Page 2 of 5 FirstFirst 1 2 3 4 ... LastLast
Results 11 to 20 of 46

Hybrid View

  1. #1
    Player
    LittleArrow's Avatar
    Join Date
    Apr 2011
    Posts
    682
    Character
    Little Sprinkles
    World
    Gilgamesh
    Main Class
    Warrior Lv 70
    Maybe someone can explain this to me, I don't understand how they were able to get his account even though he had an OTP. He just got email confirmation to remove the OTP and that confirmation number was never put in. They still took it off and got his account.
    (0)

  2. #2
    Player
    Thoosa's Avatar
    Join Date
    Apr 2017
    Posts
    329
    Character
    Thoosa Starburst
    World
    Lich
    Main Class
    Black Mage Lv 90
    Quote Originally Posted by LittleArrow View Post
    Maybe someone can explain this to me, I don't understand how they were able to get his account even though he had an OTP. He just got email confirmation to remove the OTP and that confirmation number was never put in. They still took it off and got his account.
    That doesn't make sense to me either, if the attackers tried to log onto the official site to reset his account, they would have been asked for a one time password which they wouldn't have had?
    (0)

  3. #3
    Player
    Espon's Avatar
    Join Date
    Aug 2013
    Posts
    1,021
    Character
    N'kilah Razhi
    World
    Cactuar
    Main Class
    Paladin Lv 100
    When you log into a fake website, it asks for your OTP. Once you hand over your info, the website then immediately logs into your account and removes the OTP and sticks a new one on to keep you out of your account. Yes, the OTP changes every minute, but they only need that minute if you accidentally hand that number out.
    (4)

  4. #4
    Player
    LittleArrow's Avatar
    Join Date
    Apr 2011
    Posts
    682
    Character
    Little Sprinkles
    World
    Gilgamesh
    Main Class
    Warrior Lv 70
    Quote Originally Posted by Espon View Post
    When you log into a fake website, it asks for your OTP. Once you hand over your info, the website then immediately logs into your account and removes the OTP and sticks a new one on to keep you out of your account. Yes, the OTP changes every minute, but they only need that minute if you accidentally hand that number out.
    Yes I understand that, but to remove it they need the confirmation which is only sent to the email which we got. I don't understand how they can remove it if they don't get the confirmation code to remove.
    (0)

  5. #5
    Player
    Mosha's Avatar
    Join Date
    Apr 2020
    Posts
    648
    Character
    Mosha Mina
    World
    Balmung
    Main Class
    Warrior Lv 96
    Quote Originally Posted by LittleArrow View Post
    Yes I understand that, but to remove it they need the confirmation which is only sent to the email which we got. I don't understand how they can remove it if they don't get the confirmation code to remove.
    did he use the same password for both email and his SE account?
    (0)

  6. #6
    Player
    DanielNegreanu_Adamantoise's Avatar
    Join Date
    Mar 2022
    Posts
    117
    Character
    Daniel Negreanu
    World
    Adamantoise
    Main Class
    Gladiator Lv 90
    So they got his email too?
    (0)

  7. #7
    Player
    Espon's Avatar
    Join Date
    Aug 2013
    Posts
    1,021
    Character
    N'kilah Razhi
    World
    Cactuar
    Main Class
    Paladin Lv 100
    Quote Originally Posted by LittleArrow View Post
    Yes I understand that, but to remove it they need the confirmation which is only sent to the email which we got. I don't understand how they can remove it if they don't get the confirmation code to remove.
    They don't need the email. Logging into the account gives them the emergency removal code which they can then input to remove your OTP.
    (1)

  8. #8
    Player
    Lieri's Avatar
    Join Date
    Apr 2021
    Posts
    347
    Character
    Valesti Nibelung
    World
    Tonberry
    Main Class
    White Mage Lv 90
    Change the email password. It's more important especially if it's work/business related.
    It could be that they managed to get into the email but marked it as unread after reading it.
    For the things that were stolen the GM will probably return it and ban the hacker. They have the logs.
    I don't think the hacker will destroy the house or release the plot. If anything they will see it as $.
    (0)
    Last edited by Lieri; 06-05-2022 at 10:49 PM.

  9. #9
    Player
    DanielNegreanu_Adamantoise's Avatar
    Join Date
    Mar 2022
    Posts
    117
    Character
    Daniel Negreanu
    World
    Adamantoise
    Main Class
    Gladiator Lv 90
    I really have a hatred for the use of secret words, they are a security anti-pattern.

    What road did you grow up on? Mom’s maiden name? Impossible to figure that info out! Right??

    Well I’m hoping having your email secured is enough to get everything restored.

    It should always be secured by the email account and/or phone number. If you can change the password on an account without those… smh.. the SE should stop whatever they are doing and fix that. And ditch “secret words” while they are at it..
    (2)

  10. #10
    Player
    Valkyrie_Lenneth's Avatar
    Join Date
    Mar 2011
    Location
    Limsa Lominsa
    Posts
    8,037
    Character
    Lynne Asteria
    World
    Jenova
    Main Class
    Viper Lv 100
    Quote Originally Posted by DanielNegreanu_Adamantoise View Post
    I really have a hatred for the use of secret words, they are a security anti-pattern.

    What road did you grow up on? Mom’s maiden name? Impossible to figure that info out! Right??

    Well I’m hoping having your email secured is enough to get everything restored.

    It should always be secured by the email account and/or phone number. If you can change the password on an account without those… smh.. the SE should stop whatever they are doing and fix that. And ditch “secret words” while they are at it..
    It's a lot harder if you haven't plastered yourself all over social media
    (5)

Page 2 of 5 FirstFirst 1 2 3 4 ... LastLast

Tags for this Thread