• Log InLog In
  • Register
Liquid`
Team Liquid Liquipedia
EST 00:58
CET 06:58
KST 14:58
  • Home
  • Forum
  • Calendar
  • Streams
  • Liquipedia
  • Features
  • Store
  • EPT
  • TL+
  • StarCraft 2
  • Brood War
  • Smash
  • Heroes
  • Counter-Strike
  • Overwatch
  • Liquibet
  • Fantasy StarCraft
  • TLPD
  • StarCraft 2
  • Brood War
  • Blogs
Forum Sidebar
Events/Features
News
Featured News
TL.net Map Contest #21: Winners4Intel X Team Liquid Seoul event: Showmatches and Meet the Pros10[ASL20] Finals Preview: Arrival13TL.net Map Contest #21: Voting12[ASL20] Ro4 Preview: Descent11
Community News
Starcraft, SC2, HoTS, WC3, returning to Blizzcon!25$5,000+ WardiTV 2025 Championship5[BSL21] RO32 Group Stage4Weekly Cups (Oct 26-Nov 2): Liquid, Clem, Solar win; LAN in Philly2Weekly Cups (Oct 20-26): MaxPax, Clem, Creator win9
StarCraft 2
General
Starcraft, SC2, HoTS, WC3, returning to Blizzcon! TL.net Map Contest #21: Winners RotterdaM "Serral is the GOAT, and it's not close" Weekly Cups (Oct 20-26): MaxPax, Clem, Creator win 5.0.15 Patch Balance Hotfix (2025-10-8)
Tourneys
Constellation Cup - Main Event - Stellar Fest $5,000+ WardiTV 2025 Championship Merivale 8 Open - LAN - Stellar Fest Sea Duckling Open (Global, Bronze-Diamond) $3,500 WardiTV Korean Royale S4
Strategy
Custom Maps
Map Editor closed ?
External Content
Mutation # 498 Wheel of Misfortune|Cradle of Death Mutation # 497 Battle Haredened Mutation # 496 Endless Infection Mutation # 495 Rest In Peace
Brood War
General
[BSL21] RO32 Group Stage BGH Auto Balance -> http://bghmmr.eu/ SnOw's ASL S20 Finals Review Practice Partners (Official) [ASL20] Ask the mapmakers — Drop your questions
Tourneys
[Megathread] Daily Proleagues [BSL21] RO32 Group B - Sunday 21:00 CET [BSL21] RO32 Group A - Saturday 21:00 CET BSL21 Open Qualifiers Week & CONFIRM PARTICIPATION
Strategy
Current Meta PvZ map balance How to stay on top of macro? Soma's 9 hatch build from ASL Game 2
Other Games
General Games
Stormgate/Frost Giant Megathread Dawn of War IV Nintendo Switch Thread ZeroSpace Megathread General RTS Discussion Thread
Dota 2
Official 'what is Dota anymore' discussion
League of Legends
Heroes of the Storm
Simple Questions, Simple Answers Heroes of the Storm 2.0
Hearthstone
Deck construction bug Heroes of StarCraft mini-set
TL Mafia
TL Mafia Community Thread SPIRED by.ASL Mafia {211640}
Community
General
US Politics Mega-thread Things Aren’t Peaceful in Palestine Russo-Ukrainian War Thread YouTube Thread Dating: How's your luck?
Fan Clubs
White-Ra Fan Club The herO Fan Club!
Media & Entertainment
Anime Discussion Thread Movie Discussion! [Manga] One Piece Korean Music Discussion Series you have seen recently...
Sports
2024 - 2026 Football Thread NBA General Discussion MLB/Baseball 2023 TeamLiquid Health and Fitness Initiative For 2023 Formula 1 Discussion
World Cup 2022
Tech Support
SC2 Client Relocalization [Change SC2 Language] Linksys AE2500 USB WIFI keeps disconnecting Computer Build, Upgrade & Buying Resource Thread
TL Community
The Automated Ban List Recent Gifted Posts
Blogs
Saturation point
Uldridge
DnB/metal remix FFO Mick Go…
ImbaTosS
Why we need SC3
Hildegard
Career Paths and Skills for …
TrAiDoS
Reality "theory" prov…
perfectspheres
Our Last Hope in th…
KrillinFromwales
Customize Sidebar...

Website Feedback

Closed Threads



Active: 1538 users

Blizzard Security Breach - Page 11

Forum Index > SC2 General
442 CommentsPost a Reply
Prev 1 9 10 11 12 13 23 Next All
YungLee
Profile Joined February 2011
29 Posts
August 10 2012 02:55 GMT
#201
the automated process
EvanED
Profile Joined October 2009
United States111 Posts
Last Edited: 2012-08-10 03:08:47
August 10 2012 03:03 GMT
#202
On August 10 2012 10:30 Wuster wrote:
1 business week isn't all that long. What they said is pretty reasonable at face value.

After all, the PSN mess was exacerbated by them claiming that no personal data was lost, then no financial data was lost, then 'actually they got everything'. That's not just bad PR, it also prevents customers from actually doing anything about the security breach in a timely manner

So does not saying anything for a week...

On August 10 2012 10:58 Sir.Kimmel wrote:
This takes into account a basic desktop server..... which can do roughly I think 25k passwords a second with standard bruteforcing it really depends... while our system at work using 4 gpus (mmm cuda) can do 1.7 billion a second... there are custom password cracking machines such as Reliks which does 25 billion a second http://www.hackingtheuniverse.com/infosec/tools/gpu-password-cracking

Their time numbers are based off of 4 billion passwords/sec.

On August 10 2012 11:30 Sinensis wrote:
People should learn to use passphrases. Contrary to popular belief having numbers and symbols in your password does not make it more difficult to crack. Adding length to your password is the only way to make it more secure.

That's not true! It's barely even partly true.

Common substitutions like "1" for "l" and "0" for "o" don't add nearly as much security as you might think, nor do non-alphanumeric characters stuck at the beginning or end of you passwords. However, "not adding as much as you think" is still adding some, and better application of symbols can add quite a bit of extra strength without adding length.

(Now, that said... I have pass "phrases" (somewhere between a phrase and an XKCD-style "correct horse battery staple" collection of unrelated words) that I use for a couple of my higher-value accounts. (That is, those that I don't use "hunter2" on. :-)) So I'm not dissing the idea -- in fact, I'd recommend it. Though I'd go for a much less common phrase than any of your examples.)
Deleted User 135096
Profile Blog Joined December 2010
3624 Posts
August 10 2012 03:19 GMT
#203
On August 10 2012 07:42 mataxp wrote:
As a PSN user, dejá vu

save for the whole unencrypted text file full of sensitive information...or am I not remembering that right?
Administrator
Azera
Profile Blog Joined December 2010
3800 Posts
August 10 2012 03:21 GMT
#204
Goddamit, I really don't want to change passwords just to stay safe...
Check out some great music made by TLers - http://bit.ly/QXYhdb , by intrigue. http://bit.ly/RTjpOR , by ohsea.toc.
TheEmulator
Profile Blog Joined July 2010
28092 Posts
August 10 2012 03:23 GMT
#205
This is so annoying. I have to spend 3 minutes changing my password.
Administrator
Ballistixz
Profile Joined January 2010
United States1269 Posts
August 10 2012 03:28 GMT
#206
this was bound to happen sooner or later. the sheer ammount of ignorance and arrogance blizzard was posing with there security has finnally backfired on them. the thousands of hacks D3 got during the first few weeks/months of D3s released was brushed aside by blizzard saying "lol get an authenticator." at times they act like they couldnt be breached just because of the fact that "we have never been breached before in all of blizzards history".

maybe now blizz will finnally step up there damn security instead of telling everyone and there mom to "get a authenticator and u will be 99.99% safe derp".
julianto
Profile Joined December 2010
2292 Posts
Last Edited: 2012-08-10 03:31:55
August 10 2012 03:28 GMT
#207
On August 10 2012 12:23 TheEmulator wrote:
This is so annoying. I have to spend 3 minutes changing my password.

I spent 30 minutes changing passwords and security questions connected in any way to my blizzard account. Now all I need to do is change my security questions for battlenet itself. Too bad there wasn't an option to change the security questions in the first place.

edit: I'd really like Blizzard's password character limit to be much, much higher.

On August 10 2012 11:13 Nosferatos wrote:
I've been e-mailed by an "fake" blizzard e-mail account since the 25th of last month, with new mails every 3rd day since. Asking me to give up personal/account info, because im trying to "Sell my Diablo 3 Account". I venture to guess that the breach must have happend around the 25th of July, if so the detection time was pretty slow....

If I was in your situation, I'd troll them back. Give them some derogatory message in the form of a password.
¯\_(ツ)_/¯
Zato-1
Profile Blog Joined March 2009
Chile4253 Posts
August 10 2012 03:32 GMT
#208
On August 10 2012 07:38 Probe1 wrote:
So change your passwords. Got it.

(Before anyone says "Oh no Probe u sux at reading", cryptographically scrambled versions.. do you trust your account and information on that? Do you?")

Salted hashes of passwords are still easy to crack if the password itself is common (read: if it can be found on a password dictionary that hackers use to brute force passwords), and Battle.net passwords are capped at 16 characters for some stupid reason, so I'd wager that a large percentage of these "cryptographically scrambled" versions of passwords can and will be cracked.

So as Probe said... change your passwords, yeah.
Go here http://vina.biobiochile.cl/ and input the Konami Code (up up down down left right left right B A)
Dodgin
Profile Blog Joined July 2011
Canada39254 Posts
August 10 2012 03:33 GMT
#209
On August 10 2012 12:28 Ballistixz wrote:
this was bound to happen sooner or later. the sheer ammount of ignorance and arrogance blizzard was posing with there security has finnally backfired on them. the thousands of hacks D3 got during the first few weeks/months of D3s released was brushed aside by blizzard saying "lol get an authenticator." at times they act like they couldnt be breached just because of the fact that "we have never been breached before in all of blizzards history".

maybe now blizz will finnally step up there damn security instead of telling everyone and there mom to "get a authenticator and u will be 99.99% safe derp".


Well, if you have an authenticator you would be safe even if they did get your password.
zhurai
Profile Blog Joined September 2010
United States5660 Posts
August 10 2012 03:39 GMT
#210
On August 10 2012 10:16 Integra wrote:
Show nested quote +
On August 10 2012 09:11 Corrosive wrote:
Stuff like this happens often to companies like this. As long as blizzard didn't store everything in plaintext like Sony did, everything should be fine.

If you want to see how long it would take your password to be cracked check this out
http://howsecureismypassword.net/

according to this website it will take them 40 undecillion years or in numbers:40,464,702,078,891,060,000,000,000,000,000,000,000 years to crack my password... goodluck with that.

maybe if they try cracking it on one computer with a single core
Twitter: @zhurai | Site: http://zhurai.com
bakedace
Profile Blog Joined March 2010
United States672 Posts
August 10 2012 03:40 GMT
#211
On August 10 2012 12:28 Ballistixz wrote:
this was bound to happen sooner or later. the sheer ammount of ignorance and arrogance blizzard was posing with there security has finnally backfired on them. the thousands of hacks D3 got during the first few weeks/months of D3s released was brushed aside by blizzard saying "lol get an authenticator." at times they act like they couldnt be breached just because of the fact that "we have never been breached before in all of blizzards history".

maybe now blizz will finnally step up there damn security instead of telling everyone and there mom to "get a authenticator and u will be 99.99% safe derp".


Nothing is ever completely secure. Anything can be hacked. Using an authenticator is just common sense for anything you want to protect on the internet.
Aberu
Profile Blog Joined April 2010
United States968 Posts
Last Edited: 2012-08-10 03:49:25
August 10 2012 03:48 GMT
#212
On August 10 2012 07:42 mataxp wrote:
As a PSN user, dejá vu


Well not quite, Blizzard wasn't storing their passwords unencrypted.

I'm not panicking my password would take over 63 million years to crack apparently.
srsly
babysimba
Profile Joined November 2010
10466 Posts
August 10 2012 03:49 GMT
#213
It's not a big deal getting hacked if your bnet acct only has sc2, or you didn't invest too much into WoW/D3. There's nothing valuable in a sc2 acct. Just don't have your bnet password link to your more personal accounts, and you can easily recover it back.

All in all, I learn quite a few things about passwords in this thread though :D
Integra
Profile Blog Joined January 2008
Sweden5626 Posts
Last Edited: 2012-08-10 03:56:20
August 10 2012 03:54 GMT
#214
On August 10 2012 10:34 ggrrg wrote:
Show nested quote +
On August 10 2012 10:16 Integra wrote:
On August 10 2012 09:11 Corrosive wrote:
Stuff like this happens often to companies like this. As long as blizzard didn't store everything in plaintext like Sony did, everything should be fine.

If you want to see how long it would take your password to be cracked check this out
http://howsecureismypassword.net/

according to this website it will take them 40 undecillion years or in numbers:40,464,702,078,891,060,000,000,000,000,000,000,000 years to crack my password... goodluck with that.


I feel like you're somewhat overdoing it ^^ Do you really feel like typing 29 characters just to enter bnet?
According to that website my bnet password is crackable in 19 seconds... I use this password for most stuff I don't care about. But my "secure" password feels somewhat weak, too. 345k years for a regular desktop... I guess it's time to add a number and a special character.

I'm a IT specialist, so its a habit from work. My normal passwords (yes I have a different password for each website and program I use) usually are around 50 letters. All websites can't take those kinds of passwords though. And the time constraints is no problem for me since I'm a seasoned programmer, I type fairly fast, hell it happens that I even use programming code, like parts of functions as my passwords Think I used some newly developed php code I made for the simpleMachine forum as my password for my twitter account, lol
"Dark Pleasure" | | I survived the Locust war of May 3, 2014
Jedclark
Profile Blog Joined February 2011
United Kingdom903 Posts
August 10 2012 03:56 GMT
#215
It's a good day to live in Europe. Wonder who the hackers were, and what their purpose was once they got the information.
"They make it so scrubnubs can PM me. They make it so I can't ignore scrubnubs!" - "I'm gonna show you how great I am." MKP fan since GSL Open Season 2 #hipsternerd
Zato-1
Profile Blog Joined March 2009
Chile4253 Posts
August 10 2012 04:07 GMT
#216
On August 10 2012 12:39 zhurai wrote:
Show nested quote +
On August 10 2012 10:16 Integra wrote:
On August 10 2012 09:11 Corrosive wrote:
Stuff like this happens often to companies like this. As long as blizzard didn't store everything in plaintext like Sony did, everything should be fine.

If you want to see how long it would take your password to be cracked check this out
http://howsecureismypassword.net/

according to this website it will take them 40 undecillion years or in numbers:40,464,702,078,891,060,000,000,000,000,000,000,000 years to crack my password... goodluck with that.

maybe if they try cracking it on one computer with a single core

Actually, if you're serious about cracking a large number of passwords then you don't care so much about your processor, you'll get a high-end graphics card to do the brunt of the work because they have orders of magnitude more computing power for this purpose. Also, in its estimate, that site makes the rather huge (and probably incorrect) assumption that the programs hackers use will be sequentially trying completely random sequences of characters, when there are substantially more efficient ways to crack more than enough bad passwords to make it worth your while.
Go here http://vina.biobiochile.cl/ and input the Konami Code (up up down down left right left right B A)
EvanED
Profile Joined October 2009
United States111 Posts
August 10 2012 04:07 GMT
#217
The good part of this is it finally kicked me to go fix my password situation a bit. I was using the same password on Battle.Net as a few other, moderate-importance sites, including my Google account. So I went through and fixed those and now they have different and stronger passwords.

And that password strength site says that my new Google password will take 97,807,199,722,288,020,000,000,000,000,000,000,000,000,000 (97 tredecillion) years to crack :-).

On the downside, I also figured I'd bump up the length on the password for my bank, and... it has a max length of 10 characters. That just boggles my mind, especially because otherwise they're really quite good and have a pretty sophisticated and nice web banking setup.
Pucca
Profile Blog Joined January 2012
Taiwan1280 Posts
August 10 2012 04:10 GMT
#218
I really hope they did not get access to my cards on my account I hate when I read these things it always make me anxious!
Master Chief
MVega
Profile Joined November 2010
763 Posts
August 10 2012 04:11 GMT
#219
To the people speculating whether the phishing emails are related to the breach, or wondering if when you first received such an email was the start of the "breach": No. If that were the case the breach occured back in 2005. That's when WoW players started getting spammed with those emails. So no. That's just pretty standard phishing stuff that's not related. They seem to send those out at random. I know people that get those and don't even have WoW or Diablo accounts or even Battle.net accounts.
bumkin: How can you play like 50 games per day... I 4gate 2 times then it's nap time
sudosu
Profile Joined October 2011
France120 Posts
Last Edited: 2012-08-10 14:23:46
August 10 2012 04:12 GMT
#220
"cryptographically scrambled versions"
"each password would have to be deciphered individually"

And why the hell are the passwords ciphered and not hashed ? There is absolutely no reason to store ciphered passwords because there is even less reason to decipher a password.

Anyway Blizzard seems to have reacted in a good and quick way, that's nice.
Prev 1 9 10 11 12 13 23 Next All
Please log in or register to reply.
Live Events Refresh
Next event in 6h 2m
[ Submit Event ]
Live Streams
Refresh
StarCraft 2
Nina 174
ProTech125
StarCraft: Brood War
Calm 10709
Zeus 1054
Leta 275
Tasteless 239
EffOrt 188
Bale 21
Icarus 8
League of Legends
JimRising 645
Counter-Strike
taco 31
Other Games
tarik_tv12746
summit1g11670
WinterStarcraft445
C9.Mang0276
NeuroSwarm96
ViBE96
goatrope33
Organizations
Other Games
gamesdonequick912
Counter-Strike
PGL130
StarCraft: Brood War
UltimateBattle 40
StarCraft 2
Blizzard YouTube
StarCraft: Brood War
BSLTrovo
sctven
[ Show 13 non-featured ]
StarCraft 2
• AfreecaTV YouTube
• intothetv
• Kozan
• IndyKCrew
• LaughNgamezSOOP
• Migwel
• sooper7s
StarCraft: Brood War
• BSLYoutube
• STPLYoutube
• ZZZeroYoutube
League of Legends
• Scarra1123
• Stunt498
• Jankos280
Upcoming Events
OSC
6h 2m
LAN Event
9h 2m
Korean StarCraft League
21h 2m
CranKy Ducklings
1d 4h
LAN Event
1d 9h
IPSL
1d 12h
dxtr13 vs OldBoy
Napoleon vs Doodle
BSL 21
1d 14h
Gosudark vs Kyrie
Gypsy vs Sterling
UltrA vs Radley
Dandy vs Ptak
Replay Cast
1d 17h
Sparkling Tuna Cup
2 days
WardiTV Korean Royale
2 days
[ Show More ]
LAN Event
2 days
IPSL
2 days
JDConan vs WIZARD
WolFix vs Cross
BSL 21
2 days
spx vs rasowy
HBO vs KameZerg
Cross vs Razz
dxtr13 vs ZZZero
Replay Cast
3 days
Wardi Open
3 days
WardiTV Korean Royale
4 days
Replay Cast
5 days
Kung Fu Cup
5 days
Classic vs Solar
herO vs Cure
Reynor vs GuMiho
ByuN vs ShoWTimE
Tenacious Turtle Tussle
5 days
The PondCast
6 days
RSL Revival
6 days
Solar vs Zoun
MaxPax vs Bunny
Kung Fu Cup
6 days
WardiTV Korean Royale
6 days
Liquipedia Results

Completed

BSL 21 Points
SC4ALL: StarCraft II
Eternal Conflict S1

Ongoing

C-Race Season 1
IPSL Winter 2025-26
KCM Race Survival 2025 Season 4
SOOP Univ League 2025
YSL S2
Stellar Fest: Constellation Cup
IEM Chengdu 2025
PGL Masters Bucharest 2025
Thunderpick World Champ.
CS Asia Championships 2025
ESL Pro League S22
StarSeries Fall 2025
FISSURE Playground #2
BLAST Open Fall 2025
BLAST Open Fall Qual

Upcoming

BSL Season 21
SLON Tour Season 2
BSL 21 Non-Korean Championship
Acropolis #4
IPSL Spring 2026
HSC XXVIII
RSL Offline Finals
WardiTV 2025
RSL Revival: Season 3
META Madness #9
BLAST Bounty Winter 2026: Closed Qualifier
eXTREMESLAND 2025
ESL Impact League Season 8
SL Budapest Major 2025
BLAST Rivals Fall 2025
TLPD

1. ByuN
2. TY
3. Dark
4. Solar
5. Stats
6. Nerchio
7. sOs
8. soO
9. INnoVation
10. Elazer
1. Rain
2. Flash
3. EffOrt
4. Last
5. Bisu
6. Soulkey
7. Mini
8. Sharp
Sidebar Settings...

Advertising | Privacy Policy | Terms Of Use | Contact Us

Original banner artwork: Jim Warren
The contents of this webpage are copyright © 2025 TLnet. All Rights Reserved.