Hello im using android. and when i goggle i saw many ppl complaint about one time password. is anyone can recommend a good otp software? i read goggle authenticator is good enough. can i use it for ff14? please need help. thank you guys
Printable View
Hello im using android. and when i goggle i saw many ppl complaint about one time password. is anyone can recommend a good otp software? i read goggle authenticator is good enough. can i use it for ff14? please need help. thank you guys
You do not need a third party tool. SE has a specific app for Android and iPhone to provide the one-time password. It is in the app store for both as, I believe, "Square Enix Software Token".
Technically she is correct. There are many phone compromises that would allow for the software app to be potentially bypassed. That said, the software token is still more secure than not having any at all, as it adds a secondary time-based authentication factor beyond the static name and password.
It can be hacked. Never doubt it. The question in security is never "can" but "is it worth it". As of right now, I would say the answer to this question is no in this case. It is definitely worth it to hack account information in general as it can be used for data mining in general and hacking multiple websites. But as of right now I would say it is not worth it to target specific peoples phones for the off chance of getting a password that must be used in 60 seconds of capture.
So while the security token is absolutely without a doubt more secure than the software token, I do not believe that at this time there is any evidence that the additional security it provides is substantial enough to be necessary for those who do not have one, but do have the ability to use a software token.
The problem that people encounter with the Android/iOS Token Apps is that someone could still gain control of your phone and figure out your token serial and such and take your account that way. With a physical token, they would need to go to greater lengths.
Or you can have Square Mail you the actual RSA Token, I keep it on my keychain. You don't have to have the app to use it. I've had it since 1.0 and it still works.
I currently use a program called Bluestacks. Its in beta but works well. It is an Android Emulator.
That way I know if I lose my phone or whatever, I have the ability to get the OTP.
I didn't say physical access to the phone, i'm talking about it being compromised over the internet. I mean, many people root/jailbreak their phones without knowing the potential consequences. You can't compromise a physical token over the internet. Sure you can set up a man in the middle attack and such, but that takes more work. So, yes, it makes perfect logical sense.