Page 1 of 3 1 2 3 LastLast
Results 1 to 10 of 27

Hybrid View

  1. #1
    Player
    Emulord's Avatar
    Join Date
    Apr 2011
    Location
    Federal Union against Child Kidnapping (do not use our acronym)
    Posts
    825
    Character
    Micha'el Mulord
    World
    Ragnarok
    Main Class
    Warrior Lv 70

    Authenticator for iOS / Android

    Hello,

    I find it very convenient to use my iPhone / Android Phone to connect to my Google Account, thanks to the app they have published on their respective stores.

    It works the very same way than the SE token for FFXI/FFXIV, meaning it generates a personal 6-digit code every 30 secs. When using it for the first time, the computer client delivers you a unique key to type in the iPhone app, which will thus guaranty the uniqueness of the 6-digit codes displayed on each of the devices you will use.

    Here's a screenshot of the app:


    The main advantage - non counting the fact you can authenticate from anywhere at anytime, since the app doesn't use any Internet data - is that in case you lose your mobile phone, you can deactivate the app - actually, revoke the codes it will generate - in favor of another one.

    Why not adopting such a system in place of the current authenticators, and in the mean time get rid of the limiting factors of the battery and risks of loss/forgetting/breakage. How annoying it is not to be able to play for a month, because you forgot to take the little gadget with you (talking of my own experience), or to be obliged to contact SE when you've run out of battery...

    Wouldn't it be a logical evolution of SE's technology?

    _________________________________

    Edit 1: The iPhone app IS offline, and it's easy for you to set a password on your phone to prevent intruders to access it. I don't know Android well, but on iOS, there isn't a lot a threats other than the acquaintances who can physically touch your terminal for the moment.

    Edit 2: Would use a smartphone people who'd be able/want to. It is out of the question to make the classical tokens that still work useless, or even to stop further production, they still prove they can keep accounts secure.
    (1)
    Last edited by Emulord; 10-14-2012 at 11:21 PM.
    FFXIV - Actu / Let's Play: www.emulord.com
    (Micha'el Mulord, serveur Ragnarok)

  2. #2
    Player
    Churchill's Avatar
    Join Date
    Jun 2012
    Posts
    513
    Character
    Chad Thunderkoch
    World
    Hyperion
    Main Class
    Marauder Lv 70
    The Security Token is nothing more than a way for SE to get more money. It doesn't actually provide additional security because in order to remove it, all you need to do is have the security code from the back of ANY token - not the token actually linked to the account.

    If SE actually cared about account security, they would use a system such as this like Blizzard uses, but they do not. They care about getting an extra 20$.
    (2)

  3. #3
    Player
    Gokulo's Avatar
    Join Date
    Mar 2011
    Location
    Limsa-Lominsa
    Posts
    462
    Character
    Teisha Linne
    World
    Moogle
    Main Class
    Arcanist Lv 80
    Quote Originally Posted by Churchill View Post
    The Security Token is nothing more than a way for SE to get more money. It doesn't actually provide additional security because in order to remove it, all you need to do is have the security code from the back of ANY token - not the token actually linked to the account.

    If SE actually cared about account security, they would use a system such as this like Blizzard uses, but they do not. They care about getting an extra 20$.
    Hmm, but don't you remove the token after logging on the account? Which would mean you still need to proper one.
    (0)

  4. #4
    Quote Originally Posted by Churchill View Post
    The Security Token is nothing more than a way for SE to get more money.
    The company I work for uses them too, so clearly they're just a money grab. Clearly.
    (0)

  5. #5
    Player

    Join Date
    Apr 2012
    Location
    The Eorzean library
    Posts
    1,118
    Quote Originally Posted by Elexia View Post
    The company I work for uses them too, so clearly they're just a money grab. Clearly.
    Not every security token system is built equally.

    SE's security token system is painfully easy to remove, I'm hoping "The company you work for" doesn't have similar issues.

    And yeah, I agree with an Android / iOS authenticator. More and more people are doing it.
    (0)

  6. #6
    Quote Originally Posted by Ingolf View Post
    Not every security token system is built equally.

    SE's security token system is painfully easy to remove, I'm hoping "The company you work for" doesn't have similar issues.
    They use the same token (Vasco), it's easily removed on SE's end because people would bitch if it wasn't easy to remove. You should know that by now.
    (1)

  7. #7
    Player

    Join Date
    Apr 2012
    Location
    The Eorzean library
    Posts
    1,118
    Quote Originally Posted by Elexia View Post
    They use the same token (Vasco), it's easily removed on SE's end because people would bitch if it wasn't easy to remove. You should know that by now.
    Hence: "Not every security token system is built equally.".

    I'm aware a lot of organisations use Vasco security tokens, but the system behind it is down to the company using it.

    It's a bad decision on SE's part, and goes against the fundamentals of the ideal behind a security token. (not that surprising seeing as it's XI and XIV)
    (0)
    Last edited by Ingolf; 10-14-2012 at 04:15 AM.

  8. #8
    Player
    Coldfire's Avatar
    Join Date
    May 2011
    Location
    Gridania
    Posts
    1,130
    Character
    Nero Coldfire
    World
    Sargatanas
    Main Class
    Goldsmith Lv 50
    I got my token with the CE. But it's true that it has... "issues" xD
    But having the generator on a smartphone would be an even worse idea. While it is a bit more convenient, it also opens new ways for others to steal your account. Nowadays smartphones are targeted by trojans alot. The safest key/TAN-generator is offline.
    (0)

  9. #9
    Player
    Emulord's Avatar
    Join Date
    Apr 2011
    Location
    Federal Union against Child Kidnapping (do not use our acronym)
    Posts
    825
    Character
    Micha'el Mulord
    World
    Ragnarok
    Main Class
    Warrior Lv 70
    Quote Originally Posted by Coldfire View Post
    I got my token with the CE. But it's true that it has... "issues" xD
    But having the generator on a smartphone would be an even worse idea. While it is a bit more convenient, it also opens new ways for others to steal your account. Nowadays smartphones are targeted by trojans alot. The safest key/TAN-generator is offline.
    The iPhone app IS offline, and it's easy for you to set a password on your phone to prevent intruders to access it. I don't know Android well, but there isn't a lot a threats of this kind on iOS for the moment.
    (0)
    FFXIV - Actu / Let's Play: www.emulord.com
    (Micha'el Mulord, serveur Ragnarok)

  10. #10
    Player
    Norack's Avatar
    Join Date
    Nov 2011
    Posts
    649
    Character
    Norack Sunstorm
    World
    Sargatanas
    Main Class
    Conjurer Lv 80
    Quote Originally Posted by Emulord View Post
    The iPhone app IS offline, and it's easy for you to set a password on your phone to prevent intruders to access it. I don't know Android well, but there isn't a lot a threats of this kind on iOS for the moment.
    But it is attached to a foreign hardware device. Even if it never goes online, there are hundreds if not thousands of other ways to steal it. Blizzard is able to do it cause they have the money needed for forensic and security specialists and I doubt SE has that kinda money anymore.
    (0)

Page 1 of 3 1 2 3 LastLast