Teddy wrote on May 23, 2012, 00:40:
Kitkoan wrote on May 22, 2012, 21:29:
In short, its your fault if our security is broken, thanks for the money.
Not to mention, they totally dodged the issue. So, what happened with this? A lot of accounts got hacked, why? Your security at fault or the users security at fault? What steps are being taken to prevent further problems? Are their steps being taken? Is it being looked into? Or are you just going to point at the Authenticator and hope the problem goes away?
Here's someone that's never had to deal with account security before.
General tip for you, it's almost ALWAYS the user's fault when it comes to security breaches, whether it's games or network security within companies. Users choose poorly constructed passwords, re-use passwords over and over, release their information constantly to phishing scams and other unseemly sources, get viruses on their home machines that consistently need to be weeded out as they transfer files in.
You can protect against direct breaches of your own system. You can't protect against stupid users that don't maintain their own security. That goes for Blizzard just the same as it goes for any other company out there.
Short of Blizzard taking control of your computer and filtering or blocking out any questionable websites for you, what exactly would you like them to do?
Its not almost ALWAYS the users fault. Many times its an inside job, more so when money is involved. And while many users don't always use the best security skills, its seems like there might be more to this to see a sudden jump in these hijacked accounts.
As for what can Blizzard do? Well I mentioned that in another post. Their systems can make note of IP locations when the user logs in. If someone who last logged in 2 hours ago in the state of New York is now suddenly logging in from Washington, flags should go up. The Warden program should also send warnings off that it is sending information to Blizzards systems from the same system but with different account information in a short span of time.
Are the IP connections coming from in the country or out?
Is a character giving 90%+ of its equipment and/or gold to another account and receiving little to nothing back in the trade? Does this person have a history with the character they are giving these items/gold to? People don't randomly give all their worn equipment/gold to a random stranger in these games, this is unusual behaviour and should at least be noted by the system and have the items/gold noted with a GM-only-seeable tag to keep dibs on it to see if something is up).
Is the character that is getting the items/receiving all this gear from strangers doing it to more then 10 accounts in a short time span? This should make a notice go to a GM to start looking at the account. Blizzard keeps a record log of all communications in game and if one account, not character but account, is getting 90%+ of random players equipment and/or gold without any chatting between them and have no past records of being in touch through the account (WoW, SC2, D3 in the past), this should be looked into.
A system can have many flags in place to look for unusual behaviour that should at least try to get a GM's attention to watch for this kinda of stuff.
*automatically refuses to place horse heads in anyone's bed*