Item Search
     
BG-Wiki Search
Page 7 of 9 FirstFirst ... 5 6 7 8 9 LastLast
Results 121 to 140 of 163
  1. #121
    Day
    Day is offline
    IMPERIAL CONCUBINE OF ME
    Coolest Monkey In The Jungle

    Join Date
    Sep 2007
    Posts
    21,547
    BG Level
    10

    They are expiring, just not in the way we thought it was going to work, god this title is so misleading. Once you use it, it expires, otherwise you got 27~ minutes to punch it in.

  2. #122
    E. Body
    Join Date
    Mar 2006
    Posts
    2,333
    BG Level
    7

    Quote Originally Posted by Izzy View Post
    That's what people aren't getting. They think that when you hit the keychain button, it magically sends a sub-space beacon message to SE and they know that's the current key.

    Again, the key is basically a 30 second timer that's synced with a duplicate 30 second timer at SE headquarters.
    but...but...but... i wanted to pretend every time i hit the button it was like calling the enterprise! he's dead jim; and so is my imaginary adventures as Mr.Spekk i mean Spock.

  3. #123

    ▲▲

    Join Date
    Aug 2005
    Posts
    6,803
    BG Level
    8
    FFXIV Character
    Pikarya Saisei
    FFXIV Server
    Excalibur

    Just called the POL help center this morning, and even though the lady said she couldn't help me with support of the tokens function, she said they it could be a temporary thing until they get most (if not all tokens) rolled out by the end of this month.

    So maybe its just until everyone gets used to it/gets it setup for the first time. Then maybe they'll change it. Just an optimistic thought.

  4. #124
    WASTE OF CURRENCY
    I CAN'T I CAN'T I CAN'T

    Join Date
    Feb 2006
    Posts
    9,065
    BG Level
    8
    FFXIV Character
    Izzy Izumi
    FFXIV Server
    Sargatanas
    FFXI Server
    Phoenix
    WoW Realm
    Arthas

    Quote Originally Posted by Day View Post
    They are expiring, just not in the way we thought it was going to work, god this title is so misleading. Once you use it, it expires, otherwise you got 27~ minutes to punch it in.
    Yea I know. I can't change the title though...I tried.

  5. #125
    Day
    Day is offline
    IMPERIAL CONCUBINE OF ME
    Coolest Monkey In The Jungle

    Join Date
    Sep 2007
    Posts
    21,547
    BG Level
    10

    I like your "STEAL THE HQ" image btw :3

  6. #126
    WASTE OF CURRENCY
    I CAN'T I CAN'T I CAN'T

    Join Date
    Feb 2006
    Posts
    9,065
    BG Level
    8
    FFXIV Character
    Izzy Izumi
    FFXIV Server
    Sargatanas
    FFXI Server
    Phoenix
    WoW Realm
    Arthas

    I put the big one I made in the crafting section ^O^/

    http://img4.imageshack.us/img4/9165/...synthinyou.jpg

  7. #127
    New Spam Forum
    Join Date
    Jul 2007
    Posts
    197
    BG Level
    3
    FFXI Server
    Gilgamesh

    Quote Originally Posted by mackerel View Post
    With a 6 digit code there are 1,000,000 possible passwords.
    Most of the time, there will be 40 valid passwords.
    1/25000 password attempts will work most of the time.

    My math is rough here but the concept is good:
    If there are 1,000,000 possibilities and a new code becomes valid every 30 seconds,
    there are 2 new codes per minute, 120 per hour, 8333 per day, 3,041,666 per year.
    On average, every possible code will be valid once per 4 months.
    The assumption that the algorithm will not repeat a password is the flaw in your theory. The RSA card implementations can produce the same code before iterating through all the codes. This is to prevent brute force attacks such as yours from counting on the fact that the algorithm will repeat during a set interval. This alone will increase the duration from 4 months to any given amount of time that is determinant on the collision distribution and seed complexity.

    At any given 27 minute interval your chances are basically reset based on strength of the hash function and its ability to not have concentrated collisions in a certain small range(another topic altogether). If there is a lockout duration, it pretty much means that your chance of bruteforcing probability wise has to do with the total number of attempts breaking the culmulative probability of trying so many times. And that is still not definitive but a chance.

    Furthermore, it is easy to programmatically identify bruteforce attempts. The proxy argument about just using another proxy is poor. There are not an indefinite number of proxies available and the number of proxies available diminishes at a much faster rate than simple programmatic IP banning process for excessive bruteforce attacking.

    Because there is the Square-Enix Username and password. Your theory also only applies to people that are compromised via keylogger and not change their account security at any given point through a long duration. Business logic for the hackers must also be played in. With Long brute force investment to hack accounts with variable unverifiable payload, is it worth it to break in to random unknown account which could potentially be a mule or a poor character?

  8. #128
    Canada
    Join Date
    Oct 2006
    Posts
    1,482
    BG Level
    6
    FFXIV Character
    Mlle Skjie
    FFXIV Server
    Hyperion
    FFXI Server
    Sylph
    WoW Realm
    Madoran

    Quote Originally Posted by AoshiZ View Post
    The assumption that the algorithm will not repeat a password is the flaw in your theory. The RSA card implementations can produce the same code before iterating through all the codes. This is to prevent brute force attacks such as yours from counting on the fact that the algorithm will repeat during a set interval. This alone will increase the duration from 4 months to any given amount of time that is determinant on the collision distribution and seed complexity.

    At any given 27 minute interval your chances are basically reset based on strength of the hash function and its ability to not have concentrated collisions in a certain small range(another topic altogether). If there is a lockout duration, it pretty much means that your chance of bruteforcing probability wise has to do with the total number of attempts breaking the culmulative probability of trying so many times. And that is still not definitive but a chance.

    Furthermore, it is easy to programmatically identify bruteforce attempts. The proxy argument about just using another proxy is poor. There are not an indefinite number of proxies available and the number of proxies available diminishes at a much faster rate than simple programmatic IP banning process for excessive bruteforce attacking.

    Because there is the Square-Enix Username and password. Your theory also only applies to people that are compromised via keylogger and not change their account security at any given point through a long duration. Business logic for the hackers must also be played in. With Long brute force investment to hack accounts with variable unverifiable payload, is it worth it to break in to random unknown account which could potentially be a mule or a poor character?

    This. The 27 minute window changes nothing in a realistic scenario. You are far more secure with this token than without it.

  9. #129
    Space Pope
    Join Date
    Oct 2006
    Posts
    361
    BG Level
    4
    FFXI Server
    Diabolos

    Quote Originally Posted by Skjie View Post
    This. The 27 minute window changes nothing in a realistic scenario. You are far more secure with this token than without it.
    I suspect it's generically a 30-minute token. Minus the time between the initial button-press and when you link that specific token to the SE account.

    for instance:

    12:00 - press button, recieve number
    12:00-12:03 - fill out webpage form with number recieved, SE account info, etc.
    12:03 - press "submit". The form will take that number you entered and consider it valid at *this* exact time, not 3 minutes prior.

    I wonder, if you waited 29 minutes to submit your key to the SE synchronization page, would your later numbers only be valid for 1 minute intervals? Since they'd be rolling off the end of the algorithm.

  10. #130
    Nidhogg
    Join Date
    Jun 2007
    Posts
    3,528
    BG Level
    7
    FFXI Server
    Odin
    WoW Realm
    Lightbringer

    Under normal circumstances, a wormhole can only be maintained for slightly more than 38 minutes.[38] Extending the wormhole duration beyond this requires tremendous amounts of power, such as that provided by a nearby black hole,[39][40], energy beings,[41] or advanced technologies.[3][42]

    http://en.wikipedia.org/wiki/Stargate_(device)

    WE HAVE OUR ANSWER! :-þ

  11. #131
    Relic Weapons
    Join Date
    Nov 2005
    Posts
    338
    BG Level
    4

    Quote Originally Posted by Stubwub View Post
    Has anyone contacted SE about this? Where can we go to let them know they're not expiring.
    There is no need to contact SE on this, it is working as expected.

    Same deal goes for my place of employment, and if it's good enough for my company, I'm more than confident it is sufficient for a mmorpg.

    My token is almost exactly the same as the ffxi one, made by the same vendor even. Each code lasts around 30 mins and a new code is generated every 30 seconds.

    The security is still there, even if a code is valid for 30 or so minutes. The brute force arguments that I've read in this thread isn't a valid argument. Not only is there a limit on attempts, but the time required to break the key is much larger than the <30 minutes you have before the key changes.

  12. #132
    YOU ARE SEARED
    Dungeon Master of the House of Weave

    Join Date
    May 2007
    Posts
    4,453
    BG Level
    7
    WoW Realm
    Kilrogg

    Quote Originally Posted by shaddix View Post
    15 minutes, 5th failed attempt was done at :04 and first successful attempt after that was at :19
    Can you try this again but use an "old" code? Like, fudge it until it locks out, then use a code generated at the 13 minute mark in the lockout period when it unlocks.

    I'm curious to know if it's constantly generating the codesets or if it only starts reading and accepting during non-lockout periods...if the latter then this is pretty damnedably safe from anything short of someone cracking the seed algorithm.

  13. #133
    E. Body
    Join Date
    Mar 2006
    Posts
    2,333
    BG Level
    7

    Quote Originally Posted by Norellicus View Post
    Can you try this again but use an "old" code? Like, fudge it until it locks out, then use a code generated at the 13 minute mark in the lockout period when it unlocks.

    I'm curious to know if it's constantly generating the codesets or if it only starts reading and accepting during non-lockout periods...if the latter then this is pretty damnedably safe from anything short of someone cracking the seed algorithm.
    the token has NO WAY of knowing if the account is locked out. it just keeps using a function to generate numbers based off the internal clock. period. you can lock out your account. you can delete the account. SE can close their servers. alien overlords could descend upon the earth wiping out all human life in preparation for terraforming the planet into something habitable for their powerful, space faring race. and the token will continue to generate numbers. will the server accept numbers that would have been generated in a lockout period? who knows. maybe, maybe not. that's an implementation question, but the token will keep generating them regardless of what fate befalls your account or the human race.

  14. #134
    WASTE OF CURRENCY
    I CAN'T I CAN'T I CAN'T

    Join Date
    Feb 2006
    Posts
    9,065
    BG Level
    8
    FFXIV Character
    Izzy Izumi
    FFXIV Server
    Sargatanas
    FFXI Server
    Phoenix
    WoW Realm
    Arthas

    hahahahahhaah

  15. #135
    Day
    Day is offline
    IMPERIAL CONCUBINE OF ME
    Coolest Monkey In The Jungle

    Join Date
    Sep 2007
    Posts
    21,547
    BG Level
    10

    I think he meant the server that matches the code from the token to whatever it has to match, not so much the token itself. Something server side has to be generating the same set of codes as the token right?

  16. #136
    New Merits
    Join Date
    Jun 2007
    Posts
    219
    BG Level
    4
    FFXI Server
    Cerberus

    Quote Originally Posted by Seraph View Post
    Under normal circumstances, a wormhole can only be maintained for slightly more than 38 minutes.[38] Extending the wormhole duration beyond this requires tremendous amounts of power, such as that provided by a nearby black hole,[39][40], energy beings,[41] or advanced technologies.[3][42]

    Stargate (device) - Wikipedia, the free encyclopedia

    WE HAVE OUR ANSWER! :-þ
    Fuck yeah Stargate!

    I started rewatching SG-1 recently. Good times.

  17. #137
    E. Body
    Join Date
    Mar 2006
    Posts
    2,333
    BG Level
    7

    Quote Originally Posted by Day View Post
    I think he meant the server that matches the code from the token to whatever it has to match, not so much the token itself. Something server side has to be generating the same set of codes as the token right?
    i highly doubt that the server is constantly generating the codes and logging them through a sliding window. figure 50,000 accounts every 40 seconds and that's a lot of chugging. instead, when you login, it generates F(T), F(T-30), F(T-60), etc. and sees if any of the elements of that list match the key you submitted.

  18. #138
    E. Body
    Join Date
    Nov 2008
    Posts
    2,048
    BG Level
    7
    FFXI Server
    Bismarck

    not to sure about this time out amount. i just tested, and i could only use a password once, even within a 30 second period.

  19. #139
    COPPER-SHELLED QUADAV
    COPPER-SHELLED QUADAV
    COPPER-SHELLED QUADAV

    Join Date
    Oct 2008
    Posts
    1,136
    BG Level
    6

    Quote Originally Posted by Spekkio View Post
    the token has NO WAY of knowing if the account is locked out. it just keeps using a function to generate numbers based off the internal clock. period. you can lock out your account. you can delete the account. SE can close their servers. alien overlords could descend upon the earth wiping out all human life in preparation for terraforming the planet into something habitable for their powerful, space faring race. and the token will continue to generate numbers. will the server accept numbers that would have been generated in a lockout period? who knows. maybe, maybe not. that's an implementation question, but the token will keep generating them regardless of what fate befalls your account or the human race.
    Reminds me of

    http://badblue.com/temp/080410-st-opening-shot.jpg
    A badly garbled distress call was just received.

    http://badblue.com/temp/090216-st-spock-sensor.jpg
    Captain, computer scanning recognized the location ZZ9 Plural Z Alpha ... then we lost the signal...

    http://badblue.com/temp/090216-st-starfield.jpg
    Our sensors show this entire region has been destroyed.

    http://badblue.com/temp/090216-st-kirk.jpg
    That's. Incredible.

    http://img21.imageshack.us/img21/165...sabledship.jpg
    The signal appears to be coming from a small object of unknown origin, made up of high density polyethylene and thermoplastic carbonate groups.

    http://badblue.com/temp/090216-st-spock.jpg
    Readings are difficult due to subspace interference, but the object has taken heavy damage and remains functional. It may be related to the Twentieth-Century phenomenon known as "RMT-PWNER".

    http://badblue.com/temp/090216-st-kirk-alert.jpg
    RMT? Not that. It might. Be. Hostile to. Us.

    http://badblue.com/temp/090216-st-sp...or-serious.jpg
    Sir... sensors indicate the device is generating random numbers at a geometrically increasing frequency.

    http://badblue.com/temp/090216-st-sulu.jpg
    Captain! The number refresh rate has increased to maximum!

    http://badblue.com/temp/090216-st-battle-stations.jpg
    Number stream has resolved to a visual data transmission.

    http://badblue.com/temp/090216-st-decker3.jpg
    MY ACCOUNT THEY HACKED MY ACCOUNT I HAD NINURTA'S SASH TOO

    http://badblue.com/temp/090216-st-kirk-2.jpg
    Did you call the. Help. Desk or a. GM?

    --
    The SEA page says passwords are supposed to no longer work after 30 seconds, so this is not working as planned.

  20. #140
    Salvage Bans
    Join Date
    Jul 2005
    Posts
    853
    BG Level
    5
    FFXIV Character
    Zumi Kasumi
    FFXIV Server
    Sargatanas
    FFXI Server
    Phoenix

    Also it would take a lot longer to brute force it. Like someone already mentioned you get locked out for 10 min after 5 incorrect codes.

Page 7 of 9 FirstFirst ... 5 6 7 8 9 LastLast

Similar Threads

  1. FFXI on Mac: Working in Parallels 4.0
    By fussel in forum FFXI: Everything
    Replies: 90
    Last Post: 2009-03-30, 22:58
  2. Epic Hard FFXI Boss Killed In One Minute (Kotaku)
    By Xyle in forum FFXI: Everything
    Replies: 79
    Last Post: 2008-09-21, 19:38
  3. FFXI AH Search Toolbar in Firefox 2.0
    By Stromgarde in forum FFXI: Everything
    Replies: 3
    Last Post: 2007-03-25, 05:01
  4. How to change salvage in 5 minutes of your time
    By Lordwafik in forum FFXI: Everything
    Replies: 100
    Last Post: 2007-02-06, 21:48
  5. free ffxi dl code mooch
    By Shaodin in forum FFXI: Everything
    Replies: 1
    Last Post: 2006-02-02, 17:25
  6. Kirin in 15 minutes?
    By Benadar in forum FFXI: Everything
    Replies: 25
    Last Post: 2005-10-03, 01:36