Results 1 to 9 of 9
  1. #1
    Player
    AdamuKun322's Avatar
    Join Date
    Aug 2013
    Posts
    684
    Character
    Sinon Everglade
    World
    Ultros
    Main Class
    Gladiator Lv 80

    SE what countermeasures are taking for the Heartbleed Bug?

    My account may have been compromised by it and I have e-mailed support to fix the problem. So, what countermeasures are you taking or is anyone else having issues trying to log in with all the correct credentials and it keeps saying you're wrong?
    (0)

  2. #2
    Player Zaft's Avatar
    Join Date
    Jan 2012
    Location
    Ul'dah
    Posts
    703
    Character
    Leo Strut
    World
    Excalibur
    Main Class
    Gladiator Lv 70
    Quote Originally Posted by AdamuKun322 View Post
    My account may have been compromised by it and I have e-mailed support to fix the problem. So, what countermeasures are you taking or is anyone else having issues trying to log in with all the correct credentials and it keeps saying you're wrong?
    Square Enix hasn't said whether or not they were effected by Heartbleed. That being said, give support a call and they'll see what's going on with your account.

    Remember, the best way to secure any account is with an authenticator. You can buy one for something like $7 (free S&H), or just download the app on your phone. Even if your username/password get compromised, it's very difficult to get into an account with an authenticator.
    (0)

  3. #3
    Player
    AdamuKun322's Avatar
    Join Date
    Aug 2013
    Posts
    684
    Character
    Sinon Everglade
    World
    Ultros
    Main Class
    Gladiator Lv 80
    Right. I mean atm I am logged into both Forums and Lodestone under an old password and I changed it to a new one, but it still won't let me sign in. I e-mailed SE and will follow up with a call on Monday if the issue is not resolved.
    (0)

  4. #4
    Player
    Ninix's Avatar
    Join Date
    Aug 2013
    Posts
    381
    Character
    Talim Amariyo
    World
    Balmung
    Main Class
    Arcanist Lv 60
    Quote Originally Posted by AdamuKun322 View Post
    Right. I mean atm I am logged into both Forums and Lodestone under an old password and I changed it to a new one, but it still won't let me sign in. I e-mailed SE and will follow up with a call on Monday if the issue is not resolved.
    This has nothing to do with the Heartbleed vulnerability, which SE's management site was not affected by.

    Try clearing your cookies.
    (2)
    Last edited by Ninix; 04-13-2014 at 12:13 PM.

  5. #5
    Player
    Limecat's Avatar
    Join Date
    Dec 2012
    Posts
    1,359
    Character
    Limecat Indignatio
    World
    Hyperion
    Main Class
    White Mage Lv 90
    They're changing the encryption to ROT13.
    (1)

  6. #6
    Player
    Doki's Avatar
    Join Date
    Aug 2012
    Location
    Ul'dah
    Posts
    1,490
    Character
    Doki Waku
    World
    Faerie
    Main Class
    Warrior Lv 100
    I'd love to see an official response to this as well. While I hope it's nothing, it's always nice to be sure.
    (0)

  7. #7
    Player
    Moheeheeko's Avatar
    Join Date
    Aug 2013
    Posts
    757
    Character
    Asrah Stone
    World
    Behemoth
    Main Class
    Conjurer Lv 66
    Get a security key, problem solved.
    (2)

  8. #8
    Player
    C-croft's Avatar
    Join Date
    Sep 2012
    Posts
    907
    Character
    Cloudcroft Ieyasu
    World
    Goblin
    Main Class
    Marauder Lv 52
    lol huge security exploit found, can be used against hardware as well as many important websites such as banks, social sites, email... but nope, gotta attack FFXIV players instead.
    (0)

  9. #9
    Player kidvideo's Avatar
    Join Date
    Sep 2013
    Posts
    803
    Character
    Ember Rage
    World
    Coeurl
    Main Class
    Arcanist Lv 80
    Well... there's this https://lastpass.com/heartbleed/?h=n...tasyxiv.com%2F

    "Site: na.finalfantasyxiv.com
    Server software: Apache
    Was vulnerable: Possibly (known use OpenSSL, but might be using a safe version)
    SSL Certificate: Possibly Unsafe (created 10 months ago at Jun 2 00:00:00 2013 GMT) Additional checks SSL certificate history checks yielded no new information
    Assessment: It's not clear if it was vulnerable so wait for the company to say something publicly, if you used the same password on any other sites, update it now."

    EDIT: Just found what I was looking for:
    "Before you log into a sensitive service check filippo.io/Heartbleed/ to see if the site has updated to SSL 1.01g, although beware some false negatives have been reported. But if it says it’s updated it is. Then you should also check to make sure any previously vulnerable site has updated its ssl certificate which you can do at https://sslcheck.globalsign.com/ or do several of these tests at https://www.ssllabs.com/ "
    (0)
    Last edited by kidvideo; 04-16-2014 at 08:36 AM.