.

So what'd they take? According to Blizzard's FAQ on the matter, players in the North American region--which includes Australia for reasons that I'm sure would make sense if someone bothered to describe it--have the following items to worry about:

  • Email addresses
  • Answers to secret security questions
  • Cryptographically scrambled versions of passwords (not actual passwords)
  • Information associated with the Mobile Authenticator
  • Information associated with the Dial-in Authenticator
  • Information associated with Phone Lock, a security system associated with Taiwan accounts only
  • In addition to this list of North American information, all users except those with China-based accounts had their email address taken.

So that means, at the minimum, your email address is out there. If you're part of what Blizzard considers its North American region, the answer to your secret security question is out there, too. Considering the number of sites that don't let you choose what your secret question is (if mine is any indication, Blizzard is among them), this may be an actual concern for you. Anyone that doesn't let you create your own custom secret question is a Bad Person. Blizzard says that an automated process to update secret questions and answers will be available in the near future. In the meantime, if you use the same secret question/answer combo on multiple sites, this might be a good time to tear your hair out and yell at the sky for a bit.

The FAQ goes on to say that the company believes that physical Blizzard Authenticators are secure, but app-based authentication will eventually require an update. For more details on how your password was stored and why it's unlikely that this will lead to your actual password getting out in the open, read the rest of Blizzard's FAQ... after you're finished changing your password, that is.

Jeff Gerstmann on Google+

209 Comments

Avatar image for brackynews
Brackynews

4385

Forum Posts

27681

Wiki Points

0

Followers

Reviews: 5

User Lists: 48

Edited By Brackynews
Avatar image for gordo789
Gordo789

364

Forum Posts

2

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

Edited By Gordo789

cool, they can play as much Diablo III as they want because i could not care less about that fucking game.

Avatar image for pop
Pop

2769

Forum Posts

4697

Wiki Points

0

Followers

Reviews: 0

User Lists: 8

Edited By Pop

they said something about global accounts too.

Avatar image for deactivated-653d2db498d3a
deactivated-653d2db498d3a

155

Forum Posts

155

Wiki Points

0

Followers

Reviews: 0

User Lists: 3

Can you even change your security questions?

Avatar image for bollard
Bollard

8298

Forum Posts

118

Wiki Points

0

Followers

Reviews: 3

User Lists: 12

Edited By Bollard

@Bell_End said:

this is why we need biometrics as security pronto. nobody would be able to hack my face

Well, you say that, but in all honesty it's just a different form of password. To verify what your face/eye/fingerprint look like Blizzard still need to keep a copy of it, right? So hackers could just steal that, and write a program that presents that data when asked for your biometrics. That's all scanners do, convert real world shit to data, and data is easy to copy.

Avatar image for rawson
Rawson

143

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 3

Edited By Rawson

All the more reason to get a fucking authenticator.

Avatar image for kiri90
Kiri90

301

Forum Posts

0

Wiki Points

0

Followers

Reviews: 1

User Lists: 6

Edited By Kiri90

¡Viva la revolución! Haha

Avatar image for superkidsid
superkidsid

29

Forum Posts

120

Wiki Points

0

Followers

Reviews: 0

User Lists: 4

Edited By superkidsid

If only I had real answers to the secret questions maybe I would remember them better.

Avatar image for harpell
Harpell

209

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

Edited By Harpell

Oh, those hackers!

Avatar image for theanticitizen
theanticitizen

426

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 1

Edited By theanticitizen
@Xeirus

@TheMasterDS said:

I'm going to trust them and leave the password as it is. I really don't care if someone plays my Diablo 3 or Starcraft II account, there's nothing of value there. Well, I suppose if someone got in and deleted my progress or sold off all my stuff that'd be a bummer, but seeing as I haven't played Diablo 3 in months it wouldn't be that much of one.

I felt the same way, haha. I'm not even mad, because I just don't care.

The thing is they would also have access to your email account tied to your battle.net account, and if that's tied to any sort of financial information...well...
Avatar image for spicyrichter
SpicyRichter

748

Forum Posts

102

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

Edited By SpicyRichter

Unprofessional... companies need to be held accountable for the security of our personal information!

Avatar image for mr48
mr48

104

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

Edited By mr48

@Bell_End: Are you fucking serious? Its Blizzard's fault for not having enough security, as much as it is the hackers fault for breaking in.

Avatar image for musubi
musubi

17524

Forum Posts

5650

Wiki Points

0

Followers

Reviews: 8

User Lists: 17

Edited By musubi
@theanticitizen
@Xeirus

@TheMasterDS said:

I'm going to trust them and leave the password as it is. I really don't care if someone plays my Diablo 3 or Starcraft II account, there's nothing of value there. Well, I suppose if someone got in and deleted my progress or sold off all my stuff that'd be a bummer, but seeing as I haven't played Diablo 3 in months it wouldn't be that much of one.

I felt the same way, haha. I'm not even mad, because I just don't care.

The thing is they would also have access to your email account tied to your battle.net account, and if that's tied to any sort of financial information...well...
Only if you are dumb enough to keep the same password for both services.
Avatar image for mr48
mr48

104

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

Edited By mr48

@_Horde said:

The security question is "banana".

I think you mean BANANER

Avatar image for penguindust
penguindust

13129

Forum Posts

22

Wiki Points

0

Followers

Reviews: 0

User Lists: 3

Edited By penguindust

I used to think hackers were cool, in-line skating, club kids who fought "the Man" in between sexing up a young Angelina Jolie. I dug their non-conformist lifestyle and their appreciation of classic television. My illusions have been shattered, my admiration is no more.

This is why we can't have nice things...then again, I don't think I have a Battle.net account so who am I to complain? Really, I wanted an excuse to reminisce about Angelina Jolie's breasts.

Avatar image for obsurveyor
Obsurveyor

109

Forum Posts

2

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

Edited By Obsurveyor

Because of the Real Money auction house, Blizzard might actually be breaking the law by not notifying people about the security breach sooner.

Avatar image for xeirus
Xeirus

1729

Forum Posts

418

Wiki Points

0

Followers

Reviews: 1

User Lists: 2

Edited By Xeirus

@Demoskinos said:

@theanticitizen
@Xeirus

@TheMasterDS said:

I'm going to trust them and leave the password as it is. I really don't care if someone plays my Diablo 3 or Starcraft II account, there's nothing of value there. Well, I suppose if someone got in and deleted my progress or sold off all my stuff that'd be a bummer, but seeing as I haven't played Diablo 3 in months it wouldn't be that much of one.

I felt the same way, haha. I'm not even mad, because I just don't care.

The thing is they would also have access to your email account tied to your battle.net account, and if that's tied to any sort of financial information...well...
Only if you are dumb enough to keep the same password for both services.

I don't think it's dumb really.

I work tech support for clinics and we have close to 20 different systems we have to keep seperate passwords for, this does not include our personal accounts, so keeping them the same, or at least similar, is almost a must.

Avatar image for avidwriter
avidwriter

775

Forum Posts

25

Wiki Points

0

Followers

Reviews: 1

User Lists: 0

Edited By avidwriter

GG Blizzard. Good to know all those monthly money is going to good use.

Avatar image for korwin
korwin

3919

Forum Posts

25

Wiki Points

0

Followers

Reviews: 0

User Lists: 2

Edited By korwin

@Xeirus said:

@Demoskinos said:

@theanticitizen
@Xeirus

@TheMasterDS said:

I'm going to trust them and leave the password as it is. I really don't care if someone plays my Diablo 3 or Starcraft II account, there's nothing of value there. Well, I suppose if someone got in and deleted my progress or sold off all my stuff that'd be a bummer, but seeing as I haven't played Diablo 3 in months it wouldn't be that much of one.

I felt the same way, haha. I'm not even mad, because I just don't care.

The thing is they would also have access to your email account tied to your battle.net account, and if that's tied to any sort of financial information...well...
Only if you are dumb enough to keep the same password for both services.

I don't think it's dumb really.

I work tech support for clinics and we have close to 20 different systems we have to keep seperate passwords for, this does not include our personal accounts, so keeping them the same, or at least similar, is almost a must.

No it's dumb, critical services should never share the same password.

Avatar image for lava
Lava

771

Forum Posts

2164

Wiki Points

0

Followers

Reviews: 7

User Lists: 8

Edited By Lava

Come on hackers, stop being so dumb.

Avatar image for dvorak
dvorak

1553

Forum Posts

616

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

Edited By dvorak

Just another reason to have two-factor authentication wherever you do business. Because this way, you don't give a fuck even if someone gets your password.

Avatar image for tebbit
tebbit

4659

Forum Posts

861

Wiki Points

0

Followers

Reviews: 3

User Lists: 6

Edited By tebbit

"Greetings!
 
It has come to our attention that you are trying to sell your personal Diablo III account(s).
As you may not be aware of, this conflicts with the EULA and Terms of Agreement.
If this proves to be true, your account can and will be disabled. 
It will be ongoing for further investigation by Blizzard Entertainment's employees.
If you wish to not get your account suspended you should immediately verify your account ownership. 
 
You can confirm that you are the original owner of the account to this secure website with:
https://us.battle.net/login/en/?ref=http%3A%2F%2Fus.battle.net%2Fd3%2Fen%2Findex&app;=com-d3
 
Login to your account, In accordance following template to verify your account.
 
* First and Surname
* Secret Question and Answer
Show * Please enter the correct information
 
If you ignore this mail your account can and will be closed permanently.

Once we verify your account, we will reply to your e-mail informing you that we have dropped the investigation.
 
Regards,
 
Account Administration Team
Blizzard Entertainment 
http://www.blizzard.com/support/
Diablo III , Blizzard Entertainment 2012"

Well.

Avatar image for g0rd0nfr33m4n
G0rd0nFr33m4n

826

Forum Posts

2263

Wiki Points

0

Followers

Reviews: 12

User Lists: 18

Edited By G0rd0nFr33m4n

@Rawson said:

All the more reason to get a fucking authenticator.

You think a company failing to keep your info safe deserves more of your hard earned cash ? ... For failing ? No no! I'll change my password and not give them money, thank you very much.

Avatar image for xeirus
Xeirus

1729

Forum Posts

418

Wiki Points

0

Followers

Reviews: 1

User Lists: 2

Edited By Xeirus

@Korwin said:

@Xeirus said:

@Demoskinos said:

@theanticitizen
@Xeirus

@TheMasterDS said:

I'm going to trust them and leave the password as it is. I really don't care if someone plays my Diablo 3 or Starcraft II account, there's nothing of value there. Well, I suppose if someone got in and deleted my progress or sold off all my stuff that'd be a bummer, but seeing as I haven't played Diablo 3 in months it wouldn't be that much of one.

I felt the same way, haha. I'm not even mad, because I just don't care.

The thing is they would also have access to your email account tied to your battle.net account, and if that's tied to any sort of financial information...well...
Only if you are dumb enough to keep the same password for both services.

I don't think it's dumb really.

I work tech support for clinics and we have close to 20 different systems we have to keep seperate passwords for, this does not include our personal accounts, so keeping them the same, or at least similar, is almost a must.

No it's dumb, critical services should never share the same password.

Feel free to try and manage 20-30 different passwords and get back to me.

Avatar image for condemned
Condemned

6

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

Edited By Condemned

Been a while since I signed in, thanks for the heads up.

Avatar image for usgrovers
usgrovers

177

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

Edited By usgrovers

I can hardly wait for the all digitial future... the future where we have a unique logon for every single publisher required to play games and this kind of thing happens every week.

Avatar image for xerxes8933a
xerxes8933a

226

Forum Posts

12

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

Edited By xerxes8933a

@Xeirus said:

@Korwin said:

Feel free to try and manage 20-30 different passwords and get back to me.

With that many passwords, you should just write them down on paper. These days it's a hell of a lot more likely that some server somewhere will get hacked then someone will break into your house and steal the notepad in your desk drawer.

Avatar image for jakkblades
jakkblades

423

Forum Posts

4

Wiki Points

0

Followers

Reviews: 0

User Lists: 9

Edited By jakkblades

@Xerxes8933A said:

@Xeirus said:

@Korwin said:

Feel free to try and manage 20-30 different passwords and get back to me.

With that many passwords, you should just write them down on paper. These days it's a hell of a lot more likely that some server somewhere will get hacked then someone will break into your house and steal the notepad in your desk drawer.

Here's an idea. Book-encode your passwords. Use the same formula for all your passwords (the third word of chapters 5 9 and 12 for instance) and make that your password, but use a different book for each password.

Avatar image for theanticitizen
theanticitizen

426

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 1

Edited By theanticitizen

@Xeirus @Korwin yes, because, you know, having different passwords GUARANTEES that hackers cannot change/access passwords and information right? Surely they've never thought of that.

Avatar image for dooscent
dooscent

197

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 6

Edited By dooscent

For what it's worth -

I saw a few people saying that Blizzard uses Case Sensitivity -- they don't. And through a blog (which I don't remember anymore, I'm sorry!) a former Blizzard security guy gave a pretty good explanation as to why they don't need to be. All the same, he admitted that it would still be a rather convenient step.

On the plus side, it means you can totally enter your information with the caps lock on. So there's that.

Avatar image for forcen
Forcen

2746

Forum Posts

29709

Wiki Points

0

Followers

Reviews: 1

User Lists: 31

Edited By Forcen

@Xeirus: Get lastpass.

Avatar image for xeirus
Xeirus

1729

Forum Posts

418

Wiki Points

0

Followers

Reviews: 1

User Lists: 2

Edited By Xeirus

@GenocidalKitten said:

@Xeirus said:

@Korwin said:

@Xeirus said:

@Demoskinos said:

@theanticitizen
@Xeirus

@TheMasterDS said:

I'm going to trust them and leave the password as it is. I really don't care if someone plays my Diablo 3 or Starcraft II account, there's nothing of value there. Well, I suppose if someone got in and deleted my progress or sold off all my stuff that'd be a bummer, but seeing as I haven't played Diablo 3 in months it wouldn't be that much of one.

I felt the same way, haha. I'm not even mad, because I just don't care.

The thing is they would also have access to your email account tied to your battle.net account, and if that's tied to any sort of financial information...well...
Only if you are dumb enough to keep the same password for both services.

I don't think it's dumb really.

I work tech support for clinics and we have close to 20 different systems we have to keep seperate passwords for, this does not include our personal accounts, so keeping them the same, or at least similar, is almost a must.

No it's dumb, critical services should never share the same password.

Feel free to try and manage 20-30 different passwords and get back to me.

I do and do you know how I do it 1Password. Easy

But, the fact that you have a bunch of passwords to manage and it's hard to do, doesn't make it any less dumb to have same password for stuff, all it does is justify why you do it.

I think you're all giving me advice for something I don't need... I've yet to be hacked (knock on wood) and I didn't really ask for advice. I was simply explaining why people keep their passwords similar and calling people stupid for doing it when 99% of people are guilty of it just rang a little hollow and pompous.

@Forcen said:

@Xeirus: Get lastpass.

That's a really cool software, I doubt I'll use it, but thanks for sharing I always wondered if something like that was available, maybe one day :)

Avatar image for korwin
korwin

3919

Forum Posts

25

Wiki Points

0

Followers

Reviews: 0

User Lists: 2

Edited By korwin

@GenocidalKitten said:

@Xeirus said:

@Korwin said:

@Xeirus said:

@Demoskinos said:

@theanticitizen
@Xeirus

@TheMasterDS said:

I'm going to trust them and leave the password as it is. I really don't care if someone plays my Diablo 3 or Starcraft II account, there's nothing of value there. Well, I suppose if someone got in and deleted my progress or sold off all my stuff that'd be a bummer, but seeing as I haven't played Diablo 3 in months it wouldn't be that much of one.

I felt the same way, haha. I'm not even mad, because I just don't care.

The thing is they would also have access to your email account tied to your battle.net account, and if that's tied to any sort of financial information...well...
Only if you are dumb enough to keep the same password for both services.

I don't think it's dumb really.

I work tech support for clinics and we have close to 20 different systems we have to keep seperate passwords for, this does not include our personal accounts, so keeping them the same, or at least similar, is almost a must.

No it's dumb, critical services should never share the same password.

Feel free to try and manage 20-30 different passwords and get back to me.

I do and do you know how I do it 1Password. Easy

But, the fact that you have a bunch of passwords to manage and it's hard to do, doesn't make it any less dumb to have same password for stuff, all it does is justify why you do it.

This. My job involves me having privileged access to multi government systems... needless to say there's a lot to keep track of and fairly strict security requirements.

Avatar image for majkiboy
Majkiboy

1104

Forum Posts

5

Wiki Points

0

Followers

Reviews: 0

User Lists: 8

Edited By Majkiboy

So what about the ol' hackers vs crackers? Does anyone still care (or ever cared) about the difference?

Avatar image for dooscent
dooscent

197

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 6

Edited By dooscent

@Majkiboy:

I think people stopped caring around the time Matthew Lillard started screaming "HACK THE PLANET!"

Avatar image for doobie
doobie

612

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

Edited By doobie

must use this as an excuse to remind everyone how little i care about D3. after playing it for 400 hours

don't worry though guys every time a thread or news story even remotely mentions Blizzard or D3 i will remind you all just how much i don't care and i will always finish the sentence with something witty and clever like FUCK YOU BLIZZARD or sometimes even just FUCK YOU

Avatar image for arkasai
arkasai

734

Forum Posts

120

Wiki Points

0

Followers

Reviews: 0

User Lists: 1

Edited By arkasai

@Majkiboy: Not much to discuss there, generally people who root iPhones and Android phones are cool dudes in most people's books while Chinese hackers that steal your identity should be shot.

Avatar image for dolsande
dolsande

61

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

Edited By dolsande

Why did it take so long for them to tell us? The battle.net post is dated 9th of August and they got hacked on the 4th. I seem to remember people bitching at Sony when they took too long to tell people that they had been hacked. Maybe people are just getting used to it, which kind of sucks. Fucking A-hole hackers.

Avatar image for newfiebullet
NewfieBullet

134

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

Edited By NewfieBullet

My account already got hacked, lost all my items and gold, and the funny thing is I was on the second act in normal so I basically had shit gear. So now I have to start the game over... Great

Avatar image for jayzilla
Jayzilla

2709

Forum Posts

18

Wiki Points

0

Followers

Reviews: 0

User Lists: 7

Edited By Jayzilla

Never played a Blizzard game. Kinda stoked now I haven't.

Avatar image for pip_fox
Pip_Fox

34

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 4

Edited By Pip_Fox

sometimes i wonder if its always the same person who breaks into these companies' databases and takes our info. Some sort of Dr. Evil-like maniac who plans to hold our email addresses ransom for ONE MILLION DOLLARS. But of course that cant be true...

Avatar image for shaunage
Shaunage

948

Forum Posts

152

Wiki Points

0

Followers

Reviews: 4

User Lists: 10

Edited By Shaunage

As an Australian using a UK copy of the game because it was slightly cheaper, consider me mildly pleased I've avoided this.

Avatar image for corey_f
Corey_F

24

Forum Posts

5

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

Edited By Corey_F

Yea.... So I may have forgotten my secret question answer..... meh then again haven't played starcraft in a while.

Avatar image for mercer
Mercer

211

Forum Posts

5

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

Edited By Mercer

@JoeyRavn said:

@CrossTheAtlantic said:

@Ravenlight said:

@Bell_End said:

this is why we need biometrics as security pronto. nobody would be able to hack my face

You say that, but it would only be a matter of time.

Clearly, hasn't seen Mission Impossible. It's only a matter of time, people!

Nicholas Cage is way ahead of you guys. Waaay ahead.

I see your Cage and raise you another Criuse: Minority Report :D

But that's a rather more er...extreme form of identity theft lol

Avatar image for imbarkus
imbarkus

46

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

Edited By imbarkus

@Bell_End: No, it's possible. I'm pretty sure I saw that in a Nicholas Cage movie, so it's gotta be true. Wesley Snipes did it with an eyeball on a pen in Demolition Man. you want to lose your eyeball!!?!

Avatar image for smilingpig
SmilingPig

1370

Forum Posts

5

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

Edited By SmilingPig

I want my money back...and the time you stole from me Blizzard...and a baby murlock toy.

Avatar image for duskwind
Duskwind

148

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

Edited By Duskwind

I just went through the battle.net password recovery system to figure out just how easy it would be for someone to change my password and log into my account. Seems like Blizzard sends a code to the mobile phone you registered with the account, and only then can you reset the password. So I guess the danger is minimal at best.