Item Search
     
BG-Wiki Search
Page 8 of 14 FirstFirst ... 6 7 8 9 10 ... LastLast
Results 141 to 160 of 267
  1. #141
    Fake Numbers
    Join Date
    Nov 2006
    Posts
    80
    BG Level
    2

    Yes I know how the device works, Ive seen them around when I was playing wow. I'm sure USB is not as safe as you can get a virus that will just ask for an ID from the device and will send it to another computer that will hack in to your account. But thats just a theoretical possibility, I was just talking from a pure convenience standpoint.

    Also why would SE have 2 parallel gaming interfaces. Blizzard is merging wow with battle.net, steam a proven working game interface. Will SE just abandon playonline because it has a bad reputation? I would lean more towards an overhaul. Its just my opinion anyways. No one on this board has any real influence or knowlage over what crazy plans SE has in the next few years. Hell we dont even know what the next mmo is about I'm just saying its a good idea for them to plan ahead and get an encryption service in place for when they do replace rapture. Having it ready for FFXI is just an added bonus.

    Quote Originally Posted by Tobatobu View Post
    I'll probably get one, just because I have spent 5 years playing this game and don't want it to end cause I loaded a bad animated .gif when I visited a website.

    Questions:

    Willl one device be syncable to multiple accounts?

    If you already have a similar device for WoW or your bank, can it be used for your FFXI account?
    There should be some sort of serial number on it that you enter and confirm to playonline. You will not be able to use similar devices because you wont be able to give SE the encryption key thats compared to the time to give you the correct number you need to enter.

  2. #142
    Nidhogg
    Join Date
    Jun 2007
    Posts
    3,528
    BG Level
    7
    FFXI Server
    Odin
    WoW Realm
    Lightbringer

    I'm starting to be convinced that SE could be handing out free money and quality blow jobs and certain people would still find a reason to complain.

    How is optional legitimate additional security ever a bad thing?

  3. #143
    D. Ring
    Join Date
    Apr 2006
    Posts
    4,738
    BG Level
    7
    FFXI Server
    Siren

    Nice, I'll probably get one but I'm curious to find out the price and specifics so I'll wait 'til then to decide for sure.

    Quote Originally Posted by Tobatobu View Post
    I'll probably get one, just because I have spent 5 years playing this game and don't want it to end cause I loaded a bad animated .gif when I visited a website.
    Bingo, my thoughts exactly. My life wouldn't fall apart if my account got hacked, but damn. It represents years of my life and effort. I don't handle it lightly and this sounds like an important tool to securing my account that I value.

    The in-game item is an unexpected icing on the cake. Not a bad idea of them to add more player incentive either. I just hope to god it's not that fugly white and red rejected David Bowie coat they displayed at fanfest.

  4. #144
    Myr said I should dodge roll
    Join Date
    Sep 2008
    Posts
    3,061
    BG Level
    7
    FFXIV Character
    Fiendish One
    FFXIV Server
    Hyperion
    FFXI Server
    Sylph

    So let me get this straight. Squenix wants US to pay for an item that makes our login more secure because THEY FAILED TO DO SO?



    BRILLIANT!



    Seriously, they should be giving these out for fucking free to every paying account.

  5. #145
    Chram
    Join Date
    Jun 2006
    Posts
    2,539
    BG Level
    7

    Quote Originally Posted by Seraph View Post
    I'm starting to be convinced that SE could be handing out free money and quality blow jobs and certain people would still find a reason to complain.

    How is optional legitimate additional security ever a bad thing?
    If this was Alla, we would be arguing that $5 was too much for it, and that if you login once a day it would cost you almost $2000 a year to use!

    (Thinking of the MMM bitching thread, can't find the link now.)

  6. #146
    Hydra
    Join Date
    Dec 2007
    Posts
    136
    BG Level
    3
    FFXI Server
    Quetzalcoatl

    Quote Originally Posted by Spekkio View Post
    they have a very finite window to attack and once that's up, they're done. it's not a perfect system, no. nothing is. well nothing except what i described above. the question is if it's a BETTER system. to that, i'd have to answer yes. it makes us more secure than we were, so it's at least a step in the right direction.
    The thief wouldn't know the password your putting in until its "completely" typed in, they don't know the moment you push the button on the token.

    The time frame from finishing the input of the OTP and logging in would be roughly less then 10 seconds.

    Once a OTP password is generated on the token and is then entered and used to access the server, on the server side, that Key is disabled and will not work again until a long time. The token will also not generate that same key again for a long time, by math or programming I don't remember.

    Someone did the math once and it was on some research post on Digg, for the same OTP to be the key would take minimum 2~ years. I'll have to hunt down the news clip post.(One news post i recall had a Man manually try to break a 512 bit encrytion and layered a 12x12 foot room with enough paper and notes to make a tree)

    The only way someone could get your account is to

    A. Steal the Token
    B. Intercept your input submission in real time and time the block of your submission to the server and be ready fast to log in instead.(Roughly 50secs or less based on your input speed of the OTP).

    But Choice B could be and will most likely be even more hindered by the fact that If I recall, all RSA tokens aren't designed to instantly generate on the go, but instead every 60secs(Repeatedly pushing the button won't change it). When you push that button it displays the recent code and gives you a timer on the side how much longer that one will last. you could actually be putting in a code that has 20 seconds left. Shrinking the window for the thief even more.

    But this is all based on the route of encryption SE goes by. On the Go process would use to much battery power and I don't think is standard. It would also destroy the OTP's locking upon logging in with the 2 year cool down.

    I think the only question for now is, Will SE be cheap? Will SE be Smart with the format Choice, Pre-Generate Time, or On the Go?

  7. #147
    Xaru
    Guest

    Quote Originally Posted by Fiendishone View Post
    So let me get this straight. Squenix wants US to pay for an item that makes our login more secure because THEY FAILED TO DO SO?



    BRILLIANT!



    Seriously, they should be giving these out for fucking free to every paying account.
    The problem is squarely with the stupidity of the users, not the security of POL or FFXI. This item helps with the PEBCAK issue and isn't meant to remedy any security failing on the part of SE.

  8. #148
    A. Body
    Join Date
    Jul 2008
    Posts
    4,046
    BG Level
    7
    FFXI Server
    Caitsith

    Quote Originally Posted by Fiendishone View Post
    So let me get this straight. Squenix wants US to pay for an item that makes our login more secure because THEY FAILED TO DO SO?



    BRILLIANT!



    Seriously, they should be giving these out for fucking free to every paying account.
    You know...

    Nevermind.

  9. #149
    Ranger
    9900klub

    Join Date
    Apr 2005
    Posts
    9,976
    BG Level
    8
    FFXIV Character
    Sonomaa Kihten
    FFXIV Server
    Gilgamesh
    FFXI Server
    Bahamut
    WoW Realm
    Durotan
    Blog Entries
    12

    Quote Originally Posted by alabamahotpocket View Post
    While this Security Token is great for account password protection, its useless against session hijacking type of trojans because of the way ffxi is designed.

    Let me explain what i mean with an example. Ill use the windower plugin LightLuggage as example (im not saying LL is a trojan lol, just using it to explain session hijacking).

    As plugin developer, i could add some extra code to this plugin that only gets activated if a character named "Somerandomcharacter" sends the plugin user (the victim) a trade request. Once this trade request is sent from the exploiter (in this case me, the developer), the plugin could block all the user input from windower, and start sending keyboard commands to the game. It only takes a few key clicks to accept the trade, put up all your Gil in trade window and hit OK. All trades are final, right?

    If the trojan was well written, it could even check players equip and unequip high priced items (like KC) for trading. Same with bazaars.

    There's no security code to confirm if the trade was legit or not (unless the "in-game bonus" in announcement means you can use the device to confirm in-game trades, bazaaring, delivery boxing and selling on AH).

    The plugin dont even need internet access, so your firewall and antivirus programs would not protect you in this case. Having access to FFXI data in your PC memory is good enough.

    Since the source code of the plugin is not open to public, you cant really know if something extra was added to it. You probably wont even know which plugin did it. It could happen while you are afk to eat or just doing overnight bazaaring.

    Also, this dont have to be windower plugin. Im just using it as example since many ppl use those. It could be some random virus you picked up from somepage.com or the functionality could be built in the claiming bot you are using.

    As long as the FFXI items/gil can be turned into real life money, RMT will be after your stuff, and they dont care what methods are used to get it.

    /cheers
    every plugin through windowers website is gone through with a fine tooth comb by the lead dev, if you are downloading 3rd party plugins and tools without verifying the creator first you deserve to get your shit hijacked

  10. #150
    Nidhogg
    Join Date
    Jun 2007
    Posts
    3,528
    BG Level
    7
    FFXI Server
    Odin
    WoW Realm
    Lightbringer

    Quote Originally Posted by Sonomaa View Post
    every plugin through windowers website is gone through with a fine tooth comb by the lead dev, if you are downloading 3rd party plugins and tools without verifying the creator first you deserve to get your shit hijacked
    Humanity is working around the clock to build a better idiot.

    I still have yet to hear a realistic example from anyone on how this new security measure could possibly backfire, unless the user is an idiot. The only thing I can think of is eventually the battery life of the key will die, or will eventually be lost to hardware failure. Even then, it should be fairly easy to get a new one. Plus, if this system is too potentially inconvenient for some people, you don't even need to get it.

    Forget stupid Pandy Warden PR announcements. SE just needs to keep doing stuff like this to keep in the good graces.

  11. #151
    Sandworm Swallows
    Join Date
    Dec 2006
    Posts
    7,328
    BG Level
    8

    Quote Originally Posted by Seraph View Post
    Humanity is working around the clock to build a better idiot.

    I still have yet to hear a realistic example from anyone on how this new security measure could possibly backfire, unless the user is an idiot. The only thing I can think of is eventually the battery life of the key will die, or will eventually be lost to hardware failure. Even then, it should be fairly easy to get a new one. Plus, if this system is too potentially inconvenient for some people, you don't even need to get it.

    Forget stupid Pandy Warden PR announcements. SE just needs to keep doing stuff like this to keep in the good graces.
    That is the thing that I don't get about the people complaining about this...

    If you don't think it will work, they don't buy the freaking thing. It's not required.

    If you don't think it will work, pretty much the whole world thinks you are an idiot, but you can still do whatever you want.

  12. #152
    Sea Torques
    Join Date
    Oct 2005
    Posts
    522
    BG Level
    5
    FFXI Server
    Kujata

    even though I barely play anymore, gonna be really tempted to buy this just for the hell of it

  13. #153
    A. Body
    Join Date
    Jul 2006
    Posts
    4,224
    BG Level
    7

    Quote Originally Posted by fusionx View Post
    Information on the Security Token's release date and price, as well as further details regarding the in-game bonus, will be announced at a later date.
    Authenticator, FUCK YEAH.

    Bravo for S-E taking up something Blizzard had in months ago, as it works.

  14. #154
    COPPER-SHELLED QUADAV
    COPPER-SHELLED QUADAV
    COPPER-SHELLED QUADAV

    Join Date
    Oct 2008
    Posts
    1,136
    BG Level
    6

    ...and if it runs off of a little solar cell, the OTP tag should never run out of power.

    Calintzpso has got it right in terms of how difficult these are to break through. Someone already posted the XKCD joke about just beating someone over the head until they hand over the tag.

  15. #155
    Nidhogg
    Join Date
    Feb 2008
    Posts
    3,790
    BG Level
    7
    FFXIV Character
    Tsugaru Mifra
    FFXIV Server
    Hyperion
    FFXI Server
    Ragnarok

    Quote Originally Posted by Spekkio View Post
    the only 100% secure system is a computer that's off. in a 3 foot thick block of concrete. buried. at the bottom of the mariana trench.
    PARANOIA.

    As long as a computer is left untouched by humans and disconnected from the internet, it is 100% safe.

    But that's a tree falling in the woods. What's the point in having it?

  16. #156
    E. Body
    Join Date
    Mar 2006
    Posts
    2,333
    BG Level
    7

    Quote Originally Posted by Calintzpso View Post
    The thief wouldn't know the password your putting in until its "completely" typed in, they don't know the moment you push the button on the token.

    The time frame from finishing the input of the OTP and logging in would be roughly less then 10 seconds.

    Once a OTP password is generated on the token and is then entered and used to access the server, on the server side, that Key is disabled and will not work again until a long time. The token will also not generate that same key again for a long time, by math or programming I don't remember.

    Someone did the math once and it was on some research post on Digg, for the same OTP to be the key would take minimum 2~ years. I'll have to hunt down the news clip post.(One news post i recall had a Man manually try to break a 512 bit encrytion and layered a 12x12 foot room with enough paper and notes to make a tree)

    The only way someone could get your account is to

    A. Steal the Token
    B. Intercept your input submission in real time and time the block of your submission to the server and be ready fast to log in instead.(Roughly 50secs or less based on your input speed of the OTP).

    But Choice B could be and will most likely be even more hindered by the fact that If I recall, all RSA tokens aren't designed to instantly generate on the go, but instead every 60secs(Repeatedly pushing the button won't change it). When you push that button it displays the recent code and gives you a timer on the side how much longer that one will last. you could actually be putting in a code that has 20 seconds left. Shrinking the window for the thief even more.

    But this is all based on the route of encryption SE goes by. On the Go process would use to much battery power and I don't think is standard. It would also destroy the OTP's locking upon logging in with the 2 year cool down.

    I think the only question for now is, Will SE be cheap? Will SE be Smart with the format Choice, Pre-Generate Time, or On the Go?
    correct. collisions on a 6 digit tag assuming that there is no statistical bias towards any set of numbers would be exceptionally rare. it's a hash, so collisions can happen, but the same could be said of any password hash where the hash output's range has a smaller cardinality than the input domain. assuming that the password's range is 1 six digit number in base 10, the cardinality of that range is 10^6 or 1,000,000 combinations. as there are ~525,949 minutes per year (thanks google calculator!) it would take almost 2 years as you say to duplicate a key assuming the hash is properly implemented. for all intensive purposes, once a key is used you can pretty much count it dead for the rest of reasonable examination of this problem.

    the second scenario is actually not all that implausible though. if a trojan were to get on your system, it could simply intercept and block all traffic from ffxi while at the same time logging keystrokes. by mechanically shooting it off to a remote location and mechanically logging in, it would not be unfeasible for an attacker to hijack your login attempt and use that to gain access to your account within a matter of 1-2 seconds. odds on, if the OTP hasn't expired by the time you keyed it in, it wouldn't expire before an attacker could use it to log in. this demonstrates that if your computer is infected, you ARE still vulnerable to having your account stolen, but red flags will be going off like mad when you can't connect in. you also know that if you successfully connect, your session was not hijacked and your credentials are safe. it's not perfect, but it's a good step.

  17. #157
    New Spam Forum
    Join Date
    Nov 2006
    Posts
    161
    BG Level
    3

    Quote Originally Posted by Fiendishone View Post
    So let me get this straight. Squenix wants US to pay for an item that makes our login more secure because THEY FAILED TO DO SO?



    BRILLIANT!



    Seriously, they should be giving these out for fucking free to every paying account.
    Yeah, see, not everyone wants or needs something like this. For example, if you play on console only, and only console, then your odds of getting hacked are near zero.

    Think of it this way, your password is a standard deadbolt on an apartment door, while this dongle thing is an iron bar across the door. Options always cost extra, and this is no exception.

    Now, as for the item, I hope it's something for the legs. I need something to complete my whole "I'm a SE whore" outfit...

  18. #158
    Nidhogg
    Join Date
    Jun 2007
    Posts
    3,528
    BG Level
    7
    FFXI Server
    Odin
    WoW Realm
    Lightbringer

    Quote Originally Posted by Keyln View Post
    Now, as for the item, I hope it's something for the legs. I need something to complete my whole "I'm a SE whore" outfit...
    Tarutaru butt plug to prevent unauthorized intrusion. It even keeps to the theme.

  19. #159
    Witty Custom Title
    Join Date
    Dec 2006
    Posts
    2,849
    BG Level
    7
    FFXIV Character
    Eticket Pogona
    FFXIV Server
    Hyperion
    FFXI Server
    Valefor

    Quote Originally Posted by Araelus View Post
    ...and if it runs off of a little solar cell, the OTP tag should never run out of power.
    except for the fact that most hardcore FFXI players haven't seen sunlight in 5 years

  20. #160
    Banned.

    Join Date
    Mar 2007
    Posts
    15,501
    BG Level
    9
    FFXIV Character
    Patricia Lanvaldear
    FFXIV Server
    Sargatanas

    Quote Originally Posted by Eticket View Post
    except for the fact that most hardcore FFXI players haven't seen sunlight in 5 years
    zing!

Page 8 of 14 FirstFirst ... 6 7 8 9 10 ... LastLast

Similar Threads

  1. Average Life Cycle of a Square Enix Security Token
    By LinktheDeme in forum FFXI: Everything
    Replies: 27
    Last Post: 2020-04-28, 20:46
  2. Square Enix Security Token Problem ><
    By Martys in forum FFXI: Everything
    Replies: 27
    Last Post: 2009-10-21, 14:12
  3. Replies: 884
    Last Post: 2009-06-15, 14:49
  4. Square Enix Security Token
    By fobber in forum FFXI: Everything
    Replies: 2
    Last Post: 2009-04-08, 23:11
  5. Replies: 1134
    Last Post: 2009-04-07, 20:40
  6. Square Enix Security Token Fair or Not
    By dejet in forum FFXI: Everything
    Replies: 3
    Last Post: 2009-03-31, 12:49
  7. Win a Square Enix Security Token
    By Pikko in forum FFXI: Everything
    Replies: 17
    Last Post: 2009-03-19, 13:42