Welcome Guest ( Log In | Register )

Outline · [ Standard ] · Linear+

 URGENT NEWS TO ALL BNET ACC USERS, our accs are compromised

views
     
deathTh3Cannon
post Aug 10 2012, 09:58 AM

Getting Started
**
Junior Member
248 posts

Joined: Aug 2011
Username : uguysstillplayingdiablo3
Password : ialreadyuninstallandvendorallmyequips
TSThe Amateur Working Bee
post Aug 10 2012, 09:58 AM

Regular
******
Senior Member
1,646 posts

Joined: Aug 2010
QUOTE(Gen @ Aug 10 2012, 09:54 AM)
Hi folks, in the Bnet account management, where to click and change the security question ?
*
you need to send a support ticket to bnet admins to reset it for you, but they say they gonna prompt a security question change "soon", no specific time given

for your reference: http://www.ehow.com/how_8508652_reset-bliz...t-question.html


Added on August 10, 2012, 9:59 am
QUOTE(deathTh3Cannon @ Aug 10 2012, 09:58 AM)
Username : uguysstillplayingdiablo3
Password : ialreadyuninstallandvendorallmyequips
*
email:stillhavemydemonhuntertagonmysiggy

This post has been edited by The Amateur Working Bee: Aug 10 2012, 09:59 AM
metalfreak
post Aug 10 2012, 10:11 AM

Working out is not my routine, it's my new lifestyle
*******
Senior Member
3,300 posts

Joined: Jan 2003
Just changed my password and all =.=" meh...may be blizzard was being hacked or some shit...thats why the lag LOL


Balaclava
post Aug 10 2012, 10:30 AM

5-Star Swagger
*****
Senior Member
941 posts

Joined: Jul 2010
Actually, the letter contents were toned down from the following,

Dear users,

We had a breach in our systems and it wasn't prevented as soon as we could as our staffs were busy setting up the new rates for RMAH and explaining to the Board of Directors how money kept flowing in automatically. Sad but true, your accounts are compromised and while we kept ourselves busy counting figures that kept flowing in, it's up to you to safeguard your account.

kkthanksbye,
Mike
Kissan
post Aug 10 2012, 10:30 AM

Getting Started
**
Junior Member
137 posts

Joined: Apr 2012
From: Forensic Department
D3 so fvcked up... Already knew something shit is coming when those 2 cases of hacking happened to lyn members.

jay wilson meme : hacking then we DOUBLE IT.
neoengsheng
post Aug 10 2012, 11:05 AM

Getting Started
**
Junior Member
261 posts

Joined: Jul 2009
Quoting Bashiok
QUOTE
We've been taking the situation extremely seriously from the start, and have done everything possible to verify how and in what circumstances these compromises are occurring. Despite the claims and theories being made, we have yet to find any situations in which a person's account was not compromised through traditional means of someone else logging into their account through the use of their password. While the authenticator isn't a 100% guarantee of account security, we have yet to investigate a compromise report in which an authenticator was attached beforehand.

If your account has been hacked, please view the previous post for information on contacting our support department.
and Lylirra

QUOTE
We'd like to take a moment to address the recent reports that suggested that Battle.net® and Diablo® III may have been compromised. Historically, the release of a new game -- such as a World of Warcraft® expansion -- will result in an increase in reports of individual account compromises, and that's exactly what we're seeing now with Diablo III. We know how frustrating it can be to become the victim of account theft, and as always, we're dedicated to doing everything we can to help our players keep their Battle.net accounts safe -- and we appreciate everyone who's doing their part to help protect their accounts as well. You can read about ways to help keep your account secure, along with some of the internal and external measures we have in place to help us achieve our security goals, at our account security website here: http://www.battle.net/security" class="bml-link-url2">www.battle.net/security</a>.

We also wanted to reassure you that the Battle.net Authenticator and Battle.net Mobile Authenticator (a free app for iPhone and Android devices) continue to be some of the most effective measures we offer to help players protect themselves against account compromises, and we encourage everyone to take advantage of them. In addition, we also recently introduced a new service called Battle.net SMS Protect, which allows you to use your text-enabled cell phone to unlock a locked Battle.net account, recover your account name, approve a password reset, or remove a lost Authenticator. Optionally, you can set up the Battle.net SMS Protect system to send you a text message whenever unusual activity is detected on your account, keeping you aware of important (and possibly unwanted) changes.

For more information on the Authenticator, visit http://us.battle.net/support/en/article/ba...thenticator-faq

For more on the Battle.net Mobile Authenticator, visit http://us.battle.net/support/en/article/ba...thenticator-faq

For more on Battle.net SMS Protect, visit http://us.battle.net/support/en/article/ba...net-sms-protect

We also have other measures built into Battle.net to help protect players. Occasionally, when Battle.net detects unusual login activity that differs from your normal behavior -- such as logging in from an unfamiliar location -- we may prompt you for additional information (such as the answer to one of your security questions) and/or require you to perform a password reset through the Battle.net website. World of Warcraft players might be familiar with this security method already, and Diablo III players may begin to encounter it as well.

As always, if you think you've been the victim of an account compromise, head to the "Help! I've Been Hacked!" tool at <a href="http://us.battle.net/en/security/help for assistance.
Summary of the data that was illegally accessed:

With regard to Mobile Authenticators, information was taken that could potentially compromise the integrity of North American Mobile Authenticators."
"Email addresses
Answers to secret security questions
Cryptographically scrambled versions of passwords (not actual passwords)
Information associated with the Mobile Authenticator
Information associated with the Dial-in Authenticator

Inb4 Blizz no use authenticator.
cowithgun
post Aug 10 2012, 11:57 AM

A cow that can play notebook & phone
*******
Senior Member
2,248 posts

Joined: Sep 2010
Changed password. This is kind of serious. To be able to accessed all these info, the attackers are probably in the system for weeks...

Will wait for further instructions on how to change security question and update Mobile Authenticator.
gaeria84
post Aug 10 2012, 11:58 AM

Enthusiast
*****
Senior Member
837 posts

Joined: Mar 2005
Blizzard, I am disappoint sad.gif

Anyways, if you use the same password for your facebook, forums, banking, you might want to change that also.
squall0833
post Aug 10 2012, 12:11 PM

Regular
******
Senior Member
1,473 posts

Joined: Oct 2006
From: Jupiter


hmm,

if u got link paypal acc to bnet acc, they can get access to ur paypal meh?
they still need a password for ur paypal before doing any changes or transaction in ur b.net acc, the only thing they know about ur paypal is ur paypal email address

if u got cc added in bnet acc, then you really GG la

This post has been edited by squall0833: Aug 10 2012, 12:11 PM
gaeria84
post Aug 10 2012, 12:22 PM

Enthusiast
*****
Senior Member
837 posts

Joined: Mar 2005
Just had a thought.

user posted image
TSThe Amateur Working Bee
post Aug 10 2012, 12:23 PM

Regular
******
Senior Member
1,646 posts

Joined: Aug 2010
AHAHAHHAHAHA oh god lol
cowithgun
post Aug 10 2012, 12:26 PM

A cow that can play notebook & phone
*******
Senior Member
2,248 posts

Joined: Sep 2010
QUOTE(gaeria84 @ Aug 10 2012, 12:22 PM)
Just had a thought.
*
+1

LOL that is Mikey Morhamad

This post has been edited by cowithgun: Aug 10 2012, 12:27 PM
OnGx2
post Aug 10 2012, 12:33 PM

Getting Started
**
Junior Member
213 posts

Joined: May 2009
worst case, deebee joined diablo and raged and hacked all the CM and admin account to troll the players
SUSedge85
post Aug 10 2012, 01:18 PM

hepi hepi goyang bersama
******
Senior Member
1,299 posts

Joined: Jun 2008


more worried of my other acccounts. banking email etc... sigh...
polarzbearz
post Aug 10 2012, 02:32 PM

Gracie
*******
Senior Member
4,816 posts

Joined: Apr 2007


Thanks for sharing, changed mine after reading this rclxub.gif
olman
post Aug 10 2012, 03:56 PM

Regular
******
Senior Member
1,998 posts

Joined: Jan 2003


LOL so much for insisting always online is the best !!!

i told yall so, i told ya

This post has been edited by olman: Aug 10 2012, 04:08 PM
metalfreak
post Aug 10 2012, 04:13 PM

Working out is not my routine, it's my new lifestyle
*******
Senior Member
3,300 posts

Joined: Jan 2003
yeap. having to play online. f***ed up. =.="
Quazacolt
post Aug 10 2012, 05:32 PM

Riding couple
*******
Senior Member
5,366 posts

Joined: Jan 2007
From: KL Malaysia


QUOTE(olman @ Aug 10 2012, 03:56 PM)
i told yall so, i told ya
*
heh.
farkinid
post Aug 10 2012, 05:33 PM

Enthusiast
*****
Senior Member
997 posts

Joined: Feb 2007


So I've had some time to sit down and think about this. This hacking is very bad. At this point, the attackers have got your
  • email address
  • secret question and answer
  • salted passwords[
I would like to state that even though the passwords are salted, its still crackable. Any basic maths geek will be able to tell you that with a large enough database, the constants can be deduced easily. This leaves your real password.

I have read an article about this and I think the author is on the right track when he says SRP may not be strong enough. Link to article. Read if you are interested in the theory of it.

But note that the author is an interested party when bashing Blizz AND like he said, its impossible to avoid break-ins. Although as long as there was a battlenet server to store and maintain user's characters, this would have happened. It doesn't matter if there was an offline aspect to D3.
TSThe Amateur Working Bee
post Aug 10 2012, 05:40 PM

Regular
******
Senior Member
1,646 posts

Joined: Aug 2010
QUOTE(farkinid @ Aug 10 2012, 05:33 PM)
So I've had some time to sit down and think about this. This hacking is very bad. At this point, the attackers have got your

  • email address
  • secret question and answer
  • salted passwords[
I would like to state that even though the passwords are salted, its still crackable. Any basic maths geek will be able to tell you that with a large enough database, the constants can be deduced easily. This leaves your real password.

I have read an article about this and I think the author is on the right track when he says SRP may not be strong enough. Link to article. Read if you are interested in the theory of it.

But note that the author is an interested party when bashing Blizz AND like he said, its impossible to avoid break-ins. Although as long as there was a battlenet server to store and maintain user's characters, this would have happened. It doesn't matter if there was an offline aspect to D3.
*
that 3 keys are actually all they need to access our acc, they can butter up whatever facts they want, secret answer alone can bypass half of the "security" they have for accs lol, and like u said, encrypted passwords are nothing these days

3 Pages < 1 2 3 >Top
 

Change to:
| Lo-Fi Version
0.0176sec    0.26    5 queries    GZIP Disabled
Time is now: 2nd December 2025 - 02:44 AM