Tobold's Blog
Sunday, April 29, 2007
 
Hackers are idiots

Somebody is trying to hack my World of Warcraft account, by taking my publicly available e-mail address and entering it on Blizzard's site, claiming to have forgotten the userID and password. The flaw in that plan? Of course the information gets send to me, not to the hacker. What an idiot! Already happened several times with my Google account too, but never got the wannabe-hacker anywhere.
Comments:
Maybe he's trying to lock out your account? Harassment, rather than an attempt to steal.

I know some services block your password if you ask for your account info, as a security measure. (Not sure how "oh! I remember!" is a security breach, but oh well.)
 
I wouldn't exactly call this 'hacking'.

Actually Tobold, if there is an idiot in this situation, it's you. Don't use public email addresses for private things like game accounts or banking or anything like that.
 
Chris, I don't. The account I got this message from is my dead US account, which was opened before I put my e-mail on my blog. All my banking, shopping and other game accounts are on my private e-mail. The Google account is necessarily linked to the GMail address, but if you ask for the password to be sent, it arrives at my private e-mail too.
 
Actually.. one way of hacking into someone's account is to click on the "I forgot my password" button and then sniffing the password from the email traffic or retrieving it from the victim's email server.

Of course, this assumes that the hacker is skilled enough to break into a router or an email server..
 
Blizzard added a change your email yourself function a while ago on EU, so i speculate its on US aswell. Go to change contact information and go down to email and you should be able to select "change email" and follow the instructions from there.
 
and the possilbe hacker is?

Chris said...
I wouldn't exactly call this 'hacking'.

Actually Tobold, if there is an idiot in this situation, it's you. Don't use public email addresses for private things like game accounts or banking or anything like that.


Wake up on the wrong side of the wookie cave? People make mistakes, such is life. Tying a game account to a public email address may not but the smartest thing to do I agree, however it is also idiotic to make assumptions without knowing the entire story.
 
Im telling you, these game companies need to implement some new standards for security. I have dreams of an IP whitelist system. Where I log into the my account and specify which IP ranges are allowed to access the account site, and game. Quite a bit harder to test a stolen password when your IP is restricted from accessing the account page + game for the specified account.

Ahh to be young.. and a robot.
 
Post a Comment

<< Home
Newer›  ‹Older

  Powered by Blogger   Free Page Rank Tool