Someone find Woozie to figure this out for us haha.
Someone find Woozie to figure this out for us haha.
I get 416 days, 16 hours on the (almost certainly flawed) assumption that it cycles through every possible password before repeating. 36 million seconds for 1 million distinct strings, divided by 60 seconds in a minute, 60 minutes in an hour, 24 hours in a day.
Anyway, forgive me for going back and forth on this, but I think that regardless of the fact that it's 60x as many codes as I previously wrote, this is not in itself an objection to the fact that SE keeps a somewhat large block of valid codes. If an RMT is trying the same code every 36 seconds, it doesn't matter if SE has 1 valid code, 10 valid codes, or 1000 valid codes open at the same time. Employing that strategy they would be equally likely in all cases to stumble across the correct one in a fixed amount of time.
Basically, while I was wrong on the number of different codes that are generated over 138 hours (13.8k instead of 231), this doesn't change the fact that someone entering the same code repeatedly has the exact same chance of gaining unauthorized access to your account regardless of the size of the valid code block.
I do think, as I indicated earlier, that a larger block would allow for some method of increasing the number of different codes attempted over the same period of time (and thereby increase the likelihood of gaining access), but I don't really trust myself to do the reasoning correctly at this time. (Nor am I sure what premises to use. Can RMT only attempt to access once every 20-30 seconds like a regular login? Or would they have some faster method that would allow them to try more codes in the same period of time at the outset?)
The chances of guessing a completely random 6 digit # are 1 in 1 million. At ten seconds per guess, this is 115.74 days average to get one account. At thirty seconds per guess, it's 347.22 days average. At 30 seconds per attempt spamming the same number, this is 173.61 days average to get one account. If you assume 100 codes are valid at all times, cycling one code out as one new code comes in this drastically drops to 1.16 days average if randomly guessing every 10 seconds, or 3.47 days average if randomly guessing every 30 seconds. It goes down to 173.58 days average if spamming the same number(it's basically just given 100 free chances once).
Editted a few times, pretty sure those are all correct now.
Is everyone who is making a 'time to crack' guess assuming the RMT already have all of your other passwords?
Yes, and that you're on vacation without your PC so you don't keep getting booted off while they attempt to access it.
It's not about whether or not they guess versus try the same number. It's about whether SE keeping an hour's worth of codes significantly weakens security against someone employing the "same number" method (it doesn't), and whether it weakens security against someone who knows this employing a more sophisticated method (it seems like it could, but I'm not sure if it's by a significant amount).
If you guess incorrectly 5 times in a row are you temporarily locked out? I think our normal PW's are this way right?
It looks like it locks you out, but you dont' get a different error message. I tried 12+ attempts just typing gibberish and never got a different error. I always got the same error, however now, typing in the correct passwords doesn't let me login either.
Edit so yeah its locking you out after some amount of wrong attempts. I'll test again with just the one time pass whenever it lets me login again. Maybe I can pin down how many attempts it gives you.
edit: with just typing in the wrong one-time password. I'll use correct SE password.
POL-5311 is what i'm getting using the correct passwords after being cockblocked for using the wrong passwords.
can't login to SE account site either "Because password entry has failed multiple times, you will not be able to log in for several minutes."
Nevermind. :s
Yes, that's true. I was trying to say that simply pushing the button on your keychain does not disable the previous passwords on the server side. ENTERING a newer password from your keychain into POL WILL disable the older ones server side.
Yes. And it probably varies a little bit per token. The 27 minute thing I mean. That just happens to be the cutoff for mine.
Edit: also it finally let me login. So the timeout after you enter too many bad passwords is at least 10+ minutes. Trying to find out how many attempts you're given. It is probably the same on se account site so would be coo if it just says on there somewhere.
With a 6 digit code there are 1,000,000 possible passwords.
Most of the time, there will be 40 valid passwords.
1/25000 password attempts will work most of the time.
My math is rough here but the concept is good:
If there are 1,000,000 possibilities and a new code becomes valid every 30 seconds,
there are 2 new codes per minute, 120 per hour, 8333 per day, 3,041,666 per year.
On average, every possible code will be valid once per 4 months.
A password is valid for 27 minutes, unless there is a successful login.
The chinese hacker who got your POL/SE ID and password through a keylogger or trojan can guess 123456 for your one-time password, and on average get into your account during one 27 minute span out of 4 months. If they try 4 different passwords, not even required to be in the same 30 second span, they'll get your account in one month on average.
It's safe to assume that organized hackers capable of creating a password-stealing keylogger or trojan are capable of automating POL login attempts. They don't have to sit at the keyboard typing in your ID and password and guessing a 6 digit code. To people capable of creating fishbots, gardening bots, auction house bots, it's a trivial thing to make a login bot. It can beep or even call their cell phone when they get into an account. And there's nothing personal about it, you're not a person to them, just money waiting to be taken. This token does require them to put in more effort, but not a lot more effort as is.
Since the security token's serial number is required in order to deactivate the one-time password feature, they won't be able to lock you out of your account. I hope. They'll still be able to strip your valuables, but they'll have to do it in one sitting. They'll still be able to move you to Carbuncle and change your name to Jslhgashg. They can order A Crystalline Prophecy and a new security token from the login screen and have it charged to your credit card. But hopefully they can't lock you out of your new server.
If SE were to change the lifespan of a password to a more standard 3 minutes, the effort to hack your account would be 9 times greater on average. 9 months instead of 1 month if they guess 4 passwords. So they make their bot guess 36 passwords every 27 minutes, and it's back to 1 month.
What else can SE do? Blocking IPs with more than X failed login attempts causes the hackers to use proxy servers and dynamic IPs. Blocking entire countries hurts legitimate users and gets long-range missiles shot over SE HQ. The sky is falling! Seriously though, the security token does provide a reasonable deterrant to hackers, and limits the damage they can cause when they get in.
5 attempts. I tried the 5th incorrect attempt at :04 so I'll try again at :14 and :15 :16 :17 to see when it lets you back in.
Instead of logging into your FFXI account once they've keylogged your SE ID and password, what if they logged directly into your SE account page at account.square-enix.com, and then changed your password there? Then you would be locked out.
hehe... and that's also assuming that the key will never generate the same password more than once in a years time. also, i believe they'd only get in 30 attempts an hour at the most because of the autolock on x amount of failures feature.
even if the thing only made my account 5 times harder to hack into, i'd still welcome it.