So let's see, those of us that had this happen:
We have token'd accounts, we get an email from POL stating that we may have been compromised. Personally I know I actually was like, last week, but it seems because I did not attempt to relog after being knocked offline, at least for some time, nothing happened.
Anyways, get the email from POL stating to change PW. I had already changed it, so I didn't change my PW again. Perhaps my PW was changed by POL 'for my protection'?
I think that's possible or it's a POL exploit to change that account password... hopefully having the separate and more secure SE account and token is enough to keep our accounts safe if the first layer is hacked.
I just got my account locked and they can't say if it's been moved or anything, guess we'll find out Monday! The plus side is no one has seen me on any server from flist and I was able to change my SE account np, so I think those are positive signs that I was just changed on the first (and most annoying) layer.
Whoever did all of this must of been pretty professional. My friend has played the game since release, doesn't use I.E, doesn't go to any related FFXI sites and was still hit while on a security token. He has scanned his PC with 3 different scanners kaspersky, malwarebytes and avg all turning up nothing. My friend isn't an idiot, before he quit he ran a successful LS which had over 200m in our gilbank so he's already an extremely paranoid dude when it comes to this sorta shit.
Heh, I wish I was so lucky to have not been spotted elsewhere. A friend just spotted me on Alexander, and I can't get into my account as of like a half hour ago. Someone spotted me on ragnarok earlier so it must have happened this morning. I don't use a token, but now I wish I kind of did. It's not like I wander around places where I can get keylogged by RMTs or any shit like that though.
Hopefully you'll come out safer than I did.
Does anyone know a way I can start right now getting my password reset, or am I hosed till monday?
Well true, but it's probably at least a little bit safer.
Thing I don't get is that I haven't even had to type in my PW for months either cause I keep it saved, so I'm at a loss for how I could have been hacked, since keylogging probably wouldn't work. But then I know zilcho about hacking so I could just be retarded.
Ok so, dumb question, and sorry if it's been discussed already....
My passwords are set up so that I have to input a password at the first POL login screen, but my actual POL ID password is set to -saved-, so there is no keyboard input to keylog. The first password keeps anyone else from logging in locally, but wouldn't help anyone who was trying to log into my account from some other computer if somehow they managed to get it. Right?
So is this secure? Or is it possible for hackers to hijack the (saved) password as it is being sent out to SE? And if the answer is that they can't get at it, why is everyone not doing this instead of bothering with security tokens, etc. ?
Thanks. D:
Well, as I just stated, I've had my password saved on my PoL for months. I haven't typed it in for a long ass time. So I would suspect it's probably not safe. How they get it, I have no clue. But they obviously can, so I dunno what to tell you. Cross your fingers and hope you're not unlucky next month in the next round of hackings? :/
Oh, I must have just missed your post. Sorry.
Damn, the sky really is falling.
Yep, hoping I can get all my shit back and my money that the hacker inevitably spent 20 bucks of to server hop me, otherwise I guess I'm just gonna not play MMOs till 14 comes out heh. Damn retarded that SE won't handle compromised account services on weekends though, seems like a service you'd want to offer at least 7 days a week, if not 24/7 <_<
Yeah, I've always found that to be incredibly retarded - to run a 24/7 operation but not run 24/7 service. Along with the lack of a toll-free number. It's total fail.
The big issue is that the passwords are being changed so I can't even log in from the playonline website membership area. (https://secure.square-enix.com/cisweb/app) Somehow someone is changing passwords w.o needing token access.
Without needing any access really, since I think I've got the same issue basically, just that I don't have a token. Sounds about right.