Get rid of Bnet Security check

Not trying to be rude or anything here. But Bnet security check code. Needs to be removed…

SO lets talk about “man in the middle attacks”. Basically if the system a person is using to login, is compromised. I am NOT endangering more than 1 account at a time, of being attacked.

Now, with 2 accounts being logged into (email account and Blizzard) and if this was a “hot” computer where it had a R.A.T. present. This would now have 2 accounts compromised.

(An email account and the Blizzard account. )

It is quite simple. As long as an account has 2 simple yet very sophisticated and “hard” forms of security on ONE login screen

“user name”

“password” it works out very well!


When you went to

“email address”

“password”.

You have reduced that security factor.

If I know your email address and can login to random websites. I can now just mill websites and see if it generates an “inncorrect user password” - thus knowing that I have found out that it is an EMAIL address registered to the website. Which has removed 1/3rd of the equation.

Google and hotmails biggest issues is: they use an email FIRST, then a button, then ask for a password. SO a person can sit there all day and figure out what email addresses are registered to a website.


You are 100% welcome to hide this post, but I am telling you, this is a really bad idea and you do need to know about it.

Oh and for the love of all things on earth. no SMS phone verification stuff. Thats a quick way to lose an account if a phone is smashed, broken, stolen or the towers are down.

“In the world of computer security, security does not exist, only obstacles and hurdles”.

Just create a unique email account for all blizzard games; boom, no more problems. I highly recommend getting a few domains that have support for “catch-all” email addresses so that you can just make up email addresses and they are all forwarded to a private inbox that no one knows about. For example, say you buy the domain “hsjduikh . com”, you can then just specify the email address “djfhskldfhuihuifdgvgy78432brjhkg @ hsjduikh . com” that will automatically get redirected to “me@hsjduikh.com”. Ezpz and fairly secure. Everyone should own their own domain in this day and age, but no one teaches about these principles, so we’re left with companies to pick up the pieces instead of blaming the people that employ bad security practices.

1 Like

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.