Item Search
     
BG-Wiki Search
Page 1 of 2 1 2 LastLast
Results 1 to 20 of 22
  1. #1
    Smells like Onions
    Join Date
    Oct 2007
    Posts
    4
    BG Level
    0

    Account Security: An open letter to SE

    Hello BG Community,

    I'm writing this, because of I get tired of sending "Suggestions" via the POL Online formular, which obviously get ignored.

    I've been on 2 sides of the game a lot. One side, a player, loyal LS member, and the other side, monitoring the "scene" behind, recent hacks, exploits and so on. Just on a side note, I'm not belonging to the bad guys, developing and using bots and stuff. I've been into game programming and securing (including working on punkbuster like anti-cheat clients for free mmorpgs) in the past and I'm just really sad when I see the poor trys of Squeenix to give their players some faked security.

    I'd like to write down my suggestion I've made in the past 3 or 4 years I'm into FFXI, to show the community what is possible, and hope that Mr. SquareEnixCommunitySupport (or however he is named) copys & pasted this thread to his supervisor.

    Account Security
    Recently, many people have been hacked. At least 5 people in the closer circle of what I call "online friends" in the past weeks. Well, of course its a bit of their own fault. But there are some SIMPLE things that saves your customers frustration about being hacked, and your IT guys to get the backup from the character.

    One Key-Word in my eyes is "E-Mail confirmation"... let me give a few examples:

    - At the moment, you can easily change a password once you are logged in. Which hackers can do script controlled, giving the user not enough time to log back in, once he gets disconnected. If you send an E-Mail to the user, which includes a small, random generated code, he has to enter to complete the password change you gain a huge portion of extra security to the account, since a hacker (or "friend" who just uses the account data) has to get access to the Mail Account of the user, too. Of course, you should not make the E-Mail Adress of the User visible in any way in the profile or user data, so the hacker cannot directly see the adress and provider use, and try the aquired FFXI Password to logon the Mail Account (trust me, some users are that stupid).

    - The same thing should be done to confirm a server switch. This also reduces unnecessary troubles with the billing, since Users are not happy if they have to pay for a server change a hacker has done, and your accounting department is not happy changing bills all the time.

    - Ok, one more small thing to think of. Changing payment method should require E-Mail verification, too, so you can ask a security question if the user wants to change his mail address i.E. "please enter the last 4 digits of your credit card / bank account". Just to prevent the hacker enters his mail adress and recieves all confirmation mails

    Another thing that really bugged me a lot is the "User logged on from another terminal". I've seen quite some people in the middle of Dynamis or a Linkshell event DCing, come back online, warp, go anon, and 20 minute later be on another server.

    And if the upper security improvesments apply we could have one more problem. The hacker cannot change a password, so you would be having a fight with the hacker for the logon. Imagin, you DC, logon on again => DC the hacker, the hacker logs back on => you DC... and so on... the winner is the one who has the longest breath to keep the game up, and noone of the 2 has enough time to get to the password change screen..

    This thing is also quite simple to prevent. At logon, give the user an option to bind the account to the current ip address for X hours.
    This could be done by 2 differnt ways:
    1. Before a User logs on, give him a small button named "request one time password". He recieves an Mail with a one time password he can enter. Then his account gets bound to his IP Adress, meaning, noone else can login to this account.
    2. For Users with a security token, they could easily enter a SECOND code, to activate the bind to the IP address.

    The onliest thing which is very important, the one time password / the second token code must be entered after the first authentication phase has passed, meaning POL is already online. The reason behind that, is that current trojans / hacks can acutally sniff informations before POL goes online, an block your whole POL Client so you cannot go online for a certain amount of time. And we don't want to give the hacker the chance to recieve all passwords and token codes to lock out a user from his character for X hours as the account could then be bound to the hackers IP.

    With an account bound to an IP address for X hours a user has enough time, to change his passwords, scan his computer for trojans, or even reformat the hard drive and reinstall

    Well... I just wanted to continue to write something about a punkbuster similar client, which can be easily updated immediatly and seperatly from FFXI, to prevent botting and feed the client to scan for the newest bots... but I think I wrote enough wall of text for today.

    I hope this text will be read by some SE employees... in the hope they think about it, and not have FFXIV suffer the same problem.

    Thanks,
    Stiller_Fan
    -not being hacked since 5 years (never).

  2. #2
    The Syrup To Waffles's Waffle
    Join Date
    Jun 2007
    Posts
    5,045
    BG Level
    8
    FFXIV Character
    Cair Bear
    FFXIV Server
    Excalibur
    FFXI Server
    Fenrir

    Quote Originally Posted by Stiller_Fan View Post
    I'm writing this, because of I get tired of sending "Suggestions" via the POL Online formular, which obviously get ignored.
    So what makes you think posting it here will work? Hint: they don't really care.

  3. #3
    Smells like Onions
    Join Date
    Oct 2007
    Posts
    4
    BG Level
    0

    Well... it wouldn't be the first time a Online-Game-Provider changes something due to "popluar demand". Maybe I'm just trying to make people make some constructive suggestions themselfes to SE, so I'm not the only one caring about your accounts

  4. #4
    Ridill
    Join Date
    Aug 2008
    Posts
    12,467
    BG Level
    9
    FFXIV Character
    Satori Komeiji
    FFXIV Server
    Sargatanas
    FFXI Server
    Asura

    Its obvious that they know about BG. I mean, Sage Sundi was wearing a BG hat at Vana'Fest 2009.

    Either way, I've been hack free since I started playing Anarchy Online in 2001.

    I don't know how, don't know why, but I thank whoever's out there for my luck.

  5. #5
    Old Merits
    Join Date
    Oct 2007
    Posts
    1,085
    BG Level
    6

    1. Security token.

    2. Don't be stupid and put yourself at risk by browsing risky sites.

    Honestly, it's not that hard to prevent yourself from getting hacked. I went about four years without a hack before the token came out. (Still hack free after said token).

  6. #6
    Relic Shield
    Join Date
    Apr 2009
    Posts
    1,514
    BG Level
    6

    I like your suggestions Stiller and it is good to see people offering help to other players. The only thing I think would be the stopping point in implementing more steps for users is that people will incessantly bitch and moan about how they have to do that extra step to secure their accounts. In my opinion, if it was an optional feature, it would be more successful.

  7. #7
    New Spam Forum
    Join Date
    Nov 2008
    Posts
    170
    BG Level
    3
    FFXI Server
    Lakshmi

    I love these suggestions and I would love to hear about your idea on how to stop botting.

    But here is what I was thinking. The e-mail confirmation for both server change and password change would stop a lot of the hacks. Of course, if they had a keylogger on your computer for a while they probably know your primary e-mail adress and password. But, that doesn't mean it's not worthwhile.

    All you would have to do is make an e-mail account on another computer (even at the library if you were super paranoid) and then never access it with your computers at home. Then if bad stuff happens, you can reformat your hard drive then the next day go to the library and pick up your new password.

    Also, about the logging in battles. There is an easier fix than the one that you stated. There could be an option that you could select that upon use if your account is logged on from somewhere else, it would disconnect them and change your password to a randomly generated one and e-mail it to you. This way, if you got that message, you could reformat your HDD, go to your e-mail and continue playing. Think of all the accounts that would have been saved by these simple things.

  8. #8
    Sandworm Swallows
    Join Date
    Dec 2007
    Posts
    7,109
    BG Level
    8

    This is like the 100th topic like this. The token is 100% if your not a moron. OMFG some guy in game said i need to go to this website and put in all my info, WTF I GOT HACKED... yea. They have done enough to protect your account.

    Should they have a class when you buy MMO's that you have to take before you can log in? They have done enough, now its your change to not be a dumbass.

    Firefox with plugins, Antispywear, Firewall : Google it.

  9. #9
    WASTE OF CURRENCY
    I CAN'T I CAN'T I CAN'T

    Join Date
    Feb 2006
    Posts
    9,065
    BG Level
    8
    FFXIV Character
    Izzy Izumi
    FFXIV Server
    Sargatanas
    FFXI Server
    Phoenix
    WoW Realm
    Arthas

    This thread happens once a month...

  10. #10
    Dragoon Princess
    My Little Ixion

    Join Date
    Nov 2007
    Posts
    1,668
    BG Level
    6
    FFXIV Character
    Kaiyoko Star
    FFXIV Server
    Sargatanas
    FFXI Server
    Caitsith
    WoW Realm
    Destromath

    <3 my token and firefox with plugins and it loves my FFXI account back :3

  11. #11
    E. Body
    Join Date
    Jun 2008
    Posts
    2,365
    BG Level
    7
    FFXI Server
    Phoenix

    Quote Originally Posted by Yabby View Post
    Firefox with plugins, Antispywear, Firewall : Google it.
    I agree. I haven't had malware on my computer in over 6 years now and I'm not super careful about what sites I visit or what I download. Generally all you need is common sense and the right protection on your computer.

  12. #12
    Hydra
    Join Date
    Oct 2007
    Posts
    121
    BG Level
    3

    Quote Originally Posted by Stiller_Fan View Post
    Hello BG Community,
    One Key-Word in my eyes is "E-Mail confirmation"... let me give a few examples:

    - At the moment, you can easily change a password once you are logged in. Which hackers can do script controlled.

    - The same thing should be done to confirm a server switch.

    - Ok, one more small thing to think of. Changing payment method should require E-Mail verification.

    This thing is also quite simple to prevent. At logon, give the user an option to bind the account to the current ip address for X hours.
    I agree with the email confirmations. The current state of security relying wholly on the security token for security is inadequate. Decent security controls ought to be expected from the beginning of the subscription to FFXI. I do find it unusual that SE expects its playerbase to protect the integrity of their accounts when the default level of security is lacking and the only alternative is to pay for an upgrade.

    I myself have a security token but I do feel as though SE is placing the weight of account security on the user rather than on themselves. You point out weaknesses which can be easily implemented. SE has no good excuse for failing to implement them

    THe IP lock doesn't seem to be as useful to me, and I can see being a mixed bag. RMT can use it to lock themsleves in should they find access to the account. If my dynamic IP address changes mid-session then I will have to wait for the end of the lock. It's only use is to protect against an unlikely hack.

  13. #13
    Sea Torques
    Join Date
    Mar 2007
    Posts
    611
    BG Level
    5
    FFXI Server
    Sylph

    I'd ignore the messages too if the grammar/sentence structure was as bad in the originals as they are here.

  14. #14
    Banned.

    Join Date
    Jul 2005
    Posts
    17,471
    BG Level
    9
    FFXI Server
    Ifrit
    WoW Realm
    Area 52

    I would rather lose my account than give SE another 15$ for security, when it's their fucking job to make it secure.


    And really, the chance of getting hacked is low. It's real, but not worth the 15$ investment.

  15. #15
    Old Merits
    Join Date
    Feb 2006
    Posts
    1,109
    BG Level
    6
    FFXIV Character
    Lex Luger
    FFXIV Server
    Hyperion
    FFXI Server
    Quetzalcoatl
    WoW Realm
    Demon Soul

    Not this shit again.

  16. #16
    Sea Torques
    Join Date
    Oct 2005
    Posts
    604
    BG Level
    5
    FFXI Server
    Gilgamesh

    Just once I would like to see an "open letter to SE" that was concise.

  17. #17
    Campaign
    Join Date
    Sep 2007
    Posts
    6,631
    BG Level
    8
    FFXIV Character
    Sean Kipling
    FFXIV Server
    Midgardsormr

    Quote Originally Posted by Anthonystar View Post
    <3 my token and firefox with plugins and it loves my FFXI account back :3
    This.

    Quote Originally Posted by Militant View Post
    Not this shit again.
    Also this...

  18. #18
    Old Merits
    Join Date
    Nov 2007
    Posts
    1,002
    BG Level
    6
    FFXI Server
    Asura

    IP locking would suck for people on dial-up or DSL connections like me, where if the modem redials, you now have a new IP address and just got locked out for a while. Most ISPs don't give you a static IP address, so if your connection drops, you have a new IP when it goes back up.

    I don't see the point of them having it so that logging in is allowed to force a disconnect of the account on another machine. Most online services I use that limit logins simply error telling you that you are already logged in. Even a failed attempt to log into an FFXI account logs you out of it (or so was stated in a thread I read in the past few months here when security token discussion was still somewhat new), meaning someone can spam you if they figure out your unchangable POL ID or SE ID.

  19. #19
    Sandworm Swallows
    Join Date
    Jul 2008
    Posts
    7,147
    BG Level
    8

    There's one of these every month, like everyone else said. You'd think, with that kind of frequency, SE might have read and considered one of them by now. But they won't, and they never will, and you're wasting your time writing it, our time reading it, and the mods' time locking it.

  20. #20
    Puppetmaster
    Join Date
    Oct 2007
    Posts
    60
    BG Level
    2
    FFXI Server
    Cerberus

    Um, you guys misunderstood the IP locking I think.
    To me it reads, like IP locking occurs only if you select it. So it's optional to the user to lock his account to an IP adress, if you are currently trying to be hacked and thrown out of your account all the time as the guy who tries to hack you logs in.

    And to be honest... if I get DCed due to a hacker, relog and activate the IP lock. I am more happy if I cannot play for a few hours cause my dial up connection reset, instead of finding myselfe naked on some random server.

    But it's really kinda sad to see how "easy" an account can be more secured... and nothing happening.

    And to be honest... if I see recent viruses which spread by Windows Security holes within the glimp of eye, and Microsoft patching this only once a month, I'd be happy about some extra security like that. If I set out an Virus, and get 100 Accounts within the first 60 minutes I'd be happy cause MS, McAfee, Trendmicro and whoever also needs some time to write and publish new Virus definitions

Page 1 of 2 1 2 LastLast

Similar Threads

  1. Open letter to Square FFXI staff.
    By FondofSE in forum FFXI: Everything
    Replies: 5
    Last Post: 2009-04-09, 11:30
  2. An Open Letter to Square-Enix
    By Kimiko in forum FFXI: Everything
    Replies: 191
    Last Post: 2008-12-14, 11:22
  3. Letter to SE with suggestions on improving end game, etc
    By Kiyara in forum FFXI: Everything
    Replies: 12
    Last Post: 2008-05-27, 08:04
  4. I want to come up with an open letter to SE
    By Seki in forum FFXI: Everything
    Replies: 3
    Last Post: 2007-02-03, 19:49