http://i16.photobucket.com/albums/b20/Cat0234/osk.png
Well, this should stop the hacking wave.
Better late than never, but this is a very nice touch by SE.
http://i16.photobucket.com/albums/b20/Cat0234/osk.png
Well, this should stop the hacking wave.
Better late than never, but this is a very nice touch by SE.
All it would take is for a key-logger to track the mouse position relative to the game window and log where it clicks and that'd be rendered bogus no?
Nice of them to try anyways, it'll stop them for awhile until they break this as well. The system really needs a security pin/question in the account-settings section though, unless they added one of those as well?
Now that is a very nice touch, thank you SE.
edit: I was kind of thinking that too, but with different screen resolutions and just repositioning it constantly you would still stay fairly safe.
Holy shit.
EDIT: Nice wallpaper.
Theoretically, you're right, but this is a step in the right direction for SE. Obviously security questions would be even nicer for PW changes and such, but ya know, baby steps. They tried the software-based keyboard for the LS community and it had a relative degree of success. I know *I* use it when I log in to the LS community now.Originally Posted by Kaisha
The letter and number locations should randomize every time you start it up, that would work fine.
I agree with the baby steps comment. Rather than say things like it's still not safe, we should be glad they're headed in the right direction to making things better.
Good job SE.
Where do you get this from? I dont see it anywhere in POL news.
Edit: Nvm I see it now, wasn't there like 2 mins ago.
Official announcement:
http://www.playonline.com/ff11us/polnew ... 3581.shtml
Jun. 9, 2008 11:55 [PDT] From: PlayOnline
Heightened Security on the Windows PlayOnline Viewer
Due to the sudden increase in unauthorized access on the internet, PlayOnline has decided to heighten the security for all of its related services. As part of these security measures, we have introduced the following features.
- The software keyboard
We have implemented a special field for entering passwords (PlayOnline passwords and PlayOnline mail passwords) and other important information through a software-based keyboard that uses the mouse for text entry.
The software keyboard is displayed when you select one of the password-entry fields on the PlayOnline Viewer. Because each key is entered by clicking with the mouse, this software is effective against a type of spyware known as a keylogger that is capable of stealing information entered through regular keyboards.
You can, of course, still enter your password with a keyboard as usual, but we recommend using the software keyboard to improve your private information’s safety. The software keyboard provides safety and security for users who enter their passwords each time without saving them.
- Security Settings
We introduced "Security Settings" to manage PlayOnline passwords with even further heightened security.
Because passwords entered on the PlayOnline Viewer are encrypted and saved to the hard drive to prevent other computers from decrypting them, even if the corresponding file is stolen, no password information will be accessible.
To advance our security technology even further in dealing with spyware, we have made the encryption key for each computer randomly generated and saved to a destination folder the user designates in "Security Settings." For example, if the user saves the key file to an external device such as a USB memory card and disconnects the device when it is not needed, security will be considerably strengthened.
"Security Settings" has been added to the PlayOnline Viewer's Login menu. After selecting it and designating a destination folder for the encryption key, a file name composed of random alphanumeric characters will be created in that folder.
*The encrypted PlayOnline password and encryption key will not only be accessed when starting the PlayOnline Viewer and logging in, but will also be periodically accessed while playing an online game or using the Viewer. In particular, be careful about the following things:
- If you have saved the encryption key to an external device or a network drive, do not disconnect the device while playing a game or using the PlayOnline Viewer.
- If you have saved the file to an external device or a network drive, make sure the drive is the same as the one designated in "Security Settings."
*If the PlayOnline Viewer cannot access the encryption key, the saved PlayOnline password information will be erased and the encryption key will become unusable. In such a case, your account will not be affected, but you will need to re-enter your PlayOnline password to save it to a new encryption key. Each time you use "Security Settings," a new key file is generated with a new random file name and different contents. Deleting an old file will not cause any problems.
*"Security Settings" are shared by all registered members, and users cannot designate different folders for each member. Also, if PlayOnline password information is erased, it will be necessary for all registered members to re-enter their PlayOnline passwords once more.
Originally Posted by Tomiko
Sadly most people expect home runs every time. It is easy to forget that security is a work in progress and that this may seem rudimentary but it is a step in the right direction for once, no matter how you slice it. They could have easily released their patented phrase "We will look into this issue further" and never hear anything EVER again. While it does not solve the issue, it is a step and A step is better than NO step at all.
I hope the stick with it and go upward from here in regards to security.
Combine this with storing your l/p in some /random directory or on a usb key makes this security patch amazing. A nice step in the right direction SE. Cookies for you!
That's great. While it wont stop someone who wants to specifically hack ffxi, it will hurt many of the most generics keylogger.
The other security thing is pretty nice for paranoid people too.
even though it is possible to bypass security such as this, it's really a great addition to have for a few reasons. The keyloggers that RMT usually use are the same ones that have been in circulation for the past 5 years that compromise any kind of info; not just FFXI. With this in place, it will take a little while before one is designed specifically to compromise this; and in which case it does happen, SE has more control over what further protective methods can be put in place.
I've been playing 5 years and I never understood why people were so critical of Square/Enix until now.
Two of my very dear friends had their passwords changed last week, their FFXI data unlinked from the Community site, and all of their equipment moved to easily identifiable RMT accounts and sold.
AN ONSCREEN KEYBOARD THAT WINDOWS ALREADY HAS IN IT DOESN'T MEAN JACK SHIT.
I'm sorry, but that's how pissed off I am. This isn't a few isolated cases of friends jacking accounts, or RMT groups getting lucky with randomly placed Keyloggers. This is a concentrated, perfectly executed attack on many of the people who have played years and years and keep everyone involved in this game employed.
SE knows this, that's why they responded so quickly (with this fucking joke) to make up for the fact that they have no way to prevent this from happening. The two hacks I personally know about were both done Friday after the information center was closed, leaving RMT full access to people I love's accounts for over 60 hours.
Attention everyone on earth:
THERE'S NO FOOL PROOF WAY TO PREVENT ANY SYSTEM FROM BEING HACKED EVER.
SE NEEDS TO:
1) Create a Password that, along with full name/birthday/social security number/Full Credit Card Number WITH CVV, can be used 24/7/365 through an automated system to lock accounts/change passwords/any other thing that can be automated for your account. YOU COULD PUT THIS ON POL's WEBSITE.
I've seen every single post about how players accuse other players of not being secure/letting out their info/etc, and SE's smug responses to hackings in POL notices saying people need to up their security. This is the easiest way to prevent it, and it took me maybe 5 minutes to think of it. gg idiots and lazy assholes, could have thought of this instead of pointing the finger.
2) Allow players to create their own rollback points so that, with the assistance of a GM, they are able to retrieve lost Equipment/Progress using the Password I stated above. They could limit them to say, 2 months or so, and could only be performed if you had said info/password from 1).
WOW, HOW FUCKING HARD WAS THAT.
It's Square Enix's job to create a way for players to regain control of their accounts. This is the first time I have ever been dissapointed with SE, and that says a lot considering the myriad of out of control yet easily solved problems I have seen in FF over the years.
This is the biggest threat FFXI has ever seen.
The sad part is that is almost the easiest one to remedy.
your friends desserved to get hacked
I see this, it seems great but am I missing something here?
My account was jacked recently and I never typed into the password. It had been stored on the computer long before the theft. smart.dll hooked onto pol.exe somehow and no one seems to have posted exactly how it worked but it seems it was more than just a keylogger. So does this encryption thing protect the user Id and password in memory as well?
1. Get K.club and make a rollback point.Originally Posted by didgist
2. Sell K.club.
3. Give gil to a friend.
4. Rollback
5. Repeat in 2 months.
1. Get K.club and make a rollback point.
2. Sell K.club.
3. Give gil to a friend.
4. Rollback
5. Buy new accounts for you and a friend because they were banned for exploiting a little used and, thus, easily tracked system.
5. Slap yourself
Fixed.
GM(Or STF) Assistance pertains to verifying you were hacked, tracking where the items you are rolling back into went, and making sure it's not a scam. Maybe a bit overboard, but losing your account to RMT seems worse.
SE has redeemed itself, kind of.
One of my friends who was hacked Friday called in today and was given back their account. She found out that the character had been moved from Fenrir to Kujata and all the money items had been sold.
SE gave back the account, is moving the character back to it's original server within a week, and is performing a FULL ROLLBACK, giving back every single item that was on the account the last time the account was legitimately logged in to.
If you get hacked by the "Insert first 3 letters of server "Insert Chinese" group PLEASE CONTACT SQUARE ENIX INFORMATION CENTER(Yes, Redundant, but I hear many compromised accounts are given up on). It seems they know exactly why they introduced these "Security Measures" and are ready to take drastic steps to compensate players for this rash of hackings.
I still think something needs to be done to give players more control over the accounts that they pay every month to use, but i'm back to being understanding of SE's position considering that they know something is happening and are gladly helping players who are victims of these attacks.
However, try convincing the people who weren't given rollbacks now. Why SE is picking and choosing is beyond me, maybe they are just giving full rollbacks now because they finally figured out that this is an attack and not the result of bad security.
7 days =/= 7 days. 7 days = who fucking knows, wait until you get an e-mail...if you ever get one.Originally Posted by didgist