UNDERLINE FOR EMPHASIS YO
UNDERLINE FOR EMPHASIS YO
Sorry for the long wait for a reply, I've been busy all day and am in downtime from a shitty party.Originally Posted by didgist
I said sympathize with hackees, not hackers. The people who were hacked. I'm closer to idolizing hackers than sympathizing with them, real hackers I mean not script kiddies. I think I clearly stated that I didnt think it was any good. Wait, think? Oh shit, that's not something you're doing, let me quote specifically:
It's called fucking evolution, you start out small and work your way up. They'll get it right eventually or die out. I dont think I was apologizing for anything though (Other than just now for being late with a reply), I'm not sure where you pulled that from.Originally Posted by Me, smarter than you
Additionally, I'd like to mention that AoshiZ made a very well thought out post; and while I haven't the expertise to back anything he says to much of a degree I'd look into what he's siting, he seems to make a great deal of sense.
Edit: Underlining for emphasis.
In other words you have no idea what you're talking about. Thanks for chiming in!Additionally, I'd like to mention that AoshiZ made a very well thought out post; and while I haven't the expertise to back anything he says to much of a degree I'd look into what he's siting, he seems to make a great deal of sense.
FFXI is years and years old, hackings are nothing new nor something they have no business being prepared for, and I underline things because bold/italic/underline are provided by the forum owners. If there was a big enough problem to create an onscreen keyboard with insane over the top encryption then it's obviously a problem big enough to warrant them giving players a way to freeze their accounts 24/7 instead of M-F 9-6pm PST.
The fact that we only have the call center to rely on now is enabling hackers to use accounts for 14-15 hours at a time even if the user is sitting at his computer staring at the login screen and his/her friends are spamming GM calls to get the account locked. That's a big giant gaping massive fucking security hole that no re-hashed security measure that fanboys start drooling over is going to fix.
I love FF. I hate watching people get hacked. You being a dick about people losing 4-5 years of progress is just you proving you like to be a pain in the ass, not that you're more intelligent than someone dealing with a real unresolved issue.
Also it's "Citing".
You being smarter than me obviously has something to do with your inability to spell.
EDIT:![]()
My inability to spell citing has nothing to do with you not being able to coherently respond to anything I actually said and only personally attack my credentials without providing your own. It's not that I don't have any idea what I'm talking about, I said I don't have expertise. I've dabbled with it, I've done encryption/decryption algorithms, made my own viruses, but I'm no where near able to tell you about current cryptography.
I already told you, I agree that there should be steps taken to further increase the ease of which players can secure themselves.
You don't have to tell me about "watching people get hacked." Just today I've watched another friend get hacked without being able to do anything about it but watch in horror. I'm actually unsure of how that's going at the moment, but while I wish him luck, he admits to have been using IE. Tough shit.
And while these issues may be currently unresolved, that's because they're currently working on them, which this is, as I said numerous times now, a work in progress. Baby steps, evolution, one step at a time, etc. You're taking things to an extreme by saying this is all for nothing and making some blatantly wrong points. Let's go over the onscreen keyboard bit again if you want.
Honestly, you coming into the thread and being all butthurt about your friends being hacked and being overly critical of SE, who is only doing what any corporate company does, which is being slow and developing things after massive amounts of testing and consideration. They're not a security company, they're a gaming company. You should be thankful that they're doing anything at all. It's not their job to secure YOUR computer, it's not as if SE's databases are being hacked and the RMT are stealing passwords that way. SE's done their job, they're secure, end of transaction. (Though, again, to be fair, they really should improve upon their customer service and SHOULD institute some way of locking your account at a moments notice 24/7) If anything, I must commemorate SE for just putting up with all the shit their fanbase gives them.
Um... security by obscurity is by far the worst possible method. Any text will tell you that.Originally Posted by AoshiZ
Security by obscurity is by far the worst possible method when used on its own. For example securing your wireless network just by not showing an SSID, while effective against the most inexperienced of users is ineffective for anyone with some sort of packet sniffing program. However, when combined with encryption tools it be quite effective. If you're using an encryption method and don't announce what method that is, it's much more difficult to crack. You'd probably end up resorting to looking at patterns to identify the encryption, however if you go further and add an encryption algorithm that's just as effective as any other, let's assume MD5, but unknown, you'll remove being able to compare it to known encryption methods and being able to use already known methods of manipulation.Originally Posted by Skjie
Why? It is a two way street and the collective playerbase bitching about things gives them direction and keeps players paying monthly. Why do people make it seem like harassing a group of developers with ideas to mutually make the game BETTER is some sort of crime or annoyance? Most of the ideas they use are poached from players so the players have good ideas ready to be used and to SE that should mean nothing but profits.If anything, I must commemorate SE for just putting up with all the shit their fanbase gives them.
Players are the ones keeping them above water in profits during a time the SE president just released a 'new direction' statement, which means trouble. The FFXI playerbase has been fiercely loyal even during the times that the developers have treated the playerbase like a piece of meat so i find it laughable to say that they should be applauded for putting up with us. Seriously.
It is their job because at the end of the day an unhappy player will not recommend this game to friends and will most likely not pick up the next SE MMO. That may be laughable now but the next SE MMO will not have the luxury of a 'Final Fantasy' title attached to it, which is what helped sell this game. It may be trivial, but i can imagine many people would avoid the next MMO simply because of the way SE handled FFXI across the board.You should be thankful that they're doing anything at all. It's not their job to secure YOUR computer, it's not as if SE's databases are being hacked and the RMT are stealing passwords that way. SE's done their job, they're secure, end of transaction.
SE is doing what they can to help customers and it is true that it is the players responsibility to protect themselves as best as they can but ultimately it is in Squares hands to overall deter RMT and hackers through various methods. Players have their end of the bargain and the stakes are high but so many things in this game scream 'devote all your hacking resources here!' and until they change that appearance, the hacking attempts and vectors of attack are only going to keep exponentially increase.
From the lackluster and unsafe community site, the easy as hell to abuse World Transfer Service, the 9-6 customer service, the bogged down workers at the help desk, the lack of official forums, slow GM support, no 24-7 hotline,.... the list goes on.
The players have a long road ahead of them in maintaining security in a dynamic enviroment where custom keyloggers and programs will be always be out there but there is no denying that SE has an even greater task in needing to close the gaping holes in security and support that are currently being abused to no end - this new keyboard is just the start hopefully.
The job is no where near done.
Huh? Even if you have a great algorithm, hiding it (IE: proprietary) does little to nothing for it in the long run. Not to mention, most of the time, when you are actively trying to hide your encryption scheme, you're doing it partially because flaws exist. The best, and most used algorithms are, (I'll admit to not having any texts nearby and being too lazy to search online to 100% verify) publically reviewed so that any flaws can be ironed out. Your security is in using appropriate keys, not in trying to obscure your algorithm.Originally Posted by #686578
(PS: Your first sentence didn't actually make any sense at all, in an encryption scheme, it's not like SbO is it's own entity that can be used. As well, an SSID has nothing to do with the sort of password hashing that we're talking about in regards to POL. That is a horrible analogy.)
not sure how this makes the program safer, but i have an antivirus & anti yadda yadda, not sure if it helps but i have my program on an external harddrive so when i am not playing i just unplug it
What's in your opinion the most safe (and possibly free) web browser?Originally Posted by #686578
---> (i'm not arguing i'm just asking cause i really don't know)
Mozilla Firefox is great! Opera is another free one, not sure if it's as secure/powerful as Firefox is but I don't know personally.
I use a very gutted version of WIN XP for this and other reasons.
=D>Originally Posted by ronin sparthos
Bingo. I have no intention of ever playing another SE MMO because of how they managed FFXI. Their complete cluelessness coupled with an inexplicable stubbornness with regards to changing even the most rudimentary aspects that would improve the game boggles my mind. It has taken NINE MONTHS (maybe more) for them to come out with some sort of preventative measures, as opposed to reactive measures, to combat the hackings. This should have been a top priority. Instead, they chose to bury their heads in the sand and blame the people getting hacked. WHAT THE FUCK. They're lucky they have ANY players left after that bullshit.
Fast forward to today, there's still no simple security question in place that would be required to change POL subscription information. One of the easiest and quickest things to implement, and they fail. Granted they're taking stabs at making things more secure, but why the hell did it take almost a whole year to address this? Sorry, Square-Enix has proven to me beyond the shadow of a doubt that they're incompetent fools who are not deserving of my money beyond FFXI. If it weren't for the fact that I have so much time vested in FFXI and play with some great people, I'd have left long ago. (That and they do throw us a bone every now and then, this latest patch kicking MUCH ass being a good example. Damn them for stringing me along!)
Lynx.Originally Posted by EvilSid
(I'm being serious)
I'm sorry, you deserve more of thought out response, however I've got things to do, so I'm going to have to blanket a reply to several statements. It's one thing for the fanbase to complain about a nerf, or about glitches in the game and another for the security flaws that FFXI has because SE doesn't scan your system. I still maintain that SE shouldn't be held responsible for security issues past their own equipment (and thus all the most recent keylogging things being people's faults not SEs), but I see you don't share the opinion and I don't think that this point will be able to go much further without pointless debate.Originally Posted by ronin sparthos
This seems to be about the one thing I can agree with you on. But this is because when a company sells you something (of this variety) they're also selling you customer service.Originally Posted by ronin sparthos
I'd like to say that while I believe it's not SE's job to handle these types of issues, I must say that I dont think they shouldn't. I too think I already said that this keyboard is the start of that as well.Originally Posted by ronin sparthos
While true, that's not to say that a modification of a well known algorithm couldn't be used and have the same effect, except that you dont know specifically what algorithm it is which, I will continue to say, means you can't use well known exploits against it. This is of course assuming the best case scenario where there aren't so many flaws as your statement might seem to imply. In addition to using appropriate keys doing something as simple as just not making public what algorithm you're using, not using a typically well known algorithm (that is still as effective and keeping flaws to a minimum, if such a thing exists), or something similar would add just that little bit more that wasn't there before. It seems that you might be thinking I mean something else when I say obscuring their encryption algorithm, I seem to be making a lot of unclear statements I believe. I'd like to use another analogy if you'll excuse my horrid ability to come up with one.Originally Posted by Skjie
Let's say we use a simple algorithm of just making a letter the next in the alphabet, A->B, B->C, and so on.
Encryption becomes Fodszoujpo. This is not very secure. And please, excuse this for oversimplicity sakes, I realize it's completely insulting to what yet may be intelligence on the internet, however I'm trying to keep it overly simple; it's not a one way function, etc etc. When we know the algorithm used, we can easily come up with past known exploits "Oh look, we can easily just go down one letter in the alphabet and reproduce the input." However, not knowing the algorithm, they'd have to look at the pattern, realize that it's so simple, and either come up with their own exploit or compare it to previous encryption schemes to try and find something. It's not much, however it's still there as that added benefit of security. Obscurity should never be used on it's own or relied upon as your only method of protection.
As far as my SSID analogy, you're right, it was horrible. I just couldn't think of anything better.
http://i80.photobucket.com/albums/j1...indenberg1.jpg
So, it's not the companies fault that they overlooked a massive gap regarding the safety of it's customers?
How come my Credit Card doesn't get hacked? Why only my account?
It's an easily exploitable system due to the fact that there are large time periods where players have no way to regain control of their accounts. The people currently hacking accounts that you think are oh so ingenious aren't using any complex alogrythms as much as they are common sense.
Closed information center = Merry Christmas RMT.
That's the point I keep trying to make to you, it's not virus scans or onscreen keyboards or anything that the players can do that will remedy this, it's getting rid of the fact that nearly 15 hours of the day are open season on any and all Final Fantasy XI accounts. I refuse to accept anything less because it's been 6-7 years and there is no excuse for it.
Here's your ticket, have a nice flight.
So it's the customers faults they're retarded?... yes.Originally Posted by didgist
I'm sorry I guess I should add more to this post. Uh, right, um... Not an antivirus software company. So... yeah. I guess they could bring in gameguard or something.
Your file holding user/pass is still the same, however SE changed the encryption scheme on it.Originally Posted by Elipse
Your KEY for decoding the file is able to be saved to random places.
Now theres 2 possibilities for what happened to your account:
1) you got hacked before the update, and your account was on a 'to-hack list' and they just didnt get around to yours until after patch
2) SE may not reencrypt the file with the new encryption until you go manually specify your encryption key path. Its possible your file was still sitting there with the old encryption. But well never know how SE did that though and not know how it was done. Most likely #1
Sorry for the late response, you cut my sentence off.Originally Posted by Skjie
Yes the strongest algorithms are the public ones. My statement said the following:
"This private key could further be encrypted with another key generated uniquely by a proprietary encryption based off the machine."
Obscurity although weak (was pointed out by another member) is still a level of security that you add ontop of any type of security infrastructure. Although AES is considered strong, you don't advertise that you are using it in a commercial environment. You advertise it when you want hack testing in proving strength of algorithms.
Furthermore, The most important aspect that you do not understand is that the process is handled entirely client side (for the unique system identifier). The way the private key is generated must be a secret. This is why this algorithm must be secret. If it were known then people could simulate the process and generate the keys. This is why I said proprietary. Please look into why keys need to be secret.
Here is an article about key generation that might help:
http://en.wikipedia.org/wiki/Key_generation
Thank you for telling me exactly what I didn't understand. If I didn't have you or wikipedia to explain it to me, I'd have to resort to the half dozen textbooks I have in my living room from school.Originally Posted by AoshiZ
Meanwhile, my entire point is that saying that using a proprietary algorithm does not, in the long run, provide you with any measurable extra security. If you are relying on the fact that no one has seen your process yet in order to protect your data, you're already screwed. NOTE: (I'm going to bust out bold for this) proprietary algorithms are neither necessarily strong or weaker. Telling people that something is better because it is proprietary is balls. Something is better because it can be demonstrated to be.
PS: The method of generating the key does not have to be secret. All that matters is what you feed into the algorithm is secret and the algorithm output is sufficiently complex.