Page 9 of 14 FirstFirst ... 7 8 9 10 11 ... LastLast
Results 81 to 90 of 132
  1. #81
    Player
    Dreathor's Avatar
    Join Date
    Aug 2013
    Posts
    45
    Character
    Dreathor Carter
    World
    Diabolos
    Main Class
    Arcanist Lv 51
    Like people said you should of just sent a report in. If anything left out HOW you found this out etc because now I could do it without issue if I chose to.

    Good find though because this and teleport hack are like "omfg really?" issues lol....
    (0)

  2. #82
    Player
    Silverwalk's Avatar
    Join Date
    Jun 2011
    Posts
    111
    Character
    Silver Darkmoon
    World
    Balmung
    Main Class
    Gladiator Lv 50
    Quote Originally Posted by eyloi View Post
    Sessions are not IP locked. I'm able to use my friend's account from Texas, and he lives in Japan.

    If I tried that in WoW, it would auto lock the account.
    It did IP lock in 1.0 if you tried to log in from a new IP your account was locked untilyou changed your password
    (0)

  3. #83
    Player
    Zoner's Avatar
    Join Date
    Mar 2012
    Posts
    145
    Character
    Zoner Hellscythe
    World
    Coeurl
    Main Class
    Dark Knight Lv 90
    Is this for real, if so it needs to be fixed asap!
    (0)

  4. #84
    Player
    LordSideKicks's Avatar
    Join Date
    Aug 2013
    Location
    Limsa Lominsa
    Posts
    405
    Character
    J'ordance Nunh
    World
    Behemoth
    Main Class
    Marauder Lv 50
    Using the Security token / Software token is still a better protection then having non.
    (0)

  5. #85
    Player
    Splice's Avatar
    Join Date
    Mar 2011
    Location
    LL
    Posts
    79
    Character
    Tachi Grace
    World
    Ultros
    Main Class
    Miner Lv 70
    Some ppl seem to forget the main purpose many ppl use the token setup is so they can avoid the IP lock, so if you get the session ID of someone who used a token it no longer checks the IP. This is almost reversal logic, I would rather have my account lock when it logs in from a diff IP than the alternate.

    You could almost argue the token makes your security worse if you have virus's...
    (0)

  6. #86
    Player
    Alavastre's Avatar
    Join Date
    Aug 2013
    Location
    Gridania
    Posts
    243
    Character
    Gerad Rabanastre
    World
    Cactuar
    Main Class
    Conjurer Lv 50
    Quote Originally Posted by Blimbeard View Post
    That's kind of like saying 'I always wear my seatbelt and I've never had a car crash therefore seatbelts completely prevent car crashes'. You shouldn't really accuse people of being mentally challenged when you obviously have no actual comprehension of what the issue detailed in this thread is.

    Security tokens such as this are not useless, and it is always good practice to exercise safe browsing and PC security. However, anyone with a technical understanding of how these things work can see that there is indeed an issue here. There's no good reason that a session id shouldn't expire after logoout in this sort of context of usage. I would certainly hope that SE address this issue swiftly.
    Don't try to reason with it.
    (3)
    "You keep using that word. I don't think it means what you think it means."

  7. #87
    Player
    Susanoh's Avatar
    Join Date
    Oct 2013
    Posts
    142
    Character
    Cain Villiers
    World
    Hyperion
    Main Class
    Armorer Lv 50
    People who say things like "just don't get hacked or it's your own fault" are missing the point here. The security token is supposed to be an extra layer of security that the user can set up to prevent outside sources from accessing your account. So that even if someone were to obtain your user name and password, they would not be able to easily access your account. If a hacker can easily grab an unencrypted session ID that never expires and use that and only that to access your account indefinitely, it bypasses the token and makes it essentially worthless. Yes, users should take precautions not to get hacked, but SE should also take the necessary steps in ensuring that the security options they're giving to the users are working properly.
    (5)

  8. #88
    Player
    Ronyx's Avatar
    Join Date
    Mar 2011
    Location
    Gridania
    Posts
    394
    Character
    Karse Farrence
    World
    Sargatanas
    Main Class
    Paladin Lv 72
    Interesting. I agree having a token is still good enough, but yah this must be address asap.
    (0)

  9. #89
    Player
    Cienna's Avatar
    Join Date
    Sep 2011
    Posts
    121
    Character
    Cienna Darkmoon
    World
    Balmung
    Main Class
    Archer Lv 50
    Quote Originally Posted by Ronyx View Post
    Interesting. I agree having a token is still good enough, but yah this must be address asap.
    Physical tokens are not bullet proof: RSA which served many Fortune 500 companies had their tokens hacked. Millions were affected, DoD contractors, banks, businesses, etc.. http://www.secureworks.com/cyber-thr...rsacompromise/ more here also: http://www.securenvoy.com/blog/2012/...logy-turnpike/ Tokens can be an extra layer of protection, but that is all they are, an extra layer, you still need to take precautions and SE still needs to patch up holes on their end. It is a 2-way street.
    (2)

  10. #90
    Player
    HamHam's Avatar
    Join Date
    Dec 2011
    Location
    Ul'dah, Eorzea
    Posts
    250
    Character
    Hamtaro Kakamaro
    World
    Excalibur
    Main Class
    Arcanist Lv 50
    Well. Ppl need to stop going to porn sites. That'll save you from 90% of the viruses in the internet.
    (0)

Page 9 of 14 FirstFirst ... 7 8 9 10 11 ... LastLast