And thats why these forums are best ^_^ /s
but going back on topic. I really like that added that as an option. The more options the better.
for a year, would you rather be secretly filmed at random moments and have the footage uploaded to your social media or loose $100 when ever you said a curse word?
Thank you so, so much for adding third party Authenticator support!
The official Software Token was major liability and massive inconvenience on mobile devices that can switch carriers on the fly. Carrier switching resets the Software Token, requiring the Emergency Removal Password to access your account. This would happen several times a week on my device, making it impossible to log into the game without digging up the Emergency Removal Password, removing the Software Token, and re-registering the Software Token.
Thank you, thank you, THANK YOU!
There are many 2FA you can use aside from Google Auth. I am using 1Password with built in 2FA.
Using 1Password with built-in 2FA defeats the purpose really hard. Now anyone would only need your account password and has everything he needs.
Hi All
As I have to use the Google Authenticator for Work and several other important websites.
I thought I would give it a whirl with FFXIV
Boy I am I glad I set an Emergency Password
Even after checking that both my PC & Mobile are synchronised on time, on average I have to enter at least 3 x 'One-Time Passwords' due to 'Wrong Password Error'
Twice I have been timed out of my account, though it is nice that SE send an email warning that multiple attempts at logging in have just taken place.
So why is FFXIV Launcher so un-reliable with 'One-Time Passwords' compared to Websites I have to log into multiple times per day???
honestly if you're going to use a google compatible authenticator I suggest Winauth on your PC and use it to add to Authy on your Cellphone/tablet. I haven't used the google garbage for years, it's old/clunky an has no way to backup incase something happens to your device. you can do a encrypted backup of Winauth and put it wherever you know you will have access to it should something happen and Authy is cloud based encrypted(if you lose your password for it you lose all the authenticators in it)
Because it's very specific about the time and only allows the password for the 30 second window you are in. Technically it's more secure, but it doesn't allow for any time skew and increases the potential errors for clients if their clocks are slightly out.
Although other websites will have their own rules, in my experience it's common that anything requiring a one time password would accept the current password, but also the password before AND the password after (so increasing the login window size from 30 seconds to 1 minute and 30 seconds). This is why with other websites you can still submit as password as it's about to change, but with XIV as soon as the password changes, it's instantly denied.
It'd be nice if SE would change their system to do this as well, but I'm just happy they're using a standard authenticator now so I'll live with it. If your password is about to timeout, just wait for it to change first
Edit: Also just adding, whatever software you're using to generate the code might not be looking at the current time and rather generating the password right now and just showing a 30 second timer. The password should be changed at :00 and :30 seconds in the minute, but some software just ignores that.
You can check by loading up your software to generate a code and then also watching the clock. If it changes at anything other than :00 or :30 then the software is wrong and that's why you get the login problems. As mentioned above with other websites this isn't a problem as they accept the passwords that come before/after, but XIV is more picky.
Last edited by worldofneil; 05-26-2021 at 03:20 AM.
I believe the feature he wants is part of Blizzards launcher.
If your device and IP address do not change, you don't have to log in again. When I load the app I'm auto logged in and don't need to use my authenticator again until I manually log out of the app.
It's no less secure from outsiders, as a different IP or device throws up a "enter authenticator code" message, but it is less secure from inside. Like your pissed off sibling can log in your computer while you're not there just to screw with you for example.
If I didn't fully trust my husband, I'd not use that option, and if I had kids around I'd *certainly* not use it, but it is definitely convenient.
It's basically protection from brute force hacks. No more, no less.
That.. sounds pretty dangerous. The longer the window the more likely that those phishing sites would get hold of the victims’ accounts, which defeats the part of the point of having 2FA.Although other websites will have their own rules, in my experience it's common that anything requiring a one time password would accept the current password, but also the password before AND the password after (so increasing the login window size from 30 seconds to 1 minute and 30 seconds). This is why with other websites you can still submit as password as it's about to change, but with XIV as soon as the password changes, it's instantly denied.
It'd be nice if SE would change their system to do this as well, but I'm just happy they're using a standard authenticator now so I'll live with it. If your password is about to timeout, just wait for it to change first
I actually switched from the SE’s own app to Microsoft’s Authenticator in hopes of a shorter window, because SE’s own one felt pretty long.
Absolutely, although this is only a problem when users copy/paste links and give their information out without actually checking if they're official... Maybe SE had enough of people of falling for this hence the made it only a very short window.
i can't remember how long the SE official app was for their OTP, but anything based on Google Authenticator's OTP system is in 30 second intervals so using another client doesn't make any difference as they're all still generating 30 second codes.
|
![]() |
![]() |
![]() |
|
Cookie Policy
This website uses cookies. If you do not wish us to set cookies on your device, please do not use the website. Please read the Square Enix cookies policy for more information. Your use of the website is also subject to the terms in the Square Enix website terms of use and privacy policy and by using the website you are accepting those terms. The Square Enix terms of use, privacy policy and cookies policy can also be found through links at the bottom of the page.