Diablo® III

Important Security Update

08/09/2012 03:59 PMPosted by Fionessane
... Seriously? How is it ignorant or inaccurate? They had "no control" over this? Wha?


What control did they have? They got compromised. It happens, and they told us. Do you think that they would have willingly allowed themselves to be compromised? Don't be dense. That fool was making posts saying out-of-hand, sky-is-falling things. I called him on it. End of story.


I work in IT. There are measures that can be taken to prevent compromise. I've worked in a lot of tightly-run ships, and I've worked in a lot of "seat of your pants, it'll never happen to us" shops. Which do you think Blizzard is?
Shame on you Blizzard. I've never seen such a great company fall so fast. Blizzard you make me sick to my stomach because of what you've allowed this D3 experience to become.
So, they have our encrypted passwords. How long will it take for them to unencrypt them? With all the money floating around because of the AH, and with our accounts tied in with Paypal, which itself is tied to our CC/Bank info, why should we NOT panic?

What is Blizzard doing to fix this situation?


It sounds like the passwords are stored using a one-way encryption method. It would take a LOT of computational time to crack one password, let alone millions. I'm not worried about that, so much as I am worried about the authenticator and secret question access.


If they have your secret question/answer and the serial # of your mobile authenticator, the encrypted password won't matter.
Just wow, and i bought the collectors edition of this. :/
Im so let down, however i do agree that Morhaime addressed this issue to the
public very quickly and is taking the appropriate steps, thats more than
most would have done.
I remember when a lot of people got hacked. The statement was user end problem. really? I think the server was compromised long ago and only now after a good amount of time of investigation blizzard admits it. Where the fan boys are now?

More than one month without play the game, came back here to see if they fixed the crap they did with 1.0.3 and now this ...
90 Undead Warlock
8765
08/09/2012 03:57 PMPosted by superclove
Please [url="http://www.blizzard.com/securityupdate"]click here[/url] to read an important security update about your Battle.net account.


I find it disconcerting that instead of really making it clear in the article title, you decide to label it obscurely as a "Security update". You also haven't emailed any of your Battle.net users to notify them of the breach, so users who haven't actively logged into B.net are still unaware that their information has been stolen.

Blizzard, it is clear that you're intentionally avoiding taking every possible step to ensure your customers are aware of this serious issue.


Posted 26 minutes ago...

They're just responding to the situation
Please [url="http://www.blizzard.com/securityupdate"]click here[/url] to read an important security update about your Battle.net account.


I find it disconcerting that instead of really making it clear in the article title, you decide to label it obscurely as a "Security update". You also haven't emailed any of your Battle.net users to notify them of the breach, so users who haven't actively logged into B.net are still unaware that their information has been stolen.

Blizzard, it is clear that you're intentionally avoiding taking every possible step to ensure your customers are aware of this serious issue.


Of course, they need to keep this as low key as they possibly can.

08/09/2012 04:01 PMPosted by haxity
Shame on you Blizzard. I've never seen such a great company fall so fast. Blizzard you make me sick to my stomach because of what you've allowed this D3 experience to become.

QFT
Edited by Runar#1385 on 8/9/2012 4:03 PM PDT
Scary. I'll be changing stuff as soon as I get home.


It sounds like the passwords are stored using a one-way encryption method. It would take a LOT of computational time to crack one password, let alone millions. I'm not worried about that, so much as I am worried about the authenticator and secret question access.


If they have your secret question/answer and the serial # of your mobile authenticator, the encrypted password won't matter.


My point exactly.
So, they have our encrypted passwords. How long will it take for them to unencrypt them? With all the money floating around because of the AH, and with our accounts tied in with Paypal, which itself is tied to our CC/Bank info, why should we NOT panic?

What is Blizzard doing to fix this situation?


probably give us all a free month of subscription time to D3 lol....oh wait.... never mind
Might I suggest offering a REFUND to all players that have less than 60 hours played on their accounts?
LOOOOL NO WONDER EVERY1 WAS GETTING HACKED A WEEK AFTER THE GAME CAME OUT.

Inb4authenicatefanboy
08/09/2012 04:01 PMPosted by Hedda


What control did they have? They got compromised. It happens, and they told us. Do you think that they would have willingly allowed themselves to be compromised? Don't be dense. That fool was making posts saying out-of-hand, sky-is-falling things. I called him on it. End of story.


I work in IT. There are measures that can be taken to prevent compromise. I've worked in a lot of tightly-run ships, and I've worked in a lot of "seat of your pants, it'll never happen to us" shops. Which do you think Blizzard is?

And you think a company as large as blizzard doesn't have measures in place to prevent compromise? How would they have lasted as long as they have as a company if their security measures were terrible? I've only heard of them getting hacked one other time, years ago. For a company as large, long running, and profitable as blizzard- i'm kinda surprised it hasn't happened more. PSN hasn't been around all that long, and they already go hacked, and to boot had none of their customers' personal info encrypted?
08/09/2012 03:59 PMPosted by Fionessane
... Seriously? How is it ignorant or inaccurate? They had "no control" over this? Wha?


What control did they have? They got compromised. It happens, and they told us. Do you think that they would have willingly allowed themselves to be compromised? Don't be dense. That fool was making posts saying out-of-hand, sky-is-falling things. I called him on it. End of story.


You're absolutely out of your mind if you think companies don't have control over their risk management.
08/09/2012 04:02 PMPosted by Rìghteous
logged into my account immediately to check my accounts and change my password and secret question


How the hell did you change your secret question?


can't find anywhere to change this either...
page doesnt exist, typical.
This forum is read-only.

Please report any Code of Conduct violations, including:

Threats of violence. We take these seriously and will alert the proper authorities.

Posts containing personal information about other players. This includes physical addresses, e-mail addresses, phone numbers, and inappropriate photos and/or videos.

Harassing or discriminatory language. This will not be tolerated.

Forums Code of Conduct

Report Post # written by

Reason
Explain (256 characters max)
Submit Cancel

Reported!

[Close]