Don't spread false info please. People are dumb enough for not using one (who can). Now we just need to promote the non use of the token.
Printable View
Actually, the authenticator can be bypassed. Someone pointed out a massive security flaw that bypasses the launcher and lets anyone log into any account and all they need is the session ID which is surprisingly easy to obtain. I have personally witnessed this and am shocked at such a security flaw.
Apparently, they have fixed it to be IP-locked now? I don't know the specifics, but people have been reporting that when they log in from a different IP, their account gets locked until they confirm it through email etc. Similar to how things worked in 1.0. For people with dynamic IPs, maybe it will be a hassle, but I think it's a welcome change. I'm not sure how this will affect session IDs, but nonetheless, it will make logins from external areas a bit harder.
If you have something that can read that session from the process believe me that nothing can stop it from redirecting the game login page to a fake one and steal the data you insert.
Just because it can be bypassed doesn't mean you don't have to do the best to protect yourself.
It's as if I wouldn't wear a bulletproof vest because they can shot me in the head anyway.
The session IDs are now being made invalid when you log off. What you are seeing is an interruption in service. If someone tried to log into your account while you are on, they get the error that someone is already logged in, it doesn't boot you out.
Is this what is happening? http://na.finalfantasyxiv.com/lodest...1cbefd7134829f
They changed something, the chances of brute forcing a significant number of session IDs are about as high as the Sun going nova, today. It doesn't have a high enough success rate to make sense to any hacker, not to mention that it gives SE an opportunity to trace them more effectively and IP ban their sorry rear ends.