Someone's trying to get invited to Bayohne's house for Thanksgiving dinner.
Glad someone posted about this. I hope SE fixes this ASAP.
This really should be a high priority I hope we get a response soon.
It's highly likely it only uses a subset of all possible combinations, it may be a hash function instead of a truly random number.
In which case by looking at valid session ID's and trying around those numbers it makes it much more likely to find a "hit".
Also consider that there may be no maximum attempts like a password system, allowing a hacker to try hundreds of possible session ID's a second.
This is much like finding a wireless encryption key.
Why did they remove the IP lock used in version 1.0? Any time your ip changed you had to change your password to unlock your account.
I was able to find this in literally five clicks. Two to start the software, one to select FFXIV, one to open the context menu and one to hit 'properties'. Furthermore, I was able to close the game, copypasta the command line into a console, and it worked.
Also, to all those freaking out over being able to hack SIDs, it's far more likely that someone will try to just use one you've already been using. Someone could just grab the one I found below and use it after I log out; the issue is not the ability to brute-force or guess, it's that the SIDs don't expire upon logout.
http://i.imgur.com/a0wSIm2.png
Session ID's should ALWAYS become invalid at the end of a session. yikes!
Bumping for the night/evening crew. This needs to be fixed please.
http://i1207.photobucket.com/albums/...MaxBumpGIF.gif
I'd like to hear some proper comments on this. How secure are actual logins if this all is true? Is there any point in having a security token at all until then? How afraid do I have to be on every login before this gets fixed (if it is an issue that needs fixing in the first place)?
This is very scary. Seems like a slip up on SE's part. I'm glad people are bringing this up so they can fix it.
For everyone else, be careful when you log into or go onto FFXIV related sites. Make sure they're trustworthy. Like the OP said, sounds like they don't even have to phish or keylog it. Just a virus from a browser vunerability might be enough to get around your security.