A keylogger will see that you pressed caps lock/shift, that you hit that random £ key, there are 2 ways to avoid a keylogger getting your passwords, they are to use the on screen keyboard and the security token.
all a strong password does is make it alot harder for somone to brute force a password, however this takes alot of time and it is easy to be noticed, therefore it isnt used much, that is why keyloggers are used, so unless you tell me you use the onscreen keyboard then your account is still vulrable to hacking because of a keylogger, that is why banks either use a security token, or a memorable word that you select certain letters from using drop down boxes, which avoid the problems with keyloggers.
I agree I dont know you, but you are still vulnrable to a keylogger even though you use caps, symbols, letters and numbers and with the options we have all you can do to prevent a keylogger is to use the on-screen keyboard or security token.
I do however agree they should give it to players free, or use a smartphone app, or you could have just bought the CE when it was around, and got a token free
Also there is spyware that can take screenshots and send those to hackers which makes the onscreen keyboard, better than a physical one, but doesnt completly solve the problem.
However the only 2 ways to hack an account that uses a security token is the unlikly event of a successful brute force of a password that is constantly changing or to get hold of the algorithm that caclulates the password (which I assume is based on the serial number of the device) if it is based on the serial number then a hacker would need to hack SE and get all the serial numbers of the tokens off thier database and start guessing the OTP with the algorithm and required information for the algorithm to work.
This will take a long time, and after a few accounts got hacked SE would be wise to it if they correctly audit the network and take counter measures.



Reply With Quote


which at the end we should thank The hackers 

