Keychain Authenticator
iPhone Authenticator
The authenticator generates a 6 or 8 digit number which is used as a one-time password (OTP). Knowing the username and account password isn't enough. The authenticator is available as a stand-alone device (sold by Blizzard and called Key Fob), or a smartphone app available on iOS or Android.
The numbers generated are predictable in nature so that the server can come up with the same number as your authenticator at the same time. How that happens is the secret sauce and a well guarded secret. However, even if that secret got out, it still wouldn't make your authenticator vulnerable. The seed that starts the sequence when the Authenticator begins its life is based on a range of variables, many of them random, for each individual authenticators. So for someone to figure out exactly the sequence of numbers generated by your authenticator, that person needs to know precisely the algorithm used and the parameters that built the start of life of your particular Authenticator. Quite a lot a work just to get into one account.

But you should still be careful

Be warned, though, the numbers generated have a 60 seconds life span. If you get lured to a phishing site that asks your username, password and authenticator code (and assuming you typed all that), you are still very vulnerable for the lifespan of the number. If the hacker gets your info and acts on it fast enough, you could still get hacked so it's very important to always be aware of the sites you visit. However, the chances of that are slim since it all has to happen within a 60 seconds window or less.

Questions frequently asked on the forums

What Is It?

The Authenticator is a physical key fob while the Mobile Authenticator is a mobile phone application that generates an 8 digit code that is entered after entering your World of Warcraft Password. This second factor of authentication helps to secure your account from being hacked.

I change my password frequently, I don't need one do I?

Are you sure? Frequent changes are not defense against key-loggers. Even if you believe you are safe against those, brute force attacks are more common than you might think. In the time between password changes, a hacker could get in your account. With the ever changing authentication code, you won't have to worry about that.

What's in it for me?

Besides security of your account, you also get a cute little Core Hound Pup. [Core Hound Pup Image]

How bad is getting hacked, really? Its just a game, and Blizzard can replace everything right?

If you are hacked, the process for restoring your character to its default state can take weeks. You'll first need to contact Blizzard to verify your account (as most hacks result in the account being locked out), change your password, and unlock your account. Once this is done, you'll need to login to each character you have and take inventory of what's missing. You'll then need to submit a GM Ticket with a list of the missing items from each character for them to restore... and then you wait. The ticket will be escalated from a GM to a specialized team. That team will investigate your situation, and once verified, will mail you your items and gold back.
  1. This process can take 2 or more weeks depending on many factors including holidays, how many hacks are occurring, etc.
  2. You may not get all items back. Some items or gold amounts may not be restored.
  3. During this time, its likely you've been cleaned out... no armor, no money, no mana-replenishing drinks, nothing.

Where do I get one?

You can get the Authenticator Key Fob from the Blizzard Store here. [1] The key fob costs US$6.50.
You can get the Mobile Authenticator for the iPhone or iPod Touch here. [2] The application is Free.
You can get the Mobile Authenticator for Android by searching the Android Market for " Authenticator" [3]
You can get the Mobile Authenticator for other phones on US/EU Carriers here. [4] The application costs 99¢US.

Is there a guild policy?

Alea Iacta Est has no restriction or policy governing the use of an authenticator. However, the officers strongly recommend use of authenticator.

Shouldn't Guild Officers be required to have an authenticator?

While previously they were not required to, the policy has changed.

What about the Guild Master?

Lanctharus has an authenticator.

What does Ingvar the Plunderer think?

Ingvar the Plunderer says (in a posh British accent), "Really, get an authenticator.... or I WILL PAINT MY FACE WITH YOUR BLOOD!!!!"


  1. Added layer of protection for your accounts
  2. Easy to use and adds little time to login


  1. If you lose, break or otherwise destroy the authenticator you will be locked out of your WoW account until you can get it removed.
  2. Adds extra step to login process


What do I do if I break/lost my Authenticator?

Blizzard will have several support options available to assist you and ensure that the impact on your play experience is minimized in the event of a problem with your Authenticator. Please contact Billing and Account Services for assistance if you have questions.

What can I do beforehand to make the process easier if I do lose/break it?

Physical authenticators (the ones sold by Blizzard) all have a serial number in the back. The Mobile Phone Applications have a serial number in the setup screen of the application. It is highly recommended to write down that serial number somewhere like a Google Docs document, for instance. That way, if you lose your authenticator or left it at home while on a trip, you can easily use the serial number to call Blizzard and have it removed from your account temporarily so you can still play.