Results 1 to 5 of 5
  1. #1
    Player
    Platinum_Disco's Avatar
    Join Date
    Aug 2013
    Posts
    190
    Character
    Mithrandir Olorin
    World
    Jenova
    Main Class
    Pugilist Lv 50

    One-Time Password suggestion

    Why is the input for our one-time password hidden with dots? The phone app I used vividly displays my 6-digit otp, and sometimes I find myself misstyping my otp. Just a small suggestion would be to have the otp box not hide the input, because it really doesn't hide anything
    (1)

  2. #2
    Player
    Nicobo's Avatar
    Join Date
    Nov 2013
    Posts
    1,602
    Character
    Nico Nico
    World
    Goblin
    Main Class
    Alchemist Lv 70
    I recall a story of stolen FF11 account, someone logon his FF11 account (PlayStation2) in his friend's retail game shop,
    he didn't notice the display was projected to another TV inside the shop's display window.
    He used the soft-keyboard and someone outside the shop saw the process and stole his account successfully.
    (0)

  3. #3
    Player
    EricCartmenez's Avatar
    Join Date
    Jun 2014
    Posts
    354
    Character
    Veronica Venom
    World
    Siren
    Main Class
    Archer Lv 90
    The one-time password continually changes, so the person would have to note and get logged in before the password expires, so Platinum_Disco's request is quite valid. That said, this is probably an RSA token, if not a similar 3rd party software, and it's very typical to keep the password hidden when you type even if you're looking at it on your phone or other device.
    (0)

  4. #4
    Player
    Niwashi's Avatar
    Join Date
    Aug 2013
    Posts
    5,248
    Character
    Y'kayah Tia
    World
    Coeurl
    Main Class
    Ninja Lv 50
    Quote Originally Posted by Nicobo View Post
    I recall a story of stolen FF11 account, someone logon his FF11 account (PlayStation2) in his friend's retail game shop,
    he didn't notice the display was projected to another TV inside the shop's display window.
    He used the soft-keyboard and someone outside the shop saw the process and stole his account successfully.
    That could be a danger with the regular password, the one that doesn't change and could be used to log in again. The one-time password is different, though. Once used (or within a few seconds even if not used), it becomes invalid and cannot be used again. It doesn't matter if someone else sees what it was when you logged in, since that won't be the password any more.

    I agree with the OP. Password masking makes sense and should be kept for the main static password, but not for the one-time password.
    (0)

  5. #5
    Player
    Souljacker's Avatar
    Join Date
    Apr 2011
    Posts
    1,220
    Character
    Last Hero
    World
    Coeurl
    Main Class
    Thaumaturge Lv 90
    Why not just offer what Blizzard does and if you are logging in from the same location on the same machine, don't even ask for the one-time password? They have had that in place for years now and I love it. Never once been hacked using it, either - so all those armchair security experts who have no idea how these systems work please give it a rest.
    (0)