1. FFXIV Reset Timers
    Last daily reset was 12 hours, 1 minutes ago / Next daily reset is in 11 hours, 58 minutes
    Last weekly reset was 4 days, 5 hours, 1 minutes ago / Next weekly reset is in 2 days, 4 hours, 58 minutes
Page 21 of 25 FirstFirst ... 11 19 20 21 22 23 ... LastLast
Results 401 to 420 of 499
  1. #401
    Yoshi P
    Join Date
    Aug 2006
    Posts
    5,139
    BG Level
    8
    FFXIV Character
    Dead Gye
    FFXIV Server
    Lamia
    FFXI Server
    Ragnarok

    If the packets being sent are basically plaintext, then encryption does make the system more secure. It would be due to having to specifically create an event and find the corresponding packet to know what you need to send, instead of being able to just watch and find out all the commands easily. That is the one situation I can think of where encryption alone will increase security. However I haven't paid enough attention to this whole thing to know if SEs shit was as bad as lolplaintext.

    However, you NEED to authenticate these commands. And if you don't encrypt the authentication then what's the point.

  2. #402
    Fake Numbers
    Join Date
    May 2008
    Posts
    87
    BG Level
    2
    FFXI Server
    Cerberus

    Quote Originally Posted by Cutriss View Post
    Depends on the obfuscation method but I don't think you're seriously evaluating the statements. See my example above. I think you're considering the probability that obfuscation makes a target stand out by trying not to stand out (example - blank SSIDs), and that's not really going to my example at all.

    Also your best case seems to basically take the position of O(29385902385923n) = O(n), which masks the fact that in this case we want to increase ω(n) (from memory here, forgive me if I'm using the wrong notation) so that we reduce the chances of a successful attack being carried out.

    Don't confuse this with things like security theater. Techniques like port-knocking (however flawed they may be) don't even register on the scale of impact to the authorized user, but add a few orders of magnitude to the complexity for the random attacker, and without foreknowledge of the layer, make a target appear less vulnerable.

    Do they stop a dedicated, focused attack? Eventually not, but it increases the likelihood of being able to see (and stop) the attack in progress.

    If you'd like to continue to debate this I'm welcome it. If you'd rather just make blanket assumptions on the Internet and pretend you've always been right, then I'll just move on.
    My fucking brain just exploded.

  3. #403
    Salvage Bans
    Join Date
    Oct 2013
    Posts
    929
    BG Level
    5

    Quote Originally Posted by Cutriss View Post
    Depends on the obfuscation method but I don't think you're seriously evaluating the statements. See my example above. I think you're considering the probability that obfuscation makes a target stand out by trying not to stand out (example - blank SSIDs), and that's not really going to my example at all.
    Maybe you made a post and it didn't go through or I'm retarded and can't read, because I don't see an example above.

    I also wasn't pretended to be right, I invoked the NIST as an authority. If you can prove NIST wrong, you will be rich.

    The only example you list is port knocking which doesn't even exist in the world of production. It's a nice way to cover your tracks as part of a rootkit on a production system

    Quote Originally Posted by Deadgye View Post
    If the packets being sent are basically plaintext, then encryption does make the system more secure. It would be due to having to specifically create an event and find the corresponding packet to know what you need to send, instead of being able to just watch and find out all the commands easily. That is the one situation I can think of where encryption alone will increase security. However I haven't paid enough attention to this whole thing to know if SEs shit was as bad as lolplaintext.

    However, you NEED to authenticate these commands. And if you don't encrypt the authentication then what's the point.
    I can literately teach a child how to break through encryption. You don't need to know or care how the data is encrypted. You wait for a packet to be sent, scan for that in memory, find out what writes to that memory, follow the code backwards and you got the unencrypted data. Hook into that function, and you see the full stream of unencrypted data being sent. Takes 10 min tops.

    Real world example. Game compresses the data to make it hard to see, compression library has a vulnerability, attack gets control of the server that way. The game hurt itself by adding fake security.

    They just need to validate the commands, like you said. It is that simple. Don't try to hide anything, just assume the attackers can see everything because they can.

  4. #404
    Sandworm Swallows
    Join Date
    Dec 2007
    Posts
    7,112
    BG Level
    8

    Quote Originally Posted by Cutriss View Post
    Well they did that in XI, for whatever that's worth.

    Obfuscation *alone* isn't security. Obfuscation is still useful to enhance security.

    My company is paying a firm for penetration testing right now. They've asked us for a bunch of information to help them identify our systems and help them proceed with the testing. Defeats the purpose IMHO.
    It does. This isn't a true pen test if they are asking for this type of information up front. For the few years I've been doing this, getting most of the information can be done by a simple phone call to the right person.

  5. #405
    Melee Summoner
    Join Date
    Sep 2013
    Posts
    29
    BG Level
    1

    Here's the thing about obfuscation: It is neither necessary nor sufficient to achieve actual security. Validating client commands ON THE SERVER is both necessary and sufficient. Hence: obfuscation is useless.

    As lilbubbles mentions, it's trivial to hook into the function that has unencrypted packet data right before it sends it but before it encrypts it, or right after it receives it and decrypts it.

    the only thing encryption is useful for is preventing unauthorized parties from reading your data: aka, privacy as lilbubbles stated on the previous page.

  6. #406
    Physicist
    Join Date
    Feb 2005
    Posts
    4,492
    BG Level
    7
    FFXIV Character
    Raineer Severus
    FFXIV Server
    Hyperion
    FFXI Server
    Siren
    WoW Realm
    Area 52

    Instead of debating whether encryption is useful to security (personally I think it's adding another screen door to the screen door already on your house), look at it another way.

    Development takes resources, resources are limited. You can put time into one thing. Choose authentication or encryption.

    One masks the problem (perhaps very well, perhaps not), the other fixes the problem.

  7. #407
    New Merits
    Join Date
    Aug 2006
    Posts
    243
    BG Level
    4
    FFXIV Character
    Mirai Amariyo
    FFXIV Server
    Gilgamesh
    FFXI Server
    Sylph

    Quote Originally Posted by Yabby View Post
    This isn't a true pen test if they are asking for this type of information up front.
    If they are performing a White or Grey Box test, this is not uncommon.

    Quote Originally Posted by Yabby View Post
    For the few years I've been doing this, getting most of the information can be done by a simple phone call to the right person.
    If they were performing a social engineering vector as part of their test, this would be the case.

  8. #408
    Relic Shield
    Join Date
    Jan 2008
    Posts
    1,519
    BG Level
    6
    FFXIV Character
    Zettai Ryouiki
    FFXIV Server
    Gilgamesh
    FFXI Server
    Quetzalcoatl
    WoW Realm
    Mal'Ganis

    Bans are going out for people that abused the leve turn in exploit. Only time will tell if the same will happen to people that used matless crafting.

  9. #409
    Day
    Day is offline
    IMPERIAL CONCUBINE OF ME
    Coolest Monkey In The Jungle

    Join Date
    Sep 2007
    Posts
    21,547
    BG Level
    10

    good.

  10. #410
    The Once and Future Wamoura
    Join Date
    Aug 2005
    Posts
    18,133
    BG Level
    9
    FFXIV Character
    Rocl Montaigne
    FFXIV Server
    Excalibur
    FFXI Server
    Bahamut
    WoW Realm
    Quel'Thalas

    now to ban the people who killed clearly bugged twintanias and we'll be good

  11. #411
    Nidhogg
    Join Date
    Dec 2005
    Posts
    3,503
    BG Level
    7
    FFXIV Character
    Xenor Vernix
    FFXIV Server
    Ragnarok

    They didn't ban those who killed bugged Titans so why would they ban those?

  12. #412
    The Once and Future Wamoura
    Join Date
    Aug 2005
    Posts
    18,133
    BG Level
    9
    FFXIV Character
    Rocl Montaigne
    FFXIV Server
    Excalibur
    FFXI Server
    Bahamut
    WoW Realm
    Quel'Thalas

    because yoshi-p didn't brag only 100 ppl would beat titan obviously

  13. #413
    Relic Shield
    Join Date
    Apr 2009
    Posts
    1,514
    BG Level
    6

    Quote Originally Posted by Ezek View Post
    Bans are going out for people that abused the leve turn in exploit. Only time will tell if the same will happen to people that used matless crafting.
    I wonder if he means matless crafting too in the answer below:
    http://forum.square-enix.com/ffxiv/t...=1#post1452776
    Since we are on the topic of cheating, there is another thing I wanted to mention. Recently, a player uploaded a video of them using a third party program. While this cheat was already addressed by us, they made it seem like the cheat was still an ongoing issue. Honestly, this is an interference of our business because it has a huge negative impact on the community. Please note that we will not be taking these actions lightly and plan to take action if it gets out of hand.

    While it is okay for players to upload in-game videos of ARR, we never approved the videos of players using third party programs. We appreciate your cooperation regarding this matter.

  14. #414
    Banned.

    Join Date
    Nov 2008
    Posts
    589
    BG Level
    5
    FFXI Server
    Valefor

    Lol rocl is so butt hurt over the twintania thing.

  15. #415
    But I don't want my title changed
    Join Date
    Nov 2008
    Posts
    6,486
    BG Level
    8
    FFXIV Character
    Fievel Mousekewitz
    FFXIV Server
    Excalibur

    Quote Originally Posted by Vendog View Post
    Lol rocl is so butt hurt over the twintania thing.
    lol

  16. #416
    Old Odin
    Join Date
    Dec 2011
    Posts
    6,197
    BG Level
    8
    FFXIV Character
    Seravi Edalborez
    FFXIV Server
    Hyperion
    FFXI Server
    Titan

    Quote Originally Posted by Vendog View Post
    Lol rocl is so butt hurt over the twintania thing.
    nah he jelly

  17. #417
    Campaign
    Join Date
    Sep 2007
    Posts
    6,631
    BG Level
    8
    FFXIV Character
    Sean Kipling
    FFXIV Server
    Midgardsormr

    Quote Originally Posted by Mistress Stowastiq View Post
    I wonder if he means matless crafting too in the answer below:
    http://forum.square-enix.com/ffxiv/t...=1#post1452776
    When I read that I figured they were referring to the guy who used Cheat Engine to change item codes (Since we know that was fixed before most people even saw the video/were aware of it), but I wasn't sure myself.

  18. #418
    CoP Dynamis
    Join Date
    Oct 2006
    Posts
    294
    BG Level
    4

    Well, for the record, I just happened to be beside someone that completed 100 leves in a matter of seconds (they got all the achievements at the same time), so shit isn't fixed lol

  19. #419
    Relic Shield
    Join Date
    Apr 2009
    Posts
    1,514
    BG Level
    6

    Quote Originally Posted by Uryuu View Post
    When I read that I figured they were referring to the guy who used Cheat Engine to change item codes (Since we know that was fixed before most people even saw the video/were aware of it), but I wasn't sure myself.
    Hmm. Well he mentioned that he had to be delicate about what he said because it would just make it easier for ppl to cheat.

    I think he is referring to that levy vid with the level up spam because it made the biggest commotion in OF. People kept posting new threads the OF, getting them deleted and thus, thinking no one dealt with it when they actually had but did not let the community know. I did get the sense of his utter frustration with the whack a mole they are playing daily.

    While they are hiring more staff or implementing a system by which they can separate queries by the game they came from, I bet it also will help if we put "FFXIV" on the title any GM requests or reports because it looks like the Dragon Quest debacle was embarrassing.

    @Drakath, you sure they just didn't buy or hoard all their turn in items and do them at once?

  20. #420
    Salvage Bans
    Join Date
    Oct 2013
    Posts
    929
    BG Level
    5

    Sometimes it can take time to properly fix the exploit(a rushed fix can be worse), as long as they are able to log and send out bans I am happy.

Page 21 of 25 FirstFirst ... 11 19 20 21 22 23 ... LastLast