Tuesday 8 July 2008

WoW Account Lockdown

Finally, after 4 years, Blizzard have figured out how to make you immune* to keyloggers.

Let me introduce you to The Blizzard Authenticator available on the new Blizzard Store; a two factor authentication device that gives you a one time passcode in addition to your usual username/password login.

What you do is buy this Authenticator for £6 from the Blizzard Store. When it arrives you need to tie it to your account (or accounts) through the account administration area on the WoW website (presumably done with the serial number of the fob).

Now when you go to log into WoW you press a button and it will give you a randomly generated number produced with a combination of your unique seed and then time. Blizzard will then perform the same operation on the login servers because they have the time and your unique seed and if the 2 codes match then your in.

It's a one time code and it expires after 60-90 seconds. So even if a key loggger got hold of your password, account name and this passcode it is useless to them as the passcode has already expired.

So unless your are extremely unlucky and get hit by a "Man-in-the-Middle" attack then you are now secure from being hacked.

You keylogging gold selling account hacking bastards can die in a train wreck!

Unfortunately by the time I heard of this the Blizzard EU store had run out :(

*OK, 99.9% immune, whatever, a lot safer, look somewhere else for accurate figures ... blah!

No comments: