Feeds

World of Warcraft spykit gets encrypted

Increases effective stealth level by 5

5 things you didn’t know about cloud backup

Tuesday's patch to World of Warcraft introduced new content and tweaks to the land of Azeroth, but with it came an important change to The Warden, Blizzard's ill-famed tool against cheaters.

According to Warden-watching modders, the latest version is now encrypted, adding a major barrier for tinfoil hats who track what information the application sends home to Blizzard.

The Warden's function as an anti-hacking sentry was already cause for concern for some privacy advocates. From the moment players log into the game, The Warden checks open window names, process names, memory modifications, DDL names and other pieces of data in the background. The goal is to determine if the user has a specific hack or program loaded and sends back a "yes" or "no" answer to Blizzard.

At any given time, there is one version of The Warden active in a set of WoW servers. But Blizzard fights would-be countermeasures against The Warden by switching between hundreds of different copies of The Warden with the same functionality, but containing slight modifications in the code.

This technique of polymorphic code is more commonly applied in computer viruses and worms as a way to avoid detection from anti-virus and intrusion detection software. According to The WardenNet, a website dedicated to tracking the iterations of the application, there are about 320 copies of The Warden in circulation.

World of Warcraft tinfoil hat

There are some legitimate arguments for the intrusion of privacy. Massive Multiplayer economies such as WoW can be ravaged by gold-farming bots or hacks. It's Blizzard's responsibility to not only protect the game experience, but their intellectual property and marketability of the game. And nothing, after all, is forcing anyone to play if they disagree with the policy.

Blizzard maintains that The Warden does not gather any personally identifiable information about the player. They claim only information about the account is sent back. Third-party applications such as The Governor and ISXWarden could previously monitor The Warden and curtail activities the authors deem invasive.

But with Blizzard now utilizing a different random cryptographic hash function in every copy of The Warden, customers lose that potential safeguard. On one hand, most customers have already put a large amount of trust in the company by giving Blizzard their credit card to pay the monthly fee. On the other, this could theoretically give Blizzard access to other pieces of private information without customer knowledge.

Such a scenario may be a stretch, but the change is indicative of the leaps of faith some companies are asking (and too often not asking) their customers to make in order to protect their software.

As of this publication, Blizzard has not returned requests for comment. ®

Secure remote control for conventional and virtual desktops

More from The Register

next story
One HUNDRED FAMOUS LADIES exposed NUDE online
Celebrity women victimised as Apple iCloud accounts reportedly popped
Rubbish WPS config sees WiFi router keys popped in seconds
Another day, another way in to your home router
Goog says patch⁵⁰ your Chrome
64-bit browser loads cat vids FIFTEEN PERCENT faster!
NZ Justice Minister scalped as hacker leaks emails
Grab your popcorn: Subterfuge and slur disrupts election run up
HP: NORKS' cyber spying efforts actually a credible cyberthreat
'Sophisticated' spies, DIY tech and a TROLL ARMY – report
NIST to sysadmins: clean up your SSH mess
Too many keys, too badly managed
Scratched PC-dispatch patch patched, hatched in batch rematch
Windows security update fixed after triggering blue screens (and screams) of death
Attack flogged through shiny-clicky social media buttons
66,000 users popped by malicious Flash fudging add-on
New Snowden leak: How NSA shared 850-billion-plus metadata records
'Federated search' spaffed info all over Five Eyes chums
prev story

Whitepapers

Endpoint data privacy in the cloud is easier than you think
Innovations in encryption and storage resolve issues of data privacy and key requirements for companies to look for in a solution.
Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Advanced data protection for your virtualized environments
Find a natural fit for optimizing protection for the often resource-constrained data protection process found in virtual environments.
Boost IT visibility and business value
How building a great service catalog relieves pressure points and demonstrates the value of IT service management.
Next gen security for virtualised datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.