A brief RealID roundup

In a particularly stunning display of announce-first apologise-never, Blizzard have now linked our real names to our WoW accounts via their RealID system, whether we’ve used it at all or not.

The Internet is going crazy – and for once, with good reason.

**Addons can access your real name


The RealID system appears to be quite insecure. Any addon you have installed can access your real name. Here’s a quick script (from MMO Champion via Threadmeters) to demonstrate the problem. Copy-paste it to your WoW chat window and press ENTER to check if an addon can currently access your real name through WoW.

(I may turn it into an easy-install addon to check your safety in the near future – post if that would be helpful.)

That, of course, is no problem if you read all the code of every addon you install, or personally know and trust all the people who write and update all your addons.

(I’m British. That was sarcasm.)

I’d expect this potential exploit to be fixed, but so far we have no word of that from Blizzard. If it isn’t fixed, I’d be astonished if we don’t see a malware addon exploiting it within six months.

You’ll have to use your real name on any worldofwarcraft.com forum posts

[Update: Blizzard have backed down on this. You’ll not have to use your real name on the forums. Still no word on the RealID exploit above, though.]

That’s a problem for a lot of reasons. One of the Blizzard community managers aptly demonstrated a lot of them in a Jeremy Clarkson-esque fashion by posting his real name to show how safe it was.

Turns out, not very.

The best discussion of the problem I’ve seen comes from Elitist Jerks, where, in an unprecedented move, the moderators have lifted their ban on whining for this one topic.

EJ has a lot of excellent debate and discussion of everything WoW will lose if it loses anonymity. A lot of the top-level theorycrafters are also overachievers in other areas, and don’t want, for example, their highly successful law careers linked via Google to postings about being an orc.

Solutions please?

Tobold has a guide to turning RealID off on your system. Unfortunately, the only way to avoid RealID at present is to use the Parental Controls to, er, pretend to be your own parent. I can’t possibly see how that could go wrong.

“Your dad says you can’t play WoW past 10pm!”

“But that’s me! I pretended to be my own father to opt out of your idiot scheme!”

“Alright, sonny, off to bed or it’ll be no hot chocolate for you.”

However, as the suddenly-sibylline Tobold points out, with Blizzard already making major security gaffes and annoucing rather sweeping additions to the RealID system, if you want your identity to remain safe in WoW, this may be the best and only way.

There may yet be another twist.. Multiple sources (on the Internets, natch) are claiming that both the UK and French data protection authorities are currently investigating Blizzard with relation to RealID. Let’s see what happens.

Link Sources

  • Addon test script source mmochampion via Threadmeters.com.
  • Blizzard CM real name fail linked from WoWRiot because the official forum thread has, unsurprisingly, Gone Away.
  • Opt-out link from the inimitable Tobold.