Results 1 to 10 of 62

Hybrid View

  1. #1
    Player
    Klaleara's Avatar
    Join Date
    May 2020
    Posts
    104
    Character
    Sylveras Wolfedrake
    World
    Jenova
    Main Class
    Black Mage Lv 85
    Quote Originally Posted by Valkyrie_Lenneth View Post
    Nah, they capture the code with the fake login site then immediately enter it into the client. That's how they login.


    2fa won't help you if you give them the code lol.
    Depends on the 2fa you have? Most 2fa's is just a text to your phone, not an actual token. It seems that FF14 uses the token version though, which is meh imo.
    (0)

  2. #2
    Player
    Valkyrie_Lenneth's Avatar
    Join Date
    Mar 2011
    Location
    Limsa Lominsa
    Posts
    8,038
    Character
    Lynne Asteria
    World
    Jenova
    Main Class
    Viper Lv 100
    Quote Originally Posted by Klaleara View Post
    Depends on the 2fa you have? Most 2fa's is just a text to your phone, not an actual token. It seems that FF14 uses the token version though, which is meh imo.
    No I mean, you have to put in the code it gives you when you log in right?

    If you give them the code when you "log in" to the phishing site, then the 2fa is pointless because you gave them the code to get in.
    (10)

  3. #3
    Player
    Klaleara's Avatar
    Join Date
    May 2020
    Posts
    104
    Character
    Sylveras Wolfedrake
    World
    Jenova
    Main Class
    Black Mage Lv 85
    Quote Originally Posted by Valkyrie_Lenneth View Post
    No I mean, you have to put in the code it gives you when you log in right?

    If you give them the code when you "log in" to the phishing site, then the 2fa is pointless because you gave them the code to get in.
    A lot of (And my preferred method) of 2FA tokens are pushed. Meaning, you'll get a text, or a push to your 2FA app. Meaning, it can't get scammed like this due to the fact that the site would tell you to put in your 2FA, but you couldn't receive your 2FA token since you actually didn't attempt to sign in.

    The scammers would get your login info, but they wouldn't actually be able to get into your account, due to the fact that they didn't get your token.
    (0)