Results 1 to 10 of 111

Hybrid View

  1. #1
    Player
    Solarra's Avatar
    Join Date
    Jul 2015
    Location
    Gridania
    Posts
    887
    Character
    Sylbritt Muscadet
    World
    Cerberus
    Main Class
    Archer Lv 89
    OP Sorry to hear about your troubles. I have no idea why you aren't getting help since it seems clear the theft occurred while your friend's character was being hacked. I'm not sure if posting here is going to help but it will at least highlight the issue for any FC leaders who may be unaware that unlike other games, 'promote' in FFXIV includes permission to promote to and above your own rank.

    We really need a revamp of the FC 'hierarchy'. This has caused so many problems for FCs due to people not realising how it works and thinking their FC assets are safe.
    Not every FC leader wants to be a dictator but sadly the only way to safeguard the gil, goods etc in your FC is for the leader to prevent other ranks accessing them. As soon as you start sharing power and giving permissions to lower ranks, you are at risk. I'd dearly love Square to make us a proper heirarchy but this issue has been going on for years (as a quick search of this forum will show) and nothing has ever been done.

    Edit: Of course, even if the FC leader restricts permissions but then gets hacked themselves, there would be a similar situation to the one here. I would have assumed any money illicitly taken from the chest would be returned if it could be proven that the person taking it had been hacked. However, this incident makes me wonder if that is indeed the case. Some official word on that would help FC leaders decide where to keep their FC's gil.
    (2)
    Last edited by Solarra; 08-25-2019 at 04:01 AM.

  2. #2
    Player
    Valkyrie_Lenneth's Avatar
    Join Date
    Mar 2011
    Location
    Limsa Lominsa
    Posts
    8,037
    Character
    Lynne Asteria
    World
    Jenova
    Main Class
    Viper Lv 100
    Quote Originally Posted by Solarra View Post
    OP Sorry to hear about your troubles. I have no idea why you aren't getting help since it seems clear the theft occurred while your friend's character was being hacked. I'm not sure if posting here is going to help but it will at least highlight the issue for any FC leaders who may be unaware that unlike other games, 'promote' in FFXIV includes permission to promote to and above your own rank.

    We really need a revamp of the FC 'hierarchy'. This has caused so many problems for FCs due to people not realising how it works and thinking their FC assets are safe.
    Not every FC leader wants to be a dictator but sadly the only way to safeguard the gil, goods etc in your FC is for the leader to prevent other ranks accessing them. As soon as you start sharing power and giving permissions to lower ranks, you are at risk.

    I'd dearly love Square to change this and make us a proper heirarchy but this issue has been going on for years (as a quick search of this forum will show) and nothing has ever been done.
    Or just make sure anyone with gil/rank privileges has a security token.
    (5)

  3. #3
    Player
    Solarra's Avatar
    Join Date
    Jul 2015
    Location
    Gridania
    Posts
    887
    Character
    Sylbritt Muscadet
    World
    Cerberus
    Main Class
    Archer Lv 89
    Quote Originally Posted by Valkyrie_Lenneth View Post
    Or just make sure anyone with gil/rank privileges has a security token.
    Sound advice, I definitely agree the token is worth getting. However, I believe some of the people hacked via the fake Twitch accounts had the security token and still got hacked.
    (1)

  4. #4
    Player
    Valkyrie_Lenneth's Avatar
    Join Date
    Mar 2011
    Location
    Limsa Lominsa
    Posts
    8,037
    Character
    Lynne Asteria
    World
    Jenova
    Main Class
    Viper Lv 100
    Quote Originally Posted by Solarra View Post
    Sound advice, I definitely agree the token is worth getting. However, I believe some of the people hacked via the fake Twitch accounts had the security token and still got hacked.
    One time password when entered into a field that isn't the login prompt is still valid when re-entered by the bot that captured it on the fake site.

    Also, OTP uses an algorithm to determine the good passcodes. Assuming you got enough entries into the fake login from one account, you could break the algorithm and be able to log in whenever.
    (2)
    Last edited by Valkyrie_Lenneth; 08-25-2019 at 04:16 AM.

  5. #5
    Player
    Dustytome's Avatar
    Join Date
    Aug 2015
    Posts
    2,707
    Character
    Fox Briarthorn
    World
    Sargatanas
    Main Class
    Culinarian Lv 100
    Quote Originally Posted by Solarra View Post
    Sound advice, I definitely agree the token is worth getting. However, I believe some of the people hacked via the fake Twitch accounts had the security token and still got hacked.
    From what I saw, that was always a case of people readily giving the information (albeit not to whom they thought they were submitting it to) over to a 3rd party. If you tell someone your login information and the current one time password, they can log in immediately and that's just what the scammers did.
    (3)

  6. #6
    Player
    NanaWiloh's Avatar
    Join Date
    Aug 2015
    Posts
    2,464
    Character
    Nana Wiloh
    World
    Lamia
    Main Class
    Astrologian Lv 100
    Quote Originally Posted by Dustytome View Post
    From what I saw, that was always a case of people readily giving the information (albeit not to whom they thought they were submitting it to) over to a 3rd party. If you tell someone your login information and the current one time password, they can log in immediately and that's just what the scammers did.
    Its known as man in the middle attack. If you enter you login info and OTP on any site other then SE's or the launcher then you are handing access to your account to someone else.
    (0)
    Note: Taking advice from a players alt, is like taking advice from a voice in a dark room. Criticism is a two way street remember that!!

  7. #7
    Player
    Arazehl's Avatar
    Join Date
    Dec 2015
    Posts
    681
    Character
    Julianna Arrisit
    World
    Jenova
    Main Class
    Dancer Lv 90
    How in the world does a level 1 that is in the FC for an hour get ranked an officer's or higher rank within that time to have access to FC funds? Seems to me this is clearly faulted with password sharing which is against ToS and neglect on who has access to deposits and withdrawals of FC funds which again is neglect on the leader of the FC and that of your said "friend".

    This has "neglect" written all over it, and wanting SE (big daddy) to fix things, when you and your FC need to face the consequences that comes from mismanagement. I am surprised they rolled back this friends account. It was awfully nice of them to do this much.
    (8)