Page 3 of 14 FirstFirst 1 2 3 4 5 13 ... LastLast
Results 21 to 30 of 132
  1. #21
    Player Eldarion18's Avatar
    Join Date
    Oct 2011
    Location
    Empyreal Paradox
    Posts
    103
    Character
    Shawn Cody
    World
    Tonberry
    Main Class
    Lancer Lv 50
    This is a really good find. Wow. This needs to be addressed.
    (5)

  2. #22
    Player
    Ninix's Avatar
    Join Date
    Aug 2013
    Posts
    381
    Character
    Talim Amariyo
    World
    Balmung
    Main Class
    Arcanist Lv 60
    As stupid as this whole system is (seriously, what good is a session ID if the "session" lasts indefinitely??) you probably should not have posted this publicly on the SE forums. I know you mean well but SE has banned for less.
    (1)

  3. #23
    Player
    Histoire's Avatar
    Join Date
    Aug 2012
    Posts
    113
    Character
    Cia Mir
    World
    Goblin
    Main Class
    Scholar Lv 80
    And now I don't feel safe anymore. Token or not, that's insane.
    (4)

  4. #24
    Player
    Moontide's Avatar
    Join Date
    Sep 2013
    Posts
    146
    Character
    Liliha Liha
    World
    Mateus
    Main Class
    Dark Knight Lv 70
    Holy poo pie, is this in bug reports already? This is frightening if it's true.
    (4)

  5. #25
    Player
    Amyas's Avatar
    Join Date
    May 2012
    Location
    Limsa Lominsa
    Posts
    775
    Character
    Amyas Leigh
    World
    Ragnarok
    Main Class
    Armorer Lv 50
    So... all you have to do is get a (very specific) virus?

    Unless SE's official sites get infected, I'm not seeing the issue here.
    (0)

  6. #26
    Player
    TheRac25's Avatar
    Join Date
    Apr 2011
    Posts
    415
    Character
    Krell Ynjynor
    World
    Excalibur
    Main Class
    Fisher Lv 50
    ahh so the mystery of the hijacked accounts spamming has been solved
    making the sessions bound to an ip and expire after one use would probly stop 95% of the rmt spam
    (4)
    Last edited by TheRac25; 10-08-2013 at 02:03 AM.

  7. #27
    Player
    TheRac25's Avatar
    Join Date
    Apr 2011
    Posts
    415
    Character
    Krell Ynjynor
    World
    Excalibur
    Main Class
    Fisher Lv 50
    Quote Originally Posted by Ninix View Post
    As stupid as this whole system is (seriously, what good is a session ID if the "session" lasts indefinitely??) you probably should not have posted this publicly on the SE forums. I know you mean well but SE has banned for less.
    the only people that would benefit by this not being posted are the ones exploiting it to spam rmt adverts
    since SE is too stupid to figure it out after over a month of it being exploited id say its past due
    (1)
    Last edited by TheRac25; 10-08-2013 at 02:11 AM.

  8. #28
    Player
    hobostew's Avatar
    Join Date
    Aug 2013
    Location
    Ul'dah
    Posts
    459
    Character
    Astrid Arkwright
    World
    Brynhildr
    Main Class
    Monk Lv 90
    I really hope they don't sweep this under the rug. Seems like one SERIOUS oversight! <_<

    Might want to change the title though as you may end up discouraging some from using an authenticator which would probably cause more harm than good.

    Was anyone else surprised at the OPs post? I half expected a crazy tinfoil conspiracy thread about how a "friend" got hacked and they totally used an authenticator.
    (5)

  9. #29
    Player
    Rane's Avatar
    Join Date
    Mar 2011
    Location
    Limsa Lominsa
    Posts
    663
    Character
    Rane Farstrider
    World
    Excalibur
    Main Class
    Dragoon Lv 100
    Thank you, Taal, for the detailed (yet clear) explanation of what appears to be a major security issue with FFXIV. This is a really disappointing design oversight, and one that Square-Enix needs to fix as soon as possible.


    Quote Originally Posted by TheRac25 View Post
    ahh so the mystery of the hijacked accounts spamming has been solved
    making the sessions bound to an ip and expire after one use would probly stop 95% of the rmt spam
    I thought the same thing when I read the OP. This does seem to explain the hijacked account spamming, though there could be other security flaws being exploited as well.
    (4)

  10. #30
    Player
    GabrielK's Avatar
    Join Date
    Aug 2013
    Location
    Eorzea
    Posts
    183
    Character
    Vyndel Farstrider
    World
    Odin
    Main Class
    Summoner Lv 70
    If this is true, it's a stupid mistake on the security team's part. A ridiculous flaw.
    The minimum they should do is bind the session on IP and invalidate it if a different IP tries to access the service with it.

    Also, I believe their sessions last 1 month... just checked this site's session id... heh.
    (3)

Page 3 of 14 FirstFirst 1 2 3 4 5 13 ... LastLast