• Log InLog In
  • Register
Liquid`
Team Liquid Liquipedia
EDT 13:56
CEST 19:56
KST 02:56
  • Home
  • Forum
  • Calendar
  • Streams
  • Liquipedia
  • Features
  • Store
  • EPT
  • TL+
  • StarCraft 2
  • Brood War
  • Smash
  • Heroes
  • Counter-Strike
  • Overwatch
  • Liquibet
  • Fantasy StarCraft
  • TLPD
  • StarCraft 2
  • Brood War
  • Blogs
Forum Sidebar
Events/Features
News
Featured News
[ASL22] Ro4 Preview: Mirror Mirror6[ASL22] Ro8 Preview: Within Reach5[ASL22] Ro8 Preview: In A Tizzy11[ASL22] Ro16 Preview: Holy Diver5[ASL22] Ro16 Preview: Rough Waters10
Community News
Rollback Netcode in Brood War645.0.17 Patch Notes - October 7, 202621Weekly Cups Results (Sep 28-Oct 4)0SC4ALL: II SC2 Complete Invited Player Lineup10StarCraft II 5.0.17 PTR Patch Notes (Sept 30, 2026)78
StarCraft 2
General
5.0.17 Patch Notes - October 7, 2026 [Old] StarCraft 3 Reportedly in Development StarCraft II 5.0.17 PTR Patch Notes (Sept 30, 2026) How do you feel about the mass reverts in the 5.0.17 PTR? Weekly Cups Results (Sep 28-Oct 4)
Tourneys
RSL 2026 Offline Finals LCQ Sign-Ups $3,500 WardiTV Not-Summer Championship ScienceCraft (October 24-25) - Live Event Stellar Fest TWO the Moon (Dec 16-20) ISSL (IntoTheTV x SOOP SC2 League): Premier
Strategy
[H] ZvP Mid-Late Game: Stalkers Collossi HT
Custom Maps
[M] (2) Sweltering Sands [M] (2) Frigid Storage
External Content
Mutation # 546 Catch the Train The PondCast: SC2 News & Results Mutation # 545 And Drops and Rifts Mutation # 544 Double Trouble
Brood War
General
BW General Discussion Sagi.gg Launcher Released ChatGPT cheats at StarSkirmish SCAI tournament Rollback Netcode in Brood War TL Sidebar missing streams
Tourneys
[Megathread] Daily Proleagues [ASL22] Semifinal A [ASL22] Semifinal B [ASL22] Ro8 Day 4
Strategy
Simple Questions, Simple Answers Cliff Jump Revisited (1 in a 1000 strategy) Replay Review Process - What do you do?
Other Games
General Games
Stormgate/Frost Giant Megathread Nintendo Switch Thread General RTS Discussion Thread Warcraft III: The Frozen Throne Total Annihilation Zero
Dota 2
Dota 2 Champions League Season 3 Begins April 25!
League of Legends
[TL LoL EUW IHs] Teemo shall perish
Heroes of the Storm
Heroes of the Storm 2.0
Hearthstone
Deck construction bug
TL Mafia
TL Mafia Community Thread
Community
General
US Politics Mega-thread Canadian Politics Mega-thread Things Aren’t Peaceful in Palestine Russo-Ukrainian War Thread Artificial Intelligence Thread
Fan Clubs
Serral Fan Club
Media & Entertainment
[Manga] One Piece Movie Discussion! Diablo Animated Series on Netflix
Sports
Football (Soccer) Thread TeamLiquid Health and Fitness Initiative For 2023 MLB/Baseball 2023
World Cup 2022
Tech Support
Computer Build, Upgrade & Buying Resource Thread
TL Community
Recent Gifted Posts
Blogs
The Link Between Gaming and …
TrAiDoS
[ASL22] Ro4 Day1 Ticket Giv…
bITt.mAN
38 yo Retired SWE loo…
PurE)Rabbit-SF
Can Bots Beat Pros?? Starcr…
namkraft
[meme] I finally understa…
LUCKY_NOOB
Customize Sidebar...

Website Feedback

Closed Threads



Active: 11930 users

Blizzard Security Breach - Page 5

Forum Index > SC2 General
442 CommentsPost a Reply
Prev 1 2 3 4 5 6 7 21 22 23 Next All
netherh
Profile Blog Joined November 2011
United Kingdom333 Posts
August 09 2012 23:30 GMT
#81
It's lucky they don't do anything stupid like make all the passwords case insensitive... Oh wait.
-RusH
Profile Joined June 2012
United States240 Posts
August 09 2012 23:31 GMT
#82
I can't seem to find how to edit the secret question/answer. Anyone know where?
Life..
Eufouria
Profile Blog Joined March 2011
United Kingdom4425 Posts
Last Edited: 2012-08-09 23:32:10
August 09 2012 23:31 GMT
#83
On August 10 2012 08:26 R1CH wrote:
Show nested quote +
On August 10 2012 08:22 BadgerBadger8264 wrote:
On August 10 2012 07:38 Probe1 wrote:
So change your passwords. Got it.

(Before anyone says "Oh no Probe u sux at reading", cryptographically scrambled versions.. do you trust your account and information on that? Do you?")


Not saying you shouldn't change your password just to be completely sure, but if you'd know anything about the hashes used to encrypt passwords and how long it takes to decipher even a single password you would know that it's practically impossible for the people that have stolen the hash to obtain even a single password from that information within a month (and even that is stretching it as they'd need a cluster of powerful machines brute forcing the hash constantly for the duration), let alone retrieving a decent amount of stolen passwords. It's honestly not even close to being worth the power/rental costs of doing so to obtain an account worth maybe 100$. This is obviously assuming Blizzard doesn't use horribly outdated encryption, though.

I don't think you're aware of how password hashing works. Do you not think there are millions of people with "password123" or equally terrible passwords in those stolen hashes? Why would you need a month to break that?

Its so bad nobody would ever use it, so hackers won't even try it. Metagame.

So can we all expect to be added to a bunch more spam email lists because of this?
BadgerBadger8264
Profile Joined March 2011
Netherlands409 Posts
Last Edited: 2012-08-09 23:35:57
August 09 2012 23:32 GMT
#84
On August 10 2012 08:26 R1CH wrote:
Show nested quote +
On August 10 2012 08:22 BadgerBadger8264 wrote:
On August 10 2012 07:38 Probe1 wrote:
So change your passwords. Got it.

(Before anyone says "Oh no Probe u sux at reading", cryptographically scrambled versions.. do you trust your account and information on that? Do you?")


Not saying you shouldn't change your password just to be completely sure, but if you'd know anything about the hashes used to encrypt passwords and how long it takes to decipher even a single password you would know that it's practically impossible for the people that have stolen the hash to obtain even a single password from that information within a month (and even that is stretching it as they'd need a cluster of powerful machines brute forcing the hash constantly for the duration), let alone retrieving a decent amount of stolen passwords. It's honestly not even close to being worth the power/rental costs of doing so to obtain an account worth maybe 100$. This is obviously assuming Blizzard doesn't use horribly outdated encryption, though.

I don't think you're aware of how password hashing works. Do you not think there are millions of people with "password123" or equally terrible passwords in those stolen hashes? Why would you need a month to break that?


Typically passwords are hashed in combination with a username and other information. You can't simply hash "password123" and have thousands of results turn up. You'd have to know the hashing algorithm used by Blizzard, then for every individual user, hash "password123" and compare it to the stored hash. That still obviously wouldn't take a month to do with a single password, so you're right that it is probably feasible to do that for very common passwords and obtain a good amount of accounts. Still, if your password is even remotely unique, they will never realistically obtain it.
sour_eraser
Profile Joined March 2011
Canada932 Posts
Last Edited: 2012-08-09 23:34:21
August 09 2012 23:32 GMT
#85
Ehh. Doesnt really affect me much considering I have diff passwords for all my email and other games. lol
But I want to know if we need to know Previous Answer to Secret Question when they force us change it into new one. I forgot mine :/
"What's the f*cking point of censoring a letter if everyone and their mother knows what it stands for.... F*cking morons"
VPVanek
Profile Joined August 2010
Canada238 Posts
August 09 2012 23:33 GMT
#86
Well I guess I am changing my password now ahahah
FoXer
Crying
Profile Joined February 2011
Bulgaria778 Posts
August 09 2012 23:33 GMT
#87
On August 10 2012 08:31 -RusH wrote:
I can't seem to find how to edit the secret question/answer. Anyone know where?

i think the security question is not changeable.
Determination~ Hard Work Surpass NATURAL GENIUS!
thatsundowner
Profile Joined July 2011
Canada312 Posts
August 09 2012 23:33 GMT
#88
On August 10 2012 08:30 netherh wrote:
It's lucky they don't do anything stupid like make all the passwords case insensitive... Oh wait.


if somebody gets the password case sensitivity is irrelevant and brute forcing is not how the vast majority of stolen b.net accounts are taken. it's kind of an irrelevant thing, and not a big deal at all that they don't do it
"you're gonna fail" in latin
entropius
Profile Joined June 2010
United States1046 Posts
August 09 2012 23:37 GMT
#89
On August 10 2012 08:26 R1CH wrote:
Show nested quote +
On August 10 2012 08:22 BadgerBadger8264 wrote:
On August 10 2012 07:38 Probe1 wrote:
So change your passwords. Got it.

(Before anyone says "Oh no Probe u sux at reading", cryptographically scrambled versions.. do you trust your account and information on that? Do you?")


Not saying you shouldn't change your password just to be completely sure, but if you'd know anything about the hashes used to encrypt passwords and how long it takes to decipher even a single password you would know that it's practically impossible for the people that have stolen the hash to obtain even a single password from that information within a month (and even that is stretching it as they'd need a cluster of powerful machines brute forcing the hash constantly for the duration), let alone retrieving a decent amount of stolen passwords. It's honestly not even close to being worth the power/rental costs of doing so to obtain an account worth maybe 100$. This is obviously assuming Blizzard doesn't use horribly outdated encryption, though.

I don't think you're aware of how password hashing works. Do you not think there are millions of people with "password123" or equally terrible passwords in those stolen hashes? Why would you need a month to break that?


Wouldn't salting the hashes make this sort of thing impossible? I have in mind the sort of attack where the attacker computes the hash of "password123" and compares it to all the hashes to see if it matches any of them (which is only O(log N)), which would be foiled by salts -- in that case they've got to do the hash algorithm N times instead of just once to check N hashes against each dictionary word. Of course, if the passwords are suitably weak then you can probably afford this -- just check the simplest ones against all of them.

It's been a while since I studied this stuff, of course, so I could be wrong.
IM_Junior
Profile Joined April 2012
Mexico29 Posts
August 09 2012 23:38 GMT
#90
Thx in advance, password changed just to be safe for the moment !!!!
Zerg for life !!! --- DRG / Stephano / Leenock / Life and Nesteaaaaaa
Silidons
Profile Blog Joined September 2010
United States2813 Posts
August 09 2012 23:39 GMT
#91
I noticed that in the past 2 days or so, I went from getting ~5 spam mail a day on my bnet email to 20. I have an Auth and use different PW's for different things, but now I gotta change it >_<
"God fights on the side with the best artillery." - Napoleon Bonaparte
Maluk
Profile Joined August 2011
France987 Posts
Last Edited: 2012-08-09 23:43:52
August 09 2012 23:39 GMT
#92
Does anyone know if my credit card number is somewhere in Blizzard's datas if I used it only to buy StarCraft 2, and not for any monthly payment ?
Edit : Yes, my question probably sounds pretty noob but I am clueless concerning hacks t.t
ROOTIllusion
Profile Blog Joined August 2010
United States1060 Posts
August 09 2012 23:40 GMT
#93
Didnt something like this happen a year or so ago? damn hackers
www.twitter.com/rootillusion & www.facebook.com/illusionsc2
jnkw
Profile Joined November 2010
Canada347 Posts
August 09 2012 23:42 GMT
#94
On August 10 2012 08:37 entropius wrote:
Show nested quote +
On August 10 2012 08:26 R1CH wrote:
On August 10 2012 08:22 BadgerBadger8264 wrote:
On August 10 2012 07:38 Probe1 wrote:
So change your passwords. Got it.

(Before anyone says "Oh no Probe u sux at reading", cryptographically scrambled versions.. do you trust your account and information on that? Do you?")


Not saying you shouldn't change your password just to be completely sure, but if you'd know anything about the hashes used to encrypt passwords and how long it takes to decipher even a single password you would know that it's practically impossible for the people that have stolen the hash to obtain even a single password from that information within a month (and even that is stretching it as they'd need a cluster of powerful machines brute forcing the hash constantly for the duration), let alone retrieving a decent amount of stolen passwords. It's honestly not even close to being worth the power/rental costs of doing so to obtain an account worth maybe 100$. This is obviously assuming Blizzard doesn't use horribly outdated encryption, though.

I don't think you're aware of how password hashing works. Do you not think there are millions of people with "password123" or equally terrible passwords in those stolen hashes? Why would you need a month to break that?


Wouldn't salting the hashes make this sort of thing impossible? I have in mind the sort of attack where the attacker computes the hash of "password123" and compares it to all the hashes to see if it matches any of them (which is only O(log N)), which would be foiled by salts -- in that case they've got to do the hash algorithm N times instead of just once to check N hashes against each dictionary word. Of course, if the passwords are suitably weak then you can probably afford this -- just check the simplest ones against all of them.

It's been a while since I studied this stuff, of course, so I could be wrong.


Given that there exist many extremely common passwords like 'password', it is not unreasonable to assume that rainbow tables might exist for a large number of possible salts per common password.
EleanorRIgby
Profile Joined March 2008
Canada3923 Posts
August 09 2012 23:43 GMT
#95
damn this sucks but i think hackers usually go for wow/d3 accounts, sc2 accounts are probably the least profitable
savior did nothing wrong
Kambing
Profile Joined May 2010
United States1176 Posts
August 09 2012 23:43 GMT
#96
On August 10 2012 08:37 entropius wrote:
Show nested quote +
On August 10 2012 08:26 R1CH wrote:
On August 10 2012 08:22 BadgerBadger8264 wrote:
On August 10 2012 07:38 Probe1 wrote:
So change your passwords. Got it.

(Before anyone says "Oh no Probe u sux at reading", cryptographically scrambled versions.. do you trust your account and information on that? Do you?")


Not saying you shouldn't change your password just to be completely sure, but if you'd know anything about the hashes used to encrypt passwords and how long it takes to decipher even a single password you would know that it's practically impossible for the people that have stolen the hash to obtain even a single password from that information within a month (and even that is stretching it as they'd need a cluster of powerful machines brute forcing the hash constantly for the duration), let alone retrieving a decent amount of stolen passwords. It's honestly not even close to being worth the power/rental costs of doing so to obtain an account worth maybe 100$. This is obviously assuming Blizzard doesn't use horribly outdated encryption, though.

I don't think you're aware of how password hashing works. Do you not think there are millions of people with "password123" or equally terrible passwords in those stolen hashes? Why would you need a month to break that?


Wouldn't salting the hashes make this sort of thing impossible? I have in mind the sort of attack where the attacker computes the hash of "password123" and compares it to all the hashes to see if it matches any of them (which is only O(log N)), which would be foiled by salts -- in that case they've got to do the hash algorithm N times instead of just once to check N hashes against each dictionary word. Of course, if the passwords are suitably weak then you can probably afford this -- just check the simplest ones against all of them.

It's been a while since I studied this stuff, of course, so I could be wrong.


Not necessarily, e.g., http://www.openwall.com/john/.

Passwords in practice are frequently suitably weak and amendable to cracking (e.g., via a dictionary attack). Knowing how the passwords were salted --- or at least narrowing it down to a small set of salting schemes --- makes things more tractable as well.

So theoretically intractable. Practically hard to do, but not impossible.
Pufftrees
Profile Joined March 2009
2449 Posts
August 09 2012 23:43 GMT
#97

This is just... unacceptable. What the flux.

+ Show Spoiler +
Blizzard is such a joke
Chance favors the prepared mind.
RoyGBiv_13
Profile Blog Joined August 2010
United States1275 Posts
August 09 2012 23:45 GMT
#98
I went to a talk at DEFCON about fuzzing d3, where they showed just how secure blizzard's password system is. I would not be worried about them breaking you password hash (a properly salted and hashed password is a difficult thing to unravel). The security questions are a real risk though.
Any sufficiently advanced technology is indistinguishable from magic
Dingobloo
Profile Blog Joined September 2010
Australia1903 Posts
Last Edited: 2012-08-09 23:46:54
August 09 2012 23:45 GMT
#99
On August 10 2012 08:37 entropius wrote:
Show nested quote +
On August 10 2012 08:26 R1CH wrote:
On August 10 2012 08:22 BadgerBadger8264 wrote:
On August 10 2012 07:38 Probe1 wrote:
So change your passwords. Got it.

(Before anyone says "Oh no Probe u sux at reading", cryptographically scrambled versions.. do you trust your account and information on that? Do you?")


Not saying you shouldn't change your password just to be completely sure, but if you'd know anything about the hashes used to encrypt passwords and how long it takes to decipher even a single password you would know that it's practically impossible for the people that have stolen the hash to obtain even a single password from that information within a month (and even that is stretching it as they'd need a cluster of powerful machines brute forcing the hash constantly for the duration), let alone retrieving a decent amount of stolen passwords. It's honestly not even close to being worth the power/rental costs of doing so to obtain an account worth maybe 100$. This is obviously assuming Blizzard doesn't use horribly outdated encryption, though.

I don't think you're aware of how password hashing works. Do you not think there are millions of people with "password123" or equally terrible passwords in those stolen hashes? Why would you need a month to break that?


Wouldn't salting the hashes make this sort of thing impossible? I have in mind the sort of attack where the attacker computes the hash of "password123" and compares it to all the hashes to see if it matches any of them (which is only O(log N)), which would be foiled by salts -- in that case they've got to do the hash algorithm N times instead of just once to check N hashes against each dictionary word. Of course, if the passwords are suitably weak then you can probably afford this -- just check the simplest ones against all of them.

It's been a while since I studied this stuff, of course, so I could be wrong.


They actually tell us the method by which they encrypt the passwords in the faq:

http://en.wikipedia.org/wiki/Secure_Remote_Password_protocol

It includes the username, password, salt and an unspecified hash function, so dictionary attacks aren't likely to be a problem.

Again, no guarantee's but they seem to have done due diligence with regards to making getting the actual password very difficult given just the hash.
Kambing
Profile Joined May 2010
United States1176 Posts
August 09 2012 23:45 GMT
#100
On August 10 2012 08:43 EleanorRIgby wrote:
damn this sucks but i think hackers usually go for wow/d3 accounts, sc2 accounts are probably the least profitable


Likely that they can't differentiate without cracking the account. And besides, your email address and secret answers can be enough to do damage. For example, some (badly designed) sites will let your reset a password immediately after you successfully answer a secret question without sending email to your account first.
Prev 1 2 3 4 5 6 7 21 22 23 Next All
Please log in or register to reply.
Live Events Refresh
Patches Events
00:00
Patch Clash S1 Special #1
RotterdaM1047
TKL 369
IndyStarCraft 307
Liquipedia
[ Submit Event ]
Live Streams
Refresh
StarCraft 2
RotterdaM 1047
ByuN 438
TKL 369
IndyStarCraft 307
Reynor 170
BRAT_OK 49
StarCraft: Brood War
Britney 51641
Calm 2727
Shuttle 448
actioN 171
firebathero 112
Mini 89
Mong 41
White-Ra 26
scan(afreeca) 18
Aegong 16
[ Show more ]
soO 16
Sacsri 6
Dota 2
Gorgc11094
Counter-Strike
fl0m6097
Heroes of the Storm
Grubby2520
Liquid`Hasu401
MindelVK11
Other Games
Liquid`RaSZi1991
FrodaN1342
B2W.Neo729
olofmeister516
Khaldor465
KnowMe313
crisheroes182
Livibee178
ToD94
Mew2King80
Organizations
Other Games
gamesdonequick367
BasetradeTV204
[ Show 19 non-featured ]
StarCraft 2
• Hinosc 32
• Adnapsc2 12
• Reevou 8
• niya90s 1
• AfreecaTV YouTube
• intothetv
• Kozan
• IndyKCrew
• Migwel
StarCraft: Brood War
• Airneanach77
• Azhi_Dahaki29
• BSLYoutube
• STPLYoutube
• ZZZeroYoutube
Dota 2
• WagamamaTV494
Counter-Strike
• C_a_k_e 1662
Other Games
• imaqtpie821
• Shiphtur645
• tFFMrPink 9
Upcoming Events
BSL Open Qualifier
1h 4m
BSL Open Qualifier
1h 4m
OSC
5h 4m
Replay Cast
5h 4m
OSC
18h 4m
WardiTV Weekly
1d 17h
PiGosaur Cup
2 days
Kung Fu Cup
2 days
The PondCast
3 days
Online Event
4 days
[ Show More ]
Korean StarCraft League
5 days
Afreeca Starleague
5 days
Rush vs Soulkey
CranKy Ducklings
5 days
BSL Open Qualifier
6 days
Sparkling Tuna Cup
6 days
Liquipedia Results

Completed

Acropolis #5 - GSB
Blizzard Classic Cup 2026
Copium Cup

Ongoing

ASL Season 22
Super Anchor Qualifying S3
Acropolis #5
HCC Season 3
ESL Pro League Season 24
Stake Ranked Episode 4
1win Private Club #1
Logitech G Play Connect 2026
SL StarSeries Fall 2026
FISSURE Playground #3
BLAST Open Fall 2026
Esports World Cup 2026
BLAST Bounty Summer 2026

Upcoming

Acropolis #5 - GSC
BSL Season 23
SC4ALL II: Brood War
BSL 23: Non-Korean Championship
HSC XXX
Stellar Fest 2: Lunar Cup
SC4ALL II: StarCraft II
Kung Fu Cup 2026 Grand Finals
RSL Offline Finals
eXTREMESLAND 2026
PGL Major Singapore 2026
Stake Ranked Episode 6
BLAST Rivals Fall 2026
IEM Beijing 2026
Stake Ranked Episode 5
PGL Masters Bucharest 2026
1win Private Club #2
Thunderpick World Champ. '26
TLPD

1. ByuN
2. TY
3. Dark
4. Solar
5. Stats
6. Nerchio
7. sOs
8. soO
9. INnoVation
10. Elazer
1. Rain
2. Flash
3. EffOrt
4. Last
5. Bisu
6. Soulkey
7. Mini
8. Sharp
Sidebar Settings...

Advertising | Privacy Policy | Terms Of Use | Contact Us

Original banner artwork: Jim Warren
The contents of this webpage are copyright © 2026 TLnet. All Rights Reserved.