Item Search
     
BG-Wiki Search
Page 2 of 4 FirstFirst 1 2 3 4 LastLast
Results 21 to 40 of 66

Thread: New Security measures.     submit to reddit submit to twitter

  1. #21
    Pens win! Pens Win!!! PENS WIN!!!!!
    Join Date
    Dec 2005
    Posts
    8,032
    BG Level
    8
    FFXI Server
    Odin

    Re: New Security measures.

    Quote Originally Posted by Elipse
    I see this, it seems great but am I missing something here?

    My account was jacked recently and I never typed into the password. It had been stored on the computer long before the theft. smart.dll hooked onto pol.exe somehow and no one seems to have posted exactly how it worked but it seems it was more than just a keylogger. So does this encryption thing protect the user Id and password in memory as well?
    The l/p were were in the same directory and was encripted. All anyone needed to do is to gain access to this file and read it. It's why SE is allowing uses to save there l/p information in any dir. they want now.

  2. #22
    Hydra
    Join Date
    Aug 2007
    Posts
    100
    BG Level
    3

    Re: New Security measures.

    7 days =/= 7 days. 7 days = who fucking knows, wait until you get an e-mail...if you ever get one.
    That's why I said "kind of" lol

    Still, even offering to do something like this is light years away from the "We'll look into it" Square-Enix we all know and love.

  3. #23
    Fishing Guru
    Join Date
    Jan 2007
    Posts
    4,722
    BG Level
    7

    Re: New Security measures.

    Quote Originally Posted by didgist
    7 days =/= 7 days. 7 days = who fucking knows, wait until you get an e-mail...if you ever get one.
    That's why I said "kind of" lol

    Still, even offering to do something like this is light years away from the "We'll look into it" Square-Enix we all know and love.
    True lol, just wanted to make sure your friend didn't have his hopes up for 7 days.

  4. #24
    Sea Torques
    Join Date
    Aug 2007
    Posts
    566
    BG Level
    5

    Re: New Security measures.

    Quote Originally Posted by vagus
    Combine this with storing your l/p in some /random directory or on a usb key makes this security patch amazing. A nice step in the right direction SE. Cookies for you!
    Can someone explain exactly how this works, or if I understand it right?

    I see it like:
    - You put a usb memory card in
    - You start PoL then go into "security settings" and you can save a file to the memory card
    - The file saved to the memory card, now has to always be in to sign in to PoL, must be kept in while playing, and noone can ever sign in as you if the memory card is not in a computer.
    - If you lose memory card or delete the file, you now need to re-enter PoL ID, password etc, but can go ahead and do the same process all over again with a new file

    If this is the new way..its seems unbeatable to hackers. Just have to say that I am one of the "paranoid" people, and havent played ffxi on computer since the hacking first got big. If the way I see it is correct, this is the best update ever...combined with the new mouse input keyboard makes it even better. Again, looking to confirm the way I see it, mainly the bold part.

  5. #25
    Old Merits
    Join Date
    Sep 2004
    Posts
    1,198
    BG Level
    6

    Re: New Security measures.

    AN ONSCREEN KEYBOARD THAT WINDOWS ALREADY HAS IN IT DOESN'T MEAN JACK SHIT.
    Well it actually does. Not everyone knows about it. Some people only play on PC, but do not know a lot about Windows at all. And that doesn´t mean that they are dumb or are clueless.

    Also I wonder why so many people are again complaining. Looks like some people can´t do anything else then whining about everything that gets changed.
    The softkeyboard and the Security Settings are great.

    Most people I see so far that lost their account were those downloading cracked bot programms or not the real windower. Honestly those deserve it.

  6. #26
    Sea Torques
    Join Date
    Jul 2006
    Posts
    500
    BG Level
    5
    FFXI Server
    Odin

    Re: New Security measures.

    Quote Originally Posted by didgist
    THERE'S NO FOOL PROOF WAY TO PREVENT ANY SYSTEM FROM BEING HACKED EVER.
    Quote Originally Posted by didgist
    NO FOOL PROOF WAY
    Ya, really. It's not SEs fault if you're a fool.

    Damned mindset of people "it's just internet, it just has to work, I don't need to have a clue".

    This is a generic problem, not FFXI only.

    That being said... I've been running Windows 2000/XP since at least XP is released... Without antivirus. Never been infected once.

    /edit: Every single suggestion here can be broken by malware. The only thing actually raising the security barrier would be an external authentication token (RSA SecurID or something similar or even a tool generating one-time-passwords running on your java capable mobile phone).

  7. #27
    Fake Numbers
    Join Date
    Jun 2008
    Posts
    76
    BG Level
    2
    FFXI Server
    Ragnarok
    WoW Realm
    Hakkar

    Re: New Security measures.

    My account was hacked at the end of May.

    Now I'm waiting for roll back of game data, two weeks have passed and didn't get the email yet. I've contacted the Information Center (as the policy says) and they've said me I can't do nothing but await... wow, that's confortable

    Btw I really appreciate these new measures, but since I'm unable to play and make some tests (I've got overdue fees but I won't pay them until they recover everything), I've registered here to ask you how they work.

    The "security setting" is the most important, 'cause I was hacked without having typed my password over years

    I was just wondering what peripheral could be the most safe to store those data in that file. The fact it must be inserted all the time when playing the game and not just when starting POL makes me angry... if I play a lot of time (and I did) there are more chances it can be stealed as if it was in the hard-disk.

    If there's any technician here, please give us some suggestion on what's the most safe external peripheral.

    I was thinking to use the old dear floppy drive, cause most computers don't have it anymore, and maybe a malware wouldn't check into the A: drive... Any other suggestion? Like.. um.. smart card reader?
    I don't know anything about these things, 'cause it's the first time I'm caring about security at these levels (I just thought keeping firewall and antivirus updated would be enough, but indeed it's not).

    Let me know something..

  8. #28
    WASTE OF CURRENCY
    I CAN'T I CAN'T I CAN'T

    Join Date
    Feb 2006
    Posts
    9,065
    BG Level
    8
    FFXIV Character
    Izzy Izumi
    FFXIV Server
    Sargatanas
    FFXI Server
    Phoenix
    WoW Realm
    Arthas

    Re: New Security measures.

    Can't key hash with windower

  9. #29
    Hydra
    Join Date
    Aug 2007
    Posts
    100
    BG Level
    3

    Re: New Security measures.

    Well it actually does. Not everyone knows about it. Some people only play on PC, but do not know a lot about Windows at all. And that doesn´t mean that they are dumb or are clueless.
    That's exactly what the fuck it means, genius.

    If you don't take the time to learn your OS and it's weaknesses and security measures then you are the reason people even try these hacks. RMT or whoever know there are a million fucking idiots out there with computers who don't know something as simple as an onscreen keyboard, and they are going to target methods of hacking that will easily succeed against people who think their computer requires the same amount of security as a toaster.

    With the amount of flaming that goes on in BluGartr's forums i'm shocked that someone is telling me that not knowing what an onscreen keyboard is not a sign of being a novice windows user. This is the advanced section of Blugartr forums, people not knowing their shit getting blasted is why we are here. You don't see people flaming others for poor security knowledge? This is the easiest fucking thing ever, people I know have been using the on-screen keyboard for over a year now for this exact reason. SE implements it into FFXI and it's a nice touch? Why not just tell people where their onscreen keyboard is?

    "If you don't know how to use an onscreen keyboard it's no problem, but if you get hacked by a group that's circumventing security measures to gain access to players accounts then you're an idiot." Hi moron, my name is Pete.

    First off, both of my friends who were hacked never entered their passwords with keyboards. One of them had theirs saved, and another used the on screen keyboard Windows already has(FUCK YEAH IRONY). We aren't a HNMLS, no one bots or uses tools, we would never risk our accounts because we play for each others company. So fuck you^^.

    It doesn't matter what you think, SE offering to rollback accounts and then bullshitting people is an obvious sign they know it's out of their hands. In my opinion they are having delays because they never expected this to happen, this is way more than some fucktard botter downloading a keylogger with his new Faf-bot.

    The point I am trying to make is that SE is taking credit for a security measure that is already present on your system or unnecessary. I've been playing a very long time and never once have I expected SE to get it right on even the 8th time, but this is too much. People getting randomly hacked even though they are updating flash and scanning their systems everyday is bullshit, in this situation no matter what is done the hackings seemed unavoidable.

    Being able to call in/log in 24/7 to something that can lock your account is NOT too much to ask.

  10. #30
    Rainbow Dash was here,
    Applejack is a silly filly.

    Join Date
    Jan 2008
    Posts
    1,425
    BG Level
    6

    Re: New Security measures.

    Quote Originally Posted by Faggot
    Being able to call in/log in 24/7 to something that can lock your account is NOT too much to ask.
    No, it's not too much to ask for at all, too bad you're a fucking idiot and all if not most of your argument is made invalid by even standard keyloggers being able to detect the onscreen keyboard. You're a fagggot, get over yourself. The SE's software keyboard is superior in that it's localized to that specific program, the keyloggers that are already in place are going to have to be custom tailored for detecting that specifically. It's not much, but it's just one more step towards having something that works.

    In addition to being able to call in at any time to lock your account after basic security questions set by you (I dont know a PIN of somesort, you know what I'm talking about), there should be that a set of security questions that you setup for basic things like transferring servers.

    Don't get me wrong, I'm the last person to sympathize with hackees. I think while they may not have deserved it, they didn't exactly help themselves usually did they.

  11. #31
    Hydra
    Join Date
    Aug 2007
    Posts
    100
    BG Level
    3

    Re: New Security measures.

    Don't get me wrong, I'm the last person to sympathize with hackees. I think while they may not have deserved it, they didn't exactly help themselves usually did they.
    You don't have to sympathize with criminals if you condemn their victims. You can get over your fucking self, you're insulting real hackers by saying that the new "Superior" POL on screen keyboard couldn't be hacked within 24 hours. I'm going to play FFXI until they shut it down, and be a Square-Enix fanboy until the day I die. I don't apologize, losing friends of mine to stupid fucking reasons like being hacked is going to piss me off.

  12. #32
    Fake Numbers
    Join Date
    Jun 2008
    Posts
    76
    BG Level
    2
    FFXI Server
    Ragnarok
    WoW Realm
    Hakkar

    Re: New Security measures.

    You're flaming for no reason.. the on-screen keyboard is the last thing of this update we should pay attention at.

    The most important thing is the numeric random named folder with the encrypted password data to be stored in a CUSTOM place.

    I've just asked few posts ago if anyone has a suggestion on how this could be done efficiently. For example I could let POL place it in a floppy disk (which I can remove when I'm not playing).. and I could see if it works with manual block on, so that files couldn't be copied elsewhere.

    If you have any other ideas for a safer place to store that folder in, let us know.

  13. #33
    Ridill
    Join Date
    Oct 2005
    Posts
    10,210
    BG Level
    9
    FFXI Server
    Asura

    Re: New Security measures.

    The random name and custom place doesn't keep another program from knowing where it's at. All it has to do is look it up in the same place POL looks it up, unless the name/location of that file is stored on the servers and is cleared from memory each time after it verifies it on your computer.

  14. #34
    New Spam Forum
    Join Date
    Jul 2007
    Posts
    197
    BG Level
    3
    FFXI Server
    Gilgamesh

    Re: New Security measures.

    Quote Originally Posted by didgist
    With the amount of flaming that goes on in BluGartr's forums i'm shocked that someone is telling me that not knowing what an onscreen keyboard is not a sign of being a novice windows user. This is the advanced section of Blugartr forums, people not knowing their shit getting blasted is why we are here. You don't see people flaming others for poor security knowledge? This is the easiest fucking thing ever, people I know have been using the on-screen keyboard for over a year now for this exact reason. SE implements it into FFXI and it's a nice touch? Why not just tell people where their onscreen keyboard is?
    Actually, it really depends on the way that it was implemented. The software keyboard that SE has provided may not necessarily function like the windows counterpart. It could be generating a stream cipher as the keys are being pressed based off of a private key that changes every time you login to playonline. This private key could further be encrypted with another key generated uniquely by a proprietary encryption based off the machine. I've bolded prioprietary because that is the key word. One of the biggest defenses against Cryptanalysis is to hide the encryption algorithm. Otherwise the cryptanalysis needs the following to even remotely have chance:

    Quoted material below:
    Ciphertext-only: the cryptanalyst has access only to a collection of ciphertexts or codetexts.
    Known-plaintext: the attacker has a set of ciphertexts to which he knows the corresponding plaintext.
    Chosen-plaintext (chosen-ciphertext): the attacker can obtain the ciphertexts (plaintexts) corresponding to an arbitrary set of plaintexts (ciphertexts) of his own choosing.
    Adaptive chosen-plaintext: like a chosen-plaintext attack, except the attacker can choose subsequent plaintexts based on information learned from previous encryptions. Similarly Adaptive chosen ciphertext attack.
    Related-key attack: Like a chosen-plaintext attack, except the attacker can obtain ciphertexts encrypted under two different keys. The keys are unknown, but the relationship between them is known; for example, two keys that differ in the one bit.

    Stream Cipher link:
    http://en.wikipedia.org/wiki/Stream_cipher

    Cryptanalysis link:
    http://en.wikipedia.org/wiki/Cryptanalysis

    Quote Originally Posted by Khamsin
    The random name and custom place doesn't keep another program from knowing where it's at. All it has to do is look it up in the same place POL looks it up, unless the name/location of that file is stored on the servers and is cleared from memory each time after it verifies it on your computer.
    There are industry strength clientside encryption algorithms that have been proven to be robust. Lets just hope that they revamped the implementation because it has been vulnerable in the past. However I do not expect SE to tell us whenever they increase or enhance their implementation (which would alert people onto trying to break it again).

    Some helpful links for knowledge on third party authorities and public keys:
    http://en.wikipedia.org/wiki/Public-key_cryptography

    Of course there are weaknesses, but these are what we use to secure online bank transactions and such. If they were so easy to break, then these genius RMT'ers should probably invest into making profit directly by hacking bank transactions themselves.

    I personally would be very confident if SE were to implement state of the art industry level encryption. (which they may have with this update... but we'll just have to hope)

  15. #35
    Sea Torques
    Join Date
    Aug 2007
    Posts
    566
    BG Level
    5

    Re: New Security measures.

    Quote Originally Posted by vagus
    Combine this with storing your l/p in some /random directory or on a usb key makes this security patch amazing. A nice step in the right direction SE. Cookies for you!
    Can someone explain exactly how this works, or if I understand it right?

    I see it like:
    - You put a memory card in
    - You start PoL then go into "security settings" and you can save a file to the memory card
    - The file saved to the memory card, now has to always be in to sign in to PoL, must be kept in while playing, and noone can ever sign in as you if the memory card is not in a computer.
    - If you lose memory card or delete the file, you now need to re-enter PoL ID, password etc, but can go ahead and do the same process all over again with a new file

    If this is the new way..its seems unbeatable to hackers. Just have to say that I am one of the "paranoid" people, and havent played ffxi on computer since the hacking first got big. If the way I see it is correct, this is the best update ever...combined with the new mouse input keyboard makes it even better. Again, looking to confirm the way I see it, mainly the bold part.

  16. #36
    Banned.

    Join Date
    Oct 2005
    Posts
    3,421
    BG Level
    7

    Re: New Security measures.

    Due to the sudden increase in unauthorized access on the internet
    what

  17. #37
    Hydra
    Join Date
    Aug 2007
    Posts
    100
    BG Level
    3

    Re: New Security measures.

    Of course there are weaknesses, but these are what we use to secure online bank transactions and such. If they were so easy to break, then these genius RMT'ers should probably invest into making profit directly by hacking bank transactions themselves.

    I personally would be very confident if SE were to implement state of the art industry level encryption. (which they may have with this update... but we'll just have to hope)
    $15 x Number of Players + Money from all of the sale and resale of FFXI Data = Fuck yes they should.

    Also the RMT target "petty" markets like this, if you hack bank transactions Federal Agencies can and will find you and prosecute you for it. Hacking a internet game for sums of 200-1000+$ at a time is still a crime, but SE is not a federally regulated, protected, and monitored bank either. It's hacking you loging in to Playonline VS. hacking you wiring 100 bucks to your cousin from your bank account. I would hope that the latter warrants far more severe punishment.

    Also I apologize, I didn't think about them using encryption for the POL Keyboard. I'm not doubting SE put a decent amount of thought or ingenuity into these new security devices, it's just that the only way to truly offer protection is to allow players, once again, 24/7 access to a system that can freeze their account because my bank offers me that same service for one reason. People can and will steal your shit in all aspects of life. Period.

    I'm not horribly familiar with how powerful common keyloggers are, wouldn't it be possible to bypass the on screen keyboard by logging this?

    POL Opens
    Screenshot on Mouse Click
    Boom, mouse cursor positions for every character in your password.
    Do the keys from the onscreen keyboard light up or blink when you click them as well?

  18. #38
    New Spam Forum
    Join Date
    Jul 2007
    Posts
    197
    BG Level
    3
    FFXI Server
    Gilgamesh

    Re: New Security measures.

    Quote Originally Posted by didgist

    POL Opens
    Screenshot on Mouse Click
    Boom, mouse cursor positions for every character in your password.
    Do the keys from the onscreen keyboard light up or blink when you click them as well?
    It is possible to program something that takes screenshots on mouseclicks. This is, however, not discrete and requires huge amounts of bandwidth to send screenshots for everymouse click. Would consume CPU and be noticeabley awkward. Another disadvantage of this type of approach is that after POL has started, the spyware would be unable to tell where in POL the application has progressed and would be forced to take screenshots all the time if SE programmed this custom component with high security. Combinations of Keys pressed on the keyboard and mouseclicks in rapid succession would also be hard to follow because of the inherent lag and delay of screencapturing and the speed of keyboard input. I doubt anyone would resort to this in that it requires alot of human overhead to steal the information as well.

  19. #39
    Relic Horn
    Join Date
    Dec 2007
    Posts
    3,411
    BG Level
    7
    FFXIV Character
    Purrrfect Lee
    FFXIV Server
    Hyperion
    FFXI Server
    Cerberus

    Re: New Security measures.

    Quote Originally Posted by AoshiZ
    Quote Originally Posted by didgist

    POL Opens
    Screenshot on Mouse Click
    Boom, mouse cursor positions for every character in your password.
    Do the keys from the onscreen keyboard light up or blink when you click them as well?
    It is possible to program something that takes screenshots on mouseclicks. This is, however, not discrete and requires huge amounts of bandwidth to send screenshots for everymouse click. Would consume CPU and be noticeabley awkward. Another disadvantage of this type of approach is that after POL has started, the spyware would be unable to tell where in POL the application has progressed and would be forced to take screenshots all the time if SE programmed this custom component with high security. Combinations of Keys pressed on the keyboard and mouseclicks in rapid succession would also be hard to follow because of the inherent lag and delay of screencapturing and the speed of keyboard input. I doubt anyone would resort to this in that it requires alot of human overhead to steal the information as well.
    The amount of data from a ss of the pol window =/= the data for the entire screen. You can only click so fast, it doesn't seem very likely to me that your computer would have trouble taking a snapshot of just pol on every click.

    I like the idea of maybe somewhere on the pol website where you could lock out your account. Different criteria for verifying ownership would help a lot. Quite obviously the thieves are going to change the billing info on the account as soon as they can. More verification for world transferring would be good, but there really isn't much difference in the end whether they could shift or not; your shit is still gonna get jacked.

    I'm still somewhat confused about how my account was taken. I did have the virus from the original realplayer exploit on somepage, but I also had my info stored in pol.

    I'd say the fact that SE still has people waiting for account verification/investigation after half a year indicates that they had no idea so much shit could hit the fan.

  20. #40
    Gunitsoldier
    Guest

    Re: New Security measures.

    From the looks of it, this is good but either imdoinitwrong or it's not working for me. I went to Security Settings and said yes, designed a spot, says its been made etc to make sure if i put it on disk it has to be in , blabla, Yes. Do I type the text in the created file into my text bar or something? I know nothing of stuff like this so forgive me if I sound like an idiot.

Page 2 of 4 FirstFirst 1 2 3 4 LastLast

Similar Threads

  1. Replies: 46
    Last Post: 2007-10-11, 09:33
  2. IMPORTANT ~ Dynamis Reformation + New Rules
    By in forum FFXI: Everything
    Replies: 28
    Last Post: 2005-02-03, 10:42