Results 1 to 10 of 32

Hybrid View

  1. #1
    Player Oddwaffle's Avatar
    Join Date
    Jun 2011
    Posts
    69
    Character
    Yummypie
    World
    Leviathan
    Main Class
    WHM Lv 99
    The security token is something like a coded watch. It ticks every so often (like a watch) and gives you a number. That means it's constantly running and will run out of battery similar to a watch. The battery for these are usually large and can last for a few years unless you constantly press the button to make it shows the numbers. However, the quality of the battery leaves a bit to wonder as it's made in china and I don't have many good experience with china made electronics. On the other hand, I have opened a similar token before and it's possible to replace the battery. You might have to reset it and sync it again with SE (like syncing a watch with your current time).

    While the token is fairly secure, it's not going to miraculously preventing you from getting hacked. I'll give you an example. Suppose you have a keylogger on your PC that can interfere with POL. You log on, type in your 6-digits and the keylogger steals the digits while crashing your POL. So you can't put in new digits to prevent a log on until you can get rid of the keylogger. On the other side of the world, the criminal now has a fresh 6-digit code every time you attempt to log in. Thus he can log in and steal all your stuff. The whole process of stealing all your valuables take about 10-15 on your main if he just throw away the rare/ex and load your character with valuables and teleport it.

    A clear head will go much further in protecting yourself in the hostile internet.
    (0)

  2. #2
    Player Atomic_Skull's Avatar
    Join Date
    Mar 2011
    Posts
    1,248
    Character
    Bjorne
    World
    Fenrir
    Main Class
    MNK Lv 5
    Quote Originally Posted by Oddwaffle View Post
    On the other hand, I have opened a similar token before and it's possible to replace the battery. You might have to reset it and sync it again with SE (like syncing a watch with your current time).
    Square Enix and Blizzard use VASCO Digipass GO 6 tokens. It is not possible to replace the battery in these, it will suicide if you tamper with it. Also the key is kept in volatile RAM and when the battery runs down to a certain % it is lost (I'm not sure if it just runs down and is lost or if the token suicides itself when it determines the battery has lost too much power for it to run reliably anymore, probably the latter)

    It is in theory possible to extract the key from one of these tokens but it requires equipment and facilities only available to large corporations and governments, and because each token has a unique key you would be spending millions to break one person's account and one person's only. So it's completely not worth it. They have designed these things to be very physically tamper resistant.
    (0)