Also on AOL
- Autos
- Technology
- Lifestyle
- Gaming
- Finance
- Entertainment on AOL
- Lifestyle on AOL
- Sports on AOL
- Travel on AOL
- More on AOL
Featured Galleries
Joystiq
© 2013 AOL Inc. All rights Reserved. Privacy Policy | Terms of Use | Trademarks | AOL A-Z HELP | About Our Ads

Reader Comments (Page 1 of 1)
6-19-2011 @ 11:53AM
Joseph Smith said...
"so they may use system info and a combination of all of the above to generate unique keys for systems"
And once the hackers determine what the algorithm is to determine this information, all they need to do is insert code into their keyloggers to capture this from your computer along with your username/pwd. Since this hash is UNCHANGING, it will always be valid. Unlike the authenticator, which IS a continuously changing code.
Alternatively, they can just continue using man in the middle attacks, which instead of stealing your authenticator code, will steal the 'location id' that blizz has put in.
I don't pretend to know what's happening on Blizzard's side for the authentication, but then I'm not the party that's interested in finding ways around it. Trust me when I say that the gold farmers are already hard at work trying to determine how to get around Blizzard's code without needing the authenticator information, now that the possibility exists.