TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Important Security Update (Battle.net user information compromised)

45 pointsby chaudalmost 13 years ago

6 comments

NelsonMinaralmost 13 years ago
Valuable target. Battle.net is the login system for Warcraft and Diablo, both games where player accounts have significant cash value. The gold and items in a serious Warcraft player's account are often worth well over $50 and are relatively easy to strip and sell on a black market. Diablo 3 has a legitimized real money auction house, only heightening the risks for Blizzard.
simonbrownalmost 13 years ago
Is anyone familiar with the Secure Remote Password protocol, and how secure it is in comparison to hashing and salting passwords using algorithms like bcrypt and PBKDF2?
评论 #4364001 未加载
newman314almost 13 years ago
FWIW, this is Battle.net's password policy. <a href="http://imgur.com/q2oPZ" rel="nofollow">http://imgur.com/q2oPZ</a><p>It also appears that cut&#38;paste is disabled for the change password fields which is REALLY annoying.
评论 #4364984 未加载
评论 #4365155 未加载
评论 #4365156 未加载
adamzochowskialmost 13 years ago
How does this affect users with Key Fobs?<p><a href="http://us.blizzard.com/store/search.xml?q=authenticator" rel="nofollow">http://us.blizzard.com/store/search.xml?q=authenticator</a>
评论 #4364284 未加载
talon88almost 13 years ago
I'm be quite willing to bet that the attack vector was a compromised password that was reused to access their admin panel.
评论 #4363893 未加载
MordinSolusalmost 13 years ago
I don't quite understand the 16 character password limit.
评论 #4363912 未加载
评论 #4363941 未加载