• Log InLog In
  • Register
Liquid`
Team Liquid Liquipedia
EDT 17:38
CEST 23:38
KST 06:38
  • Home
  • Forum
  • Calendar
  • Streams
  • Liquipedia
  • Features
  • Store
  • EPT
  • TL+
  • StarCraft 2
  • Brood War
  • Smash
  • Heroes
  • Counter-Strike
  • Overwatch
  • Liquibet
  • Fantasy StarCraft
  • TLPD
  • StarCraft 2
  • Brood War
  • Blogs
Forum Sidebar
Events/Features
News
Featured News
Team TLMC #5 - Finalists & Open Tournaments0[ASL20] Ro16 Preview Pt2: Turbulence10Classic Games #3: Rogue vs Serral at BlizzCon9[ASL20] Ro16 Preview Pt1: Ascent10Maestros of the Game: Week 1/Play-in Preview12
Community News
BSL 2025 Warsaw LAN + Legends Showmatch0Weekly Cups (Sept 8-14): herO & MaxPax split cups4WardiTV TL Team Map Contest #5 Tournaments1SC4ALL $6,000 Open LAN in Philadelphia8Weekly Cups (Sept 1-7): MaxPax rebounds & Clem saga continues29
StarCraft 2
General
StarCraft II 5.0.15 PTR Patch Notes #1: Maru - Greatest Players of All Time Weekly Cups (Sept 8-14): herO & MaxPax split cups Team Liquid Map Contest #21 - Presented by Monster Energy SpeCial on The Tasteless Podcast
Tourneys
SC2's Safe House 2 - October 18 & 19 RSL: Revival, a new crowdfunded tournament series Maestros of The Game—$20k event w/ live finals in Paris Sparkling Tuna Cup - Weekly Open Tournament SC4ALL $6,000 Open LAN in Philadelphia
Strategy
Custom Maps
External Content
Mutation # 491 Night Drive Mutation # 490 Masters of Midnight Mutation # 489 Bannable Offense Mutation # 488 What Goes Around
Brood War
General
ASL20 General Discussion Soulkey on ASL S20 BW General Discussion ASL TICKET LIVE help! :D NaDa's Body
Tourneys
[ASL20] Ro16 Group C [ASL20] Ro16 Group D Small VOD Thread 2.0 [Megathread] Daily Proleagues
Strategy
Simple Questions, Simple Answers Muta micro map competition Fighting Spirit mining rates [G] Mineral Boosting
Other Games
General Games
Stormgate/Frost Giant Megathread Borderlands 3 Path of Exile Nintendo Switch Thread General RTS Discussion Thread
Dota 2
Official 'what is Dota anymore' discussion LiquidDota to reintegrate into TL.net
League of Legends
Heroes of the Storm
Simple Questions, Simple Answers Heroes of the Storm 2.0
Hearthstone
Heroes of StarCraft mini-set
TL Mafia
TL Mafia Community Thread
Community
General
US Politics Mega-thread Russo-Ukrainian War Thread Things Aren’t Peaceful in Palestine UK Politics Mega-thread Canadian Politics Mega-thread
Fan Clubs
The Happy Fan Club!
Media & Entertainment
Movie Discussion! [Manga] One Piece Anime Discussion Thread
Sports
2024 - 2026 Football Thread Formula 1 Discussion MLB/Baseball 2023
World Cup 2022
Tech Support
Linksys AE2500 USB WIFI keeps disconnecting Computer Build, Upgrade & Buying Resource Thread High temperatures on bridge(s)
TL Community
BarCraft in Tokyo Japan for ASL Season5 Final The Automated Ban List
Blogs
i'm really bored guys
Peanutsc
I <=> 9
KrillinFromwales
The Personality of a Spender…
TrAiDoS
A very expensive lesson on ma…
Garnet
hello world
radishsoup
Lemme tell you a thing o…
JoinTheRain
RTS Design in Hypercoven
a11
Customize Sidebar...

Website Feedback

Closed Threads



Active: 1415 users

Blizzard Security Breach - Page 14

Forum Index > SC2 General
442 CommentsPost a Reply
Prev 1 12 13 14 15 16 23 Next All
Trasko
Profile Blog Joined July 2010
Sweden983 Posts
August 10 2012 07:48 GMT
#261
On August 10 2012 07:42 mataxp wrote:
As a PSN user, dejá vu



loooool. Same here.... /fml
Jaedong <3
Deleted User 101379
Profile Blog Joined August 2010
4849 Posts
August 10 2012 07:48 GMT
#262
Every month another company loses customer data, when will this trend stop?

I use unique email adresses for everything i register to and it's funny to see new spam popping up all the time. The worst offenders are my sc2replayed@, buffed@ and startrekonline@ adresses, it got so annoying that i started blocking those completely since i stopped using those month before i started getting spam. I guess my blizzard[1-3]@ adresses will be next for the spam flood. I hope i'll never see the day where i have to block teamliquid@... but well, this site is protected by a wizard so it's unlikely to happen.

Well, at least on the other hand it shows me that some other companies are as bad as the one i work for.
Aterons_toss
Profile Joined February 2011
Romania1275 Posts
August 10 2012 07:56 GMT
#263
Well, at least i live in EU and i have a unique pas for blizzard.
But yeah, they are to incompetent to build an anti hack for there game and now they can't even protect customer info...
Are there no good gaming companies left out there ? When you start failing at game design that's one, when you fail at protecting customer info and not fixing bug that's another thing.
Oh well, CD projekt red for new blizzard ?
A good strategy means leaving your opponent room to make mistakes
imJealous
Profile Joined July 2010
United States1382 Posts
August 10 2012 08:01 GMT
#264
On August 10 2012 16:48 Morfildur wrote:
Every month another company loses customer data, when will this trend stop?

I use unique email adresses for everything i register to and it's funny to see new spam popping up all the time. The worst offenders are my sc2replayed@, buffed@ and startrekonline@ adresses, it got so annoying that i started blocking those completely since i stopped using those month before i started getting spam. I guess my blizzard[1-3]@ adresses will be next for the spam flood. I hope i'll never see the day where i have to block teamliquid@... but well, this site is protected by a wizard so it's unlikely to happen.

Well, at least on the other hand it shows me that some other companies are as bad as the one i work for.

+ trick for the win

I don't think you can call it a trend though, hackers finding a way in is like a fact of life.
... In life very little goes right. "Right" meaning the way one expected and the way one wanted it. One has no right to want or expect anything.
windzor
Profile Joined October 2010
Denmark1013 Posts
August 10 2012 08:02 GMT
#265
On August 10 2012 16:43 RoberP wrote:
If the passwords they stole are encrypted, the chances of breaking the cypher on an 8 letter password are about zero. They'd be better off just trying to guess your password ^^. Still worth changing the secret question though.


Actually wrong. It depends on what kind of hashed passwords they got. Seeing as they mention SRP i guess the hacker was eavesdropping the login information in that protocol, or else it makes no sense for blizzard to mention the protocol.

If it was the actual database of the passwords, which might be because they got hold of other account information, the standard way of hashing passwords was considered broken by the author 2 months ago. Then blizzard should have be scared.

But my money is still on the eavesdropping of the SRP which means blizzards security office isn't fired this time around.
Yeah
malaan
Profile Joined September 2010
365 Posts
August 10 2012 08:02 GMT
#266
wonderful... this comes 1 week after I just got all my money back from a card cloning...
Rannasha
Profile Blog Joined August 2010
Netherlands2398 Posts
August 10 2012 08:04 GMT
#267
On August 10 2012 17:02 windzor wrote:
Show nested quote +
On August 10 2012 16:43 RoberP wrote:
If the passwords they stole are encrypted, the chances of breaking the cypher on an 8 letter password are about zero. They'd be better off just trying to guess your password ^^. Still worth changing the secret question though.


If it was the actual database of the passwords, which might be because they got hold of other account information, the standard way of hashing passwords was considered broken by the author 2 months ago. Then blizzard should have be scared.


MD5 hasn't been the "standard way of hashing passwords" for years now. Some websites with terrible security may still use it, but anyone who knows anything about securing a system will have moved away from MD5 a long time ago.
Such flammable little insects!
multiversed
Profile Joined December 2010
United States233 Posts
August 10 2012 08:04 GMT
#268
this entirely defeats the intent and purpose of an authenticator. the only reason to ever use one of these was the fact that it was completely secure and sold as an absolute level security. i am beyond annoyed by this and blizzard should kill themselves. teehee.
Team Liquid is the used the tampon of the starcraft community.
Eisregen
Profile Joined September 2011
Germany967 Posts
August 10 2012 08:07 GMT
#269
glad I never ever enter real information bout me or any finanial infos =)
They can spam my email if they want to, will bore me ^^
Photo-Noob@ http://www.flickr.com/photos/eisregen1983/
MaV_gGSC
Profile Blog Joined November 2010
Canada1345 Posts
August 10 2012 08:10 GMT
#270
better change my password asap. This reminds me of the PSN incident
Life's good :D
Ragnarork
Profile Blog Joined June 2011
France9034 Posts
Last Edited: 2012-08-10 08:14:45
August 10 2012 08:12 GMT
#271
On August 10 2012 16:48 Morfildur wrote:
Every month another company loses customer data, when will this trend stop?

I use unique email adresses for everything i register to and it's funny to see new spam popping up all the time. The worst offenders are my sc2replayed@, buffed@ and startrekonline@ adresses, it got so annoying that i started blocking those completely since i stopped using those month before i started getting spam. I guess my blizzard[1-3]@ adresses will be next for the spam flood. I hope i'll never see the day where i have to block teamliquid@... but well, this site is protected by a wizard so it's unlikely to happen.

Well, at least on the other hand it shows me that some other companies are as bad as the one i work for.


It won't...

I see one main reason for that (though I'm sure that there are more than one, I'm not sure which...)

The fact that companies sometimes overlook security to gain efficiency is playing a role. I think you know what happened with LinkedIn and the leaked hashed password, they were hashed with SHA1 without what we call a "salt" (a random sequence of numbers/letters attached to the hash of the password in order to make this hash unique, even for 2 identical passwords).

SHA1 is a hashing algorithm that we know since 2005 that it has security flaws ( for those interested in the details : http://en.wikipedia.org/wiki/SHA-1).
Not adding a salt to the hashs also makes the security very weak.
This weak security can be seen (personal opinion there) as either linkedIn wanting a fast encryption method, or plain stupidity.
Moreover, those password were stolen thanks to an SQL injection, a common security flaw that is now known for a long time.

Since we still have in 2012 companies that overlook security to gain efficiency, or just by plain stupidity, it won't help stopping this trend. I don't know if you remember Lulzsec, but they weren't "that" good as hackers. They just found very simple security breaches in companies that were quite carefree BEFORE being targeted by hackers. Today, any website that isn't secured against SQL injection is vulnerable to very simple (and easy to find) intrusive methods...

Then, I don't think Blizzard was quite lazy, but a thing they say in the FAQ is that being a huge company on the internet makes you a target tested and tested again on security, either by Black hats or (unofficial) white hats (that first crack, and then contact the company to reveal the flaw).
LiquipediaWanderer
Jinsho
Profile Joined March 2011
United Kingdom3101 Posts
August 10 2012 08:19 GMT
#272
Considering that the only personal data actually lost were email adresses, this is way harmless. Could have potentially been much worse.
klo8
Profile Joined August 2010
Austria1960 Posts
Last Edited: 2012-08-10 08:22:56
August 10 2012 08:22 GMT
#273
On August 10 2012 17:02 windzor wrote:
Show nested quote +
On August 10 2012 16:43 RoberP wrote:
If the passwords they stole are encrypted, the chances of breaking the cypher on an 8 letter password are about zero. They'd be better off just trying to guess your password ^^. Still worth changing the secret question though.


Actually wrong. It depends on what kind of hashed passwords they got. Seeing as they mention SRP i guess the hacker was eavesdropping the login information in that protocol, or else it makes no sense for blizzard to mention the protocol.

If it was the actual database of the passwords, which might be because they got hold of other account information, the standard way of hashing passwords was considered broken by the author 2 months ago. Then blizzard should have be scared.

But my money is still on the eavesdropping of the SRP which means blizzards security office isn't fired this time around.

MD5 has been considered unsafe for a long while now. Already in 1996, a researcher wrote:
"The presented attack does not yet threaten practical applications of MD5, but it comes rather close ... in the future MD5 should no longer be implemented...where a collision-resistant hash function is required."

And in 2005:
Later that year, MD5's designer Ron Rivest wrote, "md5 and sha1 are both clearly broken (in terms of collision-resistance)."


I guess, the point is: Don't use MD5 (or SHA1, or any hash function that you can evaluate very quickly) for hashing passwords, not even a salt value will help you out because MD5 is broken. Use Bcrypt or something similar instead.
This post is clearly not a hurr, as you can see from the graph, the durr never intersects with the derp.
teamamerica
Profile Blog Joined July 2010
United States958 Posts
Last Edited: 2012-08-10 09:00:00
August 10 2012 08:25 GMT
#274
Edit: Whoops I'm dumb. md5 != md5crypt.
RIP GOMTV. RIP PROLEAGUE.
XiWi
Profile Joined August 2012
11 Posts
August 10 2012 08:27 GMT
#275
I'm worried about what information exactly was stolen, and some hacker now social engineering to dig more information.
ChemBroTron
Profile Joined January 2011
Germany194 Posts
Last Edited: 2012-08-10 08:35:56
August 10 2012 08:34 GMT
#276
On August 10 2012 16:48 Morfildur wrote:
Every month another company loses customer data, when will this trend stop?


This will never end and it is not a trend, it is a criminal act. The question is: how save were for example the passwords stored. Save (like Blizzard says for itself, but better change the password for more safety) or unsave (like Sony/PSN).
seiferoth10
Profile Joined May 2010
3362 Posts
August 10 2012 08:40 GMT
#277
I'm honestly surprised it took this long. With 8 years of paying customers' info from WoW, I would imagine they have been a prime target for a long time.
Ragnarork
Profile Blog Joined June 2011
France9034 Posts
August 10 2012 08:41 GMT
#278
By the way I'm a bit confused. How can they say that, with the hackers possessing E-Mails AND security questions' answers, the accounts are safe... ? (Well, even before changing the answer...)
LiquipediaWanderer
GabrielB
Profile Joined February 2003
Brazil594 Posts
August 10 2012 08:48 GMT
#279
On August 10 2012 17:41 Ragnarork wrote:
By the way I'm a bit confused. How can they say that, with the hackers possessing E-Mails AND security questions' answers, the accounts are safe... ? (Well, even before changing the answer...)

I'm not sure how it works on Blizzard, but some sites ask for your email and the answer for your security question. If you provide them correctly, they send you an email with a link to reset your password. So the hacker would still need access to your email.
multiversed
Profile Joined December 2010
United States233 Posts
August 10 2012 08:54 GMT
#280
so i am looking for a way to change my security question and am not finding it online. does this require a phone call for all of my accounts? that is further disappointing if the case... i don't even remember the questions atm, let alone the answers.
Team Liquid is the used the tampon of the starcraft community.
Prev 1 12 13 14 15 16 23 Next All
Please log in or register to reply.
Live Events Refresh
Next event in 12h 22m
[ Submit Event ]
Live Streams
Refresh
StarCraft 2
UpATreeSC 216
NeuroSwarm 178
SteadfastSC 162
StarCraft: Brood War
Britney 14515
Shuttle 260
Dewaltoss 103
Larva 57
Aegong 38
Sexy 21
ZZZero.O 15
Dota 2
monkeys_forever295
Fuzer 171
Counter-Strike
flusha308
Stewie2K295
Super Smash Bros
Mew2King46
Heroes of the Storm
Liquid`Hasu567
Other Games
summit1g6328
FrodaN1544
fl0m989
shahzam351
mouzStarbuck247
ToD236
C9.Mang0148
Trikslyr38
PPMD31
Organizations
StarCraft 2
Blizzard YouTube
StarCraft: Brood War
BSLTrovo
sctven
[ Show 19 non-featured ]
StarCraft 2
• davetesta31
• RyuSc2 1
• intothetv
• sooper7s
• Migwel
• AfreecaTV YouTube
• LaughNgamezSOOP
• IndyKCrew
• Kozan
StarCraft: Brood War
• STPLYoutube
• ZZZeroYoutube
• BSLYoutube
Dota 2
• C_a_k_e 4203
League of Legends
• Doublelift4370
• imaqtpie1423
• TFBlade839
• Shiphtur279
Other Games
• Scarra1352
• WagamamaTV354
Upcoming Events
RSL Revival
12h 22m
Zoun vs Classic
Map Test Tournament
13h 22m
Korean StarCraft League
1d 5h
BSL Open LAN 2025 - War…
1d 10h
RSL Revival
1d 12h
Reynor vs Cure
BSL Open LAN 2025 - War…
2 days
RSL Revival
2 days
Online Event
2 days
Wardi Open
3 days
Monday Night Weeklies
3 days
[ Show More ]
Sparkling Tuna Cup
4 days
LiuLi Cup
5 days
The PondCast
6 days
Liquipedia Results

Completed

Proleague 2025-09-10
Chzzk MurlocKing SC1 vs SC2 Cup #2
HCC Europe

Ongoing

BSL 20 Team Wars
KCM Race Survival 2025 Season 3
BSL 21 Points
ASL Season 20
CSL 2025 AUTUMN (S18)
LASL Season 20
RSL Revival: Season 2
Maestros of the Game
StarSeries Fall 2025
FISSURE Playground #2
BLAST Open Fall 2025
BLAST Open Fall Qual
Esports World Cup 2025
BLAST Bounty Fall 2025
BLAST Bounty Fall Qual
IEM Cologne 2025
FISSURE Playground #1

Upcoming

2025 Chongqing Offline CUP
BSL World Championship of Poland 2025
IPSL Winter 2025-26
BSL Season 21
SC4ALL: Brood War
BSL 21 Team A
Stellar Fest
SC4ALL: StarCraft II
EC S1
ESL Impact League Season 8
SL Budapest Major 2025
BLAST Rivals Fall 2025
IEM Chengdu 2025
PGL Masters Bucharest 2025
Thunderpick World Champ.
CS Asia Championships 2025
ESL Pro League S22
TLPD

1. ByuN
2. TY
3. Dark
4. Solar
5. Stats
6. Nerchio
7. sOs
8. soO
9. INnoVation
10. Elazer
1. Rain
2. Flash
3. EffOrt
4. Last
5. Bisu
6. Soulkey
7. Mini
8. Sharp
Sidebar Settings...

Advertising | Privacy Policy | Terms Of Use | Contact Us

Original banner artwork: Jim Warren
The contents of this webpage are copyright © 2025 TLnet. All Rights Reserved.