Blizzard Security Is Sadly Inadequate

and They Are Intentionally Ripping People Off, There Is Proof Of This!

GG BLIZ....LET'S SCREW STUFF UP AGAIN!!!
Credit for this post goes to Sheeana (Level 34 Dranei hunter) of  Shadows of the Void Guild on Gorgonnash Realm

This was recently posted in the general forums at Blizzard by s friend of mine that is leaving the game due to changes....he is not alone, as many others are leaving as well. Seems that most of the new accounts are actually 'Smoke & Mirrors' of the farmers 

"I am so exited that Blizzard is finally making the game so great for us little folk. I can use the honor and badges I farmed so far to purchase all the new Season 3 gear...after all, I only have to work for a couple of weeks to get my arena team's score up where it usually is, and from then on I have this great gear to wear, with no strings attached!
I am thrilled I don't even have to consider using and worry about challenging new content that may take months to achieve, heck, I think I’ll ignore all the work on the new instances you’ve done altogether. This awesome shortcut to great purps, is so amazing that it may just lead to me trying more challenging things...like other games that are more like WoW used to be, when things were actually fun, challenging and when pvp had the same sense of accomplishment for most players as the pve content did. I can remember the months of struggle for end-game content and the same epic struggle for being a great pvp'er as well. But wow, its magic, the old great days are all gone, and now anyone, even my 7-year old can get great gear with little or no effort.

Thanks Bliz, this is fantastic....."
 

 
Seems like the right take on WoW
Credit for this post goes to Onishfu (Level 70 Gnome Warlock) of  TBaggers Anonymous LMB Guild on Dark Iron Realm

This guy is right on!

WoW is a money-making juggernaut, and there’s no arguing it. It has been an incredible financial success. Much like American Idol, however, WoW is popular but terribly bad. And the blame here lies on most of YOU (the playerbase) as well as the developers.

Let me explain a little here (if your IQ is less than 83, discontinue reading and /flame… if not, read on)…

How WoW fails because of the developers:

There are two clearly identifiable stages of play in an MMORPG (although they can be broken down separately further than this): the character building and the end-game. Both of these stages are necessary to the development and maintenance of a “good” game. A strong character building stage, although it can be time-consuming and boring at times, is necessary to give the game world and the characters within it meaning. This ‘character building’ stage is what makes you feel connected to your character, what helps you build initial relationships with other people in the game, and what gives you a reason to CARE when something happens to you.

The end-game is an equally (if not more) crucial part of the game because, theoretically, at some point the majority of the playerbase will be at this stage. This is the stage where, at least temporarily, you have all of your skills. You have all of your equipment. You have all of your enchantsments/enhancements/etc. Sure, you may change around your character a little in the future… but for the most part, you are DONE playing the game for the sole reason of numerically advancing your character.

WoW attempts to completely avoid this stage of the game by forcing players to engage in “grinds” to create their characters. As soon as the leveling grind is finished, a reputation grind is introduced. As soon as the “rep grind” is over, you need to grind honor, arena points, etc. This is a cheap, stalling tactic that is meant to do nothing but cover the fact that there IS NO END-GAME play. By the time you have “maxed out” your character with everything you NEED to be fully competitive with other players, there is a new expansion or a new set of items or something else that becomes a requirement.

In a GOOD MMORPG, there is no need for eternal character development. In a good game, there are fun activities to enjoy end-game. Meaningful PvP, sieges, city-building, and other activities have been utilized in other games in the past to provide activities for players beyond grinding for new equipment. After all… what is really the point for grinding for new equipment? In WoW, you run the same raid for the 500th time in hopes that your last piece of armor will drop… and what do you do when it has?

An easier example of this is the following: picture that right now, today, a GM came to you in-game and created a character of every race/class combination, insta-leveled them all to 70, and equipped them all with all of the best armor and weapons and such in the game (with the best enchants/gems/etc). I honestly think that most players, at this point, would realize there was NOTHING LEFT FOR THEM TO DO and quit WoW. Isn’t this a sign that there is something fundamentally flawed with the approach to the game?

A truly entertaining and well designed game would still be fun to play and have CONTENT outside of grinding additional gear or items. WoW needs to realize this at some point, or it will be its eventual downfall.

The developers of the game, however, aren’t the only ones who are the problem here…

How the playerbase fails:

That’s right, most of the people who are reading this post are actively contributing to the failure of this game.

I’m an active forum reader (although fairly infrequent poster) and the attitude of most of the people in the WoW community disgusts me. Someone makes a post about arena or honor gear, and is instantly flamed with 10 responses of “OMG THIS IZ FREE EPIX YOU SHOULD HAVE TO WORK FOR THEM BY RAIDING!”

You people do realize that “raiding” is a WoW/EQ ideology that really has very small place in future MMOs? You do realize that raiding is a GRIND activity where the most difficult part is coordinating enough people to actually show up and participate? I did some raiding prior to BC, and I have no idea how you people can all think that you somehow “earned” the right to be able to PvP (because you have gear in a gear-based game) simply because you joined a group of 39 other people who repeat the same exact sequence of events 3 nights a week.

The playerbase needs to realize that getting equipment is a means to an end and stop clamoring for things like new dungeons and more items which don’t actually add ANY CONTENT to the game. A new dungeon with new-looking monsters and a different map isn’t new CONTENT, it’s just existing content slightly morphed and increased in its level requirement. Rather, START clamoring for new real new content in the form of END-GAME CONTENT… city building, player housing, sieges, meaningful PvP, or anything else that makes an MMO an MMO.

Start making this feel more like a virtual world and less like a bunch of instanced, scripted encounters (which even BGs and arena feel like most of the time). A real game has player interaction to the point that you can become infamous for your deceit and rampant slaughter or famous for your defense of the innocent and upholding of values; gameplay that MEANS something besides making sure you get your 30% of your games so you can get your points and get something shiny to play with.

 

 

Layered Security Suggestions

65,000 + WoW Hacked Accounts Linked To Identity Theft
story to follow
 
QUESTION SENT, WAITING ON REPLY
story to follow
 
REPLY FROM BLIZZARD

01/18/2007 - UPDATE

story to follow

 
QUESTION SENT, WAITING ON REPLY

01/16/2007

0. NEED INFO ON TBC AFFECT WITH ITEM RESTORE | 01/16/2007 08:22:47 AM PST
I need to know if installing TBC will affect any item restoration due to my account being hacked 3 + weeks ago (haven't gotten anything back yet) :( :( :(

I do not want to install if it will affect any chance i have of getting my stuff back!

I vowed to leave and never comeback after last night (6 posts, no responses) with BC in hand, but my wife reminded me that we play together, side by side. So yeah, she guilt tripped me, but this is the only reason I am still here.

Since I am definitely being ignore by the investigation team (bordering on descrimination) for the pestering i've done (which does not surprise me at all coming from Bliz, since I deal with them on a daily basis through corporate). But what does surprise me is that an executive member from a Blizzard partner would get treated this way. Of course there is really no way to know but I have seen many accounts, since Jan. 5th, completely restored in less that two weeks, yet I am still waiting after 3 weeks. What gives Bliz or is this just the same old customer service that we have come to despise....Promise everything, deliver nothing!

Please feel free to answer the question above as soon as possible.

TY

 
WELL BLIZ GG

01/15/2007 - Yes, More News

Blizzard in their infinite wisdom bordering on internet fraud and discrimination against it's account holders, has indeed by lack of action, lost many, many accounts this fair night.... Estimates are in the thousands, but by the time the release is done, it will probably be nearer to the tens of thousands of senior subscriptions. In all their positioning for the release of The Burning Crusade expansion, they have forsaken the accounts of players that got them where they are.

BEWARE NEW SUBSCRIPTION HOLDERS!!! IN THREE TO SIX MONTHS THIS WILL BE YOU AS WELL. IF YOU DON'T MIND PLAYING FOR HOURS AND HOURS JUST TO SEE YOUR GAINS STOLEN, THEN PLAY/PAY AHEAD!!!

 
PROOF OF DISCRIMINATION BY BLIZZARD???

01/15/2007 - Major Breaking News!!! Blizzard, Vivendi, World of Warcraft and The Burning Crusade On The Ropes?

Seems like we definitely have a case for discrimination against Blizzard/Vivendi! The story about the guy that knew the GM getting his account back after only 4-days is indeed true; he has sent me the emails and screenshots of the in-game mail to prove it.
But the biggest shock is I have received the same proof from at least 3 others that have had their accounts restored in less than 2-weeks and they don't know any GM's. I truly believe that this must mean that someone id doing their job very well and that the person help most of us is very bad - this is very unlikely, considering they are just account rollbacks and take all of 5 minutes to complete!
The one thing all of these restored accounts have in common is that they only contacted CS and the Game Masters (in game) once. I believe anyone that repeated bothered upon the hacking of their account and since by sending many emails and bothering the GM's repeatedly about their items being returned, is being discriminated against by being made to wait much longer or not even getting their items at all.
Not only that but the grapevine in the Bliz forums has it that if your items are not restored by the time TBC is released , you can forget ever getting them back as Bliz will use this as an excuse to not have to bother, citing the games architecture change.
I have indeed sent this, once again to the IFCC and the NY and CA AG's. We'll see where this turns up

 
BREAKING NEWS!!!

01/13/2007 - Breaking News

As many as 350,000 game accounts in USA alone have sworn to leave Blizzards World of Warcraft as of the release of Blizzard's expansion 'World of Warcraft: The Burning Crusade'. This is mainly due to stolen/hacked accounts that have not been restored, Lack of security and terrible customer service to those located in the USA (remember stolen or 'hacked' accounts may also mean your personal and credit info gets taken as well). Seems as though membership has actually waned in the US while China has gone wild (most of the keylogger 'phone home' IP addresses are located in China). This past spring the membership was substantially different, with approximately 5 million subscribers and most were located in North America, when now with 8 million it seems only 25% are in North America and most (3.5 Million) are in China. This is very disturbing news for Bliz since it seems WoW may be on the way out here at home (their base country).

Good going Bliz, let's alienate the ones that put us here and concentrate on bragging that you have more gold farmer/account hackers. Oh and by the way Blizzard, your secret is out, it only takes about 30 seconds (ref: Blizzard Tech Support Employee) to roll back a character to a time before the hack/theft taking place, so what's your excuse? Well, I think we all know the answer...new content and new accounts (no matter whether they are legit or thieves accounts, are much more important to you then the established accounts. Sounds like all you want is bragging rights here, well watch out for Age of Conan, because most of the players we've talked to are going there, upon it's release, if something isn't done quickly...before TBC. With that in the future and the criminal migrating to a new game as well, you'll be back down to a more manageable 4-5 million accounts or less, before you know it. Kind of reminds us of what happened to Star Wars Galaxies, doesn't it and they are almost non-existent now, WAKE UP BLIZ, YOUR EGO IS WINNING AND YOUR PLAYERS ARE SCREAMING FOUL!

 
BLIZZARD DISCRIMINATES???

UPDATE!!! 01/12/2007 - Account restore neglected for speaking out against Blizzard WoW security policies!!! Isn't that discrimination?

Blizzard restores account in 4 days!!! Just 4 days ago another account was hacked and indeed it was a RL friend of mine, not only that but a partner to my company as well.

Disheartening news you say?.....I think not, one more tale to prove that the Blizzard name is synonymous with BULL SHIT!
He happens to know a GM (Game Master) that works for Blizzard...his account was restored in 4 days.....average time for restoration...if Bliz ever gets around to it?....3-4 WEEKS!!!

So politics as usual, huh Bliz? Seems like discrimination to me!

I don't know, but they may be opening themselves up for all kinds of problems here.

Okay, maybe not, but not only does it seem they may have an inside hijacker, but now they offer preferential treatment, if you know the right people.

LOL, guess the virtual world is not much different than the real world, including the undesirable criminal elements. Oh I guess thats just Blizzard!
 

 
OMFG, BLIZZARD We Are Ashamed To Be Partnered With You!!!

01/09/2007 - Update            I just received this today

   
       
 
Greetings,

Thank you for contacting the Account Administration department with regards to the World of Warcraft account you are using. The World of Warcraft investigation team is still in the process of researching the account for possible compromise and determining the steps needed to conclude this situation. Unfortunately, these issues can take an extended amount of time to fully resolve. They will contact you with the results of their investigation as soon as they have completed all appropriate actions.

In the meantime, please make sure to scan the computer system you are using to remove all viruses, Trojan files, and key loggers. It is important to note that simply scanning your computer for viruses is not necessarily enough; please be sure to run a spyware removal tool for the sake of extra security. You can find links to such tools through the security site offered hereafter.

For more computer/Internet security tips, please visit http://www.blizz


 
 
       
 
-----Original Message-----
From:
To: wowaccountadmin@blizzard.com
Sent: 12/27/2006 10:36:26 AM
Subject: Re: World of Warcraft - Password reset

This is being forwarded to all concerned:

Dear Blizzard,

Okay folks this has been implemented through our business and is extremely
simple to do. During the software install (or patch in this case) during
each login the IP address is logged and stored in account settings/log.
During each logout the IP address is refreshed and re-written.
All logins following will be tied to a specific IP address that is only
refreshed during the logout operation. Once this is accomplished, logging in
from a different IP address will trigger the activation of a 'Secret
Question' answer request. Only the owner would be likely to have this
answer. To make this even more secure, the question/answer would allow the
user to login, but would be automatically reset
 

 
 
     


Let's see that's 14 days to officially answer a letter by email and it was even sent to me incomplete...lol. And everyone wondered what Bliz was doing with their time......WE HAVE NO F'NG IDEA......But whatever it is, they are certainly not earning their money.

  • They are however, willfully and I think intentionally being negligent to their awesome responsibilities to their subscribers

  • They are grossly inadequate to their subscriber's credit card, personal information and identity theft security capabilities or lack thereof.

  • They are, in my opinion, guilty of Internet Fraud!*

* one of the definitions of fraud, "Intentionally selling an item advertised as serviced by you, but you have no intention of servicing"

 

Major Update!

01/05/2007 - UPDATE
WoW! 900+ more accounts hacked in just 4 hours and survey reveals extreme drop in established account playtime! Is this a new trend or the beginning of the downfall of WoW as we know it!

Just hours after Blizzard making their statement about not concentrating on the single player for account restoration another 900+ accounts were hacked by at least one Keylogger that sent its information to a number of IP addresses located in China**. When told of this, "This is absolutely unacceptable, Blizzard has the tools, why don't they use them or implement a simple IP based security login solution", stated Mr. Rick Hawkins, CEO and Chief Design Engineer for one of the top custom gaming system manufacturers in the Northeast and a Microsoft, Intel, AMD & nVidia Partner. "A simple redesign of their login systems with a few 'Hooks' of their own would all but eliminate keyloggers as a threat, for now I wouldn't recommend anyone using their credit card to pay these accounts, it is too dangerous".

As for the survey that was posted here last month, it showed a sharp decline of approximately 62% in playtime among senior* WoW gaming accounts. There were over 4000 participants in the poll and it showed a very alarming trends (results below), you can also take the survey here

Of 4026, 1074 are newer players and do not fit the demographic for this survey***.
Of 4026 Participants 2952 fit the demographic of senior player.

Of 2952, 1121 Played more than they did 1 year ago (37.9%)
Of 1121, 362 really need a life or should at least attempt to get one (32.3%) (12.3% Over-all)
Of 1121, 221 said they like the new content (19.7%) (7.5% Over-all)
Of 1121, 335 said they have real life friends that play (29.9%) (11.3% Over-all)
Of 1121, 151 said they wanted more gear (13.5%)  (5.1% Over-all)
Of 1121, 52 said they had other reasons (4.6%) (1.7% Over-all)

Of 2952 Seniors, 1831 stated they played at least 50% less then they did a year ago (62.0%)
Of 1831 Seniors, 129 said they didn't have as much spare time (7.1%) (4.4% Over-all)
Of 1831 Seniors, 357 said they were bored & were waiting for new content or expansion (19.5%) (12.1% Over-all)
Of 1831 Seniors, 581 said they got so bored they stopped playing, but I still pay for my account (31.7%) (19.7% Over-all)
Of 1831 Seniors, 692 said they fear logging in because of security issues (37.8%) (23.4% Over-all)
Of 1831 Seniors, 72 said they had other reasons (3.9%) (2.4% Over-all)

Boredom and security issues have plagued 57.6% of the senior players that participated in this survey. I don't know about you, but this is something Blizzard should pay attention to, almost 25% of the senior players over-all are afraid to login, that's ludicrous. No matter how many new accounts you get (it's how they advertise), if the older accounts don't play, the numbers are skewed and misleading.

* Senior is defined as an established account of more than one year
** Information logged on a locally hacked account system
*** Survey results are accurate within 0.1%

 

Major Update!

01/04/2007 - UPDATE!
News from Blizzard - from Blizzard Account Services, phone conversation13:34PM (recorded/transcribed) after 43 minute wait on hold.
All account security investigation personnel are to busy to accept outside calls from subscribers over issues of item replacement or hacked accounts, due to the nature of the account dumps initiated by Warden, Blizzard's new security watch dog. Programs such as AVG free anti-virus, Zone Alarm Pro firewall, and even AIMfix (a program designed, in partnership with AOL, to remove AIM viruses and trojans) have been named among the possible false triggers to Warden and that there should be an official announcement forthcoming.

When, I called again, I stated that it was not due to warden as the account had not been banned and was told by Blizzard that they are not concentrating on smaller issues at this time, but instead are looking in to mass account reactivations.

Sounds like they do not care about their single account holders or that any of us have been hacked by the lack of security in their company. I have even reported this to the IFCC (Internet Fraud Complaint Center-->FBI) and hopefully at least someone will look into making Blizzard more accountable to its subscribers and their security needs, such as they did with a few others 3-4 years ago.

In the meantime I guess we are supposed to keep paying for an account that we can't use and they have no intention on resolving in an appropriate period of time...is that not one of the definitions of fraud, 'Intentionally selling an item advertised as serviced by you, but you have no intention of servicing'....very interesting, huh?
 

Major Update!

01/03/2007 - UPDATE!
It is confirmed! A hacked version of the background downloader did come out of Blizzard, bringing with it a rather nasty little custom keylogger. This explains a lot since there were so many accounts hacked and stolen since the last patch. Now that we know it must have been an inside job*, please look at these links to satisfy your curiosity. What kind of company is this, Gaming or Spyware? You Decide!!!

TG Daily

BBC News

GIN (Game Industry News)

Rootkit.com

Softpedia.com

These are just a few, should you decide to Google 'Warden World of Warcraft', you will find many, many more!

* There has been no denial or confirmation of this from Blizzard
 

 

World of Warcraft.....We can only hope they wake up at Blizzard!

01/02/2007
World of Warcraft boasts some of the most robust gameplay and content on the planet and that is the draw to the common gamer, what they do not tell you is the security nightmare that it also boasts for the home user!

From keyloggers to trojans this gaming mmorpg is a virtual nightmare for the system that runs it. AVG, Avira, Kapersky Mcafee and Norton's miss almost all of these keyloggers until it is too late. By the time these little custom programs are added to their DB's the damage is done and it isn't just limited to the gaming login and password, it can also lead to credit, banking, online account and full identity theft.

Granted, Blizzard now has the largest online client list, but they are also way behind their competition and the corporate or real world in security with the lack of IP linked security triggers, they rely completely on a launcher that has little or no effect what-so-ever on the keyloggers that are indeed stealing thousands of accounts per month, resulting in thousands of dollars worth of lost time and use of these account for their clients. Taking up valuable time and resources to re-instate and restore these stolen/hacked accounts, instead of putting the time where it would do the most good by increasing the security of the game and login system itself. There have even been rumors of their background downloader itself being a carrier at one time of a very wise keylogger that led to thousands of accounts being stolen, this would be an extremely suspicious event indeed. The amount of account bannings linked with these thieves is staggering, by Blizzard’s own account they have banned more than 100,000 accounts in total.

All-in-all a great game, but is it worth the money to have your entire identity stolen and think of it this way adults are not the only victim. Let's say you have an account for Napster and pay so much per download, if your account info is stolen then someone could download hundreds of songs before being stopped and the account holder would be liable to pay for these. Or even take for instance the mother that does her banking on the same system as her children that happen to play World of Warcraft and after a few days can no longer pay her bills because some international hacker just stole her financial identity.

Some may say that this type of security should fall to the consumer, and normal antivirus and firewalls should be our responsibility, however when it comes to these keyloggers their rising popularity and irresponsible security is what allows them to flourish so wildly, when a simple IP security tag refreshed at the end of each session and set to trigger the rest of their 'already in place' though inadequate security measures would surely do the trick.

Granted this is only one instance of the security of these types of online programs with inadequate security that is wreaking havoc on the home user's system, but at this time it is indeed the most prevalent and a fairly simple solution is at hand.

Ideas include blizzard supplying a downloadable anti-keylogger program for little or no cost, as these programs rarely cost more than $20-30 to begin with, why not sell it for $10-15 and make even more money as it seems what they are more intent on getting rather than supplying the service they insist that they give us. Not only that, they could probably develop their own specialized anti-keylogging program for pennies and include it in a patch or offer it for download

Or even a simple IP based approach to these things – Blizzard already logs our IP address every time we log in on our game accounts, these are also the same account logins for payments, storage of credit cards, passwords, etcetera, maybe not the ideal situation but let’s see what we can do with this.

Once you log out of the game, they refresh the stored IP address. Should you or a hacker attempt to login from a different IP address, this triggers your secret answer request which is already part of their mundane security system. Now this secret answer system, you set up at the beginning of creating your account and you do not have a manual means of changing it, Blizzard manages that.

Once you have logged into your account or game with the correct answer, it is then wiped clean so no one can use it again and an email is automatically sent to the account holders registered email address containing a random question and answer for the next time if need be. Yes it would be the responsibility of the account holder to write this info down or just print it out and keep it in a safe place. The email would of course have to explain that you account attempted to login from a different IP that would also alert you to the possibility of a keylogger being present on your system.

This process would be a very simple solution to a quickly growing problem and all but eliminate keyloggers from being able to be used to steal accounts the way they are now.

To all the people that say someone would just write a smarter keylogger, I say no…let me explain.

We will address ‘Hook’ type keyloggers (90% of the ones written)

Keyloggers are very small programs that monitor the keystrokes you make and what program they correspond to. The key word here is small, so small in fact that they slip in almost completely undetected by the average internet security program and just like a virus they can be disguised to look or act like another program, or even be embedded into a program that you may intentionally want to or have downloaded. Many of them are recognized by the system user because of this and they in turn tell their firewall or internet security system to ignore it. If someone were to write a larger more sophisticated program to get around this type of system, it would really defeat its purpose and even hamper its ability to perform. So it wouldn’t be done, because it would be too much of a hassle for the criminal.

To conclude this story, I presented this type of solution to blizzard and they quickly dismissed the whole issue stating they could not use ideas from an outside source…..
Okay first off, I am a partner to Blizzard as well as many other companies like Microsoft, Intel, AMD & nVidia and an outsider I am not. So much so that one of their competitors (I can’t say which one) picked this up and are trying to implement it. Once done they will be advertising as the most secure MMORPG on line.

I also realize that for dial customers or any ISP that changes IP’s constantly that this may be inconvenient, but for the safety and security, it would be well worth it.

We can only hope that Blizzard comes to their sense and implements something of their own that compares to this.
 
Layered Security Suggestions

All privileges for this info are in public domain to use as you will for information purposes only. These pages are not to be used in any way for the degradation of icedragonslair.com or its owners/operators. These are observations and opinions and are intended as same. If you really must contact us, please do so by email here