View Single Post
10-17-09, 10:29 PM   #1
Bluspacecow
Giver of walls of text :)
 
Bluspacecow's Avatar
AddOn Author - Click to view addons
Join Date: Dec 2006
Posts: 770
New Battle.net merge security tip : Dis associate your toon name from your email !

Oh dear I'm getting the writing bug again.

With the coming mandatory battle net merging there have been concerns raised over this possibly making it easier for a hacker to hack you.

IMHO Before they can hack your email address they need to of course know if there is a World of Warcraft account attached to that email address.

There are several things you can do to alleviate these concerns :

1) DISSASSOCIATE YOUR TOON NAMES FROM YOUR EMAIL ADDRESS :

By making sure there is nothing out there on the interwebs linking your specific toon name to your email address the hackers won't know if there is a world of warcraft account attached to that email.

Many forum sites have an option to hide your email address from other members. Go to all of these and make sure that where you've mentioned what you toon name is make sure people can't get your email from there. Have a look at your profile and see if someone can click through to get your email (possibly do this while logged out).

On Wowinterface.com you can do this by going to :

http://www.wowinterface.com/forums/p...do=editoptions

And turning off Email options -> "Receive Email from Other Members". If they want you they can send you a PM which gets sent to your email address anyway if you have the option "Receive Email Notification of New Private Messages"

2) CHANGE THE EMAIL ADDRESS MERGED TO YOUR BATTLE NET ACCOUNT(IF ALREADY MERGED)

Go to Gmail.com or some reasonably secure email provider.

Get a new one from there just for wow related stuff.

Next go to the Battle net site and login.

US will be https://us.battle.net EU will be https://eu.battle.net Other locales I'm not sure but the use of https://battle.net should redirect you

You should now be looking at the management screen.

There's a link there for "Changing your email address"

Change it there.

A verification email gets sent to you.

Don't forgot to add this new email address into your email client in case you get emails from Blizzard in the future.

3) DON'T USE A HOTMAIL.COM , YAHOO.COM , MSN.COM OR LIVE.COM EMAIL.

They have been hacked in the past so I wouldn't trust them. I'm not one of those people who like to spread fear & uncertainty like this but heres news of the most recent time they got hacked :

http://lifehacker.com/5374745/10000-...-leaked-online
http://www.neowin.net/news/main/09/1...-leaked-online

4) MAKE SURE YOU ARE USING A STRONG PASSWORD

http://www.wired.com/threatlevel/200...000-passwords/

The most common password is "123456".

C'mon people. Don't be silly gooses here. Don't use any of the common passwords in that link above. Don't make it "123456". Or "password" or "letmein4" or anything in the dictionary or anything that can be easily guessed.

Use a code phrase only you can remember about yourself. Don't base it on anything anyone out there on the interwebs can research like your birthday or your kids birthday or anything like that.

EG Let's say you like dogs. Your personal favourite dog is shai peis. You try to make it something people can't guess you use the phrase "myfavdogsisblueshaipeis"

Fairly long, fairly hard to guess and in the middle of the alphabet to boot.

Let's make it slightly harder to guess. Let's replace some characters with numbers and easily remembered

myfavd0gs!$blu3$ha!p3!$

Really long , almost impossible to guess and oh dear god I think I've gone a bit overboard here

The point is the numbers you choose to replace the characters with should be things you can easily remember. EG replace all e with 3's or all 1 with ! s with $ etc etc etc

The idea is to make it a password that's long , hard to guess and really hard for a hacker to password for just by using your run of the mill dictionary attack. You also need to make it so you can reproduce it quickly and easily when you need to log in.

I was going to put something in here about Authenticators but I didn't want to imply you needed to go out and buy one to be considered secure.

If anyone wants to add more stuff about making your battle net account more secure please feel free to do so.
__________________
tuba_man on Apple test labs : "I imagine a brushed-aluminum room with a floor made of keyboards, each one plugged into a different test box somewhere. Someone is tasked with tossing a box full of cats (all wearing turtlenecks) into this room. If none of the systems catch fire within 30 minutes, testing is complete. Someone else must remove the cats. All have iPods." (http://community.livejournal.com/tec...t/2018070.html)

Last edited by Bluspacecow : 10-17-09 at 10:52 PM.
  Reply With Quote