Page 1 of 2 1 2 LastLast
Results 1 to 10 of 34

Hybrid View

  1. #1
    Player
    Aurikai's Avatar
    Join Date
    Nov 2021
    Posts
    99
    Character
    Auri'kai Starfall
    World
    Faerie
    Main Class
    Bard Lv 90
    Using OTP with FFXIV login is painful, bad enough you need to enter password every time, but OTP also. There's a thing called OAuth that issues security tokens once you pass all authentication checks so you don't need to provide this stuff every time, apparently Blizzard can implement this but not SE. Cumbersome login processes always forces bad security habits by users.
    (0)

  2. #2
    Player
    SaberMaxwell's Avatar
    Join Date
    Jul 2017
    Posts
    1,244
    Character
    Saber Maxwell
    World
    Faerie
    Main Class
    Gunbreaker Lv 90
    Quote Originally Posted by Aurikai View Post
    Using OTP with FFXIV login is painful, bad enough you need to enter password every time, but OTP also. There's a thing called OAuth that issues security tokens once you pass all authentication checks so you don't need to provide this stuff every time, apparently Blizzard can implement this but not SE. Cumbersome login processes always forces bad security habits by users.
    Convenience and security are ever on opposite sides of a spectrum.
    (4)
    Quote Originally Posted by Packetdancer View Post
    I either buy my own sandwich or I end up with pork-nostrils.

  3. #3
    Player
    Aurikai's Avatar
    Join Date
    Nov 2021
    Posts
    99
    Character
    Auri'kai Starfall
    World
    Faerie
    Main Class
    Bard Lv 90
    Quote Originally Posted by SaberMaxwell View Post
    Convenience and security are ever on opposite sides of a spectrum.
    No they aren't, OAuth is easily fixes this, this isn't host based security, doubt you have a clue about IAM systems, so not surprised you would say something that naive.

    Lots of banks and other institutions use that same technology to ease logins, even Office 365 does, even Blizzard, so you're just making excuses for SE spending poorly on security because you lack knowledge of how it works.
    (2)
    Last edited by Aurikai; 10-08-2022 at 11:15 AM.

  4. #4
    Player
    SaberMaxwell's Avatar
    Join Date
    Jul 2017
    Posts
    1,244
    Character
    Saber Maxwell
    World
    Faerie
    Main Class
    Gunbreaker Lv 90
    (4)
    Last edited by SaberMaxwell; 10-08-2022 at 11:18 AM.
    Quote Originally Posted by Packetdancer View Post
    I either buy my own sandwich or I end up with pork-nostrils.

  5. #5
    Player
    Aurikai's Avatar
    Join Date
    Nov 2021
    Posts
    99
    Character
    Auri'kai Starfall
    World
    Faerie
    Main Class
    Bard Lv 90
    No you stated a blanket statement that had nothing to do with the topic at hand, which was OAuth would make it easier for users to login. Saying nothing is 100% secure is like saying you should never drive or fly because cars aren't 100% safe, it's pointless thinking and completely dismissive. You can make excuses for SE not implementing that technology all you want, nothing you've said has provided any relevant counter arguments for why they shouldn't.
    (1)

  6. #6
    Player
    Boblawblah's Avatar
    Join Date
    May 2022
    Posts
    2,322
    Character
    Shara Dei-ji
    World
    Ultros
    Main Class
    Arcanist Lv 90
    Quote Originally Posted by Aurikai View Post
    No you stated a blanket statement that had nothing to do with the topic at hand, which was OAuth would make it easier for users to login. Saying nothing is 100% secure is like saying you should never drive or fly because cars aren't 100% safe, it's pointless thinking and completely dismissive. You can make excuses for SE not implementing that technology all you want, nothing you've said has provided any relevant counter arguments for why they shouldn't.
    Saying "convenience and security are on opposite sides of the spectrum" isn't defending SE, take a step back, you're attacking someone who isn't against you.
    (5)

  7. #7
    Player
    Aurikai's Avatar
    Join Date
    Nov 2021
    Posts
    99
    Character
    Auri'kai Starfall
    World
    Faerie
    Main Class
    Bard Lv 90
    Quote Originally Posted by Boblawblah View Post
    Saying "convenience and security are on opposite sides of the spectrum" isn't defending SE, take a step back, you're attacking someone who isn't against you.
    Then why make that generalized statement at all? It's not relevant to the discussion which is WHY SE hasn't implemented this for users convenience.
    (1)

  8. #8
    Player
    DPZ2's Avatar
    Join Date
    Feb 2015
    Posts
    2,612
    Character
    Dal S'ta
    World
    Gilgamesh
    Main Class
    Bard Lv 97
    Quote Originally Posted by Aurikai View Post
    No you stated a blanket statement that had nothing to do with the topic at hand, which was OAuth would make it easier for users to login. Saying nothing is 100% secure is like saying you should never drive or fly because cars aren't 100% safe, it's pointless thinking and completely dismissive. You can make excuses for SE not implementing that technology all you want, nothing you've said has provided any relevant counter arguments for why they shouldn't.
    The authentication method may be one you prefer, but it is not the be-all-and-end-all you assume.

    The major problem with OAuth as used by Blizzard is that it requires you to have a cell phone or tablet in order to use it. If you don't have one (and it appears to be required for the 'instant' authentication you appear to be pushing), it becomes much more cumbersome to use than a physical authenticator.
    (2)

  9. #9
    Player
    Aurikai's Avatar
    Join Date
    Nov 2021
    Posts
    99
    Character
    Auri'kai Starfall
    World
    Faerie
    Main Class
    Bard Lv 90
    Quote Originally Posted by DPZ2 View Post
    The authentication method may be one you prefer, but it is not the be-all-and-end-all you assume.

    The major problem with OAuth as used by Blizzard is that it requires you to have a cell phone or tablet in order to use it. If you don't have one (and it appears to be required for the 'instant' authentication you appear to be pushing), it becomes much more cumbersome to use than a physical authenticator.
    OAuth has nothing to do with the authentication, you can do OAuth with username and password, it's merely a framework for exchanging temporary tokens to KNOWN devices. The fact that I even need to explain this, shows your way out of depth and shouldn't be arguing this. It's used on every single mobile app you have that doesn't require login every time, most bank websites, and a lot of other companies. I guess you guys know more Microsoft, Okta, Apple, Google, and thousands of others who use this technology every day, apparently Sony is the leader in technology according to your standards.

    This is why hardly participate on these forums, SE can do wrong to most posters here, no matter the facts stacked against them.
    (3)

  10. #10
    Player
    VelKallor's Avatar
    Join Date
    Jan 2021
    Location
    Limsa Lominsa
    Posts
    2,590
    Character
    Vel Kallor
    World
    Kujata
    Main Class
    Red Mage Lv 100
    apparently Blizzard can implement this
    Blizzard couldnt..sorry make that WOULDNT....implement the appear offline feature they promised for five years ( the fact that they blatantly LIED to their players about it didnt help ), have pathetic privacy controls ingame, have a system that allows ANYONE to add you as a friend and track you anywhere, cant or wont implement an account wide ignore system, ties all games to their launcher and FORCED a mandatory voice app on the launcher that CANT be turned off and until a huge uproar, then fixed that voice app to NOT screw with global volume settings, said app was also tied into the entire system sound settings, caused massive system errors because it was a resource hog.

    The fact they they had a/ not tested it to prevent that issue and b/ did not allow players to opt OUT of having it installed in the first place says it all.
    (3)

Page 1 of 2 1 2 LastLast