anterozz wrote:You're mentioning that kind of hack. You're not mentioning the one were they actually hacked accounts with 0 malware/virus usage, or the ones where they still were able to login when the physical authenticators were still linked to the accounts. Or how they removed authenticators despite needing the physical serial behind the authenticator.
Yes, I did. It is easy to hack a phone with a malicious app that roots the phone and grabs the serial and login information. Or did you TL/DR? Here, I'll quote that sentence for you.
Uzephi wrote:Also if a phone is jailbroken and/or rooted, the authenticator seriail is easily accessible through the data/data directory of the phone. (can only be accessed with superuser rights). There is known root exploits for all types of phones to get temp root access and grab this serial. Again, this is on the USER's side of the spectrum, not Blizzard's. IE you download a playstore app that was "fan made" to maybe show your character's stats or something and it had the malicious code to temp root your phone and grab the serial, and sometimes LOGIN (if you have the armory app, that logs you in and saves your login credentials at a superuser level as well) credentials. That makes it pretty easy to compromise the account.
Edit: if a physical authenticator was compromised, it was in the infancy of the introduction of said authenticators and has been stated by blizzard it was malware that was on the PC that sent the codes to the hacker for them to duplicate the serial or remove it via what I said before. Not once did blizzard admit to their data center being compromised. It has always been the user's fault of bad security measures.