Blizzard - fixed without reporting; original findings shown

https://blizzard.com
Recommended Configuration Proprietary; Email; SMS
Alternate Configuration 1
Alternate Configuration 2
Alternate Configuration 3
Account/Password Recovery PR SMS; PR email
Remarks automatic SMS backup signup using phone number on file; automatic email backup signup using email on file; proprietary app can be disabled with SMS
Responses

Notified on January 11, 2020.

Received response on January 15, 2020; response comprised of a template acknowledgement.

Silently fixed vulnerability without notifying us as of March 8, 2020; this page represents our original findings.

img
2fa_backup_step0.PNG
img
2fa_backup_step1.PNG
img
2fa_proprietary_active.png
img
2fa_proprietary_inactive.png
img
2fa_proprietary_signup_setup0.png
img
2fa_proprietary_signup_setup1.png
img
2fa_signup_step0.png
img
2fa_signup_step1.PNG
img
2fa_signup_step2.PNG
img
phone_reg.png
img
pr_step0.PNG
img
pr_step1.PNG
img
pr_step2.PNG
img
pr_step3.PNG