Welcome Guest ( Log In | Register )

Outline · [ Standard ] · Linear+

 blizzard authenticator

views
     
TSnikridhwan
post May 21 2012, 11:26 PM, updated 14y ago

Getting Started
**
Junior Member
123 posts

Joined: Feb 2010



Lets just see how many actually uses the blizzard authenticator.. I heard even with blizzard authenticator got hacked..
DrLaboo
post May 22 2012, 11:15 AM

♥ surprised buttsek ♥
******
Senior Member
1,004 posts

Joined: Feb 2011
From: Your House



i use capalang phone can use this meh?

This post has been edited by DrLaboo: May 22 2012, 11:16 AM
Shadow Kun
post May 22 2012, 11:16 AM

TOASTY!
****
Senior Member
621 posts

Joined: Sep 2008
From: Middle of Nowhere
whaz is blizzhurrdurr??
StorMx
post May 22 2012, 11:18 AM

Getting Started
**
Junior Member
143 posts

Joined: Apr 2011
You dont have an option of

"No, I dont use an authenticator."
StnlySam
post May 22 2012, 11:27 AM

New Member
*
Junior Member
36 posts

Joined: May 2012
From: PJ, Sel


QUOTE(StorMx @ May 22 2012, 11:18 AM)
You dont have an option of

"No, I dont use an authenticator."
*
yah..agree. but how bout the sms alert? that one not authenticator right? hmm.gif
aLertz
post May 22 2012, 11:35 AM

Overconfidence is a flimsy shield
******
Senior Member
1,111 posts

Joined: Mar 2005
From: TaiPinG / Singapore



no smart phone...guess i'll go have a look at the sms alert see can use on my fon anot biggrin.gif
dishwasher
post May 22 2012, 11:56 AM

heterochromatic babe
*****
Senior Member
851 posts

Joined: Nov 2004


The authenticator app is something you download for your android/iPhone device, which provides you with a code every time you log in. Its very different from the SMS alert thingy. That one only sends you an SMS when you change your account password or transfer money off your account to paypal, kinda like what most banks do now with regards to online transactions.
phoenixxx
post May 22 2012, 12:11 PM

Sesquipedalian hittin' the quasihemdemisemiquaver
******
Senior Member
1,241 posts

Joined: Mar 2005
i use the smartphone authenticator. seems that can be hacked too, but nevertheless added security
ChcGamer
post May 22 2012, 12:12 PM

Ngau
******
Senior Member
1,534 posts

Joined: May 2005


I'm using physical one smile.gif

Gotten a core hound pet for my WoW account as well
tarvalslain87
post May 22 2012, 12:38 PM

(•_•) / ( •_•)>⌐■-■ / (⌐■_■)
Group Icon
Staff
5,054 posts

Joined: Aug 2008


Im using the phone authenticator plus the SMS alert just for extra protection... I think Blizzard should be having a lot of complaints on this hacking issue...
LOOOOOOL
post May 22 2012, 01:44 PM

what is this
*****
Senior Member
704 posts

Joined: Oct 2007
From: Anywhere
how this authentication work ah actually???? each time i login to diablo 3 game i need to get the passcode?? or only needed when i login to www.battle.net?
xander
post May 22 2012, 02:05 PM

Finally
*****
Senior Member
836 posts

Joined: Jun 2005
QUOTE(tarvalslain87 @ May 22 2012, 12:38 PM)
Im using the phone authenticator plus the SMS alert just for extra protection... I think Blizzard should be having a lot of complaints on this hacking issue...
*
bro,

is there any charges from the telco side for SMS received?
athlonmax
post May 22 2012, 02:41 PM

On my way
****
Junior Member
558 posts

Joined: Jan 2003
From: Batu Caves/Gombak



QUOTE(LOOOOOOL @ May 22 2012, 01:44 PM)
how this authentication work ah actually???? each time i login to diablo 3 game i need to get the passcode?? or only needed when i login to www.battle.net?
*
for login diablo,it didnt ask u for the authenticator number,only when login to bnet account and wow.
oh im using physical authenticator after my wow got hacked couple years back.

This post has been edited by athlonmax: May 22 2012, 02:43 PM
C-Fu
post May 22 2012, 02:56 PM

Ninja-Fu
******
Senior Member
1,051 posts

Joined: Apr 2005
From: Brisbane, QLD, Ostolia



you can select in the settings if you want it to auth everytime you login (d3, b.net, wow, etc) or everyweek.

but just a note, the authenticator IS NOT fool-proof. it's been defeated before, and WILL be defeated again.

wanna know why those haxxors need a maximum of 2 mins to clear out your account, even with the auth?

it's because the way blizzard uses the auth. everytime it generates a code, you have a few seconds (20-30 secs?) until it generates a new one.

but even if the code has expired after 30 secs, you still can use it. i think there is a grace period of 60-120secs before the code truly expires on b.net's side.

so a hacker can get your code with the MITM method (or some other exploit), login, change your password, add you as a friend, clean up account, and bye bye. all in under 2 minutes.

but however it is, no authenticator can be stronger than good logic - update antivirus, don't reuse your password with email, stop running unneeded programs/apps while playing, etc. it may be a hassle to you, but remember you only need to be screwed once.

This post has been edited by C-Fu: May 22 2012, 02:57 PM
Deimos Tel`Arin
post May 22 2012, 03:03 PM

The LYN Kondom Man
*******
Senior Member
4,202 posts

Joined: Jan 2003
From: THE ONE AND ONLY CHOO CHOO TRAIN KINGDOM




QUOTE(C-Fu @ May 22 2012, 02:56 PM)
you can select in the settings if you want it to auth everytime you login (d3, b.net, wow, etc) or everyweek.

but just a note, the authenticator IS NOT fool-proof. it's been defeated before, and WILL be defeated again.

wanna know why those haxxors need a maximum of 2 mins to clear out your account, even with the auth?

it's because the way blizzard uses the auth. everytime it generates a code, you have a few seconds (20-30 secs?) until it generates a new one.

but even if the code has expired after 30 secs, you still can use it. i think there is a grace period of 60-120secs before the code truly expires on b.net's side.

so a hacker can get your code with the MITM method (or some other exploit), login, change your password, add you as a friend, clean up account, and bye bye. all in under 2 minutes.

but however it is, no authenticator can be stronger than good logic - update antivirus, don't reuse your password with email, stop running unneeded programs/apps while playing, etc. it may be a hassle to you, but remember you only need to be screwed once.
*
seems like clean habits without authenticator is better.
tarvalslain87
post May 22 2012, 03:28 PM

(•_•) / ( •_•)>⌐■-■ / (⌐■_■)
Group Icon
Staff
5,054 posts

Joined: Aug 2008


QUOTE(xander @ May 22 2012, 02:05 PM)
bro,

is there any charges from the telco side for SMS received?
*
Im not sure is there any charges or not. Will check next month's bill statement. If there are charges, shouldnt be much and Im expecting it to be free.
C-Fu
post May 22 2012, 03:41 PM

Ninja-Fu
******
Senior Member
1,051 posts

Joined: Apr 2005
From: Brisbane, QLD, Ostolia



QUOTE(Deimos Tel`Arin @ May 22 2012, 03:03 PM)
seems like clean habits without authenticator is better.
*
better yeah, but like i said, you only need to be screwed once. then you're on the other side of the "battle" already biggrin.gif

having more security is good, but nothing beats safe surfing. i personally would still recommend having beefed-up security that blizzard offers than none/little at all. reading up at blizzard forum on people's issues is making me (slightly) paranoid rclxub.gif not to mention having a friend who got screwed as well, but probably not through hacking, but some server-side issues.

lyn is an open forum, anybody can read comments, especially that "post your battletag" thread. you never know who reads them and posts there icon_idea.gif

This post has been edited by C-Fu: May 22 2012, 03:42 PM
Deimos Tel`Arin
post May 22 2012, 03:42 PM

The LYN Kondom Man
*******
Senior Member
4,202 posts

Joined: Jan 2003
From: THE ONE AND ONLY CHOO CHOO TRAIN KINGDOM




QUOTE(C-Fu @ May 22 2012, 03:41 PM)
better yeah, but like i said, you only need to be screwed once. then you're on the other side of the "battle" already biggrin.gif

having more security is good, but nothing beats safe surfing. i personally would still recommend having beefed-up security that blizzard offers than none/little at all. reading up at blizzard forum on people's issues is making me (slightly) paranoid  rclxub.gif  not to mention having a friend who got screwed as well, but probably not through hacking, but some server-side issues.
*
eh read this
QUOTE(nodeffect @ May 22 2012, 02:28 PM)
It's not really because of keylogger on your PC... It's their server. Even Blizzard's autehntication is not really helping.

Read more here: http://www.tomshardware.com/news/Exploit-h...-RPG,15713.html

and this : http://us.battle.net/d3/en/forum/topic/5235706038
*
it is problem on server.

blizzard's battle.net server not secure enough.
dafuq is this.
C-Fu
post May 22 2012, 03:47 PM

Ninja-Fu
******
Senior Member
1,051 posts

Joined: Apr 2005
From: Brisbane, QLD, Ostolia



yeah, i know about that issue. time and history have shown that blizzard/activision will keep their mouth shut whenever they have problems (in a good or bad way) until shit hits the fan smile.gif my best guess would be that they were trained by our Malaysian politicians sweat.gif


with the money pouring in, it's a surprise why they won't implement a machine auth feature like facebook where if you logged in using some unknown/new device, it'll send you an sms asking you to verify. it's a very simple and effective tool to prevent account takeovers in facebook/gmail/etc, and yet nobody there seems to care.

This post has been edited by C-Fu: May 22 2012, 03:50 PM
alex82
post May 22 2012, 03:52 PM

^_^
***
Junior Member
371 posts

Joined: Sep 2006
i use both mobile & blizz auth along with keyscrambler & zemana antikeylogger
FunnyGuyonly1
post May 22 2012, 04:10 PM

Getting Started
**
Junior Member
142 posts

Joined: Jan 2003
From: TanJung Rambutan


Here is some tips for you guys who may not know about the authenticator.

http://itunes.apple.com/us/app/battle.net-...d306862897?mt=8 <- for I Devices
https://play.google.com/store/apps/details?...zzard.bma&hl=en <- for Android

Purpose of using the apps/tools is to authenticate the genius account holder.

so far im using it to avoid attackers such as the exploit (happen before when i was playing my wow in one of the cc, acc was been hacked) after i have using the authenticator there was no issue.

Based on "C-Fu" mention about the hacker take advantage of the changing time of the running number to be changed yes this might happen that y the be implementing SMS alert.

i think they have doing some research to releasing the tools (not making for fun).

is just for additional security only biggrin.gif


but one importing that mention by "Deimos Tel`Arin" is good to have clean practice to perform login by changing the password frequently to avoid been hacked.

enjoy the game and have a secure log in biggrin.gif


Cheers
phoenixxx
post May 22 2012, 04:12 PM

Sesquipedalian hittin' the quasihemdemisemiquaver
******
Senior Member
1,241 posts

Joined: Mar 2005
hey , check out the sms thing also.

http://us.battle.net/support/en/article/ba...net-sms-protect
takkicom
post May 22 2012, 04:28 PM

Casual
***
Junior Member
422 posts

Joined: Sep 2008
if hack then i dont play lor if they no retrieve
Liuteva
post May 22 2012, 06:11 PM

Empty.
*******
Senior Member
2,991 posts

Joined: Jun 2007
From: Johor


I started to use phone one since a year ago play WoW, good to improve account security. smile.gif

 

Change to:
| Lo-Fi Version
0.0464sec    0.20    6 queries    GZIP Disabled
Time is now: 30th November 2025 - 06:01 PM