• Log InLog In
  • Register
Liquid`
Team Liquid Liquipedia
EST 11:22
CET 17:22
KST 01:22
  • Home
  • Forum
  • Calendar
  • Streams
  • Liquipedia
  • Features
  • Store
  • EPT
  • TL+
  • StarCraft 2
  • Brood War
  • Smash
  • Heroes
  • Counter-Strike
  • Overwatch
  • Liquibet
  • Fantasy StarCraft
  • TLPD
  • StarCraft 2
  • Brood War
  • Blogs
Forum Sidebar
Events/Features
News
Featured News
TL.net Map Contest #21: Winners8Intel X Team Liquid Seoul event: Showmatches and Meet the Pros10[ASL20] Finals Preview: Arrival13TL.net Map Contest #21: Voting12[ASL20] Ro4 Preview: Descent11
Community News
Starcraft, SC2, HoTS, WC3, returning to Blizzcon!33$5,000+ WardiTV 2025 Championship6[BSL21] RO32 Group Stage4Weekly Cups (Oct 26-Nov 2): Liquid, Clem, Solar win; LAN in Philly2Weekly Cups (Oct 20-26): MaxPax, Clem, Creator win9
StarCraft 2
General
RotterdaM "Serral is the GOAT, and it's not close" TL.net Map Contest #21: Winners Starcraft, SC2, HoTS, WC3, returning to Blizzcon! 5.0.15 Patch Balance Hotfix (2025-10-8) Weekly Cups (Oct 20-26): MaxPax, Clem, Creator win
Tourneys
$5,000+ WardiTV 2025 Championship Sparkling Tuna Cup - Weekly Open Tournament Constellation Cup - Main Event - Stellar Fest Merivale 8 Open - LAN - Stellar Fest Sea Duckling Open (Global, Bronze-Diamond)
Strategy
Custom Maps
Map Editor closed ?
External Content
Mutation # 498 Wheel of Misfortune|Cradle of Death Mutation # 497 Battle Haredened Mutation # 496 Endless Infection Mutation # 495 Rest In Peace
Brood War
General
BW General Discussion [ASL20] Ask the mapmakers — Drop your questions [BSL21] RO32 Group Stage BGH Auto Balance -> http://bghmmr.eu/ SnOw's ASL S20 Finals Review
Tourneys
[Megathread] Daily Proleagues [ASL20] Grand Finals [BSL21] RO32 Group B - Sunday 21:00 CET [BSL21] RO32 Group A - Saturday 21:00 CET
Strategy
Current Meta PvZ map balance How to stay on top of macro? Soma's 9 hatch build from ASL Game 2
Other Games
General Games
Path of Exile Stormgate/Frost Giant Megathread Dawn of War IV Nintendo Switch Thread ZeroSpace Megathread
Dota 2
Official 'what is Dota anymore' discussion
League of Legends
Heroes of the Storm
Simple Questions, Simple Answers Heroes of the Storm 2.0
Hearthstone
Deck construction bug Heroes of StarCraft mini-set
TL Mafia
TL Mafia Community Thread SPIRED by.ASL Mafia {211640}
Community
General
US Politics Mega-thread Russo-Ukrainian War Thread Things Aren’t Peaceful in Palestine YouTube Thread Dating: How's your luck?
Fan Clubs
White-Ra Fan Club The herO Fan Club!
Media & Entertainment
Anime Discussion Thread Movie Discussion! [Manga] One Piece Korean Music Discussion Series you have seen recently...
Sports
2024 - 2026 Football Thread NBA General Discussion MLB/Baseball 2023 TeamLiquid Health and Fitness Initiative For 2023 Formula 1 Discussion
World Cup 2022
Tech Support
SC2 Client Relocalization [Change SC2 Language] Linksys AE2500 USB WIFI keeps disconnecting Computer Build, Upgrade & Buying Resource Thread
TL Community
The Automated Ban List Recent Gifted Posts
Blogs
Coffee x Performance in Espo…
TrAiDoS
Saturation point
Uldridge
DnB/metal remix FFO Mick Go…
ImbaTosS
Why we need SC3
Hildegard
Reality "theory" prov…
perfectspheres
Our Last Hope in th…
KrillinFromwales
Customize Sidebar...

Website Feedback

Closed Threads



Active: 1820 users

Blizzard Security Breach - Page 14

Forum Index > SC2 General
442 CommentsPost a Reply
Prev 1 12 13 14 15 16 23 Next All
Trasko
Profile Blog Joined July 2010
Sweden983 Posts
August 10 2012 07:48 GMT
#261
On August 10 2012 07:42 mataxp wrote:
As a PSN user, dejá vu



loooool. Same here.... /fml
Jaedong <3
Deleted User 101379
Profile Blog Joined August 2010
4849 Posts
August 10 2012 07:48 GMT
#262
Every month another company loses customer data, when will this trend stop?

I use unique email adresses for everything i register to and it's funny to see new spam popping up all the time. The worst offenders are my sc2replayed@, buffed@ and startrekonline@ adresses, it got so annoying that i started blocking those completely since i stopped using those month before i started getting spam. I guess my blizzard[1-3]@ adresses will be next for the spam flood. I hope i'll never see the day where i have to block teamliquid@... but well, this site is protected by a wizard so it's unlikely to happen.

Well, at least on the other hand it shows me that some other companies are as bad as the one i work for.
Aterons_toss
Profile Joined February 2011
Romania1275 Posts
August 10 2012 07:56 GMT
#263
Well, at least i live in EU and i have a unique pas for blizzard.
But yeah, they are to incompetent to build an anti hack for there game and now they can't even protect customer info...
Are there no good gaming companies left out there ? When you start failing at game design that's one, when you fail at protecting customer info and not fixing bug that's another thing.
Oh well, CD projekt red for new blizzard ?
A good strategy means leaving your opponent room to make mistakes
imJealous
Profile Joined July 2010
United States1382 Posts
August 10 2012 08:01 GMT
#264
On August 10 2012 16:48 Morfildur wrote:
Every month another company loses customer data, when will this trend stop?

I use unique email adresses for everything i register to and it's funny to see new spam popping up all the time. The worst offenders are my sc2replayed@, buffed@ and startrekonline@ adresses, it got so annoying that i started blocking those completely since i stopped using those month before i started getting spam. I guess my blizzard[1-3]@ adresses will be next for the spam flood. I hope i'll never see the day where i have to block teamliquid@... but well, this site is protected by a wizard so it's unlikely to happen.

Well, at least on the other hand it shows me that some other companies are as bad as the one i work for.

+ trick for the win

I don't think you can call it a trend though, hackers finding a way in is like a fact of life.
... In life very little goes right. "Right" meaning the way one expected and the way one wanted it. One has no right to want or expect anything.
windzor
Profile Joined October 2010
Denmark1013 Posts
August 10 2012 08:02 GMT
#265
On August 10 2012 16:43 RoberP wrote:
If the passwords they stole are encrypted, the chances of breaking the cypher on an 8 letter password are about zero. They'd be better off just trying to guess your password ^^. Still worth changing the secret question though.


Actually wrong. It depends on what kind of hashed passwords they got. Seeing as they mention SRP i guess the hacker was eavesdropping the login information in that protocol, or else it makes no sense for blizzard to mention the protocol.

If it was the actual database of the passwords, which might be because they got hold of other account information, the standard way of hashing passwords was considered broken by the author 2 months ago. Then blizzard should have be scared.

But my money is still on the eavesdropping of the SRP which means blizzards security office isn't fired this time around.
Yeah
malaan
Profile Joined September 2010
365 Posts
August 10 2012 08:02 GMT
#266
wonderful... this comes 1 week after I just got all my money back from a card cloning...
Rannasha
Profile Blog Joined August 2010
Netherlands2398 Posts
August 10 2012 08:04 GMT
#267
On August 10 2012 17:02 windzor wrote:
Show nested quote +
On August 10 2012 16:43 RoberP wrote:
If the passwords they stole are encrypted, the chances of breaking the cypher on an 8 letter password are about zero. They'd be better off just trying to guess your password ^^. Still worth changing the secret question though.


If it was the actual database of the passwords, which might be because they got hold of other account information, the standard way of hashing passwords was considered broken by the author 2 months ago. Then blizzard should have be scared.


MD5 hasn't been the "standard way of hashing passwords" for years now. Some websites with terrible security may still use it, but anyone who knows anything about securing a system will have moved away from MD5 a long time ago.
Such flammable little insects!
multiversed
Profile Joined December 2010
United States233 Posts
August 10 2012 08:04 GMT
#268
this entirely defeats the intent and purpose of an authenticator. the only reason to ever use one of these was the fact that it was completely secure and sold as an absolute level security. i am beyond annoyed by this and blizzard should kill themselves. teehee.
Team Liquid is the used the tampon of the starcraft community.
Eisregen
Profile Joined September 2011
Germany967 Posts
August 10 2012 08:07 GMT
#269
glad I never ever enter real information bout me or any finanial infos =)
They can spam my email if they want to, will bore me ^^
Photo-Noob@ http://www.flickr.com/photos/eisregen1983/
MaV_gGSC
Profile Blog Joined November 2010
Canada1345 Posts
August 10 2012 08:10 GMT
#270
better change my password asap. This reminds me of the PSN incident
Life's good :D
Ragnarork
Profile Blog Joined June 2011
France9034 Posts
Last Edited: 2012-08-10 08:14:45
August 10 2012 08:12 GMT
#271
On August 10 2012 16:48 Morfildur wrote:
Every month another company loses customer data, when will this trend stop?

I use unique email adresses for everything i register to and it's funny to see new spam popping up all the time. The worst offenders are my sc2replayed@, buffed@ and startrekonline@ adresses, it got so annoying that i started blocking those completely since i stopped using those month before i started getting spam. I guess my blizzard[1-3]@ adresses will be next for the spam flood. I hope i'll never see the day where i have to block teamliquid@... but well, this site is protected by a wizard so it's unlikely to happen.

Well, at least on the other hand it shows me that some other companies are as bad as the one i work for.


It won't...

I see one main reason for that (though I'm sure that there are more than one, I'm not sure which...)

The fact that companies sometimes overlook security to gain efficiency is playing a role. I think you know what happened with LinkedIn and the leaked hashed password, they were hashed with SHA1 without what we call a "salt" (a random sequence of numbers/letters attached to the hash of the password in order to make this hash unique, even for 2 identical passwords).

SHA1 is a hashing algorithm that we know since 2005 that it has security flaws ( for those interested in the details : http://en.wikipedia.org/wiki/SHA-1).
Not adding a salt to the hashs also makes the security very weak.
This weak security can be seen (personal opinion there) as either linkedIn wanting a fast encryption method, or plain stupidity.
Moreover, those password were stolen thanks to an SQL injection, a common security flaw that is now known for a long time.

Since we still have in 2012 companies that overlook security to gain efficiency, or just by plain stupidity, it won't help stopping this trend. I don't know if you remember Lulzsec, but they weren't "that" good as hackers. They just found very simple security breaches in companies that were quite carefree BEFORE being targeted by hackers. Today, any website that isn't secured against SQL injection is vulnerable to very simple (and easy to find) intrusive methods...

Then, I don't think Blizzard was quite lazy, but a thing they say in the FAQ is that being a huge company on the internet makes you a target tested and tested again on security, either by Black hats or (unofficial) white hats (that first crack, and then contact the company to reveal the flaw).
LiquipediaWanderer
Jinsho
Profile Joined March 2011
United Kingdom3101 Posts
August 10 2012 08:19 GMT
#272
Considering that the only personal data actually lost were email adresses, this is way harmless. Could have potentially been much worse.
klo8
Profile Joined August 2010
Austria1960 Posts
Last Edited: 2012-08-10 08:22:56
August 10 2012 08:22 GMT
#273
On August 10 2012 17:02 windzor wrote:
Show nested quote +
On August 10 2012 16:43 RoberP wrote:
If the passwords they stole are encrypted, the chances of breaking the cypher on an 8 letter password are about zero. They'd be better off just trying to guess your password ^^. Still worth changing the secret question though.


Actually wrong. It depends on what kind of hashed passwords they got. Seeing as they mention SRP i guess the hacker was eavesdropping the login information in that protocol, or else it makes no sense for blizzard to mention the protocol.

If it was the actual database of the passwords, which might be because they got hold of other account information, the standard way of hashing passwords was considered broken by the author 2 months ago. Then blizzard should have be scared.

But my money is still on the eavesdropping of the SRP which means blizzards security office isn't fired this time around.

MD5 has been considered unsafe for a long while now. Already in 1996, a researcher wrote:
"The presented attack does not yet threaten practical applications of MD5, but it comes rather close ... in the future MD5 should no longer be implemented...where a collision-resistant hash function is required."

And in 2005:
Later that year, MD5's designer Ron Rivest wrote, "md5 and sha1 are both clearly broken (in terms of collision-resistance)."


I guess, the point is: Don't use MD5 (or SHA1, or any hash function that you can evaluate very quickly) for hashing passwords, not even a salt value will help you out because MD5 is broken. Use Bcrypt or something similar instead.
This post is clearly not a hurr, as you can see from the graph, the durr never intersects with the derp.
teamamerica
Profile Blog Joined July 2010
United States958 Posts
Last Edited: 2012-08-10 09:00:00
August 10 2012 08:25 GMT
#274
Edit: Whoops I'm dumb. md5 != md5crypt.
RIP GOMTV. RIP PROLEAGUE.
XiWi
Profile Joined August 2012
11 Posts
August 10 2012 08:27 GMT
#275
I'm worried about what information exactly was stolen, and some hacker now social engineering to dig more information.
ChemBroTron
Profile Joined January 2011
Germany194 Posts
Last Edited: 2012-08-10 08:35:56
August 10 2012 08:34 GMT
#276
On August 10 2012 16:48 Morfildur wrote:
Every month another company loses customer data, when will this trend stop?


This will never end and it is not a trend, it is a criminal act. The question is: how save were for example the passwords stored. Save (like Blizzard says for itself, but better change the password for more safety) or unsave (like Sony/PSN).
seiferoth10
Profile Joined May 2010
3362 Posts
August 10 2012 08:40 GMT
#277
I'm honestly surprised it took this long. With 8 years of paying customers' info from WoW, I would imagine they have been a prime target for a long time.
Ragnarork
Profile Blog Joined June 2011
France9034 Posts
August 10 2012 08:41 GMT
#278
By the way I'm a bit confused. How can they say that, with the hackers possessing E-Mails AND security questions' answers, the accounts are safe... ? (Well, even before changing the answer...)
LiquipediaWanderer
GabrielB
Profile Joined February 2003
Brazil594 Posts
August 10 2012 08:48 GMT
#279
On August 10 2012 17:41 Ragnarork wrote:
By the way I'm a bit confused. How can they say that, with the hackers possessing E-Mails AND security questions' answers, the accounts are safe... ? (Well, even before changing the answer...)

I'm not sure how it works on Blizzard, but some sites ask for your email and the answer for your security question. If you provide them correctly, they send you an email with a link to reset your password. So the hacker would still need access to your email.
multiversed
Profile Joined December 2010
United States233 Posts
August 10 2012 08:54 GMT
#280
so i am looking for a way to change my security question and am not finding it online. does this require a phone call for all of my accounts? that is further disappointing if the case... i don't even remember the questions atm, let alone the answers.
Team Liquid is the used the tampon of the starcraft community.
Prev 1 12 13 14 15 16 23 Next All
Please log in or register to reply.
Live Events Refresh
Next event in 1h 39m
[ Submit Event ]
Live Streams
Refresh
StarCraft 2
RotterdaM 575
BRAT_OK 79
Livibee 51
StarCraft: Brood War
Jaedong 1542
GuemChi 1330
EffOrt 1072
Stork 747
Light 703
Snow 454
Larva 452
Mini 346
Rush 255
Barracks 246
[ Show more ]
sSak 116
Leta 116
JYJ44
Aegong 40
Backho 37
sorry 29
zelot 26
soO 19
Terrorterran 17
scan(afreeca) 12
HiyA 12
Bale 10
Dota 2
qojqva3401
420jenkins246
syndereN234
Other Games
singsing1984
DeMusliM369
crisheroes328
Lowko270
Hui .166
Liquid`VortiX149
KnowMe120
oskar106
QueenE37
Trikslyr25
Organizations
Counter-Strike
PGL190
Other Games
BasetradeTV9
StarCraft 2
Blizzard YouTube
StarCraft: Brood War
BSLTrovo
sctven
[ Show 17 non-featured ]
StarCraft 2
• Kozan
• IndyKCrew
• sooper7s
• AfreecaTV YouTube
• Migwel
• intothetv
• LaughNgamezSOOP
StarCraft: Brood War
• Michael_bg 5
• STPLYoutube
• ZZZeroYoutube
• BSLYoutube
Dota 2
• C_a_k_e 2963
• WagamamaTV518
League of Legends
• Nemesis4571
• TFBlade860
Other Games
• Shiphtur86
• tFFMrPink 7
Upcoming Events
LAN Event
1h 39m
Lambo vs Harstem
FuturE vs Maplez
Scarlett vs FoxeR
Gerald vs Mixu
Zoun vs TBD
Clem vs TBD
ByuN vs TBD
TriGGeR vs TBD
Korean StarCraft League
10h 39m
CranKy Ducklings
17h 39m
IPSL
1d 1h
dxtr13 vs OldBoy
Napoleon vs Doodle
LAN Event
1d 1h
BSL 21
1d 3h
Gosudark vs Kyrie
Gypsy vs Sterling
UltrA vs Radley
Dandy vs Ptak
Replay Cast
1d 6h
Sparkling Tuna Cup
1d 17h
WardiTV Korean Royale
1d 19h
IPSL
2 days
JDConan vs WIZARD
WolFix vs Cross
[ Show More ]
LAN Event
2 days
BSL 21
2 days
spx vs rasowy
HBO vs KameZerg
Cross vs Razz
dxtr13 vs ZZZero
Replay Cast
2 days
Wardi Open
2 days
WardiTV Korean Royale
3 days
Replay Cast
4 days
Kung Fu Cup
4 days
Classic vs Solar
herO vs Cure
Reynor vs GuMiho
ByuN vs ShoWTimE
Tenacious Turtle Tussle
5 days
The PondCast
5 days
RSL Revival
5 days
Solar vs Zoun
MaxPax vs Bunny
Kung Fu Cup
5 days
WardiTV Korean Royale
5 days
RSL Revival
6 days
Classic vs Creator
Cure vs TriGGeR
Kung Fu Cup
6 days
Liquipedia Results

Completed

BSL 21 Points
SC4ALL: StarCraft II
Eternal Conflict S1

Ongoing

C-Race Season 1
IPSL Winter 2025-26
KCM Race Survival 2025 Season 4
SOOP Univ League 2025
YSL S2
Stellar Fest: Constellation Cup
IEM Chengdu 2025
PGL Masters Bucharest 2025
Thunderpick World Champ.
CS Asia Championships 2025
ESL Pro League S22
StarSeries Fall 2025
FISSURE Playground #2
BLAST Open Fall 2025
BLAST Open Fall Qual

Upcoming

BSL Season 21
SLON Tour Season 2
BSL 21 Non-Korean Championship
Acropolis #4
IPSL Spring 2026
HSC XXVIII
RSL Offline Finals
WardiTV 2025
RSL Revival: Season 3
META Madness #9
BLAST Bounty Winter 2026: Closed Qualifier
eXTREMESLAND 2025
ESL Impact League Season 8
SL Budapest Major 2025
BLAST Rivals Fall 2025
TLPD

1. ByuN
2. TY
3. Dark
4. Solar
5. Stats
6. Nerchio
7. sOs
8. soO
9. INnoVation
10. Elazer
1. Rain
2. Flash
3. EffOrt
4. Last
5. Bisu
6. Soulkey
7. Mini
8. Sharp
Sidebar Settings...

Advertising | Privacy Policy | Terms Of Use | Contact Us

Original banner artwork: Jim Warren
The contents of this webpage are copyright © 2025 TLnet. All Rights Reserved.