Page 13 of 14 FirstFirst ... 3 11 12 13 14 LastLast
Results 121 to 130 of 132
  1. #121
    Player Kosmos992k's Avatar
    Join Date
    Aug 2013
    Location
    Ul'Dah
    Posts
    4,349
    Character
    Kosmos Meishou
    World
    Behemoth
    Main Class
    Paladin Lv 90
    Quote Originally Posted by KisaiTenshi View Post
    Basically, security-wise, it's not possible for SE to secure the client machine (or PS3.) If someone already has a rootkit on that system, absolutely nothing is going to stop the account from being stolen if that's specifically what they're looking for. The Authenticator is only "worthless" in this sense because the machine itself is worthless.
    Securing the PS3 is not a major issue, The only systems which can be rooted are the ones already rooted by their owners, and PSN periodically updates itself to prevent folks with hacked consoles participating in PSN, so their authentication will typically take care of that. In any event there is a dearth of 3rd party malware that does anything to a PS3 rooted or otherwise.
    (0)

  2. #122
    Player
    Annah's Avatar
    Join Date
    Sep 2013
    Posts
    529
    Character
    Annah Gynnterais
    World
    Brynhildr
    Main Class
    White Mage Lv 80
    Quote Originally Posted by Soukyuu View Post
    I don't think posting the thread was the right thing to do OP. There are channels you should have used to report it directly to SE (and by that I don't mean the bug report forums but the ingame "contact us" -> "report a bug" form in the game helpdesk.)
    he did. That's why he posted it here. The thing is, the DEVs and GMs do not even read those reports...the DEV here even said they didn't last week.
    (0)

  3. #123
    Player
    Soukyuu's Avatar
    Join Date
    Mar 2011
    Posts
    2,086
    Character
    Crim Soukyuu
    World
    Ragnarok
    Main Class
    Pugilist Lv 50
    Quote Originally Posted by Annah View Post
    he did. That's why he posted it here. The thing is, the DEVs and GMs do not even read those reports...the DEV here even said they didn't last week.
    You're several pages late, someone told me he did already. Also the devs don't post here, only community reps. And what they said is that they don't provide replies, not that they don't read the reports.
    (1)

    [ AMD Phenom II X4 970BE@4GHz | 12GB DDR3-RAM@CL7 | nVidia GeForce 260GTX OC | Crucial m4 SSD ]

  4. #124
    Player
    Claire_Farron's Avatar
    Join Date
    Aug 2013
    Posts
    16
    Character
    Eclaire Farron
    World
    Sargatanas
    Main Class
    Gladiator Lv 50
    In this thread people who can't potato.
    (0)

  5. #125
    Player
    Jess72's Avatar
    Join Date
    Aug 2013
    Posts
    84
    Character
    Violet Whetu
    World
    Behemoth
    Main Class
    Thaumaturge Lv 85
    What I don't understand is this part..

    I was able to give only an old, supposed to be expired, session ID to a friend and they were able to log into my account and characters from an entirely different location in the world. I did not provide an account name, password, or one time password.

    How exactly did his friend log into the account without account name and password?
    (0)

  6. #126
    Player
    Ticktick's Avatar
    Join Date
    Aug 2013
    Posts
    5
    Character
    Ticktick Seeker
    World
    Behemoth
    Main Class
    Archer Lv 16
    Quote Originally Posted by Jess72 View Post
    What I don't understand is this part..

    I was able to give only an old, supposed to be expired, session ID to a friend and they were able to log into my account and characters from an entirely different location in the world. I did not provide an account name, password, or one time password.

    How exactly did his friend log into the account without account name and password?
    the session id is tied to the account, so if you have the session ID, it thinks you're the other person.
    (2)

  7. #127
    Player
    Cienna's Avatar
    Join Date
    Sep 2011
    Posts
    121
    Character
    Cienna Darkmoon
    World
    Balmung
    Main Class
    Archer Lv 50
    Quote Originally Posted by Jess72 View Post
    What I don't understand is this part..

    How exactly did his friend log into the account without account name & password?
    Using the session ID & the command line, you login without the launcher, thus no password, account name or token needed- just the session ID.
    http://forum.square-enix.com/ffxiv/t...=1#post1390622

    That is where the session ID comes into play. The launcher invokes the game client by executing ffxiv.exe with extra command line parameters. It appends DEV.TestSID=xxxx, where xxx is the session ID, to the launch command. Here is the issue with that. That session ID is now plainly visible with any basic process inspector such as Microsoft's Process Explorer. This means it is incredibly easy for any virus that is on the computer to obtain the information. This also means it is possible to bypass the launcher to load the game client by just repeating the same command at the command line.
    (3)

  8. #128
    Player
    Soukyuu's Avatar
    Join Date
    Mar 2011
    Posts
    2,086
    Character
    Crim Soukyuu
    World
    Ragnarok
    Main Class
    Pugilist Lv 50
    An interesting thing I noticed since the latest patch is that now I am getting a 90k error followed by "authentification failed" one, forcing me to close the client. I seem to not be the only one, see discussion thread here.

    The reason why I'm posting here is, does anyone think they might have implemented a session ID timeout but it's not working as intended? The timespan between those kicks seems to be around 4 hours for me. Maybe the session expires despite having a valid connection?
    (1)

    [ AMD Phenom II X4 970BE@4GHz | 12GB DDR3-RAM@CL7 | nVidia GeForce 260GTX OC | Crucial m4 SSD ]

  9. #129
    Player
    illriginalized's Avatar
    Join Date
    Dec 2011
    Posts
    289
    Character
    Illmortal Tyr
    World
    Excalibur
    Main Class
    Thaumaturge Lv 60
    SE you need to fix this. This is a freaking security hole.
    (1)

  10. #130
    Player
    Devourn's Avatar
    Join Date
    Feb 2014
    Posts
    31
    Character
    Shad Yyz
    World
    Behemoth
    Main Class
    Arcanist Lv 90
    Yeah, good luck with getting an official support response. All I ever see are Forum Moderators apologizing for their ineptitude.
    (0)

Page 13 of 14 FirstFirst ... 3 11 12 13 14 LastLast