|
|
Can anyone that has the authenticator confirm if they have been hacked or not? Although my account has not yet been compromised, many are still reporting having their accounts hacked.
If it is true that the authenticator makes no difference to whether an account can be hacked or not and if these more recent (as of 2 mins ago) claims of compromised accounts are genuine then BLIZZARD, you need to bring the servers down. |
|
|
I think that authenticator problem might be related to two things:
1. Mobile version only. It is possible to hack a mobile phone to get a serial number of a Authenticator. Also serial number might be stored on your mobile app store provider (true for Apple, don't know how's with Google). It's not related to keyring authenticator as serial number is stored only on Blizz's server and your pocket ;) 2. If you have turned off asking about authenticating number every time you're logging, it's possible to hack your machine and use it to break into your account as it won't require authentication from aready authenticated machine. |
|
|
Lost about a million gold (items, gems, materials) and 8 levels on a character. I got like 40% of my items and gold back after waiting an hour on the phone for some guy saying it's my fault and that I have a keylogger on my pc.
I've never been hacked nor scammed before. I have plenty of security on my pc. I got a brother who's a data technician. This here ain't my fault other then that I've played public game from where they got into my account somehow because there's an exploit in the game. Now I've lost hours of gameplay and dont really wanna play before there's a complete fix of this. I only got 1 out of 2 recovery left. Then I have to wait a year before getting 2 more. And as I can see it there's still a possibility that I get hacked again without even playing the game and after I've changed my password. And yes this is Blizz fault since they did not find that exploit. I'm mad and gj Blizz! |
|
|
AMK i got hacked off all my golds, I posted a ticket for account recovery and blizzard didn't even respond to it! thank you blizz for your security
Edited by Ronaldo#2982 on 23/05/2012 06:48 BST
|
|
|
Logged in today first time after sunday just to find my main character and stash emptied. Ive been playing online games since 1999 and never been a victim of online theft before.
Ive been always very careful with my account information and always used up-to-date antivir programs. I even used 2 different programs to scan my computer and nothing was found. Changed all my account information immediately and contacted support but no answer so far. Basically what was done is that one of my 2 characters was completely stripped and everything from stash was stolen. Also unknown name appeared in friends-list and my lvl24 character was found from act 4. I dont care if I ever get lost items back since it wasnt much. But reading LOT about similiar cases im starting to suspect that its not my end that has been compromised and would like to know what is going on. |
|
|
That's the usual policy - calming the users down until they actually acknowledge that the game has been indeed compromised.
As soon as you see people saying that they were hacked and that this has never happened to them before, you know something went terribly !@#$ing wrong. I myself was never hacked in 10 years, apart from one time when I have actually shared my password with someone. Thankfully, my account is intact, but if it were, I'd be certain that there's a leak in Blizz's servers. |
|
|
They get your email they get your account
|
|
I've had my account "hacked". Logged out last night at approx 11pm GMT, with my level 27 Monk, aptly named Monkeymagic :D I log in tonight after work at approximately 8pm to find the monk character completely empty. All gold, all items are gone.
Hilariously, Blizzard ticket response was a generic cut and paste effort claiming they can only do 2 rollbacks in a lifetime of the account, and I will lose progress. Also, the following I found particularly helpful: IMPORTANT - Please note that there will be progress lost, due to the fact that there is a limited amount of saved points that we can roll back from. VoShiX will be rolled back to level 55. This is why we are requesting your permission to continue, so that you are aware of the consequences. Nice of them to give me a new character 18 levels higher than the one I had.... The worst part is that they effectively insult me, with a blanket statement implying that they are not to blame, pasting passwords when the error 37 issue arose, and that I probably had keyloggers on my system. My system is absolutely spotless security wise, and is cleaned every single day on start up and shutdown, with me personally checking the system too (yes, I'm that paranoid). Basically they've accepted no responsibility for what looks to me like their servers being hacked. The only difference I can see is that my monk character was actively using the auction house, while my other character wasn't, which is conveniently fine. Strange that, if my account has been hacked, eh? Now I'm waiting for them to roll back my character from 27 to 55. Yes, this service was worth paying £70 for. |
|
|
Glad to hear blizz is claiming ignorance with the sheer number of reports. I have an authenticator and now will never play a public game again since blizz is being COMPLETELY ignorant. Better safe than sorry. Especially with thr RMAH right around the corner
|
|
|
To the people posting about having been hacked; you need to state whether you had the authenticator active or not. Blizzard have responded on the .us boards that there has yet to be an instance of an account with the authenticator active, being hacked. This has been confirmed by Blizz several times now.
|
|
5 Gnome Rogue
0
|
For those who haven't seen yet, Watched the video - he does mention that after he was hacked he got an authenticator - so we know that he wasnt using one before. So far we've seen players only claiming to have an authenticator active - and a Blizzard post stating there has been no confirmed cases where players had an authenticator attached before they were hacked. While the authenticator isn't a 100% guarantee of account security, we have yet to investigate a compromise report in which an authenticator was attached beforehand. - http://us.battle.net/d3/en/forum/topic/5149619846?page=29#571 Later someone does state "his brother" had an authenticator and was hacked - and the blue poster requests the battletag - oddly enough the player did not respond. It makes you wonder how many people have an authenticator but are not using it, or only quickly add one after the damage is done... At the end of the day being hacked is not a nice experience, whether it's failure to secure your own computer (very likely looking at the history of WoW accounts that have been hacked), some kind of exploit allowing the access (possible but absolutely no facts evidencing this yet), or that battle.net has been compromised (unlikely). Blizzard has provided the usual advice on securing your computer as they should. They are also still investigating. It certainly doesnt hurt to try different virus scanners or take those extra steps, if this turns out to be something more than your own computer that is not secure, Blizzard will respond and provide information. |
|
|
For those who haven't seen yet, LOL why does he needs to respond, battle tag is right there, visible like everyone else or I am that stupid ? |
|
|
[quote] 1. How do you know ? Btw even if it uses sessions it should be shared only with client <> server not with anyone else. |
|
|
I have to go with this too. I will openly state that I was alarmed by all the reports I have read these last few days, and whilst I will defend Blizzard when I think they are wrongly accused, I will not if I have facts proving the opposite. What I have seen... Statements like "my friend was hacked with an authenticator".. I have seen numerous gaming sites pushing the point that D3 accounts are being hacked and these press sites adding to the "people with authenticators" are being hacked. But I have yet to see one single person come forward and say "I was hacked with an authenticator and Blizzard can check I am telling the truth". Again, I was alarmed to begin with.. yet my account that has an authenticator seems to have been completely left alone. What I think has happened here is rumour mills, so called "Chinese whispers" (no pun intended) and press sites jumping to the same alarm state I did, but printing it... people read it, people believe it and one by one the community come together to form a lynch mob. Someone even started a thread on Tech for those hacked asking them to answer a few simple questions (well, 13 questions actually..) but one question was "Do you have an authenticator".. this was posted 7 hours ago... all the replies to this question thus far has been "No" or "No but I have one now". At least one positive thing has come of all this, players may not see themselves as infallable anymore and are investing more time and effort in their PC and account security. That can only be a good thing. Also, had Blizzard's security been breached, there are regulations stating that should any private information be compromised, full disclosure must be made, and if you think Blizzard ignore legal obligations, ask your friends in certain European countries that cant use RAF, even though it would make Blizzard hundreds of thousands, if not millions of Euros over the years if they ignored legal requirements.
Edited by Shammoz#2396 on 22/05/2012 23:40 BST
|
|
|
Am I missing something here?
Why should people have to buy authenticators (free app notwithstanding IF you have an iphone)? Steam manage to protect their customers pretty well, without charging them for it. It is Blizzard's responsibility to protect the customer, not the other way round. They provide the service and ask people to pay for it, therefore they have a duty of care to the customer. Hiding behind authenticators is just plain horse !@#$, and people need to stop being asked to swallow it. Can we please stop defending this company from their incompetence. That's bad enough, but to instead blame the customer is just plain insulting. I have no doubt that some people need to be more careful in general, but this is clearly an issue with Blizzard's systems being compromised on their end.
Edited by Lazygunn#2854 on 22/05/2012 23:51 BST
|
|
|
But this does not mean that Steam accounts don't get hacked, after all, it would be pointless to provide a help article on how to recover a hacked steam account if it doesn't happen... https://support.steampowered.com/kb_article.php?ref=2347-qdfn-4366 My post was certainly not to say that everyone that does not have an authenticator is asking for an account hack, I am dispelling the myth that a lot are posting in this thread that accounts with the authenticator have been hacked, there has been no proof of this at all. It is worth providing confidence to those that have invested in an auth that it is a sound investment, beacuse it simply is. Edit:
Again, there is legislation in place that states that if personal account information is compromised, full disclosure MUST be made. Just as Cryptic did a few weeks ago when they discovered a breach from over a year ago, they had to openly disclose it.
Edited by Shammoz#2396 on 22/05/2012 23:56 BST
|
|
|
What I have seen... http://www.examiner.com/article/accounts-on-diablo-3-hacked I'm sure the journalist Tara Swadley would glady come forward with those exact words. She had an authenticator yet still got hacked. Read her article. |
|
|
What I have seen... I've read that article, on a dozen or more websites.. maybe she will post in the US version of this thread as a willing guinea pig because she would be the first to come forward and as such would claim glory and I would then admit I am wrong should Blizzard check and agree that an auth was on her account. Until then, Press is press, I take more persuasion than that. Call me cynical but web press (as in paper) is all about getting the readers, the more sensational, the better... does not cut it with me, not when Blizzard are under the disclosure obligations that law requires.
Edited by Shammoz#2396 on 23/05/2012 00:00 BST
|
In addition to that, when Steam was hacked a few months ago, they had to disclose it as well. It is just the law. Not even the most powerful company in the world can deviate from such a law. |
|
|
I've got an authenticator and have yet to be hacked. Then again, I don't buy gold or use botting programs either so that may have something to do with it.
|
Threats of violence. We take these seriously and will alert the proper authorities.
Posts containing personal information about other players. This includes physical addresses, e-mail addresses, phone numbers, and inappropriate photos and/or videos.
Harassing or discriminatory language. This will not be tolerated.