Jump to content

Recommended Posts

Posted
Have you seen the big bang theory? If so you should do what Sheldon does :)

 

Don't take your Klingon Battleth (sp?) with you either, it just causes more problems.

Posted
I am certain the keyring authenticators are more secure than the app ones

 

[PEDANT MODE ENGAGE]

This isn't true. The same algorithm is used to generate the key for the hardware authenticator as for the software one. The only difference is the platform it runs on. The hardware auths are better in my opinion because you can't accidentally uninstall them, but that's not the same as being more secure.

[/pedant]

 

In all seriousness, you probably fell for a phishing scam and didn't even realise it. Failing that, I know this is obvious but have you run a virus scan? It could be that you have a trojan/keylogger or something. Even if you don't really use the machine on the web, sometimes just visiting a webpage is enough to get an infection.

Posted

 

In all seriousness, you probably fell for a phishing scam and didn't even realise it. Failing that, I know this is obvious but have you run a virus scan? It could be that you have a trojan/keylogger or something. Even if you don't really use the machine on the web, sometimes just visiting a webpage is enough to get an infection.

 

PC is scanned daily and up to date. I have checked running processes and services, startup even ran hijackthis and spybot for good measure.

I'm racking my brain to think if I have accessed battle.net anywhere other than my iphone/ipad and that PC.

 

And no, I haven't fallen for a phishing scam, that I can be certain of.

Posted
This isn't true. The same algorithm is used to generate the key for the hardware authenticator as for the software one. The only difference is the platform it runs on.

 

Are you certain?

The software authenticator produces an 8 digit code and the hardware authenticator (at least the version a colleague has) generates a 6 digit code.

Posted
Are you certain?

The software authenticator produces an 8 digit code and the hardware authenticator (at least the version a colleague has) generates a 6 digit code.

 

Yeah you're right, after doing some googling it appears that the keyring auth produces a 6 digit code where the smartphone app produces an 8 digit code. Surely that would mean the smartphone app is technically more secure then?

Posted
PC is scanned daily and up to date. I have checked running processes and services, startup even ran hijackthis and spybot for good measure.

I'm racking my brain to think if I have accessed battle.net anywhere other than my iphone/ipad and that PC.

 

And no, I haven't fallen for a phishing scam, that I can be certain of.

 

It sounds to me much like the situation which arises with a large amount of credit and debit card fraud, where the people who run the system have been bribed. If it were a normal user, I'd expect a hack on the PC, but a geek? Unlikely that the PC has been hacked.

Posted

I'm racking my brain to think if I have accessed battle.net anywhere other than my iphone/ipad and that PC.

 

What about compromised public access points?

 

or someone using something like Droidsheep to collect logon information?

Posted
What about compromised public access points?

 

or someone using something like Droidsheep to collect logon information?

 

This is what I'm thinking, does the wow app pass the security info in plaintext, etc etc

Posted
Yeah you're right, after doing some googling it appears that the keyring auth produces a 6 digit code where the smartphone app produces an 8 digit code. Surely that would mean the smartphone app is technically more secure then?

 

Not necessarily, depends on how the app is written...

 

This is what I'm thinking, does the wow app pass the security info in plaintext, etc etc

 

With a dedicated hardware authenticator (I've not seen them, don't know how they work, so I may be way off here) I imagine it has the sole purpose of generating a key for you, probably based on it's own preset seed and the current time, linked to your account and verified on the server - can't get safer than that, even if your browser passes the key in plain text, it'll mean nothing to anyone within a minute or so.

 

With an app, there are tons of potential security flaws, as @CHR1S points out...

  • Thanks 1
Posted (edited)
[PEDANT MODE ENGAGE]

This isn't true. The same algorithm is used to generate the key for the hardware authenticator as for the software one. The only difference is the platform it runs on. The hardware auths are better in my opinion because you can't accidentally uninstall them, but that's not the same as being more secure.

[/pedant]

 

[paranoia][pedant]I am more concerned with the possibility of data on my phone being stolen. Since I have the WoW Armory App, if I were to use the Authenticator, it would mean my WoW login details and authenticator details are contained on the same device. I consider this insecure. I also consider the possibility of the authenticator algorithm being replicated a higher risk with a 'software' version than the hardware version. With the hardware version, in order to replicate it a potential account-thief would have to have access to the physical device, but that device does not contain account details so it would be hard to match it against my account. Yes, potentially given enough computing power they could brute force the algorithm replication but that would be more hassle than it was worth. My saying that IMO the software authenticator is less secure is based on the ease-of-theft of the data and the fact that my account details for my WoW account would be contained on a single device via the authenticator and armory app, NOT that the authenticator algorithm is different or less effective. Perhaps I should have clarified my view...[/pedant][/paranoia]

Edited by AMLinington
Posted

The plot thickens, today my twitter account was hacked. I exclusively use that on iPhone and iPad only!

I think one of the hotels I accessed their wifi was compromised, no other option now.

Posted
The plot thickens, today my twitter account was hacked. I exclusively use that on iPhone and iPad only!

I think one of the hotels I accessed their wifi was compromised, no other option now.

 

Did you need a username and password to access their WiFi?

 

I won't use hot spots unless I'm given a unique username and password, all too easy to set up a laptop to receive connections and sniff out passwords etc...

Posted

Oh dear, full password reset. I hate having to do that - I've got so many accounts I lose track of them, a full password reset usually takes several days for me :-S I wonder how long it will be before we can start suing institutions for loss of personal fidelity based on their poor security (although before other users start flaming me and telling me it's impossible, I AM aware that there are usually disclaimers and 'Insitution X is not responsible for loss of data when using our WiFi system' blah blah blah blah) but with the increase in use of smart phones and tablet devices and the amount of data we use/store/transmit, the provider of the WiFi service must start to take steps to ensure the safety of that data.

 

I was at a hotel this weekend in the middle of nowhere with no 3G signal and barely enough signal to make a phone call, had the hotel WiFi actually supported my smartphone instead of repeatedly redirecting me to their venues advert I would have had no choice but to send work-related data over their WiFi (had I in fact been staying there as a consequence of work, which I wasn't, so I turned WiFi off and waited until I got home to check my Facebook account and look at the pictures of my friends wedding).

 

If you don't mind my asking, which hotels were you staying in as I think we'd all be interested to know whether compromised WiFi might affect one of us at some point?

Posted
We were in Amsterdam a year back and someone in a flat adjacent to our hotel had set up a wireless access point with the same SSID as the hotel so they could harvest login details. The head of security at the hotel said it was a common problem.
Posted

Omi San Francisco, The Moana Surf Rider Waikiki and the Hilton Grand Vacations Elara in Vegas, I also jumped on the airport wifi in San Fran and Vegas and a restaurant in Vegas too.

 

Live and learn eh!

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...