PDA

View Full Version : Security flaw allows addons to expose full real life names without user permission


TalonBot
07-06-2010, 12:50 PM
http://www.blogcdn.com/www.wow.com/media/2010/05/realid-article-header-thingy-unique-title.jpg

There is a flaw in the design of the Real ID system (http://forums.wow-europe.com/thread.html?topicId=13816898018&sid=1#0) which, (as we understand it) thanks to you being an automatic Real ID friend of yourself, allows any addon to expose your real life name to anything or everyone; even if you have not marked those people as a Real ID friend.

We're hopeful that Blizzard corrects this design issue soon. From what we can tell, this has not yet been fixed.

In the mean time, we strongly encourage users to make sure only trusted addons are installed. Take a few minutes and be doubly sure that only those addons you need and know where they come from are running.
Filed under: News items (http://www.wow.com/category/news-items/)

Security flaw allows addons to expose full real life names without user permission (http://www.wow.com/2010/07/06/security-flaw-allows-addons-to-expose-full-real-life-names-witho/) originally appeared on WoW.com (http://www.wow.com) on Tue, 06 Jul 2010 15:30:00 EST. Please see our terms for use of feeds (http://www.weblogsinc.com/feed-terms/).

Read (http://forums.wow-europe.com/thread.html?topicId=13816898018&sid=1#0) | Permalink (http://www.wow.com/2010/07/06/security-flaw-allows-addons-to-expose-full-real-life-names-witho/) | Email this (http://www.wow.com/forward/19543875/) | Comments (http://www.wow.com/2010/07/06/security-flaw-allows-addons-to-expose-full-real-life-names-witho/#comments)

http://feedads.g.doubleclick.net/~a/D8fwVaBrRX0hFBwXFpY0HF_8VsY/0/di (http://feedads.g.doubleclick.net/~a/D8fwVaBrRX0hFBwXFpY0HF_8VsY/0/da)
http://feedads.g.doubleclick.net/~a/D8fwVaBrRX0hFBwXFpY0HF_8VsY/1/di (http://feedads.g.doubleclick.net/~a/D8fwVaBrRX0hFBwXFpY0HF_8VsY/1/da)



More... (http://feedproxy.google.com/~r/WowInsider/~3/60PMgDeOzwg/)