Item Search
     
BG-Wiki Search
Page 6 of 9 FirstFirst ... 4 5 6 7 8 ... LastLast
Results 101 to 120 of 163
  1. #101
    New Spam Forum
    Join Date
    Aug 2008
    Posts
    155
    BG Level
    3

    Quote Originally Posted by Izzy View Post
    Instead of logging into your FFXI account once they've keylogged your SE ID and password, what if they logged directly into your SE account page at account.square-enix.com, and then changed your password there? Then you would be locked out.
    Pretty sure you have to use the one time password on the SE page once the token is registered.

    So you need the token to get access to your account on the web as well.

    I hope someone is contacting SE about this? The passes should only last a minute at most, if you ask me.

    EDIT: Just checked. You need to use the pass generated by the token to log in to your SE account on the web.

  2. #102
    Zarion
    Guest

    Quote Originally Posted by setzor View Post
    i haven't checked yet, but do you have to enter your secret question/answer in order to change information on there? /shrug
    iirc you have to use your password AND your one time password from the token to log onto your SE account as well.

  3. #103
    Campaign
    Join Date
    Sep 2007
    Posts
    6,631
    BG Level
    8
    FFXIV Character
    Sean Kipling
    FFXIV Server
    Midgardsormr

    Quote Originally Posted by Zarion View Post
    iirc you have to use your password AND your one time password from the token to log onto your SE account as well.
    Yes you do. (Once the token is reg'd.)

  4. #104
    Failed Sex Ed
    Join Date
    Aug 2007
    Posts
    2,391
    BG Level
    7

    15 minutes, 5th failed attempt was done at :04 and first successful attempt after that was at :19

  5. #105
    Hyperion Cross
    Join Date
    Jan 2007
    Posts
    8,915
    BG Level
    8
    FFXIV Character
    Kai Bond
    FFXIV Server
    Gilgamesh

    Quote Originally Posted by setzor View Post
    i haven't checked yet, but do you have to enter your secret question/answer in order to change information on there? /shrug
    But don't you need the 6 digit password as well as your SE password to get in, in the first place?

    EDIT: Nevermind, replied late and people mentioned it.

  6. #106
    New Merits
    Join Date
    Dec 2007
    Posts
    235
    BG Level
    4
    FFXI Server
    Ifrit

    Quote Originally Posted by Zarion View Post
    iirc you have to use your password AND your one time password from the token to log onto your SE account as well.
    right, but i think we're assuming that yer token key got keylogged/cracked and that they have enough information to log into your SE account. wouldn't be a big deal if the passwords only lasted the 30 seconds that was originally told to us.. it does bother me somewhat, but I'm not starting any online petitions over it ;b

  7. #107
    Nidhogg
    Join Date
    Jan 2006
    Posts
    3,701
    BG Level
    7

    The "20 tries per hour, max" thing pretty much negates any issues with the 30 minute expiration, then. Might want to edit the title of of this thread to something less panic-inducing lol

  8. #108
    New Merits
    Join Date
    Dec 2007
    Posts
    235
    BG Level
    4
    FFXI Server
    Ifrit

    Quote Originally Posted by Suiram View Post
    The "20 tries per hour, max" thing pretty much negates any issues with the 30 minute expiration, then. Might want to edit the title of of this thread to something less panic-inducing lol
    agreed, someone always wants to be the "i told you so" hero...

    "SEE, I TOLD YOU IT WASN'T REALLY SAFE! CHINESE ARE RUNNING CRAYS NOW GENERATING MILLIONS OF PASSWORDS A SECOND, YOU AREN'T SAFE!!! THEY'RE GONNA HOLD OUR ACCOUNTS HOSTAGE UNTIL WE BUY GILZ FROM THEM!!!!"

  9. #109
    Bagel
    Join Date
    Sep 2007
    Posts
    1,397
    BG Level
    6
    FFXI Server
    Valefor

    Quote Originally Posted by Suiram View Post
    The "20 tries per hour, max" thing pretty much negates any issues with the 30 minute expiration, then. Might want to edit the title of of this thread to something less panic-inducing lol
    I am still a little uneasy about the fact that passwords live longer than the lockout time (27 minutes versus 15 minutes).

    If I have all your other info and the only thing holding me back is your security token, all I have to do is have a bot try 123456 every 20 minutes. The account will get locked out every 5 tries but that lockout expires in 15 minutes so the bot can continue on its normal 20-minute-interval schedule without even noticing the account was ever locked.

    The 20 minute intervals would still be short enough that the bot would not miss the 27-minute window where 123456 is actually valid.

    Edit: But at least if you play regularly you would get booted and take action.

  10. #110
    New Merits
    Join Date
    Dec 2007
    Posts
    235
    BG Level
    4
    FFXI Server
    Ifrit

    Quote Originally Posted by Gergall View Post
    I am still a little uneasy about the fact that passwords live longer than the lockout time (27 minutes versus 15 minutes).

    If I have all your other info and the only thing holding me back is your security token, all I have to do is have a bot try 123456 every 20 minutes. The account will get locked out every 5 tries but that lockout expires in 15 minutes so the bot can continue on its normal 20-minute-interval schedule without even noticing the account was ever locked.

    The 20 minute intervals would still be short enough that the bot would not miss the 27-minute window where 123456 is actually valid.

    Edit: But at least if you play regularly you would get booted and take action.
    if they were locking my account out every 15 minutes i'd probably notice and do something about it, like, change my SE password, and call POL asap.

  11. #111
    E. Body
    Join Date
    Jun 2008
    Posts
    2,365
    BG Level
    7
    FFXI Server
    Phoenix

    Quote Originally Posted by setzor View Post
    right, but i think we're assuming that yer token key got keylogged/cracked and that they have enough information to log into your SE account. wouldn't be a big deal if the passwords only lasted the 30 seconds that was originally told to us.. it does bother me somewhat, but I'm not starting any online petitions over it ;b
    Might as well assume they're in your room beating you over the head with a Shadow Lord statue demanding your log-in info.

  12. #112
    WASTE OF CURRENCY
    I CAN'T I CAN'T I CAN'T

    Join Date
    Feb 2006
    Posts
    9,065
    BG Level
    8
    FFXIV Character
    Izzy Izumi
    FFXIV Server
    Sargatanas
    FFXI Server
    Phoenix
    WoW Realm
    Arthas

    I understand you need the random code+password to login to SE's account. What I'm asking is if you also need a NEW code to change any information in the page once you're logged in?

    If not, then RMT could just brute force the SE webpage then change your password and start over again on the POL client. If they do require a 2nd code, you will be safe.

  13. #113
    New Merits
    Join Date
    Dec 2006
    Posts
    200
    BG Level
    4
    FFXI Server
    Odin

    Quote Originally Posted by setzor View Post
    if they were locking my account out every 15 minutes i'd probably notice and do something about it, like, change my SE password, and call POL asap.
    Does it lock your account for 15 minutes, or lock attempts on any account from that computer for 15 minutes?

  14. #114
    Day
    Day is offline
    IMPERIAL CONCUBINE OF ME
    Coolest Monkey In The Jungle

    Join Date
    Sep 2007
    Posts
    21,547
    BG Level
    10

    I can't help but feel like you're grasping at straws to poke holes in the token at this point.

    I will believe a hacked token account when I see it, and I probably still wont believe it.

  15. #115
    WASTE OF CURRENCY
    I CAN'T I CAN'T I CAN'T

    Join Date
    Feb 2006
    Posts
    9,065
    BG Level
    8
    FFXIV Character
    Izzy Izumi
    FFXIV Server
    Sargatanas
    FFXI Server
    Phoenix
    WoW Realm
    Arthas

    Quote Originally Posted by Day View Post
    I can't help but feel like you're grasping at straws to poke holes in the token at this point.

    I will believe a hacked token account when I see it, and I probably still wont believe it.
    I'm not really trying to poke holes in it. I am really happy this tool is available for us to use. I've used these things many times before, and the timeout SE set on the password is absurd compared to any of the other keyfobs I've used before. I'm just questioning their reasoning for allowing a password to be usable for 30 mins instead of for the normal 30-60 seconds.

  16. #116
    Nidhogg
    Join Date
    Jan 2006
    Posts
    3,701
    BG Level
    7

    Maybe it was unintentional, like they misplaced a 0 or something? lol

    From Square Enix Account Management System:

    How do I use my security token?

    Pushing the button on the token will display a 6-digit one-time password. Please enter this password when logging into your Square Enix account.
    The password will change every 30 seconds, so please be sure to enter the password before the 30 seconds have passed.

    I entered my one-time password, but I can't log in.

    If over 30 seconds have passed since the one-time password was produced, a new password will be created. Please enter your password within 30 seconds.
    Both of those suggest that they anticipated the code expiring quickly enough to cause concern for players. So maybe it's a mistake they'll fix later. Either way it seems inconsequential in light of the above.


    By the way, also amusing from that page:

    I forgot my Square Enix account, password, security question, and its answer.

    Please contact the Information Center.

  17. #117
    E. Body
    Join Date
    Mar 2006
    Posts
    2,333
    BG Level
    7

    if someone else had all the credentials besides the token and was able to lock you out of your account, the alternative if you did not have the token would be they'd lock you out of your account permanently by changing the password. this clearly demonstrates that the token IS offering a greater level of security.

    you're also ignoring in all your calculations of 138.9 hrs the fact that there's the sliding window of valid passwords even if the lockout effect could be defeated.

    WALL O TEXT WARNING! tldr at end.
    if the token's password updates every 30 seconds, if you roll a failure against a code you know it's not one of the current 40 active passwords, 30 seconds later you only know it's not a member of 39 valid passwords, 30 more seconds later, it's only not a member of 38 of them. as you can see, each roll is check against the range of the crypto function minus the rolls known to be failures multiplied by a factor to correct for the number of slots in the set of valid keys at a given time. i'm sure we can express this as a sum across n from 0 to 40 but i'm not gonna burn the time right now to figure out the expression.
    END WALL O TEXT
    tldr: 138.9 hrs is a far shorter estimation of the time required to try enough random passwords until you hit one of the 40 active ones.

    while SE's decision to make the token values last for almost 30 minutes does seem a little odd, mathematically it does not significantly reduce the security of the system.

    btw, i'm late to the party in answering this, but it's perfectly plausible that codes older than the one most recently entered could be invalidated. since the values are deterministic, the system merely takes the entered key and compares it to the computed current key, the key from 30 seconds ago, the key from 60 seconds ago, on back for 30 minutes. if say it's 12:00 right now and you entered your key from 11:55, the servers could determine if the key came from 11:55 or before and refuse it, only accepting keys generated after 11:55:30. the server doesn't need to communicate with the device to know what keys it wants to refuse as long as the token keeps chugging out new keys.

  18. #118
    Canada
    Join Date
    Oct 2006
    Posts
    1,482
    BG Level
    6
    FFXIV Character
    Mlle Skjie
    FFXIV Server
    Hyperion
    FFXI Server
    Sylph
    WoW Realm
    Madoran

    Change your POL password every 6 months.

  19. #119
    WASTE OF CURRENCY
    I CAN'T I CAN'T I CAN'T

    Join Date
    Feb 2006
    Posts
    9,065
    BG Level
    8
    FFXIV Character
    Izzy Izumi
    FFXIV Server
    Sargatanas
    FFXI Server
    Phoenix
    WoW Realm
    Arthas

    Quote Originally Posted by Spekkio View Post
    the server doesn't need to communicate with the device to know what keys it wants to refuse as long as the token keeps chugging out new keys.
    That's what people aren't getting. They think that when you hit the keychain button, it magically sends a sub-space beacon message to SE and they know that's the current key.

    Again, the key is basically a 30 second timer that's synced with a duplicate 30 second timer at SE headquarters.

  20. #120
    New Spam Forum
    Join Date
    Aug 2008
    Posts
    155
    BG Level
    3

    Has anyone contacted SE about this? Where can we go to let them know they're not expiring.

Page 6 of 9 FirstFirst ... 4 5 6 7 8 ... LastLast

Similar Threads

  1. FFXI on Mac: Working in Parallels 4.0
    By fussel in forum FFXI: Everything
    Replies: 90
    Last Post: 2009-03-30, 22:58
  2. Epic Hard FFXI Boss Killed In One Minute (Kotaku)
    By Xyle in forum FFXI: Everything
    Replies: 79
    Last Post: 2008-09-21, 19:38
  3. FFXI AH Search Toolbar in Firefox 2.0
    By Stromgarde in forum FFXI: Everything
    Replies: 3
    Last Post: 2007-03-25, 05:01
  4. How to change salvage in 5 minutes of your time
    By Lordwafik in forum FFXI: Everything
    Replies: 100
    Last Post: 2007-02-06, 21:48
  5. free ffxi dl code mooch
    By Shaodin in forum FFXI: Everything
    Replies: 1
    Last Post: 2006-02-02, 17:25
  6. Kirin in 15 minutes?
    By Benadar in forum FFXI: Everything
    Replies: 25
    Last Post: 2005-10-03, 01:36