Security and convenience are on opposite sides of a spectrum.
Security and convenience are on opposite sides of a spectrum.
Yes, the SE token is poorly implemented. It’s not insecure but it does leave a lot to be desired for usability.
They tie the certificate to the device ID which is just silly these days as not only does this prevent multi-device registration options (which all modern MFA solutions: Duo, Okta, Google Authenticator) but I’m sure many of you have experienced the need to re-register the soft token if you restore from a backup or get a new device.
There are better ways to do this now that allows you to register on multiple devices while making sure it’s a device you own.
I would not be in favor of not prompting for MFA every log in like Blizzard allows. There are plenty of ways this can be exploited though you would have to be part of a targeted attack. However they could implement a MFA push so that you just have to accept to decline a log in rather than having to fire up the token app and put in a code every time.
|
|
![]() |
![]() |
![]() |
|
|
Cookie Policy
This website uses cookies. If you do not wish us to set cookies on your device, please do not use the website. Please read the Square Enix cookies policy for more information. Your use of the website is also subject to the terms in the Square Enix website terms of use and privacy policy and by using the website you are accepting those terms. The Square Enix terms of use, privacy policy and cookies policy can also be found through links at the bottom of the page.
Reply With Quote



