Nijle
Member since: Oct 11th, 2006
Nijle's Latest Comments
Blog Activity
| Blog | # of Comments |
|---|---|
| Card Squad | 4 Comments |
| Joystiq | 1 Comment |
| Engadget | 1 Comment |
| AOL TV | 2 Comments |
| Joystiq Nintendo | 1 Comment |
| WoW | 27 Comments |
| Joystiq Xbox | 1 Comment |
| Massively | 1 Comment |




Breaking: Sign up to test The Old Republic
Sep 29th 2009 12:48PM (Massively)The Queue: Shields, forums, and more on raid difficulty
Dec 4th 2008 12:49PM (WoW)LMAO
Around Azeroth: Super-size me
Oct 23rd 2008 10:30AM (WoW)Nice!
Spellpower 101, or how I learned to love unified attributes
Oct 14th 2008 11:47AM (WoW)Take my paladin for example. His Gladiators Salvation currently has 375 healing and 175 damage. After patch it will have 199 Spell power. That's going to equal the same amount of Healing power, and increase my damage by 24 on that one item. Now take all my healing gear i have and add it all up, i'm getting a big spell damage boost!
Lake Wintergrasp: Balance, badges, bosses, and bling
Oct 13th 2008 9:12AM (WoW)The Engineer's dilemma
Sep 23rd 2008 3:06PM (WoW)The Engineer's dilemma
Sep 23rd 2008 2:58PM (WoW)Such things like saddle bags, windscreens, rims, exhaust kits, performance upgrades, biker jackets from tailors, etc.
??
Ask a beta tester: Let's get this party started!
Jul 28th 2008 11:50AM (WoW)Authenticators sold out, for now
Jul 3rd 2008 10:22AM (WoW)Lets ask a question here, what is the #1 way your account gets hacked? The answer is KEYLOGGERS. SecurID tokens do have vulnerabilities, and the #1 vulnerability to a SecurID two-factor authentication token is the man-in-the-middle type of attack. Since you are putting in a one time password and that gets logged, it will be utterly USELESS to a keylogger type of attack.
Man in the middle type of attacks work like this. You log into the game, it sends your username/password/ and one time 6 digit code out on to the internet. The "man in the middle" intercepts this data from you, then forwards the same info to the blizzard servers. Now they are logged in as you. For this type of use (a video game) this also would be useless. Why? Well think about it. Lets say you are plugged into a network in a college dorm and some Computer hacker geek type saw you playing wow saw your L33t gear and decided he wants to hack your account. He performs a man in the middle attack on you and logs into the game. In the mean time you have hit submit on the log-in page and are now waiting to log in. The client never gets the response from the authentication server and times out. He is running your toon to the bank intent on selling all your phat loot. You say, oh well let me try again and you submit again, this time you log in and he will be logged out. If he tries to use that 6 digit code you originally sent again it will not work as it will time out after about 60 seconds when the token code changes. Again the hacker fails, next time he'll just come steal your token off your desk :)
Lets say someone does know the algorithm that they use in the blizzard tokens. Again even if they had your account password (from say a keylogger) they would still need to get the (typically 128bit) key associated to your token. This is only stored on the host server and inside the token and you will never be sending this key out over the internet. So when you send your login/password and 6 digit code to the server, the server knows which 128bit key is yours (from the username/password you sent) and plugs that into the time based algorithm to check if your 6 digit code was correct.
Please unless you know what you are talking about do not post crap like "oh these will be hacked in three weeks" it really makes you sound dumb. Blizzard could not have picked a better layer of security to add to the game IMHO.
Reading between the lines: are more PvE to PvP transfers possible?
Jun 16th 2008 10:40AM (WoW)Have had both leveling experiences, i feel it took less time to level on the pvp server since i had done it twice before. I also enjoyed the increased challenge of the PVP side.