Results 1 to 10 of 24

Hybrid View

  1. #1
    Player
    worldofneil's Avatar
    Join Date
    Aug 2013
    Posts
    2,650
    Character
    Scott Pilgrim
    World
    Omega
    Main Class
    White Mage Lv 100
    Quote Originally Posted by Fyana View Post
    Blizzard, that has a 12 year old MMO much more successful than this one has terrible security.
    I never said terrible. I said weaker.

    Quote Originally Posted by Fyana View Post
    doesn't require you to type it in EVERY single time you log out
    Quote Originally Posted by Fyana View Post
    Stop condescending people when you don't even do your research!
    Please do YOUR research. Any system that caches your authentication is inherently weaker that one that requires it every single time. I'm not really sure how you can disagree with that.

    While the risk of someone coming from the same IP address during that time period is extremely minimal (unless you're somewhere public or in a building where everyone uses the same Internet connection/IP address...), my point is it's still a weakness that SE does not have because they require you to type in a code every time. Blizzard are doing it simply to make it more convenient with a risk they probably consider acceptable.

    Great as push notifications like you're describing are (and yes I have the Blizzard one too), the advantage is that code generation does not require an active Internet connection, receiving a notification does. Amazing as it sounds there are still people that don't have mobile data on their phones and aren't always in areas with Wi-Fi.

    Yes I'm aware that you can generate a code manually using the Blizzard app, and sure SE could support both codes and push, but from their point of view, why bother. What they have works and it integrates well with their physical token solution.
    (4)

  2. #2
    Player
    enthauptet's Avatar
    Join Date
    Aug 2015
    Location
    Gridania
    Posts
    719
    Character
    Judy Hopps
    World
    Excalibur
    Main Class
    Dragoon Lv 100
    Quote Originally Posted by worldofneil View Post
    physical token solution.
    Might want to ask RSA if you think keyfobs and software tokens are actually secure. Theoretically producing fewer keys is actually more secure by reducing your attack surface.

    Anyway if you are really this worried about the security of your token then your token would not be your primary concern anyway tbh as your authentication is only as secure as how it is transmitted. Without being privy to any of the details of their system architecture talking about it doesn't mean anything.
    (0)
    Last edited by enthauptet; 10-14-2017 at 03:17 AM.

  3. #3
    Player
    worldofneil's Avatar
    Join Date
    Aug 2013
    Posts
    2,650
    Character
    Scott Pilgrim
    World
    Omega
    Main Class
    White Mage Lv 100
    Quote Originally Posted by enthauptet View Post
    Might want to ask RSA if you think keyfobs and software tokens are actually secure.
    That's not really the topic at hand, but SE aren't using tokens from RSA, they're using rebranded Vasco DIGIPASS GO 6's.

    Quote Originally Posted by enthauptet View Post
    Theoretically producing fewer keys is actually more secure by reducing your attack surface.
    I'll be completely honest, I don't know if that's the case or not. I'll take your word for it!

    Quote Originally Posted by enthauptet View Post
    your authentication is only as secure as how it is transmitted.
    It's transmitted over HTTPS to ffxiv-login.square-enix.com. Their server could be locked down a bit more, but given that we have to provide the OTP each time, personally that's good enough for me. Your mileage may vary.
    (0)