Feeds

World of Warcraft spykit gets encrypted

Increases effective stealth level by 5

Securing Web Applications Made Simple and Scalable

Tuesday's patch to World of Warcraft introduced new content and tweaks to the land of Azeroth, but with it came an important change to The Warden, Blizzard's ill-famed tool against cheaters.

According to Warden-watching modders, the latest version is now encrypted, adding a major barrier for tinfoil hats who track what information the application sends home to Blizzard.

The Warden's function as an anti-hacking sentry was already cause for concern for some privacy advocates. From the moment players log into the game, The Warden checks open window names, process names, memory modifications, DDL names and other pieces of data in the background. The goal is to determine if the user has a specific hack or program loaded and sends back a "yes" or "no" answer to Blizzard.

At any given time, there is one version of The Warden active in a set of WoW servers. But Blizzard fights would-be countermeasures against The Warden by switching between hundreds of different copies of The Warden with the same functionality, but containing slight modifications in the code.

This technique of polymorphic code is more commonly applied in computer viruses and worms as a way to avoid detection from anti-virus and intrusion detection software. According to The WardenNet, a website dedicated to tracking the iterations of the application, there are about 320 copies of The Warden in circulation.

World of Warcraft tinfoil hat

There are some legitimate arguments for the intrusion of privacy. Massive Multiplayer economies such as WoW can be ravaged by gold-farming bots or hacks. It's Blizzard's responsibility to not only protect the game experience, but their intellectual property and marketability of the game. And nothing, after all, is forcing anyone to play if they disagree with the policy.

Blizzard maintains that The Warden does not gather any personally identifiable information about the player. They claim only information about the account is sent back. Third-party applications such as The Governor and ISXWarden could previously monitor The Warden and curtail activities the authors deem invasive.

But with Blizzard now utilizing a different random cryptographic hash function in every copy of The Warden, customers lose that potential safeguard. On one hand, most customers have already put a large amount of trust in the company by giving Blizzard their credit card to pay the monthly fee. On the other, this could theoretically give Blizzard access to other pieces of private information without customer knowledge.

Such a scenario may be a stretch, but the change is indicative of the leaps of faith some companies are asking (and too often not asking) their customers to make in order to protect their software.

As of this publication, Blizzard has not returned requests for comment. ®

Mobile application security vulnerability report

More from The Register

next story
HIDDEN packet sniffer spy tech in MILLIONS of iPhones, iPads – expert
Don't panic though – Apple's backdoor is not wide open to all, guru tells us
NEW, SINISTER web tracking tech fingerprints your computer by making it draw
Have you been on YouPorn lately, perhaps? White House website?
LibreSSL RNG bug fix: What's all the forking fuss about, ask devs
Blow to bit-spitter 'tis but a flesh wound, claim team
Black Hat anti-Tor talk smashed by lawyers' wrecking ball
Unmasking hidden users is too hot for Carnegie-Mellon
Manic malware Mayhem spreads through Linux, FreeBSD web servers
And how Google could cripple infection rate in a second
NUDE SNAPS AGENCY: NSA bods love 'showing off your saucy selfies'
Swapping other people's sexts is a fringe benefit, says Snowden
Own a Cisco modem or wireless gateway? It might be owned by someone else, too
Remote code exec in HTTP server hands kit to bad guys
prev story

Whitepapers

Reducing security risks from open source software
Follow a few strategies and your organization can gain the full benefits of open source and the cloud without compromising the security of your applications.
Consolidation: The Foundation for IT Business Transformation
In this whitepaper learn how effective consolidation of IT and business resources can enable multiple, meaningful business benefits.
Application security programs and practises
Follow a few strategies and your organization can gain the full benefits of open source and the cloud without compromising the security of your applications.
Boost IT visibility and business value
How building a great service catalog relieves pressure points and demonstrates the value of IT service management.
Consolidation: the foundation for IT and business transformation
In this whitepaper learn how effective consolidation of IT and business resources can enable multiple, meaningful business benefits.