Page 6 of 7 FirstFirst ... 4 5 6 7 LastLast
Results 51 to 60 of 66
  1. #51
    Player
    AsakuraVN's Avatar
    Join Date
    Aug 2013
    Posts
    131
    Character
    Kyo Asakura
    World
    Tonberry
    Main Class
    Ninja Lv 70
    Quote Originally Posted by Tupsi View Post
    ....What? I've been playing MMOs since at least 2001 and have NEVER been randomly flagged as RMT or anything.
    It's common, just because it doesn't happen to you doesn't mean it's some extremely rare event...

    Although somehow it seems a lot worse in ARR, due to the game mechanics right now actually encourage RMT, for the fact that it's hard to make gil, no active ingame GMs, chat filter is useless & doesn't even have CD on shout, then comes the lack of easy reporting/blisting, no clear information/communication from devs, crappy support, confusing services, ect... This game right now is RMT paradise...
    Loading...
    (1)

  2. #52
    Player
    Millerna's Avatar
    Join Date
    Mar 2012
    Location
    Gridania
    Posts
    632
    Character
    Millerna Astor
    World
    Phoenix
    Main Class
    White Mage Lv 100
    Quote Originally Posted by OrganizationXIll View Post
    I did and I press the button and it gives me a nice little code. I put it in the one time password blank when logging in and it says "invalid password". Everytime.

    My question if it did work: If it did work... how does it? The little keyfob you press the button on doesn't connect with SE in anyway. You just press the button and it gives a code. If this is the case they servers must have all the codes in a bank and in that case how is it secure? You, in theory, could just use the code it gives you and use it with any other account that also uses the token? I'm glad it doesn't work like that.
    You need to register the token on the square enix account page. If you don't register it, it will tell you your password is wrong. Also, the app doesn't connect to Square servers. The token is generated based on a variety of things including the token's serial number (which you add to your account), current timestamp and other variables.
    (0)

  3. #53
    Player OrganizationXIll's Avatar
    Join Date
    Aug 2013
    Location
    Ul'dah
    Posts
    285
    Character
    Soraxas Straeh
    World
    Goblin
    Main Class
    Conjurer Lv 50
    Quote Originally Posted by Millerna View Post
    You need to register the token on the square enix account page. If you don't register it, it will tell you your password is wrong. Also, the app doesn't connect to Square servers. The token is generated based on a variety of things including the token's serial number (which you add to your account), current timestamp and other variables.
    I have registered it. It still doesn't work. I am pretty sure the app has to connect to SE servers in someway, else how does it know what the little keyfob gives me for a code?
    (0)

  4. #54
    Player
    Keota's Avatar
    Join Date
    Aug 2013
    Location
    Gridania
    Posts
    6
    Character
    Jin Keota
    World
    Phoenix
    Main Class
    Conjurer Lv 50
    Quote Originally Posted by OrganizationXIll View Post
    I did and I press the button and it gives me a nice little code. I put it in the one time password blank when logging in and it says "invalid password". Everytime. I get my family to check behind me as I press each each key and they agree it doesn't work. It requires a smartphone too I assume. The app connects with SE servers and sets the one time password for you.
    Ummmmm, if you turn over the Token you should see a serial number. You need to go onto your Account Page to activate the security token to your account with this number. Once it's been activated you can only log in if you enter the 6-digit code you get when you press the button along with your Username and Password in the launcher.
    (0)

  5. #55
    Player
    Rivienne's Avatar
    Join Date
    Aug 2013
    Posts
    347
    Character
    Rivienne Bertouaint
    World
    Behemoth
    Main Class
    Conjurer Lv 36
    Quote Originally Posted by Tupsi View Post
    The only way to do this is session hijacking, which pretty much means you get specifically targeted.
    Not always specifically targeted per-se, though as part of an overall audience perhaps. Someone running an older browser that has an un-patched exploit, wanders to a specific website, and it is all over. A persistent cross scripting hack via injected code, potentially embedded into a forum post. Then the attackers just have to sit and wait for someone using an older browser who also has a current session open. Probably from logging into the forums. So open these forums which requires key to post, and another forum with has the malicious code embedded in the post itself. Example would be someone who logs into both these official forums as well as third party forums in the same period of time, they have the exploit, the malicious system auto-captures everything, and adds it to the database of accounts to try later.

    I would hope that SE has the usual exploits blocked from their end, but there are browser exploits that you can't avoid. This is why it is always recommended you upgrade you browser with every single security patch. Just in case. Most newer browsers have various techniques to help prevent XSS.
    (0)

  6. #56
    Player
    Felis's Avatar
    Join Date
    Mar 2011
    Location
    Gridania
    Posts
    12,287
    Character
    Skadi Felis
    World
    Ragnarok
    Main Class
    Pugilist Lv 70
    Quote Originally Posted by Lygastin View Post
    the password are not 1234567890..... and sure token hm sounds legit to me that all FF player have to buy token to protect their account.....
    If you have a smartphone you can get the token app for free
    (1)

  7. #57
    Player
    Millerna's Avatar
    Join Date
    Mar 2012
    Location
    Gridania
    Posts
    632
    Character
    Millerna Astor
    World
    Phoenix
    Main Class
    White Mage Lv 100
    Quote Originally Posted by OrganizationXIll View Post
    I have registered it. It still doesn't work. I am pretty sure the app has to connect to SE servers in someway, else how does it know what the little keyfob gives me for a code?
    The app generates its own code, doesn't have anything to do with the physical token. You can also only register 1 token on the account, so you either register a physical token, or you register the app token, you can't use both at the same time.
    (0)

  8. #58
    Player
    Fenwick's Avatar
    Join Date
    Jul 2012
    Location
    Limsa Ul'dania
    Posts
    215
    Character
    Fenwick Fuerlas
    World
    Balmung
    Main Class
    Conjurer Lv 50
    Quote Originally Posted by ilJumperMT View Post
    I have yet to see anyone who was banned to be innocent.
    I take it you have deep personal incite into all of these people, and know them personally to be scumbags? Nope, alright just checking.
    (0)

  9. #59
    Player
    Zaiken's Avatar
    Join Date
    Dec 2011
    Posts
    405
    Character
    Celestia Raine
    World
    Sargatanas
    Main Class
    Pugilist Lv 50
    Doesn't FFXIV will not let you log in if the IP Address is different from your Computer? Meaning if someone log in to your Account from another Computer it will send an email and blocked it?

    I think it will ask you to changed your password if you log in from another Computer with a different IP Address. I guess if you get a key log they will probably have your email account password too. I like how they did it in Tera better, when you log in from different Computer you will need a 4 numbers pass phrased send to your email and you need that to log in and authorize that the current Computer can be allow.

    The most important steps is to have the latest Anti Virus, Windows Firewall, use Fire Fox only instead of Internet Explorer. Never log in to your email or changed your password on a Computer that you been Hacked.
    (1)

  10. #60
    Player
    ispano's Avatar
    Join Date
    Oct 2011
    Posts
    2,753
    Character
    Melfina Amastacia
    World
    Excalibur
    Main Class
    Lancer Lv 60
    Quote Originally Posted by OrganizationXIll View Post
    I have registered it. It still doesn't work. I am pretty sure the app has to connect to SE servers in someway, else how does it know what the little keyfob gives me for a code?
    The tokens are time synced. When you register one with the number on the back, and then use it, the server will know what code you should have at that time due to the time sync. That's why if the battery dies, you can't replace it(the battery) since the token will have lost sync.

    http://en.wikipedia.org/wiki/Security_token

    Read the part where it mentions Time Synchronized Tokens.
    (1)

Page 6 of 7 FirstFirst ... 4 5 6 7 LastLast