Page 6 of 9 FirstFirst ... 4 5 6 7 8 ... LastLast
Results 51 to 60 of 88
  1. #51
    Player
    Ryuko's Avatar
    Join Date
    Mar 2011
    Posts
    1,281
    Character
    Ryuko Kanzeon
    World
    Hyperion
    Main Class
    Summoner Lv 90
    I am very much a fan of a mobile authenticator. I'm less likely to lose my phone than I am to lose this small keychain thing. Mobile authenticators seem to be pretty stable thus far, although you never know what the future brings.
    (0)

  2. #52
    Player
    Impulse's Avatar
    Join Date
    Mar 2011
    Location
    Gridania
    Posts
    346
    Character
    Dashe Voln
    World
    Excalibur
    Main Class
    Monk Lv 100
    Quote Originally Posted by Jinko View Post
    Hmm ?? You were talking about login and password nothing about authenticator (do I have to quote you or can you not remember what you typed?), its pretty obvious they can't steal an account if they don't have the one time password lol...
    No, you simply took a small part of my post out of context. Read the whole damn thing and read the post I was responding to, you'll see that the other person was talking about a user putting in their one time use, time sensitive code along with the rest of their info, getting hacked in the process.

    Quote Originally Posted by Jinko View Post
    Yea and as I said show me a case of Blizzard running into issues because of this, the password only lasts for a matter of 10 second, so even if the one time password was transmitting over the internet the person on the other end would have to log in with 10-15 seconds making it almost impossible.
    You do realize that neither Delsus or I have said anything about Blizz's app being insecure, right? Gogdamn you're dense.
    (1)

    XI: Shadowtaru (Alexander) Manifest (Shiva) Volnaru (Asura)
    1.0: Delirium Impulse (Mysidia Gungnir)
    ARR: Dashe Herate (Sargatanas) Dashe Voln (Excalibur)

  3. #53
    Player
    Jinko's Avatar
    Join Date
    Mar 2011
    Location
    Gridania
    Posts
    5,656
    Character
    Jinko Jinko
    World
    Moogle
    Main Class
    Arcanist Lv 80
    Ok lets go back a little bit to the first time Delsus quotes me and says

    Quote Originally Posted by Delsus View Post
    Thats what anti-malware is for, and a little bit of common sense, I have never had a keylogger on my laptop, or any virus infact although I use lets say high risk software (not FFXIV related) because I have common sense about where I download from.
    Doesn't it look like you wer the first person to be aggressive for no apparent reason ?

    Funnily it wasn't even a reply to something I said to you and then somehow you turned it around on me about what Ziyyigo-Tipyigo said about phone security.

    Anyways seriously Whatever !!

    Edit:- Ok I get it now, your on the same server, assuming the same LS and one of you is trying to defend the other hence why he replied to my post. (gottcha)
    (0)
    Last edited by Jinko; 04-19-2012 at 06:10 AM.

  4. #54
    Player
    Zumi's Avatar
    Join Date
    Mar 2011
    Location
    Gridania
    Posts
    4,966
    Character
    Zumi Kasumi
    World
    Sargatanas
    Main Class
    Paladin Lv 100
    I don't own a cell phone so this wouldn't really matter to me one way or the other.
    (0)

  5. #55
    Player
    Delsus's Avatar
    Join Date
    Mar 2011
    Location
    Ul'dah, where else?
    Posts
    3,697
    Character
    Delsus Highwind
    World
    Odin
    Main Class
    Red Mage Lv 86
    Quote Originally Posted by Jinko View Post
    Ok lets go back a little bit to the first time Delsus quotes me and says



    Doesn't it look like you were the first person to be aggressive for no apparent reason ?

    Funnily it wasn't even a reply to something I said to you and then somehow you turned it around on me about what Ziyyigo-Tipyigo said about phone security.

    Anyways seriously Whatever !!

    Edit:- Ok I get it now, your on the same server, assuming the same LS and one if trying to defend the other hence why he replied to my post. (gottcha)
    I was mearly saying that there are ways to protect against keyloggers, which is what you (admittedly rightly) said people can use to get your username and password, a valid comment, let me go back a bit:

    Your reply to that was that I am against security, although I said anti-malware will protect against keyloggers.

    How is using anti-malware being agains security, also you will have not used common sense when you downloaded that keylogger because you will have visited a suspicious website/downloaded an infected file/opened a dodgy email attatchment, to get it, they don't just appear from nowhere.

    And with an authenticator (physical or on a smartphone) it would never have happened. Your fault I have no sympathy for you.
    (0)

  6. #56
    Player
    Jinko's Avatar
    Join Date
    Mar 2011
    Location
    Gridania
    Posts
    5,656
    Character
    Jinko Jinko
    World
    Moogle
    Main Class
    Arcanist Lv 80
    Yea I get it now, I'm just guna leave it, somehow wires got crossed ... and everyone lived happily ever after.
    (0)

  7. #57
    Player
    Delsus's Avatar
    Join Date
    Mar 2011
    Location
    Ul'dah, where else?
    Posts
    3,697
    Character
    Delsus Highwind
    World
    Odin
    Main Class
    Red Mage Lv 86
    Quote Originally Posted by Jinko View Post
    Yea I get it now, I'm just guna leave it, somehow wires got crossed ... and everyone lived happily ever after.
    I'm happy to leave it if you now realise we are on the same side, lets just let this awesome idea get to the devs to make (we can have it as a stand alone app, looking at it, the 2.0 app will make it a security flaw because we will be signed in on it, so standalone app yes please, and appart from the work load on the devs, I don't see why they cant get it out before 2.0.
    (1)

  8. #58
    Player
    Lollerblades's Avatar
    Join Date
    Mar 2011
    Location
    Ul'dah
    Posts
    345
    Character
    Aro Foreal
    World
    Ragnarok
    Main Class
    White Mage Lv 100
    Let's hope with enough general interest in the idea it might actually happen
    (0)

  9. #59
    Player

    Join Date
    Mar 2011
    Location
    Gridania
    Posts
    1,987
    Before thinking about that, SE may want to fix the login process in XIV.

    Currently auth is only done once, before starting the game client through a ****** web based interface that uses Internet Explorer (yeah for vulnerabilities \o/). As soon as the credentials are verified and the game client started, then you are free to log on/log off as will. Even worse, you can be connected on as many computers as you want, with different IPs address, provided that your character isn't online on XIV, you can remain on the main menu.

    So technically, any "hacker" could "steal" your credentials (not hard if a victim's computer is infected), log on with them once without the victim being able to notice (the "hacker" would just need to make sure that he uses that OTP before the victim does, but since the auth is based on IE it's really not hard to mess up with your victim IE proxy settings to make sure that he cannot log on for a bit), wait for few hours or a even a day, use victim's account behind his back (impossible to notice unless you are on).

    As for the OTP itself, it works for way longer than 10 or 30 seconds like some people are claiming. You will receive a new password every 10~30 seconds, but any password generated and unused is valid for a way longer time frame (can be as long as 15 minutes)

    I just tried now, generated my OTP @ 0.04. Logged on with it @ 0.11. That is how people still manage to get "compromised" because of phishing website. The window given to the hacker is large enough to enable him to use information the victim entered. And since the OTP the victim entered didn't reach SE's server but the phishing site instead, the OTP remain valid for the hacker to use.
    (0)
    Last edited by Antipika; 04-19-2012 at 08:22 AM.
    Antipika.
    Deathsmiles II-X - Difficulty Lv.2+ (1CC/2LC ALL clear) : http://youtu.be/pjRuwv_-MlI?hd=1
    Touhou 13 - Ten Desires (all clear) : http://www.youtube.com/view_play_list?p=PL194872B2BBA7CA67
    Touhou 12.5 - Double Spoiler (all clear) : http://www.youtube.com/view_play_list?p=BD180E7054F3C1A2
    Touhou 9.5 - Shoot the Bullet (all clear) : http://www.youtube.com/view_play_list?p=53B01AAE8A03BDD1
    Touhou 8 - Imperishable Night (all clear) : http://www.youtube.com/view_play_list?p=7A5C1FF6BDAD1C1B

  10. #60
    Player
    VytasBismarck's Avatar
    Join Date
    Apr 2012
    Posts
    100
    Character
    Vytas Bismarck
    World
    Hyperion
    Main Class
    Thaumaturge Lv 50
    Great idea imho. Doesn't have to replace Security Token, but would be great option for those who prefer to use their phone instead, and don't want to wait for a shipment of Token cause they could just download the app instantly.
    (0)

Page 6 of 9 FirstFirst ... 4 5 6 7 8 ... LastLast