by revengous » 13 Jun 12, 5:00 pm
PalZer0 wrote:revengous wrote:what gaping holes? I've seen none
Passwords not case sensitive? No lockout for excessive incorrect login attempts? No lockout for strange activity like attempting to log in from a totally different country?
If you don't class those as gaping holes in an authentication system, I'd hate to see what you do. That's not to mention the flaw that allows someone to grab every active Battle.net email.
There was a fair bit of discussion of their poor security practices
in this thread with a couple of links to threads on Blizzard's Diablo 3 forums.
everyone keeps going on about case sensitive, at uni we were required to code a number of encryption/decryption programs, for some of them we were required to convert everything to uppercase in order to decrypt/store the information, however I doubt blizzard would be using an encryption like this, Im sure they have a good reason for it.
providing you have an authenticator, you should have no trouble with the other things - mines set to sms alert on changes and require authentication whenever I log in from another location.
blizzard push for everyone to use the authenticator because it works. its like ignoring directions then complaining when you get lost.
have you tried logging in multiple times on your diablo 3 account to see if there is a lock out? do you even own d3 or are just trying to cause trouble?