Item Search
     
BG-Wiki Search
Page 5 of 9 FirstFirst ... 3 4 5 6 7 ... LastLast
Results 81 to 100 of 163
  1. #81
    WASTE OF CURRENCY
    I CAN'T I CAN'T I CAN'T

    Join Date
    Feb 2006
    Posts
    9,065
    BG Level
    8
    FFXIV Character
    Izzy Izumi
    FFXIV Server
    Sargatanas
    FFXI Server
    Phoenix
    WoW Realm
    Arthas

    Someone find Woozie to figure this out for us haha.

  2. #82
    Nidhogg
    Join Date
    Jan 2006
    Posts
    3,701
    BG Level
    7

    Quote Originally Posted by Izzy View Post
    Drink bleach.

    I just came up with 347.2~ days to attempt every single combination. Is that right?
    I get 416 days, 16 hours on the (almost certainly flawed) assumption that it cycles through every possible password before repeating. 36 million seconds for 1 million distinct strings, divided by 60 seconds in a minute, 60 minutes in an hour, 24 hours in a day.

    Anyway, forgive me for going back and forth on this, but I think that regardless of the fact that it's 60x as many codes as I previously wrote, this is not in itself an objection to the fact that SE keeps a somewhat large block of valid codes. If an RMT is trying the same code every 36 seconds, it doesn't matter if SE has 1 valid code, 10 valid codes, or 1000 valid codes open at the same time. Employing that strategy they would be equally likely in all cases to stumble across the correct one in a fixed amount of time.

    Basically, while I was wrong on the number of different codes that are generated over 138 hours (13.8k instead of 231), this doesn't change the fact that someone entering the same code repeatedly has the exact same chance of gaining unauthorized access to your account regardless of the size of the valid code block.

    I do think, as I indicated earlier, that a larger block would allow for some method of increasing the number of different codes attempted over the same period of time (and thereby increase the likelihood of gaining access), but I don't really trust myself to do the reasoning correctly at this time. (Nor am I sure what premises to use. Can RMT only attempt to access once every 20-30 seconds like a regular login? Or would they have some faster method that would allow them to try more codes in the same period of time at the outset?)

  3. #83
    Melee Summoner
    Join Date
    Sep 2008
    Posts
    31
    BG Level
    1
    FFXI Server
    Lakshmi

    Quote Originally Posted by dejet View Post
    if it does that be great but i do not think so. because i put the wrong SE PW in and the right one time numbe(and it said wrong PW)

    so i did it agian with the same code and i got in.

    lets put it this way the RMT would have to be out to get you. there are much better ways then spaming your ID and hoping to fucking hell it has something good on it lol

    what if its some lvl 30mule account? they just spent 5 and 1/2 days and got shit from it lol.
    It wouldn't be terribly difficult for the RMT to figure out who to target when we have threads like, "How much gil do you have?"

  4. #84
    Banned.

    Join Date
    Oct 2007
    Posts
    5,674
    BG Level
    8

    The chances of guessing a completely random 6 digit # are 1 in 1 million. At ten seconds per guess, this is 115.74 days average to get one account. At thirty seconds per guess, it's 347.22 days average. At 30 seconds per attempt spamming the same number, this is 173.61 days average to get one account. If you assume 100 codes are valid at all times, cycling one code out as one new code comes in this drastically drops to 1.16 days average if randomly guessing every 10 seconds, or 3.47 days average if randomly guessing every 30 seconds. It goes down to 173.58 days average if spamming the same number(it's basically just given 100 free chances once).

    Editted a few times, pretty sure those are all correct now.

  5. #85
    Nidhogg
    Join Date
    Jun 2007
    Posts
    3,528
    BG Level
    7
    FFXI Server
    Odin
    WoW Realm
    Lightbringer

    Is everyone who is making a 'time to crack' guess assuming the RMT already have all of your other passwords?

  6. #86
    Failed Sex Ed
    Join Date
    Aug 2007
    Posts
    2,391
    BG Level
    7

    Quote Originally Posted by Seraph View Post
    Is everyone who is making a 'time to crack' guess assuming the RMT already have all of your other passwords?
    Yes, also, they are brute forcing the accounts of everyone who is reading this thread right now.

  7. #87
    Nidhogg
    Join Date
    Jan 2006
    Posts
    3,701
    BG Level
    7

    Quote Originally Posted by Seraph View Post
    Is everyone who is making a 'time to crack' guess assuming the RMT already have all of your other passwords?
    Yes, and that you're on vacation without your PC so you don't keep getting booted off while they attempt to access it.


    Quote Originally Posted by Thorny View Post
    It doesn't really matter if they spam the same # over and over or continually guess, either way the chances of guessing a completely random 6 digit # are 1 in 1 million. At ten seconds per guess, this is 115.74 days to get one account. At 30 seconds per attempt spamming the same number, this is 347.22 days to get one account.
    It's not about whether or not they guess versus try the same number. It's about whether SE keeping an hour's worth of codes significantly weakens security against someone employing the "same number" method (it doesn't), and whether it weakens security against someone who knows this employing a more sophisticated method (it seems like it could, but I'm not sure if it's by a significant amount).

  8. #88
    Fishing Guru
    Join Date
    Jan 2007
    Posts
    4,722
    BG Level
    7

    If you guess incorrectly 5 times in a row are you temporarily locked out? I think our normal PW's are this way right?

  9. #89
    Banned.

    Join Date
    Oct 2007
    Posts
    5,674
    BG Level
    8

    Quote Originally Posted by Suiram View Post
    Yes, and that you're on vacation without your PC so you don't keep getting booted off while they attempt to access it.




    It's not about whether or not they guess versus try the same number. It's about whether SE keeping an hour's worth of codes significantly weakens security against someone employing the "same number" method (it doesn't), and whether it weakens security against someone who knows this employing a more sophisticated method (it seems like it could, but I'm not sure if it's by a significant amount).
    Even if it's not very sophisticated, it weakens it 100 fold against blind guesses. Basic logic is basic. Also, editted before you posted that :X

  10. #90
    Nidhogg
    Join Date
    Jan 2006
    Posts
    3,701
    BG Level
    7

    Quote Originally Posted by Thorny View Post
    Even if it's not very sophisticated, it weakens it 100 fold against blind guesses. Basic logic is basic. Also, editted before you posted that :X
    Sorry I missed your edit. What you wrote seems right.

  11. #91
    Failed Sex Ed
    Join Date
    Aug 2007
    Posts
    2,391
    BG Level
    7

    Quote Originally Posted by cdgreg View Post
    If you guess incorrectly 5 times in a row are you temporarily locked out? I think our normal PW's are this way right?
    It looks like it locks you out, but you dont' get a different error message. I tried 12+ attempts just typing gibberish and never got a different error. I always got the same error, however now, typing in the correct passwords doesn't let me login either.

    Edit so yeah its locking you out after some amount of wrong attempts. I'll test again with just the one time pass whenever it lets me login again. Maybe I can pin down how many attempts it gives you.

    edit: with just typing in the wrong one-time password. I'll use correct SE password.

    POL-5311 is what i'm getting using the correct passwords after being cockblocked for using the wrong passwords.

    can't login to SE account site either "Because password entry has failed multiple times, you will not be able to log in for several minutes."

  12. #92
    New Spam Forum
    Join Date
    Oct 2006
    Posts
    188
    BG Level
    3
    FFXI Server
    Phoenix

    Nevermind. :s

  13. #93
    WASTE OF CURRENCY
    I CAN'T I CAN'T I CAN'T

    Join Date
    Feb 2006
    Posts
    9,065
    BG Level
    8
    FFXIV Character
    Izzy Izumi
    FFXIV Server
    Sargatanas
    FFXI Server
    Phoenix
    WoW Realm
    Arthas

    Yes, that's true. I was trying to say that simply pushing the button on your keychain does not disable the previous passwords on the server side. ENTERING a newer password from your keychain into POL WILL disable the older ones server side.

  14. #94
    New Merits
    Join Date
    Jan 2009
    Posts
    214
    BG Level
    4
    FFXI Server
    Lakshmi

    Quote Originally Posted by Izzy View Post
    Yes, that's true. I was trying to say that simply pushing the button on your keychain does not disable the previous passwords on the server side. ENTERING a newer password from your keychain into POL WILL disable the older ones server side.
    So to be clear, you have up to 27 minutes worth of previous passwords available to use at any given time until you enter one. Then all passwords before and including the entered password are now invalid?

  15. #95
    Failed Sex Ed
    Join Date
    Aug 2007
    Posts
    2,391
    BG Level
    7

    Quote Originally Posted by hypnotizd View Post
    So to be clear, you have up to 27 minutes worth of previous passwords available to use at any given time until you enter one. Then all passwords before and including the entered password are now invalid?
    Yes. And it probably varies a little bit per token. The 27 minute thing I mean. That just happens to be the cutoff for mine.

    Edit: also it finally let me login. So the timeout after you enter too many bad passwords is at least 10+ minutes. Trying to find out how many attempts you're given. It is probably the same on se account site so would be coo if it just says on there somewhere.

  16. #96
    New Merits
    Join Date
    Dec 2006
    Posts
    200
    BG Level
    4
    FFXI Server
    Odin

    With a 6 digit code there are 1,000,000 possible passwords.
    Most of the time, there will be 40 valid passwords.
    1/25000 password attempts will work most of the time.

    My math is rough here but the concept is good:
    If there are 1,000,000 possibilities and a new code becomes valid every 30 seconds,
    there are 2 new codes per minute, 120 per hour, 8333 per day, 3,041,666 per year.
    On average, every possible code will be valid once per 4 months.

    A password is valid for 27 minutes, unless there is a successful login.
    The chinese hacker who got your POL/SE ID and password through a keylogger or trojan can guess 123456 for your one-time password, and on average get into your account during one 27 minute span out of 4 months. If they try 4 different passwords, not even required to be in the same 30 second span, they'll get your account in one month on average.

    It's safe to assume that organized hackers capable of creating a password-stealing keylogger or trojan are capable of automating POL login attempts. They don't have to sit at the keyboard typing in your ID and password and guessing a 6 digit code. To people capable of creating fishbots, gardening bots, auction house bots, it's a trivial thing to make a login bot. It can beep or even call their cell phone when they get into an account. And there's nothing personal about it, you're not a person to them, just money waiting to be taken. This token does require them to put in more effort, but not a lot more effort as is.

    Since the security token's serial number is required in order to deactivate the one-time password feature, they won't be able to lock you out of your account. I hope. They'll still be able to strip your valuables, but they'll have to do it in one sitting. They'll still be able to move you to Carbuncle and change your name to Jslhgashg. They can order A Crystalline Prophecy and a new security token from the login screen and have it charged to your credit card. But hopefully they can't lock you out of your new server.

    If SE were to change the lifespan of a password to a more standard 3 minutes, the effort to hack your account would be 9 times greater on average. 9 months instead of 1 month if they guess 4 passwords. So they make their bot guess 36 passwords every 27 minutes, and it's back to 1 month.

    What else can SE do? Blocking IPs with more than X failed login attempts causes the hackers to use proxy servers and dynamic IPs. Blocking entire countries hurts legitimate users and gets long-range missiles shot over SE HQ. The sky is falling! Seriously though, the security token does provide a reasonable deterrant to hackers, and limits the damage they can cause when they get in.

  17. #97
    Failed Sex Ed
    Join Date
    Aug 2007
    Posts
    2,391
    BG Level
    7

    5 attempts. I tried the 5th incorrect attempt at :04 so I'll try again at :14 and :15 :16 :17 to see when it lets you back in.

  18. #98
    WASTE OF CURRENCY
    I CAN'T I CAN'T I CAN'T

    Join Date
    Feb 2006
    Posts
    9,065
    BG Level
    8
    FFXIV Character
    Izzy Izumi
    FFXIV Server
    Sargatanas
    FFXI Server
    Phoenix
    WoW Realm
    Arthas

    Instead of logging into your FFXI account once they've keylogged your SE ID and password, what if they logged directly into your SE account page at account.square-enix.com, and then changed your password there? Then you would be locked out.

  19. #99
    New Merits
    Join Date
    Dec 2007
    Posts
    235
    BG Level
    4
    FFXI Server
    Ifrit

    Quote Originally Posted by mackerel View Post
    With a 6 digit code there are 1,000,000 possible passwords.
    Most of the time, there will be 40 valid passwords.
    1/25000 password attempts will work most of the time.

    My math is rough here but the concept is good:
    If there are 1,000,000 possibilities and a new code becomes valid every 30 seconds,
    there are 2 new codes per minute, 120 per hour, 8333 per day, 3,041,666 per year.
    On average, every possible code will be valid once per 4 months.

    A password is valid for 27 minutes, unless there is a successful login.
    The chinese hacker who got your POL/SE ID and password through a keylogger or trojan can guess 123456 for your one-time password, and on average get into your account during one 27 minute span out of 4 months. If they try 4 different passwords, not even required to be in the same 30 second span, they'll get your account in one month on average.

    It's safe to assume that organized hackers capable of creating a password-stealing keylogger or trojan are capable of automating POL login attempts. They don't have to sit at the keyboard typing in your ID and password and guessing a 6 digit code. To people capable of creating fishbots, gardening bots, auction house bots, it's a trivial thing to make a login bot. It can beep or even call their cell phone when they get into an account. And there's nothing personal about it, you're not a person to them, just money waiting to be taken. This token does require them to put in more effort, but not a lot more effort as is.

    Since the security token's serial number is required in order to deactivate the one-time password feature, they won't be able to lock you out of your account. I hope. They'll still be able to strip your valuables, but they'll have to do it in one sitting. They'll still be able to move you to Carbuncle and change your name to Jslhgashg. They can order A Crystalline Prophecy and a new security token from the login screen and have it charged to your credit card. But hopefully they can't lock you out of your new server.

    If SE were to change the lifespan of a password to a more standard 3 minutes, the effort to hack your account would be 9 times greater on average. 9 months instead of 1 month if they guess 4 passwords. So they make their bot guess 36 passwords every 27 minutes, and it's back to 1 month.

    What else can SE do? Blocking IPs with more than X failed login attempts causes the hackers to use proxy servers and dynamic IPs. Blocking entire countries hurts legitimate users and gets long-range missiles shot over SE HQ. The sky is falling! Seriously though, the security token does provide a reasonable deterrant to hackers, and limits the damage they can cause when they get in.
    hehe... and that's also assuming that the key will never generate the same password more than once in a years time. also, i believe they'd only get in 30 attempts an hour at the most because of the autolock on x amount of failures feature.

    even if the thing only made my account 5 times harder to hack into, i'd still welcome it.

  20. #100
    New Merits
    Join Date
    Dec 2007
    Posts
    235
    BG Level
    4
    FFXI Server
    Ifrit

    Quote Originally Posted by Izzy View Post
    Instead of logging into your FFXI account once they've keylogged your SE ID and password, what if they logged directly into your SE account page at account.square-enix.com, and then changed your password there? Then you would be locked out.
    i haven't checked yet, but do you have to enter your secret question/answer in order to change information on there? /shrug

Page 5 of 9 FirstFirst ... 3 4 5 6 7 ... LastLast

Similar Threads

  1. FFXI on Mac: Working in Parallels 4.0
    By fussel in forum FFXI: Everything
    Replies: 90
    Last Post: 2009-03-30, 22:58
  2. Epic Hard FFXI Boss Killed In One Minute (Kotaku)
    By Xyle in forum FFXI: Everything
    Replies: 79
    Last Post: 2008-09-21, 19:38
  3. FFXI AH Search Toolbar in Firefox 2.0
    By Stromgarde in forum FFXI: Everything
    Replies: 3
    Last Post: 2007-03-25, 05:01
  4. How to change salvage in 5 minutes of your time
    By Lordwafik in forum FFXI: Everything
    Replies: 100
    Last Post: 2007-02-06, 21:48
  5. free ffxi dl code mooch
    By Shaodin in forum FFXI: Everything
    Replies: 1
    Last Post: 2006-02-02, 17:25
  6. Kirin in 15 minutes?
    By Benadar in forum FFXI: Everything
    Replies: 25
    Last Post: 2005-10-03, 01:36