Page 1 of 2 1 2 LastLast
Results 1 to 10 of 13
  1. #1
    Player
    RyanW's Avatar
    Join Date
    Sep 2013
    Posts
    9
    Character
    Rhys El
    World
    Leviathan
    Main Class
    Lancer Lv 50

    SQEX TOKEN should replicate Google 2-step encyption.

    The requirement to enter a one-time password each time users log in makes the SQEX TOKEN app less appealing as a security solution.

    SQEX has incorrectly flagged my account as compromised three times, usually when I play outside of a normal time (like the occasional all-night session). I downloaded the SQEX Token to try and prevent this inconvenience.

    After using it for a few days, I would rather change my password every months when SQEX incorrectly thinks I've been hacked and locks my account.

    Suggest that SQEX attempt to replicate the user experience of Google's "2-step encryption."
    1. User registers phone and links to account.
    2. User logs in for first time and enters one-time code.
    3. Users computer is securely synced to account
    4. No further "one-time password" is necessary unless unsafe activity is detected.
    (2)

  2. #2
    Player
    Andrewzz's Avatar
    Join Date
    Sep 2013
    Posts
    53
    Character
    Alassea Stormgaze
    World
    Hyperion
    Main Class
    Archer Lv 50
    I wholeheartedly agree with this.
    (0)

  3. #3
    Player

    Join Date
    Jan 2012
    Posts
    518
    Um, what is "Google's 2-step encryption" and how does that relate to the security problem the Token system SE and many other MMOs and other types of organisation solves?
    (0)

  4. #4
    Player
    Andrewzz's Avatar
    Join Date
    Sep 2013
    Posts
    53
    Character
    Alassea Stormgaze
    World
    Hyperion
    Main Class
    Archer Lv 50
    He's speaking of Google Authenticator. You require to enter the one time code only once on your PC, so you mark it as "safe"

    https://play.google.com/store/apps/d...ticator2&hl=en
    (0)

  5. #5
    Player
    worldofneil's Avatar
    Join Date
    Aug 2013
    Posts
    2,650
    Character
    Scott Pilgrim
    World
    Omega
    Main Class
    White Mage Lv 100
    Quote Originally Posted by RyanW View Post
    Users computer is securely synced to account
    On your local computer the Google identifier is stored in a cookie. If you clear your browser cookies (or even use a different browser), it won't know who you are and you'll have to use the one-time-password again the next time you login to Google.

    If SE were to replicate that behaviour (and mark a computer as safe), they'd have to store that information on your computer somewhere which automatically makes it a target for would-be hackers (like they did with the autosave password file that FFXI used).

    SE probably don't want the headache of people screaming about their accounts being compromised, even though they used one-time-passwords, because it makes the whole system sound insecure so they don't give us the option to register a particular computer as "safe".

    Personally I'd rather they did use Google Authenticator, but as it is right now I have it on my home-screen of my phone and opening it gives me a code straight away so it couldn't really be much simpler.
    (0)

  6. #6
    Player
    Andrewzz's Avatar
    Join Date
    Sep 2013
    Posts
    53
    Character
    Alassea Stormgaze
    World
    Hyperion
    Main Class
    Archer Lv 50
    It could be implemented using IP, so while your modem doesn't reset or if you're using a static IP you won't require to input the code again.
    (0)

  7. #7
    Player
    ZohnoReecho's Avatar
    Join Date
    Aug 2013
    Posts
    958
    Character
    Zohno Reecho
    World
    Ragnarok
    Main Class
    Pugilist Lv 70
    The launcher uses an internet explorer frame, so they can probably its cookies.
    (0)

  8. #8
    Player
    gadzi_h's Avatar
    Join Date
    Oct 2013
    Posts
    129
    Character
    Gadzi Hajaz
    World
    Gilgamesh
    Main Class
    Archer Lv 50
    This happened to me today, SQEX KB documents even say the token is there to prevent the need to change your password and your account will not be flagged if you used the token. But for some reason they flag your account.
    (0)

  9. #9
    Player
    worldofneil's Avatar
    Join Date
    Aug 2013
    Posts
    2,650
    Character
    Scott Pilgrim
    World
    Omega
    Main Class
    White Mage Lv 100
    Quote Originally Posted by Andrewzz View Post
    It could be implemented using IP, so while your modem doesn't reset or if you're using a static IP you won't require to input the code again.
    True and to be fair that is how Guild Wars 2 does it. I have to wonder how many people forget they have a security token added (and lose/change their phone etc) if they use it so infrequently.

    Quote Originally Posted by ZohnoReecho View Post
    The launcher uses an internet explorer frame, so they can probably its cookies.
    Yes that's true, I didn't think of that. I had a look and sure enough there's a cookie for ffxiv-login.square-enix.com.
    (0)

  10. #10
    Player
    Andrewzz's Avatar
    Join Date
    Sep 2013
    Posts
    53
    Character
    Alassea Stormgaze
    World
    Hyperion
    Main Class
    Archer Lv 50
    Quote Originally Posted by worldofneil View Post
    I have to wonder how many people forget they have a security token added (and lose/change their phone etc) if they use it so infrequently.
    Is not like that, your modem will reset itself every week or so, so you would have to input the code on a weekly basis.
    (0)

Page 1 of 2 1 2 LastLast