Log in to ZYGOR
Log in with social media
OR
Log in with Zygor account

Announcement

Collapse
No announcement yet.

Keeping your account secure sticky

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

    Keeping your account secure sticky

    The sticky, although being generally good is wrong in one very important area

    "The authenticators (in hand, not Ipod apps) have a fixed number of codes that are on a fixed loop"

    this is NOT true at all!!! The code generated is computed from the current time & date and the token's secret 128 bit seed number known only to blizzard's logon server - there is no loops. no fixed sequences - otherwise as you say they would be VERY easy to crack. The calculation of the number is a one way calculation - meaning that you cannot work out the seed number of teh authenticator from the generated codes. You also cannot reverse engineer the seed number as the tokens have tamper resistancy built into them (i.e. any attempt to "read" the seed from the internal chip will destroy the seed data.)

    The authenticators are extremely secure, they are used world wide by big coioprporations (including my own company) for remote network access

    See here for a detailed explanation of how the RSA SecurID technology as used in these authenticators works, and why they are so secure.

    http://en.wikipedia.org/wiki/SecurID

    Just one quote from teh article
    "RSA SecurID currently commands over 70% of the two-factor authentication market (source: IDC) and 25 million devices have been produced to date"

    if they were so easy to crack, they wouldn't be so very popular...

    I would gladly give you my account password, but my authenticator you would have to prise out of my cold dead hands....

    #2
    I wanted to see how long a code stayed good for and I can assure you that its not very long. I use the iPhone version and I wrote down the numbers so after the code changed I would still have them. Within about 5 seconds of the code changing on the screen it would not work.

    I also logged in and then logged out and tried the same code before it changed and it would not work. Since it had already been used I had to wait for a new code to be generated.

    The authenticator is a great addition. For those who don't know. You need to use the code when you log into the battle.net website or the manage account section from worldofwarcraft.com. You also must use the code when logging into the game.

    You do not enter the code when logging into the world of warcraft forums. So worst case someone who key logs or hacks you should only be able to get you banned from the official forums.

    Comment

    Working...
    X