Yeah, I suppose this is true.Neither have I but it doesn't mean it never happens. Nothing is foolproof.
The authenticators, whether software or physical, are an additional layer of protection that help reduce the risk. I don't have a mobile phone so I had to get the physical token. Do I regret paying the $15 for it (which included the shipping/handling fees)? Not one bit. Do I think my account is 100% secure because I have one? Of course not. I still need to use common sense in my online interactions. Even normally careful people can make mistakes sometimes.
One thing I'll note is that a password manager is really useful here, and not for the reason you'd expect. If you get what looks like it's supposed to be a login page, and you hit 'auto-fill' on your password manager and it does not fill out, then that's a big warning sign that you might not be on the site you think you are. Because the password manager doesn't care what the site looks like, it looks at the URL and sees it isn't where it thinks it's supposed to be. That's half of the reason I have my parents using password managers now. (The other half being "please stop using the same 4 passwords everywhere, dad, or writing down every password in a notebook, mom; your approach to security is going to give me an aneurysm".)
I mean, even savvy sorts can have an off day and fall for it, especially if tired. One of my friends fell for this, even though they normally would not; they'd had a long day, they were exhausted, they logged on to check stuff and got a tell, and copy/pasted it to look at it without really thinking or fully engaging brain the way they normally would. (And lost a looooot of gil as a result.) Using a password manager's autofill would've probably provided the "Wait, why didn't that work?" moment that would've shaken them back to full awareness rather than exhausted-brain autopilot.
The 2FA token is great, but it isn't enough. Plus the Square-Enix 2FA token also has a very long timer on it; if you provide that 2FA code on a phishing site (as you are baited into doing on this one), there is more than enough time for someone to log in as you. I mean, even the standard TOTP or HOTP implementations that Google Authenticator, Authy, 1Password, etc. have are flawed that way; they just have shorter (30 second) timers. But with bots that could log in with the provided credentials, even the 30 second window would probably be long enough.
Though, I mean, the best (and final) defense against such things is "just be careful whenever you have a login page which you didn't type the address for yourself".
I aim to make my posts engaging and entertaining, even when you might not agree with me. And failing that, I'll just be very, VERY wordy.Originally Posted by Packetdancer
The healer main's struggle for pants is both real, and unending. Be strong, sister. #GiveUsMorePants2k20 #HealersNotRevealers #RandomOtherSleepDeprivedHashtagsHere
The rest of your post is excellent and I agree with it I just wanna touch on this bit.
It's very likely automated. There isn't someone sitting around waiting for an alert to pop up telling him someone fell for the phishing site. It's much more likely that once someone enters that information it's nearly instantly populated into a game client and logged in without human intervention.
It's only at that point a human operator would probably make more sense to take over, but even then I wouldn't put it past them to bot the gil removal, FC gil check, and future tell spam.
http://king.canadane.com
Oh, I agree; it absolutely is. I suspect the entire process is automated given how quickly it happens, and how it seems to work identically for everyone who’s reported it. There wouldn’t even need to be any human involvement beyond the victim entering their information. I meant “someone” in the abstract sense, as even if the login is done entirely automated there’s still someone behind the scenes running those bots.The rest of your post is excellent and I agree with it I just wanna touch on this bit.
It's very likely automated. There isn't someone sitting around waiting for an alert to pop up telling him someone fell for the phishing site. It's much more likely that once someone enters that information it's nearly instantly populated into a game client and logged in without human intervention.
I aim to make my posts engaging and entertaining, even when you might not agree with me. And failing that, I'll just be very, VERY wordy.Originally Posted by Packetdancer
The healer main's struggle for pants is both real, and unending. Be strong, sister. #GiveUsMorePants2k20 #HealersNotRevealers #RandomOtherSleepDeprivedHashtagsHere
Contact a GM in-game, I don't think "general discussion" will help.
Larek Darkholme @ Ragnarok
Last edited by Yue_Amariyo; 07-08-2020 at 05:05 AM.
Hello, nice to meet you!
FF14 player as of: 6/3/2020.
Platform: Ps4
|
![]() |
![]() |
![]() |
|
Cookie Policy
This website uses cookies. If you do not wish us to set cookies on your device, please do not use the website. Please read the Square Enix cookies policy for more information. Your use of the website is also subject to the terms in the Square Enix website terms of use and privacy policy and by using the website you are accepting those terms. The Square Enix terms of use, privacy policy and cookies policy can also be found through links at the bottom of the page.