11 ms·
Diablo 3 bug report: "Passwords not case-sensitive."
- gte910h 14y agoUse a passphrase then if this bothers you? If you want to be serious about security of your account, use one of the two factor authentication systems available that they offer. The faster passwords stop looking like: C@tV0m!t And start looking like: correct battery horse staple the better for security and actually remembering the phrase rather than writing it down. (XKCD on this: http://xkcd.com/936/ http://xkcd.com/936/)
- icebraining 14y agoWell, in the same forum there's also this: http://us.battle.net/d3/en/forum/topic/5149150816 http://us.battle.net/d3/en/forum/topic/5149150816 I don't understand why there is a 16 character limit on user passwords.
- gte910h 14y agoIt's not technically a limit, as much as a truncation. I still would be happy if they lengthened that.
- icebraining 14y agoI'd say it's a limit caused by truncation, but this is rather irrelevant.
- TWAndrews 14y agoOne has to imagine that the actual phrase "correct battery horse staple" is a fairly poor choice of password, at this point though...
- karlshea 14y agoFacebook does sort of the same thing: http://www.zdnet.com/blog/facebook/facebook-passwords-are-not-case-sensitive-update/3612 http://www.zdnet.com/blog/facebook/facebook-passwords-are-no... Yes, it's possibly less secure. But for both Facebook and all of the Blizzard games there are other options if you are concerned.
- chetan51 14y agoMakes sense.
- tylermenezes 14y agoFacebook's is a little better - you can't disregard case entirely. Blizzard just cut the search space by a lot. Then again, it would be pretty difficult to brute force a password in Battle.net, to be honest. I'm assuming they'd lock out the account after just a handful of tries.
- elithrar 14y ago> Then again, it would be pretty difficult to brute force a password in Battle.net, to be honest. I'm assuming they'd lock out the account after just a handful of tries. Correct. ~5 failed attempts forces you to use your authenticator code, and if you don't have one, you need to use their reset form and a captcha.
- chaud 14y agoThe game clients will lock an account out after ~20 or 30 attempts and I assume the website will do the same. No one is going to brute force an account.
- duaneb 14y agoYea, until someone steals their hashes.
- TWAndrews 14y agoAll your hashes are belong to us
- chetan51 14y agoThat seemed like a pretty bad way to handle it by Blizzard, though.
- karlshea 14y agoI agree, the mods on that forum seem like they forgot where their last straw went.
- Bud 14y agoAlthough this is a really silly bug, I did already know about it (it's the same in WoW), so frankly at the moment, I'm more concerned about the Diablo 3 bug which is causing a lot of us to not be able to successfully login and play, at all. Really not good.
- elithrar 14y ago> Although this is a really silly bug, Personally, I don't believe it is a bug at all. They have obviously made the decision to not enforce case in an effort to reduce customer service load/player frustration. Yes, it reduces the time needed to brute force your password if someone got hold of their user DB. But 1) we are still talking an excessively long time (their min. password length is 8) and 2) once they have that, you may have bigger problems. Whilst this is only anecdotal (over several years of WoW/SC2), the majority of compromised Battle.net accounts are through keyloggers/malware and phishing scams. In those cases, you can have a 40 character password with all the case sensitivity you like and it won't matter at all.
- emmelaich 14y agoIndeed, case sensitivity is annoying. Better off giving the user a warning for weak passwords. I'm even inclined to consider chars within the sets 0o and 1lL i the same, but that's even more controversial :-)
- drivebyacct2 14y agoI don't think anyone's nearly as concerned about case enforcement as they are about backend storage of passwords. I can assume some (plausibly safe) ways of storing/verifying passwords that are case insensitive, but I'm not naive enough to assume they do.
- eridius 14y agoWhy do you need to compare in a case-insensitive manner? Just lowercase the password before hashing it, and the backend doesn't even have to care.
- 14y ago
- tylermenezes 14y agoThey don't (or didn't, I haven't checked in the last few months) allow special characters, either. Seriously - what? (Then again, my bank does the same thing.)
- nodata 14y agoSo use a long password without them: password strength is what counts, not funny rules about special characters and minimum characters.
- nsmartt 14y agoThis is not the point. Users are put at risk because Blizzard fails to adequately impose security. Tech savvy users can just use a stronger password, but the others are put at risk by what I can only call negligence.
- Jare 14y ago(based on my anecdotal evidence) Most "normal" people do not use caps letters in their passwords. If you force them to do it, they'll capitalize the first letter and that's it. Compared to this, the lower amount of password-related troubles and customer service probably results in better overall password security. Phishing, keyloggers and various social hacks are the real problem. Blizzard has always been very active in this regard with their constant and visible reminders that "Blizzard will NEVER ask for your password", but most users disregard even that.
- nsmartt 14y agoMy fault. I didn't explain properly. I didn't mean it in the normal way- to require strict passwords. I meant in the sense that users who do add a capital in order to up their account security don't get that security added. Only users who know about this bug and go the extra mile then will benefit from the view of "So just make a better password without." I apologize if this is worded badly. I'm not feeling up to my usual ritual of rewording my post until I'm convinced it makes perfect sense to those who don't have magical insight into my mind.
- Steko 14y agoNot a bug. If you're worried about security as a user, d/l the free authenticator. If you're worried about Blizzard, don't -- they're big kids. You can run your 10+ million user game platform the way you want, Blizzard will run theirs the way they want.
- rcgs 14y agoJust like how we shouldn't worry about big kids Sony and their 70+ million network being compromised? Telling people not to worry about security works until they, inevitably, have their data compromised. Technically aware consumers have a responsibility to put pressure on companies to be secure with information.
- Steko 14y agoDid Sony offer a free authenticator? At any rate I'm not shedding tears for Sony if that's what you're asking. "Technically aware consumers have a responsibility to put pressure on companies to be secure with information." No one's shown that Blizzard has been unsecure with anyone's information. I see a lot of people running around like the sky is falling when it's not.
- Groxx 14y agoPrecisely the same way, yes. Sony's network being compromised had absolutely nothing to do with password case sensitivity, and absolutely everything to do with shoddy practices elsewhere that opened a massive hole into their database, allowing them to download millions of accounts worth of data. Millions of accounts from a single breach somewhere. Not millions of accounts individually brute forced because their case-insensitive passwords made them trivially guessable. We should be worried that Blizzard will get hacked like PSN was. That would be potentially catastrophic. But case sensitivity has almost no effect on password security unless your users ALL use random passwords.
- Zarathust 14y agoSo I need to buy a smartphone to enjoy basic security features.
- deleted 14y ago[deleted]
- kecebongsoft 14y agoI am interested to know how are they storing case insensitive passwords if they were not plain text, they only way I could imagine is by converting them in a full lower/upper case before hashing is performed.
- dangrossman 14y agoYou answered your own question.
- Jare 14y agoI'm curious, why would you doubt that your "only way" would not be what they do? It works, it's simple, it has no downsides.
- rmc 14y agoSome people think that they must be storing the passwords in plain text ( http://news.ycombinator.com/item?id=4022765 http://news.ycombinator.com/item?id=4022765)
- zeroonetwothree 14y agoThis wouldn't be so bad if they didn't restrict their passwords to at most 16 characters :(.
- gregcmartin 14y agoIf there is brute force protection on the login function blocking a username or IP from attempting x times in y hours AND there is a minimum of 8 characters then I can say thats strong protection on the backend. You are much more vulnerable to having your password phished rather than bruteforced.
- vibrunazo 14y agoComplete security newbie here. Doesn't it make brute force attacks almost worthless when you just have a minimum time between each login request after too many attempts per IP ? So you can only try to login every 30sec after you've failed 10 times in a row? I thought brute-forcing logins were a thing of the past after people started implementing this min time between requests strategy. The only weakness I can imagine would be a massive botnet forcing logins, but even then it would be severely limited. Am I missing something silly?
- Steko 14y agoCorrect, the heavy lifting for basic security is not done with a pw that has 50 bits of entropy and drives off your casual playerbase, it's done on blizzard's backend with lockouts after a few failed attempts.
- bluecalm 14y ago>Am I missing something silly? Yes. It's not that the bad guys try bruteforce to login multiple times and wait to be banned. They could (will/might) steal db with hashed passwords, do their decrypting at home and then login with what they got. The stronger the password (or better, ie slower to calculate hash used) the more time they need for that thus giving more time for Blizzard to realize passwords were compromised and block all accounts/force global password change. Really clever bad guys can do their homework before they have a chance to put their hands on hashed passwords by preparing hashes for say all passwords which are simple combination of words [1]. Now, once password db is compromised they just look for matching hashes and have instant access to some accounts. This is why you are told to use "strong" passwords, if they just try to "bruteforce log-in" that really wouldn't matter much. [1] http://en.wikipedia.org/wiki/Rainbow_table http://en.wikipedia.org/wiki/Rainbow_table
- Steko 14y agoThis assumes they aren't salting the hashes. But Blizzard apparently[1] uses SRP 6+ which does salt the hashes meaning if you and me have the same password we will still have unique hashes. [1] http://www.reddit.com/r/netsec/comments/u2168/blizzard_intentionally_makes_passwords_noncase/c4rtmae http://www.reddit.com/r/netsec/comments/u2168/blizzard_inten...
- tszming 14y agoNot sure about Diablo but one of the reasons I can think of why some web site's password is case in-sensitive (it is not uncommon) - they are checking the user password directly with MySQL, e.g. select * from users where user = 'john' and password = 'PASSWORD'; -- the password is actually case in-sensitive if your table collation is ci (which is the default) Of course this also implies the site is storing the password as plain text..
- gizzlon 14y agois that true if "password" is char or varchar as well? Or only for text fields?
- tszming 14y agoFor nonbinary strings (CHAR, VARCHAR, TEXT), string searches use the collation of the comparison operands The default character set and collation are latin1 and latin1_swedish_ci, so nonbinary string comparisons are case insensitive by default. http://dev.mysql.com/doc/refman/5.1/en/case-sensitivity.html http://dev.mysql.com/doc/refman/5.1/en/case-sensitivity.html
- rmc 14y agoIn that case there is a much much much bigger problem than case sensitivity. Hint: storing passwords in plain text
- TazeTSchnitzel 14y agoThat or they just do `password.lower()`
- tptacek 14y agoThat's not what Battle.net does. They use SRP, which dictates a specific strong cryptographic storage.
- Shivetya 14y agoWhat about, battletags do not obey real id preferences in your battlnet account? As in, I was in Diablo 3 beta. I joined numerous public groups. Apparently anyone who was in those groups can now see if I play World of Warcraft, which server I am on, and even what zone I am in. and there is nothing I can do about it. Zero, zilch, oh except buy Diablo 3 and change my settings from there because it can access features of my account the standard account management system cannot.
- Freestyler_3 14y agoI run a phone emulator and run the blizzard authenticator app on it.Works great for me and adds some security.
- ufo 14y agoDoesn't that kind of defeat the purpose of two-factor authentication?
- RKearney 14y agoThis has been the case since as long as I can remember. Not sure why it's an issue all of a sudden.
- soccerdave 14y agoAlso, most banks don't enforce case-sensitivity. I just logged in to my Chase account ignoring the case.
- loup-vaillant 14y agoEntropy of [a-z0-9] per character : 5,1 bits Entropy of [A-Za-z0-9] per character : 5,95 bits Entropy lost by case insensitivity (per character): 0,85 bits (15%) Bottom line: add 2 characters, and your password stays strong. Still, it would cool to warn users, or at least explicitly advise them to use longer passwords.
- Retric 14y agoOr if you care just use an authenticator which adds significant entropy without forcing you to remember anything. http://us.blizzard.com/store/search.xml?q=authenticator http://us.blizzard.com/store/search.xml?q=authenticator they all have free android / iOS apps.
- speleding 14y agoNot only is the entropy difference small, there is also an added benefit in less users having to reset their password. Forgetting how their password was capitalized is a big problem for people. Letting improved user experience trump a tiny bit of extra security is a good tradeoff for Blizzard. They're not a bank.
- JackC 14y agoFWIW, I think I read at one point that WoW accounts were worth more on the black market than credit card numbers. So security isn't totally unimportant.
- stordoff 14y agoI wonder if this (to some extent) offsets the loss of security by converting to uppercase. I know that I have reduced the complexity of passwords I forget (often by limiting them to lowercase), so I suspect other users do the same when they reset.
- loup-vaillant 14y ago> They're not a bank. Definitely not. My bank forces me to use only numbers, and only six of them. Strooonng security. The only way out of key loggers I suppose (they make me click on numbered boxes).
- TomGullen 14y agoThis isn't a bug at all. I would question the assumption that case sensitivity increases the actual search space significantly, theoretically it does but in practise most users will: - Uppercase first letter only - All lowercase It's a usability decision from Blizzard, not a bug.
- peeters 14y agoAlso, to address this comment in the thread: > This means they probably store passwords in plain text, unsalted, etc. This is unbelievable. It absolutely does not make that any more likely. All you have to do is normalize it to upper/lower case before hashing and you have case insensitivity.
- fffggg 14y agoThe following banks and financial institutions also silently discard case-sensitivity: Citibank Chase Wells Fargo E-Trade US Bank Fidelity Investments SECU HSBC TechCU
- alirov 14y agoI just tried my American Express account and you can add that to the list of financial institutions discarding case-sensitivity.
- blindhippo 14y agoWhen are we, as a society, going to solve the password problem? Passwords are a terrible mechanism for solving security - to make them "secure" you have to enforce stringent policies creating passwords that are not memorable to many users, leading to passwords being written down. Add in the fun of needed to know far too many passwords (my daily count is at 17...). Honestly I don't know enough about cryptography or security in general, but could an application be locked down using a public/private key (ala, SSH)? I'd love the ability to generate my own key (with my own password) and assign it to any application.
- dclowd9901 14y agoProbably when bio-based methods of authentication become cheaper and more commonplace. The problem is the passwords themselves: having to remember something arbitrary and outside the normal context of your day. Hell, their sole purpose is to be cumbersome.
- scoot 14y agoIs it completely beyond the bounds of possibility that they're storing the password as originally entered (salted & hashed), but trying all combinations of upper / lower case at login-time (only after the entered password fails)? It would only be for a small subset of logins, and for the majority of passwords, a manageable number of combinations (2^num-alpha-chars-in-passwd). I believe Facebook do something similar.