| |||||
| | #16 |
| Playing RLXIV Bronze Ribbon of Service Join Date: Dec 2008 Location: Austin, TX
Posts: 615 Style: Light Theme V7 Thanks: 176
Thanked 122x in 70 Posts
| Re: New Hackings Begin ... Security Token or Not. This. They haven't quite yet reached the point of hacking routers or ISPs to intercept sessions. That would probably allow hacking even PS2, depending on details of how it works. After all, the PC malware can have key loggers too. But this is why SSH has an initial key exchange the first time you talk to a new host. BOTH sides exchange their unique public key, and store the other key somewhere. Every time you start a session, they send something encrypted with the private key, and if it doesn't match up, it bitches you about the potential MAN IN THE MIDDLE ATTACK and you have to confirm that you want to continue. HTTPS is also designed to identify MITM situations. FFXI is a bit more complicated, because I think it uses UDP to allow packets to be lost without breaking the connection, so it's not one big stream like SSH or HTTPS. But the main point is that if your protocol isn't secure from a MITM attack, and people are sufficiently motivated, it will happen eventually. And apparently it's easy now on Winderz for malware on your own computer to be MITM. About the only way you can keep a PIN code secure is to do what the US banks do, and inject an encryption key into the pinpad's RAM, which encrypts the PIN with the pad's own unique key before it ever leaves the (potted) hardware device. And the bank has to have a database of every keypad and what key it's using. The difference with the token is that your PIN is effectively 0000, and the encryption is the same for like 30 seconds, so if they're fast enough, they can use it from somewhere else. SE needs to go hire some crypto guys, FAST, and figure out how to secure the password/account information related parts of the protocol. (They can't encrypt everything, because that's a lot of extra CPU usage on the server side.) Whenever you have an amateur roll his own security, there's always going to be holes. So anyhow, I guess this explains the recent drop in RMT gil prices. If SE isn't going to block them from spamming us, the least I can do is watch the price to see how much they're hurting. (Aside: I remember back in the old days of modems, I was shocked when I found out that AOL's protocol transmitted your password in the clear. Holy WTF Batman. I think when they added TCP/IP connections, it was still in the clear at first.)
__________________ Elwynn @ Fairy | PS2 | Rank 10 Windurst, 5 Bastok, 5.5 San d'Oria WHM75 BLM75 PUP49 THF45 NIN40 RDM38 BST37 RNG23 COR20 WAR09 F10.5 W45.0 S39.6 G52.2 Cl60.0+1 L47.2 B36.2 A60.0 Co56.1 more |
| | |
| The following user says "Thank You" to Elwynn for above post: | Pteryx (09-12-2009) |
| | #17 |
| Veteran Member Allied Ribbon of Bravery Join Date: Oct 2003 Location: UK
Posts: 1,570 Style: Light Theme V7 Thanks: 10
Thanked 37x in 23 Posts
My Mood: | Re: New Hackings Begin ... Security Token or Not. To do that don't you also need to input a password from the security token again?
__________________ |
| | |
| | #18 | |
| ~ Mama Gamer ~ Golden Star Join Date: May 2006 Location: Al'Taieu
Posts: 4,480 Style: Light Theme V7 Thanks: 610
Thanked 880x in 569 Posts
My Mood: | Re: New Hackings Begin ... Security Token or Not.
They aren't ever using your token to even get control of your character. As you attempt to log in, the token code that you use while your POL is hanging is what they intercept and use to change your password. I don't think this has happened that much, but from what I read of the thread on BG, it's possible. As far as I know, they haven't been stealing accounts, just taking over your connection and stripping them. People report that their friends red dot for a minute, then warp from what they're doing to delivery box all of their stuff to some 3rd party.
__________________ ~Aksannyi~~Hades~~75WHM~75RDM~75BLM~75SMN~73WAR~67SCH~47BRD~ ~Mama Gamer~~Quitted July 2009~~Excellence LS~ ~~ ~~ ~~ ~~ ~~ ~~ ~~ Quote:
| |
| | |
| | #19 |
| Playing RLXIV Bronze Ribbon of Service Join Date: Dec 2008 Location: Austin, TX
Posts: 615 Style: Light Theme V7 Thanks: 176
Thanked 122x in 70 Posts
| Re: New Hackings Begin ... Security Token or Not. Wow. This is a real {/facepalm} if true. Apparently the FFXI design just relies way too much on the client preventing you from doing crazy things. First speed/pos hacks, then tell spam (which apparently bypasses the client), now delivery boxing in the middle of nowhere? (sure, they could make it check your pos first, just don't idle next to a dbox NPC, lol)
__________________ Elwynn @ Fairy | PS2 | Rank 10 Windurst, 5 Bastok, 5.5 San d'Oria WHM75 BLM75 PUP49 THF45 NIN40 RDM38 BST37 RNG23 COR20 WAR09 F10.5 W45.0 S39.6 G52.2 Cl60.0+1 L47.2 B36.2 A60.0 Co56.1 more |
| | |
| | #20 | |||
| Interior Decorator Bronze Star | Re: New Hackings Begin ... Security Token or Not. Quote:
Quote:
Quote:
__________________ "I have a forebrain, my ability to abstract thoughts allow for all kinds of things" - Red Mage 8-Bit theater | |||
| | |
| The Following 3 Users Say Thank You to Ziero For This Useful Post: |
| | #21 | |
| Junior Member | Re: New Hackings Begin ... Security Token or Not. Quote:
| |
| | |
| | #22 | |||
| The Closer Super Moderator Brass Wings of Service Join Date: Nov 2004 Location: In the little corner in my mind
Posts: 6,942 Style: Light Theme V7 Thanks: 306
Thanked 1,111x in 657 Posts
My Mood: | Re: New Hackings Begin ... Security Token or Not.
My son's account was hacked and he used a token. He is well educated in computers, in fact, he's fucking amazing when it comes to them. So he didn't have a trojan or keylogger or anything on his computer when it happened so don't assume that you HAVE to have one. As I explained in another thread on this forum, the very suspicious thing that happened when he reported it was that they took care of it very quickly. If anyone has dealt with SE, they know how slow they are to fix issues like this so when my son was back in full swing within approx 2 days of reporting it....ya thats damn odd. The GM was just trading him stuff like crazy. He'd say "I had this." and boom he'd get a trade and the GM would give it to him. About the only thing he had a problem with was abjurations...the GM was only going to give him the abj and not the cursed piece. LOL So ya...damn strange that they were so accommodating. He thought he'd be out of the game at least a month. Makes you think that they knew there was an issue somewhere...
__________________ Quote:
Quote:
Quote:
| |||
| | |
| | #23 |
| Sticky Paws Sterling Star Join Date: May 2006 Location: Southern California
Posts: 3,201 Style: Light Theme V7 Thanks: 256
Thanked 678x in 434 Posts
My Mood: | Re: New Hackings Begin ... Security Token or Not.
Meh. There are two kinds of people who can say with confidence "I don't have keylogger or other malware on my computer," when the computer is connected to the Internet. 1. People who know just enough about computers to be dangerous (usually, to themselves). 2. Computer security experts--professionals who work on protecting computers, or breaking computer protections, or both. The rest of us lesser computer geeks go by best practices and hope for no malware.
__________________ “I’m in pain, but I’m happy.” “It hurts, but I can smile.” “That’s why I can tell you from the depths of my being…” |
| | |
| The following user says "Thank You" to IfritnoItazura for above post: | Durahansolo (09-03-2009) |
| | #24 | |
| Lives in Drury Lane Super Moderator Mythril Star Join Date: May 2004 Location: Portugal
Posts: 3,984 Style: Light Theme V7 Thanks: 139
Thanked 500x in 274 Posts
My Mood: | Re: New Hackings Begin ... Security Token or Not. so much truth
__________________ ![]() OMGGGGGGGGGGGG heartframe.tumblr.com Quote:
| |
| | |
| | #25 |
| Is not wearing pants! Join Date: May 2008 Location: Florida ^^
Posts: 440 Style: Light Theme V7 Thanks: 128
Thanked 82x in 49 Posts
| Re: New Hackings Begin ... Security Token or Not.
I posted in another thread, I suspect that 1 or 2 things have happened to SE in the past 30 days. 1. Their Registration server got hacked, and this would explain why TGM's Son was so well taken care of. 2. Someone or some group is very unhappy with SE's 3-d secure decisions. and they have the knowledge to exploit some weakness's in SE's security. Supposedly according to BG the registration servers went down this morning, and people couldn't log into POL or the game. 3. ??? 4. Both |
| | |
| The following user says "Thank You" to ShepardG for above post: | Elwynn (09-04-2009) |
| | #26 |
| The Lone Dark Wolf Brass Ribbon of Service Join Date: Jan 2006 Location: Somewhere in Mexico...
Posts: 1,027 Style: Light Theme V7 Thanks: 7
Thanked 5x in 5 Posts
| Re: New Hackings Begin ... Security Token or Not.
SE is digging it's own grave with the POOREST AND LAMEST customer support that I havee ever known
|
| | |
| | #27 | |||
| Soldier Tony Allied Ribbon of Bravery Join Date: Oct 2006 Location: Flint, MI
Posts: 1,761 Style: Light Theme V7 Thanks: 398
Thanked 259x in 177 Posts
My Mood: | Re: New Hackings Begin ... Security Token or Not. Quote:
Quote:
__________________ ----------------------- ![]() "There will come a day when the world will realize that Superman can no longer create miracles. If my name was Superman, that day would be today." 4/29/2009 - Me Quote:
| |||
| | |
| | #28 |
| The Lone Dark Wolf Brass Ribbon of Service Join Date: Jan 2006 Location: Somewhere in Mexico...
Posts: 1,027 Style: Light Theme V7 Thanks: 7
Thanked 5x in 5 Posts
| Re: New Hackings Begin ... Security Token or Not.
WEll, a freind of mine got hacked, it has been 2 weeks and SE has not given his account back...
|
| | |
| | #29 | ||
| Soldier Tony Allied Ribbon of Bravery Join Date: Oct 2006 Location: Flint, MI
Posts: 1,761 Style: Light Theme V7 Thanks: 398
Thanked 259x in 177 Posts
My Mood: | Re: New Hackings Begin ... Security Token or Not. Quote:
#1 Account gets hacked, info changed so you can't log back in. #2 Call SE to be shut down because none of the information matches. #3 Get told someone will contact you about this. #4 Wait.... #5 Call back. #6 SE Gets tired of you calling so they send you a letter to be notarized and set back. #7 Letter is sent back #8 Wait.... #9 SE emails you some contact information to call them with so that you can get your account unlocked. #10 Call SE to get account back. #11 Get account back. #12 Get to resurface all deleted characters and pay monthly bill lol. That's how it was last April, but I dunno how it works now.
__________________ ----------------------- ![]() "There will come a day when the world will realize that Superman can no longer create miracles. If my name was Superman, that day would be today." 4/29/2009 - Me Quote:
| ||
| | |
| | #30 |
| The Lone Dark Wolf Brass Ribbon of Service Join Date: Jan 2006 Location: Somewhere in Mexico...
Posts: 1,027 Style: Light Theme V7 Thanks: 7
Thanked 5x in 5 Posts
| Re: New Hackings Begin ... Security Token or Not.
He was told by SE that they are investigating the report of "missing" items. The account is currently locked up. The hackers moves his char and his mules to different servers and his CC ws charged 100 UDS so yeah.... |
| | |
![]() |
| Tags |
| begin, hackings, security, token |
| Thread Tools | |
| Display Modes | |
| |