• Log InLog In
  • Register
Liquid`
Team Liquid Liquipedia
EDT 23:08
CEST 05:08
KST 12:08
  • Home
  • Forum
  • Calendar
  • Streams
  • Liquipedia
  • Features
  • Store
  • EPT
  • TL+
  • StarCraft 2
  • Brood War
  • Smash
  • Heroes
  • Counter-Strike
  • Overwatch
  • Liquibet
  • Fantasy StarCraft
  • TLPD
  • StarCraft 2
  • Brood War
  • Blogs
Forum Sidebar
Events/Features
News
Featured News
[ASL22] Ro24 Preview: Siren's Call8[ASL22] Ro24 Preview: Summer's End9Serral wins HomeStory Cup 2915Serral wins Maestros of the Game 244ByuL, and the Limitations of Standard Play3
Community News
Official StarCraft website teases new content ahead of BlizzCon?83Stellar Fest TWO the Moon (Dec 16-20)9Weekly Cups (August 24-30): Patches' balance mod takes over3New 3v3 BGH Ladder (and more) on ShieldBattery!40Weekly Cups (August 17-23): Zerg dominate the week6
StarCraft 2
General
Nexon wins bid to develop StarCraft IP content, distribute Overwatch mobile game SC4ALL: II Winner Will Earn a Spot at HSC 30! Weekly Cups (August 24-30): Patches' balance mod takes over Balance hotfix patch 5.0.16b (July 16) September World Ranking: herO leads, Serral climbs
Tourneys
2026 GSTL Announcement Sparkling Tuna Cup - Weekly Open Tournament Stellar Fest TWO the Moon (Dec 16-20) IntoTheTV X SOOP SC2 League : Weekly & Monthly SC2 INu's Battles#20 [BO.9]
Strategy
[G] Having the right mentality to improve
Custom Maps
Nexus Wars 2021 GUIDE [M] (2) Industrial Park
External Content
Mutation # 541 Binary Choice The PondCast: SC2 News & Results Mutation # 540 Dodge This Mutation # 539 Thunder Dome
Brood War
General
[Personal Project Share] Terran Defense v0.60 Gypsy to Korea Official StarCraft website teases new content ahead of BlizzCon? BGH Auto Balance -> http://bghmmr.eu/ ASL22 General Discussion
Tourneys
Brood War in Budapest ! WORTEX 2026 BW Finals KCM Race Survival 2026 Season 3 [Megathread] Daily Proleagues BSL LAN Party - Kraków 29-30 August - OPEN SIGNUPS
Strategy
Odyssey Mineral Stack Saturation Replay Review Process - What do you do? Game Theory for Starcraft Fighting Spirit mining rates
Other Games
General Games
Nintendo Switch Thread Diablo IV EVE Corporation [Maplestory Hardcore] Let's Play~!! General RTS Discussion Thread
Dota 2
Official 'what is Dota anymore' discussion
League of Legends
[TL LoL EUW IHs] Teemo shall perish TSM pausing esports and CLG Dead
Heroes of the Storm
Heroes of the Storm 2.0
Hearthstone
Deck construction bug
TL Mafia
TL Mafia Power Rank TL Mafia Community Thread NeO.D_StephenKing vs This Guy From 1 Million Dance
Community
General
US Politics Mega-thread Things Aren’t Peaceful in Palestine Artificial Intelligence Thread Canadian Politics Mega-thread UK Politics Mega-thread
Fan Clubs
MarineLorD Fan Club The Creator Fan Club The ShoWTimE Fan Club
Media & Entertainment
Movie Discussion! Anime Discussion Thread
Sports
Football (Soccer) Thread TeamLiquid Health and Fitness Initiative For 2023 MLB/Baseball 2023 NBA General Discussion
World Cup 2022
Tech Support
Computer Build, Upgrade & Buying Resource Thread
TL Community
The Automated Ban List Northern Ireland Global Starcraft
Blogs
Dreaming of BW patches (mod…
c3rberUs
Regacy Esports: The Bh…
regacyesports
Violent Games and Crime Rate…
TrAiDoS
LOCKPICKING NOOB
LUCKY_NOOB
Cathedral Of CS And NY pizza a…
FuDDx
Customize Sidebar...

Website Feedback

Closed Threads



Active: 9095 users

Blizzard Security Breach - Page 14

Forum Index > SC2 General
442 CommentsPost a Reply
Prev 1 12 13 14 15 16 23 Next All
Trasko
Profile Blog Joined July 2010
Sweden983 Posts
August 10 2012 07:48 GMT
#261
On August 10 2012 07:42 mataxp wrote:
As a PSN user, dejá vu



loooool. Same here.... /fml
Jaedong <3
Deleted User 101379
Profile Blog Joined August 2010
4849 Posts
August 10 2012 07:48 GMT
#262
Every month another company loses customer data, when will this trend stop?

I use unique email adresses for everything i register to and it's funny to see new spam popping up all the time. The worst offenders are my sc2replayed@, buffed@ and startrekonline@ adresses, it got so annoying that i started blocking those completely since i stopped using those month before i started getting spam. I guess my blizzard[1-3]@ adresses will be next for the spam flood. I hope i'll never see the day where i have to block teamliquid@... but well, this site is protected by a wizard so it's unlikely to happen.

Well, at least on the other hand it shows me that some other companies are as bad as the one i work for.
Aterons_toss
Profile Joined February 2011
Romania1275 Posts
August 10 2012 07:56 GMT
#263
Well, at least i live in EU and i have a unique pas for blizzard.
But yeah, they are to incompetent to build an anti hack for there game and now they can't even protect customer info...
Are there no good gaming companies left out there ? When you start failing at game design that's one, when you fail at protecting customer info and not fixing bug that's another thing.
Oh well, CD projekt red for new blizzard ?
A good strategy means leaving your opponent room to make mistakes
imJealous
Profile Joined July 2010
United States1382 Posts
August 10 2012 08:01 GMT
#264
On August 10 2012 16:48 Morfildur wrote:
Every month another company loses customer data, when will this trend stop?

I use unique email adresses for everything i register to and it's funny to see new spam popping up all the time. The worst offenders are my sc2replayed@, buffed@ and startrekonline@ adresses, it got so annoying that i started blocking those completely since i stopped using those month before i started getting spam. I guess my blizzard[1-3]@ adresses will be next for the spam flood. I hope i'll never see the day where i have to block teamliquid@... but well, this site is protected by a wizard so it's unlikely to happen.

Well, at least on the other hand it shows me that some other companies are as bad as the one i work for.

+ trick for the win

I don't think you can call it a trend though, hackers finding a way in is like a fact of life.
... In life very little goes right. "Right" meaning the way one expected and the way one wanted it. One has no right to want or expect anything.
windzor
Profile Joined October 2010
Denmark1013 Posts
August 10 2012 08:02 GMT
#265
On August 10 2012 16:43 RoberP wrote:
If the passwords they stole are encrypted, the chances of breaking the cypher on an 8 letter password are about zero. They'd be better off just trying to guess your password ^^. Still worth changing the secret question though.


Actually wrong. It depends on what kind of hashed passwords they got. Seeing as they mention SRP i guess the hacker was eavesdropping the login information in that protocol, or else it makes no sense for blizzard to mention the protocol.

If it was the actual database of the passwords, which might be because they got hold of other account information, the standard way of hashing passwords was considered broken by the author 2 months ago. Then blizzard should have be scared.

But my money is still on the eavesdropping of the SRP which means blizzards security office isn't fired this time around.
Yeah
malaan
Profile Joined September 2010
365 Posts
August 10 2012 08:02 GMT
#266
wonderful... this comes 1 week after I just got all my money back from a card cloning...
Rannasha
Profile Blog Joined August 2010
Netherlands2398 Posts
August 10 2012 08:04 GMT
#267
On August 10 2012 17:02 windzor wrote:
Show nested quote +
On August 10 2012 16:43 RoberP wrote:
If the passwords they stole are encrypted, the chances of breaking the cypher on an 8 letter password are about zero. They'd be better off just trying to guess your password ^^. Still worth changing the secret question though.


If it was the actual database of the passwords, which might be because they got hold of other account information, the standard way of hashing passwords was considered broken by the author 2 months ago. Then blizzard should have be scared.


MD5 hasn't been the "standard way of hashing passwords" for years now. Some websites with terrible security may still use it, but anyone who knows anything about securing a system will have moved away from MD5 a long time ago.
Such flammable little insects!
multiversed
Profile Joined December 2010
United States233 Posts
August 10 2012 08:04 GMT
#268
this entirely defeats the intent and purpose of an authenticator. the only reason to ever use one of these was the fact that it was completely secure and sold as an absolute level security. i am beyond annoyed by this and blizzard should kill themselves. teehee.
Team Liquid is the used the tampon of the starcraft community.
Eisregen
Profile Joined September 2011
Germany967 Posts
August 10 2012 08:07 GMT
#269
glad I never ever enter real information bout me or any finanial infos =)
They can spam my email if they want to, will bore me ^^
Photo-Noob@ http://www.flickr.com/photos/eisregen1983/
MaV_gGSC
Profile Blog Joined November 2010
Canada1345 Posts
August 10 2012 08:10 GMT
#270
better change my password asap. This reminds me of the PSN incident
Life's good :D
Ragnarork
Profile Blog Joined June 2011
France9034 Posts
Last Edited: 2012-08-10 08:14:45
August 10 2012 08:12 GMT
#271
On August 10 2012 16:48 Morfildur wrote:
Every month another company loses customer data, when will this trend stop?

I use unique email adresses for everything i register to and it's funny to see new spam popping up all the time. The worst offenders are my sc2replayed@, buffed@ and startrekonline@ adresses, it got so annoying that i started blocking those completely since i stopped using those month before i started getting spam. I guess my blizzard[1-3]@ adresses will be next for the spam flood. I hope i'll never see the day where i have to block teamliquid@... but well, this site is protected by a wizard so it's unlikely to happen.

Well, at least on the other hand it shows me that some other companies are as bad as the one i work for.


It won't...

I see one main reason for that (though I'm sure that there are more than one, I'm not sure which...)

The fact that companies sometimes overlook security to gain efficiency is playing a role. I think you know what happened with LinkedIn and the leaked hashed password, they were hashed with SHA1 without what we call a "salt" (a random sequence of numbers/letters attached to the hash of the password in order to make this hash unique, even for 2 identical passwords).

SHA1 is a hashing algorithm that we know since 2005 that it has security flaws ( for those interested in the details : http://en.wikipedia.org/wiki/SHA-1).
Not adding a salt to the hashs also makes the security very weak.
This weak security can be seen (personal opinion there) as either linkedIn wanting a fast encryption method, or plain stupidity.
Moreover, those password were stolen thanks to an SQL injection, a common security flaw that is now known for a long time.

Since we still have in 2012 companies that overlook security to gain efficiency, or just by plain stupidity, it won't help stopping this trend. I don't know if you remember Lulzsec, but they weren't "that" good as hackers. They just found very simple security breaches in companies that were quite carefree BEFORE being targeted by hackers. Today, any website that isn't secured against SQL injection is vulnerable to very simple (and easy to find) intrusive methods...

Then, I don't think Blizzard was quite lazy, but a thing they say in the FAQ is that being a huge company on the internet makes you a target tested and tested again on security, either by Black hats or (unofficial) white hats (that first crack, and then contact the company to reveal the flaw).
LiquipediaWanderer
Jinsho
Profile Joined March 2011
United Kingdom3101 Posts
August 10 2012 08:19 GMT
#272
Considering that the only personal data actually lost were email adresses, this is way harmless. Could have potentially been much worse.
klo8
Profile Joined August 2010
Austria1960 Posts
Last Edited: 2012-08-10 08:22:56
August 10 2012 08:22 GMT
#273
On August 10 2012 17:02 windzor wrote:
Show nested quote +
On August 10 2012 16:43 RoberP wrote:
If the passwords they stole are encrypted, the chances of breaking the cypher on an 8 letter password are about zero. They'd be better off just trying to guess your password ^^. Still worth changing the secret question though.


Actually wrong. It depends on what kind of hashed passwords they got. Seeing as they mention SRP i guess the hacker was eavesdropping the login information in that protocol, or else it makes no sense for blizzard to mention the protocol.

If it was the actual database of the passwords, which might be because they got hold of other account information, the standard way of hashing passwords was considered broken by the author 2 months ago. Then blizzard should have be scared.

But my money is still on the eavesdropping of the SRP which means blizzards security office isn't fired this time around.

MD5 has been considered unsafe for a long while now. Already in 1996, a researcher wrote:
"The presented attack does not yet threaten practical applications of MD5, but it comes rather close ... in the future MD5 should no longer be implemented...where a collision-resistant hash function is required."

And in 2005:
Later that year, MD5's designer Ron Rivest wrote, "md5 and sha1 are both clearly broken (in terms of collision-resistance)."


I guess, the point is: Don't use MD5 (or SHA1, or any hash function that you can evaluate very quickly) for hashing passwords, not even a salt value will help you out because MD5 is broken. Use Bcrypt or something similar instead.
This post is clearly not a hurr, as you can see from the graph, the durr never intersects with the derp.
teamamerica
Profile Blog Joined July 2010
United States958 Posts
Last Edited: 2012-08-10 09:00:00
August 10 2012 08:25 GMT
#274
Edit: Whoops I'm dumb. md5 != md5crypt.
RIP GOMTV. RIP PROLEAGUE.
XiWi
Profile Joined August 2012
11 Posts
August 10 2012 08:27 GMT
#275
I'm worried about what information exactly was stolen, and some hacker now social engineering to dig more information.
ChemBroTron
Profile Joined January 2011
Germany194 Posts
Last Edited: 2012-08-10 08:35:56
August 10 2012 08:34 GMT
#276
On August 10 2012 16:48 Morfildur wrote:
Every month another company loses customer data, when will this trend stop?


This will never end and it is not a trend, it is a criminal act. The question is: how save were for example the passwords stored. Save (like Blizzard says for itself, but better change the password for more safety) or unsave (like Sony/PSN).
seiferoth10
Profile Joined May 2010
3362 Posts
August 10 2012 08:40 GMT
#277
I'm honestly surprised it took this long. With 8 years of paying customers' info from WoW, I would imagine they have been a prime target for a long time.
Ragnarork
Profile Blog Joined June 2011
France9034 Posts
August 10 2012 08:41 GMT
#278
By the way I'm a bit confused. How can they say that, with the hackers possessing E-Mails AND security questions' answers, the accounts are safe... ? (Well, even before changing the answer...)
LiquipediaWanderer
GabrielB
Profile Joined February 2003
Brazil594 Posts
August 10 2012 08:48 GMT
#279
On August 10 2012 17:41 Ragnarork wrote:
By the way I'm a bit confused. How can they say that, with the hackers possessing E-Mails AND security questions' answers, the accounts are safe... ? (Well, even before changing the answer...)

I'm not sure how it works on Blizzard, but some sites ask for your email and the answer for your security question. If you provide them correctly, they send you an email with a link to reset your password. So the hacker would still need access to your email.
multiversed
Profile Joined December 2010
United States233 Posts
August 10 2012 08:54 GMT
#280
so i am looking for a way to change my security question and am not finding it online. does this require a phone call for all of my accounts? that is further disappointing if the case... i don't even remember the questions atm, let alone the answers.
Team Liquid is the used the tampon of the starcraft community.
Prev 1 12 13 14 15 16 23 Next All
Please log in or register to reply.
Live Events Refresh
Next event in 6h 52m
[ Submit Event ]
Live Streams
Refresh
StarCraft 2
WinterStarcraft314
RuFF_SC2 208
SpeCial 188
StarCraft: Brood War
Shuttle 1934
Hyuk 234
910 72
sSak 58
ggaemo 55
Terrorterran 11
Yoon 11
Shinee 5
Dota 2
NeuroSwarm204
Counter-Strike
minikerr49
Super Smash Bros
Mew2King83
Heroes of the Storm
Khaldor142
Other Games
summit1g8334
JimRising 818
PiGStarcraft350
XaKoH 122
ViBE66
Organizations
Other Games
gamesdonequick2567
BasetradeTV92
[ Show 10 non-featured ]
StarCraft 2
• practicex 23
• AfreecaTV YouTube
• intothetv
• Kozan
• IndyKCrew
• Migwel
StarCraft: Brood War
• Light_VIP 50
• BSLYoutube
• STPLYoutube
• ZZZeroYoutube
Upcoming Events
Sparkling Tuna Cup
6h 52m
OSC
8h 52m
Shopify Rebellion Sundays
11h 52m
Mixu vs TBD
Spirit vs TBD
Clem vs TBD
Patches Events
12h 52m
OSC
20h 52m
Afreeca Starleague
1d 6h
Soma vs Shuttle
BeSt vs Rush
WardiTV Weekly
1d 7h
Monday Night Weeklies
1d 12h
Afreeca Starleague
2 days
Leta vs ggaemo
Jaedong vs Queen
GSL
2 days
[ Show More ]
PiGosaur Cup
2 days
Kung Fu Cup
3 days
Replay Cast
3 days
The PondCast
4 days
KCM Race Survival
4 days
Escore
5 days
IntoTheTV X SOOP
5 days
CranKy Ducklings
6 days
Liquipedia Results

Completed

Proleague 2026-09-02
PiG Sty Festival 8.0
Light Tournament 2026

Ongoing

KCM Race Survival 2026 Season 3
K-JUNGMAN
ASL Season 22
Super Anchor Qualifying S3
CSL 2026 AUTUMN (S22)
Acropolis #5
Acropolis #5 - TRS
RSL Revival: Season 6
Calamity Invitational
Big Dog Cup 2026 Div 1
BLAST Open Fall 2026
Esports World Cup 2026
Esports World Cup 2026: LCQ
BLAST Bounty Summer 2026
BLAST Bounty Summer Qual
Stake Ranked Episode 3
XSE Pro League 2026

Upcoming

Escore Tournament S3: King of Kings
Blizzard Classic Cup 2026
Acropolis #5 - GSA
Acropolis #5 - GSB
Acropolis #5 - GSC
SC4ALL II: Brood War
HSC XXX
Stellar Fest 2: Lunar Cup
SC4ALL II: StarCraft II
Kung Fu Cup 2026 Grand Finals
RSL Offline Finals
BLAST Rivals Fall 2026
IEM Beijing 2026
Stake Ranked Episode 5
PGL Masters Bucharest 2026
1win Private Club #2
Thunderpick World Champ. '26
ESL Pro League Season 24
Stake Ranked Episode 4
1win Private Club #1
Logitech G Play Connect 2026
SL StarSeries Fall 2026
FISSURE Playground #3
TLPD

1. ByuN
2. TY
3. Dark
4. Solar
5. Stats
6. Nerchio
7. sOs
8. soO
9. INnoVation
10. Elazer
1. Rain
2. Flash
3. EffOrt
4. Last
5. Bisu
6. Soulkey
7. Mini
8. Sharp
Sidebar Settings...

Advertising | Privacy Policy | Terms Of Use | Contact Us

Original banner artwork: Jim Warren
The contents of this webpage are copyright © 2026 TLnet. All Rights Reserved.