Results 1 to 10 of 24

Hybrid View

  1. #1
    Player
    enthauptet's Avatar
    Join Date
    Aug 2015
    Location
    Gridania
    Posts
    719
    Character
    Judy Hopps
    World
    Excalibur
    Main Class
    Dragoon Lv 100
    Quote Originally Posted by worldofneil View Post
    physical token solution.
    Might want to ask RSA if you think keyfobs and software tokens are actually secure. Theoretically producing fewer keys is actually more secure by reducing your attack surface.

    Anyway if you are really this worried about the security of your token then your token would not be your primary concern anyway tbh as your authentication is only as secure as how it is transmitted. Without being privy to any of the details of their system architecture talking about it doesn't mean anything.
    (0)
    Last edited by enthauptet; 10-14-2017 at 03:17 AM.

  2. #2
    Player
    worldofneil's Avatar
    Join Date
    Aug 2013
    Posts
    2,650
    Character
    Scott Pilgrim
    World
    Omega
    Main Class
    White Mage Lv 100
    Quote Originally Posted by enthauptet View Post
    Might want to ask RSA if you think keyfobs and software tokens are actually secure.
    That's not really the topic at hand, but SE aren't using tokens from RSA, they're using rebranded Vasco DIGIPASS GO 6's.

    Quote Originally Posted by enthauptet View Post
    Theoretically producing fewer keys is actually more secure by reducing your attack surface.
    I'll be completely honest, I don't know if that's the case or not. I'll take your word for it!

    Quote Originally Posted by enthauptet View Post
    your authentication is only as secure as how it is transmitted.
    It's transmitted over HTTPS to ffxiv-login.square-enix.com. Their server could be locked down a bit more, but given that we have to provide the OTP each time, personally that's good enough for me. Your mileage may vary.
    (0)