Blizzard Responds to Diablo 3 Account Hacks

Latest Videos FromTom's Hardware
Kevin Parrish
Contributor

Kevin Parrish has over a decade of experience as a writer, editor, and product tester. His work focused on computer hardware, networking equipment, smartphones, tablets, gaming consoles, and other internet-connected devices. His work has appeared in Tom's Hardware, Tom's Guide, Maximum PC, Digital Trends, Android Authority, How-To Geek, Lifewire, and others.

  • Either it is the lack of an authenticator or Blizzard just put their foot into their mouth. It would be most amusing it were the latter. Maybe then they would stop thinking that their system as it is, is flawless.
    Reply
  • SinisterSalad
    Allowing offline use would be the best way to counter this.
    Reply
  • seroism
    Blizzard knows it's happening but doesn't want to acknowledge it. They're trying desperately to fix the problem before the RMAH is launched. My money is on the hackers....
    Reply
  • DoofusOfDeath
    Would the man-in-the-middle attack be avoided if D3 used SSL ?
    Reply
  • DroKing
    Why are they talking out of their asses? They've had WoW for how long? Enough said.
    Reply
  • djscribbles
    Some of the rumors floating around point to joining a public game (which gives the hacker access to your session id, which he can then spoof) as being all that is needed to be hacked.
    Maybe true, maybe not, but I'm not going to go try to find any new friends until this dies down.

    Another rumored cause is people infected with malware that lets a hacker use their PC as a proxy server to bypass their authenticator which is configured to "not ask every time" mode, the hacker would be able to login without authentication because the request is coming from the victims own infected PC.

    Personally, I think this is a huge risk to blizzards reputation, I sure hope they are willing to admit if the vulnerability is on their side, and get it fixed soon. Personally I think this seems way too 'big' to be a bunch of schmoes with PC's loaded with malware, but it would be possible they have been saving up a big list of targets, as battlenet accounts were around long before diablo3 launched, and there is likely a large intersection between diablo3 players, wow players, and SC3 players.
    Reply
  • bgaimur
    http://imgur.com/oGxWd

    This picture sums up the entire situation. By the way, that picture proves it's Blizzard's fault.
    Reply
  • maxinexus
    Play with the someone you know.
    Reply
  • bgaimur
    DoofusOfDeathWould the man-in-the-middle attack be avoided if D3 used SSL ?Using SSL on a d3 session would be about as useful as putting a password on a telnet session. If you need to ask why, just take my word for it. No.
    Reply
  • spookyman
    Its a shame you can play this game like the original Diablo. It was great to play on a local area network at work and play with friends without having to log on to the internet.

    As for the account problems. How hard is it to secure your account?

    Could they use WoW as a guide on account security.
    Reply