If you're worried about security as a user, d/l the free authenticator.
If you're worried about Blizzard, don't -- they're big kids. You can run your 10+ million user game platform the way you want, Blizzard will run theirs the way they want.
If you're worried about security as a user, d/l the free authenticator.
If you're worried about Blizzard, don't -- they're big kids. You can run your 10+ million user game platform the way you want, Blizzard will run theirs the way they want.
Telling people not to worry about security works until they, inevitably, have their data compromised. Technically aware consumers have a responsibility to put pressure on companies to be secure with information.
"Technically aware consumers have a responsibility to put pressure on companies to be secure with information."
No one's shown that Blizzard has been unsecure with anyone's information. I see a lot of people running around like the sky is falling when it's not.
Millions of accounts from a single breach somewhere. Not millions of accounts individually brute forced because their case-insensitive passwords made them trivially guessable.
We should be worried that Blizzard will get hacked like PSN was. That would be potentially catastrophic. But case sensitivity has almost no effect on password security unless your users ALL use random passwords.
And if you don't have a smartphone (spoilers you probably do) and you wanted an authenticator you could buy the token or emulate it on the OS of your choice...
http://developer.android.com/guide/developing/tools/emulator...
or on any java device apparently:
Edit: it's not quite an authenticator: http://us.battle.net/support/en/article/battlenet-sms-protec...
What? No it doesn't. They could just lower case all the password submissions and store the hashed version of that. When someone tries to log in, lower case what they enter, hash it, and compare to hash (or whatever the specifics are)