WoW: Blizzard Authenticator?

GEC: Discuss gaming, computers and electronics and venture into the bizarre world of STGODs.

Moderator: Thanas

Post Reply
User avatar
Sir Sirius
Sith Devotee
Posts: 2975
Joined: 2002-12-09 12:15pm
Location: 6 hr 45 min R.A. and -16 degrees 43 minutes declination

WoW: Blizzard Authenticator?

Post by Sir Sirius »

Does anyone know how secure these authenticator tokens are? Link.
Image
User avatar
Teleros
Jedi Council Member
Posts: 1544
Joined: 2006-03-31 02:11pm
Location: Ultra Prime, Klovia
Contact:

Re: WoW: Blizzard Authenticator?

Post by Teleros »

It just generates a 6-digit code to put in after your username & password (and register the authenticator with your account). Basically another layer of security in case someone gets your password, although 6 digits means it's only a million possible combinations :P .
User avatar
Graeme Dice
Jedi Master
Posts: 1344
Joined: 2002-07-04 02:10am
Location: Edmonton

Re: WoW: Blizzard Authenticator?

Post by Graeme Dice »

Sir Sirius wrote:Does anyone know how secure these authenticator tokens are? Link.
They are as secure as the tokens themselves are. If you don't have it plugged into your machine, you won't be able to play your account, and neither will anyone else. There's no conceivable way to predict what the next sequence of numbers the dongle will produce is without actually pressing the button, so your account is essentially safe.
"I have also a paper afloat, with an electromagnetic theory of light, which, till I am convinced to the contrary, I hold to be great guns."
-- James Clerk Maxwell (1831-1879) Scottish physicist. In a letter to C. H. Cay, 5 January 1865.
User avatar
Beowulf
The Patrician
Posts: 10621
Joined: 2002-07-04 01:18am
Location: 32ULV

Re: WoW: Blizzard Authenticator?

Post by Beowulf »

Teleros wrote:It just generates a 6-digit code to put in after your username & password (and register the authenticator with your account). Basically another layer of security in case someone gets your password, although 6 digits means it's only a million possible combinations :P .
True, it's only a million possible combinations, but it's not bruteforcable. It changes, making it impossible to do so.
"preemptive killing of cops might not be such a bad idea from a personal saftey[sic] standpoint..." --Keevan Colton
"There's a word for bias you can't see: Yours." -- William Saletan
User avatar
D.Turtle
Jedi Council Member
Posts: 1909
Joined: 2002-07-26 08:08am
Location: Bochum, Germany

Re: WoW: Blizzard Authenticator?

Post by D.Turtle »

Now if they would allow you to pay with something else besides credit cards (which very many people do not use in Germany), I would own one of these things...
User avatar
Sir Sirius
Sith Devotee
Posts: 2975
Joined: 2002-12-09 12:15pm
Location: 6 hr 45 min R.A. and -16 degrees 43 minutes declination

Re: WoW: Blizzard Authenticator?

Post by Sir Sirius »

Graeme Dice wrote:They are as secure as the tokens themselves are. If you don't have it plugged into your machine, you won't be able to play your account, and neither will anyone else. There's no conceivable way to predict what the next sequence of numbers the dongle will produce is without actually pressing the button, so your account is essentially safe.
It doesn't actually plug in to the computer, you just push a button and type the code in when requested.
Image
User avatar
charlemagne
Jedi Knight
Posts: 924
Joined: 2008-10-13 02:28am
Location: Regensburg, Germany

Re: WoW: Blizzard Authenticator?

Post by charlemagne »

Why would one need one of those? Are all WoW-accounts hacked on a regular basis, or what?
Image
User avatar
Mr Bean
Lord of Irony
Posts: 22463
Joined: 2002-07-04 08:36am

Re: WoW: Blizzard Authenticator?

Post by Mr Bean »

charlemagne wrote:Why would one need one of those? Are all WoW-accounts hacked on a regular basis, or what?
Stealing a WoW account is good money. A nice HL account stripped of items and golds can yield anywhere from 50$ to 1000$ if they can redo the account details and Ebay it off.

"A cult is a religion with no political power." -Tom Wolfe
Pardon me for sounding like a dick, but I'm playing the tiniest violin in the world right now-Dalton
User avatar
Spyder
Sith Marauder
Posts: 4465
Joined: 2002-09-03 03:23am
Location: Wellington, New Zealand
Contact:

Re: WoW: Blizzard Authenticator?

Post by Spyder »

Many companies use hardware tokens like these for VPN authentication. As long as Blizzard provide real time support for when the tokens go out of sync there shouldn't be a problem.

As for the security, you could create a virtual key if you had the algorithm used to generate the codes, the serial number of the token, 2 consecutive codes and you were able to synchronise with the server. In other words, if you can't get your hands on the physical key then you're probably not getting through.
:D
User avatar
charlemagne
Jedi Knight
Posts: 924
Joined: 2008-10-13 02:28am
Location: Regensburg, Germany

Re: WoW: Blizzard Authenticator?

Post by charlemagne »

Mr Bean wrote: Stealing a WoW account is good money. A nice HL account stripped of items and golds can yield anywhere from 50$ to 1000$ if they can redo the account details and Ebay it off.
I see, didn't occur to me that this might be widespread. Boy I'm glad to be hooked to a niche MMORPG ;)
Image
User avatar
Broomstick
Emperor's Hand
Posts: 28846
Joined: 2004-01-02 07:04pm
Location: Industrial armpit of the US Midwest

Re: WoW: Blizzard Authenticator?

Post by Broomstick »

On the other hand, most accounts are hacked because the owners are dumbshits. They use paid leveling services, download hacks that may be virus-infested, and loan out their passwords to "friends". Yes, sometimes you can do everything right and still get your account stolen, but with so many idiots in the world the Bad Guys usually don't bother.
A life is like a garden. Perfect moments can be had, but not preserved, except in memory. Leonard Nimoy.

Now I did a job. I got nothing but trouble since I did it, not to mention more than a few unkind words as regard to my character so let me make this abundantly clear. I do the job. And then I get paid.- Malcolm Reynolds, Captain of Serenity, which sums up my feelings regarding the lawsuit discussed here.

If a free society cannot help the many who are poor, it cannot save the few who are rich. - John F. Kennedy

Sam Vimes Theory of Economic Injustice
User avatar
Gil Hamilton
Tipsy Space Birdie
Posts: 12962
Joined: 2002-07-04 05:47pm
Contact:

Re: WoW: Blizzard Authenticator?

Post by Gil Hamilton »

Broomstick wrote:On the other hand, most accounts are hacked because the owners are dumbshits. They use paid leveling services, download hacks that may be virus-infested, and loan out their passwords to "friends". Yes, sometimes you can do everything right and still get your account stolen, but with so many idiots in the world the Bad Guys usually don't bother.
It's easy enough to get a dumbass to download a keylogger program that they don't really need to try very hard to go out of their way to bust people.
"Show me an angel and I will paint you one." - Gustav Courbet

"Quetzalcoatl, plumed serpent of the Aztecs... you are a pussy." - Stephen Colbert

"Really, I'm jealous of how much smarter than me he is. I'm not an expert on anything and he's an expert on things he knows nothing about." - Me, concerning a bullshitter
Post Reply