Security for the WoWer
(zomg no moar keyloggerz)

Almost every day, I see someone posting that their account has been hacked, their keys have been logged, their purples sharded, their gold gone, etc etc. I threw together this simple site because in response to all this I see a lot of misconceptions and bad information on how to keep safe.

The basics of security

You've heard it all before, but it's important.

About keyloggers

There are a lot of misconceptions about keyloggers. Time to clear that up.

  1. Your keyboard is not the only thing being monitored!
  2. Copy/Pasting your password will not protect you from a keylogger. (see #1)
  3. A virtual keyboard will not help either. (see #1)
  4. IP restrictions won't help much either. Consider that people move around, go to a friend's, and their IP at home may change quite often as well. It's even possible at times that the new IP would bear no similarity at all to the old. It'd be a huge hassle, and a fair majority of WoW players probably have no clue what an IP address is. Once an account is compromised, what's to stop them from adding whatever IP they want to the allowed list?
  5. A captcha-type system such as Bank of America's sitekey won't help.
  6. A dual-password system like one posted on the suggestions board, where the WoW client (or even the server) stores one password which you chose at account-creation and you enter a second won't help either.

There is only one way to keep login information safe, even on an infected computer: two-factor authentication. That's why captchas and dual-password systems will not work, they are still single-factor schemes. They're both "something you know" as opposed to "something you are" or "something you have." For an example of a working two-factor authentication scheme, take a look at Paypal's security key.

Given that WoW doesn't support such a scheme yet the best way to keep your login info safe is not to get your computer infected and not to share your login info with anyone.

About Addons

Legitimate addons cannot harm your computer, as they contain no executable code. While it is theoretically possible that a hacker could find a weakness in WoW's LUA interpreter and exploit it, the chance of that happening is rather slim.

If you download an addon and it contains an executable (.exe, .bat, .pif, .com) delete it -- addons don't need executables and if it did, it's against TOS as a 3rd-party program anyway.