Hello BG Community,
I'm writing this, because of I get tired of sending "Suggestions" via the POL Online formular, which obviously get ignored.
I've been on 2 sides of the game a lot. One side, a player, loyal LS member, and the other side, monitoring the "scene" behind, recent hacks, exploits and so on. Just on a side note, I'm not belonging to the bad guys, developing and using bots and stuff. I've been into game programming and securing (including working on punkbuster like anti-cheat clients for free mmorpgs) in the past and I'm just really sad when I see the poor trys of Squeenix to give their players some faked security.
I'd like to write down my suggestion I've made in the past 3 or 4 years I'm into FFXI, to show the community what is possible, and hope that Mr. SquareEnixCommunitySupport (or however he is named) copys & pasted this thread to his supervisor.
Account Security
Recently, many people have been hacked. At least 5 people in the closer circle of what I call "online friends" in the past weeks. Well, of course its a bit of their own fault. But there are some SIMPLE things that saves your customers frustration about being hacked, and your IT guys to get the backup from the character.
One Key-Word in my eyes is "E-Mail confirmation"... let me give a few examples:
- At the moment, you can easily change a password once you are logged in. Which hackers can do script controlled, giving the user not enough time to log back in, once he gets disconnected. If you send an E-Mail to the user, which includes a small, random generated code, he has to enter to complete the password change you gain a huge portion of extra security to the account, since a hacker (or "friend" who just uses the account data) has to get access to the Mail Account of the user, too. Of course, you should not make the E-Mail Adress of the User visible in any way in the profile or user data, so the hacker cannot directly see the adress and provider use, and try the aquired FFXI Password to logon the Mail Account (trust me, some users are that stupid).
- The same thing should be done to confirm a server switch. This also reduces unnecessary troubles with the billing, since Users are not happy if they have to pay for a server change a hacker has done, and your accounting department is not happy changing bills all the time.
- Ok, one more small thing to think of. Changing payment method should require E-Mail verification, too, so you can ask a security question if the user wants to change his mail addressi.E. "please enter the last 4 digits of your credit card / bank account". Just to prevent the hacker enters his mail adress and recieves all confirmation mails
Another thing that really bugged me a lot is the "User logged on from another terminal". I've seen quite some people in the middle of Dynamis or a Linkshell event DCing, come back online, warp, go anon, and 20 minute later be on another server.
And if the upper security improvesments apply we could have one more problem. The hacker cannot change a password, so you would be having a fight with the hacker for the logon. Imagin, you DC, logon on again => DC the hacker, the hacker logs back on => you DC... and so on... the winner is the one who has the longest breath to keep the game up, and noone of the 2 has enough time to get to the password change screen..
This thing is also quite simple to prevent. At logon, give the user an option to bind the account to the current ip address for X hours.
This could be done by 2 differnt ways:
1. Before a User logs on, give him a small button named "request one time password". He recieves an Mail with a one time password he can enter. Then his account gets bound to his IP Adress, meaning, noone else can login to this account.
2. For Users with a security token, they could easily enter a SECOND code, to activate the bind to the IP address.
The onliest thing which is very important, the one time password / the second token code must be entered after the first authentication phase has passed, meaning POL is already online. The reason behind that, is that current trojans / hacks can acutally sniff informations before POL goes online, an block your whole POL Client so you cannot go online for a certain amount of time. And we don't want to give the hacker the chance to recieve all passwords and token codes to lock out a user from his character for X hours as the account could then be bound to the hackers IP.
With an account bound to an IP address for X hours a user has enough time, to change his passwords, scan his computer for trojans, or even reformat the hard drive and reinstall
Well... I just wanted to continue to write something about a punkbuster similar client, which can be easily updated immediatly and seperatly from FFXI, to prevent botting and feed the client to scan for the newest bots... but I think I wrote enough wall of text for today.
I hope this text will be read by some SE employees... in the hope they think about it, and not have FFXIV suffer the same problem.
Thanks,
Stiller_Fan
-not being hacked since 5 years (never).
XI Wiki




