Thread Rating:
  • 1 Vote(s) - 5 Average
  • 1
  • 2
  • 3
  • 4
  • 5
People being hacked since the last Server Check.
SaptaZapta Wrote:No. You are thinking of a different kind of device, which I think is generically called a "plug". That device needs to be plugged into your computer, and responds with its (fixed) id when queried, thus giving this "extra password" you mentioned.

The authenticator doesn't work that way. When you ask to log in, a code is generated somewhere and sent to the authenticator, which displays it. You must copy the number and type it into the login screen to prove you're holding the device. The number expires within a few seconds, so even if someone finds it out, it's useless to them.

Err that's not how the blizzard authenticator works. They're basically PRNGs each with a relatively unique seed. On the blizzards side they store the seed of your authenticator with your account info. When you press the button on your authenticator a pseudo random number is generated using the seed and time. You enter this number to login. Blizzard then use the seed for your account and time to generate the same pseudo random number which is then used to compare with the number you entered. There is no communication between the authenticator and blizzard that can be intercepted which is the whole point.

Obviously if the blizzards database is broken into then hackers can take the seed and use it to log in to your account.
Reply


Messages In This Thread
People being hacked since the last Server Check. - by happylight - 2011-12-12, 06:10 PM

Forum Jump:


Users browsing this thread: 3 Guest(s)