Blizzard Sued over Battle.net Authentication


Recommended Posts

Dumb. #1 It's optional and not mandatory.

It is mandatory. Blizzard security is not first class. In fact this is probably one of the less secure online service around.

I got my battle.net account hacked even if i was using a perfectly secure password 10 random digits (numbers and letters with a cap and a special) that was unique. I did not have any keyloggers on my system and did not fall for any scam or phishing. All the addons was clean addons millions of people use like dbm and i downloaded them using my 2nd PC. Never bought money i farm my own things. The PC was clean as it is also my work PC and i never use it to browse sites that are not offcial or forums (like neowin) or to check hotmail or gmail. This is my work PC and it is used to work only (check my work emails, browse msdn and such) and also play games since it is a good machine. I use my 2nd less powerful PC to browse the web and do not so much secure things. I'm 100% sure the breach came from Blizzard side.

I never got hacked ever. Not before not after. Hotmail never hacked. Gmail never hacked. Guild Wars 1 and 2 never hacked. Live never hacked. I think most people using battle.net without an auth got hacked at least once.

I will honestly not shed a tear for Activision Blizzard after faction change. They got greedy and i would call this karma. Well deserved class action lawsuit.

i was forced to use one by blizzard after my account was comprimised or they wouldnt reinstate my account, and hell it was thier fault my account was comprimised not mine

I can't wait to hear your explanation as to how its Blizzard's fault your account was compromised.

I never got hacked ever. Not before not after. Hotmail never hacked. Gmail never hacked. Guild Wars 1 and 2 never hacked. Live never hacked. I think most people using battle.net without an auth got hacked at least once.

Yeah, not even close.

Since Blizzard doesn't even make passwords case sensitive, it opens everyone's accounts up to being hacked rather easily. Doesn't take long for people to brute force a password, especially when you don't have to do capital letters anywhere.

Blizzard has posted time and time agian, if you don't have an Authenticator, you are compromising your account. That if you do get hacked, it will be harder to get anything back because you "Didn't take ALL the avenues to secure it."

Due to blizzard basically saying in the past that an Authenticator is needed to keep your account secure, they have opened themselves up for this.

Doesn't matter what you think, because the law doesn't work that way. There is merit to this suit, although in reality, it is stupid.

capitals doesn't necessarily make your password safer.

password_strength.png

Sure it does. It adds an extra layer of protection. You could have horseapplestaplebattery, or you could have HorseaPPlestaPLEbatterY, which would make it even more complex. It doesn't make sense to leave an option out that only helps strengthen something.

Not sure the lawsuit makes sense, unless the guy wants restitution for the $4 or so it costs to get the authenticator. For those almighty people here saying that the hacking is "Your fault!" not Blizzards, you may want to research the issue and see how many people with and without authenticators have been hacked. I myself was hacked, and had a very very good password for the account as well as an authenticator; now, before you say "well, it had to be your computer!", i give you some info about my pc and me. I am an IT manager who has worked for companies such as Symantec IT internal department, MessageLabs IT internal department and now a private Chemical plant, again internal IT deparment....so with all that in mind, i have made sure that my PC IS as secure and clean as possible, not only for a stupid game, but also to make sure information on my pc is not compromised.

I also ran wow clean, without addons etc, and any updates were all downloaded using the client....so when my account got hacked, i made sure to do before calling blizzard a full forensic analysis of my machine, including firewall logs, av scans, spyware scans, etc, etc, etc......what i found was that my computer was clean, and my account was hacked either directly from Blizzard or my isp had some issues with man in the middle attacks, and blizzards traffic encryption had or has been compromised (do not know which).

So, going back to the suit.....smart? maybe, depends what the person wants, if he wants restitution for the authenticator then sure, have blizzard refund his $4 or so...anything else is a joke, although having blizzard change some of their warnings or making them give out warnings when something does happen like getting hacked would be nice.

While many times it's the user's fault for being hacked, there are times when they truly did nothing wrong.

I have 2 WoW accounts for example, both with strong unique passwords not used anywhere else. My main one has an authenticator on it, and was never hacked. My old one however, despite not being in use anymore, didn't have an authenticator. 2 years of having not logged into that account, I receive an email that the account has been suspended. Not exactly sure what the hell they did to break into the account, as my password was strong, unique, and hadn't even been used for 2 years...

Same thing happened to a friend of mine with his Guild Wars account.

So yeah, I'm quite under the belief that if you don't have an authenticator, you will likely be hacked eventually. Doesn't matter if hasn't happened thus far, it's still possible, even if your account isn't in use.

---

Anyway, I'm definitely no fan of Blizzard these days. Still, I think this case is just straight baloney. :sleep2:

While many times it's the user's fault for being hacked, there are times when they truly did nothing wrong.

I have 2 WoW accounts for example, both with strong unique passwords not used anywhere else. My main one has an authenticator on it, and was never hacked. My old one however, despite not being in use anymore, didn't have an authenticator. 2 years of having not logged into that account, I receive an email that the account has been suspended. Not exactly sure what the hell they did to break into the account, as my password was strong, unique, and hadn't even been used for 2 years...

Same thing happened to a friend of mine with his Guild Wars account.

So yeah, I'm quite under the belief that if you don't have an authenticator, you will likely be hacked eventually. Doesn't matter if hasn't happened thus far, it's still possible, even if your account isn't in use.

---

Anyway, I'm definitely no fan of Blizzard these days. Still, I think this case is just straight baloney. :sleep2:

Are you sure those weren't phishing emails like the ones every gets regardless of if they even play the game?

Are you sure those weren't phishing emails like the ones every gets regardless of if they even play the game?

No, but I do get those as well. I never open them, and they're properly placed in the spam section of Gmail. I worked with Blizzard to have the account restored, simply for the fact that it was my account and I didn't want anyone using it for whatever malicious purposes. Also slapped the iOS authenticator on it for (free) added safety.

Sure it does. It adds an extra layer of protection. You could have horseapplestaplebattery, or you could have HorseaPPlestaPLEbatterY, which would make it even more complex. It doesn't make sense to leave an option out that only helps strengthen something.

But it only makes it more complex to remember.

Are you sure those weren't phishing emails like the ones every gets regardless of if they even play the game?

I know in my case it wasn't. I know which ones are real/fake but even then, for ANY link dealing with accounts, I always check to see if the link is actually valid. I've never had anything hacked before.

This is pretty common with WoW. Lots of people I've known that practice good computer security stopped playing WoW and then had their accounts hacked (they didn't have authenticators). Authenticators are pretty much a requirement now or you're guaranteed to get hacked...

Not by much. And the added security can only help.

Not really, there's a level where security peaks and there's not really a point in adding further security anyway, and it does make it significantly harder to remember when random stuff in the password is upper cased.

Personally my password isn't technically nearly as complex as the base password there. but in reality it's more secure and shorter and doesn't rely on any special cases, and I don't get hacked.

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • But the reality is it will work for people's needs, and they don't care about the technology that makes it. Clearly not everyone's needs, but that low end space where personal laptops were only used to type emails, watch content and browse websites, but they didn't want to do that on a small screen device. Heck, writing that out I can now see the connection and reason it'll do so well. Apple is about experience. If the experience is bad, they don't release it. Low end Windows laptop manufacturers up until this point have not taken that into consideration ever before, so slow laggy usage with brittle slimey plastic shells were common. I hope that the low end space at least creates better physical products that last a bit longer, and if Microsoft get their act together, they could also have a solid OS on such low end hardware that would actually make the experience work for what the hardware was intended for. The fact that the CPU is a "cellphone", sorry mobile phone processor is irrelevant. It's about the experience, and so far, that sounds quite solid.
    • Hello, Bonjour is Apple's implementation of a multicast-DNS service, which allows devices running Apple's software and/or hardware to find each other on your local network.  I believe the Windows version was last updated around 2010. If you do not need it, you can stop and disable the Bonjour service in the Services Control Manager (filename: SERVICES.MSC).  Once you have done that, the operating system will no longer attempt to load the service. Regards, Aryeh Goretsky  
    • This AMD RX 9070 16GB GPU that performs close to Nvidia 5070 is under $600 by Sayan Sen With the memory shortage that's prevalent nowadays, discounts are super-hard to get. As such we post good deals whenever they pop up. Recently, we covered a few great discounts on SSDs wherein you can get a 4TB TeamGroup NVMe PCIe Gen4 drive for just $400 thanks to a special coupon. If you want a faster product but don't need all that capacity, you can also opt for Samsung's 990 PRO 2TB that is on sale for its lowest price in over three months. Let's say though that you are on the hunt for a 1440p gaming card. In that case AMD's RX 9070 non-XT can help, and with its 16GB VRAM, you can also run AI models locally without worrying about bottlenecking (check out our recent 9070 GRE reviews for gaming and productivity to get an idea). The PowerColor Reaper variant of the RX 9070 is currently on sale for just $580 which is a very good price in the current state of affairs (purchase link under the specs table down below). The Reaper cooler on this 9070 uses a triple‑fan design with ring‑blade fans, paired with premium dual ball bearings to extend lifespan and reduce friction. "Intelligent" fan control allows the fans to remain idle at lower temperatures, only spinning up when the GPU is under load. A nickel‑plated copper base makes direct contact with both the GPU and memory modules, helping to spread heat evenly. PowerColor also applies Honeywell PTM7950 phase‑change thermal interface material (TIM), which fills microscopic gaps between the die and heatsink for more efficient thermal transfer. The fan shroud is shorter in height as the firm has made it such that it can be used in certain SFF (small form factor) cases. The technical specifications of the Reaper RX 9070 are given in the table below: Specification Value Stream Processors 3584 Units Video Memory 16GB GDDR6 Memory Speed 20.0 Gbps Memory Interface 256-bit Engine Clock Game Clock: up to 2070 MHz Boost Clock: up to 2520 MHz Bus Standard PCI Express 5.0 x16 Display Connectors 1 x HDMI 2.1b, 3 x DisplayPort 2.1a Maximum Resolution DisplayPort: 7680 × 4320 HDMI: 7680 × 4320 Board Dimensions 289mm × 111mm × 41mm 304mm × 127mm × 42mm (with bracket) Slot 2 Minimum System Power Requirement 600W Power Connectors Two 8-pin PCI Express Get the PowerColor Reaper RX 9070 at the links below (you get only a 90-day warranty on Woot): PowerColor Reaper Radeon RX 9070 16GB Graphics Card (RX9070 16G-A): $579.99 (Sold and Shipped by Amazon US) (Was: $700) PowerColor Reaper Radeon RX 9070 16GB Graphics Card (RX9070 16G-A): $559.99 (Sold and Shipped by Woot US) Good to know This Amazon deal is U.S. specific, and not available in other regions unless specified. We only use first-party seller links (at the time of article publishing); ensure that you purchase from a first-party seller link only. Check out Today's Deals on Amazon | or our recent tech deals. Become a Prime member (for Students or SNAP) via Neowin Get Prime Access - Prime for half price (for qualifying Medicaid, EBT, SNAP) Subscribe to Prime Video, Audible Plus, Music Unlimited or Kindle Unlimited via Neowin As an Amazon Associate, we earn from qualifying purchases.
    • Are they marketed as an entry into astronomy or astrophotography? I do astrophotography. With big rigs, lots of computers, cables and headaches. I love it. And by learning this ridiculously complex hobby, I’ve learned about the objects I’m shooting. Astronomy followed from photography.
    • Microsoft confirms Recycle Bin bug across all versions of Windows by Usama Jawad A couple of days ago, we reported that the latest Patch Tuesday update has seemingly resulted in a lot of issues for many users, including OneDrive and Dropbox access problems, BitLocker recovery lockouts, and BSODs. Although Microsoft is yet to acknowledge these bugs, it has confirmed another, relatively smaller issue across all supported versions of Windows. In an update on its Windows Release Health Dashboard, Microsoft has confirmed that after installing June's Patch Tuesday update (KB5094126), you'll experience unexpected behavior when leveraging Recycle Bin. Basically, when you attempt to delete an item from the Recycle Bin, the confirm dialog will show you the internal file name of that content rather than the actual name. For example, the file may be named abc.png, but the confirm dialog will ask if you're sure that you want to permanently delete $Rxxxxx.png from the Recycle Bin. This is pretty much it for the scope of the bug itself; it just displays the wrong name in the confirm dialog. The correct name will be shown in the list view of the Recycle Bin and if you restore the file, it will return with the correct name as well. This issue affects pretty much all supported versions of Windows client and server, including: Client: Windows 11, version 26H1; Windows 11, version 25H2; Windows 11, version 24H2; Windows 11, version 23H2; Windows 10, version 22H2; Windows 10 Enterprise LTSC 2021; Windows 10 Enterprise LTSC 2019; Windows 10 Enterprise LTSB 2016 Server: Windows Server 2025; Windows Server 2022; Windows Server 2019; Windows Server 2016; Windows Server 2012 R2; Windows Server 2012 As things currently stand, Microsoft is working on a concrete solution that will be released in a "future" Windows update. It remains to be seen if the firm will wait till the next Patch Tuesday or roll out an out-of-band (OOB) fix. The good news is that commercial customers can deploy a workaround right now, but they will have to reach out to Microsoft Support for Business for additional details.
  • Recent Achievements

    • Week One Done
      Jordan Smith earned a badge
      Week One Done
    • Reacting Well
      BizSAR earned a badge
      Reacting Well
    • First Post
      AndreaB earned a badge
      First Post
    • Week One Done
      Huge Trailer earned a badge
      Week One Done
    • Week One Done
      Classifyskilleducation earned a badge
      Week One Done
  • Popular Contributors

    1. 1
      +primortal
      578
    2. 2
      +Edouard
      184
    3. 3
      PsYcHoKiLLa
      75
    4. 4
      Michael Scrip
      72
    5. 5
      neufuse
      64
  • Tell a friend

    Love Neowin? Tell a friend!