36Degrees Posted April 19, 2012 Posted April 19, 2012 Have you seen the big bang theory? If so you should do what Sheldon does Don't take your Klingon Battleth (sp?) with you either, it just causes more problems.
Sdrawkcab Posted April 19, 2012 Posted April 19, 2012 I am certain the keyring authenticators are more secure than the app ones [PEDANT MODE ENGAGE] This isn't true. The same algorithm is used to generate the key for the hardware authenticator as for the software one. The only difference is the platform it runs on. The hardware auths are better in my opinion because you can't accidentally uninstall them, but that's not the same as being more secure. [/pedant] In all seriousness, you probably fell for a phishing scam and didn't even realise it. Failing that, I know this is obvious but have you run a virus scan? It could be that you have a trojan/keylogger or something. Even if you don't really use the machine on the web, sometimes just visiting a webpage is enough to get an infection.
CHR1S Posted April 19, 2012 Author Posted April 19, 2012 In all seriousness, you probably fell for a phishing scam and didn't even realise it. Failing that, I know this is obvious but have you run a virus scan? It could be that you have a trojan/keylogger or something. Even if you don't really use the machine on the web, sometimes just visiting a webpage is enough to get an infection. PC is scanned daily and up to date. I have checked running processes and services, startup even ran hijackthis and spybot for good measure. I'm racking my brain to think if I have accessed battle.net anywhere other than my iphone/ipad and that PC. And no, I haven't fallen for a phishing scam, that I can be certain of.
Bromcom_John Posted April 19, 2012 Posted April 19, 2012 This isn't true. The same algorithm is used to generate the key for the hardware authenticator as for the software one. The only difference is the platform it runs on. Are you certain? The software authenticator produces an 8 digit code and the hardware authenticator (at least the version a colleague has) generates a 6 digit code.
Sdrawkcab Posted April 19, 2012 Posted April 19, 2012 Are you certain? The software authenticator produces an 8 digit code and the hardware authenticator (at least the version a colleague has) generates a 6 digit code. Yeah you're right, after doing some googling it appears that the keyring auth produces a 6 digit code where the smartphone app produces an 8 digit code. Surely that would mean the smartphone app is technically more secure then?
Flatpackhamster Posted April 19, 2012 Posted April 19, 2012 PC is scanned daily and up to date. I have checked running processes and services, startup even ran hijackthis and spybot for good measure. I'm racking my brain to think if I have accessed battle.net anywhere other than my iphone/ipad and that PC. And no, I haven't fallen for a phishing scam, that I can be certain of. It sounds to me much like the situation which arises with a large amount of credit and debit card fraud, where the people who run the system have been bribed. If it were a normal user, I'd expect a hack on the PC, but a geek? Unlikely that the PC has been hacked.
JJonas Posted April 19, 2012 Posted April 19, 2012 I'm racking my brain to think if I have accessed battle.net anywhere other than my iphone/ipad and that PC. What about compromised public access points? or someone using something like Droidsheep to collect logon information?
CHR1S Posted April 19, 2012 Author Posted April 19, 2012 What about compromised public access points? or someone using something like Droidsheep to collect logon information? This is what I'm thinking, does the wow app pass the security info in plaintext, etc etc
LosOjos Posted April 19, 2012 Posted April 19, 2012 Yeah you're right, after doing some googling it appears that the keyring auth produces a 6 digit code where the smartphone app produces an 8 digit code. Surely that would mean the smartphone app is technically more secure then? Not necessarily, depends on how the app is written... This is what I'm thinking, does the wow app pass the security info in plaintext, etc etc With a dedicated hardware authenticator (I've not seen them, don't know how they work, so I may be way off here) I imagine it has the sole purpose of generating a key for you, probably based on it's own preset seed and the current time, linked to your account and verified on the server - can't get safer than that, even if your browser passes the key in plain text, it'll mean nothing to anyone within a minute or so. With an app, there are tons of potential security flaws, as @CHR1S points out... 1
CHR1S Posted April 19, 2012 Author Posted April 19, 2012 No, I mean the wow armoury app on iOS, that uses your username and password and has no authenticator for it.
AMLinington Posted April 20, 2012 Posted April 20, 2012 (edited) [PEDANT MODE ENGAGE] This isn't true. The same algorithm is used to generate the key for the hardware authenticator as for the software one. The only difference is the platform it runs on. The hardware auths are better in my opinion because you can't accidentally uninstall them, but that's not the same as being more secure. [/pedant] [paranoia][pedant]I am more concerned with the possibility of data on my phone being stolen. Since I have the WoW Armory App, if I were to use the Authenticator, it would mean my WoW login details and authenticator details are contained on the same device. I consider this insecure. I also consider the possibility of the authenticator algorithm being replicated a higher risk with a 'software' version than the hardware version. With the hardware version, in order to replicate it a potential account-thief would have to have access to the physical device, but that device does not contain account details so it would be hard to match it against my account. Yes, potentially given enough computing power they could brute force the algorithm replication but that would be more hassle than it was worth. My saying that IMO the software authenticator is less secure is based on the ease-of-theft of the data and the fact that my account details for my WoW account would be contained on a single device via the authenticator and armory app, NOT that the authenticator algorithm is different or less effective. Perhaps I should have clarified my view...[/pedant][/paranoia] Edited April 20, 2012 by AMLinington
X-13 Posted April 20, 2012 Posted April 20, 2012 All this for a game..... WoW - It takes over your life.
CHR1S Posted April 22, 2012 Author Posted April 22, 2012 The plot thickens, today my twitter account was hacked. I exclusively use that on iPhone and iPad only! I think one of the hotels I accessed their wifi was compromised, no other option now.
LosOjos Posted April 23, 2012 Posted April 23, 2012 The plot thickens, today my twitter account was hacked. I exclusively use that on iPhone and iPad only! I think one of the hotels I accessed their wifi was compromised, no other option now. Did you need a username and password to access their WiFi? I won't use hot spots unless I'm given a unique username and password, all too easy to set up a laptop to receive connections and sniff out passwords etc...
AMLinington Posted April 23, 2012 Posted April 23, 2012 Oh dear, full password reset. I hate having to do that - I've got so many accounts I lose track of them, a full password reset usually takes several days for me :-S I wonder how long it will be before we can start suing institutions for loss of personal fidelity based on their poor security (although before other users start flaming me and telling me it's impossible, I AM aware that there are usually disclaimers and 'Insitution X is not responsible for loss of data when using our WiFi system' blah blah blah blah) but with the increase in use of smart phones and tablet devices and the amount of data we use/store/transmit, the provider of the WiFi service must start to take steps to ensure the safety of that data. I was at a hotel this weekend in the middle of nowhere with no 3G signal and barely enough signal to make a phone call, had the hotel WiFi actually supported my smartphone instead of repeatedly redirecting me to their venues advert I would have had no choice but to send work-related data over their WiFi (had I in fact been staying there as a consequence of work, which I wasn't, so I turned WiFi off and waited until I got home to check my Facebook account and look at the pictures of my friends wedding). If you don't mind my asking, which hotels were you staying in as I think we'd all be interested to know whether compromised WiFi might affect one of us at some point?
tech_guy Posted April 23, 2012 Posted April 23, 2012 We were in Amsterdam a year back and someone in a flat adjacent to our hotel had set up a wireless access point with the same SSID as the hotel so they could harvest login details. The head of security at the hotel said it was a common problem.
CHR1S Posted April 23, 2012 Author Posted April 23, 2012 Omi San Francisco, The Moana Surf Rider Waikiki and the Hilton Grand Vacations Elara in Vegas, I also jumped on the airport wifi in San Fran and Vegas and a restaurant in Vegas too. Live and learn eh!
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now