<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: On Security</title>
	<atom:link href="http://marriedirl.com/2008/07/on-security/feed/" rel="self" type="application/rss+xml" />
	<link>http://marriedirl.com/2008/07/on-security/</link>
	<description>Gaming, Marriage and all the Fun Stuff Inbetween</description>
	<lastBuildDate>Sat, 15 May 2010 09:42:07 -0700</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.3</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Jack</title>
		<link>http://marriedirl.com/2008/07/on-security/comment-page-1/#comment-511</link>
		<dc:creator>Jack</dc:creator>
		<pubDate>Mon, 04 Aug 2008 17:33:33 +0000</pubDate>
		<guid isPermaLink="false">http://marriedirl.com/?p=65#comment-511</guid>
		<description>I&#039;ve activated my authenticator now....
As I see....
Authenticator is need for both login to play AND for web account managment.....

To detach the authenticator you have two methods...
If you have the authenticator and no longer want to use it.... just login in account managment and detach it

otherwise, call customer support</description>
		<content:encoded><![CDATA[<p>I&#8217;ve activated my authenticator now&#8230;.<br />
As I see&#8230;.<br />
Authenticator is need for both login to play AND for web account managment&#8230;..</p>
<p>To detach the authenticator you have two methods&#8230;<br />
If you have the authenticator and no longer want to use it&#8230;. just login in account managment and detach it</p>
<p>otherwise, call customer support</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: me</title>
		<link>http://marriedirl.com/2008/07/on-security/comment-page-1/#comment-459</link>
		<dc:creator>me</dc:creator>
		<pubDate>Wed, 30 Jul 2008 19:54:44 +0000</pubDate>
		<guid isPermaLink="false">http://marriedirl.com/?p=65#comment-459</guid>
		<description>so what&#039;s the latest on this? has blizzard ever admitted their responsibility in individual hacking / social engineering hacks?</description>
		<content:encoded><![CDATA[<p>so what&#8217;s the latest on this? has blizzard ever admitted their responsibility in individual hacking / social engineering hacks?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jack</title>
		<link>http://marriedirl.com/2008/07/on-security/comment-page-1/#comment-454</link>
		<dc:creator>Jack</dc:creator>
		<pubDate>Wed, 30 Jul 2008 00:39:59 +0000</pubDate>
		<guid isPermaLink="false">http://marriedirl.com/?p=65#comment-454</guid>
		<description>Any follow up?
thanks</description>
		<content:encoded><![CDATA[<p>Any follow up?<br />
thanks</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Is the Authenticator Safe? &#124; 8 Bit Culture</title>
		<link>http://marriedirl.com/2008/07/on-security/comment-page-1/#comment-434</link>
		<dc:creator>Is the Authenticator Safe? &#124; 8 Bit Culture</dc:creator>
		<pubDate>Sat, 26 Jul 2008 09:37:25 +0000</pubDate>
		<guid isPermaLink="false">http://marriedirl.com/?p=65#comment-434</guid>
		<description>[...] post hints that a keylogger may be the culprit.  Further, the victim&#8217;s co-guildie posted more information about the attack.  Aside from the attack itself, there is the lasting effect of the authenticator [...]</description>
		<content:encoded><![CDATA[<p>[...] post hints that a keylogger may be the culprit.  Further, the victim&#8217;s co-guildie posted more information about the attack.  Aside from the attack itself, there is the lasting effect of the authenticator [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Fiordhraoi</title>
		<link>http://marriedirl.com/2008/07/on-security/comment-page-1/#comment-419</link>
		<dc:creator>Fiordhraoi</dc:creator>
		<pubDate>Fri, 25 Jul 2008 18:13:07 +0000</pubDate>
		<guid isPermaLink="false">http://marriedirl.com/?p=65#comment-419</guid>
		<description>Don&#039;t get me wrong, I think that the authentication system is a great idea in theory.  I wouldn&#039;t have bought one otherwise.

But for any security system to work, there has to be training and procedures to make sure that it is not subverted by the people who have control over it.

THAT is why I think this story is important.  The most likely scenarios are that one way or another, a Blizzard employee was mislead, tricked, or convinced to remove the authenticator from the account.

Now, if the &quot;theory&quot; some people are pushing (at least on WOWinsider, etc) that someone she knew managed to get into her house and get her CD key, and knew the answer to her secret question, etc, then it is understandable and the blame doesn&#039;t lie at Blizzard&#039;s feet.  Unfortunately, being that she lives alone, the possibility of it is rather remote - no convenient &quot;pissed off roomate,&quot; etc.

That is why I think this situation should be investigated as quickly as possible.  The odds are that Blizzard&#039;s staff is not doing what they should be, and that needs to be remedied ASAP.</description>
		<content:encoded><![CDATA[<p>Don&#8217;t get me wrong, I think that the authentication system is a great idea in theory.  I wouldn&#8217;t have bought one otherwise.</p>
<p>But for any security system to work, there has to be training and procedures to make sure that it is not subverted by the people who have control over it.</p>
<p>THAT is why I think this story is important.  The most likely scenarios are that one way or another, a Blizzard employee was mislead, tricked, or convinced to remove the authenticator from the account.</p>
<p>Now, if the &#8220;theory&#8221; some people are pushing (at least on WOWinsider, etc) that someone she knew managed to get into her house and get her CD key, and knew the answer to her secret question, etc, then it is understandable and the blame doesn&#8217;t lie at Blizzard&#8217;s feet.  Unfortunately, being that she lives alone, the possibility of it is rather remote &#8211; no convenient &#8220;pissed off roomate,&#8221; etc.</p>
<p>That is why I think this situation should be investigated as quickly as possible.  The odds are that Blizzard&#8217;s staff is not doing what they should be, and that needs to be remedied ASAP.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Teresa</title>
		<link>http://marriedirl.com/2008/07/on-security/comment-page-1/#comment-418</link>
		<dc:creator>Teresa</dc:creator>
		<pubDate>Fri, 25 Jul 2008 16:23:49 +0000</pubDate>
		<guid isPermaLink="false">http://marriedirl.com/?p=65#comment-418</guid>
		<description>Honestly, the only way I see they could have gotten in was via Social Engineering.  I&#039;ve done Customer Service, and a lot of the time, even though its policy for Customers to fully identify themselves, some co-workers will just be lax/lazy and just go through with things without fully identifying the caller, and making sure they&#039;re who they say they are.  Part bad training, part bad employee.

As to the authenticators.. The only way a keylogger could have used the authenticator&#039;s password, is if the OP &amp; the keylogger hit enter at the same time.  Once you hit enter to log in, the authenticator password used becomes disabled so you CANT use it again.  The only way to get around this is if you had 2 computers, typed in passwords, typed in Authenticator passwords, and hit enter on both computers the same second.</description>
		<content:encoded><![CDATA[<p>Honestly, the only way I see they could have gotten in was via Social Engineering.  I&#8217;ve done Customer Service, and a lot of the time, even though its policy for Customers to fully identify themselves, some co-workers will just be lax/lazy and just go through with things without fully identifying the caller, and making sure they&#8217;re who they say they are.  Part bad training, part bad employee.</p>
<p>As to the authenticators.. The only way a keylogger could have used the authenticator&#8217;s password, is if the OP &amp; the keylogger hit enter at the same time.  Once you hit enter to log in, the authenticator password used becomes disabled so you CANT use it again.  The only way to get around this is if you had 2 computers, typed in passwords, typed in Authenticator passwords, and hit enter on both computers the same second.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Pat</title>
		<link>http://marriedirl.com/2008/07/on-security/comment-page-1/#comment-417</link>
		<dc:creator>Pat</dc:creator>
		<pubDate>Fri, 25 Jul 2008 15:27:56 +0000</pubDate>
		<guid isPermaLink="false">http://marriedirl.com/?p=65#comment-417</guid>
		<description>@me
Yeah!  Jump on the Blizzard hate train!  Did it escape your attention that Blizzard didn&#039;t &quot;sell these when they offer limited protection&quot;?  The fault obviously lay outside the authenticator system itself.  Grow up.</description>
		<content:encoded><![CDATA[<p>@me<br />
Yeah!  Jump on the Blizzard hate train!  Did it escape your attention that Blizzard didn&#8217;t &#8220;sell these when they offer limited protection&#8221;?  The fault obviously lay outside the authenticator system itself.  Grow up.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: JdJdJd</title>
		<link>http://marriedirl.com/2008/07/on-security/comment-page-1/#comment-415</link>
		<dc:creator>JdJdJd</dc:creator>
		<pubDate>Fri, 25 Jul 2008 14:25:38 +0000</pubDate>
		<guid isPermaLink="false">http://marriedirl.com/?p=65#comment-415</guid>
		<description>There is another possibility that I don&#039;t think I&#039;ve seen mentioned. 

Someone at Blizzard (probably low level employee, GM, ect....) who has access to the right information is selling accounts. I&#039;m not saying this is what happened but it&#039;s possible. They don&#039;t make a lot of money. 

Fiordhraoi has the other options above. The one I&#039;ve listed and the Blizz employee making a mistake are probably the most likely/easiest to accomplish.</description>
		<content:encoded><![CDATA[<p>There is another possibility that I don&#8217;t think I&#8217;ve seen mentioned. </p>
<p>Someone at Blizzard (probably low level employee, GM, ect&#8230;.) who has access to the right information is selling accounts. I&#8217;m not saying this is what happened but it&#8217;s possible. They don&#8217;t make a lot of money. </p>
<p>Fiordhraoi has the other options above. The one I&#8217;ve listed and the Blizz employee making a mistake are probably the most likely/easiest to accomplish.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Fiordhraoi</title>
		<link>http://marriedirl.com/2008/07/on-security/comment-page-1/#comment-414</link>
		<dc:creator>Fiordhraoi</dc:creator>
		<pubDate>Fri, 25 Jul 2008 14:18:16 +0000</pubDate>
		<guid isPermaLink="false">http://marriedirl.com/?p=65#comment-414</guid>
		<description>@Phoenix

Yes, to log into account management, or even just the official WOW forums, you are asked to provide the token key.</description>
		<content:encoded><![CDATA[<p>@Phoenix</p>
<p>Yes, to log into account management, or even just the official WOW forums, you are asked to provide the token key.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Phoenix Lawin</title>
		<link>http://marriedirl.com/2008/07/on-security/comment-page-1/#comment-409</link>
		<dc:creator>Phoenix Lawin</dc:creator>
		<pubDate>Thu, 24 Jul 2008 23:36:07 +0000</pubDate>
		<guid isPermaLink="false">http://marriedirl.com/?p=65#comment-409</guid>
		<description>I dont have an authenticator because I live in a different part of the world, but was just wondering -- are you asked for an authenticator ID when logging in to your account online via the website as well? Because if they don&#039;t.... that&#039;s just pretty dumb. Two ways to log into your account and yet leave one of them vulnerable?</description>
		<content:encoded><![CDATA[<p>I dont have an authenticator because I live in a different part of the world, but was just wondering &#8212; are you asked for an authenticator ID when logging in to your account online via the website as well? Because if they don&#8217;t&#8230;. that&#8217;s just pretty dumb. Two ways to log into your account and yet leave one of them vulnerable?</p>
]]></content:encoded>
	</item>
</channel>
</rss>
